Distinct-app

Trust Centre

A plain-language look at how Distinct-app handles privacy, security and compliance. For the underlying legal documents themselves, see the Legal Hub.

This page states only what has been verified or is factually true. It does not claim POPIA certification, government approval, or that the platform is "100% compliant" or "fully secure" - no such claims are made anywhere on this site.

Company & privacy governance

Legal entity
DNF Financial Services (Pty) Ltd
Registration
South African private company - Companies and Intellectual Property Commission (CIPC) 2025 / 778485 / 07
Business address
27a Ronalds Road, Kloof, KwaZulu-Natal, 3610, South Africa
Information Officer
T. Stumke - registered with the Information Regulator
Privacy contact
privacy@distinct-app.com

Privacy

Legal

  • PAIA Manual - how to request access to information we hold, under the Promotion of Access to Information Act.
  • A single, platform-wide Terms of Service applies across Distinct-app apps, with an application-specific Privacy Notice or additional operational terms only where applicable - see the Legal Hub.

Security

High-level statements only, for controls that have been technically verified. Detailed infrastructure configuration and vulnerability information are not published here.

  • Business data is isolated per tenant using database-level row security policies, not just application-layer checks.
  • Administrative access to the shared platform console is restricted to authorised super-admin accounts and enforced on every request, not only in the interface.
  • Sensitive internal tables (data-subject requests, compliance evidence, incident records) are not reachable through the public database API at all - only through authorised server-side code.
  • All production traffic is served over HTTPS/TLS.
  • Every application's source code and running deployment is scanned on a recurring schedule for exposed secrets, known-vulnerable dependencies, code-level security issues, and common web vulnerabilities; findings are tracked centrally through to resolution.
  • An incident-response process exists for handling suspected security or privacy incidents.

Subprocessors

Third-party service providers actually in use across Distinct apps. See the full subprocessor register for details.

ProviderServiceData processing / hosting location
SupabaseDatabase, authentication, file storage (per app)eu-north-1 (AWS Stockholm, Sweden)
VercelApplication hostingus-east-1 (Washington, D.C., USA)
CloudflareDNS, some app hosting, R2 object storage, inbound email routing, AI inference fallbackGlobal network; R2 location is bucket-specific (Western Europe for the shared bucket)
Anthropic, PBCAI inference for the in-app AI assistant (primary provider), where enabledUnited States
Google LLC"Sign in with Google" authentication; Gemini AI inference for the assistant and for content generation (Flyer, Logo apps), where enabledUnited States and other locations where Google operates
GitHub, Inc. (Microsoft)Source-code hosting and CI/CD, including automated security and quality scansUnited States
Paystack South Africa (Pty) LtdPayment processing for Distinct-app subscriptions and Paystack-enabled transactionsSouth Africa and other jurisdictions used in Paystack's payment infrastructure
ResendOutbound transactional email (where configured)United States, per Resend's Privacy Policy
sms1.smsmessenger.co.zaSMS delivery (Marketing app)South Africa
Black Forest Labs (FLUX)AI image generation (Logo, Flyer, Marketing apps)Not publicly disclosed by the provider; requests are made via its hosted API

Compliance evidence

  • An Information Officer is registered with the Information Regulator.
  • A process exists for submitting and working data-subject requests (access, correction, deletion, objection, marketing withdrawal).
  • Privacy Notices and other legal documents are version-tracked, with an effective date recorded for each version.
  • A subprocessor register is maintained and reviewed.
  • A Personal Information Impact Assessment (PIIA) process is maintained across the platform's applications.
  • A security-incident response process is documented and maintained.

Detailed internal reports are not published by default. Enterprise customers can request a Trust Pack summarising this information - contact privacy@distinct-app.com.