Trust Centre
A plain-language look at how Distinct-app handles privacy, security and compliance. For the underlying legal documents themselves, see the Legal Hub.
This page states only what has been verified or is factually true. It does not claim POPIA certification, government approval, or that the platform is "100% compliant" or "fully secure" — no such claims are made anywhere on this site.
Company & privacy governance
- Legal entity
- DNF Financial Services (Pty) Ltd
- Registration
- South African private company — Companies and Intellectual Property Commission (CIPC) 2025 / 778485 / 07
- Information Officer
- T. Stumke — registered with the Information Regulator
- Privacy contact
- privacy@distinct-app.com
Privacy
- Privacy Notice — what we collect, why, and your rights.
- Data Subject Rights & Requests — access, correction, deletion, objection, marketing withdrawal.
- Retention information
Legal
- PAIA Manual — currently in draft, pending legal review and approval. This page will link to the published version once it is approved.
- Product-specific Terms are listed on the Legal Hub for each app that has them.
Security
High-level statements only, for controls that have been technically verified. Detailed infrastructure configuration and vulnerability information are not published here.
- Business data is isolated per tenant using database-level row security policies, not just application-layer checks.
- Administrative access to the shared platform console is restricted to authorised super-admin accounts and enforced on every request, not only in the interface.
- Sensitive internal tables (data-subject requests, compliance evidence, incident records) are not reachable through the public database API at all — only through authorised server-side code.
- All production traffic is served over HTTPS/TLS.
- An incident-response process exists for handling suspected security or privacy incidents.
Subprocessors
Third-party service providers actually in use across Distinct apps. See the full subprocessor register for details.
| Provider | Service | Data processing / hosting location |
|---|---|---|
| Supabase | Database, authentication, file storage (per app) | eu-north-1 (AWS Stockholm, Sweden) — confirmed from project configuration |
| Vercel | Application hosting | Project/deployment-specific — confirm actual configuration |
| Cloudflare | DNS, some app hosting, R2 object storage | Global/distributed; R2 location is bucket-specific (Western Europe for the shared bucket) |
| Paystack | Payment processing (where enabled per app) | South Africa and other jurisdictions involved in Paystack's payment infrastructure |
| Resend | Outbound transactional email (where configured) | United States — per Resend's Privacy Policy |
| sms1.smsmessenger.co.za | SMS delivery (Marketing app) | South Africa-based provider; processing/data-hosting location not contractually confirmed |
| Black Forest Labs (FLUX) | AI image generation (Logo, Flyer, Marketing apps) | Provider confirmation pending |
Compliance evidence
- An Information Officer is registered with the Information Regulator.
- A process exists for submitting and working data-subject requests (access, correction, deletion, objection, marketing withdrawal).
- Privacy Notices and other legal documents are version-tracked, with an effective date recorded for each version.
- A subprocessor register is maintained and reviewed.
- A Personal Information Impact Assessment (PIIA) process is maintained across the platform's applications.
- A security-incident response process is documented and maintained.
Detailed internal reports are not published by default. Enterprise customers can request a Trust Pack summarising this information — contact privacy@distinct-app.com.
This page is a general reference and does not replace legal advice.