Trust Centre
A plain-language look at how Distinct-app handles privacy, security and compliance. For the underlying legal documents themselves, see the Legal Hub.
This page states only what has been verified or is factually true. It does not claim POPIA certification, government approval, or that the platform is "100% compliant" or "fully secure" - no such claims are made anywhere on this site.
Company & privacy governance
- Legal entity
- DNF Financial Services (Pty) Ltd
- Registration
- South African private company - Companies and Intellectual Property Commission (CIPC) 2025 / 778485 / 07
- Business address
- 27a Ronalds Road, Kloof, KwaZulu-Natal, 3610, South Africa
- Information Officer
- T. Stumke - registered with the Information Regulator
- Privacy contact
- privacy@distinct-app.com
Privacy
- Privacy Notice - what we collect, why, and your rights.
- Data Subject Rights & Requests - access, correction, deletion, objection, marketing withdrawal.
- Retention information
Legal
- PAIA Manual - how to request access to information we hold, under the Promotion of Access to Information Act.
- A single, platform-wide Terms of Service applies across Distinct-app apps, with an application-specific Privacy Notice or additional operational terms only where applicable - see the Legal Hub.
Security
High-level statements only, for controls that have been technically verified. Detailed infrastructure configuration and vulnerability information are not published here.
- Business data is isolated per tenant using database-level row security policies, not just application-layer checks.
- Administrative access to the shared platform console is restricted to authorised super-admin accounts and enforced on every request, not only in the interface.
- Sensitive internal tables (data-subject requests, compliance evidence, incident records) are not reachable through the public database API at all - only through authorised server-side code.
- All production traffic is served over HTTPS/TLS.
- Every application's source code and running deployment is scanned on a recurring schedule for exposed secrets, known-vulnerable dependencies, code-level security issues, and common web vulnerabilities; findings are tracked centrally through to resolution.
- An incident-response process exists for handling suspected security or privacy incidents.
Subprocessors
Third-party service providers actually in use across Distinct apps. See the full subprocessor register for details.
| Provider | Service | Data processing / hosting location |
|---|---|---|
| Supabase | Database, authentication, file storage (per app) | eu-north-1 (AWS Stockholm, Sweden) |
| Vercel | Application hosting | us-east-1 (Washington, D.C., USA) |
| Cloudflare | DNS, some app hosting, R2 object storage, inbound email routing, AI inference fallback | Global network; R2 location is bucket-specific (Western Europe for the shared bucket) |
| Anthropic, PBC | AI inference for the in-app AI assistant (primary provider), where enabled | United States |
| Google LLC | "Sign in with Google" authentication; Gemini AI inference for the assistant and for content generation (Flyer, Logo apps), where enabled | United States and other locations where Google operates |
| GitHub, Inc. (Microsoft) | Source-code hosting and CI/CD, including automated security and quality scans | United States |
| Paystack South Africa (Pty) Ltd | Payment processing for Distinct-app subscriptions and Paystack-enabled transactions | South Africa and other jurisdictions used in Paystack's payment infrastructure |
| Resend | Outbound transactional email (where configured) | United States, per Resend's Privacy Policy |
| sms1.smsmessenger.co.za | SMS delivery (Marketing app) | South Africa |
| Black Forest Labs (FLUX) | AI image generation (Logo, Flyer, Marketing apps) | Not publicly disclosed by the provider; requests are made via its hosted API |
Compliance evidence
- An Information Officer is registered with the Information Regulator.
- A process exists for submitting and working data-subject requests (access, correction, deletion, objection, marketing withdrawal).
- Privacy Notices and other legal documents are version-tracked, with an effective date recorded for each version.
- A subprocessor register is maintained and reviewed.
- A Personal Information Impact Assessment (PIIA) process is maintained across the platform's applications.
- A security-incident response process is documented and maintained.
Detailed internal reports are not published by default. Enterprise customers can request a Trust Pack summarising this information - contact privacy@distinct-app.com.