Workflow+ is a workflow-automation platform for accounting firms, provided by WorkflowPlus (Pty) Ltd (registration number 2026/531054/07), trading as "Workflow+" ("we", "us", "our"), a private company incorporated in the Republic of South Africa. Under the Protection of Personal Information Act, 4 of 2013 ("POPIA"):
We are the Responsible Party for personal information we collect about you as our customer or website visitor.
Where you use the Service to process personal information about your own clients or employees, you are the Responsible Party for that information, and we act as your Operator. In that role, we process personal information on your instructions in accordance with our Terms of Use.
Our contact details are set out in section 16.
2. Scope of this policy
This policy explains how we collect, use, share, and protect personal information in connection with:
the Workflow+ web application hosted at workflowplus.co.za;
our marketing website at workflowplus.co.za;
the integrations we provide with third-party services, including Karbon and Ignition; and
the AI Assistant feature described in section 12.
3. Personal information we collect
3.1 Information you give us
Account information: your name, business email address, firm/tenant name, and role.
Authentication information: passwords (stored only as hashes), magic-link tokens (short-lived, single-use), and session cookies.
Configuration and content: recipes, work templates, categories, settings, and any other configuration you enter into the Service.
Support and correspondence: messages you send us, including support requests and feedback.
3.2 Information we retrieve on your instruction from Third-Party Services
When you connect a Third-Party Service, we retrieve information from that service using the credentials you provide (for example, a Karbon API key or an Ignition proposal email address). This may include:
From Karbon: work items, work templates, work schedules, contacts (people and organisations), colleagues (Karbon users), tasks, activity timelines, and custom-field definitions and values. This may include the names, email addresses, and role information of your clients and staff, and information relating to work performed for your clients.
From Ignition: proposal metadata, client names, and accepted-service information relayed via email.
We treat this data as Customer Data. You remain the Responsible Party for the personal information within it.
3.3 Information we collect automatically
Usage and diagnostic data: pages viewed, features used, API calls made, timestamps, error messages, and audit-log entries recording actions you take in the Service.
Device and connection data: IP address, browser type and version, operating system, and referring URL.
4. How we use personal information
We use personal information to:
provide, operate, and secure the Service, including authentication, tenant isolation, and audit logging;
perform the integrations you enable (for example, creating work items in your Karbon tenant on your instruction);
respond to your support requests and communicate with you about the Service (for example, service announcements and beta-programme updates);
detect, investigate, and prevent fraud, abuse, and security incidents;
comply with our legal obligations; and
improve the Service. Where we use data for product improvement, we use aggregated and de-identified data wherever possible, and we do not use your Customer Data to train third-party AI models.
5. Legal basis for processing (POPIA)
We process personal information in reliance on one or more of the lawful bases in section 11 of POPIA:
Contract: processing that is necessary to perform our contract with you, or to take steps at your request before entering into a contract (for example, provisioning your Tenant).
Consent: where you have provided consent (for example, by connecting a Third-Party Service and authorising the Service to act on your behalf).
Legitimate interests: our legitimate interest in operating, securing, and improving the Service, in a manner that does not unreasonably prejudice your rights.
Legal obligation: where processing is required to comply with a law of the Republic of South Africa or another jurisdiction that applies to us.
6. How we share personal information
We do not sell personal information. We share personal information only in the ways described below.
Within your Tenant: information you or your Users enter, or that we retrieve on your instruction, is visible to authorised Users of your Tenant.
With Third-Party Services you connect: when you configure an integration, we send instructions and data to that service on your behalf.
With subprocessors: we use trusted subprocessors to host the Service, send emails, and provide the AI Assistant. See section 7.
For legal reasons: we may disclose information if required to do so by law, or if we reasonably believe disclosure is necessary to comply with a legal process, protect the rights or safety of any person, or investigate fraud or a security incident.
Business transfer: if we sell, merge, or reorganise our business, personal information may be transferred as part of that transaction. We will notify affected users where required by law.
7. Subprocessors
We use the following subprocessors to operate the Service:
Subprocessor
Purpose
Location of processing
Render Services, Inc.
Application and database hosting (web application and PostgreSQL)
United States
Resend, Inc.
Transactional email delivery (magic links, invitations, service notifications)
United States
Anthropic, PBC
Large-language-model inference for the AI Assistant feature
United States
GoDaddy Operating Company, LLC
Domain registration and DNS for workflowplus.co.za
United States
We select subprocessors that offer contractual and technical safeguards that we consider appropriate for the personal information we entrust to them. We may update this list from time to time and will keep the current list available on request.
8. Cross-border transfers
Some of our subprocessors process personal information outside the Republic of South Africa, primarily in the United States. Where we transfer personal information across borders, we do so in accordance with section 72 of POPIA, and we ensure that the receiving party is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA.
9. Retention
We retain personal information for as long as we need it for the purposes set out in this policy:
Account and configuration data: for the duration of your Account, and for a reasonable period after termination to allow for reactivation, dispute resolution, and legal or audit obligations, after which it is deleted or de-identified.
Customer Data retrieved from Third-Party Services: for as long as your Account is active and the connection remains configured. On termination of your Account, we delete this data within thirty (30) days, unless we are required by law to retain it for longer.
Audit logs and security records: for up to twenty-four (24) months, so we can investigate incidents and meet security-monitoring obligations.
Marketing correspondence: until you unsubscribe, plus a reasonable period to suppress future messages.
10. Security
We take reasonable and appropriate technical and organisational measures to protect personal information against loss, unauthorised access, disclosure, or destruction. These measures include:
encryption of personal information in transit (HTTPS/TLS);
encryption at rest for our database and application storage;
tenant isolation enforced at the application layer, with tenant-scoped queries on every request;
hashed password storage and short-lived, single-use magic-link tokens;
access controls, audit logging, and role separation between operator and administrator functions;
regular review of dependencies and subprocessors.
No system is perfectly secure. If we become aware of a security compromise involving your personal information, we will notify the Information Regulator and affected data subjects in accordance with section 22 of POPIA.
11. Your rights
Subject to POPIA, you have the right to:
be notified about how we process your personal information (this policy);
request access to the personal information we hold about you;
request that we correct or delete personal information that is inaccurate, out of date, or excessive;
object, on reasonable grounds, to the processing of your personal information;
object to processing of your personal information for direct-marketing purposes; and
lodge a complaint with the Information Regulator (see section 16).
To exercise any of these rights, contact us at the address in section 16. We will respond within a reasonable time and in accordance with POPIA. For requests that concern personal information about your clients (rather than yourself), please raise the request through the firm that acts as Responsible Party for that data.
12. AI Assistant
The Service includes an AI Assistant that uses large-language-model inference provided by Anthropic. When you use the AI Assistant:
Your prompt and a limited set of tool-call results derived from your Customer Data (for example, aggregate work-item counts or a client-work summary) are sent to Anthropic in order to generate a response.
Anthropic acts as our subprocessor. Under our commercial arrangement with Anthropic, your prompts and results are not used to train Anthropic's foundation models.
We keep an audit log of AI Assistant queries associated with your Tenant, so we can operate the feature, investigate issues, and monitor cost and quality.
AI-generated output is probabilistic and may be incorrect. You must not rely on it for any regulated or safety-critical decision without independent verification.
If you would prefer not to use the AI Assistant, you can simply not open or query it. If you would like the feature disabled for your Tenant, contact us.
13. Cookies and website analytics
The Service uses cookies and similar technologies only for essential purposes, including keeping you signed in and remembering your session. We do not currently use third-party advertising cookies. If we introduce analytics cookies in future, we will update this policy and, where required, ask for your consent.
14. Children
The Service is a business tool intended for use by accounting firms and their staff. It is not directed at children under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice in the Service before the change takes effect. The "Effective date" at the top of this policy shows when it was last updated.