Dynamic AFS

Privacy Policy

Last updated:

Ducharme Consulting ("we", "us" or "our") respects your privacy. This policy explains how personal information is handled when you visit this website or use Dynamic AFS (the "service"), including its financial reporting and document management features.

1. Information we collect

  • Account information: your name, email address, user identifier, organisation and access permissions, provided by you, your organisation or our sign-in service.
  • Information you submit: financial records, reports, supporting documents and other content uploaded or entered into the service, which may contain personal information.
  • Support information: details you provide when you contact us or request assistance.
  • Technical information: your IP address, session details and diagnostic or security logs generated when you access the service.

Please only submit information you are authorised to share. Some information is necessary to sign in or use a feature; without it, that feature may be unavailable.

2. How we use information

We use information to authenticate users, manage access to organisations and records, provide reporting and document features, respond to support requests, maintain the service and investigate errors or misuse. Information may also be used to meet contractual obligations and applicable legal requirements.

Depending on the circumstances, processing is necessary to provide the agreed service, comply with law or protect legitimate interests such as service security. Where processing relies on your consent, you may withdraw that consent.

3. Your organisation's information

When your organisation provides access to the service, it determines which records are submitted and who is authorised to access them. We process those records to provide the service to that organisation. Its own privacy policies and retention requirements may also apply. Requests about an organisation's records should be directed to its administrator or information officer.

4. Cookies and similar technologies

The service uses cookies to support sign-in, maintain your session and help protect requests against forgery. You can manage or delete cookies in your browser settings. Blocking cookies may prevent you from signing in or using parts of the service.

Some fonts and interface resources are loaded from external providers, including Google Fonts and content delivery networks. Your browser sends those providers technical information, such as your IP address, when requesting these resources.

5. When information is shared

Information may be available to authorised users and administrators in your organisation and to service providers supporting hosting, storage, authentication and technical support. If your organisation uses connected features such as Google Sheets, information needed for those features is processed through the relevant provider.

Information may also be disclosed where required by law, to respond to lawful requests, protect rights or investigate misuse, or where you or your organisation authorise the disclosure.

6. Security and retention

We use access controls and other reasonable safeguards to protect personal information. No online service or method of storage can guarantee absolute security. Keep your sign-in details confidential and notify your administrator if you suspect unauthorised access.

Information is retained for as long as needed to provide the service and meet applicable contractual, record-keeping and legal requirements. Retention depends on the type of information and your organisation's requirements; deleting an account does not necessarily remove records the organisation must retain.

7. International processing and other websites

Hosting and connected services may process information in countries outside your own. Where applicable, cross-border processing is subject to the protections required by data protection law. External websites and services have their own privacy policies; please review them when following a link or using an integration.

8. Your privacy rights

Subject to applicable law, including South Africa's Protection of Personal Information Act (POPIA), you may request access to your personal information, ask for correction or deletion, object to certain processing, or withdraw consent where processing depends on it. These rights may be limited by legal or contractual record-keeping obligations. We may need to verify your identity before responding.

To make a request, use the contact details below or contact your organisation's information officer. You may also raise a concern with the Information Regulator of South Africa or your local data protection authority.

9. Children's privacy

The service is intended for business and professional use, rather than use by children. If you believe a child has provided personal information through the service without appropriate authorisation, please contact us.

10. Changes and contact

We may update this policy as the service or applicable requirements change. The date above identifies the latest revision.

For questions about this policy or a privacy request, contact your usual Ducharme representative or use the contact details on the Ducharme Consulting website. Please identify the service and describe your request without including passwords or unnecessary sensitive information.