Legal

Privacy Policy

Last updated 7 May 2026

Who we are

Huka (Pty) Ltd ("Huka", "we", "us") is a South African company registered under the Companies Act 71 of 2008. We operate the Huka project management platform available at huka-za.com and its subdomains.

Our Information Officer is Dawie Willer, reachable at legal@huka-za.com.

What information we collect

We collect the following categories of personal information:

  • Account information — name, email address, job title, and firm name provided during sign-up or demo requests.
  • Usage data — pages visited, features used, and session timestamps collected through server logs and analytics.
  • Project data — content you create in Huka (project records, documents, financial data, client details) on behalf of your firm.
  • Communication data — messages sent through the contact form or to our support address.

We do not collect sensitive personal information (as defined by POPIA) unless you voluntarily provide it in project content.

Why we collect it

We process personal information for the following lawful purposes:

  • Contract performance — to provide, maintain, and support the Huka platform you have subscribed to.
  • Legitimate interest — to improve the platform, diagnose technical issues, and ensure security.
  • Legal obligation — to comply with South African tax, financial, and data protection laws.
  • Consent — for marketing emails (you may opt out at any time).

How long we keep it

  • Account and project data: retained for the duration of your subscription, plus 30 days after cancellation to allow recovery.
  • Audit logs: 90 days (Studio), 2 years (Practice), or as agreed (Enterprise).
  • Contact form submissions: 12 months.
  • Billing records: 5 years as required by the South African Revenue Service.

Who we share it with

We share personal information only with the following sub-processors, each under a written data processing agreement:

  • Supabase Inc. — database and storage provider. Customer data is hosted on AWS infrastructure in the EU (Ireland, eu-west-1) region. Supabase is a US-incorporated company.
  • Vercel Inc. — hosting and deployment platform. Customer data processed by serverless functions runs in the EU (Dublin, dub1) region. Vercel is a US-incorporated company; static assets are served via a global edge network.

All sub-processors are bound by written agreements that restrict their use of personal information to providing services to Huka. We do not sell personal information.

We will notify subscribed customers by email at least 14 days before adding a new sub-processor.

Cross-border data transfers

Your personal information is processed and stored outside the Republic of South Africa, primarily in EU (Ireland) regions. We rely on the following grounds under section 72 of POPIA:

  • Adequate protection — the EU operates the General Data Protection Regulation (GDPR), which provides protection materially equivalent to or exceeding POPIA.
  • Contract performance — the transfer is necessary to provide the Huka platform you have subscribed for.
  • Customer consent — captured through your acceptance of these terms when activating your subscription.

All sub-processors hosting your data outside South Africa are contractually bound to handle it in accordance with POPIA principles, including security safeguards, retention limits, and data subject rights.

If you are a Customer using Huka to process personal information of your own clients (data subjects), you remain responsible for informing those data subjects of the cross-border transfer as part of your own POPIA disclosures. We will provide reasonable assistance and the necessary disclosure language on request.

Your rights under POPIA

As a data subject, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request that we correct inaccurate or incomplete information.
  • Deletion — request erasure of personal information where we no longer have a lawful basis to retain it.
  • Objection — object to processing based on legitimate interest.
  • Complaint — lodge a complaint with the Information Regulator of South Africa.

To exercise any of these rights, contact our Information Officer at legal@huka-za.com. We will respond within 30 days.

Data Processing Agreements

If you use Huka to process personal information on behalf of your clients (as a responsible party or operator), we will sign a Data Processing Agreement with you on request. Contact legal@huka-za.com or use our contact form.

Cookies and analytics

The marketing site uses minimal analytics (page view counts, referrer data) without setting persistent identifiers. The Huka application does not use third-party analytics. We use a session cookie for authentication that is strictly necessary and exempt from consent requirements.

Changes to this policy

We may update this policy when our practices change. Material changes will be notified by email to account holders at least 14 days before they take effect. The current version is always available at this URL. Continued use after the effective date constitutes acceptance.