LEGAL · PRIVACY POLICY
Privacy & Data Protection.
How we protect your personal information, organization records, and financial ledger data under POPIA.
LAST UPDATED: AUGUST 2026 · POPIA COMPLIANT
This Privacy Policy outlines how Narrow handles and protects your organization's data, employee information, and financial records.
1. Overview & Commitment to Privacy
Rethynk Web Studio ("we", "us", "our") is committed to protecting the privacy and security of your personal and financial data.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Narrow Management System ("Narrow", "the Service").
We comply with applicable South African data protection legislation, including the Protection of Personal Information Act (POPIA).
2. Information We Collect
Account Data: When you register for an account, we collect basic user identification data, including your name, business email address, phone number, and organization details.
Business & Financial Data: Information you enter into Narrow to operate your business—such as cashbook entries, invoices, quotations, payroll data, customer/supplier records, and stock inventory.
Technical & Usage Telemetry: Device information, IP addresses, browser types, log data, and session activity collected automatically to ensure system performance and security.
3. How We Use Your Information
To provide, operate, and maintain the Narrow platform and its multi-tenant services.
To verify user identity, enforce role-based permissions, and prevent unauthorized access.
To process subscription billing and maintain transactional integrity across your organization's ledger.
To communicate important system updates, security alerts, and administrative notifications.
4. Multi-Tenant Data Isolation & Security
Narrow employs strict multi-tenant architecture. All organization financial records and customer data are logically partitioned by unique organization identifiers.
Data in transit is encrypted using standard Transport Layer Security (TLS), and sensitive storage is protected behind enterprise firewall standards.
We strictly limit employee access to customer production databases. Access is granted only on a need-to-know basis for authorized support or system engineering.
5. Third-Party Service Providers
Authentication Services: We use Clerk for secure identity management and authentication. Clerk processes user credentials in accordance with strict security standards.
Cloud Infrastructure: Our application servers and databases are hosted on secure, enterprise-grade cloud platforms adhering to industry compliance standards.
We do not sell, rent, or trade your personal or business financial data to third-party advertisers or marketers.
6. Your POPIA & Data Rights
As a data subject under POPIA, you have the right to request access to the personal information we hold about you.
You have the right to request correction, updating, or deletion of inaccurate, out-of-date, or unauthorized personal data.
Organization administrators can export or purge organization ledger records upon written account termination request.
8. Privacy Officer Contact Details
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information under POPIA, please contact our team at info@rethynk.co.za.
PRIVACY ENQUIRIES
Have questions about data protection?