Data Protection and Security Policy
For the Katlego Finance SME platform
Last updated 22 August 2026
1. Purpose of this document
This Data Protection and Security Policy describes the technical and organisational measures Katlego Finance applies to protect personal information and business data processed through the Katlego Finance SME platform. It supplements, and should be read together with, our Privacy Policy.
2. Encryption
Data at rest is encrypted using industry standard AES-256 encryption. Data in transit between your device and our platform is encrypted using TLS 1.3, with HTTP Strict Transport Security enforced to prevent downgrade to an unencrypted connection.
3. Access controls and authentication
Access to the platform is controlled through role based access control, with distinct permission levels for platform administrators, auditors, business owners, and business staff, enforced at the system level, not only in the user interface. Multi factor authentication, using a time based one time password or a passkey based method, is mandatory for any account action that can trigger a payout or confirm an invoice guarantee, and is available as an additional layer of protection for all accounts.
4. Multi tenant data isolation
Katlego Finance is a multi tenant platform, meaning many businesses share the same underlying infrastructure. Each business's data is isolated at the database level using row level security, so that one business's data cannot be accessed by another business's account, even in the event of an application level error. This isolation is verified through automated testing as part of our development process.
5. Audit logging
We maintain an append only audit log of significant actions taken on the platform, including risk score calculations, guarantee issuance, payouts, and administrative actions, recording the user responsible, the time of the action, and the relevant before and after state. This log supports both security investigation and regulatory accountability.
6. Infrastructure and hosting
The platform is hosted on infrastructure located within South Africa where operationally possible, to support data residency and reduce latency. Our infrastructure providers are selected and contracted subject to appropriate security and confidentiality obligations.
7. Vendor and subprocessor security
Where we engage a third party to process personal information on our behalf, including our payment services partner, our underwriting partner, and our infrastructure providers, we require that party to maintain security measures appropriate to the sensitivity of the information involved, and to notify us promptly of any security incident affecting that information.
8. Incident response and breach notification
We maintain a process for identifying, containing, and investigating security incidents. Where a security compromise has occurred that has, or is reasonably likely to have, compromised the confidentiality, integrity, or availability of personal information, we will notify the Information Regulator and affected data subjects without undue delay, in accordance with our obligations under Section 22 of POPIA, and will take reasonable steps to identify and remediate the cause of the incident.
9. Data minimisation and retention
We collect only the personal information reasonably necessary to provide the platform and its features, and retain it only for as long as necessary for the purposes described in our Privacy Policy or as required by law.
10. Business continuity
We maintain regular backups of platform data and a business continuity approach designed to allow recovery of service and data in the event of a significant infrastructure failure.
11. Employee access and confidentiality
Access to production systems and customer data by our own personnel is limited to what is necessary for their role, logged, and subject to confidentiality obligations. Personnel receive training on their data protection and security responsibilities.
12. Your responsibilities
Security is a shared responsibility. You are responsible for keeping your account credentials confidential, for enabling multi factor authentication, for ensuring only authorised staff have access to your account, and for promptly reporting any suspicious activity to us.
13. Reporting a security concern
If you believe you have identified a security vulnerability or incident affecting the Katlego Finance platform, please report it to us immediately at support@katlegofinance.co.za so we can investigate promptly.
14. Changes to this policy
We may update this policy at any time, at our own discretion, to reflect changes to our platform, our business, or applicable law. An updated version takes effect from the moment it is published on this page, and the date shown at the top of this page tells you when it last changed.
We are not obliged to notify you of a change, and you should not rely on receiving a notice. It is your responsibility to review this page regularly so that you are aware of the current version. We will make reasonable efforts to keep this page up to date and to show the date of the most recent update, but that is a courtesy to you and not an obligation on us.
If you continue to access or use the Katlego Finance platform after an updated version is published, you accept the updated version and it becomes binding on you. If you do not accept an updated version, you must stop using the platform, and you may cancel your account in accordance with our Refund and Cancellation Policy.
Where we have kept a previous version, we will provide it on request to support@katlegofinance.co.za.
Where South African law expressly requires us to notify you of a particular change, including any notification required under the Protection of Personal Information Act 4 of 2013, we will give that notice.
Related documents
These documents work together and each one forms part of your agreement with us.
- Terms and ConditionsThe agreement between your business and Katlego Finance covering the platform, subscriptions, invoice protection, and liability.
- Privacy PolicyWhat personal information the SME platform collects, why we process it, who we share it with, and your rights under POPIA.
- Refund and Cancellation PolicyHow to cancel a subscription, when a refund is available, and how guarantee fees and processing fees are treated.