Privacy Policy

Last updated: 21 July 2026

This Privacy Policy explains how DocBridge, a service operated by BVL Group of Companies ("DocBridge", "we", "us"), collects, uses, stores and protects personal information when you use our secure document-request and handover platform (the "Service"). We are committed to processing personal information lawfully and transparently in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Who we are and our role

DocBridge provides software that businesses ("Business Users") use to request documents from their own clients, employees, suppliers and other third parties ("Recipients"). In relation to documents and information that a Business User collects through the Service, the Business User is the responsible party / data controller and DocBridge acts as an operator / data processor on their behalf. In relation to a Business User's own account information, DocBridge is the responsible party.

DocBridge is a product and trading name of BVL Group of Companies and is not a separate legal or juristic person. The responsible party for the purposes of POPIA, and the data controller for the purposes of GDPR where it applies, is BVL Group of Companies. Our Information Officer can be contacted at privacy@thebvl.com.

2. Information we collect

From Business Users

  • Account and profile details: name, work email address, organisation name, contact details and business address.
  • Authentication data: securely hashed passwords and, where enabled, multi-factor authentication settings.
  • Usage and log data: sign-in times, actions taken, device and browser information, and IP address.

From Recipients

  • Contact details provided by the Business User (name, email address and, optionally, mobile number).
  • The email address a Recipient verifies to access a request, and one-time verification codes (stored only in hashed form).
  • Documents and any information contained in them that the Recipient chooses to upload in response to a request.
  • Technical data captured for security and audit purposes, such as IP address and the time a link was opened.

3. How and why we use information

  • To provide the Service: creating requests, delivering secure links, verifying access, accepting uploads, and enabling review and approval.
  • To secure the Service and detect or prevent fraud, unauthorised access and abuse.
  • To maintain an audit trail of actions taken against each request, for evidential and compliance purposes.
  • To communicate with users about requests, security notices and service updates.
  • To comply with legal obligations and respond to lawful requests.

Where GDPR applies, our legal bases are performance of a contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and, where required, consent. Under POPIA we process personal information on the corresponding lawful bases, including the conclusion or performance of a contract and compliance with an obligation imposed by law.

4. Document retention and deletion

Uploaded documents are retained only for as long as needed to fulfil the document-handover purpose set by the Business User. A Business User may delete uploaded documents at any time. Audit-log records are retained for a longer period to preserve the integrity of the compliance trail, after which they are deleted or anonymised in line with the Business User's retention settings and applicable law. When a Business User closes their account, associated personal information is deleted or anonymised within a reasonable period, except where we are required to retain it by law.

5. How we protect information

  • Encryption of data in transit (HTTPS/TLS) and at rest.
  • Documents held in private storage that is not publicly accessible; downloads occur only through short-lived, expiring signed links.
  • Row-level database security that isolates each organisation's data.
  • Access to a request gated by a secret link and a one-time email verification code.
  • Restricted internal access, audit logging, and file-type restrictions on uploads.

No method of transmission or storage is completely secure, but we maintain appropriate technical and organisational measures designed to protect personal information against loss, misuse and unauthorised access.

6. Sharing and sub-processors

We do not sell personal information. We share information only with service providers who help us operate the Service, under contractual confidentiality and data-protection obligations. Our current sub-processors include our cloud hosting, database and file-storage provider (Supabase / Lovable Cloud) and our transactional email provider (Resend). We may also disclose information where required by law or to protect our legal rights.

7. International transfers

Our providers may process data in data centres located outside South Africa or the European Economic Area. Where personal information is transferred across borders, we rely on appropriate safeguards recognised under POPIA and GDPR, such as the recipient being subject to laws or binding agreements that provide an adequate level of protection.

8. Your rights

Subject to applicable law, you may request access to, correction or deletion of your personal information, object to or restrict certain processing, and request a copy of information you provided. Because much of the information processed through the Service belongs to a Business User acting as controller, Recipients should direct requests to the Business User that sent them a request; we will assist that Business User in responding. To exercise rights regarding information for which DocBridge is responsible, contact us using the details below. You also have the right to lodge a complaint with a supervisory authority, including the Information Regulator of South Africa.

9. Children

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children except where a Business User lawfully collects a dependant's documents in the course of a regulated process.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying account holders.

11. Contact

For privacy enquiries or to exercise your rights, contact us at privacy@thebvl.com. BVL Group of Companies is the operator of DocBridge and the responsible party for account information.