1. Introduction
Enemial Technologies (Pty) Ltd ("Enemial Technologies," "we," "us," or "our") is a technology company incorporated under the laws of the Republic of Botswana, with its principal place of business at Plot 77372, Gaborone North, Botswana.
This Privacy Policy explains how we collect, use, store, share, and protect personal information when you access or use our digital platforms, including AttestWay (a digital signature and document management service) and FunInvite (an event invitation platform), collectively referred to as "the Services."
By using any of the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of our Services.
2. What Data We Collect
We collect the following categories of personal information:
- Account information: email address, first name, last name, and password (stored as a cryptographic hash).
- Documents: PDF files you upload to AttestWay for signing or management.
- Signature data: drawn signature images captured during the signing flow.
- Usage data: pages visited, actions performed, timestamps of events.
- Device and network data: IP address, browser type, operating system, and user-agent string.
- Communication data: messages sent through our contact form or support channels.
- Billing data: subscription plan, payment history. We do not store full card numbers — payments are processed by third-party providers.
3. How We Use Your Data
We use your personal information to:
- Provide, operate, and maintain the Services.
- Authenticate your identity and secure your account.
- Send transactional emails: signing links, OTP codes, completion notifications, password resets, and email verification.
- Generate signed PDF documents and audit certificates on your behalf.
- Track usage against your subscription plan limits.
- Improve platform reliability, performance, and security.
- Respond to support requests and enquiries.
- Comply with legal obligations.
We do not use your data for advertising, profiling for third-party marketing, or any purpose unrelated to the provision of the Services.
4. Legal Basis for Processing
Where applicable data protection law requires a legal basis for processing, we rely on the following:
- Contract performance: processing necessary to provide the Services you have subscribed to.
- Legitimate interests: security monitoring, fraud prevention, improving service quality, and maintaining audit trails — where these interests are not overridden by your fundamental rights.
- Consent: where you have explicitly given consent, such as optional marketing communications.
- Legal obligation: where we are required to retain or disclose data by applicable law.
5. Data Retention
- Account data: retained for as long as your account is active, plus 30 calendar days after account closure or subscription cancellation, during which you may export your data.
- Documents and signed PDFs: retained for the duration of your active subscription.
- Audit logs: retained for 7 years to support legal, regulatory, and dispute resolution requirements.
- OTP codes: automatically deleted after use or upon expiry (15 minutes).
- Support communications: retained for 2 years.
After applicable retention periods, data is permanently deleted from our systems.
6. Data Security
We apply industry-standard technical and organisational measures to protect your personal data, including:
- Encryption of data in transit using TLS (HTTPS).
- Passwords stored as bcrypt cryptographic hashes — never in plaintext.
- JWT-based authentication with short-lived access tokens and server-side refresh token revocation on logout.
- OTP codes hashed before storage and subject to attempt-rate limiting.
- Access controls that restrict data to the account owner and authorised organisation members.
- Audit logging of all significant data access and modification events.
No system can guarantee absolute security over internet-based transmission. We cannot warrant the security of information you transmit to us, but we take all reasonable precautions.
8. Your Rights
Subject to applicable law (including the Botswana Data Protection Act and, where applicable, the GDPR), you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data, subject to legal retention obligations.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to restriction: request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, please contact us at nmampare@gmail.com. We will respond within 30 days.
10. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately at nmampare@gmail.com and we will take steps to delete that information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email or in-platform notice at least 14 days before the updated Policy takes effect. The effective date at the top of this page will reflect the most recent revision. Continued use of the Services after the revised Policy becomes effective constitutes your acceptance of the changes.
12. Contact Us
For privacy-related queries, data subject requests, or concerns about our data practices, please contact:
Enemial Technologies (Pty) Ltd — Privacy
Address: Plot 77372, Gaborone North, Botswana
Postal: P O Box 80945, Gaborone, Botswana
Phone: +267 74750403 / 74996392
Email: nmampare@gmail.com
Enemial Technologies | Privacy Policy | Effective: June 6, 2025