Privacy Policy

How we handle personal information.

Effective 27 August 2026. Version 1.

Power Practice is practice management software for South African attorneys. This policy explains what personal information POWER PRACTICE (Pty) Ltd collects, why, and what rights you have under the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Who we are

POWER PRACTICE (Pty) Ltd is a private company incorporated in South Africa. For the purposes of POPIA we are the responsible party for the information described in section 3, and an operator for the information described in section 4.

Our Information Officer can be reached at info@powerpractice.co.za.

2. Two kinds of information

The software holds two distinct sets of personal information, and our role differs for each.

  • Account information about the firm and the people who sign up and use the software. We decide how this is used, so we are the responsible party.
  • Practice data: everything a firm records about its own clients, matters, opposing parties, estates, transfers, invoices and trust accounts. The firm decides how this is used. The firm is the responsible party and we process it only on the firm's instructions, as an operator under section 20 and 21 of POPIA.

3. Account information we collect

What Why
Name, work email address, telephone number, firm name, main practice area To create and administer the account, and to contact you about it
Password, stored as a one-way hash To authenticate you. We never store the password itself
Billing details and subscription status To invoice the firm. Card details are handled by our payment provider and never touch our servers
IP address, browser type, sign-in times, and a record of actions taken in the software Security, the audit trail attorneys are required to keep, and fault finding
Support correspondence To answer you and to improve the product

The lawful basis is the performance of the contract with the firm, our legitimate interest in running a secure service, and, for marketing email, your consent, which you can withdraw at any time.

4. Practice data

We do not read, sell, or use practice data for any purpose of our own. Specifically:

  • We process it only to provide the software to the firm, to keep it backed up, and to give support when the firm asks for it.
  • We do not use it to train machine learning models, and we do not permit our suppliers to.
  • Our staff access it only with the firm's permission, or where the law requires. Every such access is logged.
  • When the firm's subscription ends, the firm can export its data, and we delete it after the retention period in section 8.

Firms remain responsible for their own POPIA obligations towards their clients, including obtaining any consent the law requires and responding to their clients' requests. The software includes tools for this, such as the client consent register and the data subject request log.

5. Where the information is kept

The software and its database are hosted on Google Cloud in the Johannesburg region (africa-south1), in South Africa. Backups are kept in the same region.

Some suppliers listed in section 6 operate outside South Africa. Where information leaves the country we rely on section 72 of POPIA: the recipient is bound by a written agreement that provides substantially similar protection to POPIA.

6. Suppliers who process information for us

We use a small number of suppliers, each under a written agreement that limits them to acting on our instructions:

  • Google Cloud: hosting, database and backups (South Africa).
  • Cloudflare: network security, content delivery and email routing for our own domain.
  • PayFast: subscription and invoice payments. PayFast holds card details under its own PCI DSS certification; we never see a card number.
  • A transactional email provider: sending account and system email such as password resets.

Where a firm chooses to connect its own services, for example its own email account, bank feed, WhatsApp or calendar, information flows to that service under the firm's own agreement with it.

7. Artificial intelligence features

Some features can draft, summarise or research with the help of a language model. Before any text is sent to a model, the software removes identifying details such as names, identity numbers, addresses, telephone numbers and account numbers, and restores them only in the result shown to the user. Firms can disable these features entirely. No practice data is used to train any model.

8. How long we keep information

  • Account information: for the life of the account and five years after it closes, which is the period the Companies Act and the Tax Administration Act require us to keep financial records.
  • Practice data: for the life of the firm's subscription and 90 days after it ends, during which the firm can export it. It is then deleted, subject to any legal hold. Firms should note their own obligations, for example the five year FICA record keeping period and the Legal Practice Council's rules on accounting records, and export before the period runs out.
  • Audit logs: five years, since they exist to evidence compliance.

9. Security

Information is encrypted in transit and at rest. Access is controlled by role, every sign-in and every change to a record is logged, sensitive records carry additional access alerts, and trust and business accounting are kept apart. We test our own security and correct what we find. If a breach affects you, we will notify you and the Information Regulator as section 22 of POPIA requires.

10. Cookies

The software uses cookies that are necessary to keep you signed in and to protect against cross site request forgery. This website uses no advertising or tracking cookies.

11. Your rights

Under POPIA you may, free of charge unless the law permits a fee:

  • Ask whether we hold personal information about you, and for a copy of it.
  • Ask us to correct or delete information that is inaccurate, out of date or no longer needed.
  • Object to processing based on our legitimate interests, or to direct marketing.
  • Withdraw any consent you have given.
  • Complain to the Information Regulator.

Write to info@powerpractice.co.za. We answer within 30 days. If your request concerns practice data held by a firm that uses Power Practice, we will refer it to that firm, which is the responsible party for it.

The Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. complaints.IR@justice.gov.za.

12. Children

The software is for law firms and is not offered to anyone under 18. Practice data may include information about children, for example in family law or estate matters. The firm is responsible for the lawful basis of that processing.

13. Changes to this policy

We will notify account holders by email of any material change at least 30 days before it takes effect, and keep earlier versions available on request.

POWER PRACTICE (Pty) Ltd

info@powerpractice.co.za