Iddan
Legal

Privacy Policy

Last updated: 18 July 2026

This policy is a preliminary version. Iddan is still in active development and does not yet have a live client processing real production data. This page reflects what the platform actually does today and will be expanded as Iddan is built out further — particularly once a first client is onboarded and the full scope of process-tracking data is finalised.

This policy explains how Kinara Consulting (Pty) Ltd(registration number 2025/871359/07, "Kinara," "we," "us"), operating Iddan PFT, collects, uses, and protects personal information in connection with the Iddan platform (iddan.co.za), in line with the Protection of Personal Information Act, 4 of 2013 ("POPIA").

Kinara's other products (Qlaim, Nahshon SPLT) and the Kinara Consulting corporate website each have their own privacy policy.

Who is responsible for your information

Responsible party: Kinara Consulting (Pty) Ltd

Company registration number: 2025/871359/07

Registered address: Sandton, Gauteng, 2191

Information Officer: The appointed Information Officer, Kinara Consulting (Pty) Ltd

IO email: privacy@kinaraconsulting.com

Information Regulator registration number: 2026-062429

What we collect

  • Admin and operator accounts — full name, email address, and password (via Supabase Auth), linked to the company account you register or are added to.
  • Company records — your organisation's name and the process/production stages you configure.
  • Process-tracking records — as Iddan is used to track jobs/components through configured stages, scan events (job/component identifier, stage, timestamp) may be linked to the operator who performed the scan. The exact detail of this is still being finalised as the product is built out.

Why we collect it

To operate your company's account, let admins configure and track process/ production stages, and let operators log scan events at their station.

How we share it

We do not currently share personal information with any third party other than Supabase, which provides our database and authentication infrastructure. This section will be updated if Iddan adds features that involve other processors (for example, transactional email or AI-assisted analytics, as our other products do).

We do not sell or rent personal information to third parties.

International data transfers

Our database infrastructure (Supabase) stores data in Paris, France, within the European Union, where it is protected under the EU General Data Protection Regulation (GDPR) — a data protection framework substantially similar to POPIA. Where personal information is transferred outside South Africa, we only do so where the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or another ground permitted under section 72 of POPIA. This section will be updated if Iddan adds processors that introduce further cross-border transfers.

How long we keep it

We retain account and company data for as long as your company's Iddan account is active.

Your rights under POPIA

  • Confirm what personal information we hold about you and request a copy of it
  • Ask us to correct inaccurate information, or delete it where there's no lawful reason to keep it
  • Object to processing where applicable
  • Lodge a complaint with the Information Regulator if you believe your information has not been handled properly

To exercise any of these rights, contact our Information Officer using the details above.

Security

As Iddan is still in active development, our full security practices will be documented here as they are finalised. Account passwords are managed by Supabase Auth rather than stored by us directly.

Complaints to the Information Regulator

The Information Regulator (South Africa)

Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg

P.O. Box 31533, Braamfontein, Johannesburg, 2017

www.inforegulator.org.za

Changes to this policy

This policy will change as Iddan develops, particularly once a first client is onboarded. The "last updated" date at the top of this page reflects the most recent revision.