Feature
Data Protection

Our systems and processes are built to comply with South Africa’s Protection of Personal Information Act (POPIA). We want you to feel confident about how information is handled, so here’s a quick tour of your data’s journey with us: from the moment it’s collected to when it’s securely deleted.
Your data’s journey follows seven key stages — it is scanned, securely stored on the device, synced to our servers, protected within our secure data centres, accessed through controlled permissions, retained according to your requirements, and finally, permanently deleted when no longer needed.
Your Data's Journey
We trust this provides a clear and comprehensive overview of our unwavering commitment to safeguarding your data at every stage of its lifecycle.
Data is Scanned
What happens: Users capture documents via mobile devices — including driver’s licences, passports, vehicle discs, waybills, or other forms.
How it’s protected: Data capture fields are predefined for your lawful purpose, ensuring only authorised information is collected.
Data is Stored Securely on the Device
What happens: The platform works “offline-first,” saving data securely on the device until connectivity returns.
How it’s protected: Information is stored in a secure local database, with optional encryption. User passwords are hashed and never stored in plain text.
Data is Synced to Our Servers
What happens: Once online, data automatically syncs to our central platform.
How it’s protected: All transfers use SSL/TLS encryption, preventing interception and ensuring end-to-end security.
Data is Stored in Secure Data Centres
What happens: Data is hosted within the high-security OpenItem3 platform.
How it’s protected: Data is stored in POPIA-compliant South African centres with 24/7 security, site replication, firewalls, and AES-256 encrypted, locked databases with secure backups (not accessible by the public).
Data is Accessed on the Platform
What happens: Authorised users access data for reports or management tasks.
How it’s protected: Access is controlled through role-based permissions, with data visibility limited by segmentation and all passwords securely salted, hashed, and stored.
Data is Retained Based on Your Needs
What happens: The default retention period is 2 years; however, this can be adjusted to align with your specific business requirements.
How it’s protected: POPIA-compliant retention policies ensure no data is held longer than necessary.
Default retention period
2 years
Data is Securely Deleted
What happens: Data is stored for 2 years, after which the retention period ends or the user requests deletion. At that point, the data is permanently destroyed.
How it’s protected: Secure deletion methods — including multi-pass overwriting or physical destruction — ensure complete, irreversible removal.
View/Download Feature Info Sheet
Who gets access in the first place
Role-based access is only as strong as the login behind it. OpenItem Auth replaces passwords with facial recognition, biometrics, passcodes and 2FA, so the person opening a record is verifiably the person entitled to it.
Security standards
Openitem is built with security and privacy as a first consideration. The platform is fully compliant with POPIA, so personal information is handled to the standards the Act requires.
The apps have undergone comprehensive penetration testing to find and resolve vulnerabilities before they reach production, and Openitem follows SOC standards — rigorous controls over the systems and operations that hold client data.
In practice
POPIA compliantPenetration testedSOC standards






















































