Setdesk

These pages are a draft prepared for review. They describe what Setdesk actually does with personal information, but their wording has not been settled by a legal practitioner and they are not yet in force.

Privacy notice

What Setdesk does with personal information, and the rights you have over it under the Protection of Personal Information Act 4 of 2013.

Who is responsible

The responsible party is the company operating Setdesk. POPIA requires an information officer to be named and registered with the Information Regulator.
Still to be suppliedRegistered name, Registration number, Registered address, Information officer

Two roles, and the difference matters

Setdesk holds two kinds of personal information and stands in a different relationship to each.

For the people who sign in and use the product, we are the responsible party. We decide what is collected and why.

For everybody a workspace stores inside it, promoters, venue contacts, artists, demo submitters, the workspace is the responsible party and we are its operator. The agency decides what to record about its contacts. We process it on their instruction, and we do not use it for our own purposes.

What is held

Account details: name, email address
To sign you in and show who did what in a shared workspace. Source: you, when you sign up.
Contact records: names, email addresses, phone numbers, organisations
So bookings, advance sheets and invoices can reach the right person. Source: entered by the workspace, usually about promoters and venues.
Artist details: stage name, legal name, contact details, fees and commission
To run the diary and calculate what is owed. Source: entered by the workspace.
Banking and tax details: account number, branch, VAT number
So an invoice states where to pay. Source: entered by the workspace about itself.
Signature evidence: signer name, email, IP address, browser, timestamp
So a signed agreement can be shown to have been signed. Source: captured when somebody signs a contract.
Promo activity: whether a link was opened, plays, how far a track was heard, feedback given
So a label learns how a record is landing. Source: recorded as a recipient uses their private link.
Demo submissions: submitter name, email, and the audio sent
So an inbound demo can be listened to and answered. Source: the person submitting.

Who else receives it

Each of these is an operator under POPIA. None of them is permitted to use the information for anything other than the service they provide to us.

NeonFrankfurt, Germany (eu-central-1)
The database behind everything in the product. Receives: all of it.
VercelGlobal edge, with South African points of presence
Runs and serves the application. Receives: request data, including ip addresses, in transit.
Cloudflare R2Global object storage
Stores files: PDFs, audio masters and previews. Receives: documents and audio, which may name people.
ResendUnited States
Delivers email: sign-in codes, advance sheets, promos. Receives: recipient email addresses and message contents.
PaystackSouth Africa and Nigeria
Takes subscription payments for the product itself. Receives: the subscriber's billing details. card details never reach us.
CloudinaryUnited States
Makes the streaming preview of a promo. Receives: audio files only, deleted immediately after conversion.
InngestUnited States
Runs background jobs, such as show reminders. Receives: record identifiers, not the records themselves.

Information leaving South Africa

It does. The database sits in Frankfurt, Germany, and several of the companies above operate from the United States. Section 72 of POPIA governs transferring personal information outside the Republic, and permits it where the recipient is bound by rules or a contract that give effect to protection substantially similar to POPIA.

We rely on the data processing terms of each company listed above. Where you need those terms for your own compliance, ask and we will provide them.

How long it is kept

Information is kept for as long as the workspace holding it keeps it. Deleting a contact, a booking or a campaign removes it.

Three things are removed on a schedule, by a job that runs daily. Older versions of a generated document are deleted 30 days after a newer version replaces them. The audio attached to a demo submission is deleted 90 days after the submission is passed on or its link expires; the record that it was sent remains. And any file left in storage with nothing referring to it, which is what deleting a booking or a workspace leaves behind, is removed after 7 days.

Two things are shorter lived by design. A sign-in code is stored only as a hash and expires after ten minutes. A signed-in session lasts seven days.

Your rights

Under POPIA you may:

  • ask what personal information is held about you, and get a copy
  • ask for anything inaccurate to be corrected
  • ask for it to be deleted, where we are not required to keep it
  • object to it being processed
  • complain to the Information Regulator

If a workspace holds information about you, ask them first: they decide what to keep. The product gives every workspace a way to export everything it holds about one contact, and to erase it, so they can answer you. If you cannot reach them, write to us at privacy@setdesk.co.za and we will help.

The Information Regulator of South Africa can be reached at inforeg.org.za.

How it is protected

Every table enforces row level security in the database itself, so a workspace cannot read another workspace's rows even if the application asks it to. Fees and money sit behind a further permission, so a member without money access cannot read them at any layer.

Files are never public. Every link to a document or a track is short-lived, addressed to one recipient, and can be revoked, which takes effect on the next request. Sign-in codes and share tokens are stored only as hashes, so a copy of our database does not yield a working link.

Changes

If this notice changes materially, the version at the foot of the page changes with it, and account holders are told before the change takes effect.