Data Protection Compliance Guide
Refynne - Personal Finance Management App
Website: https://refynne.com
Developer: BPS Dynamic (bpsdynamic.com)
Overview
This document outlines how Refynne complies with data protection regulations across different jurisdictions. It serves as a reference for users, regulators, and internal compliance.
Compliance Matrix
| Regulation | Region | Status | Key Requirements |
|---|---|---|---|
| POPIA | South Africa | ✅ Compliant | Consent, Purpose limitation, Data minimization |
| GDPR | European Union | ✅ Compliant | Lawful basis, Rights, DPO, Breach notification |
| UK GDPR | United Kingdom | ✅ Compliant | Same as GDPR with UK-specific provisions |
| CCPA/CPRA | California, USA | ✅ Compliant | Right to know, delete, opt-out |
| LGPD | Brazil | ✅ Compliant | Consent, Rights, DPO equivalent |
| Privacy Act | Australia | ✅ Compliant | APPs, Transparency, Access rights |
1. South Africa - POPIA
Protection of Personal Information Act (Act 4 of 2013)
Effective Date: July 1, 2021
Compliance Measures
| POPIA Condition | How Refynne Complies |
|---|---|
| Accountability | Information Officer designated, policies documented |
| Processing Limitation | Only collect data necessary for service |
| Purpose Specification | Clear purposes stated in Privacy Policy |
| Further Processing Limitation | Data not used beyond stated purposes |
| Information Quality | Users can update/correct their data |
| Openness | Privacy Policy publicly available |
| Security Safeguards | Encryption, access controls, security audits |
| Data Subject Participation | Access, correction, deletion rights implemented |
Information Officer
Designated Information Officer: BPS Dynamic
Contact: privacy@refynne.com
User Rights Under POPIA
- Right to be notified of data collection
- Right to access personal information
- Right to request correction
- Right to request deletion
- Right to object to processing
- Right to lodge complaint with Information Regulator
Information Regulator Contact
Website: https://www.justice.gov.za/inforeg/
Email: inforeg@justice.gov.za
Phone: +27 10 023 5200
2. European Union - GDPR
General Data Protection Regulation (EU 2016/679)
Effective Date: May 25, 2018
Compliance Measures
| GDPR Principle | How Refynne Complies |
|---|---|
| Lawfulness, Fairness, Transparency | Clear legal basis, transparent processing |
| Purpose Limitation | Specific, explicit purposes documented |
| Data Minimization | Only essential data collected |
| Accuracy | Users can update their data |
| Storage Limitation | Retention periods defined |
| Integrity & Confidentiality | Encryption, security measures |
| Accountability | Documentation, DPO consideration |
Legal Bases for Processing
| Processing Activity | Legal Basis |
|---|---|
| Account management | Contract performance |
| Financial tracking | Contract performance |
| Analytics | Legitimate interest |
| Marketing | Consent |
| Security | Legitimate interest |
Data Subject Rights
| Right | Implementation |
|---|---|
| Access | In-app data export, email request |
| Rectification | In-app editing, support request |
| Erasure | Account deletion feature |
| Restriction | Support request |
| Portability | JSON/CSV export |
| Objection | Settings toggles, support request |
| Automated Decision-Making | No automated decisions made |
Data Protection Impact Assessment (DPIA)
A DPIA has been conducted for:
- Cloud data storage
- Analytics processing
- Receipt scanning (OCR)
International Transfers
For data transfers outside the EU:
- Standard Contractual Clauses (SCCs) in place
- AWS data processing agreement
- Adequacy decisions where applicable
3. United Kingdom - UK GDPR
UK General Data Protection Regulation
Effective Date: January 1, 2021 (post-Brexit)
Compliance Measures
UK GDPR requirements mirror EU GDPR. Additional considerations:
| Requirement | Implementation |
|---|---|
| UK Representative | To be appointed if required |
| ICO Registration | Completed if applicable |
| UK-specific SCCs | International Data Transfer Agreement (IDTA) |
ICO Contact
Website: https://ico.org.uk/
Phone: 0303 123 1113
4. United States - CCPA/CPRA
California Consumer Privacy Act & California Privacy Rights Act
CCPA Effective: January 1, 2020
CPRA Effective: January 1, 2023
Compliance Measures
| CCPA/CPRA Right | Implementation |
|---|---|
| Right to Know | Privacy Policy, data disclosure |
| Right to Delete | Account deletion feature |
| Right to Opt-Out | We do not sell data |
| Right to Non-Discrimination | Equal service regardless of privacy choices |
| Right to Correct | In-app editing |
| Right to Limit Use | Settings controls |
Categories of Personal Information
| Category | Collected | Sold | Shared |
|---|---|---|---|
| Identifiers | Yes | No | No |
| Commercial Information | Yes | No | No |
| Internet Activity | Yes | No | No |
| Geolocation | No | No | No |
| Biometric | No | No | No |
| Professional | No | No | No |
| Education | No | No | No |
| Sensitive | No | No | No |
"Do Not Sell My Personal Information"
Refynne does NOT sell personal information. No opt-out mechanism is required, but we provide one for transparency.
5. Brazil - LGPD
Lei Geral de Proteção de Dados (Law 13.709/2018)
Effective Date: September 18, 2020
Compliance Measures
| LGPD Principle | Implementation |
|---|---|
| Purpose | Specific purposes documented |
| Adequacy | Processing matches stated purposes |
| Necessity | Minimum data collected |
| Free Access | Users can access their data |
| Quality | Data accuracy maintained |
| Transparency | Clear privacy information |
| Security | Technical and organizational measures |
| Prevention | Proactive security measures |
| Non-Discrimination | No discriminatory processing |
| Accountability | Documentation and compliance evidence |
Data Subject Rights Under LGPD
- Confirmation of processing
- Access to data
- Correction of data
- Anonymization, blocking, or deletion
- Data portability
- Information about sharing
- Consent revocation
- Complaint to ANPD
ANPD Contact
Website: https://www.gov.br/anpd/
Email: encarregado@anpd.gov.br
6. Australia - Privacy Act
Privacy Act 1988 (Australian Privacy Principles)
Compliance Measures
| APP | Requirement | Implementation |
|---|---|---|
| APP 1 | Open and transparent management | Privacy Policy published |
| APP 2 | Anonymity and pseudonymity | Optional account creation |
| APP 3 | Collection of solicited information | Only necessary data collected |
| APP 4 | Dealing with unsolicited information | Not applicable |
| APP 5 | Notification of collection | Privacy notice at collection |
| APP 6 | Use or disclosure | Limited to stated purposes |
| APP 7 | Direct marketing | Consent-based only |
| APP 8 | Cross-border disclosure | Safeguards in place |
| APP 9 | Adoption of government identifiers | Not collected |
| APP 10 | Quality of personal information | User correction available |
| APP 11 | Security of personal information | Encryption, access controls |
| APP 12 | Access to personal information | In-app access, export |
| APP 13 | Correction of personal information | In-app editing |
OAIC Contact
Website: https://www.oaic.gov.au/
Phone: 1300 363 992
7. Technical Compliance Measures
Data Security
| Measure | Implementation |
|---|---|
| Encryption at Rest | AES-256 |
| Encryption in Transit | TLS 1.3 |
| Password Hashing | bcrypt with salt |
| Access Control | Role-based access |
| Audit Logging | All data access logged |
| Backup | Encrypted backups |
Data Minimization
| Data Type | Collected | Justification |
|---|---|---|
| Yes | Account identification | |
| Name | Optional | Personalization |
| Financial data | Yes | Core service |
| Location | No | Not needed |
| Contacts | No | Not needed |
| Photos | Optional | Receipt scanning only |
Retention Periods
| Data Type | Retention | Justification |
|---|---|---|
| Account data | Until deletion + 30 days | Service provision |
| Financial data | Until deletion + 30 days | Service provision |
| Support tickets | 2 years | Quality assurance |
| Analytics | 26 months | Service improvement |
| Logs | 90 days | Security |
8. Breach Response Plan
Notification Timelines
| Regulation | Authority Notification | User Notification |
|---|---|---|
| POPIA | As soon as reasonably possible | As soon as reasonably possible |
| GDPR | 72 hours | Without undue delay |
| UK GDPR | 72 hours | Without undue delay |
| CCPA | N/A | Most expedient time possible |
| LGPD | Reasonable time | Reasonable time |
| Privacy Act | As soon as practicable | As soon as practicable |
Breach Response Steps
- Identify - Detect and confirm breach
- Contain - Stop ongoing breach
- Assess - Determine scope and impact
- Notify - Inform authorities and users as required
- Remediate - Fix vulnerabilities
- Document - Record incident and response
- Review - Update procedures to prevent recurrence
9. Contact Information
Privacy Inquiries
Email: privacy@refynne.com
Subject Line: "Privacy Request - [Your Country]"
Data Protection Officer (if applicable)
Email: dpo@refynne.com
General Support
Email: support@refynne.com
Website: https://refynne.com/support
© 2025 BPS Dynamic. All rights reserved.