Privacy Policy
Effective Date: 4 August 2026
Version 2.0 - TeamThink Solutions (Pty) Ltd t/a Devv Technology
1. Responsible Party
The responsible party for personal information processed through Devv is TeamThink Solutions (Pty) Ltd, trading as Devv Technology, a company operating from South Africa. Privacy questions, access requests, correction requests, or deletion requests may be sent to legal@teamthink.co.za.
2. Scope of this Policy
This Privacy Policy applies to Devv Hub and Devv-operated products and services, including PropOS, Devv Inspect, WeBook, QR Orders, uStock, Stagr, Ebook Reader, Devv Studio, Teamthink service operations, partner portals, admin tools, support channels, billing workflows, and related websites. A product-specific privacy notice, service agreement, data processing addendum, or signed contract may add further detail for a specific service.
3. Personal Information We Collect
Depending on the product you use, Devv may process the following categories of personal information:
- Identity and account information: name, email address, phone number, profile photo, Devv ID, password credentials, account status, role, and access level.
- Organisation and team information: organisation name, business profile, team members, roles, branches, invites, staff schedules, and access history.
- Billing and commercial information: plan, invoices, payment references, Paystack customer/subscription codes, proof-of-payment correspondence, seat add-ons, sponsored access, referral codes, commission status, and payout-related records.
- Product operation information: bookings, services, clients, packages, orders, menus, stock, sales, receipts, reports, leads, properties, inspections, maintenance tickets, files, documents, author submissions, books, profile content, and related records.
- Communications: support tickets, emails, notices, feedback, training notes, form submissions, and admin communications.
- Technical and security information: IP address, browser or device information, session identifiers, audit logs, activity logs, timestamps, error logs, and security events.
4. How We Collect Information
We collect information directly from you, from your organisation's authorised users, from payment and infrastructure providers, from product usage, from support interactions, from uploaded files, and from partner/referral workflows. Where an organisation enters client, tenant, staff, student, customer, or author information into Devv, that organisation must have authority to do so and remains responsible for its own notices to those individuals where required by law.
5. Purposes of Processing
We use personal information for the following purposes:
- to create, confirm, secure, and manage your Devv ID;
- to provision access to Devv products, workspaces, sponsored access, trials, partner portals, and internal tools;
- to operate the specific product features you use, including bookings, inspections, stock, orders, invoices, documents, profiles, and reports;
- to process payments, subscriptions, invoices, refunds, chargebacks, author earnings, commissions, and account status changes;
- to provide support, training, service delivery, maintenance, and product communication;
- to protect platform security, prevent fraud, enforce access controls, and investigate abuse;
- to comply with legal, tax, accounting, audit, contractual, and regulatory obligations;
- to improve products using aggregated, de-identified, or operational analytics where practical.
6. Legal Grounds for Processing
Devv processes personal information where it is necessary for contract performance, authorised by your consent, required by law, necessary to protect legitimate business or security interests, necessary to protect the rights of users or organisations, or otherwise permitted by the Protection of Personal Information Act, 2013 (“POPIA”). Marketing communications are sent only where permitted and may be opted out of where applicable.
7. Data Sharing and Operators
We do not sell personal information. We share information only where reasonably required to operate Devv, provide a service, comply with law, or support an authorised workflow. Current provider categories include:
- Supabase: database, authentication, storage, and edge-function infrastructure.
- Vercel: hosting, deployment, serverless functions, and application delivery.
- Paystack: payment processing, subscription events, and payment references.
- Resend: transactional and operational email delivery.
- Expo: mobile app updates and push notification delivery for products such as Devv Inspect where enabled.
- Operational service providers: domain, email, cloud, analytics, document, accounting, or support tools used by TeamThink/Devv.
These providers may process information only for the relevant service purpose. We take reasonable steps to use providers with appropriate security, confidentiality, and data-protection commitments.
8. Cross-Border Processing
Some Devv infrastructure and service providers may process or store information outside South Africa. Where cross-border processing occurs, Devv takes reasonable steps to ensure that personal information remains protected through contractual, technical, organisational, or legal safeguards aligned with POPIA.
9. Security
Devv uses reasonable technical and organisational measures to protect personal information, including encrypted transport, authenticated access, role-based permissions, tenant isolation, audit logging, service-role restrictions, and storage controls where applicable. No system is completely secure. If you believe an account, file, workspace, payment, or personal information has been compromised, contact Support@teamthink.co.za immediately.
10. Retention
We retain personal information for as long as needed to provide the service, maintain records, comply with legal or tax obligations, resolve disputes, enforce agreements, preserve audit trails, support security investigations, or meet a legitimate operational need. Some records, such as invoices, payment history, audit logs, signed agreements, author sales records, or organisation history, may be retained even after account closure where the law or operational integrity requires it.
11. Your Rights
Subject to POPIA and applicable limitations, you may request to:
- confirm whether Devv holds your personal information;
- access a record or description of your personal information;
- correct or update inaccurate, irrelevant, excessive, outdated, incomplete, misleading, or unlawfully obtained information;
- object to processing in appropriate circumstances;
- request deletion or destruction where legally available;
- opt out of direct marketing where applicable;
- complain to the Information Regulator of South Africa.
Send requests to legal@teamthink.co.za with enough information for us to verify and process the request.
12. Children and Minors
Devv products are generally intended for users who are at least 18 years old or are using the service through a responsible organisation with appropriate authority. Devv does not knowingly create independent Devv ID accounts for children. If a product or partner programme later involves minors, Devv will require additional safeguards, consent, and product-specific terms before collecting or processing that information.
13. Changes to this Policy
Devv may update this Privacy Policy as the ecosystem, products, providers, or legal requirements change. Material changes will be communicated through email, platform notice, or another reasonable channel.
14. Contact and Complaints
Privacy requests: legal@teamthink.co.za
Security reports: Support@teamthink.co.za
Information Regulator (South Africa): inforegulator.org.za
Last Updated: April 13, 2026