YOUR EVIDENCE,YOUR FILE,NOT A PRODUCT.
You send slips, statements and tax certificates so a return can be built and checked. That is the only reason any of it is here. This page says what is stored, who else ever touches it, how long it stays and what you can ask us to do with it.
Last updated 5 September 2026.
The responsible party is a person, with a name
OptiTax is a trade mark used by Kerry Gunning t/a Green Kow, and that is the responsible party under the Protection of Personal Information Act. Questions about anything on this page, including a request to see, correct or delete what we hold, go through the support desk and reach a real person.
Five kinds of thing, and each has a job
Nothing is collected speculatively. Each row below exists because a specific part of the return cannot be built without it.
| What | Why it is there | Where it comes from |
|---|---|---|
| Name, email address, phone number | To open an account, to sign you in, to send you the link back to your own return, and to match a WhatsApp thread to the right person. | You, at signup. |
| Documents: slips, invoices, bank statements, IRP5 and other tax certificates, logbooks, medical and retirement certificates | They are the evidence the return rests on. Each one is read, sorted and kept against the return it belongs to, so a claim can point at the document behind it. | You, by upload, by email or by sending them into your WhatsApp thread. |
| Identity number and proof of address | A registered tax practitioner has to know who their client is before they can act for them. This is the practitioner's FICA file, not marketing data. | You, when a practice asks for it. |
| Bank lines: date, amount, description, the account they came from | To match business spending against the slips you already sent, so a claim is a matched pair rather than a typed number. | The statements you send us. OptiTax does not connect to your bank and has no login to it. |
| Technical records: sign in attempts, the IP address an action came from, an audit line for who did what and when | To keep the account secure, to stop somebody guessing a password, and so that if you ever ask who opened your file the answer has a name and a timestamp on it. | Generated automatically as you use the service. |
There is no sales ledger anywhere in the application, so no customer of yours is stored as a customer, and no income line is read from anything you send. That absence is stated on the SME page too, because it is a limit, not a feature.
FOUR SERVICES,AND WHAT EACH ONE GETS.
These are the only third parties the software actually sends anything to. There is no fifth one hiding behind a phrase like "our partners". Nothing is sold, nothing is shared for advertising, and nothing you send is used to train a model.
| Service | What it receives | Why |
|---|---|---|
| Meta, WhatsApp Business Platform | Your phone number, the messages in your OptiTax thread, and any photo or document you send into it. | It is the WhatsApp thread itself. If you never use WhatsApp with us, Meta receives nothing. |
| The document reader | The page image or PDF of a document you send, and nothing else about you. No name, no email, no account. | To turn a photograph of a slip into a date, an amount, a supplier and a VAT number. The engine calls one of Anthropic, OpenAI or Google Gemini, with the others as a fallback if the first cannot answer. |
| PayFast | What a payment provider needs to take a payment: the amount, the reference and your contact details. | To take subscription payments. Card numbers are entered on PayFast's own pages and never reach OptiTax. |
| The hosting company | The server the database and the documents sit on. | The application has to run somewhere. Access is by key, and the files sit outside the public web folder. |
SARS is not on this list, deliberately. OptiTax does not submit anything. A registered tax practitioner reviews the return and files it under their own name and their own SARS credentials, which is what section 240 of the Tax Administration Act requires. The review and sign off steps are set out here.
Support cannot open your documents until you say so
This is the part most software leaves vague. An operator helping you can always see that a document arrived. Opening it is a separate thing, and it needs your permission, granted four ways narrow.
One client's file
A grant covers the documents on your returns and nothing else. It is not a badge on a staff account and it does not carry over to the next person they help.
One member of staff
Granted to the person who asked, by name. Two people helping you need two grants, because "who opened my file" should have one name in the answer.
For a while
Every grant expires, 72 hours by default. Long enough to finish a conversation, short enough that forgetting to revoke one is not the same as granting it forever.
Revocable
Withdraw it whenever you like and the next attempt to open a document is refused. Nothing needs cleaning up anywhere else.
POPIA is the reason for that shape: consent has to be specific, informed and voluntary, and it has to be possible to take it back. A blanket "support may read anything" is none of those.
Kept as long as the law asks, and no longer
Tax records have to be kept for five years from the date a return is submitted, and a practitioner's client identification file has its own retention obligation under FICA. So the honest answer is that we keep your evidence for as long as those obligations run, and then it goes. If you ask for deletion earlier, we delete everything we are not legally required to hold, and we tell you what is left and why.
The site runs over HTTPS. Passwords are stored as hashes and never as text, so nobody at OptiTax can read yours. The session cookie is HttpOnly, is marked secure over HTTPS, and is set to SameSite Lax, which means another site cannot ride your login. Staff accounts with wide access carry a second factor. Uploaded documents sit outside the public web folder, so no document has a guessable address.
No. There is one cookie, the session cookie that remembers you are signed in. It is not used to follow you anywhere and it is gone when you sign out. There is no analytics script, no advertising pixel and no third party tag on any public page, which is why this site does not throw a consent banner at you.
No. A document is sent to the reader to be read and the answer comes back as fields. We do not licence your documents to anybody for training, and we do not build a model of our own on your file. What the engine does learn from is its own corrections: when a merchant name or a category is fixed, that correction is remembered so the same slip is read better next time.
POPIA requires the Information Regulator and the people affected to be told as soon as reasonably possible after a compromise is discovered. We would tell you what was taken, when, and what to do about it, in plain words, rather than a notice written to be survivable.
Six things you can ask for, and we have to answer
These are your rights under POPIA. Ask through the support desk and you get a written answer with a date on it.
A copy of everything
What we hold about you, where it came from and who has seen it. Most of it you can already see on your own dashboard, but you can ask for the whole picture in one go.
A correction
Anything wrong or out of date, fixed.
Deletion
Everything we are not legally obliged to keep.
To withdraw a consent
Support access, a WhatsApp thread, a practice acting for you. Withdrawing one does not delete your return; it stops the access.
Your file, portable
Your documents back, in the form you sent them.
To complain
To us first, and to the Information Regulator if we do not put it right.
ASK, AND YOU GETA REAL ANSWER.
A privacy question is a support ticket like any other, and it goes to a person rather than an inbox nobody reads. No account is needed to send one.

