Privacy Policy
Version 1.1Effective 6 September 2026Subject to periodic review
Applies to: the Nia LP Reporting Platform web application, its WhatsApp assistant, and the public website.
1. Who we are
The Nia LP Reporting Platform ("the Platform") is provided by Nia Impact SA (Pty) Ltd (trading as Nia Impact Invest), registration number 2023/912189/07, registered address 71 4th Street, Houghton, Gauteng, 2198, South Africa.
Under South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA") we are the responsible party. Where the EU General Data Protection Regulation ("GDPR") applies to our processing of your information — for example because the Platform is made available to you in the European Union — we are the controller.
Trigger Consulting built the Platform and runs it on our behalf. It acts as our operator (POPIA) / processor (GDPR) and may only process your information on our written instructions.
Our Information Officer under POPIA is name and title to be supplied.
Privacy contact for all requests and questions: sarah@niaimpactinvest.com
This provision is being finalised with our legal counsel and will be published in a later version.2. Who this policy covers
The Platform is invitation-only. You will only have an account because a fund manager (a "GP") or Nia invited you. This policy covers:
- GP staff — people who work at a fund that uses the Platform to report to its investors;
- Portfolio-company (investee) staff — people whose data a GP uploads on their behalf, or who use the WhatsApp assistant from a number the GP registered (they do not hold accounts);
- LP contacts — people at investors who receive reports or are recorded as a contact;
- Visitors to the public website.
If you are an LP contact or an investee contact, some of your information (typically your name and work email) is entered by the GP you deal with, not by you (see section 4).
3. What we collect
We collect and hold the following categories of personal information. We list categories, not every field; the full inventory is available on request.
| Category | Examples | Who provides it |
|---|---|---|
| Account and identity | Name, work email address, profile picture, role, language preference | You, or the person who invited you |
| Login and security credentials | Password (stored as a one-way hash), two-factor authentication secret and backup codes, passkeys | You |
| Session and device data | IP address, browser/device identifier ("user agent"), session token and expiry, which organisation you were last working in | Collected automatically when you sign in |
| Activity and audit records | A log of significant actions (sign-in, invitations, exports, support sessions), with the actor, timestamp and IP address | Collected automatically |
| Organisation and membership | The organisation you belong to, your role in it, invitations you sent or received (including the invitee's email) | You / your organisation's administrator |
| Reporting contacts | Name, work email and notes for investor (LP) and portfolio-company contacts | Entered by GP staff |
| Reporting content | Report templates, data submissions, generated reports, narratives, KPI values and supporting documents | Your organisation, or a portfolio company reporting to it |
| Uploaded documents and their extracted content | Policies, evidence files, knowledge documents, and the text and numerical values our systems extract from them | Your organisation |
| AI assistant conversations | Your questions, the assistant's answers, any file you attach to a conversation, and — on WhatsApp — your phone number | You |
| WhatsApp registration | The phone number registered by a GP administrator for a portfolio company or team member, and a label (often the contact's name) | The GP administrator |
| Notifications and email records | In-app notifications and their content; records of email delivery failures (recipient address masked) | Collected automatically |
| Usage metering | Which AI features your organisation used, when, and how much (token counts) | Collected automatically |
Supply is generally mandatory for the fields marked with an asterisk in our forms (name and email are required to hold an account). If you do not provide them we cannot create or maintain your account. Nothing in this policy is collected under a specific law that requires it.
Please do not upload special personal information (POPIA section 26 / GDPR Article 9 — health, religion, race, biometrics and similar) about identifiable individuals, or information about children (POPIA section 34). The Platform is designed for organisational impact data; free-text documents are stored as you upload them, and we ask you to remove personal details that are not needed.
4. Where your information comes from
Most information comes directly from you or is generated by your use of the Platform. Three kinds come from someone else:
- Invitations — the administrator who invites you provides your email address.
- Contact records — a GP may record your name and work email as an LP or portfolio-company contact so that reports and reminders reach you.
- WhatsApp registration — a GP administrator registers a phone number so that the person using it can talk to the assistant.
If we hold information about you that you did not provide, this policy is our notice to you under POPIA section 18(1) and GDPR Article 14. We will provide it as soon as reasonably practicable after we receive your details (POPIA section 18(2)) and, where GDPR applies, at the latest when we first contact you and in any event within one month of receiving them (GDPR Article 14(3)).
5. Why we use your information, and on what basis
| Purpose | POPIA justification (s 11) | GDPR legal basis (Art 6) |
|---|---|---|
| Creating and administering your account; letting you sign in; enforcing roles and organisation boundaries | Legitimate interests of Nia and your organisation (s 11(1)(f)); contract where you are the contracting party (s 11(1)(b)) | Legitimate interests (Art 6(1)(f)); contract (Art 6(1)(b)) where you are the contracting party |
| Running the reporting workflow: collecting submissions, extracting values, generating reports, sending reminders and notifications | Legitimate interests (s 11(1)(f)) | Legitimate interests (Art 6(1)(f)) |
| Providing the AI assistant (web and WhatsApp), including analysing documents you attach | Legitimate interests (s 11(1)(f)) | Legitimate interests (Art 6(1)(f)) |
| Keeping the Platform secure: sessions, rate limiting, audit trail, two-factor authentication, error monitoring | Legitimate interests (s 11(1)(f)); legal obligation to secure personal information (s 19) | Legitimate interests (Art 6(1)(f)); legal obligation (Art 6(1)(c)) |
| Metering AI usage against your organisation's plan | Legitimate interests (s 11(1)(f)) | Legitimate interests (Art 6(1)(f)) |
| Backups and disaster recovery | Legitimate interests (s 11(1)(f)) | Legitimate interests (Art 6(1)(f)) |
| Answering your requests and complaints; complying with law and regulators | Legal obligation (s 11(1)(c)) | Legal obligation (Art 6(1)(c)) |
Our legitimate interest is operating a secure reporting service for the fund or company that invited you, which is also that organisation's interest and, in most cases, yours. We do not use your information for marketing, profiling or advertising, and we do not sell it.
This provision is being finalised with our legal counsel and will be published in a later version.Automated decision-making. The Platform uses AI to draft narratives, flag data-quality issues, suggest KPI mappings, assess whether evidence looks sufficient and answer questions in the assistant. Every such output is advisory: outputs that feed the reporting workflow are reviewed and accepted (or rejected) by a person before they take effect, and assistant answers are shown to you as information for you to judge and have no automatic effect. We do not make decisions about you by automated means that have legal or similarly significant effects (POPIA s 71 / GDPR Art 22).
6. AI processing and the external document parser — please read
We tell you this plainly because it is the part of the Platform most likely to matter to you.
a) AI models. When you use the assistant, generate a narrative, run a data-quality check or upload documents for indexing, the relevant text — which can include passages from your organisation's documents — is sent through OpenRouter, Inc. (United States), an AI routing service, to one of the following model hosts: Anthropic, Google (Vertex AI), Amazon Web Services (Bedrock), Microsoft (Azure OpenAI) or OpenAI. Requests are configured so that they may only be served by endpoints that do not retain the content and do not use it for training ("zero data retention"). The models in use today are Anthropic's Claude models (served on Amazon Bedrock or Google Vertex AI zero-retention endpoints); Nia can switch a task to a Google Gemini or OpenAI GPT model from a short vetted list. Embeddings (numerical representations used for search) have no zero-retention endpoint; they are sent only to Microsoft Azure or OpenAI endpoints that the routing service classes as not storing or training on the input. A request that cannot be served under these rules fails rather than being sent elsewhere.
b) Document parser. When you upload an LP reporting template or a data submission as a PDF, image or scanned file — or as a Word file whose text the Platform cannot read itself, or as a PDF or Word data submission in which the Platform's own reader finds no reportable figures — the complete file is sent to LlamaIndex Inc. (LlamaCloud / LlamaParse) to be converted into text and tables. We instruct the service not to cache the document for reuse. Documents are processed in LlamaCloud's European Union region (api.cloud.eu.llamaindex.ai). Spreadsheet and CSV files, Policy Hub and knowledge documents, and files attached to an assistant conversation are always read on the Platform itself, and Word and PDF files are read on the Platform first; text from them may still be sent to the AI models described in (a). A plain-language explanation is in How the platform uses AI.
c) What we keep. The extracted text and tables, and the assistant's answers, are stored on the Platform (sections 3 and 10). Nia and Trigger Consulting do not train AI models on your data.
7. Who receives your information
We share personal information only with the service providers listed below, each of which processes it on our instructions under written data-processing terms (section 8 records the terms that have been accepted), and with your own organisation's administrators, who can see the members and content of their organisation. We publish and maintain a full sub-processor list and will notify organisation administrators before adding a provider.
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Trigger Consulting | Builds, operates and supports the Platform | All data, when needed for support (support sessions are logged with a reason) | South Africa |
| Neon, LLC | Database hosting | All Platform records | London, United Kingdom (AWS eu-west-2) |
| Cloudflare, Inc. (R2) | File storage and backup copies | Uploaded and generated files | European Union jurisdiction |
| Vercel, Inc. | Application hosting and scheduled jobs | All traffic, including IP addresses and logs | London, United Kingdom (lhr1) for application functions; global edge network for static delivery |
| OpenRouter, Inc. and the model hosts in section 6(a) | AI processing | Prompts and document passages | United States / other regions, zero-retention endpoints only (embeddings: no-data-collection endpoints at Microsoft Azure or OpenAI) |
| LlamaIndex Inc. | Document parsing | Uploaded PDF, image and scanned files, Word files with no readable text, and PDF or Word data submissions in which the Platform's own reader finds no reportable figures (section 6(b)) | European Union (Frankfurt) endpoint (api.cloud.eu.llamaindex.ai) |
| Resend, Inc. | Sending email (invitations, sign-in links, notifications, reminders) | Email address, name, message content | United States (account data and logs are stored in the US irrespective of sending region) |
| Functional Software, Inc. (Sentry) | Error monitoring | Error reports tagged with your user id and organisation id, which may include request details | European Union data region (Frankfurt) |
| Gupshup, and Meta Platforms (WhatsApp) | WhatsApp message transport | Phone number, message content | United States, Europe and Asia (per Gupshup) |
| GitHub, Inc. | Runs the off-site backup job for the database (used since 1 September 2026; not running on a schedule at present) | A copy of the database passes through GitHub's servers on its way to backup storage | United States |
We may also disclose information where the law requires it, to a regulator, or to establish or defend legal claims. We do not share your information with any other third party.
8. International transfers
Because our providers operate outside South Africa, and some outside the European Union, your information will be transferred across borders.
- From South Africa (POPIA s 72): we transfer only to providers bound by a written agreement that upholds protections substantially similar to POPIA, including limits on onward transfer (s 72(1)(a)). Nia has accepted the standard data-processing terms of each provider listed in section 7, as at 4 September 2026.
- For people in the EU (GDPR Chapter V): transfers to countries without an adequacy decision rest on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) incorporated into each provider's data-processing agreement, together with the technical measures described in sections 6 and 9. Where a provider is certified under the EU-US Data Privacy Framework we may also rely on that adequacy decision. Provision to be finalised in a later version
You may ask us for a copy of the safeguards in place by writing to the privacy contact.
9. How we protect your information
- All traffic is encrypted in transit (HTTPS); providers encrypt stored data at rest.
- Sign-in is protected by rate limiting; two-factor authentication is available to every user and is required for platform administrators; passkeys are supported.
- Each organisation's data is isolated in the application, which checks your organisation membership on every request; the WhatsApp assistant only answers numbers an administrator has registered, and derives the organisation from that registration alone.
- Sensitive operations (deleting your account, changing your email, enabling 2FA) require a recent sign-in.
- Significant actions are recorded in an audit trail. Support access by Nia or Trigger Consulting staff to your organisation's workspace is logged with a stated reason.
- AI requests are restricted to zero-retention endpoints; the document parser is instructed not to cache your files.
- Off-site database copies were taken from 1 September to 3 September 2026; the job that takes them is not running on a schedule at present, so no retention window is promised for database backups. The control for restoring the database is the database provider's continuous 6-hour point-in-time recovery window.
No system is perfectly secure. If we become aware of a security compromise affecting your personal information, we will notify the Information Regulator and affected people as soon as reasonably possible (POPIA s 22) and, where GDPR applies, the competent supervisory authority within 72 hours (GDPR Art 33) and you without undue delay where the risk to you is high (Art 34). Our incident procedure is documented in our internal incident-response runbook and is owned by our Information Officer (section 1).
10. How long we keep your information
The periods below are the settings and controls on the Platform today; where a control is not yet operating, the table says so.
| Data | Retention |
|---|---|
| AI assistant conversations (web and WhatsApp), including attached files | Retention setting 12 months after the conversation is created. The automated purge that enforces it runs daily. Conversations started before 4 August 2026, when the setting changed from 24 months, keep the 24-month period that applied when they were created. |
| Files uploaded but never attached to a record | Deleted after 24 hours. |
| Email delivery-failure records | Deleted after 30 days. |
| AI-assistant and WhatsApp rate-limit counters | Deleted after 24 hours. |
| Login sessions | Expire 30 days after you last used the Platform, or when you sign out. |
| Database backups | Off-site database copies were taken from 1 September to 3 September 2026; the job that takes them is not running on a schedule at present, so no retention window is promised for database backups. The control for restoring the database is the database provider's continuous 6-hour point-in-time recovery window. |
| Daily backup copies of uploaded files | Deleted 35 days after they are taken. |
| Account details, organisation and membership records, reporting content, uploaded documents and extracted text, audit trail, notifications, contact records, WhatsApp registrations, sign-in rate-limit records | Kept for as long as your organisation uses the Platform and thereafter until deleted on request or under our retention schedule: kept for the return window in section 14.2 of the Terms of Service and then deleted under section 14.3; nothing is kept longer unless the law requires it. |
When you delete your account (section 11), your sign-in, credential, membership and notification records are removed immediately, and audit-trail entries recorded in your name are currently deleted with them (we are changing this so that the trail is kept without your name). Content you created on behalf of your organisation remains part of that organisation's records with your name removed. Some administrator accounts cannot yet be deleted self-service; write to the privacy contact and we will do it. A deleted record persists in the file backup copies until they are deleted 35 days after they were taken, and in any database backup copy that exists until that copy is deleted; we will tell you this when we answer a deletion request.
11. Your rights and how to exercise them
You have the right to:
- Access the personal information we hold about you and receive a copy (POPIA s 23; GDPR Art 15) and, under GDPR, to receive it in a portable format (Art 20);
- Correct or complete it (POPIA s 24; GDPR Art 16) — you can edit your name, picture and email in Settings;
- Delete it (POPIA s 24; GDPR Art 17) — you can delete your own account in Settings after a recent sign-in, or ask us to do it;
- Object to processing based on legitimate interests (POPIA s 11(3); GDPR Art 21) and restrict processing in the circumstances GDPR Art 18 allows;
- Withdraw consent where processing rests on consent (none of the purposes in section 5 do);
- Complain to a regulator (section 14).
To exercise any right, email sarah@niaimpactinvest.com from the address on your account, or via your organisation's administrator. We will confirm receipt, may ask you to verify your identity, and will respond within one month (30 days); where GDPR applies and a request is complex we may extend this by up to two further months and will tell you why (GDPR Art 12(3)). Access to information that also concerns other people (for example an organisation's full member list) is prepared by Nia staff so that other people's information is not disclosed to you.
This provision is being finalised with our legal counsel and will be published in a later version.If you are an employee of a GP or portfolio company, your organisation may also hold rights and obligations in respect of your work data under its own policies.
12. Cookies
The Platform sets only cookies that are strictly necessary to run it: a sign-in session cookie (30 days from last use), a language-preference cookie and an interface-preference cookie (sidebar state). The public website sets no cookie unless you change its language. We use no analytics, advertising or third-party cookies. Details are in our Cookie Notice.
13. Children
The Platform is a business tool for people acting in a professional capacity. It is not directed at, and we do not knowingly collect information from, anyone under 18.
14. Complaints and regulators
We would like the chance to resolve any concern first — write to sarah@niaimpactinvest.com or to our Information Officer (section 1). You also have the right to complain to:
- South Africa — Information Regulator: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 · +27 (0)10 023 5200 · POPIAComplaints@inforegulator.org.za · https://inforegulator.org.za
- European Union: the supervisory authority in the EU member state where you live or work, or where you believe the infringement occurred. A list is at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
15. Changes to this policy
We will post any change here with a new version number and effective date, and will notify organisation administrators (and, for material changes, all users by email or in-app notice) before it takes effect. The version you accepted — at sign-up, when accepting an invitation, or on the re-acceptance screen after a change — is recorded against your account with the date, the language shown and the screen it was accepted on.
Related documents: Terms of Service · Data Processing Agreement for organisations (available on request) · Sub-processor list · How the platform uses AI · Cookie Notice · Breach procedure, Information Officer and retention schedule (in preparation).
Who we are and how to reach us
Nia Impact SA (Pty) Ltd (trading as Nia Impact Invest) · registration number 2023/912189/07
71 4th Street, Houghton, Gauteng, 2198, South Africa
Legal and privacy: sarah@niaimpactinvest.comSupport: hello@niaimpactinvest.com
Version history
- v1.1Across the legal set — Version 1.1, effective 6 September 2026: a wording and link tidy-up of version 1.0. Nothing is taken away and nothing new is asked of you; the only change to what the Terms require is one new commitment by Nia, in clause 21.1, which section 21.3 makes effective on publication, so no one is asked to accept again. Privacy Policy section 7: the GitHub row now says the database backup job is not running on a schedule at present, as sections 9 and 10 already said; the opening sentence of section 7 is reworded by one word. Privacy Policy sections 9 and 10: the database-backup sentences now say the off-site copies were taken from 1 to 3 September 2026 and the job is not running on a schedule; the promise itself is unchanged. Sub-processor list: Resend's legal entity is written as Plus Five Five, Inc. Terms 21.1: Nia still provides a copy of any earlier version on request, and now commits to 10 business days where the request is made in writing — the same turnaround as an export under 7.8. All documents: the legal hub and the versions page are linked from the site footer. The Cookie Notice, the AI-processing page and the German summaries carry no text change and are re-issued as 1.1 so the set shares one version.
- v1.0Version 1.0, effective 4 September 2026: the first published version, adopted by Nia Impact Invest. It supersedes the draft of 2 September 2026. Later revisions will be listed here with a summary of what changed.