Livex
Trust & compliance

Built for South African business - and its rules

POPIA, SARS and security aren't add-ons or afterthoughts. They're the foundation Livex is built on, so you can grow without looking over your shoulder.

POPIA, by default

Data stored and processed in South Africa. Encrypted at rest and in transit, with a signed DPA and full audit logs on every record.

  • SA data residency
  • Signed Data Processing Agreement
  • Consent & subject-access tooling

SARS & VAT ready

Every invoice is a valid tax invoice. Export VAT201-ready summaries and hand your accountant clean, compliant books.

  • Valid VAT tax invoices
  • VAT201 export summaries
  • SARS-friendly records

Bank-grade security

PCI-DSS-aligned payment handling, encryption everywhere, role-based access and continuous monitoring - reviewed independently.

  • PCI-DSS-aligned payment processing
  • Role-based access & SSO
  • Encrypted, monitored, backed up
Encryption everywherein transit & at rest
High availabilitycontinuously monitored
Hosted in South AfricaSA data residency
Secure paymentsPCI-DSS-aligned handling
ISO 27001 certifiedindependently audited

How we keep your data safe

Security isn't a page in a policy - it's engineered into every layer of Livex.

Encryption everywhere

Strong encryption at rest and in transit, with keys rotated and held in dedicated key management.

Role-based access & MFA

Least-privilege access, granular roles, and enforced multi-factor authentication via LivexID.

Full audit logs

Every create, change and access is logged with actor, timestamp and IP - exportable for your records.

Encrypted backups

Continuous, encrypted backups with point-in-time recovery and geo-redundant storage.

Independent testing

Regular third-party penetration testing and vulnerability scanning, with findings tracked to closure.

Vetted sub-processors

A short, published list of sub-processors - each under a signed DPA and reviewed annually.

POPIA rights, built in

Help your customers exercise their rights - in a click

Livex gives you the tooling to honour data-subject requests quickly, so you stay compliant without the paperwork scramble.

Right to access Export any person's data on request, in minutes.
Right to correction Edit or update records with a tracked change history.
Right to deletion Permanently erase data with a verifiable deletion log.
Consent management Capture, store and withdraw consent per contact.

Compliance questions

Where is my data hosted?

All Livex data is stored and processed in South Africa. It never leaves the country without your explicit instruction.

Who is the responsible party under POPIA?

You (the business) remain the responsible party for your customers' data. Livex acts as an operator processing it on your behalf, governed by our signed Data Processing Agreement.

How are data breaches handled?

We monitor continuously and, in the unlikely event of a breach affecting your data, we notify you and the Information Regulator in line with POPIA's notification requirements.

Can I get a signed DPA and security documentation?

Yes. A standard Data Processing Agreement is available to every customer, and our team can share security documentation and complete vendor security reviews on request.

How long is data retained after I cancel?

Your data stays available while your account is active and for a grace period after cancellation, after which it is permanently deleted unless you request earlier removal or a longer legal hold.

Need a DPA, security review or a chat with sales?

Our team helps SA businesses onboard compliantly, every day.