POPIA, by default
Data stored and processed in South Africa. Encrypted at rest and in transit, with a signed DPA and full audit logs on every record.
- SA data residency
- Signed Data Processing Agreement
- Consent & subject-access tooling
POPIA, SARS and security aren't add-ons or afterthoughts. They're the foundation Livex is built on, so you can grow without looking over your shoulder.
Data stored and processed in South Africa. Encrypted at rest and in transit, with a signed DPA and full audit logs on every record.
Every invoice is a valid tax invoice. Export VAT201-ready summaries and hand your accountant clean, compliant books.
PCI-DSS-aligned payment handling, encryption everywhere, role-based access and continuous monitoring - reviewed independently.
Security isn't a page in a policy - it's engineered into every layer of Livex.
Strong encryption at rest and in transit, with keys rotated and held in dedicated key management.
Least-privilege access, granular roles, and enforced multi-factor authentication via LivexID.
Every create, change and access is logged with actor, timestamp and IP - exportable for your records.
Continuous, encrypted backups with point-in-time recovery and geo-redundant storage.
Regular third-party penetration testing and vulnerability scanning, with findings tracked to closure.
A short, published list of sub-processors - each under a signed DPA and reviewed annually.
Livex gives you the tooling to honour data-subject requests quickly, so you stay compliant without the paperwork scramble.
All Livex data is stored and processed in South Africa. It never leaves the country without your explicit instruction.
You (the business) remain the responsible party for your customers' data. Livex acts as an operator processing it on your behalf, governed by our signed Data Processing Agreement.
We monitor continuously and, in the unlikely event of a breach affecting your data, we notify you and the Information Regulator in line with POPIA's notification requirements.
Yes. A standard Data Processing Agreement is available to every customer, and our team can share security documentation and complete vendor security reviews on request.
Your data stays available while your account is active and for a grace period after cancellation, after which it is permanently deleted unless you request earlier removal or a longer legal hold.
Our team helps SA businesses onboard compliantly, every day.