H&M Information Management Services (Pty) Ltd Privacy Policy
Last Updated: 23 March 2026
This Privacy Policy describes how H&M Information Management Services (Pty) Ltd (RSA Reg. No. 2023/606164/07), trading as Docwize ("Docwize", "we", "us" or "our"), collects, uses and discloses information, and what choices you have with respect to the information.
This policy applies to Docwize’s eDiscovery and automation software-as-a-service platform and related services (the "Service").
1. Definitions: Customer Data vs. Operational Data
We distinguish between two categories of data:
- "Customer Data" means all data, documents, files, metadata, structured or unstructured information, and other content uploaded to, submitted to or processed through the Service by or on behalf of you or your authorised users. You retain all ownership rights in your Customer Data. To the extent Customer Data contains Personal Data, Docwize processes it on your behalf as a Processor / Operator under our Data Processing Addendum.
- "Operational Data" means the information Docwize needs to operate the Service, including account information (names, emails), billing details, usage logs, device telemetry and platform metadata (e.g. file sizes, timestamps). Docwize processes Operational Data as an independent Controller / Responsible Party for purposes such as account administration, billing, security, fraud prevention and legal compliance.
Key distinction: We do not treat Customer Data as Operational Data. We do not use the content of your documents for marketing, advertising, or to train third-party or general-purpose AI or machine-learning models.
2. Information We Collect
A. Information You Provide
- Account Information: When you register, we collect your name, email address, password, and contact details.
- Payment Information: We collect billing details and credit card information via our secure payment processors. Docwize does not store raw credit card numbers.
- Customer Data: We store and process the documents and files you upload to provide the Service.
B. Information We Collect Automatically
- Usage Logs: We collect visual and technical logs regarding how you use the Service (e.g., features used, storage limits).
- Device and Connection Information: We collect information about your computer, phone, or other devices you use to access the Service, including IP address, browser type, and operating system.
- Cookies: We use cookies for authentication and session management. You can control cookies through your browser settings.
3. How We Use Your Information
We process your data to provide, secure and improve the Service and to support our legitimate operational needs (including billing, account administration, fraud prevention and legal compliance). Specific purposes include:
- Service Provision: To host your files, process search queries, and render document previews.
- Customer Support: To resolve technical issues you report.
- Security: To detect and prevent fraud, abuse, or security incidents.
- Legitimate Interests: To analyze aggregate usage trends (using anonymized Operational Data) to improve platform performance.
Advertising Limitation: Unlike consumer-grade services, we do not scan your Customer Data (documents) to build advertising profiles or serve you targeted ads.
4. Artificial Intelligence and Machine Learning Governance
Docwize integrates AI-enabled features such as document summarization, classification and data extraction. AI features are optional and are activated by your use of the applicable functionality. We adhere to the following governance framework:
A. No Training on Customer Data
Where AI features are used, Customer Data may be processed by third-party AI providers (such as OpenAI and Anthropic) via their commercial APIs. The current list of AI sub-processors is available on our Sub-Processors page.
- No-training commitment: Neither Customer Data nor aggregated or de-identified data derived from it may be used by Docwize or its sub-processors to train third-party or general-purpose AI or machine-learning models. AI sub-processors process Customer Data solely to provide the AI-enabled functionality requested or activated by you.
- Data isolation: Customer Data processed by AI sub-processors is not shared with other customers or the public.
B. Ephemeral Processing
When you use an AI feature (e.g. "Summarize this PDF"), the relevant text is sent to the AI provider solely to generate the response.
- Retention: AI providers may transiently retain data for abuse monitoring and safety purposes in accordance with their data processing terms, after which it is deleted. Customer Data is not permanently stored by the AI provider.
C. Human Oversight
Docwize does not manually review your Customer Data to improve AI features, except where necessary to resolve a specific support request with your written permission or to comply with valid legal process.
5. Data Sharing and Subprocessors
A. Third-Party Service Providers
We work with third-party service providers to provide website and application development, hosting, maintenance, backup, storage, virtual infrastructure, payment processing, analysis, and other services for us. These service providers may have access to or process your information for the purpose of providing those services for us.
Authorized Subprocessors: We maintain a list of authorized subprocessors at https://docwize.com/sub-processors
B. Right to Object
The notice and objection process for new sub-processors is governed by our Data Processing Addendum. In summary, we will notify you before authorising a new non-optional sub-processor to process Customer Data and provide you with an opportunity to object on reasonable data protection grounds.
C. No Sale of Data
We are strictly a paid SaaS platform. We do not sell your personal information or Customer Data to data brokers or third parties.
6. Government Requests and Transparency
We are committed to maintaining the privacy of your data against overreaching government surveillance. Our policy regarding law enforcement requests (e.g., subpoenas, warrants) is as follows:
A. Notification Unless Prohibited
If Docwize receives a government request for your Customer Data, we will attempt to notify you and provide you with a copy of the request to allow you to seek a protective order, unless:
- We are prohibited from doing so by a valid legal order (e.g. a court order or equivalent instrument under applicable law); or
- We have a good faith belief that there is an exceptional emergency involving danger of death or serious physical injury.
B. Directing Requests to You
We believe that government agencies should obtain data directly from you, the customer. We will attempt to redirect the agency to request the data from you directly whenever possible.
7. Data Retention and Deletion
A. During Subscription
We retain Customer Data for as long as your account is active to provide the Service.
B. Account Termination
Upon termination or expiry of your account:
- Export period: Your Customer Data will be available for export for thirty (30) days (or such other period as stated in your Order Form).
- Deletion from active systems: After the export period, Customer files are deleted from active production systems within approximately thirty (30) days.
- Logs, metadata and operational records: Logs, audit data, file metadata and related operational records may be retained for up to twelve (12) months where reasonably necessary for system integrity, auditability, billing reconciliation, fraud or security investigation, legal compliance or backup administration.
- Backup retention: Automated backup systems retain historical copies of your data in accordance with the applicable backup retention schedule (which includes daily, monthly and annual backup cycles). Backup copies are overwritten or deleted in the ordinary course of the retention cycle. Backups are not used for active processing and remain subject to the security and confidentiality obligations in our Data Processing Addendum.
C. Right to Erasure
You may request the deletion of your personal data by contacting us at the address below. We will process this request in accordance with applicable data protection laws, subject to any legal obligations to retain specific records (e.g. billing reconciliation, legal compliance).
8. Security and Encryption
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption in transit: All data transmitted between your device and Docwize is encrypted using current industry-standard transport-layer encryption.
- Encryption at rest: Customer Data stored on our infrastructure is encrypted at rest.
- Access controls: Access to Customer Data is restricted to authorised personnel on a least-privilege basis, with multi-factor authentication required for production systems, and subject to written confidentiality obligations.
For more detail, see the security measures described in our Data Processing Addendum.
9. International Data Transfers
Docwize is based in South Africa. However, our cloud infrastructure and subprocessors (such as AWS and OpenAI) may be located in the United States or the European Union.
- Safeguards: When transferring data across borders, we rely on legally adequate transfer mechanisms, such as the European Commission’s Standard Contractual Clauses (SCCs) and adherence to POPIA Section 72, ensuring that the recipient is subject to a law, binding corporate rule, or binding agreement which provides an adequate level of protection.
10. Your Privacy Rights and Choices
Depending on your location (South Africa, EU/UK, USA), you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Deletion: Request deletion of your personal information (Right to be Forgotten).
- Restriction: Request that we restrict the processing of your data.
- Portability: Receive your data in a structured, machine-readable format.
To exercise these rights, please contact us at support@docwize.com. We will verify your identity before processing the request.
11. POPIA and GDPR Compliance
A. POPIA (South Africa)
Docwize acts as an "Operator" for Customer Data and a "Responsible Party" for Operational Data. We comply with the conditions for lawful processing of personal information as set out in the Protection of Personal Information Act 4 of 2013.
B. GDPR (European Union/UK)
If you are located in the EEA or UK, Docwize acts as a "Data Processor" for Customer Data and a "Data Controller" for Operational Data. Our Data Processing Addendum (DPA) is publicly available at https://docwize.com/dpa.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes that reduce your rights or significantly change how we use your data, we will notify you by email or via a prominent notice within the Service at least 30 days prior to the change taking effect.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact our Information Officer:
H&M Information Management Services (Pty) Ltd
20 Baker St, Rosebank
Johannesburg, Gauteng 2196
South Africa
Email: support@docwize.com