Privacy Policy

What personal information Lenucs collects, why, who it is shared with, how long it is kept and your rights.

Version:
1.0
Effective:
2 October 2026
Last updated:
2 October 2026
Issued by:
Lenucs Pty Ltd

Some company details (such as our contact emails and Information Officer) are still being finalised and are marked “To be published”. You can reach us any time through the contact page.

Who we are

Lenucs Pty Ltd (“Lenucs”, “we”, “us”) is a South African company. We operate Lenucs Console (“Console”) and its public pages on lenucs.link, which together form one service. Lenucs Console is a product of Lenucs Pty Ltd, not a separate company.

This policy explains how we handle personal information under the Protection of Personal Information Act, 2013 (POPIA) and other laws that apply. It covers people who use Console, people who visit our website, and people who fill in forms or open pages that our customers publish on lenucs.link.

DetailValue
Legal entityLenucs Pty Ltd
ProductsLenucs Console and lenucs.link
Country of registrationSouth Africa
Registration number2026/779802/07
Physical addressYork Road, Hill Crest, Mthatha, Eastern Cape, 5099
Address for legal noticesYork Road, Hill Crest, Mthatha, Eastern Cape, 5099
Postal addressTo be published
Telephone+27 65 638 4903
Information OfficerTo be published
Privacy contactour contact form (choose “Privacy”)
Legal contactour contact form (choose “Legal”)

Lenucs Data and Customer Data

We handle two different kinds of information, and our role is different for each.

  • Lenucs Data is information we need to run our own business: accounts and sign-in, billing, security, support, platform analytics and legal compliance. For Lenucs Data, Lenucs is the responsible party: we decide why and how it is processed.
  • Customer Data is information a business using Console (a “Customer”) puts into its workspace, or that people submit through that Customer’s forms, product links and booking pages. For Customer Data, the Customer is the responsible party and decides why it is collected and how it is used. Lenucs is the operator: we process it to provide the service on the Customer’s instructions, as set out in our Data Processing Addendum.

We do not own Customer Data and we do not sell it.

What we collect

A. Account information

  • Your name, email address and, if you add one, profile photo.
  • Your password, which our authentication provider stores only as a one-way hash. Lenucs staff can’t see it.
  • Sign-in records: when your account was created, when you last signed in and whether your email address is confirmed.
  • Which Terms of Service and Privacy Policy versions you accepted and when, and your marketing email choice.

B. Business and workspace information

  • Workspace name, web address (slug), industry, company size, website, phone number, country, timezone and logo.
  • Team members, their roles and pending invitations (invitee email addresses).
  • Workspace settings, forms, automations, campaigns and other configuration.
  • CRM records your team adds: contacts (name, email, phone, company), leads, customers, revenue entries, notes, tasks and bookings.
  • For merchant verification: business name, registration number and the documents you upload (ID, proof of address, bank confirmation). Payment details you choose to show buyers, such as bank account details for EFT.

C. Information submitted through Customers’ forms

Customers build their own forms and choose what to ask. A form can include any of these, and the Customer decides which: name, email, phone, company, messages, dates, numbers, website addresses, choices, consent checkboxes, custom questions and uploaded files (on paid plans).

With each response we also store: the time it was submitted, the page or campaign link it came from (UTM tags, referring page and landing page), the device type (mobile, tablet or desktop), a random visitor identifier stored in the browser, and a one-way hash of the IP address used to stop spam. The raw IP address is not stored. If the form offers it, we also record whether the person ticked an optional marketing box, and the privacy notice shown at the time.

This is Customer Data. The Customer who published the form is responsible for it (see Customers’ responsibility).

D. Product links and orders

Customers can publish product or service pages with a name, description, price, images, buttons, external links and other content they provide. Customers are responsible for the accuracy and legality of that content.

When a buyer places an order through a product link, we store the buyer’s name, phone number, email address (if given), delivery address and notes (if given), the chosen delivery and payment method, and a daily-changing hash of the buyer’s connection used against abuse. The merchant receives this to fulfil the order. If the buyer chooses WhatsApp, their own WhatsApp app opens with the order details. Lenucs does not process the payment for the goods and is not the seller: the sale is between the buyer and the merchant.

E. Bookings

When a Customer records or receives a booking, we store the service, time, location, status, notes and the linked contact. This is Customer Data.

F. Usage, analytics and security information

  • Form analytics: views and starts, with the random visitor identifier, the traffic source, the device type and the referring website’s domain. No IP address and no browser fingerprint.
  • Product-link analytics (paid plans): page views, QR-code scans, button and share clicks, with traffic source, device type, referring domain and a daily-changing hash of the IP address and browser. Bots are filtered out. Country may be recorded where our hosting provider supplies it.
  • Activity history inside a workspace, such as “lead created” or “task completed”, and in-app notifications.
  • AI usage records: which AI action was used, by whom, the model and the number of tokens. Not the question or the answer.
  • Request logs kept by our hosting and database providers, which include IP addresses and browser details, used for security and troubleshooting.
  • Staff audit log: every action by Lenucs staff in our admin tools, with the staff member, time, a hashed network identifier and browser.

We do not use third-party advertising or analytics trackers. See the Cookie Policy.

G. Payment information

Not live yet

Console does not take online payments today. Paid plans are arranged with our team directly.

When online payments are available, card and bank details will be entered on the payment provider’s pages (we intend to use PayFast by Network International), not on Lenucs. We will receive and keep payment metadata only: payment status, transaction and subscription references, plan, amount, currency, payment date and refund status. We will not store full card numbers. The payment provider processes payment information under its own terms and privacy policy.

H. Lenucs AI

Paid workspaces can use Lenucs AI when it is switched on. When someone asks Lenucs AI a question, we send the question, up to ten recent messages from that chat, and the workspace records needed to answer it to our AI provider (currently Google, through the paid Gemini API). Depending on the question this can include lead and customer names, contact details, notes, tasks, form answers and dashboard figures that the person is allowed to see. We store usage records (model and token counts) but not the prompts or answers. Customer Data is processed only to provide the requested AI feature, and we do not use it to train AI models. See the AI Terms.

I. Communications

  • Messages you send us through the contact form, Help in Console or privacy requests, and our replies.
  • Account emails sent by our authentication provider: email confirmation and password reset.
  • In-app notifications.

We do not currently send marketing emails. If you opted in at sign-up, we keep that choice and will only use it once we send product news, always with an unsubscribe link.

Why we use it

We use personal information only for these purposes:

  • Providing Console: creating and managing accounts and workspaces, signing people in, and showing workspace data to the right people.
  • Running forms, product links and bookings: showing them, receiving submissions and orders, and delivering them to the right workspace.
  • Managing leads, customers and bookings for our Customers.
  • Analytics for Customers about their own forms and product links, and aggregated statistics for Lenucs about how the service is used.
  • Automations and Lenucs AI, when a Customer uses them.
  • Payments and plan limits, once payments are live.
  • Preventing spam, fraud and abuse, and keeping the service secure (rate limits, hashed identifiers, reports of suspicious links, merchant verification).
  • Debugging and keeping the service reliable.
  • Answering questions and support requests, and sending service, security and billing messages.
  • Complying with law, handling legal claims and enforcing our agreements.

We process personal information where it is needed to provide the service you asked for or to perform our contract with you, where we have a legitimate interest that does not override your rights (such as security and fraud prevention), where the law requires it, or with your consent (such as optional marketing emails).

Collecting only what we need

We collect personal information only for the purposes above and keep it only as long as those purposes, our contracts or the law require. We do not collect information just because it might be useful one day.

Where we can, we use aggregated or de-identified information for statistics, service analytics, performance measurement, product improvement, capacity planning, security and business reporting. Visitor identifiers are random or one-way hashes whose secret key changes every day, and we never store raw IP addresses in our database.

We do not sell personal information, and we do not share it for advertising.

Who we share it with

  • Our service providers (subprocessors), who host and run the service for us under contract. They are listed, with what they do and where, on our Subprocessors page.
  • The Customer who owns a workspace. Form responses, orders and bookings go to the business you submitted them to. Workspace members see records according to their role.
  • Authorities, where the law requires it or to protect rights, safety and property, after checking that the request is lawful.
  • A buyer or successor if Lenucs is sold or reorganised, under the same protections.

Product-link pages may link to WhatsApp, social networks or other websites. When you follow those links, the other service’s own privacy policy applies.

International transfers

Some of our providers process information outside South Africa (for example in the United States or the European Union) because that is where their infrastructure is. Where we transfer personal information across borders we do so as section 72 of POPIA allows: to providers bound by data protection terms or laws that give a level of protection substantially similar to POPIA, or where the transfer is needed to perform our contract with you. The Subprocessors page shows each provider’s location where it is known. We do not claim that all data is stored in South Africa.

How long we keep it

We keep information only as long as we need it. When the period ends, we delete it, anonymise it or dispose of it securely. Deleted information can remain in our database provider’s backups until those backups rotate out.

InformationHow long we keep itHow it is removed
Account and profileWhile your account exists. Removed when your account is deleted.Deleted on account deletion or request
Workspace records (contacts, leads, customers, bookings, tasks, notes, product links, orders)Controlled by the workspace. Kept until the workspace deletes them or the workspace is deleted.Deleted by the workspace
Form responses and uploaded filesControlled by the workspace. Deleted with the response, with "Erase this person", or with the workspace.Deleted by the workspace
Form analytics (views and starts)12 monthsDeleted automatically
Product-link analytics (page views, clicks)12 monthsDeleted automatically
In-app notifications and automation run logs12 monthsDeleted automatically
Merchant verification documents (ID, proof of address, bank letter)30 days after the application is decidedDeleted automatically
Merchant verification decision recordWhile the workspace existsReviewed and deleted manually
Support enquiries and replies2 years after the enquiry is resolved or closedDeleted automatically
Privacy and data requests3 years after completionDeleted automatically
Terms and Privacy acceptance records, marketing preference historyWhile the account exists, then removed with the accountDeleted on account deletion or request
Staff audit log2 yearsDeleted automatically
Security incident recordsAt least 5 yearsReviewed and deleted manually
Expired workspace invitations90 days after expiryDeleted automatically
AI usage records (model, token counts; no prompts or answers)While the workspace existsDeleted by the workspace
Billing and payment records (when payments are live)5 years after the transactionReviewed and deleted manually
Database backupsKept by Supabase on its backup schedule for the project's plan; deleted data leaves backups as they rotate out.Deleted automatically

Security

We use reasonable technical and organisational measures to protect personal information, described on our Security page. No online service can be completely secure. If a security compromise affects your personal information, we will investigate, contain it and notify the Information Regulator and affected people as POPIA requires. Where we act as operator for a Customer, we notify the Customer so it can meet its own obligations.

Your rights

Under POPIA you can, where the law allows:

  • ask whether we hold information about you, and get a copy of it;
  • ask us to correct or delete information that is inaccurate, out of date, excessive or unlawfully obtained;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • withdraw consent you gave, without affecting processing that already happened;
  • ask how your information is processed and who has received it;
  • complain to the Information Regulator.

How to make a request

  • Your Lenucs account: in Console, open Profile → Privacy and data to download your account data, change your marketing choice or request account deletion. You can also use the privacy request form or our contact form (choose “Privacy”).
  • Information you gave a business through its form, booking or product page: that business decides how your information is used, so please contact it first. If you can’t reach it, or you think it is misusing Lenucs, use the privacy request form, name the business, and we will forward your request or help where we can.

We may need to confirm your identity before acting. We aim to respond within 30 days, and we will tell you if we need longer or can’t act (for example where we must keep information by law). The PAIA forms and process are in our PAIA Manual.

The Information Regulator (South Africa): inforegulator.org.za.

Customers’ responsibility for their data

A business that uses Lenucs to collect leads, orders or bookings is responsible for making sure that:

  • it has a lawful reason to collect the information and asks only for what it needs;
  • it tells people who it is and how it will use their information (Console lets a form show a privacy notice and link);
  • it gets any consent the law requires, including separate consent for direct marketing;
  • it answers access, correction and deletion requests from the people whose information it holds;
  • it follows marketing laws and keeps exported information secure.

Lenucs provides the tools and infrastructure; we don’t make legal compliance decisions for Customers.

Children and special personal information

Console is for businesses and people aged 18 or older. We do not knowingly collect information from children for our own purposes.

Customers must not use Console to collect children’s personal information, or special personal information (such as health, biometric, religious or criminal information), unless the collection is lawful, they have any authorisation the law requires, and appropriate safeguards are in place. Customers should take legal advice before doing so. See the Acceptable Use Policy.

Emails and marketing

  • Transactional and security emails (email confirmation, password reset, and in future billing receipts and security notices) are part of the service and are not marketing.
  • Marketing emails are only sent if you opted in, and every one will include a way to unsubscribe. You can change your choice at any time in Profile → Privacy and data.
  • People who fill in a Customer’s form are never added to Lenucs’ marketing. A Customer may offer its own optional marketing checkbox on a form; ticking it is a choice made to that Customer, recorded with the time and the wording shown.

Changes to this policy

When we change this policy we update the version number and dates at the top. For material changes we will tell signed-in users in Console and ask them to review the new version before continuing. Earlier versions are kept on file and are available on request.

Contact

Questions about privacy: our contact form (choose “Privacy”). Requests about your information: the privacy request form.