1. Introduction
urWill ("we," "our," or "us") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service at urwill.co.za.
Responsible Party: urWill.co.za is the responsible party for the processing of your personal information as defined by POPIA.
2. Information We Collect
2.1 Information You Provide
When you create a will, you may provide:
- Personal Identifiers: Full name, South African ID number, date of birth, address, phone number, email address
- Beneficiary Information: Names, relationships, ID numbers, percentages
- Asset Information: Descriptions of property, vehicles, bank accounts, investments, estimated values
- Executor Information: Name, contact details, relationship
- Guardian Information: Name, address, contact details (if applicable)
- Special Instructions: Any additional wishes or instructions
2.2 Automatically Collected Information
We may automatically collect:
- Browser Information: IP address, browser type, device type
- Usage Data: Pages viewed, time spent on site, interaction patterns
- Cookies: Small data files stored on your device (see Cookie Policy below)
2.3 Blockchain Data
When you generate your will, we create a SHA-256 hash (cryptographic fingerprint) and store it on Azure Confidential Ledger. This hash:
- Does NOT contain your personal information
- Cannot be reverse-engineered to reveal will contents
- Provides proof your will existed at a specific time
- Is stored on an immutable blockchain (cannot be deleted or modified)
3. How We Use Your Information
We use your information to:
- Provide the Service: Generate your will document and certificate of authenticity
- Store Drafts: Save your work in browser localStorage (your device only)
- Blockchain Storage: Create immutable proof of will existence
- Improve Service: Analyze usage patterns to improve features
- Legal Compliance: Comply with legal obligations and prevent fraud
- Communication: Send important updates about your will (if you provide email)
4. Local Storage (Your Device)
Important: Your Data Stays on YOUR Device
By default, your will data is stored in your browser's localStorage (on YOUR computer/phone). This means:
- We do NOT upload or store your personal will details on our servers
- Your data stays on your device until you clear browser data or delete it
- If you clear browser data, your draft will be permanently lost
- You are responsible for securing your device
5. Data Sharing and Disclosure
5.1 We DO NOT Sell Your Data
We will NEVER sell, rent, or trade your personal information to third parties.
5.2 Service Providers
We may share data with trusted service providers:
- Microsoft Azure: For blockchain storage (Azure Confidential Ledger) and PDF storage (Azure Blob Storage)
- Vercel: For website hosting
- Analytics Providers: For usage analytics (anonymized data only)
All service providers are contractually obligated to protect your data and use it only for providing the Service.
5.3 Legal Requirements
We may disclose your information if required by law:
- To comply with court orders or subpoenas
- To protect our rights or property
- To prevent fraud or illegal activities
- To cooperate with law enforcement
5.4 Attorney Referrals
If you request an attorney referral, we may share your contact information with qualified attorneys. This is done WITH YOUR EXPLICIT CONSENT only.
6. Data Security
We implement security measures to protect your data:
- Encryption: All data transmitted over HTTPS (TLS 1.3 encryption)
- Blockchain Security: Azure Confidential Ledger uses TEE (Trusted Execution Environment)
- Rate Limiting: Protection against abuse (5 wills per hour per IP)
- Input Validation: Prevents injection attacks and malicious data
- Security Headers: HSTS, CSP, X-Frame-Options, etc.
However: No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Your Rights (POPIA)
Under POPIA, you have the following rights:
7.1 Right to Access
You have the right to request a copy of the personal information we hold about you.
7.2 Right to Correction
You have the right to request correction of inaccurate or incomplete personal information.
7.3 Right to Deletion
You have the right to request deletion of your personal information, subject to legal obligations.
7.4 Right to Object
You have the right to object to the processing of your personal information in certain circumstances.
7.5 Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Regulator of South Africa:
Website: www.justice.gov.za/inforeg
Email: inforeg@justice.gov.za
7.6 How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@urwill.co.za. We will respond within 30 days.
8. Data Retention
We retain your data as follows:
- LocalStorage (Your Device): Until you clear browser data or delete it manually
- Blockchain Hashes: Stored permanently on Azure Confidential Ledger (immutable)
- PDF Files: Stored with immutability policies (cannot be deleted for 100 years)
- Usage Logs: Retained for 90 days for security and analytics
Note: Blockchain data is immutable by design and cannot be deleted. However, the hash does not reveal any personal information.
9. Cookies and Tracking
We use minimal cookies and tracking:
- Essential Cookies: Required for the Service to function (localStorage for draft saving)
- Analytics Cookies: To understand how users interact with the Service (anonymized)
You can disable cookies in your browser settings, but this may affect Service functionality.
10. Children's Privacy
Our Service is NOT intended for individuals under 18 years old. We do not knowingly collect personal information from minors. If you believe we have collected information from a minor, please contact us immediately.
11. International Data Transfers
Your data may be stored on servers outside South Africa (Microsoft Azure data centers). We ensure adequate protection through:
- Microsoft's compliance with international data protection standards
- Standard contractual clauses
- Azure's security certifications (ISO 27001, SOC 2, etc.)
12. Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this page
- Displaying a prominent notice on our website
- Sending an email notification (if we have your email address)
13. Contact Information
For questions about this Privacy Policy or to exercise your rights, contact us at:
Summary: Your Privacy Matters
- Your will data stays on YOUR device (localStorage)
- We do NOT upload your personal will details to our servers
- We NEVER sell your data to third parties
- Blockchain hashes are anonymized (cannot reveal personal info)
- You have full rights under POPIA to access, correct, or delete your data