Security and data

Your statement data
is not marketing copy.

A trustworthy service explains what is collected, why it is processed, who can access it, how long it remains, and what happens when the job is done.

Concept policy · operational facts require Bluubin verification before production

Trust register
Source-file retentionConfirm
Extracted-file retentionConfirm
Human access controlsPublish
Subprocessor listPublish
Model-training statementConfirm

This page deliberately exposes decisions that must be completed. It does not invent certifications, hosting regions, or deletion periods.

01Data lifecycle

Four moments. A specific answer at each.

The production policy should follow the file from selection to deletion. Each stage needs a verified purpose, access rule, storage location, and duration.

01

Upload

The browser sends the chosen PDF only after the user sees the page count and conversion terms.

02

Process

The system extracts statement rows for conversion, failure handling, and security monitoring.

03

Review

The user compares the structured result with the source before export or deletion.

04

Delete

Source and extracted files follow separate, precisely published retention and early-deletion rules.

02Launch fact register

Answer the risk questions in ordinary language.

A generic “secure” badge cannot replace an operating entity, a retention period, access conditions, subprocessors, and a real incident contact.

Who operates ReconReady?

Publish the full South African legal entity, registration details, and contact address.

Confirm before launch

What is collected?

Account data, source PDFs, extracted rows, technical logs, support records, and payment records as actually implemented.

Publish clearly

Why is it processed?

Conversion, customer-requested support, security, billing, fraud prevention, and legal obligations that genuinely apply.

Publish clearly

How long are files retained?

Publish separate, exact periods for source PDFs, extracted output, backups, and account history.

Confirm before launch

Who can access files?

Explain role restrictions, exceptional support access, approval, logging, and review.

Confirm before launch

Which providers receive data?

Name subprocessors or meaningful categories, purposes, locations, and links where appropriate.

Confirm before launch

Is data used for model training?

State yes or no only after technical and contractual verification across the complete processing chain.

Confirm before launch

What happens after an incident?

Publish the security contact, assessment process, and customer or regulator notification route.

Confirm before launch
03Control categories

Only claim controls that are deployed and evidenced.

Before launch, the engineering and legal owners should verify each control, its scope, the provider involved, and the record that proves it is operating.

Encryption

Verify scope · 01

Least privilege

Verify scope · 02

Subprocessors

Verify scope · 03

Audit logs

Verify scope · 04

Backups

Verify scope · 05

Security testing

Verify scope · 06

04Privacy and POPIA

Publish the process customers can assess.

The final Privacy Notice must explain purposes, retention, security safeguards, rights requests, Information Officer details, and when ReconReady or Bluubin acts as a responsible party, operator, or both. South African counsel should review the finished documents.

10 pages / free trial

Know the data process before the first upload.

The production service should make retention, access, deletion, and support conditions easy to find—not hide them after conversion.