Komiti Privacy Policy
Website: https://komiti.co.za
1. Who We Are
Komiti is a committee management platform, developed and operated by ASAP Online, hosted on infrastructure provided by Xneelo (South Africa). Each client organisation using Komiti is provided with a dedicated, isolated instance of the platform.
For any questions about this policy or your data, contact us at info@asaponline.co.za.
2. What Data We Collect
When you use Komiti as part of your organisation’s committee, we may collect and process:
- Account information: name, email address, username, and role/permission level within your organisation’s Komiti instance
- Committee content: agendas, minutes, meeting documents, attachments, comments, and other committee records that users upload or create within the platform
- Login and access data: login timestamps, IP address (for rate-limiting and security purposes), and session information
- Technical data: browser type, device information, and similar technical data collected automatically when you access the platform
We do not collect data beyond what is necessary to operate the committee management functions of the platform.
3. How We Use Your Data
We use the data described above to:
- Provide and operate the Komiti platform for your organisation
- Authenticate users and enforce role-based access controls
- Maintain the security of the platform, including detecting and rate-limiting suspicious login activity
- Provide customer support when requested
- Comply with legal obligations where applicable
We do not use committee content or personal data for advertising, and we do not sell personal data to third parties.
4. Data Hosting and Architecture
- Komiti is deployed on a dedicated, per-client basis — each client organisation has its own separate server/domain (or subdomain) and database. Data is not shared or pooled across different client organisations (no multi-tenant database).
- Infrastructure is hosted via Xneelo, a South African hosting provider.
- Data in transit is encrypted via HTTPS/TLS.
- Data at rest is not currently encrypted for the standard Komiti deployment. Encryption at rest can be implemented on request.
5. Data Retention and Deletion
- Committee data is retained for as long as your organisation’s Komiti instance is active.
- Daily incremental backups are taken and retained for 14 days.
- If your organisation terminates its use of Komiti, the dedicated server/domain and its data are handed back to your organisation — Komiti does not retain a copy of your data after handover.
6. Sub-processors and Third Parties
Komiti does not currently use third-party sub-processors to handle client data. Because each client’s instance is hosted independently, there is no shared third-party data processing beyond the underlying hosting provider (Xneelo).
7. Security Measures
- Role-based access control (RBAC), so users only have access appropriate to their role within their organisation’s committee
- Rate limiting on login attempts (a 5-minute lockout is triggered after repeated failed attempts)
- HTTPS/TLS encryption for data in transit
- Per-client architecture, meaning no organisation’s data is stored alongside another’s
We are actively working on further security improvements, including multi-factor authentication (MFA) and full account lockout controls, planned for an upcoming release. Komiti does not currently hold third-party security certifications (e.g. ISO 27001, SOC 2).
8. Your Rights
If you have an account on Komiti, or have contributed content as part of a committee, you can request:
- A copy of the personal data held about you
- Correction of inaccurate personal data
- Deletion of your personal data, subject to any data your organisation is required to retain for administrative, legal, or record-keeping purposes (e.g. committee minutes retained as part of official records)
Requests should be directed to your organisation’s Komiti administrator in the first instance, or to info@asaponline.co.za, as your organisation is typically the data controller for committee content.
9. Cookies
Komiti uses cookies necessary for login sessions and to remember your display preferences.
10. Changes to This Policy
We may update this policy from time to time.