Privacy Policy
Plain language about what personal information InFieldX holds, why, where it lives, and the rights you have over it.
Last updated: 16 July 2026
Who we are
InFieldX is a product of Future Point Consult (Pty) Ltd, trading as “InFieldX” (“we”, “us”), with registered address at 298 Glenwood Rd, Lynnwood Park, Pretoria, 0081, South Africa. We provide business management software for field-service teams — job cards, quotes, invoicing, time tracking and an AI assistant — at app.infieldx.co. This policy is written first for the Protection of Personal Information Act (POPIA). If you use InFieldX from the EU/EEA or the UK, the GDPR sections below apply to you too.
Privacy questions, requests and complaints all go to privacy@infieldx.co. This mailbox reaches our information officer directly.
Two kinds of personal information
Your account information — your name, email address, phone number and how you use the product. For this information we are the responsible party (POPIA) / controller (GDPR).
Records your organisation stores — your clients' names, contact details, addresses, job and billing history. Your organisation decides why this information is collected; we process it only to run the product, acting as an operator (POPIA) / processor (GDPR) on your organisation's instructions. If you are a client of a business that uses InFieldX and want your details corrected or removed, contact that business first — they own the relationship and the data. We will help them honour your request.
What we collect and why
We collect what you give us when you sign up and use the product (account details, business records you enter), and technical information needed to keep the service working and safe: sign-in events, error reports, and rate-limiting counters. We rely on performing our contract with you for core processing, our legitimate interest in keeping the service secure and improving it, your consent where the law requires it, and legal obligations such as tax record-keeping.
We do not sell personal information. We do not share it with anyone except the service providers listed below, and only so they can run the product for us.
AI Assist
When you use AI Assist, your messages and the business records needed to answer them are sent to Anthropic, our AI provider, to generate the response. Anthropic processes this data on servers in the United States and, under its commercial terms, does not use your data to train its models. It may retain conversations briefly for abuse monitoring under those terms.
We do not store your AI Assist conversations after they end. We keep only technical usage records — token counts, timing and the model used — to operate usage limits.
AI Assist can only see what you can see: it works inside your login, subject to the same per-organisation isolation described on our Security page. It never changes or archives anything without your explicit confirmation, and it cannot delete records at all. Please don't enter information it doesn't need — especially ID numbers, banking details or health information.
Where your data lives
Your organisation's data is hosted with Supabase in the European Union, a region whose data protection law (GDPR) provides an adequate level of protection under POPIA section 72. Some processing happens in the United States (AI, email, error monitoring) through the providers below, each under a binding agreement that upholds a level of protection substantially similar to POPIA — and, for EU/EEA users, under GDPR transfer mechanisms such as Standard Contractual Clauses.
| Provider | What they do for us | Where |
|---|---|---|
| Supabase | Database, authentication and file storage | European Union |
| Vercel | Application hosting and delivery | Global edge network (EU/US) |
| Anthropic | AI processing for AI Assist | United States |
| Resend | Transactional email (sign-in codes, documents you send) | United States |
| Cloudflare | Bot protection on sign-in (Turnstile) | Global |
| Upstash | Rate limiting | European Union |
| Sentry | Error monitoring | United States |
We will update this list before adding or changing a provider. Business customers can find the formal terms for all of this — processor obligations, breach notification, transfer clauses — in our Data Processing Agreement.
How long we keep it
We keep your organisation's data for as long as you have an account. Deleting a record in the product marks it deleted rather than destroying it, so mistakes are recoverable. If you close your account, email us and we will export your organisation's data for you, then permanently delete it — except where the law requires us to keep specific records (for example, financial records for tax purposes).
Your rights
Under POPIA you may ask us what personal information we hold about you, ask for it to be corrected or deleted, object to processing, and complain to the Information Regulator of South Africa (inforegulator.org.za). POPIA protects juristic persons too, so these rights extend to your business's own information.
If you are in the EU/EEA or the UK, you additionally have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority.
To exercise any of these, email privacy@infieldx.co. We respond within a month.
Security, children and changes
How we protect your data — per-organisation isolation enforced in the database, audit logging, encryption in transit and at rest — is described on the Security page. InFieldX is a business tool and is not directed at children. If we change this policy in a way that matters, we will tell account owners by email before the change takes effect.