Privacy Policy
Last updated: 13 August 2026
This policy explains what personal data DashPoint Analytics (Pty) Ltd (“DashPoint,” “we,” “us”) collects when a business (“you,” “your business,” the “tenant”) uses the DashPoint platform, why we collect it, and what we do with it. It also covers the personal data your business submits to DashPoint about its own employees, since a payroll and HR system necessarily handles that data on your behalf.
1. Who this applies to
This policy covers two kinds of people: you, the business that signs up for DashPoint and controls the account, and the individuals your business enters into the system as employees — who did not sign up themselves and whose data you submit on their behalf. For your employees’ data, your business is the data controller under the Botswana Data Protection Act 2024, and DashPoint acts as a data processor, handling that data only to provide the service you’ve configured.
2. What we collect
Depending on which modules your business uses, this can include:
- Business account data: business name, registration number, BURS TIN, address, and the login details of anyone your business invites into the system.
- Employee data: full name, national ID/Omang number, date of birth, address, phone number, emergency contact details, bank account details, salary and other compensation, tax code, department, employment dates, and leave records.
- Financial records: invoices, expense claims and receipts, cash transactions, and the client/contact details your business stores in the CRM and Projects modules.
- Content you upload for AI processing: spreadsheets submitted through the onboarding import, receipt images, bank statement PDFs, and inbound emails forwarded to your DashPoint inbox address — see Section 4.
- Technical data: login sessions, and the audit trail DashPoint keeps of actions taken in your account (who did what, when).
3. Why we collect it
We collect and process this data to provide the service your business has signed up for: running payroll, calculating and remitting PAYE, generating payslips and BURS documents, tracking leave and attendance, managing HR records and contracts, invoicing your clients, logging and approving expenses, and the CRM, Projects, and Cash & reconciliation modules. We don’t collect data for any purpose beyond operating the platform your business configured — we don’t sell it, and we don’t use it to advertise to you or your employees.
4. How we use AI
Several DashPoint features use AI models (provided by Anthropic) to read and structure information you choose to submit:
- The onboarding Excel import reads a sample of your spreadsheet’s column headers and a few sample rows to work out which columns are which — it does not read every row of your data through the AI model, only enough to propose a mapping, which you review before anything is imported.
- Receipt scanning, bank statement import, and the AI inbox read the document or email you submit to extract structured data (amounts, dates, vendors) for your review before it’s saved.
- Ask DashPoint and the morning brief read data already in your account (via the same permissions your own login has) to answer questions or summarise what’s happened.
In every case, this means some of the content you submit is sent to Anthropic’s API to be processed. We don’t use your data to train AI models, and each request is scoped to your business’s own data — nothing from your account is used to answer another business’s questions.
5. Who we share it with
We use a small number of third-party providers to run DashPoint, each of which processes data strictly to provide their part of the service, not for their own purposes:
- Supabase — hosts our database, authentication, and file storage.
- Resend — sends transactional email on our behalf (invites, payslip notifications, invoice emails, password resets).
- Anthropic — processes the content described in Section 4 when you use an AI-powered feature.
We don’t sell personal data to anyone, and we don’t share it with third parties for their own marketing purposes.
6. International transfers
Because Supabase, Resend, and Anthropic all operate outside Botswana, using DashPoint means your data — including employee personal data — is processed on servers outside the country. Each of these providers maintains its own security and data protection commitments; we choose providers with strong security practices and only send them the data each specific feature actually needs.
7. How long we keep it
We keep your data for as long as your account is active. If your business deletes its workspace, the account is deactivated immediately and permanently deleted after a 30-day grace period — giving you a window to change your mind before the deletion is final. After that window, the deletion is permanent and cannot be undone.
8. Your rights
As the business account holder, you can access, correct, or export most of your data directly within DashPoint, and you can permanently delete your workspace at any time from Settings → Billing. If your business needs to correct or remove an individual employee’s record specifically, your HR administrator can do that directly in the HR module. If you’re an employee and want to see what your employer has stored about you in DashPoint, that request should go to your employer first, since they control the account — DashPoint can assist them in fulfilling it.
9. Security
Every business’s data is isolated at the database level, so one tenant’s data is never visible to another, even in the event of a bug elsewhere in the application. DashPoint keeps an append-only audit trail of significant actions taken in your account, so changes can be traced after the fact.
10. Cookies
DashPoint uses only the cookies necessary to keep you signed in. We don’t use advertising or tracking cookies, and we don’t run any third-party analytics on this site.
11. Children’s data
DashPoint is a business tool for companies and their adult employees. It isn’t directed at children, and we don’t knowingly collect data about them.
12. Changes to this policy
If we make a material change to how we handle data, we’ll update the date at the top of this page and, where the change is significant, let account owners know directly.
13. Contact us
Questions about this policy or how your data is handled can be sent to info@dashpointanalytics.co.bw.