Who we are
Randcore Development (Pty) Ltd, Johannesburg. We build websites, software and the Core products. Under POPIA we are the “responsible party” for the information on this page. The person who answers about it is our Information Officer, reachable at the address on the right.
What we collect
Only what the thing you’re using needs.
- Website and contact form: name, email, company, what you wrote. Nothing else. No tracking pixels, no fingerprinting.
- Core Platform and Core PDF accounts: your name, email, business name, billing details, and the data you put in (invoices, stock, documents). That data is yours; we are the processor.
- Support: what you send us to fix the problem, including screenshots if you attach them.
- Newsletter: your email address. We don’t track whether you opened it.
What we don’t do
We don’t sell information. We don’t share it with advertisers. We don’t combine it with data bought elsewhere. We don’t read your documents or your books unless you ask us to while fixing something, and then only that.
Cora
Cora reads only the document or business you point it at, only while you use it. Nothing you ask is used to train a model. Answers are generated on servers in South Africa or the EU; nothing is kept after the answer is shown.
Where it lives
Core data is stored on servers in Johannesburg. Backups are encrypted and kept for 30 days. Email goes through a South African provider. If we ever move any of this, we’ll say so here first.
How long
Account data: while you have an account, then 90 days, then gone. Invoices we issued you: five years, because SARS says so. Contact-form messages: a year. Newsletter: until you unsubscribe, which is one click.
Your rights
Ask, and we’ll show you what we hold, correct it, export it in a format anyone can open, or delete it. One email. No forms, no proof-of-identity theatre beyond confirming it’s your address. We reply within a working day and finish within ten.
Cookies
One, to keep you signed in to Core. None on this website. There is no banner because there is nothing to consent to.
If something goes wrong
If your data is exposed, we tell you within 72 hours, in plain words, with what happened and what to do. We also tell the Information Regulator. We don’t wait for a lawyer to soften it.