Privacy Policy

How Parama Solutions collects, uses, shares, and deletes personal information across our websites, applications, and services.

Last updated: 30 July 2026

1. Who we are

This Privacy Policy is issued by Parama Solutions (Pty) Ltd ("Parama Solutions", "we", "us", or "our"), a company incorporated in the Republic of South Africa. It applies to:

  • Our corporate website at paramasolutions.co.za
  • Our portfolio products and applications, including BoostMyCV.co, DokiSnap.com, Book4U.app, and related web, mobile, and business portals (collectively, the "Services")
  • Our Meta developer applications and integrations (including WhatsApp Business Platform / Embedded Signup used to help business customers connect messaging channels)
  • Payment and subscription flows processed through Paystack on our behalf

We are the responsible party (data controller) for personal information we collect for our own business purposes. Where a business customer uses our Services to process their end customers' data, that business is typically the responsible party and we act as an operator (data processor) under their instructions, except where we process data for our own account (billing, security, product improvement, legal compliance).

This policy is maintained at a publicly accessible, non-geo-blocked HTTPS URL and is intended to be crawlable by Meta and other reviewers.

2. Scope and Meta Platform compliance

As a Meta developer / WhatsApp solution provider (or tech provider, as applicable), we comply with Meta's Platform Terms, Developer Policies, and Developer Data Use Policy. In particular:

  • We use Meta Platform Data only for the purposes described in this policy and permitted by Meta
  • We do not sell Meta user data
  • We do not use Meta Platform Data to build user profiles for advertising unrelated to the Services the user authorised
  • We provide clear instructions for users to request deletion of their data (see Data Deletion and Section 11)
  • We honour data deletion requests for Meta Platform Data unless applicable law requires retention

3. Information we collect

3.1 Information you provide

  • Identity and contact details: name, email address, phone number, company name, job title
  • Account details: username, password (stored hashed), profile preferences, business profile information
  • Inquiry and support content: messages submitted via contact forms, support tickets, or email
  • Product content: depending on the Service — e.g. CV/resume content (BoostMyCV), documents and signatures (DokiSnap), booking details, customer contact records, and business configuration (Book4U)
  • Billing details: billing name, email, business address, VAT/tax identifiers where required (we do not store full card numbers)

3.2 Payment information (Paystack)

When you pay for subscriptions or services, payments are processed by Paystack (a Stripe company). Paystack may receive personal information such as your name, email address, phone number, payment method details, transaction amount, currency, and fraud-prevention signals. Card and bank details are handled by Paystack under their PCI-DSS compliant processes. We receive payment status, reference/transaction IDs, and limited billing metadata needed to activate or reconcile your subscription — we do not store complete card numbers on our servers.

Paystack acts as a payment service provider / data processor for transaction processing. See Paystack's privacy documentation for how they process merchant and customer data.

3.3 Meta / WhatsApp platform information

If you or your business connects Meta or WhatsApp through our Services (for example via Embedded Signup), we may process:

  • Business account identifiers (e.g. WhatsApp Business Account ID, phone number ID, Meta business / asset IDs)
  • Business display name and linked phone numbers
  • Messaging metadata and message content necessary to deliver the messaging features you enable (send/receive messages, templates, webhooks, delivery status)
  • Authorisation tokens and permissions granted during signup or OAuth-style consent flows
  • Technical identifiers related to the connection (e.g. app-scoped user IDs where provided by Meta)

We only request Meta permissions needed to provide the authorised Service. End-user message content is processed to operate messaging on behalf of the connected business customer and is not sold.

3.4 Information collected automatically

  • IP address, approximate location derived from IP, and timestamps
  • Browser type, device type, operating system, and language settings
  • Pages viewed, referring URLs, and usage/diagnostic logs
  • Cookies, local storage, and similar technologies used for session and security

4. How we use information (purposes)

We process personal information to:

  • Provide, operate, secure, and improve the Services
  • Create and manage user and business accounts
  • Respond to inquiries, support requests, and partnership discussions
  • Process subscriptions and payments via Paystack and manage billing lifecycle events
  • Enable Meta/WhatsApp onboarding and messaging features that businesses explicitly connect
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Comply with legal, tax, accounting, and regulatory obligations (including POPIA)
  • Send service notices; send marketing only where permitted and with a clear opt-out
  • Analyse aggregated or de-identified usage to improve product performance

5. Legal bases (POPIA and similar laws)

Depending on the context, we rely on one or more of the following:

  • Performance of a contract or steps prior to entering a contract
  • Legitimate interests (security, product improvement, preventing abuse), balanced against your rights
  • Consent, where required (e.g. certain marketing or optional integrations)
  • Compliance with a legal obligation

6. Sharing and disclosure

We may share personal information with:

  • Paystack — to process payments and prevent payment fraud
  • Meta Platforms — when you connect Meta/WhatsApp features; Meta processes data under its own terms and policies
  • Infrastructure and operations providers — cloud hosting, email delivery, analytics, error monitoring, and customer support tooling, under contractual confidentiality and security obligations
  • Professional advisers — lawyers, auditors, or accountants where needed
  • Authorities — when required by law, legal process, or to protect rights, safety, and security
  • Business transfers — in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards

We do not sell personal information.

7. International transfers

Our Services may be hosted or supported using infrastructure located outside South Africa. Where we transfer personal information internationally, we take steps consistent with applicable law (including POPIA) to protect that information, such as contractual safeguards with processors.

8. Retention

We retain personal information only as long as needed for the purposes described above, including to provide the Services, resolve disputes, enforce agreements, and meet legal retention requirements (for example, tax and financial record-keeping). Message and operational logs may be retained for shorter security and troubleshooting windows unless a longer period is required. When no longer needed, we delete or anonymise data where reasonably practicable.

9. Security

We implement appropriate technical and organisational measures, including encryption in transit (HTTPS), access controls, least-privilege practices, and monitoring. No method of transmission or storage is completely secure; we work to reduce risk but cannot guarantee absolute security.

10. Your rights

Under POPIA and, where applicable, other data protection laws, you may have the right to:

  • Be informed about how your personal information is processed
  • Access personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion / destruction of personal information (subject to legal limits)
  • Object to or request restriction of certain processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Information Regulator (South Africa) or another competent authority

To exercise these rights, email privacy@paramasolutions.co.za with the subject line "Data Subject Request". We may need to verify your identity before acting. We aim to acknowledge requests promptly and respond within a reasonable period (typically within 30 days, or sooner where Meta or other platform rules require faster action for Platform Data).

11. How to request deletion of your data

You can request deletion of your account and associated personal information — including Meta Platform Data we hold — at any time.

Step-by-step instructions:

  1. Send an email to privacy@paramasolutions.co.za from the email address associated with your account (or identify the relevant business account).
  2. Use the subject line: Data Deletion Request.
  3. Include: your full name, the Service/product used (e.g. Book4U, BoostMyCV, DokiSnap, or this website), and any account or business identifiers you have (email, tenant/business name, WhatsApp phone number if applicable).
  4. We will confirm receipt, verify your identity, and delete or anonymise personal information and Meta Platform Data we control, except where retention is required by law (e.g. transaction records) or needed to complete ongoing disputes/security investigations.
  5. Where your Meta connection must also be disconnected in Meta Business settings, we will advise you of any steps you should take on Meta's side.

Dedicated instructions page (for Meta App Dashboard "User Data Deletion" URL): https://paramasolutions.co.za/data-deletion

12. Cookies

We use essential cookies and similar technologies for authentication, security, and basic site function. Where we use non-essential analytics cookies, we do so in line with applicable requirements and provide controls where feasible. You can control cookies through your browser settings; disabling some cookies may affect Service functionality.

13. Children

Our Services are directed to adults and businesses. We do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact privacy@paramasolutions.co.za and we will take appropriate steps to delete it.

14. Third-party sites and product-specific notices

Our websites may link to third-party sites. Their privacy practices are governed by their own policies. Individual portfolio products may also publish supplemental notices for product-specific features; if there is a conflict on a product-specific point, the more specific notice applies to that product, while this policy remains the company-level statement for Meta and payment reviews.

15. Changes

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated via the Services or email where appropriate. Continued use after an update constitutes acceptance of the revised policy where permitted by law.

16. Contact

Parama Solutions (Pty) Ltd
Privacy requests: privacy@paramasolutions.co.za
Website: https://paramasolutions.co.za
Contact form: paramasolutions.co.za/#contact

South Africa Information Regulator: inforegulator.org.za