Privacy notice (draft)

VST- POS / Ariestotle. Last working copy: 4 September 2026.

DRAFT — not legal advice. These pages are working copy for VST Services and the licensed shop. An attorney must review and finalise them before they are treated as a contract, a POPIA notice, or a data processing agreement.

1. Two layers of personal information

Shop data (customers, sales, staff logins, till activity) is processed by the shop as responsible party. VST does not become the shop’s information officer by supplying the software.

VST data is limited to what is needed to license, support and bill: company name, installation identifiers, licence edition and seats, named Super Admin contact, and ticket content the shop sends.

2. Why VST processes shop-related data

  • Issue and verify a signed licence token.
  • Count concurrent seats as licensed. Staff browsers must be allowed before they can sign in. Super Admin may sign in from any browser. Devices are not sold as a count cap.
  • Respond to a support ticket the shop opened.
  • Restore from a backup the shop uploaded or that a technician handled on-site, only for that job.

3. What VST does not do by default

VST does not remotely browse the live till database as a standing service. Remote access, if any, is for a booked support or go-live job and should be ended when that job ends.

4. Shop duties

The shop must set an information officer in Privacy settings, handle customer access and deletion requests, and configure SMTP if it emails quotes or invoices. Document templates and VAT wording are the shop’s responsibility.

5. Retention

Licence and billing records are kept for the commercial relationship and lawful tax periods. Ticket attachments should be kept only as long as needed to close the job. Exact periods must be confirmed by the attorney and the shop’s retention policy.