What we do with your data
You paste in keys and route your business through us, so you are owed a straight answer about what we hold, why we hold it, who else touches it, and how to make us stop. That is what this page is. The engineering behind it is on the security page.
Last updated: 3 September 2026. If we change something that matters, we will tell you before it takes effect.
1. Who we are, and which hat we are wearing
COWE is operated by COWE Operations Inc. Under POPIA we are the responsible party for our own business records, and under the GDPR we are the controller of them. That covers your account, your billing, and the logs our servers keep.
For everything you run through COWE — the invoices, the customer records, the messages your workflows touch — the position reverses. You decide what goes in and why; we only act on your instructions. There you are the responsible party (controller) and we are the operator under POPIA and the processor under the GDPR. It matters because the people whose data it is come to you first, and we are obliged to help you answer them.
Our designated Information Officer is reachable at privacy@coweserv.co.za. Write there for anything on this page.
2. What we hold
Your account. Name, work email, the organisation you belong to, and your role in it. Sign-in itself runs through your identity provider — we never see or store a password.
Billing. Your plan, invoices, and a ledger of the credits your workflows consume. We never see your card. Card details go straight to the payment provider you choose; what comes back to us is a reference and a result.
Credentials you connect. The API keys you paste in for Xero, Slack, Microsoft 365 and the rest. Encrypted with a key scoped to your organisation, and decrypted only in memory for the moment a step needs one.
Workflow content. The diagrams you build, the runs they produce, and the variables carried through them — which is whatever your process happens to move. We do not choose what that is; you do.
Operational records. An audit trail of what ran and when, plus server logs and error reports. Personal details in audit messages are masked by default before they are written.
3. Why we are allowed to hold it
POPIA (section 11) and the GDPR (Article 6) both require a reason. Ours are:
- To give you the service you asked for — running your workflows, keeping your account, taking payment. Contractual necessity.
- To keep the platform standing — security monitoring, abuse prevention, capacity, fraud checks. Our legitimate interest, and yours; we have weighed it against your privacy and kept the data minimal.
- To meet obligations we cannot decline — tax, accounting, and lawful requests properly made.
- Consent, where we ask for it. Marketing email is the main one, and you can withdraw it at any time without losing the service.
For workflow content we act on your instruction, not our own reason. Establishing a lawful basis for that data is yours to do.
4. Who else touches it
We do not sell your data, and we do not share it for anyone else's advertising. A short list of suppliers helps us run the service, each under contract and each limited to what their job needs:
- Hosting and infrastructure — the servers and managed databases the platform runs on.
- Paystack, Stripe and Peach Payments — whichever rail you buy on. They take the card; we do not.
- SendGrid — the emails the platform sends you, such as an approval waiting or a credit balance running low.
- Zitadel — the identity provider behind sign-in.
- OpenAI — only when you use an AI feature, and only with what that request needs.
The current list, with what each one is for, is available on request; Enterprise customers get it with a Data Processing Addendum. Beyond that we disclose data only where the law obliges us, and we will tell you when we are permitted to.
Two things load from Google on this website: the fonts, and the small logos on our apps page. Your browser fetches those directly, so Google sees the request. There are no analytics, no advertising pixels and no tracking cookies anywhere on this site — the only cookie we set remembers whether you chose light or dark.
5. Where it goes
Some of those suppliers operate outside South Africa and outside the EEA. POPIA (section 72) and the GDPR (Chapter V) both allow that only under conditions, so transfers rest on one of: a country the European Commission has judged adequate, the EU Standard Contractual Clauses, or a binding contract giving the data protection the law requires here.
If where your data physically sits is not negotiable, Enterprise plans can run in a dedicated environment in a region you choose, or entirely on your own infrastructure. Ask us before you buy, not after.
6. How long we keep it
Run history is kept for as long as your plan says and then deleted automatically — 30 days on Starter, 90 on Pro, 365 on Enterprise. Deletion takes the whole run with it: the audit trail, the step metrics, the approvals.
Two things outlive that on purpose. Billing records are kept for as long as tax and company law require, because they are accounting records rather than operational data. And your account itself stays until you close it.
Close your account and we delete or anonymise what we hold within 90 days, excepting anything we are legally obliged to keep. If you use your own encryption key, you can revoke it and make your encrypted history permanently unreadable — including to us — without waiting for us to do anything.
7. What you can ask us for
POPIA (sections 23 to 25) and the GDPR (Articles 15 to 22) give you rights over your own data. In practice you can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct or complete it if it is wrong.
- Delete it, where we have no overriding obligation to keep it. Where an obligation does apply — an audit trail, a FICA record — we remove the details that identify you and keep only the record itself, and we tell you which obligation applied.
- Pause what we do with it while a dispute is being sorted out.
- Hand it over in a portable format, or send it to someone else.
- Object to processing we justify by legitimate interest.
- Not be subject to a decision made purely by a machine where it has a legal or similarly significant effect on you.
Write to the Information Officer. We answer within 30 days and it costs nothing unless a request is repetitive or excessive, in which case we will say so before doing anything. If the data is workflow content belonging to one of our customers, we will point you to them and help them respond.
We do not use your data for automated decisions with legal effect. Our AI features act on what you send them, when you ask.
One limit worth stating plainly: this covers the records we hold as responsible party — your account, its activity, and our logs. It does not cover data inside a workflow run by a business that uses COWE. There, that business decides what is collected and why, and the request belongs to them. Tell us and we will point you to them and help them answer it.
8. Marketing
Service email — an approval waiting, an invoice, a warning that credits are running out — is part of the product and cannot be turned off while you have an account.
Marketing email is different. POPIA section 69 requires consent for electronic marketing to someone who is not already a customer, and we treat that as the standard for everyone. One unsubscribe link, honoured on every message, and nothing you lose by using it.
9. If something goes wrong
If personal data is breached, we notify the Information Regulator and the affected people as soon as reasonably possible, as POPIA section 22 requires. Where the GDPR applies we notify the lead supervisory authority within 72 hours of becoming aware, and tell affected people directly when the risk to them is high.
If the breach touches data you process through COWE, we tell you without undue delay so you can meet your own obligations — with what we know, plainly, including the parts we do not yet know.
10. Children
COWE is a tool for businesses and is not offered to children. We do not knowingly collect data about anyone under 18. If you believe a child's data has reached us, tell the Information Officer and we will remove it.
11. If you are not satisfied
Come to us first — most things are quicker to fix than to escalate. But you do not need our permission to complain, and you can go straight to a regulator if you prefer.
South Africa: the Information Regulator, at inforegulator.org.za.
EU / EEA / UK: your national supervisory authority, wherever you live or work.