Trust
DDM Flow holds invoice, payment and bank data for the businesses that use it. Here is where that data lives and how it's protected.
Data residency
All customer data is stored in our primary Supabase Postgres database, hosted in the European Union. Our other processors — Vercel, Resend, Paystack, Yoco, Anthropic, Sentry, PostHog and Plain — also operate outside South Africa. We rely on the standard contractual safeguards those providers publish for cross-border transfers, as set out in our Privacy Policy.
Encryption
- In transit: HTTPS only on ddmflow.com, with HTTP Strict Transport Security.
- At rest: the database and file storage are encrypted (AES-256) by Supabase.
- Platform secrets, such as payment provider keys, are kept in Vercel's encrypted environment variables. API keys you create are stored only as a hash.
Access controls
- Postgres Row-Level Security is enabled on every table, so a signed-in user's database requests only reach the workspaces they belong to.
- Roles (Owner, Bookkeeper, Accountant, Viewer) control what each member can change within a workspace.
Backups
The production database runs on Supabase's Pro plan, which takes daily backups. Point-in-time recovery is not enabled yet, and we have not yet tested a restore; this section will say so once both are done.
Compliance
- POPIA (South Africa): how we process personal information is set out in our Privacy Policy and our PAIA manual.
- Workspace owners can export their data and delete their account from Settings.
Incident response
Application errors are reported to Sentry. If we have reasonable grounds to believe personal information has been accessed or acquired without authorisation, we notify affected workspace owners immediately, as section 21(2) of POPIA requires and as our Data Processing Agreement states.
Get in touch
For security disclosures, compliance questions, or a signed Data Processing Agreement, email security@ddmtech.co.za.