STATUTORY DATA SOVEREIGNTY • POPIA ACT 4 OF 2013

100% In-Border POPIA Data Residency & Legal Compliance

This authoritative architecture brief details how XDew Books (operated by Governx Pty Ltd, Reg. No. 2026/475655/07) maintains strict statutory compliance with the Protection of Personal Information Act (POPIA Act 4 of 2013), guaranteeing 100% in-border sovereign hosting in Johannesburg, South Africa.

PRIMARY SOVEREIGNTY GUARANTEE

100% In-Border POPIA Data Residency (Johannesburg Azure Hubs)

All production databases, cryptographic ledger stores, employee payroll registers, and customer invoices are provisioned and maintained exclusively within Microsoft Azure South Africa North (Region: South Africa North, Location: Johannesburg). At no point are customer records, bank statements, or personal identifiable information (PII) replicated, cached, or transferred outside the sovereign borders of the Republic of South Africa.

Primary Cloud Datacenter Infrastructure:Microsoft Azure South Africa North (Johannesburg Region)
Verify Azure SA North Hub

Compliance with POPIA Section 14 and Section 72

Section 14: Retention and Restriction of Records

POPIA Section 14 mandates that personal financial records must not be retained any longer than necessary, except where authorized by law (e.g. Section 29 of the Tax Administration Act requires a 5-year retention period for SARS compliance). XDew Books enforces cryptographic data destruction policies once statutory retention periods expire, while maintaining strict audit trails.

Section 72: Transborder Flows of Personal Information

Section 72 prohibits South African organizations from transferring personal information to a foreign country unless the recipient is subject to laws upholding substantially similar data protection principles. Because competitors like Xero and QuickBooks store company records in the United States and Europe, users take on legal liability. By hosting 100% inside South Africa, XDew Books eliminates transborder transfer risks entirely.

Cryptographic Security & Data Protection Controls

AES-256-GCM Encryption at Rest

All production databases, documents, and backups are encrypted using military-grade AES-256-GCM encryption with automated key rotation.

TLS 1.3 Encryption in Transit

Every request between your browser, mobile application, and our API clusters is enforced over TLS 1.3 with Perfect Forward Secrecy.

Granular Role-Based Access (RBAC)

Strict multi-tenant cryptographic isolation ensures tenant workspaces cannot inspect or leak records across enterprise boundaries.

Information Officer Oversight

Governx (Pty) Ltd has a registered Information Officer with the Information Regulator of South Africa to oversee compliance.