What information XtendaCore stores
XtendaCore stores account details, authentication records, tenant and cell membership, business configuration, operational records entered by tenants and users, audit history, privacy case records, and documents that users upload or route into the platform.
How XtendaCore uses information
Information is used to provide the platform, keep tenant records separated, process documents, support secure downloads, run audit and governance workflows, respond to privacy requests, and investigate privacy or security concerns.
Who owns and controls platform information
XtendaCore is responsible for operating the platform and protecting platform-managed information. Tenants remain responsible for the business records and instructions they create, approve, upload, correct, or retain inside their own tenant context.
Tenant access to platform information
Tenant users can access only the tenant areas and records their roles allow. Privacy and incident administration views use tenant-scoped services and permission checks before case lists, case details, evidence, or reports are shown.
Tenant and user data separation
Tenant identifiers, user assignments, role permissions, and active context checks are used to keep tenant data and user-facing profile information separate. A user profile can show a user's own submitted privacy requests, but it does not expose other users' or other tenants' case queues.
How uploaded documents are quarantined
Uploaded PDFs and document intake files enter an intake holding flow before tenant-facing download or processing. The platform validates document state before exposing controlled downloads.
Microsoft Defender malware scanning
Document intake is designed to run malware scanning before accepted documents move forward. Scan results are recorded for operational review and unsafe files remain out of normal user download flows.
Canonical PDF reconstruction and validation
Where secure PDF intake is used, XtendaCore rebuilds accepted PDFs into canonical platform copies and validates those copies before they are made available through controlled document delivery.
Secure invoice, scanner, OCR and AI processing
Invoice uploads, scanner intake, Gmail PDF intake, OCR, and AI extraction use the secure document intake pipeline before extracted results are presented for review. Automation assists with reading documents; it does not replace tenant review or approval.
Human review and correction
People remain responsible for checking extracted content, correcting mistakes, and deciding whether a document or case outcome is ready to use. Corrections and decisions are recorded in the relevant workflow.
Gmail PDF intake and no-redownload tracking
Gmail PDF intake records message and attachment processing markers so previously handled PDFs are not downloaded repeatedly in normal operation.
Document storage and secure downloads
Documents are served through controlled routes that check tenant context, permissions, and document status. Public pages do not expose storage locations or direct file-system paths.
Retention and secure deletion
Retention and deletion are handled through controlled tenant and platform processes. Deletion requests are reviewed because legal, accounting, dispute, security, or operational obligations may require some records to be kept for a period.
Access controls and audit history
Role-based permissions, tenant context checks, row-version checks, and privacy audit events are used across privacy operations so access and changes can be reviewed.
Privacy requests, access and correction
Signed-in users can submit access, correction, deletion, objection, complaint, and related privacy requests. Requests enter the data-subject request workflow for the selected tenant or platform context and may require identity verification before personal information is disclosed.
Reporting privacy/security incidents
Privacy complaints and security concerns are routed separately from general support. Reports enter the privacy incident workflow so authorised staff can triage, assess, contain, decide on notifications, recover, and document outcomes.
Cookies, authentication and session security
XtendaCore uses cookies and session state to sign users in, keep the correct tenant context active, and protect authenticated workflows. Keep your credentials private and sign out on shared devices.
Suppliers, processors and international processing
Some platform services may depend on infrastructure, email, security, OCR, AI, or support suppliers. Where information is processed by a supplier or outside the user's country, XtendaCore treats that as part of supplier and privacy governance rather than as a guarantee of any specific legal status.
Children and sensitive information
XtendaCore should not be used to add children's information or sensitive information unless the tenant has a lawful reason, appropriate permissions, and suitable controls for that specific use. The platform records relevant flags where privacy incident or profile workflows need them.
Contacting XtendaCore about privacy
Use the signed-in privacy request route for access, correction, deletion, objection, or complaints. Use the incident report route for suspected unauthorised access, malware, accidental disclosure, lost devices, misdirected communications, or similar security concerns. Use normal support channels for product help that is not a privacy request or security incident.
Limitations
This centre is not legal advice, a legal certification, a guarantee of security, or a promise that using XtendaCore automatically makes a tenant POPIA compliant. Tenants should review their own obligations, notices, lawful bases, contracts, access permissions, and retention choices.