Legal
Privacy Policy
Last updated: September 2026
1.Introduction and Compliance Framework
This Privacy Policy outlines how Mycelium Frameworks (Pty) Ltd, trading as Dhora ("the Company", "we", "us", or "our") collects, processes, stores, and protects personal and corporate data. As a South African registered entity, we operate under strict compliance with the Protection of Personal Information Act, No. 4 of 2013 (POPIA), and align our data transmission standards with global fintech partner networks.
2.Information We Collect
To provision virtual financial infrastructure and maintain compliance with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations, we collect:
- Personal Identifiers: Full name, national identity number, passport details, and physical residential or operating address.
- Corporate Records: CIPC registration data, SARS tax identification details, and corporate transactional bank statements.
- Technical Data: IP addresses, login parameters, and device configurations used to access our self-service dashboard API.
- Card & Transaction Data: Dedicated virtual card ledger activity, transaction amounts, merchant category codes (MCC), and billing histories.
3.How We Use Your Data
Your personal and transaction data is strictly utilized to:
- Programmatically provision, fund, and manage your virtual USD payment cards.
- Authenticate account access and authorize secure API token requests.
- Prevent, identify, and mitigate fraudulent financial activity, payment declines, and unauthorized cross-border structuring.
- Transmit necessary data securely to upstream financial infrastructure providers (such as Raenest/Geegpay) to facilitate global card settlement networks.
4.Data Sharing and International Transfers
We do not sell, rent, or trade your data to third-party marketing networks. To execute international virtual card payments, data is securely transferred via encrypted server-to-server API channels to our global banking partners. By utilizing our dashboard, you explicitly consent to the cross-border processing of ledger balances required for global web clearing.
5.Security and Retention
All data is stored utilizing bank-grade 256-bit encryption protocols. Server keys and credentials are restricted via absolute server-side execution. In compliance with AML statutory periods, financial transactional records will be retained securely for a minimum period of 5 (five) years from the date of account termination.
Data inquiries & your POPIA rights
To invoke your rights under POPIA or raise a data inquiry, contact our compliance officer: