ProAI
Services Solutions Process Pricing FAQ Book a call

Legal

Privacy Policy

Aligned with the Protection of Personal Information Act, 4 of 2013 (POPIA) · Last updated: 6 July 2026 · Effective from: 6 July 2026

Contents Overview Information Officer Information we collect Lawful basis How we use it Sharing & subprocessors Cross-border transfers Retention Your POPIA rights Cookies Security Changes Regulator Contact

This Privacy Policy explains how PROAI (Pty) Ltd (“ProAI”, “we”, “us”) collects, uses, shares, and protects personal information (“Personal Information”) in the course of running its business. It is aligned with the Protection of Personal Information Act, 4 of 2013 (“POPIA”).

In short. We collect only the information we need to run the business and deliver our services. We do not sell your information. We do not use client data to train third-party AI models. We keep information only for as long as we need to. You have rights under POPIA and we make it easy to exercise them.

Overview

ProAI is a Responsible Party under POPIA for Personal Information relating to:

  • Visitors to proai.co.za;
  • Prospective clients who enquire through the site, WhatsApp, or email;
  • Clients who commission ProAI to deliver services;
  • Suppliers and other counterparties.

Where we process Personal Information on a Client’s behalf as part of an engagement — for example, personal information contained in a Client’s customer database that is fed into a tool we build — we act as an Operator for the Client (the Responsible Party) and process that information under the terms of a written data-processing agreement.

Information Officer

The Information Officer for ProAI is:

  • Name: Gerrit Johannes de Villiers
  • Role: Director, PROAI (Pty) Ltd
  • Email: gerrit@proai.co.za
  • Postal address: 5 Richelieu Street, Coutrai, Paarl, Western Cape, 7646, South Africa

The Information Officer is registered with the Information Regulator of South Africa.

Personal Information we collect

Site visitors

When you visit our website, we collect:

  • Log data automatically collected by our hosting provider — IP address, browser type, pages visited, timestamps, and referring URL. This is used for security, diagnostics, and understanding aggregate site usage.
  • Basic analytics where enabled — anonymised page views and traffic sources. We do not use invasive tracking.

Prospective clients (enquiry form and email)

When you submit the enquiry form, WhatsApp us, or email us, we collect:

  • Name;
  • Company or organisation name;
  • Email address;
  • Phone number (optional);
  • The description of your requirement that you send us.

Clients (during and after engagements)

When you become a client, we additionally collect:

  • Contact details of your team members and stakeholders involved in the engagement;
  • Billing details required to invoice you;
  • Access credentials for the systems the Deliverables integrate with (stored securely and used only for the engagement);
  • Any Personal Information you provide to be processed as part of the Deliverables (this is handled under a separate data-processing agreement, where applicable).

Special Personal Information

ProAI does not intentionally collect Special Personal Information (as defined in POPIA) or information relating to children. If you must share such information for a legitimate business purpose, we will handle it in accordance with POPIA and any additional agreement between us.

Lawful basis for processing

We process Personal Information on the following lawful bases under POPIA:

  • Consent — where you have voluntarily provided information (for example, submitting an enquiry form).
  • Contract — where processing is necessary to enter into or perform a contract with you (for example, delivering services to a client).
  • Legal obligation — where processing is required by law (for example, retaining tax records under the Tax Administration Act).
  • Legitimate interests — where processing is necessary for the legitimate interests of ProAI or a third party, provided those interests are not overridden by your rights (for example, securing our website against attack).

How we use your Personal Information

We use Personal Information to:

  • Respond to enquiries and set up discovery calls;
  • Prepare written proposals and quotes;
  • Deliver the Services you have engaged us to perform;
  • Invoice you and receive payment;
  • Communicate with you about live engagements, including progress updates and support;
  • Comply with legal, tax, and accounting obligations;
  • Secure our systems and prevent fraud;
  • Improve our services (based on aggregated, non-identifying analysis).

We do not use your Personal Information for direct marketing without your prior consent, and any marketing email we send will include an easy way to opt out.

Sharing and subprocessors

We do not sell your Personal Information. We share it only with:

  • Subprocessors — trusted third parties that help us deliver our services. These include email and calendar providers (Google Workspace or Microsoft 365), accounting software (Xero or Sage), payment gateways where you pay by card, and cloud infrastructure providers used to host Deliverables. Each subprocessor is bound by contract to protect Personal Information consistent with POPIA.
  • AI model providers — where a Deliverable uses AI models (for example, Anthropic or OpenAI), Personal Information may be sent to those providers in the course of processing prompts. We select providers who commit not to train their models on our clients’ data by default.
  • Professional advisors — our accountants and legal advisors, under strict confidentiality obligations.
  • Regulators or law enforcement — where we are legally required to disclose.
  • Successor entities — in the event of a corporate reorganisation, sale, or merger, subject to appropriate protections.

A current list of key subprocessors is available on request to the Information Officer.

Cross-border transfers

Some of our subprocessors and AI model providers process Personal Information outside South Africa — typically in the European Union, United Kingdom, or United States. Where this happens, we rely on one or more of the transfer mechanisms permitted by section 72 of POPIA, including that:

  • The recipient is subject to a law, binding corporate rules, or binding agreement that provides an adequate level of protection; or
  • The transfer is necessary for the performance of a contract with the data subject or for their benefit; or
  • The data subject has consented to the transfer.

Where a specific engagement requires South African data residency, we will host the affected Deliverable(s) in a South African region and select subprocessors accordingly. This will be recorded in the applicable Proposal and data-processing agreement.

Retention

We keep Personal Information only for as long as we need it for the purpose it was collected, or as required by law. Typical retention periods:

CategoryRetention
Enquiry form submissions that do not become clients12 months, then deleted
Discovery call notes and unaccepted proposals24 months
Client project records and correspondence7 years after end of engagement (aligns with prescription and tax record-keeping requirements)
Financial and tax records5 years minimum under the Tax Administration Act, 28 of 2011
Website server logs90 days

After the applicable retention period, Personal Information is securely deleted or anonymised.

Your rights under POPIA

You have the following rights in respect of Personal Information we hold about you:

  • Right of access — to confirm what Personal Information we hold and receive a copy;
  • Right to correction — to have inaccurate or incomplete Personal Information corrected;
  • Right to deletion — to have Personal Information deleted where it is no longer needed for the purpose it was collected, subject to any legal retention obligations;
  • Right to object — to object to the processing of your Personal Information on reasonable grounds;
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal;
  • Right to complain — to the Information Regulator of South Africa if you believe we have not handled your Personal Information properly.

To exercise any of these rights, contact the Information Officer at gerrit@proai.co.za. We will respond within 30 days.

Cookies and tracking

This website uses only the cookies strictly necessary to deliver the site and, where enabled, a first-party or privacy-preserving analytics cookie to understand aggregate usage. We do not use invasive advertising or cross-site tracking cookies. If you prefer, most browsers let you block or clear cookies through their settings without preventing the site from functioning.

Security

We use reasonable technical and organisational measures to protect Personal Information against loss, unauthorised access, alteration, or disclosure. These include:

  • Encryption of information in transit (TLS) and at rest where technically feasible;
  • Access controls and least-privilege permissions on internal systems;
  • Multi-factor authentication on administrative and cloud accounts;
  • Regular review of subprocessor security postures and contracts;
  • Secure deletion of information at the end of its retention period.

No system is perfectly secure. In the unlikely event of a security compromise involving Personal Information, we will notify affected individuals and the Information Regulator as required by section 22 of POPIA.

Changes to this Policy

We may update this Policy from time to time. The current version is always published at proai.co.za/privacy.html with the effective date noted at the top. Where a change is material, we will notify current clients by email in advance of the change taking effect.

Information Regulator

You may lodge a complaint with the Information Regulator of South Africa:

  • Website: inforegulator.org.za
  • Complaints email: POPIAComplaints@inforegulator.org.za
  • Postal address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Contact us

Privacy queries and requests to exercise POPIA rights:

  • Email: gerrit@proai.co.za
  • Postal address: PROAI (Pty) Ltd, 5 Richelieu Street, Coutrai, Paarl, Western Cape, 7646, South Africa
  • Company registration: 2022/343301/07
  • VAT number: 4100322660

Privacy questions or a data request?

The Information Officer replies to every POPIA request personally, within 30 days.

Email the Information Officer
ProAI

Custom AI apps, conversational assistants, and workflow automation for South African SMEs. Built to ship, not to demo.

Company Services Solutions Process Governance FAQ
Legal Pricing Terms of Service Refund & Cancellation Privacy (POPIA)
Talk to us gerrit@proai.co.za WhatsApp Book a discovery call
© 2026 PROAI (Pty) Ltd · Reg 2022/343301/07 · VAT 4100322660 · Paarl, Western Cape Built with responsible AI