Privacy Policy

How we collect, use, store and protect your personal information — aligned to the Protection of Personal Information Act (POPIA) and the EU General Data Protection Regulation (GDPR).

Version 2.2Effective 11 May 2026Updated 26 July 2026POPIA · GDPR aligned
Effective Date:
Last Updated:
Version: 2.2

1. Who we are (Responsible Party / Controller)

SIYA MP Global Systems (Pty) Ltd, based in the Republic of South Africa, is the Responsible Party under POPIA and Data Controller under GDPR for personal information processed through this platform.

Privacy queries: privacy@siyampglobalsystems.co.za · General: info@siyampglobalsystems.co.za · +27 77 430 7645

2. Information we collect

  • Account: name, email, password hash, avatar, display preferences.
  • Profile & documents: optional CV, qualifications and certifications you upload to your Secure Documents Vault.
  • Communications: messages you send through Circles, support tickets, contact and quote forms.
  • AI interactions: prompts and responses; voice recordings when you use voice mode; shared screens when you enable screen analysis (processed transiently, not persisted).
  • Payment metadata: PayFast reference IDs, plan, amount, currency, status. We never receive or store your card number.
  • Technical: IP address, browser and device information, cookies, log events, usage analytics.

3. Lawful basis and purpose

  • Contract: to deliver the service you signed up for.
  • Legitimate interest: to secure the platform, prevent fraud and improve features.
  • Consent: for optional marketing, non-essential cookies, and voice/screen features you actively enable.
  • Legal obligation: for tax, accounting, and lawful requests by competent authorities.

4. Cookies and analytics

We use strictly necessary cookies (authentication, security) and a preferences cookie to remember your consent. Analytics cookies are only enabled after you accept them via our cookie banner. See our Cookie Policy.

5. Payment processing

All payments are processed by PayFast (DPO Payments (Pty) Ltd), a PCI-DSS Level 1 service provider. Card details are entered directly on PayFast's environment and never touch our infrastructure. We receive only transaction status metadata via PayFast's Instant Transaction Notification (ITN).

6. AI interactions

Prompts, files you attach and voice/screen inputs are sent to our AI providers strictly to generate the response you requested. We do not use your content to train third-party foundation models. Transcripts are retained in your account so you can review them; you can delete a conversation at any time.

7. Sharing and sub-processors

We share personal information only with sub-processors necessary to operate the service, under written data-processing agreements. Categories include: cloud hosting, database and authentication, AI model providers, PayFast (payments), email delivery, and error monitoring. A current list is available on request.

8. International transfers

Data may be processed outside South Africa or the EEA. Where this occurs we rely on adequacy decisions or Standard Contractual Clauses / equivalent safeguards.

9. Retention

  • Account data: for the life of your account plus 30 days after closure (see Cancellation Policy).
  • Transaction records: 5 years, as required by SARS and financial regulations.
  • Support tickets and Circles messages: up to 3 years unless you delete them earlier.
  • AI transcripts: until you delete the conversation or your account.

10. Your rights (POPIA & GDPR)

  • Access, correction and deletion of your personal information.
  • Data portability — export of your account data in a machine-readable format.
  • Objection to processing based on legitimate interest and to direct marketing.
  • Withdraw consent at any time for consent-based processing.
  • Lodge a complaint with the Information Regulator (South Africa) or your local supervisory authority (EU/UK).

To exercise these rights email privacy@siyampglobalsystems.co.za. We respond within 30 days.

11. Security

We use TLS in transit, encryption at rest for sensitive documents, row-level security on our database, role-based access controls, WebAuthn for admins, and continuous audit logging. No system is perfectly secure — please use a strong unique password and enable two-factor authentication where offered.

12. Children

The platform is not directed at children under 16. If you believe a child has provided us personal information, contact us and we will delete it.

13. Changes

Material changes to this policy are notified by email or in-app at least 14 days before they take effect.

Revision history

Each entry below corresponds to a recorded change to this document in the platform's version-control history. Previous versions are preserved in version control and can be produced for audit on request.

  1. Version 2.2Current
    Added Effective Date, Last Updated date, version number and revision history. No change to the substance of the policy.
  2. Version 2.1
    Canonical and og:url metadata added. No change to the policy.
    Reference: commit eb5ae05
  3. Version 2.0
    Expanded to a full POPIA and GDPR aligned policy: responsible party details, categories of information collected (including AI interactions and payment metadata), lawful bases, retention, sharing and data-subject rights.
    Reference: commit cdf183c
  4. Version 1.2
    Data-subject request address updated to info@siyampglobalsystems.co.za.
    Reference: commit ffcbff4
  5. Version 1.1
    Document title metadata corrected. No change to the policy.
    Reference: commit 35fbfc4
  6. Version 1.0
    Initial publication of the Privacy Policy.
    Reference: commit daa9267