Privacy Policy

How we handle personal information when you visit our website, contact us, work with us, receive WhatsApp notifications, or chat with a bot we run.

Last updated: 22 September 2026

1. Who we are

The Automators (Pty) Ltd, registration number 2025/800843/07 ("we", "us"), builds workflow automations, AI chatbots, voice agents and custom business systems.

  • Address: 1 Vergenoegd Bordeaux Estate, Ametis Street, Klerksdorp, North West, 2572, South Africa
  • Information Officer: Braam Raubenheimer
  • Privacy requests: braam@theautomators.co | +27 82 770 6456
  • Information Regulator registration: 2026-061974

2. What this policy covers

This policy explains how we handle personal information when you visit our website, contact us or book a call, when you or your organisation are a client, supplier or partner of ours, when you receive messages through our WhatsApp notification service, and when you chat with a bot we run for ourselves.

It follows the Protection of Personal Information Act 4 of 2013 (POPIA) and, where they apply, the EU and UK General Data Protection Regulations (GDPR). Under POPIA, information about companies and other organisations can also be personal information, so this policy covers it too.

When we work for a client, the client is in charge. If we build or run a system for a client, the client decides why and how the personal information in it is used. The client is the "responsible party" (the "controller" under GDPR) and we are its "operator" (its "processor"). Section 9 explains what we commit to in that role. If your information is in a system we run for one of our clients, please contact that client first. We will help them respond.

3. What we collect, and where it comes from

WhenWhat
You visit our websitePages viewed, device and browser type, approximate location from your IP address, collected through Google Analytics cookies
You contact us or book a callYour name, email address, phone number, organisation and role, your message, and your answers to the booking questions
You are a client, supplier or partnerContact details of the people we deal with, what we discuss and agree, proposals, contracts, invoices and payment records
You receive our WhatsApp notificationsYour WhatsApp number, the name or label you or our customer supplied, messages sent and received, your opt-in and opt-out choices, and delivery data such as timestamps and read receipts
You chat with our own botThe messages you send and any contact details you choose to give

Most of it comes from you. Some comes from your organisation (for example when a client names you as its contact), from public business sources such as your company's website, or from our customers when they ask us to send you WhatsApp notifications.

Giving us your information is voluntary. If you don't, we may not be able to reply to you, hold a call, deliver a service or pay you.

We don't ask for special personal information (such as health, religious beliefs, race, biometric data or criminal records) or identity numbers for our own purposes. Please don't send them to us.

4. Why we use it

PurposeBasis under POPIA section 11 (and GDPR article 6 where it applies)
Reply to enquiries and hold calls you bookYou asked us to, or it is a step towards a contract with you
Deliver, support and invoice our servicesPerformance of our contract with you or your organisation
Keep accounting and tax recordsLegal obligation
Understand how our website is used and improve itOur legitimate interest, and your consent to analytics cookies where the law requires it
Keep our systems and your information secureOur legitimate interest and legal obligations
Send WhatsApp notificationsYour consent, or the instruction of our customer who is responsible for them

We don't sell personal information. We don't use it to train our own artificial intelligence or machine learning models. Where a chat reply is generated for us, it may be produced by an AI model provider reached through OpenRouter, and we send only what is needed to produce that reply.

5. Direct marketing

We send marketing by email, SMS or WhatsApp only to people who have agreed to receive it, or to our existing clients about services similar to ones they already use, as section 69 of POPIA allows. Every message tells you how to opt out, and you can opt out at any time by replying or by emailing us.

6. Who we share it with

Only with the service providers we need to run the business, who are bound by contract to protect it and use it only for us:

  • Google for email, calendar, video calls and website analytics
  • Brevo for call bookings and email we send to people who have opted in
  • Zoho for invoicing and accounting
  • Hetzner Online for the servers that run our automation platform, in Germany
  • A specialist infrastructure partner who maintains our automation server
  • Cloudflare for our domain's DNS and security
  • Supabase for database hosting
  • Meta Platforms for the WhatsApp Business Platform
  • AI model providers, reached through OpenRouter, when a chatbot needs to generate a reply
  • Our accountants and professional advisers
  • Authorities, only when the law requires it

We don't share personal information with advertisers or data brokers.

7. Information that leaves South Africa

Some of these providers store or process information outside South Africa, including in the European Union, the United Kingdom and the United States. We only send personal information across the border where section 72 of POPIA allows it: the recipient is bound by a law, binding corporate rules or an agreement that gives it adequate protection (such as the GDPR, or standard contractual clauses), or you have agreed, or it is needed to perform a contract with you.

8. How we protect it

  • Access is limited to people who need it, each with their own account. We use multi-factor authentication on systems that hold personal information.
  • Information is encrypted in transit, and at rest where our providers support it.
  • Everyone who works for us is bound to confidentiality in their contract, including after they leave.
  • Where possible, systems we build for clients run in accounts the client owns and controls, so the client can see and remove our access at any time.
  • Our platforms keep logs of access and changes.
  • By default our automation server doesn't store the information passing through successful runs, only from failed runs, which we keep for a limited time to fix errors.
  • If we believe personal information we are responsible for has been accessed or acquired by someone without authority, we notify the Information Regulator and the people affected as soon as reasonably possible, as section 22 of POPIA requires. When we are acting for a client, we tell the client immediately so it can do the same.

9. When we act for our clients

When we build or run a system for a client, we:

  • process personal information only on the client's documented instructions and for the client's purposes
  • keep it confidential and secure, as sections 20 and 21 of POPIA require, and article 28 of the GDPR where it applies
  • work under a written agreement with the client
  • tell the client immediately about any suspected security compromise
  • use other service providers for the client's data only with the client's agreement
  • help the client respond to requests from the people whose information it is
  • return or delete the information when the work ends, unless the law requires us to keep it

10. How long we keep it

InformationHow long
Enquiries that don't lead to workUp to 24 months after our last contact
Client and supplier records, contracts, invoicesAs long as tax and company law requires, currently five to seven years depending on the record
WhatsApp notification data24 months after your last interaction
Website analytics14 months

After that we delete it or remove anything that identifies you.

11. Your rights

You can ask us whether we hold personal information about you and for a copy, ask us to correct or delete it, object to how we use it (including for direct marketing), and withdraw consent you have given. If the GDPR applies to you, you can also ask us to restrict processing or to give you your information in a portable format.

Email our Information Officer at braam@theautomators.co with your request. We will confirm who you are before acting and reply within 30 days.

If you're unhappy with how we've handled your information, you can complain to the Information Regulator, or to your local data protection authority if the GDPR applies to you.

12. The Information Regulator

13. Children

Our website and services are not aimed at children, and we don't knowingly collect children's information for our own purposes. Some systems we run for clients may hold information about children. There we act only on the client's instructions, and the client is responsible for the lawful basis, as sections 34 and 35 of POPIA require.

14. Cookies

Our website uses Google Analytics cookies to understand how visitors use it. You can block or delete cookies in your browser settings, or install Google's Analytics opt-out browser add-on.

15. Our WhatsApp notification service

Reply STOP to any message to stop receiving them. To have your information deleted, email braam@theautomators.co with the subject "Data Deletion Request" and the phone number concerned. We confirm deletion within 30 days. Your use of WhatsApp itself is covered by Meta's terms at whatsapp.com/legal.

16. Changes to this policy

When we change this policy we update the date at the top, and we tell our clients about any material change.

17. Contact

The Automators (Pty) Ltd

Information Officer: Braam Raubenheimer

Email: braam@theautomators.co

Phone: +27 82 770 6456