Privacy Policy
How we handle personal information when you visit our website, contact us, work with us, receive WhatsApp notifications, or chat with a bot we run.
Last updated: 22 September 2026
1. Who we are
The Automators (Pty) Ltd, registration number 2025/800843/07 ("we", "us"), builds workflow automations, AI chatbots, voice agents and custom business systems.
- Address: 1 Vergenoegd Bordeaux Estate, Ametis Street, Klerksdorp, North West, 2572, South Africa
- Information Officer: Braam Raubenheimer
- Privacy requests: braam@theautomators.co | +27 82 770 6456
- Information Regulator registration: 2026-061974
2. What this policy covers
This policy explains how we handle personal information when you visit our website, contact us or book a call, when you or your organisation are a client, supplier or partner of ours, when you receive messages through our WhatsApp notification service, and when you chat with a bot we run for ourselves.
It follows the Protection of Personal Information Act 4 of 2013 (POPIA) and, where they apply, the EU and UK General Data Protection Regulations (GDPR). Under POPIA, information about companies and other organisations can also be personal information, so this policy covers it too.
When we work for a client, the client is in charge. If we build or run a system for a client, the client decides why and how the personal information in it is used. The client is the "responsible party" (the "controller" under GDPR) and we are its "operator" (its "processor"). Section 9 explains what we commit to in that role. If your information is in a system we run for one of our clients, please contact that client first. We will help them respond.
3. What we collect, and where it comes from
| When | What |
|---|---|
| You visit our website | Pages viewed, device and browser type, approximate location from your IP address, collected through Google Analytics cookies |
| You contact us or book a call | Your name, email address, phone number, organisation and role, your message, and your answers to the booking questions |
| You are a client, supplier or partner | Contact details of the people we deal with, what we discuss and agree, proposals, contracts, invoices and payment records |
| You receive our WhatsApp notifications | Your WhatsApp number, the name or label you or our customer supplied, messages sent and received, your opt-in and opt-out choices, and delivery data such as timestamps and read receipts |
| You chat with our own bot | The messages you send and any contact details you choose to give |
Most of it comes from you. Some comes from your organisation (for example when a client names you as its contact), from public business sources such as your company's website, or from our customers when they ask us to send you WhatsApp notifications.
Giving us your information is voluntary. If you don't, we may not be able to reply to you, hold a call, deliver a service or pay you.
We don't ask for special personal information (such as health, religious beliefs, race, biometric data or criminal records) or identity numbers for our own purposes. Please don't send them to us.
4. Why we use it
| Purpose | Basis under POPIA section 11 (and GDPR article 6 where it applies) |
|---|---|
| Reply to enquiries and hold calls you book | You asked us to, or it is a step towards a contract with you |
| Deliver, support and invoice our services | Performance of our contract with you or your organisation |
| Keep accounting and tax records | Legal obligation |
| Understand how our website is used and improve it | Our legitimate interest, and your consent to analytics cookies where the law requires it |
| Keep our systems and your information secure | Our legitimate interest and legal obligations |
| Send WhatsApp notifications | Your consent, or the instruction of our customer who is responsible for them |
We don't sell personal information. We don't use it to train our own artificial intelligence or machine learning models. Where a chat reply is generated for us, it may be produced by an AI model provider reached through OpenRouter, and we send only what is needed to produce that reply.
5. Direct marketing
We send marketing by email, SMS or WhatsApp only to people who have agreed to receive it, or to our existing clients about services similar to ones they already use, as section 69 of POPIA allows. Every message tells you how to opt out, and you can opt out at any time by replying or by emailing us.
6. Who we share it with
Only with the service providers we need to run the business, who are bound by contract to protect it and use it only for us:
- Google for email, calendar, video calls and website analytics
- Brevo for call bookings and email we send to people who have opted in
- Zoho for invoicing and accounting
- Hetzner Online for the servers that run our automation platform, in Germany
- A specialist infrastructure partner who maintains our automation server
- Cloudflare for our domain's DNS and security
- Supabase for database hosting
- Meta Platforms for the WhatsApp Business Platform
- AI model providers, reached through OpenRouter, when a chatbot needs to generate a reply
- Our accountants and professional advisers
- Authorities, only when the law requires it
We don't share personal information with advertisers or data brokers.
7. Information that leaves South Africa
Some of these providers store or process information outside South Africa, including in the European Union, the United Kingdom and the United States. We only send personal information across the border where section 72 of POPIA allows it: the recipient is bound by a law, binding corporate rules or an agreement that gives it adequate protection (such as the GDPR, or standard contractual clauses), or you have agreed, or it is needed to perform a contract with you.
8. How we protect it
- Access is limited to people who need it, each with their own account. We use multi-factor authentication on systems that hold personal information.
- Information is encrypted in transit, and at rest where our providers support it.
- Everyone who works for us is bound to confidentiality in their contract, including after they leave.
- Where possible, systems we build for clients run in accounts the client owns and controls, so the client can see and remove our access at any time.
- Our platforms keep logs of access and changes.
- By default our automation server doesn't store the information passing through successful runs, only from failed runs, which we keep for a limited time to fix errors.
- If we believe personal information we are responsible for has been accessed or acquired by someone without authority, we notify the Information Regulator and the people affected as soon as reasonably possible, as section 22 of POPIA requires. When we are acting for a client, we tell the client immediately so it can do the same.
9. When we act for our clients
When we build or run a system for a client, we:
- process personal information only on the client's documented instructions and for the client's purposes
- keep it confidential and secure, as sections 20 and 21 of POPIA require, and article 28 of the GDPR where it applies
- work under a written agreement with the client
- tell the client immediately about any suspected security compromise
- use other service providers for the client's data only with the client's agreement
- help the client respond to requests from the people whose information it is
- return or delete the information when the work ends, unless the law requires us to keep it
10. How long we keep it
| Information | How long |
|---|---|
| Enquiries that don't lead to work | Up to 24 months after our last contact |
| Client and supplier records, contracts, invoices | As long as tax and company law requires, currently five to seven years depending on the record |
| WhatsApp notification data | 24 months after your last interaction |
| Website analytics | 14 months |
After that we delete it or remove anything that identifies you.
11. Your rights
You can ask us whether we hold personal information about you and for a copy, ask us to correct or delete it, object to how we use it (including for direct marketing), and withdraw consent you have given. If the GDPR applies to you, you can also ask us to restrict processing or to give you your information in a portable format.
Email our Information Officer at braam@theautomators.co with your request. We will confirm who you are before acting and reply within 30 days.
If you're unhappy with how we've handled your information, you can complain to the Information Regulator, or to your local data protection authority if the GDPR applies to you.
12. The Information Regulator
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- Postal: PO Box 31533, Braamfontein, Johannesburg, 2017
- Complaints: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za | 0800 017 160
- Website: www.inforegulator.org.za
13. Children
Our website and services are not aimed at children, and we don't knowingly collect children's information for our own purposes. Some systems we run for clients may hold information about children. There we act only on the client's instructions, and the client is responsible for the lawful basis, as sections 34 and 35 of POPIA require.
14. Cookies
Our website uses Google Analytics cookies to understand how visitors use it. You can block or delete cookies in your browser settings, or install Google's Analytics opt-out browser add-on.
15. Our WhatsApp notification service
Reply STOP to any message to stop receiving them. To have your information deleted, email braam@theautomators.co with the subject "Data Deletion Request" and the phone number concerned. We confirm deletion within 30 days. Your use of WhatsApp itself is covered by Meta's terms at whatsapp.com/legal.
16. Changes to this policy
When we change this policy we update the date at the top, and we tell our clients about any material change.
17. Contact
The Automators (Pty) Ltd
Information Officer: Braam Raubenheimer
Email: braam@theautomators.co
Phone: +27 82 770 6456
