Automize RPA SaaS Platform
Capitol Hill Consulting (Pty) Ltd
1. INTRODUCTION
Welcome to Automize. Capitol Hill Consulting (Pty) Ltd ("we", "us", "our", or "Automize") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Robotic Process Automation (RPA) software-as-a-service platform.
Who We Are:
- Company Name: Capitol Hill Consulting (Pty) Ltd
- Trading As: Automize
- Registration Number: 2019/050086/07
- Registered Address: 4 Muller Street, Bethlehem, Free State, South Africa, 9701
- Contact Email: privacy@automize.co.za
- Website: https://wills.futuregd.co.za/
Our Commitment:
We comply with applicable data protection laws, including:
- EU General Data Protection Regulation (GDPR) – European Union
- UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 – United Kingdom
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) – United States, California
- Comparable state privacy laws including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, and Rhode Island – United States
- Protection of Personal Information Act (POPIA) – South Africa
- UAE Data Protection Laws – United Arab Emirates
For a quick summary of the choices and rights available to you, see Your Privacy Choices. To exercise a right, use the privacy request form.
2. SCOPE AND APPLICATION
This Privacy Policy applies to:
- Visitors to our website
- Users of the Automize platform (web application and RPA bot software)
- Clients and their authorized users
- Third-party consultants using our platform
- Anyone who contacts us for support or information
This Privacy Policy does NOT cover:
- Data processed by our RPA bots on your behalf (you are the controller of that data)
- Websites or services linked from our platform
- Third-party consultants' own privacy practices with their clients
2.1 Our Role: Who Decides What Happens To The Data
Data protection law assigns different duties depending on who decides why and how personal data is processed. Automize holds two different roles, and which one applies depends on the data:
- Process Data – you decide, we execute. You build the automation and you choose what data it reads, writes or moves. You are therefore the responsible party under POPIA and the data controller under GDPR. Automize is the operator under POPIA and the data processor under GDPR: we process that data only on your documented instruction, and never for our own purposes.
- Account, billing, support and platform telemetry – we decide. For this data Automize is the responsible party / data controller, because we determine why it is collected and how it is used.
The written contract: POPIA section 21 requires a written contract between a responsible party and its operator, and GDPR Article 28 requires equivalent terms. Those terms form part of your service agreement – see the Terms of Service. If your organisation requires a separate Data Processing Agreement, contact privacy@automize.co.za.
What “assisting you” means in practice. Because you decide what enters the platform, you – not we – are the party able to say which records in your own content belong to a particular person. Our duty is to give you the means to act and to act on your instructions. Where you instruct us to locate, export or delete a specific person's data, we will do so and will assist you in meeting your own response deadlines.
Two limits we state rather than leave you to discover:
- Trash and backups. A deleted record or file goes to Trash for 30 days, then it is permanently deleted. Encrypted backups taken before that still hold it until they age out. Backups are kept for 7 days, so the record is gone from them within a further 7 days. Backups are never restored to bring back one deleted record, and they expire on their own.
- Artificial intelligence. Text a user submits to an AI feature, or that a bot's AI step sends through Automize, goes to the AI providers listed in § 5 as sub-processors. By default, personal details such as ID numbers, card and bank numbers, phone numbers and email addresses are hidden from the AI first (see § 16.4, which also sets out what this does not cover). The providers act under API terms that do not permit your content to be used to train their models. We do not use your content to train any model of our own, and we do not use it for analytics beyond delivering the service to you. If that ever changes, we will tell you before it does, because it would change our role for that activity.
Account Information:
- Name
- Email address
- Phone number
- Company name and address
- Job title
- Billing information (credit card details are processed by our payment provider, not stored by us)
Process Data:
- Workflow definitions and configurations you create
- Step thumbnails and failure screenshots your bots send (failure screenshots are blurred by default; your admins control both in the Bot privacy settings, see § 16.3)
- Process names and descriptions
- Application and file references in your workflows
Communications:
- Support ticket content
- Email correspondence
- Chat messages
- Phone call records
- Feedback and survey responses
Identity Verification:
- Government-issued ID (only when required for data subject requests or high-security operations)
Usage Information:
- Login dates and times
- Features used
- Process execution history
- Clicks and interactions within the platform
- Pages visited and time spent
Technical Information:
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Cookies and similar technologies
Performance Data:
- Error logs
- System performance metrics
- API usage statistics
Important: You control what leaves your machines. The files and systems your bots work with stay on your machines unless an automation sends them.
What your automations send is stored on our servers:
- Work-queue items and their output
- Transaction details
- Failure messages
- Step thumbnails and failure screenshots
- Copies of documents a bot failed to read ("document samples"), only if you opt in, kept for 90 days
The content of queue items, their output and failure messages, and transaction details and failure messages, is encrypted a second time by the application (see § 6.2).
Credentials: you choose where the passwords and keys your automations use are kept: the platform vault (encrypted with its own key), AWS Secrets Manager, or the bot machine's own keychain.
4.1 Legal Bases for Processing
We process your information based on the following legal grounds:
Contract Performance:
- Providing Automize services you've subscribed to
- Managing your account
- Processing payments
- Delivering customer support
Legitimate Interests:
- Improving our platform and services
- Security monitoring and fraud prevention
- Analytics and performance optimization
- Marketing (with opt-out option)
Consent:
- Marketing communications (where required by law)
- Non-essential cookies
- Optional features like document samples
Legal Obligation:
- Complying with tax and accounting requirements
- Responding to legal requests
- Regulatory reporting
4.2 Specific Uses
To Provide Services:
- Create and manage your account
- Enable RPA bot functionality
- Store and execute your process definitions
- Provide technical support
- Process billing and payments
To Improve Services:
- Analyze usage patterns
- Identify and fix bugs
- Develop new features
- Optimize performance
- Conduct research and analytics
To Communicate:
- Send service updates and notifications
- Respond to inquiries
- Provide customer support
- Send security alerts
- Marketing (with your consent)
To Ensure Security:
- Detect and prevent fraud
- Monitor for security threats
- Investigate security incidents
- Enforce our terms of service
5. DATA SHARING AND DISCLOSURE
Service Providers (Sub-processors):
- Amazon Web Services (AWS), Ireland: Cloud hosting and infrastructure – hosts the web platform, database, and asset storage. Includes AWS Textract for document OCR (when you upload documents to features that extract text), and AWS Rekognition for face matching (only if you build face matching into a process; see § 21.2).
- SendGrid (Twilio): Transactional email – service notifications, password resets, invites.
- WorkOS: Enterprise Single Sign-On (SAML / OIDC) federation – only for customers who choose to integrate their own identity provider.
- PayFast: Subscription payment processing – hosted-redirect checkout (we hold PCI-DSS SAQ-A; PayFast holds PCI-DSS Level 1 Service Provider attestation). We never see or store full card details.
- Anthropic / OpenAI: AI-powered features – processes the text a user submits to an AI feature, or that a bot's AI step sends through Automize. You choose what the bot sends. Personal details are hidden first by default (see § 16.4). If you connect your own AI account on a machine, that traffic goes straight from the machine to your provider, not through us.
- Sentry: Error and performance telemetry – receives error reports. Before a report is sent, it is scrubbed of passwords, keys and tokens, and of email addresses, ID numbers, card numbers, IBANs and phone numbers. Names are not recognised, so we do not promise every personal detail is removed. Reports are stored in Sentry's EU region (Frankfurt, Germany).
All sub-processors are contractually bound to protect your data and use it only for specified purposes. An up-to-date list is maintained at this location. We give clients 30 days' notice of a new sub-processor that handles their data, and they can object. If we cannot resolve an objection, the client may end the affected service, or the whole agreement if the new sub-processor cannot be avoided, without penalty.
Fonts, icons and scripts on our web pages: our pages load fonts from Google Fonts, icons from Font Awesome, and some scripts from cdnjs (run by Cloudflare). When your browser fetches these files, those companies receive your IP address and browser details. They do not set cookies for us. We rely on our legitimate interest in showing the page properly.
Third-Party Consultants:
If you are serviced by an independent consultant using Automize, they have access only to their own client data (yours), not other users' data.
5.2 We Do NOT:
- Sell your personal information to anyone
- Share your data for third-party marketing purposes
- Provide access to your process data to other clients or consultants
- Use your data for purposes unrelated to providing services
5.3 Legal Disclosures
We may disclose information when required by law:
- In response to court orders or subpoenas
- To comply with legal obligations
- To protect our rights or property
- To prevent fraud or security threats
- In connection with business transactions (merger, acquisition)
In such cases, we will notify you unless legally prohibited.
6. DATA STORAGE AND SECURITY
6.1 Where We Store Your Data
Cloud Infrastructure:
- Primary storage: AWS data centers in Ireland (eu-west-1)
- Backup storage: automatic daily backups plus point-in-time restore, encrypted at rest by AWS and kept for 7 days, then deleted automatically. Backups stay in the same region; no copy is kept in another region.
- Your data does not leave our controlled infrastructure except for sub-processors listed above
Client-Side Storage:
- RPA bot log files are stored on your own PCs/virtual desktops
- Credentials your bots use are stored where you choose: the platform vault (encrypted with its own key), AWS Secrets Manager, or the bot machine's own keychain (Windows Credential Manager, macOS Keychain)
- You control and are responsible for security of client-side data
International Transfers:
If your data is transferred internationally, we use appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by EU Commission
- Adequate security measures equivalent to GDPR/POPIA requirements
6.2 How We Protect Your Data
Technical Security Measures:
- Encryption in transit (TLS 1.2 or higher)
- Encryption at rest (AES-256) by AWS for the database, files and backups
- A second layer of encryption by the application for the content of queue items, their output and failure messages, and transaction details and failure messages. The key is held outside the database, so a copy of the database or a backup alone does not reveal this content
- Secure password storage (argon2id hashes); passwords found in known data breaches are refused
- Regular security updates and patches
- Automated daily backups, kept for 7 days
- A private database with no public access; rate limiting; weekly automated security scans
- Access controls and authentication
- Opening the content of a record (queue item data, transaction details, what a log says a step held, failure messages) needs the "See client data" permission. Company admins have it; Viewer, Operator and Editor do not, unless a company admin switches it on for that role; a custom role can be given it. Everyone else sees that a record exists, when it ran and how it ended, but not what it contains
Organizational Security Measures:
- Limited access to data (need-to-know basis)
- A small number of Automize platform staff (super users) have wider access than your own users, as on other RPA platforms. They use it only to support you and run the service
- Every time anyone, staff included, opens the content of a record, it is written to your company's tamper-evident security log
- Confidentiality agreements, security training and supplier security reviews, as required by our policies
- Incident response procedures
- Security policy enforcement
Your Responsibilities:
- Use strong, unique passwords
- Do not share login credentials
- Enable multi-factor authentication
- Secure your own devices and networks
- Report security concerns immediately
6.3 Data Retention
We retain your data for:
| Data Type |
Retention Period |
Reason |
| Account data |
Duration of service, then erased after the 30-day export window (see below) |
Contract fulfillment |
| Process definitions |
Until you delete them |
Service provision |
| Deleted records and files |
30 days in Trash, then permanently deleted; gone from backups within a further 7 days |
Lets you undo a mistake |
| Billing records |
7 years |
Legal/tax requirements |
| Support tickets |
As long as needed to support you, then deleted |
Service improvement |
| System logs |
As long as needed for security and fault-finding, then deleted |
Security monitoring |
| Run logs (execution logs) |
As set by your plan; 365 days if your plan sets none (some plans keep them for the life of the account) |
Service provision |
| Step error details |
30 days after last seen |
Service provision |
| Work-queue items |
90 days after they finish |
Service provision |
| Live screenshots from a bot (remote view) |
24 hours |
Service provision |
| Document samples (only if you opt in) |
90 days |
Service improvement |
| Face-matching images (only if you build face matching into a process) |
Deleted as soon as the check is done |
Service provision |
| Security log (including views of client data) |
365 days |
Security monitoring |
| Endpoint audit log (calls to critical endpoints) |
30 days |
Security monitoring |
| Backups |
7 days |
Disaster recovery |
| Marketing data |
Until you opt-out |
Consent-based |
Upon Service Cancellation:
- You have 30 days to export your data
- After those 30 days, we erase your company's data from the platform automatically
- Backups roll off within a further 7 days
- We keep only what we must: billing and tax records (7 years), security logs until the end of the periods above, and a record that the erasure took place
- We provide written confirmation of deletion upon request
7. YOUR RIGHTS AND CHOICES
7.1 Your Data Protection Rights
Under GDPR, POPIA, and UAE data protection laws, you have the right to:
Right to Access:
- Request a copy of your personal information
- Know how we're using your data
- Receive information about our processing activities
Right to Rectification:
- Correct inaccurate information
- Complete incomplete information
Right to Erasure ("Right to be Forgotten"):
- Request deletion of your personal information
- Subject to legal retention requirements
Right to Restriction:
- Limit how we process your data in certain circumstances
- Object to processing based on legitimate interests
Right to Data Portability:
- Receive your data in machine-readable format (JSON, CSV)
- Transfer your data to another service provider
Right to Object:
- Object to processing for direct marketing
- Object to automated decision-making
- Object to processing based on legitimate interests
Right to Withdraw Consent:
- Withdraw consent at any time (where consent is the legal basis)
- Does not affect lawfulness of prior processing
Right to Lodge a Complaint:
- File a complaint with supervisory authorities (contact info below)
7.2 How to Exercise Your Rights
The fastest way is the privacy request form – it routes directly to our privacy team and starts the verification process. You can also email privacy@automize.co.za with the subject “Data Subject Request – [your right]” and include your name, the email on your account, and a description of your request.
Verification: We may ask you to confirm control of your account email and, for sensitive requests, a second identity factor.
Response Time: We will respond within 30 days under GDPR / POPIA, 45 days under CCPA, with an optional further extension of 30 to 45 days for complex requests (we will tell you why).
No Fee: Exercising your rights is generally free, unless requests are manifestly unfounded or excessive.
Data an organisation processes with Automize: If your request is about data that one of our clients processes using Automize, that client answers it. We pass your request to the client within 1 business day and help them answer it.
No Retaliation: We will never deny service, charge a different price, or downgrade your experience because you exercised a privacy right.
7.3 Account Management
You can directly:
- Update account information in your profile settings
- Delete processes and screenshots at any time
- Export your data in JSON or CSV format
- Cancel your subscription (30-day data export window applies)
7.4 Marketing Communications
Opt-out options:
- Click "unsubscribe" in marketing emails
- Email: privacy@automize.co.za with "Unsubscribe" in subject
- Adjust preferences in your account settings
Note: You cannot opt-out of essential service communications (security alerts, billing notifications, terms updates).
8. COOKIES AND TRACKING
8.1 What Are Cookies?
Cookies are small text files stored on your device that help us provide and improve our services.
8.2 Types of Cookies We Use
Essential Cookies (Required):
- Authentication and session management
- Security features
- Load balancing
- These cannot be disabled without affecting functionality
Functional Cookies (Optional):
- Remember your preferences
- Language settings
- UI customization
Analytics Cookies (Optional):
- Understand how you use the platform
- Improve user experience
- Identify performance issues
We do NOT use:
- Third-party advertising cookies
- Cross-site tracking cookies
- Social media tracking pixels
Our pages also load fonts, icons and scripts from Google Fonts, Font Awesome and cdnjs. These providers receive your IP address (see § 5).
8.3 Managing Cookies
Browser Settings:
You can control cookies through your browser settings. Note that blocking essential cookies will prevent you from using the platform.
Our Cookie Preference Tool:
You can manage optional cookies through our cookie preference center.
Do Not Track:
We do not act on the older "Do Not Track" signal, because there is no agreed standard for it. We do honour Global Privacy Control (GPC): a GPC signal turns analytics off and hides the cookie banner.
9. CHILDREN'S PRIVACY
Automize is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.
If you believe we have inadvertently collected information from a child:
- Contact us immediately at privacy@automize.co.za
- We will delete the information promptly
10. CHANGES TO THIS PRIVACY POLICY
10.1 Updates
We may update this Privacy Policy to reflect:
- Changes in laws or regulations
- New features or services
- Improvements to our practices
10.2 Notification
Material Changes:
- Email notification to registered users
- Prominent notice on our website
- 30 days' notice before changes take effect
Minor Changes:
- Updated "Last Updated" date
- Notification via platform
10.3 Your Options
If you disagree with changes:
- You may terminate your account
- You have 30 days to export your data
- Continued use constitutes acceptance
11. THIRD-PARTY CONSULTANTS
11.1 If You Use a Consultant
If an independent consultant provides RPA services to you using Automize:
Your Relationship:
- The consultant is your service provider
- You should have a separate agreement with them
- They determine how your data is processed
Our Role:
- We provide the platform infrastructure
- We process data on the consultant's instructions
- We maintain platform security and compliance
Data Access:
- The consultant has access to data they create for you
- They cannot access other clients' data
- We do not share your data with other consultants
Privacy Concerns:
- Contact your consultant about their data practices
- Contact us about platform security or our processing activities
11.2 If You Are a Consultant
If you use Automize to service your own clients:
Your Responsibilities:
- You are the data controller for your clients' data
- You must have Data Processing Agreements with your clients
- You must comply with applicable data protection laws
- You must provide privacy notices to your data subjects
Our Responsibilities:
- We process data according to your instructions
- We maintain platform security
- We provide data processing terms in your service agreement
12. BUSINESS TRANSFERS
In the event of a merger, acquisition, reorganization, or sale of assets:
- Your information may be transferred to the new entity
- We will notify you before transfer
- The new entity will be bound by this Privacy Policy
- You will have the option to delete your account
13.1 Data Controller
Capitol Hill Consulting (Pty) Ltd
- Email: privacy@automize.co.za
- Address: 4 Muller Street, Bethlehem, Free State, South Africa, 9701
- Phone: +27 82 884 5000
13.2 Data Protection Queries
For privacy questions or data subject requests:
- Email: privacy@automize.co.za
- Subject: "Privacy Inquiry" or "Data Subject Request"
- Response time: 5 business days for inquiries, 30 days for formal requests
13.3 Security Concerns
To report security issues:
- Email: security@automize.co.za
- Subject: "Security Concern"
- Response time: 24 hours for critical issues
14. SUPERVISORY AUTHORITIES
14.1 Your Right to Complain
If you're unhappy with how we handle your data, you have the right to lodge a complaint with the relevant supervisory authority.
Ireland and the EU (GDPR):
Data Protection Commission (DPC)
- Website: https://www.dataprotection.ie
- Phone: +353 1 765 0100
- Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
- People in other EU countries can also complain to their own national regulator
United Kingdom (UK GDPR):
Information Commissioner's Office (ICO)
- Website: https://ico.org.uk
- Phone: 0303 123 1113
- Email: casework@ico.org.uk
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
South Africa (POPIA):
Information Regulator
- Website: https://www.inforegulator.org.za
- Email: complaints.IR@inforegulator.org.za
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
United Arab Emirates:
Which regulator applies depends on where the organisation is based. The DIFC and ADGM free zones have their own data protection laws and regulators.
- UAE Data Office (federal law, Decree-Law No. 45 of 2021)
- Dubai International Financial Centre: DIFC Commissioner of Data Protection, https://www.difc.ae
- Abu Dhabi Global Market: ADGM Office of Data Protection, https://www.adgm.com
15. SPECIAL SITUATIONS
15.1 Remote Access by Automize
If you purchase managed services where we remotely access your systems:
- We will access only authorized systems
- We follow strict security protocols
- All access is logged and auditable
- We do not access your data beyond what's necessary for service delivery
- Refer to our Remote Access Policy in your service agreement
15.2 Data Breaches
In the event of a data breach affecting your personal information:
- We will notify you without undue delay and within 24 hours of becoming aware of it. If you are our client, this lets you meet your own 72-hour duty to the regulator
- We will explain what happened and what data was affected
- We will tell you what steps we're taking
- We will advise you on protective measures
- We will notify relevant authorities as required by law
15.3 Law Enforcement Requests
If we receive a legal demand for your information:
- We will notify you if legally permitted
- We will challenge overbroad requests
- We will provide only the minimum information required
16. YOUR CLIENT-SIDE DATA
16.1 Data That Stays On Your Systems
Important Clarification:
You control what leaves your machines. The files and systems your bots work with stay on your machines unless an automation sends them. So do the log files on your local machines.
What your automations do send is stored on our servers: see § 3.3.
Your Responsibilities:
- Secure your own PCs and virtual desktops
- Control access to log files
- Implement encryption where appropriate
- Follow your own data protection policies
- Train your staff on data handling
Our Guidance:
We provide best practice recommendations for client-side security in our documentation.
16.2 Client-Side Logs
Log Files on Your Systems:
- May contain sensitive data depending on your processes
- Are your responsibility to secure and manage
- Should be retained according to your policies
- Should be encrypted where they contain personal data
Our Recommendations:
- Review our Log Management Guide
- Implement file access controls
- Regular log rotation and cleanup
- Include in your backup procedures
16.3 Bot Privacy Settings
Your company admins set these under Settings > Security > Bot privacy. They apply to every bot in your company. A single machine can be made stricter, never looser.
Defaults:
- Failure screenshots: blurred (you can choose off, blurred or full)
- Step thumbnails: on
- Screenshots on request (remote view): on
- Values shown in the step debugger: on
- Hide personal details from Automize AI: on (see § 16.4)
Steps and variables marked sensitive, and all vault values, are hidden everywhere in logs and the debugger. Screenshots follow the screenshot settings above.
16.4 Personal Details and AI
By default, personal details are hidden from AI. Before text goes to an AI model, the platform and the bot swap these for placeholders, and put the real values back in the answer:
- ID numbers (South African ID, UAE Emirates ID, UK National Insurance number)
- Card numbers, IBANs and bank account numbers
- Phone numbers and email addresses
- Passwords, keys and tokens
This covers a bot's AI steps through Automize and the platform's own AI features (assistant, error diagnosis, explanations, field mapping, triage).
What it does not cover:
- It does not recognise names.
- It does not change images or scanned documents. A picture or PDF page sent to AI vision or OCR is sent as is.
- It does not apply when you connect your own AI account directly on a machine.
17. DATA PROTECTION IMPACT ASSESSMENTS
For high-risk processing activities, we conduct Data Protection Impact Assessments (DPIAs) to ensure adequate safeguards.
When we conduct DPIAs:
- New features involving personal data
- Changes to data processing activities
- Use of new technologies
- When required by law
Your DPIAs:
If your use of Automize involves high-risk processing (large-scale processing of sensitive data, systematic monitoring, etc.), you may need to conduct your own DPIA. We will assist you with information about our processing activities.
18. AUTOMATED DECISION-MAKING
We do not use your personal information for:
- Automated decision-making with legal or significant effects
- Profiling that affects your rights
- AI-driven decisions about your account
Small automatic actions do happen, such as a 15-minute lock after five failed sign-ins. If one affected you unfairly, contact us and a person will review it.
19. GLOSSARY
Personal Data / Personal Information: Any information relating to an identified or identifiable individual.
Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion, etc.).
Data Controller: The entity that determines the purposes and means of processing personal data.
Data Processor: The entity that processes personal data on behalf of the controller.
Data Subject: The individual to whom personal data relates.
Sub-processor: A third party engaged by the processor to process data.
RPA (Robotic Process Automation): Technology that uses software bots to automate repetitive tasks.
20. ADDITIONAL RESOURCES
Learn More:
- Terms of Service: Terms of Service
- Service Level Agreement: Available upon request
- Security Whitepaper: Available upon request
- Data Processing Agreement: Available upon request
- Cookie Policy: Cookie Policy
Help Center:
- FAQs: Available in Help
- Documentation: Available in Help
- Best Practices: Available in Help
- Contact Support: support@automize.co.za
21. ADDITIONAL US STATE PRIVACY DISCLOSURES
This section provides the additional disclosures required by the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the comparable privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, and Rhode Island. Where these laws use different terminology, the substance is the same. For the quick summary and a single place to exercise your rights, see Your Privacy Choices.
21.1 Categories of Personal Information Collected
In the past 12 months we have collected the following categories of personal information (as defined under the CCPA / CPRA):
- Identifiers – name, email, postal address, phone number, account login, IP address. Sources: directly from you, from your employer if you sign in via an enterprise SSO. Purpose: account creation, authentication, billing, support. Disclosed to: sub-processors listed in our Trust Center (AWS for hosting, PayFast for billing, SendGrid for email, WorkOS for SSO, Sentry for error reporting). Retention: for the life of the account plus 7 years for tax / audit records.
- Customer records (Cal. Civ. Code § 1798.80(e)) – billing address, payment information (held by PayFast, not by us), employer information. Sources: directly from you. Purpose: billing, contracting. Retention: 7 years (statutory).
- Commercial information – subscription tier, usage history, products considered. Sources: automatic on use of the platform. Purpose: service provision, billing reconciliation, internal analytics. Retention: for the life of the account.
- Internet / electronic activity – pages visited, features used, clicks, login times, error logs. Sources: automatic via cookies, server logs, and Sentry. Purpose: service operation, security, debugging, product analytics. Retention: raw logs are kept only as long as needed for security and fault-finding; aggregated metrics are kept longer.
- Professional / employment information – job title, department, employer name. Sources: directly from you or your employer. Purpose: account context, support routing. Retention: for the life of the account.
We do not collect: precise geolocation; racial or ethnic origin; religious or philosophical beliefs; union membership; genetic data; sexual orientation; the content of private communications; consumer health data (other than incidental support requests).
21.2 Sensitive Personal Information
The CPRA defines “sensitive personal information” (SPI) to include items such as government identifiers, account login credentials in combination with security codes, precise geolocation, racial or ethnic origin, religious beliefs, biometric data, contents of private communications, sexual orientation, and consumer health data. We collect SPI only as strictly necessary to provide the service:
- Account credentials. Stored hashed (argon2id) and used only for authentication.
- Government ID. Collected only when needed to verify a privacy request or to satisfy a security concern; held only for as long as needed and then deleted.
- Face images (biometric data). Automize can compare the photo on an ID document with a selfie, but only when a client builds this into its own process. The client is the controller and we are the processor. The comparison runs on AWS Rekognition in Ireland, and both images are deleted as soon as the check is done. If you were asked for a selfie, contact the organisation that asked you.
We do not use SPI for any purpose other than what is reasonably necessary to provide the service you have asked for. You have the right to limit our use of SPI – submit a request via privacy-request.
21.3 We Do Not Sell or Share Personal Information
We do not sell personal information for money, and we do not share personal information with third parties for cross-context behavioural advertising as those terms are defined under the CPRA. Although we are not under a “Do Not Sell or Share” obligation, we honour an opt-out signal from you as if we were so that you have a single, predictable control surface.
21.4 Global Privacy Control (GPC)
If your browser sends the Global Privacy Control signal (the Sec-GPC: 1 header or the navigator.globalPrivacyControl JavaScript property), we treat it as a valid opt-out of any sale or share of personal information and as a request to limit the use of sensitive personal information. The signal is honoured automatically for the entire session and is persisted with the cookie consent record where one is set. It also turns analytics off and hides the cookie banner. See globalprivacycontrol.org for more.
21.5 Notice at Collection
This Privacy Policy serves as our Notice at Collection. The categories of personal information we collect, the purposes for which we collect each category, the retention period for each category, and the sale / share disclosure are set out in § 21.1, § 21.2 and § 21.3 above.
21.6 Your Rights Under US State Privacy Laws
Subject to verification, you have the right to:
- Know what personal information we hold about you, the categories, sources, purposes, recipients, and retention periods.
- Access a portable copy of your personal information.
- Correct inaccurate personal information.
- Delete personal information we hold about you (subject to limited exceptions, e.g. tax records, security logs, and on-going contractual obligations).
- Opt out of any sale or share of personal information (we do not sell or share, but you may opt out anyway).
- Limit the use of sensitive personal information.
- Withdraw consent for any consent-based processing.
- Be free from retaliation for exercising any of these rights.
- Appeal a decision we make on your request – submit an appeal to privacy@automize.co.za with subject “Appeal”. Where required by law (Virginia, Colorado, Connecticut, etc.), we will respond to the appeal within 60 days and tell you how to contact your state Attorney General if you remain unsatisfied.
21.7 Authorised Agents
You may use an authorised agent to submit a request on your behalf. We will need written permission from you authorising the agent (or a power of attorney), and we will verify your identity directly. The agent option is available on the privacy request form.
21.8 California “Shine the Light” Law
California Civil Code § 1798.83 entitles California residents to ask, once per calendar year, what personal information we have shared with third parties for their direct marketing purposes. The answer for Automize is none – we do not share personal information for third-party direct marketing.
ACKNOWLEDGMENT
By using Automize, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.
Questions? Contact us at privacy@automize.co.za – or use the privacy request form.
Document Version: 1.5
Effective Date: 29 September 2026
Last Reviewed: 29 September 2026
Next Review: September 2027