This Privacy Policy explains how [COMPANY LEGAL NAME] (“OperateOS”, “we”) processes personal information when you use the OperateOS platform, in line with South Africa’s Protection of Personal Information Act (POPIA). For POPIA purposes, the responsible party is [COMPANY LEGAL NAME], and our Information Officer can be reached at [INFORMATION OFFICER EMAIL].
1. Information we collect
(a) Account data: your name, email, business name, and role. (b) Business/Customer Data you enter or import (customers, invoices, expenses, documents, etc.). (c) Usage & technical data: log data, IP address, device/browser, and audit events. We use passwordless email codes, so we do not store passwords.
2. How we use it
To provide, secure, and improve the Service; authenticate you; deliver login codes; run AI features you invoke; prevent abuse; and comply with legal obligations. We do not sell your personal information.
3. Lawful basis & consent
We process personal information to perform our contract with you, for our legitimate business interests, to comply with law, and — where required — with your consent (given at sign-up). You may withdraw consent, subject to the effect on the Service.
4. AI processing
When you use AI features, relevant content is sent to our AI model provider(s) to generate a response. We use providers that process data to serve the request; review each provider’s terms. Do not enter information you are not permitted to share. AI outputs may be inaccurate — see our Terms.
5. Sharing & operators (subprocessors)
We share personal information only with operators who process it on our behalf under contract, including [HOSTING PROVIDER], [DATABASE PROVIDER — e.g. Neon], [AI PROVIDER(S) — e.g. Google/Anthropic/OpenAI], [EMAIL PROVIDER — e.g. Resend], and [ERROR MONITORING — e.g. Sentry]. A current subprocessor list is available on request. We may disclose information where required by law.
6. International transfers
Some operators may process data outside South Africa [SPECIFY REGIONS — e.g. the database is currently hosted in the United States]. Where personal information is transferred cross-border, we rely on POPIA’s transfer conditions (adequate protection, contractual safeguards, or your consent). [Confirm and, ideally, move data to an EU/SA region before onboarding real tenants.]
7. Retention
We keep personal information for as long as your account is active and as needed to provide the Service, then for [RETENTION PERIOD] to meet legal, tax, and audit requirements, after which it is deleted or anonymised.
8. Security
We apply reasonable technical and organisational safeguards, including encryption in transit, tenant isolation, role-based access control, rate limiting, audit logging, and least-privilege access. No system is perfectly secure. We will notify you and the Information Regulator of a breach as required by POPIA.
9. Your rights
Subject to POPIA, you may request access to, correction of, or deletion of your personal information, object to certain processing, and lodge a complaint with the Information Regulator of South Africa. To exercise your rights, contact [PRIVACY EMAIL].
10. Cookies & sessions
We use a strictly-necessary, signed session cookie to keep you logged in. We do not use advertising cookies.
11. Children & changes
The Service is for businesses and not directed at children. We may update this Policy; material changes will be notified. Questions: [PRIVACY EMAIL] · [COMPANY LEGAL NAME], [REGISTERED ADDRESS].