Home / Privacy policy
Privacy policy
Written to meet the Protection of Personal Information Act, and written so that a person can actually read it. Where the law makes us say something specific, we say it. Everywhere else we have used ordinary language.
Last updated 5 August 2026 · Version 1.0
Floserv Technologies (Pty) Ltd, registration number 2025/787630/07, a company registered in South Africa with its address at 212 Kerk Street, Rustenburg, North West, South Africa. In this policy, "we", "us" and "our" mean that company.
Our Information Officer, as POPIA requires, is Martin Schultz, reachable at [email protected]. Any request about personal information should go to that address.
This matters, because our obligations differ depending on whose information is involved.
For people who visit this website, enquire about our service, or work at a client company, we decide why and how their information is processed. Everything in this policy applies to them directly.
For the customers of our clients, the people messaging a business that uses our agent, our client is the responsible party and we are an operator processing information on their instruction. We only do what their agreement with us allows. If you are one of those customers and you want to know what is held about you, ask the business you were messaging. If they ask us, we will help them answer you.
We do not ask the agent to collect information a request does not need, and we do not collect card or banking credentials in chat at all.
We process personal information only where POPIA gives us a ground to do so. In practice that means one of the following.
Messages sent to a business using our agent are delivered through the official WhatsApp Business API, operated by Meta Platforms. Meta processes those messages in order to deliver them, under its own terms.
Where a business messages a customer first, WhatsApp's rules and POPIA both require that the customer opted in beforehand. We record that opt in with a timestamp and the wording that was agreed to. You can opt out at any time by replying to a message and asking to stop.
Conversations are processed by large language models in order to understand what is being asked and to compose a reply. This is provided through our platform, GoHighLevel.
Your conversations and documents are not used to train publicly available AI models, are not shared with other clients, and are not used to build anyone else's agent. Where our providers offer a setting that excludes customer data from training, that setting is on.
We do not sell personal information. We share it only with the sub-processors that make the service work, each of them bound to protect it. The current list is published on our security page, and covers our platform provider, our AI provider, Meta for WhatsApp delivery, and our SMS and voice providers.
We will also disclose information where a court order or the law requires it.
Some of our providers process information outside South Africa. Because our platform can route a conversation to different underlying language models depending on what is needed, that is not always the same country from one message to the next. POPIA allows this where the recipient is subject to rules or a binding agreement that provide a comparable level of protection, and our agreements with those providers are written to meet that standard.
If you want to know exactly where a specific category of information is processed, ask our Information Officer and we will tell you.
Information is encrypted in transit and at rest. Access is limited to people who need it to do their work, and that access is logged. The platform infrastructure we build on holds a SOC 2 Type II attestation covering security and availability. That certification belongs to the infrastructure provider rather than to us, and we say so plainly on our security page.
If a compromise of personal information occurs, POPIA requires us to notify the Information Regulator and the people affected as soon as reasonably possible. We will.
Under POPIA you may:
Write to our Information Officer at [email protected]. We will respond within the period POPIA allows, and normally much sooner. We may need to confirm your identity first, so that we do not hand your information to somebody else.
This website uses only what it needs to function and to understand how many people visit. We do not run advertising trackers that follow you across other websites. Details are in our cookie notice.
Our service is sold to businesses and is not directed at children. We do not knowingly collect information about a child without the consent of a competent person. If you believe we have, tell our Information Officer and we will remove it.
When this policy changes we update the date at the top. Where a change materially affects how we handle your information, we will tell clients directly rather than relying on you noticing.
Start with our Information Officer, because most things are faster to fix directly. If you are not satisfied, you may complain to the Information Regulator of South Africa.
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
[email protected]
inforegulator.org.za