Legal

Privacy Policy

Last updated: 25 September 2026

This Privacy Policy explains how AffinityAI ("AffinityAI", "we", "us" or "our") collects, uses, shares and protects personal information when you visit affinityaisystems.com (the "website"), contact us or book a consultation. We process personal information in line with South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA") and, where it applies to you, the EU and UK General Data Protection Regulation ("GDPR"). POPIA also protects information about existing juristic persons, such as companies, so "you" includes them where POPIA applies.

1. Who we are

AffinityAI (Pty) Ltd (registration number 2026/086116/07) is an enterprise AI consultancy based in Johannesburg, South Africa. "AffinityAI" is our trading name. We are the responsible party (under POPIA) and the controller (under the GDPR) for the personal information described in this policy.

2. Personal information we collect

Information you give us

  • Sales enquiries. When you use a "Contact Sales" form, we collect your email address, your message and the package you selected.
  • Email, phone and LinkedIn. If you contact us directly, we receive your contact details and whatever you choose to share.
  • Consultation bookings. Our "Schedule a Consultation" buttons open Calendly, a third-party scheduling service. Calendly collects the details you enter (usually your name, email address, chosen time and any answers you give) and shares them with us so that we can hold the meeting.

Giving us personal information is voluntary, but we need at least your email address to respond to you.

Please do not send us special personal information (such as details about your health, religious or philosophical beliefs, race or ethnic origin, or criminal behaviour) or personal information about children. We do not need it to respond to you.

Information collected automatically

  • Server and security logs. When you load a page, our hosting provider Vercel processes technical data such as your IP address, browser and device type, the page requested, the referring page and the date and time. This is needed to deliver the website, keep it secure and fix problems.
  • Display preference. We store your light or dark display preference in your browser if you choose one (see Cookies and similar technologies).
  • No cookies or tracking tools. We do not currently use cookies, or any analytics, advertising or visitor-identification tools, on our website.

Our fonts are served from our own website, so viewing a page does not send your IP address to Google Fonts.

Information from third parties

We receive booking details from Calendly and messages you send us through LinkedIn. When preparing for a meeting you have requested, we may also look at publicly available business information, such as your company's website or LinkedIn page.

3. How we use personal information and why

We use personal information only for the purposes below. Each use is justified under section 11 of POPIA and Article 6 of the GDPR:

  • Responding to enquiries, preparing proposals and scheduling consultations: necessary to take steps you asked for before entering into a contract (POPIA s11(1)(b); GDPR Art. 6(1)(b)), and our legitimate interest in answering business enquiries (POPIA s11(1)(f); GDPR Art. 6(1)(f)).
  • Delivering services and managing our relationship with clients: necessary to perform a contract (POPIA s11(1)(b); GDPR Art. 6(1)(b)).
  • Operating, securing and troubleshooting the website: our legitimate interest in a secure, working website (POPIA s11(1)(f); GDPR Art. 6(1)(f)).
  • Keeping records and meeting legal obligations, such as tax and accounting requirements or lawful requests from authorities (POPIA s11(1)(c); GDPR Art. 6(1)(c)).

Direct marketing. We send direct marketing by email or other electronic means only as section 69 of POPIA allows: if you have agreed to receive it or, if you are a client, about our own similar services. Every marketing message lets you opt out free of charge.

Automated decisions. We do not make decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects for you.

4. Who we share personal information with

We share personal information with the service providers below (operators under POPIA, processors under the GDPR), and only as far as they need it to provide their services to us:

We may also share personal information with our professional advisers (such as accountants and lawyers), who are bound by confidentiality, with authorities where the law requires it, and with a buyer or successor if our business is sold or restructured, in which case we will tell you.

Our website links to our LinkedIn company page (opens in a new tab). We do not embed LinkedIn content or tracking on this website. LinkedIn's own privacy policy (opens in a new tab) applies when you visit LinkedIn.

5. Transfers outside South Africa

Our service providers are based in, or store data in, countries outside South Africa, mainly the United States. We transfer personal information across borders only where section 72 of POPIA allows it. For example: where the recipient is bound by a law, binding corporate rules or an agreement that gives adequate protection; where the transfer is needed to take steps you asked for or to perform a contract with you; or where you have consented. If you are in the European Economic Area or the United Kingdom, we rely on the safeguards our providers offer for international transfers. These include the European Commission's standard contractual clauses, or the EU-US Data Privacy Framework where the provider takes part in it.

6. How long we keep personal information

  • Enquiries that do not lead to an engagement: up to 24 months after our last contact.
  • Client and contract records: for the engagement, then for as long as tax, company and accounting laws require (generally five to seven years) or as needed to establish, exercise or defend legal claims.
  • Consultation bookings: in line with the enquiry and client periods above.
  • Server logs: for the limited period set by our hosting provider's log retention.

When we no longer need personal information, we delete or destroy it, or de-identify it so that it can no longer identify you.

7. How we protect personal information

As section 19 of POPIA requires, we take appropriate, reasonable technical and organisational measures to prevent loss of, damage to, and unauthorised access to or use of personal information. The website is served only over encrypted HTTPS connections. Access to our mailbox and service-provider accounts is limited to the people who need it, and our service providers are bound by confidentiality and security obligations. No website, email or storage system is completely secure, so please do not send us sensitive information you do not need to share.

If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as section 22 of POPIA requires. Where the GDPR applies, we will also notify the relevant supervisory authority.

8. Your rights

Subject to POPIA and, where it applies, the GDPR, you have the right to:

  • ask whether we hold personal information about you and request a copy of it;
  • ask us to correct or update personal information that is inaccurate, incomplete, misleading or out of date;
  • ask us to delete or destroy personal information that we are no longer authorised to keep;
  • object to our use of your personal information based on our legitimate interests, and object at any time to direct marketing;
  • withdraw any consent you have given at any time. Withdrawing consent does not affect processing that took place before you withdrew it;
  • where the GDPR applies, ask us to restrict our use of your personal information or to give it to you in a portable format; and
  • lodge a complaint with the Information Regulator (see section 12).

To make a request, email info@affinityaisystems.com with the subject "Privacy request". We may ask you to verify your identity before we act on it. We will respond within a reasonable time and, where the GDPR applies, within one month. We do not charge for reasonable requests.

9. Cookies and similar technologies

Cookies and similar technologies, such as local storage, are small pieces of information stored in your browser.

We do not currently use cookies, or any analytics, advertising or visitor-identification tools, on our website, so we do not ask you to accept cookies. The only item we store is:

  • theme (local storage), which remembers your light or dark display preference if you choose one, until you clear it. It stays in your browser and is not sent to us.

An earlier version of our website used visitor-identification tools. If your browser still holds identifiers they stored for our website, we delete them automatically when you visit. Identifiers kept on other companies' domains can only be removed in your browser settings. You can also delete cookies and local storage for our website at any time in your browser settings.

If we add analytics or visitor-identification tools in future, we will update this policy and ask for your consent before they load.

10. Children

Our website and services are intended for businesses and are not directed at children under 18. We do not knowingly collect personal information about children. If you believe a child has given us personal information, please contact us and we will delete it.

11. Other websites

Our website links to third-party websites and services, such as Calendly and LinkedIn. Their own privacy policies apply when you use them, and we are not responsible for how they handle personal information.

12. Complaints

If you have a concern about how we handle your personal information, please contact our Information Officer first at info@affinityaisystems.com so that we can try to resolve it. You also have the right to lodge a complaint with South Africa's Information Regulator:

If you are in the European Economic Area or the United Kingdom, you may also complain to the data protection authority where you live or work.

13. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top shows when it last changed. If we make significant changes, such as adding a new tracking tool, we will highlight them on the website and, where consent is required, ask for your consent.

14. Contact us

AffinityAI (Pty) Ltd, Johannesburg, South Africa
Information Officer: Adrian Diepeveen
Email: info@affinityaisystems.com

See also our Terms of Use.