POPIA · South Africa

Privacy Policy

How SAFEZA AVA-X (PTY) LTD processes personal information under the Protection of Personal Information Act 4 of 2013 (POPIA), and related South African law.

SAFEZA AVA-X (PTY) LTD

1. Responsible Party and Contact

The responsible party (as defined in POPIA) for the processing of personal information described in this Privacy Policy is:

SAFEZA AVA-X (PTY) LTD

Cape Town

Kensington

Cape Town, 7405

South Africa

Johannesburg

Bryanston

Johannesburg, 2191

South Africa

Information Officer / privacy contact

Enquiries relating to this Privacy Policy, data subject requests, or POPIA compliance should be directed to our Information Officer:

Postal: SAFEZA AVA-X (PTY) LTD, attn. Information Officer, Kensington, Cape Town, 7405, South Africa.

2. Applicable Law

This Privacy Policy is issued primarily under the Protection of Personal Information Act 4 of 2013 (POPIA) and related South African law, including where relevant the Promotion of Access to Information Act 2 of 2000 (PAIA) and the Electronic Communications and Transactions Act 25 of 2002 (ECTA).

Where our processing affects individuals in other jurisdictions, we also take account of applicable foreign data protection laws (including the EU GDPR and Swiss data protection law) to the extent they apply to SAFEZA AVA-X (PTY) LTD.

SAFEZA AVA-X (PTY) LTD processes personal information in a manner consistent with POPIA's conditions for lawful processing.

3. Personal Information We Collect

We generally process personal information that you provide to us, that is generated through use of our website or services, or that is collected in the course of our business relationships, always for a defined, lawful purpose.

3.1 Identity and contact data

  • Name, surname, organisation, job title, postal or physical address, email address, and telephone number
  • Contract documents, billing and payment information (for example bank details and invoice data)
  • Other information you provide when communicating with us (including demo or contact form submissions)

3.2 Technical and usage data

  • IP address, browser type, operating system, device type, and access times
  • Log data when using our website, portals, or cloud-connected services

3.3 Publicly available information

Information from official registers or generally accessible sources, where necessary for business purposes, due diligence, or identification, processed only as permitted by law.

3.4 Customer / end-user operational data

Where we supply video analytics, access control, or related systems to customers, the customer is typically the responsible party for personal information processed in their environment. We may act as an operator (processor) under written instructions and appropriate agreements, in line with POPIA.

4. Purpose and Lawful Processing

We process personal information only for the purposes set out below, and on a lawful basis under POPIA (including consent, contract, legal obligation, or another justification recognised in Chapter 3 of POPIA).

Contract and service delivery

  • Entering into and performing contracts for our products and services (delivery, installation, support, licensing)
  • Customer service, communication, and invoicing

POPIA basis: necessary for conclusion or performance of a contract; legitimate interests of the responsible party where applicable.

Legal obligations

  • Compliance with statutory retention, tax, and company-law requirements
  • Responding to lawful requests from South African authorities and regulators

POPIA basis: compliance with an obligation imposed by law.

Legitimate interests / responsible-party interests

  • Operating, securing, and improving our website and services (including IT security and fraud prevention)
  • Establishing, exercising, or defending legal claims

POPIA basis: pursuit of the legitimate interests of the responsible party or a third party, balanced against your rights.

Consent

  • Marketing communications (newsletters, campaigns) where consent is required
  • Non-essential analytics or tracking technologies on our website

POPIA basis: voluntary, specific, and informed consent, which you may withdraw at any time.

5. Special Personal Information

POPIA affords heightened protection to special personal information, which includes biometric information (such as facial imagery used for recognition).

Where we process biometric or other special personal information in connection with our products or services (for example facial recognition or video analytics), we do so only where a lawful ground under POPIA exists, such as consent, or another authorisation in sections 26 to 33 of POPIA, and with appropriate technical and organisational safeguards.

Customers deploying SAFEZA AVA-X technology remain responsible for ensuring their own POPIA compliance in respect of data subjects captured in their environments (including notification, justification, and any required authorisations).

6. Operators and Third Parties

We only share personal information with third parties where this is necessary and lawful, including where:

  • required for contract performance (for example payment providers or logistics partners),
  • required to comply with a legal obligation (for example regulators or law-enforcement agencies),
  • provided to operators (service providers) under written agreements that impose POPIA-aligned security and processing duties, or
  • you have consented to the disclosure.

Typical recipients include:

  • South African authorities and regulators where required by law
  • IT, hosting, cloud, and communications service providers acting as operators
  • Banks and payment processors
  • Professional advisers (legal, accounting, insurance)

7. Cross-Border Transfers

Personal information may be transferred outside the Republic of South Africa only in accordance with section 72 of POPIA, including where:

  • the recipient is subject to a law, binding corporate rules, or binding agreement that provides an adequate level of protection,
  • you have consented to the transfer,
  • the transfer is necessary for the performance of a contract, or
  • another ground in section 72 applies.

Where transfers occur (for example to affiliated entities or operators abroad), we implement appropriate contractual and technical safeguards. Our product architecture emphasises on-premises and sovereign deployment options so that customer operational data can remain within South Africa or another chosen jurisdiction.

8. Cookies and Tracking

We use cookies and similar technologies (for example local storage) on our website to:

  • ensure essential functionality and security of the site, and
  • measure usage or support marketing where you have consented.

Essential cookies are required for the website to operate and cannot be disabled through our consent tools.

Restricting cookies in your browser may affect site functionality. You can change or withdraw optional cookie consent at any time via our cookie banner controls where available.

9. Security Safeguards

In line with POPIA's security safeguards condition, we implement appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, and unlawful processing. These include:

  • Encryption of data in transit (for example HTTPS/TLS)
  • Role-based access controls and multi-factor authentication where appropriate
  • Regular security reviews, backups, updates, and testing
  • Hosting and deployment options designed for data residency and auditability

No method of transmission or storage is completely secure. We will notify the Information Regulator and affected data subjects of security compromises as required by POPIA.

10. Automated Processing

Where we use personal information for analytics or profiling in connection with our website or marketing, we do so on a lawful POPIA basis (typically consent or legitimate interests, as applicable).

We do not make decisions with legal or similarly significant effects based solely on automated processing of personal information without appropriate human involvement. Where our products assist customers with automated analysis (for example video analytics), those customers remain responsible for ensuring human oversight and lawful use in their deployments.

11. Retention and Destruction

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by South African law (including tax and company records obligations). Thereafter, information is destroyed, deleted, or de-identified in a manner that prevents reconstruction.

Where information is needed for more than one purpose, access is restricted to the purpose still requiring retention until all applicable periods expire.

12. Your Rights under POPIA

As a data subject under POPIA, you have rights that include (as applicable and subject to lawful limitations):

Access (section 23 POPIA)

You may request confirmation of whether we hold personal information about you, and request a description or record of that information, subject to POPIA and PAIA procedures where applicable.

Correction, destruction, or deletion (section 24 POPIA)

You may request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained.

Objection (section 11(3) POPIA)

You may object, on reasonable grounds, to processing based on legitimate interests or for direct marketing in the circumstances provided for in POPIA.

Withdraw consent

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing already lawfully carried out.

Direct marketing

You may opt out of electronic direct marketing at any time. We will honour unsubscribe requests in accordance with POPIA and the Consumer Protection Act where applicable.

Exercising your rights

To exercise these rights, contact our Information Officer at privacy@safeza.ai. We may request reasonable proof of identity before actioning a request, to prevent unauthorised disclosure.

13. Complaints

If you believe that your personal information has been processed unlawfully, please contact us first so we can attempt to resolve the matter. You also have the right to lodge a complaint with the Information Regulator (South Africa):

Information Regulator (South Africa)

JD House, 27 Stiemens Street

Braamfontein, Johannesburg, 2001

Website: inforegulator.org.za

Complaints: POPIAComplaints@inforegulator.org.za

14. Changes to this Policy

We may update this Privacy Policy from time to time to reflect legal, operational, or product changes. The current version is always published on this page with the "Last updated" date. Material changes will be communicated in an appropriate manner (for example by notice on our website or by email where we hold a current address for that purpose).

15. Questions and Contact

For questions, suggestions, or requests regarding privacy at SAFEZA AVA-X (PTY) LTD, please contact:

Information Officer

SAFEZA AVA-X (PTY) LTD

Email: privacy@safeza.ai

Postal correspondence:

attn. Information Officer
Kensington, Cape Town, 7405, South Africa

Related: GDPR, POPIA & AI Ethics

Closing note

This Privacy Policy explains how we handle personal information and reflects our commitment to responsible processing under South African law.

Unless otherwise stated, POPIA and related South African legislation govern the processing described here.

© 2026 SAFEZA AVA-X (PTY) LTD, All rights reserved.