Back to Sign Up
VizionSA BGIS · Privacy Governance
Terms of Service
Privacy Policy
POPIA COMPLIANT & PLATFORM CERTIFIED

Privacy Policy & Data Governance

Last updated: October 2024 · Governed under POPIA (Act 4 of 2013) & Global Data Privacy Standards

Core Data Privacy & Architectural Commitments
Zero Data Sale: We never sell personal information, messaging transcripts, or commercial records to third parties.
Cryptographic Matching: Sensitive identifiers (email, phone) are hashed via MD5/SHA-256 before Meta Conversions API transmission.
Tenant-Scoped Isolation: Each tenant operates in an isolated schema preventing any cross-tenant data exposure.

1. Scope & Statutory Commitment (POPIA & GDPR)

VizionSA Business Growth Intelligence System (BGIS) operates under strict compliance with the Protection of Personal Information Act (POPIA Act 4 of 2013) of the Republic of South Africa, alongside alignment with international privacy standards including the European Union General Data Protection Regulation (GDPR). This Policy governs how personal information, business telemetry, and communication metadata are ingested, processed, and safeguarded across our multi-tenant SaaS architecture.

For the purposes of POPIA, the Client (Tenant) acts as the Responsible Party (or Data Controller) regarding all end-customer records, customer conversations, and catalog transactions. VizionSA BGIS acts strictly as an Operator (or Data Processor), executing automated pipelines, data transformation, and reporting solely in accordance with the documented instructions and tenant configuration established by the Client.

2. Personal & Business Data We Process

In delivering autonomous marketing attribution, WhatsApp conversational routing, and multi-tenant portal synchronization, BGIS ingests and processes only the data strictly necessary for operational execution:

• User & Customer Identity: WhatsApp verified profile display names, international phone numbers (MSISDN), business representative names, and authenticated administrative email addresses.

• Interaction & Conversational Metadata: Inbound and outbound WhatsApp message IDs, delivery timestamps, read receipts, conversational status tags, and categorized enquiry intent (e.g. Quote Request, Service Booking, Support). Message content is processed in real time solely to execute automated logic or route to designated human advisors.

• Commerce & Transactional Records: Meta Commerce catalog IDs, SKU references, order totals, payment channels, Paystack transaction reference identifiers, and merchant settlement subaccount codes. BGIS never stores raw credit card details or bank card security codes (CVC/CVV).

• Operational Diagnostics: IP addresses, browser user-agent tokens, API endpoint execution logs, and n8n workflow execution traces required for platform uptime, fraud prevention, and audit accountability.

3. Technical Processing & Meta Conversions API Matching

BGIS features native integration with Meta Ads Manager via the server-side Meta Conversions API (CAPI) and Meta Pixel. When an end-customer interacts with a business advertisement, triggers a WhatsApp conversation, or completes an order, server-side telemetry synchronizes standardized commercial event signals back to Meta (including ViewContent, Lead, AddToCart, InitiateCheckout, and Purchase).

Cryptographic Hashing Guarantee (SHA-256 / MD5)

To preserve total end-customer privacy, all customer identifiers (such as phone numbers and email addresses) are cryptographically hashed using industry-standard SHA-256 and MD5 normalization algorithms prior to API dispatch. Raw plaintext phone numbers, personal identities, or unhashed contact details are never transmitted across public networks or shared with external advertising servers.

4. Automation & Integration Architecture

The BGIS platform orchestrates data across five verified operational endpoints: (a) WeWeb client portal interface; (b) dedicated n8n automation and server-side processing workflows; (c) Meta WhatsApp Business Cloud APIs; (d) Paystack automated direct settlement subaccounts; and (e) client-dedicated Notion operational workspaces.

Data routing across our automation engine is stateless wherever possible. Workflow memory buffers and transient payloads in n8n are cleared immediately following execution. Intermediate customer data is only written to designated client databases to maintain real-time telemetry, orders ledgering, and lead tracking.

5. Strict Zero-Sale Data Pledge & Limited Disclosures

OUR IRREVOCABLE PLEDGE: VizionSA has never sold, leased, rented, or monetized personal information, conversation transcripts, or commercial records to third-party data brokers, ad networks, or analytics aggregators. We never will.

Disclosures of information are strictly restricted to: (1) Verified infrastructure partners essential to service delivery (Meta Graph API, Paystack Financial Services, cloud hosting providers); (2) Delivery and logistics partners (such as Bob Go) solely when the tenant activates automated physical order fulfillment; and (3) Lawful statutory compliance when compelled by a valid court order or statutory mandate issued by South African judicial authorities.

6. Multi-Tenant Architecture & Bank-Grade Security

Security is foundational to the BGIS engineering standard. All network communications, inbound webhooks, and client portal sessions are encrypted in transit using TLS 1.3 protocol standards. Stored operational databases, configuration secrets, and access tokens are encrypted at rest using AES-256 cryptographic standards.

Logical tenant isolation is strictly enforced at every application layer. Each workspace operates with mandatory tenant_id constraints at the database, workflow, and API gateway levels. No client tenant has visibility into, nor access to, another tenant's customer records, WhatsApp communications, or financial settlement telemetry.

7. Data Retention & Automated Deletion Cycles

Client operational data, customer interaction logs, and order records are retained throughout the active duration of the client's subscription to ensure uninterrupted analytics and reporting.

Upon subscription termination or formal account closure, client tenant data enters a 30-day archival grace period during which the client may request a complete data export. Following this grace period, all tenant databases, webhook queues, access tokens, and associated telemetry are automatically and irreversibly purged from our active infrastructure, subject only to statutory tax or legal retention obligations under South African law.

8. Data Subject Rights under POPIA

Under the South African Protection of Personal Information Act (POPIA), data subjects (including our clients and their end-customers) are entitled to comprehensive legal rights regarding their personal information:

• Right to Access: You may request confirmation of whether we hold personal information about you and obtain a formal copy of such records.

• Right to Correction & Rectification: You may request the correction, rectification, or updating of inaccurate, irrelevant, excessive, or outdated information.

• Right to Erasure & Deletion: You may request the destruction or permanent deletion of your personal information where retention is no longer authorized.

• Right to Object to Processing: You have the right to object at any time, on reasonable grounds, to the processing of your personal information.

• Right to Lodge a Statutory Complaint: You have the right to lodge a complaint with the South African Information Regulator at inforeg@justice.gov.za or POPIAComplaints@inforegulator.org.za.

9. Formal Privacy & Deletion Inquiries

To exercise any of your statutory rights, submit a Data Subject Access Request (DSAR), or communicate directly with our appointed Information Officer, please utilize any of our official privacy contact channels below:

Official Privacy Emailhello@vizionsa.com
Privacy Hotline / WhatsApp+27 67 443 9606
Appointed Information OfficerVizionSA Compliance Office, Cape Town, ZA

© 2024 VizionSA BGIS. All rights reserved. Registered in the Republic of South Africa. POPIA Compliant.