Legal

Privacy Policy

Version
v1.3
Effective
Not yet effective

Private staging candidate — not yet effective or published.

Version: v1.3

Last updated: 28 September 2026

This Policy explains how Whisprr (Pty) Ltd, registration number 2026/405640/07, of 24 Woods Crescent, Eagle Canyon, Honeydew, Johannesburg, Gauteng 2170, South Africa ("Whisprr", "we", "us"), processes personal information. It is a notice under the Protection of Personal Information Act 4 of 2013 ("POPIA"), not blanket consent.

1. Scope and roles

1.1 This Policy applies to our website, sales and onboarding activities, accounts, dashboard, support and operation of the Whisprr service.

1.2 Whisprr is the responsible party for personal information used for its own account administration, contracting, billing, security, service improvement, sales and legal compliance.

1.3 When Whisprr processes a customer's contacts, conversation content or other personal information on that customer's documented instructions, the customer is ordinarily the responsible party and Whisprr is its operator. The Data Processing Terms govern that processing. A customer decides why it communicates with its contacts, what information and approved knowledge it supplies, and which workflows it enables.

1.4 This Policy does not govern an independent website, Meta/WhatsApp service, bank or other third party. Their own notices apply to their processing.

2. Information we process

Depending on the relationship and configuration, we process:

a. business and contact information, such as names, roles, company details, work contact details and correspondence;

b. account and authority information, including users, roles, credentials, invite and acceptance evidence;

c. service and conversation information, including message content and media, contact identifiers, approved knowledge, routing and escalation records, AI output, delivery status and channel metadata;

d. commercial and payment information, including the accepted Order, subscription and credit records, invoices, transaction status, limited payment-provider references and billing correspondence; we do not store raw card numbers or CVV;

e. technical, security and usage information, including IP address, device and browser information, timestamps, authentication events, logs, diagnostics, feature interactions and audit trails;

f. onboarding and support information, including configurations, lawful instructions, training material, requests and incident reports; and

g. compliance information, including consent and opt-out records, complaints, information-access requests, risk and fraud indicators, and records required by law.

We do not intentionally request special personal information or children's information for ordinary use. If a valid use case requires it, the customer must disclose it during scoping so that Whisprr can assess legality and safeguards before processing.

3. Sources

We obtain information directly from customers, their authorised users and contacts; from their configured systems and approved knowledge; from messaging, identity, payment and infrastructure providers; from service use and security logs; and from lawful public or commercial business sources used for sales or verification.

If information is not obtained directly from the person, the responsible party must provide any notice required by POPIA unless an exception applies.

4. Purposes and justification

We process information only where reasonably adequate, relevant and not excessive for a lawful purpose, including to:

a. evaluate a sales enquiry, verify authority and conclude or perform the Agreement;

b. configure, provide, route, secure, support and improve the Service;

c. generate approved AI-assisted replies, classifications, summaries and escalations;

d. administer accounts, subscriptions, Credits, payment verification and invoices;

e. detect abuse, fraud, compromise and technical faults and preserve audit evidence;

f. communicate about service, support, security and material legal changes;

g. respond to data-subject, PAIA, regulator and legal requests; and

h. create genuinely de-identified or aggregate operational insight.

Depending on the activity, the lawful justification may be consent, conclusion or performance of a contract, compliance with law, protection of a legitimate interest, or pursuit of a legitimate interest that does not unjustifiably prejudice the person. Where the customer is the responsible party, it determines the lawful justification for its processing and instructions.

5. AI and automated processing

5.1 Whisprr uses AI to answer approved factual questions, classify or reroute messages, prepare summaries and perform configured communication tasks. AI output may be wrong or incomplete. Human takeover and escalation are important safeguards, and customers must apply oversight appropriate to the risk.

5.2 Customer conversations do not automatically become approved knowledge. We do not use identifiable customer conversations to train a public or general-purpose AI model without a separate written lawful basis and arrangement.

5.3 Whisprr's standard service is not designed to make solely automated decisions that have legal or similarly significant effects on a person. Customers must not configure such a decision without prior written assessment and safeguards that satisfy section 71 of POPIA and other applicable law. A person may contact the relevant customer, or Whisprr where it is the responsible party, to request information and an appropriate human review.

6. Direct marketing and service communications

6.1 We may send necessary service, billing, security and contractual communications. These are not promotional merely because they concern the Service.

6.2 We send electronic direct marketing only where permitted, including with the required consent or within a lawful existing-customer relationship. We identify the sender and provide a functional opt-out. A person may object or unsubscribe at any time without charge. Customers using the Service for marketing remain responsible for lawful contact collection, consent or other permission, suppression records, content and channel rules.

7. Sharing and operators

We disclose information only as reasonably necessary to:

a. the customer and its authorised users;

b. contracted providers supporting cloud and database infrastructure, workflow automation, AI processing, dashboard or frontend infrastructure, business email and productivity, messaging and Meta services, payment processing, security, support and professional advice;

c. a buyer, investor or successor under appropriate confidentiality and only as lawfully required for a genuine transaction; and

d. regulators, law-enforcement bodies, courts or other persons where law requires or permits disclosure.

Providers receive only the access reasonably required for their function and must be bound by appropriate privacy, confidentiality and security duties. Whisprr maintains a private provider and subprocessor register. We disclose categories publicly and provide more specific information where legally or contractually required, while protecting security and proprietary architecture.

We do not sell personal information.

8. Cross-border processing

Some contracted providers or their support personnel may process information outside South Africa. Whisprr assesses cross-border processing and uses contractual or other lawful safeguards intended to satisfy section 72 of POPIA. The applicable location and safeguard may depend on the customer's configuration and provider region. Customers must identify any contractual or legal data-location restriction before activation.

9. Security and incidents

Whisprr maintains reasonable, appropriate technical and organisational safeguards having regard to the nature of the information, foreseeable risks and available measures. These include, as applicable, tenant separation and access controls, least privilege, authentication controls, encryption in transit and at rest where supported, logging, backup and recovery controls, secure change management, provider due diligence, vulnerability management and incident procedures.

No system is risk-free. If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, Whisprr will investigate, contain and notify the responsible party, Information Regulator and affected persons as required by law. When acting as operator, Whisprr notifies the customer under the Data Processing Terms so the customer can meet its duties.

10. Retention, export and deletion

10.1 Information is retained only as long as reasonably necessary for the purpose, the Agreement, a lawful instruction or a legal, accounting, security, fraud or dispute requirement.

10.2 A customer may request an available tenant-scoped export during the Service and for 30 calendar days after termination. This request window does not extend the deletion deadline.

10.3 Subject to lawful exceptions and information still needed for an active Service, Whisprr deletes or irreversibly de-identifies identifiable customer data in active systems as soon as reasonably practicable and no later than 60 days after termination or a valid deletion request.

10.4 Protected residual copies may remain in provider backups until the normal backup lifecycle expires. They are not used for ordinary processing, and deletion or de-identification is re-applied if a backup is restored.

10.5 Genuinely de-identified product-development data may be kept for up to 24 months, then deleted or further aggregated. Irreversible aggregate statistics that cannot reasonably identify a person may be retained longer. Acceptance, payment, accounting, security and legal records may be retained for their applicable lawful periods with restricted access.

11. Cookies and platform insights

Whisprr currently uses only cookies or similar storage reasonably necessary for authentication, security, session continuity and core functionality, together with limited platform-hosting or product insights that may be generated by the service infrastructure. Whisprr does not currently deploy Google Analytics, advertising pixels or cross-site behavioural advertising on its own service.

If Whisprr later introduces non-essential analytics or advertising technologies, it will first assess applicable notice and consent requirements and update the deployed controls and this Policy before use.

12. Your rights

Subject to POPIA and other applicable law, a person may:

a. ask whether Whisprr holds personal information about them and request access;

b. request correction, updating, deletion or destruction where the legal requirements are met;

c. object to processing on reasonable grounds where the statute permits;

d. withdraw consent for future processing where consent is the basis, without affecting prior lawful processing;

e. object to direct marketing at any time;

f. request information about a significant automated decision and an appropriate opportunity to make representations; and

g. complain to the Information Regulator or pursue another statutory remedy.

Where Whisprr acts only as operator, we ordinarily refer the request to the relevant customer and assist it as required. We may verify identity and authority and may refuse or restrict a request only on a lawful ground. Access to records may also be governed by PAIA; our PAIA Manual explains that process.

13. Children and special personal information

Customers may not intentionally use the standard Service to process children's information or special personal information unless the processing is lawful, within an approved use case and protected by additional safeguards agreed before activation. Whisprr may restrict processing that creates an unassessed legal or safety risk.

14. Changes

We may update this Policy to reflect law, providers or the Service. We will give reasonable notice of a material expansion of identifiable-information use and obtain renewed consent or acceptance where legally required. Earlier notices remain available where required for accountability.

15. Contact and complaints

Information Officer: Jordan Albertyn

Whisprr (Pty) Ltd, registration number 2026/405640/07

24 Woods Crescent, Eagle Canyon, Honeydew, Johannesburg, Gauteng 2170, South Africa

Email: jordan@whisprr.co.za

Information Regulator (South Africa): inforegulator.org.za. Current complaint forms and contact channels are available on the Regulator's official website.