Legal

Privacy Policy

How AgileGypsy Labs collects, processes, stores, and protects your personal information under the Protection of Personal Information Act 4 of 2013 (“POPIA”) and the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”).

Effective Date: 31 March 2026 · Version 2.0

01

Responsible Party and Information Officer

For the purposes of POPIA, the “responsible party” controlling the processing of your personal information is:

ECTA Section 43 Mandatory Disclosures

Legal Entity:AGILEGYPSY LABS PTY LTDRegistration No.:2026/270871/07VAT Status:Not currently registered (below the R2.3 million compulsory threshold effective 1 April 2026)Street Address:125 Benoni Road, Rynfield AH, Benoni, 1501, Gauteng, South AfricaInformation Officer:John WellardContact Email:john@agilegypsy.comWebsite:agilegypsy.comInfo Regulator Ref:2026-005090IO Appointed:John Wellard — 2026-03-31 (cert issued 2026-04-01)
02

Scope & Application

This Privacy Policy applies to all personal information processed by AGILEGYPSY LABS PTY LTD in connection with the AgileGypsy Labs website (agilegypsy.com), our engineering and consulting services, our pre-engineered AI products, and the Company's other brands and websites — including KTHULHU (kthulhu.co) and Art of Zeta (artofzeta.com) — except where a brand publishes its own product-specific privacy policy (for example, Kointel at kointel.co.za/legal/privacy), in which case that policy governs the product and this policy applies to everything else. It applies to all users and clients, including juristic persons as defined in Section 3 of POPIA.

By creating an account, engaging our services, or otherwise submitting personal information to us, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please do not use our services.

03

Information We Collect (POPIA Section 18 Notification)

In accordance with Section 18 of POPIA, we inform you that we collect the following categories of personal information. The supply of this information is voluntary; however, failure to provide certain data may prevent us from responding to your enquiry, creating an account, or delivering services.

CategorySpecific Data ElementsPurposeLawful Basis
Contact DataName, email address, message content submitted via contact forms or email.To respond to enquiries, proposals, and service requests.Legitimate Interest (POPIA Section 11(1)(f))
Account DataFull name, email address, hashed password (PBKDF2-SHA256 with unique salt) where an account is created for a product or client portal.Account creation, authentication, password recovery, service communications.Contract (POPIA Section 11(1)(b))
Service / Project DataProject briefs, technical specifications, source code, knowledge-base content, and related materials shared during an engagement or ingested into an AI product on your instruction.Delivery of engineering, consulting, and AI-product services.Contract (POPIA Section 11(1)(b))
Payment DataSubscription tier, payment date, transaction reference (via our payment gateway). We do not receive, store or process your credit/debit card numbers.Subscription management, billing, financial reconciliation.Contract (POPIA Section 11(1)(b))
Technical and Device DataIP address, browser type and version, operating system, device identifiers, referring URL, pages visited, click data, session duration.Security monitoring, fraud prevention, performance analytics, troubleshooting.Legitimate Interest (POPIA Section 11(1)(f))
Communication DataEmails, support requests, and any correspondence you send to us.To respond to your enquiries, improve our service, maintain records.Legitimate Interest (POPIA Section 11(1)(f))

We collect information directly from you (when you contact us, register, or share project materials) and indirectly through technical mechanisms (cookies, server logs). We do not collect personal information from third-party sources without your knowledge.

Additional Section 18 Disclosures:

Your personal information may be transferred internationally to our operators listed in Section 7 and as described in Section 8 (International Data Transfers). You have the right to object to any processing of your personal information on reasonable grounds (see Section 12). If you are dissatisfied with how we handle your data, you have the right to lodge a complaint with the Information Regulator (see Section 18).

04

Purpose Limitation and Lawful Basis (POPIA Conditions 2 and 3)

We process your personal information only for the specific, explicitly defined, and lawful purposes listed in Section 3 above. We rely on the following lawful grounds:

  • Contractual Necessity (Section 11(1)(b)): Processing is necessary to perform our contractual obligations to you.
  • Legitimate Interest (Section 11(1)(f)): Processing is necessary for our legitimate interests (security, fraud prevention, service improvement), provided your rights do not override those interests.
  • Legal Obligation (Section 11(1)(c)): Where we are required by law to retain or disclose information.
  • Consent (Section 11(1)(a)): Where required (e.g., optional marketing), processing is based on your freely given, specific, and informed consent, which you may withdraw at any time.

We will not process your personal information for a purpose incompatible with the original collection purpose, unless we obtain your explicit consent or are compelled by law (POPIA Condition 4 — Further Processing Limitation).

05

Accountability (POPIA Condition 1)

AGILEGYPSY LABS PTY LTD accepts responsibility as the responsible party for ensuring that the conditions for lawful processing set out in POPIA are complied with at the time of the determination of the purpose and means of processing, and during the processing itself. We have appointed an Information Officer (John Wellard) to oversee compliance, respond to data subject requests, and liaise with the Information Regulator.

06

Automated Decision-Making and AI Systems (POPIA Section 71)

Our pre-engineered AI products and custom AI solutions employ automated AI components (large language models served via providers listed in Section 7) to generate outputs such as answers, classifications, summaries, qualifications, and recommendations based on the data you or your organisation supply.

Your Rights Under POPIA Section 71

Section 71 of POPIA protects you against decisions made solely by automated means which have legal or similarly significant consequences. Outputs generated by our AI systems are suggestions and drafts only — not binding determinations. You (and, where applicable, your organisation) retain the right to:

  • Review any AI-generated output before acting on it.
  • Override, correct, or reject any automated output.
  • Request human intervention or an explanation of the system's reasoning.
  • Request sufficient information about the underlying logic of the automated processing to enable you to make informed representations, as required by POPIA Section 71.

Important: AI Output Disclaimer

All data, calculations, classifications, and outputs produced by our AI systems are provided for informational purposes only. All outputs are generated by automated software and artificial intelligence systems that are inherently subject to errors, miscalculations, and misclassifications. It is your sole duty and responsibility to independently verify every element of any output for accuracy, correctness, completeness, and validity before relying on it for any purpose.

07

Third-Party Disclosures and Operators

We do not sell, rent, lease, or trade your personal information to any third party. We share data only with trusted “operators” (as defined in POPIA Section 1) who process information on our behalf under binding contractual agreements (POPIA Section 21) that require equivalent data-protection standards. In accordance with POPIA Section 18(1)(e), where our named operators change as products and engagements evolve, recipients are disclosed by category; the current named list is maintained by the Information Officer and reflected below and in our PAIA & POPIA Manual:

OperatorPurposeData SharedLocation
Cloudflare, Inc.Edge hosting, database (D1), KV caching, R2 file storage, Vectorize, Workers AI inference, CDN delivery, DDoS protection — all brands.Encrypted account, project, and session data.Global edge (nearest PoP)
Neon, Inc.Serverless Postgres database hosting for the KTHULHU application.Encrypted user account and application data.United States / EU
AI / ML providers — Google (Gemini), Anthropic (Claude), OpenAI, Voyage AIAI inference and embeddings for product features and agent pipelines across our brands.Anonymised / pseudonymised inputs where avoidable. Data is not used to train public models.United States / EU
PayFast (Pty) LtdProcessing ZAR subscription payments (Kointel).Email address and payment reference only. Card details are processed solely by the gateway.South Africa
Stitch Money (Pty) LtdProcessing product billing on agilegypsy.com (at product launch).Email address and payment reference only.South Africa
Forward Email LLCEmail delivery and forwarding for our domains.Email addresses and message content.United States

We may also disclose personal information when legally compelled by a South African court order, subpoena, or statutory requirement, or to prevent fraud or criminal activity.

08

International Data Transfers (POPIA Section 72)

Your personal information may be transferred to, and processed in, countries outside of South Africa. In accordance with Section 72 of POPIA, we ensure that any cross-border data transfer is protected by at least one of the following safeguards:

  • The recipient country has adequate data-protection legislation (e.g., EU GDPR).
  • Binding corporate rules or contractual clauses providing equivalent protection are in place.
  • You have given your consent after being informed of the potential risks.
  • The transfer is necessary for the performance of our contract with you.
09

Data Security Safeguards (POPIA Condition 7)

We implement appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of your personal information. Our security framework includes:

  • Encryption in Transit: All data is encrypted using TLS 1.3 via Cloudflare's edge network.
  • Encryption at Rest: Database records and stored files are held in encrypted Cloudflare D1 and R2 volumes.
  • Password Security: PBKDF2-SHA256, 100,000 iterations, unique cryptographically random salts, constant-time comparison.
  • Session Tokens: Short-lived, HTTP-only, Secure, SameSite JWT cookies immune to XSS extraction.
  • Access Controls: All API endpoints enforce authentication middleware. Clients can only access their own data.
  • Rate Limiting: KV-backed rate limiting to prevent brute-force and denial-of-service attacks.
10

Data Breach Notification (POPIA Section 22)

In the event of a security compromise where there are reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will:

  • Notify the Information Regulator as soon as reasonably possible after discovery, using the prescribed Security Compromise Notification process — currently submitted via the Regulator's eServices Portal (eservices.inforegulator.org.za).
  • Notify affected data subjects by email or public notice, as prescribed by Section 22(5) of POPIA.
  • Include in the notification: (a) a description of the possible consequences of the compromise; (b) a description of the measures we have taken or intend to take to address the compromise; (c) a recommendation regarding the measures you can take to mitigate the potential adverse effects; and (d) if known, the identity of the unauthorised person who may have accessed or acquired the information.
  • Maintain a register of all data breaches for accountability and regulatory reporting purposes.
11

Data Retention and Disposal (POPIA Section 14)

We retain your personal information only for as long as it is necessary to fulfil the purposes for which it was collected, or as required by law:

  • Contact enquiries: Retained for a maximum of 2 years from last correspondence, unless a longer retention is required for an ongoing engagement.
  • Active accounts and engagements: Account, project, and product data is retained for the duration of the active engagement or subscription.
  • Account deletion: If you delete your account or terminate an engagement, associated data is permanently purged from our primary databases and edge caches within 30 days.
  • Backup archives: Encrypted backup archives are rotated and destroyed within 90 days of deletion.
  • Legal obligations: Where South African law requires us to retain records for a specified period, we will retain the minimum required data for the minimum required period.
12

Data Subject Rights (POPIA Sections 23–25)

Under POPIA, you are entitled to the following rights:

  • Right of Access (Section 23): Request a copy of the personal information we hold about you.
  • Right to Rectification (Section 24): Request correction of inaccurate, irrelevant, excessive, outdated, incomplete, misleading, or unlawfully obtained personal information.
  • Right to Erasure (Section 24): Request deletion of your personal information when it is no longer necessary for the purpose for which it was collected.
  • Right to Object (Section 11(3)): You may object to the processing of your personal information on reasonable grounds relating to your particular situation, unless legislation permits such processing.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time. Withdrawal does not affect prior lawful processing.
  • Right Not to be Subject to Automated Decisions (Section 71): See Section 6 above.

To exercise any of these rights, send a written request to our Information Officer at john@agilegypsy.com. We will respond within 30 days as required by POPIA. We may request identity verification. Prescribed objection and correction forms are described in our POPIA Compliance page.

13

Special Personal Information (POPIA Section 26)

We do not collect or process special personal information as defined in Section 26 of POPIA, including information relating to religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour. If we ever need to process special personal information in the future, we will do so only with your explicit consent or as authorised by law, and this policy will be updated accordingly.

14

Children's Data (POPIA Section 35)

Our services are not designed for, or directed at, children under the age of 18 years. We do not knowingly collect personal information from minors. If we become aware that a child under 18 has provided us with personal information without verifiable parental or guardian consent, we will take immediate steps to delete such information and terminate any associated account.

15

Direct Marketing (POPIA Section 69)

We may send you essential transactional communications (service updates, security alerts, billing notifications). These are not direct marketing and do not require separate consent.

If we wish to send promotional or marketing communications by unsolicited electronic communication, we will obtain your express prior consent as required by Section 69(2) of POPIA, using the prescribed Form 4 (or a substantially similar form) under Regulation 6 of the POPIA Regulations. A failure to opt out does not constitute consent — we rely on explicit opt-in only. You may opt out at any time via the unsubscribe link or by contacting us directly.

Existing Customer Exemption (Section 69(2)):

If you are an existing customer and we obtained your contact details in the context of your purchase of a service or subscription, we may send you marketing communications about our own similar products or services, provided that: (a) you were given a reasonable opportunity to object at the time your details were collected; (b) you are given an easy, free opt-out mechanism in every communication; and (c) the communication clearly identifies us as the sender. You may opt out at any time, and we will cease such communications within 5 business days.

16

Cookies and Tracking Technologies (ECTA)

We use strictly necessary cookies required for the platform to function:

CookieTypePurposeExpiry
access_tokenStrictly NecessaryMaintains your authenticated session where an account is used. HTTP-only, Secure, SameSite=Strict flags prevent XSS/CSRF attacks.15 minutes
refresh_tokenStrictly NecessarySilently renews your authenticated session. HTTP-only, Secure, SameSite=Strict, restricted to the authentication path.7 days
kointel_refFunctionalAttributes a visit to a referral link so we can honour partner referrals. (Legacy cookie name retained for continuity.)30 days

We do not use third-party advertising cookies, tracking pixels, or re-targeting technologies. Our analytics (Plausible) are cookieless and privacy-first.

17

Information Quality (POPIA Condition 5)

We take reasonably practicable steps to ensure personal information in our possession is complete, accurate, not misleading, and updated where necessary. You are responsible for ensuring that the data and materials you provide are accurate and current. You may request an update to your information at any time by contacting the Information Officer.

18

The Information Regulator

If you believe we are processing your personal information unlawfully, or are unsatisfied with our response to a privacy request, you have the right to lodge a complaint with the Information Regulator:

The Information Regulator (South Africa)

Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Postal Address: P.O Box 31533, Braamfontein, Johannesburg, 2017

General Enquiries: inquiries@inforegulator.org.za

POPIA Complaints: POPIAComplaints@inforegulator.org.za

PAIA Complaints: PAIAComplaints@inforegulator.org.za

19

Promotion of Access to Information Act (PAIA)

In terms of Section 32 of the Constitution and the Promotion of Access to Information Act 2 of 2000 (“PAIA”), you have the right to request access to records held by AGILEGYPSY LABS PTY LTD.

PAIA Section 51 Manual:

Our PAIA Section 51 Manual is published and available at agilegypsy.com/legal/paia-manual. It details: (a) our contact details and Information Officer; (b) categories of records held; (c) the SAHRC's guide on how to use PAIA; (d) categories of records automatically available; (e) applicable legislation; and (f) the prescribed procedure for requesting access.

Requests for access to records should be directed to the Information Officer at john@agilegypsy.com.

20

Amendments to this Policy

We may update this Privacy Policy from time to time. When we make material changes:

  • We will provide at least 14 days' advance notice via email and/or website notification.
  • The Effective Date and Version number at the top of this page will be updated.
  • If you disagree with the changes, you may terminate your account or engagement before the new policy takes effect.
  • Continued use of our services after the effective date constitutes acceptance of the updated policy.

Contact the Information Officer

AgileGypsy Labs (Pty) Ltd
CIPC Registration No: 2026/270871/07
Information Regulator Reference: 2026-005090
Registered Office: 125 Benoni Road, Rynfield AH, Benoni, Gauteng, 1501
Information Officer: John Wellard
Email: john@agilegypsy.com

© 2026 AGILEGYPSY LABS PTY LTD. All rights reserved.
This Privacy Policy is written in plain, understandable language in compliance with the Consumer Protection Act, Section 22.