Privacy Policy
This Privacy Policy explains how Audomize (Pty) Ltd ("Audomize", "we", "us" or "our") collects, uses, stores, shares and protects personal information. It also explains the privacy rights that may be available to you under applicable laws, including South Africa's Protection of Personal Information Act (POPIA), the EU General Data Protection Regulation (GDPR), the UK GDPR and, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). This policy is intended to be transparent and practical. Where a specific law gives you stronger rights than this policy describes, we will honour the applicable legal requirement. Where we need consent, we will ask for it separately.
1. Who this policy applies to
This policy applies to personal information we process about:
- Website visitors who browse or interact with audomize.com.
- Prospective clients, leads and business contacts who contact us or whom we contact through channels such as email, LinkedIn, website forms, calls or scheduling tools.
- Clients and client team members who use our AI audit, consulting, automation, implementation or advisory services.
- Suppliers, contractors, collaborators and team members, where relevant.
Our services are business-to-business in nature. We do not intentionally market to consumers as a primary audience, although individual business contacts may still have privacy rights under applicable laws.
2. Personal information we collect
The exact information we collect depends on how you interact with us. We aim to collect only what is necessary for the relevant purpose.
- Contact and identification information: name, email address, phone number, job title, company name, company website, country or region and LinkedIn profile URL.
- Business and operational information: company size, industry, team structure, operational pain points, workflow details, systems currently used, discovery-call notes and stated goals.
- Service-related information: project scope, client preferences, audit findings, implementation notes, deliverables, support requests and correspondence.
- Billing and contract information: billing contact details, invoice details, payment status and basic accounting records. We do not store full credit card numbers on our own systems.
- Website and usage information: IP address, device and browser information, pages visited, approximate location, timestamps, referral source, cookie identifiers and analytics events.
- Team, contractor or supplier information: name, contact details, role, payment details and records needed for administration, contracts, tax or legal compliance.
We do not intentionally collect special categories of personal information such as health information, race or ethnicity, religious beliefs, biometric information or government identity numbers unless it is strictly necessary and lawfully permitted. Please do not send us sensitive information unless we specifically request it for a lawful purpose.
3. How we collect personal information
- Directly from you: when you complete a form, book a call, email us, attend a call, provide project information or otherwise communicate with us.
- Through business outreach: when we identify and contact relevant business prospects through tools such as LinkedIn, LinkedIn Sales Navigator, email and publicly available business information.
- Through our website: when cookies, analytics or server logs collect technical information about how the website is used.
- Through service providers: for example, scheduling tools, email systems, CRM tools, cloud storage, analytics tools, payment processors or other systems we use to operate Audomize.
- From public sources or business partners: for example, company websites, public professional profiles, directories or referrals.
4. Why we use personal information
We use personal information for the following business and operational purposes:
- Lead management and CRM: to organise contacts, manage outreach, record call notes, schedule follow-ups and understand which businesses may benefit from Audomize services.
- Marketing and outreach: to communicate with relevant business contacts about Audomize services, content, offers, events, resources or proposals, subject to applicable marketing laws and opt-out rights.
- Service delivery: to perform AI audits, workflow assessments, automation builds, advisory work, reporting, implementation support and related consulting services.
- Client support and communication: to answer questions, schedule calls, provide updates and manage the client relationship.
- Billing, contracting and administration: to issue quotes, proposals, invoices and receipts, maintain accounting records and manage agreements.
- Website operation and improvement: to maintain site functionality, understand usage, improve user experience, measure content performance and protect the website.
- Security and fraud prevention: to detect, prevent and respond to unauthorised access, spam, misuse or other security risks.
- Legal compliance and dispute management: to meet legal obligations, respond to lawful requests, enforce agreements and protect our rights.
We do not use client project details for unrelated purposes, and we do not sell personal information.
5. Lawful bases for processing
Where a lawful basis is required, we rely on one or more of the following:
- Consent: where you actively agree to a specific activity, such as receiving certain marketing communications or allowing non-essential cookies. You can withdraw consent at any time.
- Contract performance: where processing is necessary to provide services, prepare proposals, manage a client relationship or take steps before entering into a contract.
- Legal obligation: where we must keep or process information for tax, accounting, regulatory, employment or other legal reasons.
- Legitimate interests: where we have a reasonable business interest, such as improving our services, protecting our systems, managing client relationships or conducting proportionate B2B outreach, provided those interests are not overridden by your rights and freedoms.
For direct marketing, we will provide a clear way to opt out. For non-essential cookies or tracking technologies, we will seek consent where required.
6. AI tools and automated decision-making
Audomize may use AI tools and automation systems to support internal work, client delivery and business operations. This may include tools that help summarise notes, analyse workflows, draft internal materials, organise CRM information, identify operational improvement opportunities or generate recommendations for human review.
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing without human review. Any AI-generated outputs used in client work, sales processes or internal decision-making are reviewed by a person before being relied on.
Where we use third-party AI or cloud tools that process personal information, we aim to use appropriate settings, contractual safeguards and access controls. We also avoid entering unnecessary sensitive personal information into AI tools.
7. Cookies and tracking technologies
Our website may use cookies, pixels, analytics tags and similar technologies. These help the website function, help us understand usage and, where relevant, support marketing measurement.
- Essential cookies: required for core website functionality and security.
- Analytics cookies: used to understand how visitors use the website, such as page views, traffic sources, device information and general performance metrics.
- Marketing cookies or pixels: used only where applicable to measure or improve advertising and outreach performance.
You can manage cookies through your browser settings and, where available, through our cookie banner or consent tool. Disabling cookies may affect some website features.
8. When we share personal information
We share personal information only where necessary and with appropriate safeguards. This may include sharing with:
- Email, cloud and collaboration providers: such as Google Workspace or similar services used for email, documents and file storage.
- Scheduling tools: such as Calendly or similar tools used to book calls.
- CRM, outreach and marketing tools: used to manage leads, outreach, newsletters, proposals and relationship records.
- Website hosting, analytics and security providers: used to host and protect our website and understand site usage.
- Payment, banking, accounting and invoicing providers: used to process payments, issue invoices and comply with financial obligations.
- Professional advisers: such as accountants, legal advisers or consultants, where needed and subject to confidentiality duties.
- Authorities or third parties where legally required: for example, if we receive a lawful request, court order or need to protect our rights or the safety of others.
Our service providers may process personal information only for authorised purposes and are expected to protect it appropriately. We do not authorise service providers to use personal information for their own unrelated marketing.
9. International transfers
Audomize is based in South Africa, but we may work with clients internationally and use global cloud, communication, analytics, CRM, payment and hosting services. This means personal information may be processed in countries outside your country of residence.
Where required, we use appropriate safeguards for international transfers. These may include data processing agreements, standard contractual clauses, equivalent contractual protections, transfer assessments, consent where appropriate, or reliance on another lawful transfer mechanism available under applicable law.
We review our main service providers periodically and aim to use providers with appropriate privacy and security standards.
10. Security measures
We use reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. These measures may include:
- Access controls and limiting access to people and service providers who need it.
- Strong passwords, two-factor authentication and account permission management where available.
- Encryption in transit and encryption at rest where supported by our service providers.
- Use of reputable cloud and infrastructure providers with recognised security practices.
- Device security, software updates and anti-malware practices for work devices.
- Internal privacy awareness and careful handling of personal information.
- Incident response steps to investigate and respond to suspected data breaches.
No method of transmission or storage is completely secure. If you suspect that your interaction with us is no longer secure, please contact us immediately.
11. Data retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law. Our general retention approach is:
- Website analytics and usage data: generally up to 24 months, unless a shorter period is configured in the relevant tool or you opt out earlier.
- Prospective leads and business contacts: generally up to 3 years from the last meaningful interaction, unless you ask us to delete the information earlier and no legal reason requires retention.
- Client records: generally at least 7 years after project completion where needed for tax, accounting, contractual, warranty, dispute or compliance purposes.
- Marketing lists: until you unsubscribe, withdraw consent or ask us to delete your information, subject to keeping minimal suppression records to honour opt-outs.
- Contractor, supplier and employment-related records: for the periods required by applicable tax, labour, contract or accounting laws.
- Technical logs and security records: for as long as needed to protect systems, investigate incidents and maintain service integrity.
When personal information is no longer needed, we will delete it, anonymise it or securely archive it where deletion is not immediately possible.
12. Your privacy rights
Depending on where you live and which laws apply, you may have some or all of the following rights:
- Access: ask whether we hold personal information about you and request a copy.
- Correction: ask us to correct inaccurate or incomplete information.
- Deletion: ask us to delete personal information where the law allows.
- Restriction: ask us to restrict or suspend processing in certain circumstances.
- Objection: object to processing based on legitimate interests, including certain direct marketing activities.
- Portability: ask for certain information in a commonly used, machine-readable format where applicable.
- Withdraw consent: withdraw consent where we rely on consent, without affecting prior lawful processing.
- Automated decision rights: ask for human review where applicable if a decision is made solely by automated processing and has legal or similarly significant effects.
- California rights, where applicable: know, access, correct, delete, opt out of sale or sharing, limit use of sensitive personal information and not be discriminated against for exercising privacy rights.
To exercise your rights, contact us at keenan@audomize.com. We may need to verify your identity before responding. We aim to respond within legally required timeframes, typically within 30 days for GDPR or POPIA requests and within 45 days for CCPA/CPRA requests where those laws apply.
13. Marketing choices and opt-outs
You can opt out of marketing communications at any time by using the unsubscribe option in an email, replying with an opt-out request or contacting us at keenan@audomize.com.
We may still send non-marketing messages where necessary, such as service updates, appointment confirmations, invoices, security notices or responses to your enquiries.
Audomize does not sell personal information. If our practices change in a way that triggers a legal opt-out right, we will update this policy and provide the required opt-out mechanism.
14. Children's privacy
Our website and services are aimed at businesses and are not directed to children. We do not knowingly collect personal information from children under 16. If we become aware that a child has provided personal information without appropriate consent, we will delete it where required by law.
15. Data breach notification
If we become aware of a data breach affecting personal information, we will investigate, contain the issue and take appropriate remedial steps. Where the law requires notification, we will notify affected individuals and/or relevant regulators within the applicable legal timeframe.
For example, where GDPR applies, certain breaches must be notified to a supervisory authority within 72 hours of becoming aware of the breach unless the breach is unlikely to result in a risk to individuals. Under POPIA, notification may be required to the Information Regulator and affected data subjects where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
16. Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, tools, legal obligations or data practices. The latest version will be linked from our website and will show the last updated date. If we make material changes, we will take reasonable steps to notify affected individuals where required.
17. Contact and complaints
For questions, complaints or privacy-rights requests, contact Audomize at keenan@audomize.com. Our Information Officer is Keenan Lucas.
You may also have the right to complain to a relevant supervisory authority. In South Africa, this is the Information Regulator (South Africa). EU and UK individuals may contact their relevant EU supervisory authority or the UK Information Commissioner's Office. California residents may contact the California Privacy Protection Agency or the California Attorney General, where applicable. We will cooperate with applicable regulators and will make reasonable efforts to resolve privacy concerns directly with you first.