Privacy Policy
This Privacy Policy explains how Audomize (Pty) Ltd ("Audomize", "we", "us" or "our") collects, uses, stores, shares and protects personal information. It also explains the privacy rights that may be available to you under applicable laws, including South Africa's Protection of Personal Information Act (POPIA), the EU General Data Protection Regulation (GDPR), the UK GDPR and, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Audomize is established in South Africa, and POPIA applies to our processing on that basis regardless of where you are located; other laws may also apply depending on your location and the channel we use to contact you. This policy is a notice: it explains how we process personal information, but it does not by itself create your consent to anything. Where we need consent, including for direct marketing by email, we ask for it separately, for the specific purpose and channel involved, and you can withdraw it at any time.
1. Who this policy applies to
This policy applies to personal information we process about:
- Website visitors who browse or interact with audomize.com.
- Prospective clients, leads and business contacts who contact us or whom we contact through channels such as email, LinkedIn, website forms, calls or scheduling tools.
- Clients and client team members who use our AI audit, consulting, automation, implementation or advisory services.
- Suppliers, contractors, collaborators and team members, where relevant.
Our services are business-to-business in nature. We do not intentionally market to consumers as a primary audience, although individual business contacts may still have privacy rights under applicable laws.
2. Personal information we collect
The exact information we collect depends on how you interact with us. We aim to collect only what is necessary for the relevant purpose.
- Contact and identification information: name, email address, phone number, job title, company name, company website, country or region and LinkedIn profile URL.
- Business and operational information: company size, industry, team structure, operational pain points, workflow details, systems currently used, discovery-call notes and stated goals.
- Service-related information: project scope, client preferences, audit findings, implementation notes, deliverables, support requests and correspondence.
- Business-contact and data-enrichment information: professional email address, business phone number or direct dial where obtained, verification status, the source of the information, and outreach or consent history, gathered to identify and contact relevant business contacts. See section 6 for how this is used.
- Billing and contract information: billing contact details, invoice details, payment status and basic accounting records. We do not store full credit card numbers on our own systems.
- Website and usage information: IP address, device and browser information, pages visited, approximate location, timestamps, referral source, cookie identifiers and analytics events.
- Team, contractor or supplier information: name, contact details, role, payment details and records needed for administration, contracts, tax or legal compliance.
We do not intentionally collect special categories of personal information such as health information, race or ethnicity, religious beliefs, biometric information or government identity numbers unless it is strictly necessary and lawfully permitted. Please do not send us sensitive information unless we specifically request it for a lawful purpose.
For email-based outreach, we do not intentionally seek out phone numbers. Where a business phone number is returned incidentally by an enrichment tool, we delete it unless a separate, channel-specific purpose has been approved.
3. How we collect personal information
- Directly from you: when you complete a form, book a call, email us, attend a call, provide project information or otherwise communicate with us.
- Through LinkedIn: when we identify relevant business contacts using LinkedIn and LinkedIn Sales Navigator, including public profile information such as role, employer and posting activity.
- Through business-contact and data-enrichment providers: when we use tools such as Hunter, and may also use tools such as Clay, to find or verify a professional email address, business phone number or company information. These tools may draw on their own underlying data providers, and the specific source of a given data point can vary.
- Through our website: when cookies, analytics or server logs collect technical information about how the website is used.
- Through service providers: for example, scheduling tools, email systems, CRM tools, cloud storage, analytics tools, payment processors or other systems we use to operate Audomize.
- From public sources or business partners: for example, company websites, public professional profiles, directories or referrals.
4. Why we use personal information
We use personal information for the following business and operational purposes:
- Lead management and CRM: to organise contacts, manage outreach, record call notes, schedule follow-ups and understand which businesses may benefit from Audomize services.
- Marketing and outreach: to assess whether a business contact is relevant, request consent to send information about Audomize services where required, and, only where consent is given or another lawful basis applies, send a limited sequence of messages about Audomize services, content, offers, events, resources or proposals.
- Service delivery: to perform AI audits, workflow assessments, automation builds, advisory work, reporting, implementation support and related consulting services.
- Client support and communication: to answer questions, schedule calls, provide updates and manage the client relationship.
- Billing, contracting and administration: to issue quotes, proposals, invoices and receipts, maintain accounting records and manage agreements.
- Website operation and improvement: to maintain site functionality, understand usage, improve user experience, measure content performance and protect the website.
- Security and fraud prevention: to detect, prevent and respond to unauthorised access, spam, misuse or other security risks.
- Legal compliance and dispute management: to meet legal obligations, respond to lawful requests, enforce agreements and protect our rights.
We do not use client project details for unrelated purposes, and we do not sell personal information.
5. Lawful bases for processing
Where a lawful basis is required, we rely on one or more of the following:
- Consent: where you actively agree to a specific activity, such as receiving certain marketing communications or allowing non-essential cookies. You can withdraw consent at any time.
- Contract performance: where processing is necessary to provide services, prepare proposals, manage a client relationship or take steps before entering into a contract.
- Legal obligation: where we must keep or process information for tax, accounting, regulatory, employment or other legal reasons.
- Legitimate interests: where we have a reasonable business interest, such as improving our services, protecting our systems, managing client relationships, or identifying and assessing the relevance of a business contact before we ask for consent to market to them, provided those interests are not overridden by your rights and freedoms. We do not rely on legitimate interests alone as permission to send unsolicited direct marketing by email.
For direct marketing by email to anyone who is not an existing client, we follow a consent-first approach in line with POPIA: we do not send a marketing email sequence unless the person has given consent, or a specific legal exception applies. Section 6 explains how this works in practice. For non-essential cookies or tracking technologies, we will seek consent where required.
6. Business contact outreach and consent
This section explains how we identify and contact potential business clients, and how consent works for that process.
How we identify contacts. We use LinkedIn and LinkedIn Sales Navigator to identify relevant business contacts, including public profile information such as role, employer and posting activity. We also use business-contact and data-enrichment tools such as Hunter, and may also use tools such as Clay, to find or verify a work email address, business phone number or company information. These tools may draw on their own underlying data providers.
Consent-first outreach. Audomize is established in South Africa and processes personal information under POPIA regardless of where a contact is located. For a person who is not already a client, we do not send an unsolicited email marketing sequence unless the person has given consent, or another valid legal exception applies. Where we approach a new contact, we may send a single message requesting consent to be sent further information, provided the person has not previously declined or already been asked. If the person does not consent, we do not send a follow-up marketing sequence.
Consent scope. Consent to receive email does not extend to phone calls, SMS, WhatsApp or LinkedIn messages for marketing purposes. Where UK GDPR applies, we may rely on legitimate interests for limited, proportionate preliminary B2B contact processing, subject to your right to object, but our default approach for cold outreach is the consent-first model described above.
Phone numbers. Our cold-outreach process is email-based. We do not intentionally collect phone numbers through enrichment tools for cold marketing. Where we already have an active relationship with a contact, for example someone who has replied to us or connected with us on LinkedIn, we may look up a phone number separately, including through tools such as Lusha or Apollo, to arrange a call at that person's request or invitation.
Email tracking. We do not use open or click tracking in our cold-outreach emails. We measure that process through replies, consent and opt-outs rather than pixel tracking.
Human review. We may use AI and workflow tools to help organise research, remove duplicates and draft outreach messages. A person reviews the contact's relevance and the message before anything is sent. See section 7 for more on our use of AI tools.
Your choices. You can decline a consent request, unsubscribe or object to marketing at any time. We stop marketing to you promptly and keep a minimal record, such as your email address and the date you opted out, so that we do not contact you again for that purpose. See section 14 for more on marketing opt-outs.
7. AI tools and automated decision-making
Audomize may use AI tools and automation systems to support internal work, client delivery and business operations. This may include tools that help summarise notes, analyse workflows, draft internal materials, organise CRM information, identify operational improvement opportunities or generate recommendations for human review.
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing without human review. Any AI-generated outputs used in client work, sales processes or internal decision-making are reviewed by a person before being relied on.
Where we use third-party AI or cloud tools that process personal information, we aim to use appropriate settings, contractual safeguards and access controls. We also avoid entering unnecessary sensitive personal information into AI tools.
8. Cookies and tracking technologies
Our website may use cookies, pixels, analytics tags and similar technologies. These help the website function, help us understand usage and, where relevant, support marketing measurement.
- Essential cookies: required for core website functionality and security.
- Analytics cookies: used to understand how visitors use the website, such as page views, traffic sources, device information and general performance metrics.
- Marketing cookies or pixels: used only where applicable to measure or improve advertising and outreach performance.
You can manage cookies through your browser settings and, where available, through our cookie banner or consent tool. Disabling cookies may affect some website features.
9. When we share personal information
We share personal information only where necessary and with appropriate safeguards. This may include sharing with:
- Email, cloud and collaboration providers: such as Google Workspace or similar services used for email, documents and file storage.
- Scheduling tools: such as Calendly or similar tools used to book calls.
- CRM, outreach and marketing tools: used to manage leads, outreach, newsletters, proposals and relationship records, including sending tools such as Hunter.
- Business-contact and data-enrichment providers: such as Hunter and, where used, Clay, which may supply or verify professional contact and company information. These providers may act as our service providers or as independent sources of data, depending on the service.
- Website hosting, analytics and security providers: used to host and protect our website and understand site usage.
- Payment, banking, accounting and invoicing providers: used to process payments, issue invoices and comply with financial obligations.
- Professional advisers: such as accountants, legal advisers or consultants, where needed and subject to confidentiality duties.
- Authorities or third parties where legally required: for example, if we receive a lawful request, court order or need to protect our rights or the safety of others.
Our service providers may process personal information only for authorised purposes and are expected to protect it appropriately. We do not authorise service providers to use personal information for their own unrelated marketing. Not every third party listed here acts purely as our processor; data-enrichment providers may independently source the information they supply to us.
10. International transfers
Audomize is based in South Africa, but we may work with clients internationally and use global cloud, communication, analytics, CRM, payment, hosting and data-enrichment services, such as Google Workspace, LinkedIn, Hunter and, where used, Clay. This means personal information may be processed in countries outside your country of residence.
Where required, we use appropriate safeguards for international transfers. These may include data processing agreements, standard contractual clauses, equivalent contractual protections, transfer assessments, consent where appropriate, or reliance on another lawful transfer mechanism available under applicable law.
We review our main service providers periodically and aim to use providers with appropriate privacy and security standards.
11. Security measures
We use reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. These measures may include:
- Access controls and limiting access to people and service providers who need it.
- Strong passwords, two-factor authentication and account permission management where available.
- Encryption in transit and encryption at rest where supported by our service providers.
- Use of reputable cloud and infrastructure providers with recognised security practices.
- Device security, software updates and anti-malware practices for work devices.
- Internal privacy awareness and careful handling of personal information.
- Incident response steps to investigate and respond to suspected data breaches.
No method of transmission or storage is completely secure. If you suspect that your interaction with us is no longer secure, please contact us immediately.
12. Data retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law. Our general retention approach is:
- Website analytics and usage data: generally up to 24 months, unless a shorter period is configured in the relevant tool or you opt out earlier.
- Business contacts who have not responded to a consent request: we generally delete detailed research and enrichment data within 90 days of the request. We keep a minimal record, such as your email address and the date and outcome of the request, for as long as reasonably necessary so that we do not ask again.
- Engaged prospects and business contacts: where you reply, book a call or otherwise enter a genuine conversation with us, we generally retain relevant records for up to 3 years from the last meaningful interaction, unless you ask us to delete the information earlier and no legal reason requires retention.
- Client records: generally at least 7 years after project completion where needed for tax, accounting, contractual, warranty, dispute or compliance purposes.
- Marketing lists: until you unsubscribe, withdraw consent or ask us to delete your information, subject to keeping minimal suppression records to honour opt-outs.
- Contractor, supplier and employment-related records: for the periods required by applicable tax, labour, contract or accounting laws.
- Technical logs and security records: for as long as needed to protect systems, investigate incidents and maintain service integrity.
When personal information is no longer needed, we will delete it, anonymise it or securely archive it where deletion is not immediately possible.
13. Your privacy rights
Depending on where you live and which laws apply, you may have some or all of the following rights:
- Access: ask whether we hold personal information about you and request a copy.
- Correction: ask us to correct inaccurate or incomplete information.
- Deletion: ask us to delete personal information where the law allows.
- Restriction: ask us to restrict or suspend processing in certain circumstances.
- Objection: object to processing based on legitimate interests, including certain direct marketing activities.
- Portability: ask for certain information in a commonly used, machine-readable format where applicable.
- Withdraw consent: withdraw consent where we rely on consent, without affecting prior lawful processing.
- Automated decision rights: ask for human review where applicable if a decision is made solely by automated processing and has legal or similarly significant effects.
- California rights, where applicable: know, access, correct, delete, opt out of sale or sharing, limit use of sensitive personal information and not be discriminated against for exercising privacy rights.
To exercise your rights, contact us at keenan@audomize.com. We may need to verify your identity before responding. We aim to respond within legally required timeframes, typically within 30 days for GDPR or POPIA requests and within 45 days for CCPA/CPRA requests where those laws apply.
14. Marketing choices and opt-outs
You can opt out of marketing communications at any time by using the unsubscribe option in an email, replying with an opt-out request or contacting us at keenan@audomize.com.
When you opt out, we stop marketing to you promptly and keep only the minimal information needed, such as your email address, to make sure we do not contact you again for that purpose. Opting out of one channel, for example email, applies across our marketing channels unless you tell us to limit it to that channel.
We may still send non-marketing messages where necessary, such as service updates, appointment confirmations, invoices, security notices or responses to your enquiries.
Audomize does not sell personal information. If our practices change in a way that triggers a legal opt-out right, we will update this policy and provide the required opt-out mechanism.
15. Children's privacy
Our website and services are aimed at businesses and are not directed to children. We do not knowingly collect personal information from children under 16. If we become aware that a child has provided personal information without appropriate consent, we will delete it where required by law.
16. Data breach notification
If we become aware of a data breach affecting personal information, we will investigate, contain the issue and take appropriate remedial steps. Where the law requires notification, we will notify affected individuals and/or relevant regulators within the applicable legal timeframe.
For example, where GDPR applies, certain breaches must be notified to a supervisory authority within 72 hours of becoming aware of the breach unless the breach is unlikely to result in a risk to individuals. Under POPIA, notification may be required to the Information Regulator and affected data subjects where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
17. Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, tools, legal obligations or data practices. The latest version will be linked from our website and will show the last updated date. If we make material changes, we will take reasonable steps to notify affected individuals where required.
18. Contact and complaints
Audomize (Pty) Ltd is registered in South Africa at 48 Camellia Avenue, Springfield Residential Estate, George, Western Cape, 6529, South Africa. For questions, complaints or privacy-rights requests, contact us at keenan@audomize.com. Our Information Officer is Keenan Lucas.
You may also have the right to complain to a relevant supervisory authority. In South Africa, this is the Information Regulator (South Africa). EU and UK individuals may contact their relevant EU supervisory authority or the UK Information Commissioner's Office. California residents may contact the California Privacy Protection Agency or the California Attorney General, where applicable. We will cooperate with applicable regulators and will make reasonable efforts to resolve privacy concerns directly with you first.