POPIA Notice
Our notification under section 18 of the Protection of Personal Information Act, and how we build POPIA compliance into the systems we deliver.
SECTION 01Why this notice exists
The Protection of Personal Information Act 4 of 2013 gives people control over how organisations handle information about them. Section 18 requires a responsible party to tell you certain things when it collects your personal information.
This notice is that notification. It also explains, in section 13 below, how we apply POPIA to the automation systems we build for clients — which is a question prospective clients ask us often.
This notice sits alongside our Privacy Policy, which covers the same processing in more detail, and our Terms & Conditions. Where this notice is silent, the Privacy Policy applies.
SECTION 02Responsible party
Company registration number: 2023/534929/07
20 Air Street, 3rd Floor, Johannesburg, Gauteng, 2001, South Africa
Email: info@gridloop.ai
Telephone: +27 71 604 3335
SECTION 03Information Officer
POPIA makes the head of a private body its Information Officer by default. That person is accountable for our compliance, for dealing with requests from data subjects and from the Regulator, and for ensuring a compliance framework is in place.
Email: info@gridloop.ai (mark your message “Information Officer”)
Postal: 20 Air Street, 3rd Floor, Johannesburg, Gauteng, 2001
Registration with the Information Regulator is in progress. Until it is confirmed, requests and complaints should be sent to the Information Officer at the address above.
SECTION 04What we collect and from where
We collect personal information directly from you in almost every case — when you fill in our contact form, book a consultation, email or call us, meet with us, or become a client.
POPIA section 12 lets us collect from another source in limited circumstances. Where we do, it will be from:
- a public record, or information you have deliberately made public — for example a professional profile on LinkedIn or a company website;
- your employer or a colleague, where they give us your work contact details so we can deliver services to that business;
- a referrer, where someone introduces you to us with your knowledge.
The categories we process are set out in section 3 of our Privacy Policy. In summary: identity and contact details, employment and business details, the content of your communications with us, billing and payment details, website technical data, and recruitment information where you apply to us.
We do not deliberately collect special personal information or the personal information of children.
SECTION 05Purpose and lawful basis
We process personal information to respond to enquiries, arrange and hold consultations, prepare proposals, deliver and support our services, invoice and collect payment, keep statutory records, secure our website, recruit, and where permitted to market our services.
Each purpose is justified under POPIA section 11 by consent, by the necessity of performing or entering a contract, by a legal obligation, or by our legitimate interests. The full purpose-by-purpose table is in section 4 of our Privacy Policy.
We do not use personal information for a new purpose incompatible with the one we collected it for, without telling you or obtaining consent.
SECTION 06Whether supply is voluntary or mandatory
Section 18(1)(e) of POPIA requires us to tell you whether you have to give us information, and what happens if you do not.
| Situation | Status and consequence |
|---|---|
| Browsing this website | Voluntary. You need give us nothing. Server logs record technical data automatically. |
| Contact form | Voluntary, but name, email and a message are needed. Without them we cannot reply to you. |
| Booking a consultation | Voluntary, but a name, email and time slot are needed to create the appointment and send the invite. |
| Becoming a client | Required by contract. Without contact, billing and signatory details we cannot contract with you, invoice you or deliver services. |
| Invoicing and tax records | Required by law. The Companies Act, the Value Added Tax Act and the Tax Administration Act oblige us to keep certain records. |
| Job applications | Voluntary, but we cannot consider an application without the information requested. |
SECTION 07Recipients and operators
We share personal information with a limited set of service providers, each acting as our operator under POPIA sections 20 and 21, under a written agreement requiring them to process only on our instructions and to secure the information.
The categories are: our cloud and productivity provider (Google), our web host, our email provider, AI model providers where an AI feature is enabled, and our accountants, bankers, attorneys and insurers. The detail is in section 6 of our Privacy Policy.
We do not sell personal information, and we do not make it available to third parties for their own marketing.
SECTION 08Cross-border transfers
Section 18(1)(g) requires us to tell you when we intend to transfer information to another country, and what level of protection applies there.
We do transfer personal information outside South Africa — principally to the United States and the European Union, through Google and other cloud providers. We rely on the grounds in POPIA section 72: binding agreements imposing substantially similar protection, necessity for a contract with you, or your consent.
You may ask our Information Officer which providers are involved in a particular piece of processing, and in which countries they hold data.
SECTION 09The eight conditions for lawful processing
POPIA sets out eight conditions. This is how we meet them.
| Condition | How we meet it |
|---|---|
| 1. Accountability | A named Information Officer is accountable for compliance, supported by internal policies and operator agreements. |
| 2. Processing limitation | We process lawfully, minimally, and for a justified purpose; we collect directly from you wherever practicable; you may object or withdraw consent. |
| 3. Purpose specification | We collect for the specific, explicitly defined purposes in section 5, and delete or de-identify when the retention period ends. |
| 4. Further processing limitation | Any further processing must be compatible with the original purpose, or we obtain consent. |
| 5. Information quality | We take reasonable steps to keep information complete, accurate and current, and act on correction requests. |
| 6. Openness | This notice, our Privacy Policy and our PAIA manual document what we do, and we notify you as section 18 requires. |
| 7. Security safeguards | Technical and organisational measures under section 19, operator agreements under sections 20 and 21, and breach notification under section 22. |
| 8. Data subject participation | You may request access, correction or deletion, and we respond within the timelines in section 10 below. |
SECTION 10Your rights as a data subject
You have the rights listed in section 11 of our Privacy Policy — to be told what we hold, to receive a copy, to have information corrected or deleted, to object, to withdraw consent, to be free of unsolicited direct marketing, not to be subject to a purely automated decision, and to complain.
How to make a request
- Email info@gridloop.ai with “Data subject request” in the subject line, or write to our Information Officer.
- For a formal access request, use Form 2 of the POPIA regulations. To object to processing, or to request correction or deletion, use Form 3. Both are available at inforegulator.org.za, or from us on request.
- We acknowledge within about 5 working days and verify your identity.
- We respond substantively within 30 days, extendable once by up to 30 days for a complex request, with reasons.
- If we refuse, we explain why and how you can challenge it.
There is no charge, except the prescribed fee for copies in response to an access request. We will tell you the amount before proceeding.
SECTION 11Security compromises
Section 22 of POPIA requires notification where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.
If that happens, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, unless a public body responsible for criminal investigation asks us to delay. Our notification will describe the possible consequences, the measures we have taken or intend to take, what we recommend you do to mitigate harm, and the identity of the unauthorised person if we know it.
We maintain an internal incident procedure covering detection, containment, assessment, notification and review.
SECTION 12Direct marketing
Section 69 of POPIA restricts unsolicited electronic direct marketing. We will send you marketing about our services only where:
- you have consented, or
- you are an existing customer, we obtained your details in the course of a sale, the marketing relates to similar services, and you have been given a reasonable opportunity to opt out.
Every marketing message identifies us and includes a free, straightforward way to opt out. You can also opt out at any time by emailing info@gridloop.ai. Filling in our contact form or booking a call does not, on its own, sign you up to marketing.
SECTION 13POPIA in the systems we build
Our services frequently touch our clients’ own personal information — CRM records, mailboxes, documents, customer data. In that work our client is the responsible party and Gridloop acts as their operator.
Our standard approach to every engagement includes:
- A written operator agreement under POPIA sections 20 and 21, recording that we process only on the client’s documented instructions, maintain confidentiality, and notify them of any compromise without undue delay.
- Defined permissions and scoping. Each automated agent is given the narrowest access it needs, rather than blanket access to a system.
- Audit logging. Automated actions are logged so the client can see what was done, when, to which record, and under whose authority.
- Data minimisation in design. We move and store the fields a workflow actually needs, rather than copying whole records between systems by default.
- Human oversight of consequential decisions, so that a decision with legal or similarly significant effects is not left to automated processing alone, consistent with section 71.
- Handling of AI model providers as sub-operators, disclosed to the client, with client data excluded from general model training.
- Return or deletion at the end of the engagement, on the client’s instruction.
An honest scoping note. POPIA compliance is a property of a whole organisation, not of a single system. We design and build to the standards above, and we document how each system handles personal information. We cannot certify a client’s overall POPIA compliance, and our work does not replace a client’s own legal advice, their Information Officer’s duties, or their obligation to maintain their own PAIA manual and privacy notices.
SECTION 14PAIA manual
The Promotion of Access to Information Act 2 of 2000 requires private bodies to compile a manual describing the records they hold and how to request access to them.
Our PAIA manual is available free of charge on request from info@gridloop.ai, or by writing to our Information Officer at the address in section 3.
SECTION 15Complaints to the Regulator
Please raise any concern with our Information Officer first. You may also complain directly to the Regulator at any time.
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
Telephone: 010 023 5200 · Toll free: 0800 017 160
Website: inforegulator.org.za
You may also approach a court for relief under section 99 of POPIA.
SECTION 16Contact
20 Air Street, 3rd Floor, Johannesburg, Gauteng, 2001, South Africa
Email: info@gridloop.ai
Telephone: +27 71 604 3335
This POPIA Notice was last updated on 26 August 2026 and replaces any earlier version.