Privacy Policy
How Gridloop.AI collects, uses, shares and protects personal information — and the rights you have over yours.
SECTION 01Who we are
Gridloop.AI is an AI consulting and automation business based in Johannesburg, South Africa. We design, build and maintain AI automation systems for other businesses.
Gridloop.AI is a trading name of FUTR Technology Group (Pty) Ltd. For the purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”), the responsible party for the personal information described in this policy is:
Company registration number: 2023/534929/07
20 Air Street, 3rd Floor, Johannesburg, Gauteng, 2001, South Africa
Email: info@gridloop.ai
Telephone: +27 71 604 3335
Information Officer
POPIA requires every private body to have an Information Officer who is accountable for compliance. Ours is:
Email: info@gridloop.ai (marked “Information Officer”)
Where we say “we”, “us” or “Gridloop” in this policy, we mean the entity above. Where we say “you”, we mean any person whose personal information we process — a website visitor, an enquirer, a prospective client, a client contact, a supplier or a job applicant.
SECTION 02Scope of this policy
This policy covers personal information we process:
- through this website, gridloop.ai, including its contact form, booking calendar and any AI assistant features;
- when you email, call or message us, or meet with us;
- in the course of providing our consulting and automation services to clients;
- when you apply to work with us or supply services to us.
It does not cover personal information we process on behalf of a client inside a system we have built for them. In that situation the client is the responsible party and their own privacy notice applies. Section 10 explains how we handle that data.
This policy also does not cover third-party websites we link to. Their own privacy policies apply once you leave our site.
SECTION 03Personal information we collect
3.1 Information you give us directly
| Where | What we collect |
|---|---|
| Contact form | Your name, email address and the content of your message. |
| Booking a consultation | Your name, email address, the time slot you choose, and your answers to any questions on the booking form. This form is provided by Google Calendar — see section 6. |
| Email, phone or LinkedIn | Your contact details, your employer, your role, and whatever you choose to tell us. |
| AI assistant and AI audit tools | The text you type into them, including your stated role and industry. Please do not enter confidential or sensitive information into these tools. |
| Meetings and calls | Notes we take. If we ever wish to record a call, we will ask for your consent first and you may refuse. |
| Becoming a client | Billing and banking details, VAT number, signatory details, and the contact details of team members who will work with us. |
| Applying to work with us | Your CV, work history, qualifications, references and right-to-work information. |
3.2 Information collected automatically
Our hosting provider keeps standard web server logs. These typically record your IP address, the pages requested, the date and time, your browser and operating system, and the page that referred you. We use them to keep the site running, diagnose faults and detect abuse.
Because this website embeds resources served by Google (a web font, and the booking calendar), your browser connects directly to Google when you load the page. That connection reveals your IP address to Google. See section 6.
3.3 Special personal information
We do not seek out special personal information as POPIA defines it — information about religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometrics, or criminal behaviour. Please do not send it to us. If it is genuinely necessary for an engagement, we will process it only with your consent or where the law otherwise permits.
3.4 Information about children
Our services are aimed at businesses. We do not knowingly collect the personal information of children under 18. See section 14.
SECTION 04Why we process it, and on what basis
POPIA requires us to have a lawful justification for every purpose. Ours are set out below.
| Purpose | Justification under POPIA s11 |
|---|---|
| Replying to your enquiry | Your consent, given by submitting the form, and our legitimate interest in responding to people who contact us. |
| Arranging and holding a consultation | Steps taken at your request before entering into a contract. |
| Preparing proposals and quotations | Steps taken at your request before entering into a contract. |
| Delivering our services and supporting the systems we build | Performance of our contract with you or your employer. |
| Invoicing, payment and credit control | Performance of a contract, and compliance with tax and company law. |
| Keeping accounting and tax records | Compliance with an obligation imposed by law. |
| Site security, fault diagnosis and abuse prevention | Our legitimate interest in operating a secure and functioning website. |
| Sending you commercial messages about our services | Your consent, or the exception in POPIA s69 that lets us market to existing customers about similar services. Every message includes an unsubscribe option. |
| Recruitment | Steps taken at your request before entering into an employment contract. |
| Enforcing our rights or defending a claim | Establishing, exercising or defending a legal right. |
Direct marketing
We will not add you to a marketing list simply because you filled in the contact form or booked a call. If we do send you marketing email, you can opt out at any time using the unsubscribe link or by emailing info@gridloop.ai. We will action it promptly and at no cost to you.
SECTION 05Cookies and similar technologies
We use a small number of cookies and similar technologies. None of them load until you choose. When you first visit, a banner asks what you consent to, and until you answer, analytics and advertising storage stay switched off.
5.1 What we use
| Technology | Purpose | Set only if you |
|---|---|---|
| Google Tag Manager | Loads and manages the tags below. Runs in Google Consent Mode, so storage is denied until you agree. | — loads always, stores nothing without consent |
| Google Analytics 4 | Counts visits, shows which pages are read and which routes lead to an enquiry. Retained for 14 months. | accept Analytics |
| Advertising cookies | Measures whether an advert led to an enquiry, and supports remarketing. | accept Marketing |
gl_consent (local storage) | Remembers the choice you just made so we stop asking. Strictly necessary — it holds no identifier and is never sent to us. | — always |
5.2 Third-party embeds
Two Google services are embedded in the pages themselves and may set their own storage:
- Google Fonts — serves the typeface. Google receives your IP address as part of that request.
- Google Calendar appointment scheduling — loads only when you open the booking window, and behaves as a Google service inside that frame.
5.3 Changing your mind
Clear this site's data in your browser (or delete the gl_consent entry) and the banner will ask again on your next visit. You can also block or delete cookies in your browser settings at any time. Declining will not stop the site working, though the booking calendar may not function.
Declining is as easy as accepting: the banner offers Decline, Analytics only and Accept all as equal choices, and we record no analytics or advertising storage unless you pick one that allows it.
SECTION 06Third parties who process it for us
We use a small number of service providers — operators in POPIA’s language. Each is bound to process personal information only on our instructions, to keep it confidential, and to secure it. We do not sell personal information, and we do not share it with third parties for their own marketing.
| Provider | What it does for us |
|---|---|
| Google (Workspace, Calendar, Fonts) | Business email, documents, calendar and appointment scheduling; serving the website typeface. |
| Google (Tag Manager, Analytics) | Website measurement, where you have consented to it. Data is processed under Google’s data processing terms. |
| Our web host | Hosting this website and its server logs. |
| Our email provider | Delivering and storing email sent to and from our domain. |
| AI model providers | Where an AI assistant or audit feature is enabled, generating a response to the text you type into it. |
| Accountants, auditors and bankers | Bookkeeping, statutory audit, tax filing and payments. |
| Attorneys and insurers | Legal advice, and defending or pursuing claims. |
We may also disclose personal information where the law compels us to, where a court orders it, or where it is necessary to protect someone’s life or safety. If our business is sold or restructured, personal information may transfer to the acquirer, who will remain bound by this policy or one materially equivalent to it.
SECTION 07Sending information outside South Africa
Some of our providers store or process data outside South Africa, principally in the United States and the European Union. Google is the main example.
POPIA section 72 permits a cross-border transfer where at least one of the following applies. We rely on these:
- the recipient is bound by an agreement that upholds principles for lawful processing substantially similar to POPIA;
- the transfer is necessary to perform a contract between you and us, or to take steps at your request before such a contract;
- you have consented to the transfer.
Where we contract with an international provider, we rely on their data processing terms and the standard contractual clauses they offer. You may ask us which providers are involved in a specific piece of processing and where they hold data.
SECTION 08How long we keep it
We keep personal information only as long as we need it for the purpose we collected it, unless the law requires us to keep it longer.
| Category | Retention |
|---|---|
| Enquiries that do not become clients | 24 months from our last contact, then deleted. |
| Booking records | 24 months from the meeting date. |
| Client records and project files | For the engagement, then 5 years from its end, to deal with support questions and possible disputes. |
| Invoices and accounting records | 5 years, as the Companies Act and the Tax Administration Act require. |
| Web server logs | Up to 12 months. |
| Marketing consent and opt-out records | For as long as we market, plus 3 years, so we can prove we honoured your choice. |
| Unsuccessful job applications | 12 months, unless you ask us to keep your CV on file for longer. |
When a retention period ends we delete the information, or de-identify it so it can no longer be linked to you.
SECTION 09How we protect it
POPIA section 19 requires us to secure the integrity and confidentiality of personal information using reasonable technical and organisational measures. Ours include:
- encryption in transit — this website is served over HTTPS, and our email and cloud services use encrypted connections;
- multi-factor authentication on our business email, cloud storage and administrative accounts;
- access on a need-to-know basis, with permissions reviewed when someone’s role changes or they leave;
- confidentiality obligations in every employment, contractor and client agreement;
- written agreements with our operators covering security and breach notification;
- keeping software and dependencies patched, and reviewing access logs;
- backups of business-critical records.
No system is perfectly secure. If a security compromise occurs that creates a reasonable belief your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible after discovering it, as POPIA section 22 requires. Our notice will describe what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself.
SECTION 10Client data in systems we build
Our work involves building automation that touches our clients’ own data — their CRM records, mailboxes, documents and customer information. When we do that work, our client is the responsible party and we act as their operator under POPIA sections 20 and 21.
In that role:
- we process the data only for the purposes the client instructs, and never for our own purposes;
- we do not use client data to train general-purpose AI models;
- we treat it as confidential and secure it in line with section 9 above;
- we notify the client without undue delay if we believe it has been compromised;
- we build in defined permissions, access scoping and audit logging, so the client can see what an automated system did and on whose authority;
- we return or delete the data at the end of the engagement, on the client’s instruction.
Every engagement is governed by a written agreement that records these obligations. If you are a customer of one of our clients and want to exercise rights over your information, please contact that business directly — they hold the relationship with you. We will support them in responding.
SECTION 11Your rights
Under POPIA you have the right to:
- Be told whether we hold personal information about you, and to be given a description of it and of who has had access to it (sections 23 and 24, and the Promotion of Access to Information Act 2 of 2000);
- Ask for a copy of that information. We may charge a prescribed fee, and will tell you the amount before we proceed;
- Have it corrected or deleted where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully (section 24);
- Object to processing we base on legitimate interests, or to processing for direct marketing, on reasonable grounds (section 11(3));
- Withdraw consent at any time, where consent is what we relied on. Withdrawal does not affect processing that already happened lawfully;
- Not receive unsolicited electronic direct marketing without your consent or an applicable exception (section 69);
- Not be subject to a decision based solely on automated processing that has legal consequences for you, without human involvement (section 71);
- Complain to the Information Regulator, and to seek civil relief in a court (sections 74 and 99).
Exercising these rights is free, apart from the prescribed copying fee for an access request. We will never treat you less favourably for exercising them.
SECTION 12How to exercise your rights
Email info@gridloop.ai with “Data subject request” in the subject line, or write to our Information Officer at the address in section 1. Tell us what you want, and enough detail for us to find your information.
For a formal request to access information we hold, POPIA and PAIA require a prescribed form — Form 2 of the POPIA regulations for an access request, and Form 3 to object to processing or to request correction or deletion. You can download these from the Information Regulator’s website at inforegulator.org.za, or ask us and we will send them to you.
We will:
- acknowledge your request, usually within 5 working days;
- verify your identity, so we do not disclose your information to someone else;
- respond substantively within 30 days. If the request is complex we may extend this once, by up to a further 30 days, and will tell you why;
- explain our reasons if we refuse, and tell you how to challenge that decision.
We may decline a request where the law allows — for example where the information is subject to legal privilege, where disclosure would reveal someone else’s personal information, or where we are required to retain it.
PAIA manual
Our manual under section 51 of the Promotion of Access to Information Act is available free of charge on request from info@gridloop.ai.
SECTION 13Complaints
If you are unhappy with how we have handled your personal information or your request, please raise it with our Information Officer first — we would rather fix it directly.
You also have the right to complain to the regulator at any time:
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
Telephone: 010 023 5200 · Toll free: 0800 017 160
Website: inforegulator.org.za
SECTION 14Children
We do not knowingly collect or process the personal information of a child under 18 without the consent of a competent person, as POPIA section 35 requires. Our website and services are intended for business users.
If you believe a child has given us personal information, email info@gridloop.ai and we will delete it.
SECTION 15Automated decision-making
We do not make decisions about you that have legal consequences, or that seriously affect you, based solely on automated processing.
Where this website offers an AI feature — such as an assistant or an automation opportunity report — its output is informational only. It is generated by a language model, may be inaccurate or incomplete, and is not advice. A person at Gridloop reviews anything that matters before we act on it. See our Terms & Conditions for more on AI-generated content.
SECTION 16Changes to this policy
We may update this policy as our services, our providers or the law change. The Last updated date at the top of this page always reflects the current version.
If a change materially affects how we use personal information we already hold, we will take reasonable steps to tell you directly — by email where we have your address, or by a notice on this website.
SECTION 17Contact us
Questions about this policy, or about how we handle personal information:
20 Air Street, 3rd Floor, Johannesburg, Gauteng, 2001, South Africa
Email: info@gridloop.ai
Telephone: +27 71 604 3335
This Privacy Policy was last updated on 26 August 2026 and replaces any earlier version.