01Introduction
VoxMachina (Pty) Ltd ("VoxMachina", "we", "us", or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at voxmachina.co.za, engage our services, or interact with us in any other way.
This policy is drafted in compliance with the Protection of Personal Information Act, 4 of 2013 (POPIA), which is the primary data protection legislation in the Republic of South Africa.
By using our website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of our services.
02Who We Are
VoxMachina (Pty) Ltd is a South African artificial intelligence consultancy registered in the Republic of South Africa. We act as the Responsible Party (as defined by POPIA) for personal information processed through this website and in the delivery of our services.
Information Officer: privacy@voxmachina.co.za
South Africa
03Information We Collect
We collect personal information only where necessary and proportionate to the purpose for which it is collected. The categories of information we may collect include:
3.1 Information You Provide Directly
- personIdentity data: your first name, last name, and company or organisation name.
- mailContact data: your email address and telephone number.
- chatCommunication data: messages, enquiries, and feedback you send us via our contact form, email, or other channels.
- workProfessional data: your job title, industry, and information you share about your organisation's needs.
3.2 Information Collected Automatically
- devicesTechnical data: IP address, browser type and version, operating system, device identifiers, and referring URLs.
- analyticsUsage data: pages visited, time spent on pages, links clicked, and other interactions with our website.
- cookieCookie data: data collected via cookies and similar tracking technologies (see Section 10).
3.3 Information We Do Not Collect
We do not intentionally collect special personal information (as defined by POPIA) such as race, ethnicity, health data, biometric information, political opinions, religious beliefs, or sexual orientation through this website. Please do not submit such information via our contact forms.
04How We Use Your Information
We use your personal information only for specified, explicit, and legitimate purposes, including:
| Purpose | Lawful Basis |
|---|---|
| Responding to your enquiries and messages | Consent / Contractual necessity |
| Providing and delivering our AI consultancy services | Contractual necessity |
| Sending service updates and relevant communications | Consent |
| Improving our website and user experience | Legitimate interest |
| Complying with legal and regulatory obligations | Legal obligation |
| Fraud prevention and security monitoring | Legitimate interest |
05Legal Basis Under POPIA
Under POPIA, we process personal information on the following grounds (referred to as "lawful grounds for processing"):
- check_circleConsent: Where you have given clear, specific consent for us to process your personal information for a stated purpose.
- check_circleContractual necessity: Where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
- check_circleLegitimate interest: Where processing is necessary for our legitimate business interests, provided these are not overridden by your rights and interests.
- check_circleLegal obligation: Where we are required by law to process your personal information.
06Data Sharing
We do not sell, rent, or trade your personal information to third parties. We may share your information in the following limited circumstances:
- handshakeService providers (Operators): Trusted third-party vendors who assist in operating our website, sending communications, or providing supporting services — bound by data processing agreements and POPIA obligations.
- gavelLegal requirements: Where disclosure is required by law, court order, or governmental authority.
- corporate_fareBusiness transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to equivalent privacy protections.
Data sovereignty commitment: All personal data processed by VoxMachina is stored and processed within the borders of the Republic of South Africa. We do not transfer your data to foreign jurisdictions without appropriate safeguards.
07Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
- scheduleEnquiries and contact data: Retained for up to 3 years from last contact, or longer if a business relationship is established.
- scheduleClient service data: Retained for the duration of the contract plus 5 years, in line with standard business record-keeping requirements.
- scheduleWebsite analytics: Retained in anonymised or aggregated form only, after a rolling 12-month window.
08Your Rights
Under POPIA, you have the following rights with respect to your personal information:
Right of Access
Request a copy of the personal information we hold about you.
Right to Correction
Request correction of inaccurate or incomplete personal information.
Right to Deletion
Request deletion of your personal information where we no longer have a lawful basis to retain it.
Right to Object
Object to processing based on legitimate interest or for direct marketing purposes.
Withdraw Consent
Withdraw previously given consent at any time without affecting prior lawful processing.
Right to Complain
Lodge a complaint with the Information Regulator of South Africa if you believe we have violated POPIA.
To exercise any of these rights, contact our Information Officer at privacy@voxmachina.co.za. We will respond within 30 days of receiving your request.
You may also lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.
09Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, accidental loss, disclosure, alteration, or destruction. These measures include:
- httpsTLS/SSL encryption for all data in transit
- storageEncrypted storage with access controls and audit logging
- manage_accountsRole-based access controls and least-privilege principles
- securityRegular security assessments and penetration testing
- policyStaff training on data protection and information security
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Regulator and affected data subjects as required by POPIA.
11Children
Our website and services are not directed at children under the age of 18. We do not knowingly collect personal information from minors. If you believe a child has submitted personal information to us, please contact us immediately and we will delete it promptly.
12Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or prominent website notice.
We encourage you to review this policy periodically to stay informed about how we protect your information.
13Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact our Information Officer:
We will acknowledge receipt within 3 business days and respond fully within 30 days.