Privacy and POPIA
Draft for legal review. Text in highlighted brackets must be completed, and the Information Officer registered with the Information Regulator, before this notice is published.
1. Who we are
Cloudvoice (Pty) Ltd, registration number [registration number], of [registered address], is the responsible party for the personal information described in this notice when we decide why and how it is processed.
Our Information Officer is [name], who can be reached at [privacy@cloudvoice.network] or [phone number].
2. Our two roles
As a responsible party, we process information about our own customers, their staff, people who contact us, and visitors to this website.
As an operator, we process information on behalf of our business customers when they use our services: for example the callers who phone their numbers, the customers they call or message, and the debtors whose accounts they collect. Our customer is the responsible party for that information and decides why it is processed; we process it only on their instructions, keep it secure, and tell them about any security compromise. If you are one of their callers, customers or debtors, please contact that business first; we will help them respond to you.
3. What we collect
- Contact and account details: names, company, email addresses, phone numbers, billing details and sign-in records.
- Call and message records: the numbers involved, times, durations, routing and outcome of calls and messages carried on our network.
- Call content, where switched on: recordings, transcripts and summaries of calls, for example when an AI agent handles a call or a customer turns on call recording.
- Messages: the content of SMS, WhatsApp and email messages sent or received through our services.
- Consent records: when someone agrees or declines to be contacted on a channel, the exact wording they were shown, and when.
- Enquiries: what you tell us through our contact forms.
- Technical information: IP addresses and logs needed to run and secure our services.
4. Why we use it
We process personal information only for a specific, lawful purpose, and only as much as we need. We do so to:
- provide, bill for and support the services you ordered (performance of a contract);
- route, carry and record calls and messages, and keep the records the law requires us to keep (legal obligation);
- detect and prevent fraud, abuse and attacks on our network (legitimate interest);
- answer your enquiries and send you information you asked for (consent or legitimate interest);
- improve our services, using information that is anonymised or aggregated where possible.
5. Direct marketing
We send direct marketing by electronic means only to our existing customers about similar services, or to people who have agreed to receive it, as section 69 of POPIA requires. Every message tells you how to opt out, and opting out is free. Customers who use our services to contact their own customers must follow the same rules; see our acceptable use policy.
6. Who we share it with
We do not sell personal information. We share it only with:
- other telecommunications operators, to connect and deliver calls and messages;
- service providers who help us run the services, such as hosting, messaging, email, caller ID lookup and AI model providers, under written agreements that require them to protect it;
- regulators, law enforcement or courts, when the law requires it.
7. Outside South Africa
Some of our service providers, including AI voice and language model providers, process information outside South Africa. We transfer personal information across borders only where section 72 of POPIA allows it: where the recipient is bound by law, binding rules or an agreement that gives protection substantially similar to POPIA, or where the transfer is needed to perform a contract with you. [List the main providers and countries.]
8. How long we keep it
We keep personal information only as long as we need it for the purpose it was collected, or as long as the law requires. [Retention periods: call records, recordings and transcripts, messages, account and billing records, enquiries.] When we no longer need it, we delete or de-identify it.
9. How we protect it
We take reasonable technical and organisational measures to keep personal information secure, as section 19 of POPIA requires, including encryption of sensitive settings and data in transit, access control with individual sign-ins and two-step verification, logging, and regular review of our safeguards. If we believe personal information has been compromised, we will notify the Information Regulator and the people affected, or the responsible party when we act as an operator, as soon as reasonably possible.
10. Your rights
Under POPIA you may:
- ask whether we hold personal information about you, and for a copy of it;
- ask us to correct or delete information that is inaccurate, out of date, excessive or unlawfully obtained;
- object to processing based on our legitimate interest, and to direct marketing at any time;
- withdraw consent you have given, for the future;
- complain to the Information Regulator at inforegulator.org.za.
To use these rights, contact our Information Officer at [privacy@cloudvoice.network]. We may need to confirm your identity first, and we will respond within a reasonable time.
11. This website
This website sets no tracking or advertising cookies. It remembers your light or dark choice in your browser's own storage, which never leaves your device. Fonts are loaded from Google Fonts, which receives your IP address to deliver them. When you use a form, we receive what you type in it.
12. PAIA manual
Our manual under the Promotion of Access to Information Act, 2000 (PAIA), which explains how to request records we hold, is available from our Information Officer on request. [Link the PAIA manual once published.]