Privacy Policy & PAIA Notice
DataSeam (“we”, “our”, “us”) is committed to protecting the privacy and personal information of everyone who interacts with us — whether you’re a prospective client, an existing client, or a visitor to our website. This notice explains what personal information we collect, why we collect it, and how we protect it, in compliance with the Protection of Personal Information Act, 2013 (POPIA) and the Promotion of Access to Information Act, 2000 (PAIA).
Who we are
DataSeam is a managed data and business intelligence service based in South Africa. We connect small and medium business systems (accounting, e-commerce, POS, etc.) into unified dashboards. Our contact details are:
- Email: zach@dataseam.co.za
- Website: dataseam.co.za
What personal information we collect
Website visitors: We may collect your name and email address if you submit a contact form or get in touch by email. We may use website analytics that collect anonymised usage data such as pages visited and session duration.
Prospective clients: During discovery calls and proposals, we may collect your name, email address, phone number, business name, and information about your business systems.
Existing clients: We process data from your business systems, as described in our Client Services Agreement and Data Processing Agreement. This data may include your customers’ and employees’ personal information. We process this data solely on your behalf and under your instructions.
Why we collect it
- To respond to your enquiries and provide you with information about our services.
- To deliver the data pipeline and dashboard services described in our Client Services Agreement.
- To send you invoices and manage our business relationship with you.
- To comply with legal and regulatory obligations (e.g., tax record-keeping).
How we protect it
- All client data is hosted in Microsoft Azure’s South Africa North (Johannesburg) data centre.
- Data is encrypted at rest and in transit using industry-standard encryption (AES-256, TLS 1.2).
- Access to client data is restricted to authorised DataSeam personnel only.
- Credentials and API keys are stored in Azure Key Vault, not in code or documents.
AI-assisted analytics (Answers)
Our Answers feature lets you ask questions about your own business data in plain English and receive a written response. It runs on the Microsoft Azure OpenAI Service, inside the same secure Azure environment as the rest of your data. Answers has read-only access to your reporting data and cannot change your systems or your data. Your information is processed solely to answer your questions — it is never used to train AI models, and it is never exposed to other clients. Where a question is ambiguous, Answers asks you to clarify rather than guessing, and every response shows the assumptions behind it.
Who we share it with
We do not sell, rent, or share your personal information with third parties for marketing purposes. We share data only with:
- Microsoft Azure: our cloud infrastructure provider, which hosts and processes data on our behalf within South Africa. This includes the Azure OpenAI Service that powers our Answers feature, as described above.
- Your connected SaaS providers: we read data from your systems (Xero, Shopify, etc.) via their APIs. We do not write data back to these systems.
- Law enforcement or regulators: only if required by South African law.
Your rights under POPIA
You have the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate personal information.
- Request deletion of your personal information (subject to legal retention requirements).
- Object to the processing of your personal information.
- Lodge a complaint with the Information Regulator.
To exercise any of these rights, email us at zach@dataseam.co.za. We will respond within a reasonable time, and no later than thirty (30) days.
Requests for access to information (PAIA)
If you would like to request access to records DataSeam holds about you under PAIA, email zach@dataseam.co.za describing the records requested. We will respond within the timeframes set out in PAIA.
How long we keep it
- Website enquiries and marketing contacts: until you ask us to delete them.
- Client data: for the duration of the client relationship, plus thirty (30) days for data return and deletion.
- Financial records (invoices, contracts): five (5) years, as required by SARS.
Changes to this notice
We may update this privacy notice from time to time. The “last updated” date at the top of this page reflects the most recent revision. We encourage you to review this notice periodically.