CSD · BBBEE · SARS · CIPC · NATIONAL TREASURYFree during pilot · until Oct 31, 2026

Procurement Suite

AiForm Procure

Data Protection

Effective: 1 November 2026 | Last Updated: 13 August 2026 | POPIA compliant

📋 For Complete Details

This page describes our data protection principles and implementation. For full details on what we collect, why, and your rights, see our Privacy Policy.

Data Protection Principles

Our Approach

AiForm collects only information necessary for the Platform to function. We:

  • Minimise: Collect only what is needed
  • Secure: Encrypt and restrict access
  • Protect: Monitor for breaches and respond promptly
  • Respect: Honour user privacy and rights
  • Comply: Follow POPIA and South African law

Role-Based Access

Information is accessible only to:

Suppliers

Their own profile and documents

Buyers

Supplier profiles they search and suppliers responding to their RFQs

Administrators

Account and compliance data (for support and fraud prevention)

Verification Services

Specific documents needed to verify compliance (SARS, CIPC, CSD, etc.)

Law Enforcement

Information compelled by valid legal process

All staff are bound by confidentiality agreements.

Compliance Documents and Supplier Information

2.1 Supplier-Provided Documents

What You Upload:

  • CSD registration reports
  • B-BBEE certificates
  • Tax clearance certificates
  • Bank letters
  • CIDB grading certificates
  • Company registration (CIPC)
  • Director identification information
  • Insurance certificates
  • Professional qualifications

Protection:

  • Encrypted storage (AES-256 at rest)
  • Access restricted to verification staff
  • Not publicly displayed (only verification badges shown)
  • Shared with buyers only when relevant to procurement
  • Retained for 3 years after account closure (audit/regulatory)

2.2 Director and Personal Information

Information Collected:

  • Director names and ID numbers
  • Employee names (from documents)
  • Third-party references and contacts

Protection: Encrypted storage, restricted access, not publicly displayed. You can request suppression of director ID numbers from public view. Used only for verification and fraud detection.

2.3 Banking Information

What We Store:

  • Account holder name
  • Account number
  • Bank name
  • Branch code

Protection (Strict):

  • ✅ Encrypted storage (encrypted in database)
  • ✅ Never stored in plain text
  • ✅ PCI-DSS compliant handling
  • ✅ NEVER publicly visible
  • ✅ Shared only with payment processors during transactions
  • ✅ Deleted when document is deleted

2.4 Verification Workflow

  1. Supplier uploads document
  2. AiForm reviews for authenticity and matching
  3. Where applicable, we verify with official source (SARS, CIPC, CSD, CIDB)
  4. Verification badge added to supplier profile
  5. Buyer sees badge but not full document

Audit Trail: All document reviews are logged. Access to sensitive documents is tracked. Logs retained for security and compliance.

Data Security Measures

Encryption

  • In Transit: HTTPS/TLS for all data in motion
  • At Rest: Sensitive data encrypted using AES-256 in database
  • Passwords: Hashed and salted, never stored in plain text
  • Banking Details: Encrypted in database, never plain text

Access Control

  • Role-based access control (RBAC)
  • Staff can only access necessary information
  • Multi-factor authentication available for high-security accounts
  • All access logged and audited
  • Confidentiality agreements signed by all staff

Ongoing Protection

  • Regular security assessments and penetration testing
  • Continuous monitoring for unauthorised access
  • All data processors have Data Processing Agreements in place
  • Regular security assessments of third-party services

Incident Response

  • Detection: AiForm monitors for unauthorised access or breaches
  • Notification: Affected users notified within 3 business days
  • Reporting: Serious breaches reported to Information Regulator
  • Remediation: Steps taken to prevent recurrence

Sensitive Data Protection

POPIA Section 14 Compliance

AiForm processes sensitive data (director IDs, banking, health information) only where:

  • Necessary: Required for contract performance or legal compliance
  • Legitimate Interests: Fraud prevention and security
  • Consent: You have explicitly consented

Your Control

  • Director ID numbers: You can request suppression from public profile
  • Health/safety information: Encrypted and accessed only by authorized staff
  • Criminal history (if applicable): Accessed only by authorized staff, suppression available

Data Retention and Deletion

Retention Schedule

Active Accounts

Retained while account is active

After Account Closure

  • Personal Data: 90 days (for recovery), then deleted
  • Compliance Documents: 3 years (audit/regulatory)
  • Transaction Records: 7 years (tax/regulatory)
  • Logs/Analytics: 12 months (security)

Legal Holds

Information may be retained longer if:

  • Required by law (tax, regulatory, financial records)
  • Needed for legal proceedings or investigations
  • Involved in fraud or security investigation
  • Required to protect AiForm's legal interests

Cross-Border Data Transfers

Where Your Data Is Processed

South Africa (Primary)

AiForm operational data and accounts

European Union (EU)

Supabase database hosting (Ireland); GDPR adequacy applies

United States (USA)

OpenAI (AI processing), Google Analytics, Resend (email), Payment processors

Safeguards

  • EU: Protected under GDPR adequacy decision standards
  • USA: Bound by Standard Contractual Clauses (SCC) and Data Processing Agreements
  • Necessity: Transfers only where necessary for service delivery

Your Rights

  • Request data be processed only in South Africa (may limit functionality)
  • Object to transfers to specific jurisdictions
  • Contact privacy@aiformstudio.com for options

Your Rights Under POPIA

Under the Protection of Personal Information Act (POPIA), you have the right to:

Access Your Information

Request a copy of all personal information AiForm holds about you. Timeline: 20 business days. Cost: Free.

Correct Inaccurate Information

Request correction of inaccurate, incomplete, or outdated information. Timeline: 10 business days. Cost: Free.

Request Deletion

Request deletion ("Right to Be Forgotten"). Limitations: Cannot delete information required by law, needed for contracts, or involved in disputes.

Timeline: 20 business days.

Restrict Processing

Request restriction of how your data is used (e.g., stop marketing, restrict analytics). Timeline: 10 business days.

Object to Processing

Object to processing on grounds of legitimate interest. Timeline: 20 business days.

Data Portability

Request your data in a portable, machine-readable format (CSV, JSON). Covers information you provided directly (not derived data like SmartScore). Timeline: 20 business days.

How to Exercise Your Rights

Email privacy@aiformstudio.com with:

  • "Data Access Request"
  • "Data Deletion Request"
  • "Data Portability Request"
  • Or describe your specific request

Dispute Resolution and Complaints

Challenging Inaccurate Information

Supplier Verification Dispute

If AiForm's verification is incorrect, email with details. AiForm will review and correct within 10 business days if warranted.

SmartScore Dispute

If your SmartScore is based on inaccurate information, request a review via dashboard or email. AiForm will recalculate based on corrected data.

Compliance Information Dispute

If government verification data (SARS, CIPC) shows incorrectly, AiForm can request live re-verification from authorities.

Complaint to Information Regulator

If you believe AiForm has violated your rights:

Third-Party Processors

Data Processing Agreements in Place

All data processors have Data Processing Agreements (DPAs) ensuring:

  • Data is processed only as instructed
  • Adequate security measures are implemented
  • Cross-border transfers are governed by SCCs (USA) or GDPR adequacy (EU)
  • Regular security audits are conducted
  • Breach notification is required within agreed timeframe

Contact Us

Data Protection Questions

privacy@aiformstudio.com

Data Subject Rights (Access, Deletion, Portability)

privacy@aiformstudio.com with "Data [Access/Deletion/Portability] Request"

Security Incident Report

privacy@aiformstudio.com with "Security Incident Report" (Response within 3 business days)

Status: PRODUCTION — Effective 1 November 2026

See also: Privacy Policy (full details on data collection and rights) | Terms of Service

Data Protection | AiForm Procure