Data Protection
Effective: 1 November 2026 | Last Updated: 13 August 2026 | POPIA compliant
📋 For Complete Details
This page describes our data protection principles and implementation. For full details on what we collect, why, and your rights, see our Privacy Policy.
Data Protection Principles
Our Approach
AiForm collects only information necessary for the Platform to function. We:
- Minimise: Collect only what is needed
- Secure: Encrypt and restrict access
- Protect: Monitor for breaches and respond promptly
- Respect: Honour user privacy and rights
- Comply: Follow POPIA and South African law
Role-Based Access
Information is accessible only to:
Suppliers
Their own profile and documents
Buyers
Supplier profiles they search and suppliers responding to their RFQs
Administrators
Account and compliance data (for support and fraud prevention)
Verification Services
Specific documents needed to verify compliance (SARS, CIPC, CSD, etc.)
Law Enforcement
Information compelled by valid legal process
All staff are bound by confidentiality agreements.
Compliance Documents and Supplier Information
2.1 Supplier-Provided Documents
What You Upload:
- CSD registration reports
- B-BBEE certificates
- Tax clearance certificates
- Bank letters
- CIDB grading certificates
- Company registration (CIPC)
- Director identification information
- Insurance certificates
- Professional qualifications
Protection:
- Encrypted storage (AES-256 at rest)
- Access restricted to verification staff
- Not publicly displayed (only verification badges shown)
- Shared with buyers only when relevant to procurement
- Retained for 3 years after account closure (audit/regulatory)
2.2 Director and Personal Information
Information Collected:
- Director names and ID numbers
- Employee names (from documents)
- Third-party references and contacts
Protection: Encrypted storage, restricted access, not publicly displayed. You can request suppression of director ID numbers from public view. Used only for verification and fraud detection.
2.3 Banking Information
What We Store:
- Account holder name
- Account number
- Bank name
- Branch code
Protection (Strict):
- ✅ Encrypted storage (encrypted in database)
- ✅ Never stored in plain text
- ✅ PCI-DSS compliant handling
- ✅ NEVER publicly visible
- ✅ Shared only with payment processors during transactions
- ✅ Deleted when document is deleted
2.4 Verification Workflow
- Supplier uploads document
- AiForm reviews for authenticity and matching
- Where applicable, we verify with official source (SARS, CIPC, CSD, CIDB)
- Verification badge added to supplier profile
- Buyer sees badge but not full document
Audit Trail: All document reviews are logged. Access to sensitive documents is tracked. Logs retained for security and compliance.
Data Security Measures
Encryption
- In Transit: HTTPS/TLS for all data in motion
- At Rest: Sensitive data encrypted using AES-256 in database
- Passwords: Hashed and salted, never stored in plain text
- Banking Details: Encrypted in database, never plain text
Access Control
- Role-based access control (RBAC)
- Staff can only access necessary information
- Multi-factor authentication available for high-security accounts
- All access logged and audited
- Confidentiality agreements signed by all staff
Ongoing Protection
- Regular security assessments and penetration testing
- Continuous monitoring for unauthorised access
- All data processors have Data Processing Agreements in place
- Regular security assessments of third-party services
Incident Response
- Detection: AiForm monitors for unauthorised access or breaches
- Notification: Affected users notified within 3 business days
- Reporting: Serious breaches reported to Information Regulator
- Remediation: Steps taken to prevent recurrence
Sensitive Data Protection
POPIA Section 14 Compliance
AiForm processes sensitive data (director IDs, banking, health information) only where:
- Necessary: Required for contract performance or legal compliance
- Legitimate Interests: Fraud prevention and security
- Consent: You have explicitly consented
Your Control
- Director ID numbers: You can request suppression from public profile
- Health/safety information: Encrypted and accessed only by authorized staff
- Criminal history (if applicable): Accessed only by authorized staff, suppression available
Data Retention and Deletion
Retention Schedule
Active Accounts
Retained while account is active
After Account Closure
- Personal Data: 90 days (for recovery), then deleted
- Compliance Documents: 3 years (audit/regulatory)
- Transaction Records: 7 years (tax/regulatory)
- Logs/Analytics: 12 months (security)
Legal Holds
Information may be retained longer if:
- Required by law (tax, regulatory, financial records)
- Needed for legal proceedings or investigations
- Involved in fraud or security investigation
- Required to protect AiForm's legal interests
Cross-Border Data Transfers
Where Your Data Is Processed
South Africa (Primary)
AiForm operational data and accounts
European Union (EU)
Supabase database hosting (Ireland); GDPR adequacy applies
United States (USA)
OpenAI (AI processing), Google Analytics, Resend (email), Payment processors
Safeguards
- EU: Protected under GDPR adequacy decision standards
- USA: Bound by Standard Contractual Clauses (SCC) and Data Processing Agreements
- Necessity: Transfers only where necessary for service delivery
Your Rights
- Request data be processed only in South Africa (may limit functionality)
- Object to transfers to specific jurisdictions
- Contact privacy@aiformstudio.com for options
Your Rights Under POPIA
Under the Protection of Personal Information Act (POPIA), you have the right to:
Access Your Information
Request a copy of all personal information AiForm holds about you. Timeline: 20 business days. Cost: Free.
Correct Inaccurate Information
Request correction of inaccurate, incomplete, or outdated information. Timeline: 10 business days. Cost: Free.
Request Deletion
Request deletion ("Right to Be Forgotten"). Limitations: Cannot delete information required by law, needed for contracts, or involved in disputes.
Timeline: 20 business days.
Restrict Processing
Request restriction of how your data is used (e.g., stop marketing, restrict analytics). Timeline: 10 business days.
Object to Processing
Object to processing on grounds of legitimate interest. Timeline: 20 business days.
Data Portability
Request your data in a portable, machine-readable format (CSV, JSON). Covers information you provided directly (not derived data like SmartScore). Timeline: 20 business days.
How to Exercise Your Rights
Email privacy@aiformstudio.com with:
- "Data Access Request"
- "Data Deletion Request"
- "Data Portability Request"
- Or describe your specific request
Dispute Resolution and Complaints
Challenging Inaccurate Information
Supplier Verification Dispute
If AiForm's verification is incorrect, email with details. AiForm will review and correct within 10 business days if warranted.
SmartScore Dispute
If your SmartScore is based on inaccurate information, request a review via dashboard or email. AiForm will recalculate based on corrected data.
Compliance Information Dispute
If government verification data (SARS, CIPC) shows incorrectly, AiForm can request live re-verification from authorities.
Complaint to Information Regulator
If you believe AiForm has violated your rights:
- Website: https://www.justice.gov.za/inforeg/
- Email: complaints.ir@justice.gov.za
- Phone: +27 10 023 5400
Third-Party Processors
Data Processing Agreements in Place
All data processors have Data Processing Agreements (DPAs) ensuring:
- Data is processed only as instructed
- Adequate security measures are implemented
- Cross-border transfers are governed by SCCs (USA) or GDPR adequacy (EU)
- Regular security audits are conducted
- Breach notification is required within agreed timeframe
Contact Us
Data Protection Questions
Data Subject Rights (Access, Deletion, Portability)
privacy@aiformstudio.com with "Data [Access/Deletion/Portability] Request"
Security Incident Report
privacy@aiformstudio.com with "Security Incident Report" (Response within 3 business days)
Status: PRODUCTION — Effective 1 November 2026
See also: Privacy Policy (full details on data collection and rights) | Terms of Service