CSD · BBBEE · SARS · CIPC · NATIONAL TREASURYFree during pilot · until Oct 31, 2026

Procurement Suite

AiForm Procure

Privacy Policy

Effective: 1 November 2026 | Last Updated: 13 August 2026 | Jurisdiction: South African law; POPIA compliant

1. Who We Are and Our Commitment

Organization Details

  • Operator: AiForm Studio (Pty) Ltd
  • Location: South Africa (Pretoria)
  • Service: AiForm Procure — a digital platform for verified supplier discovery, RFQ workflows, and procurement coordination
  • Contact: privacy@aiformstudio.com

Our Commitment

We handle your personal information with respect, transparency, and in compliance with:

  • South African Protection of Personal Information Act (POPIA)
  • Consumer Protection Act (CPA)
  • Common law privacy duties

This policy explains how we collect, use, store, protect, and delete your personal information.

2. What Personal Information We Collect

2.1 Information You Provide Directly

Account Registration

  • Full name
  • Email address
  • Phone number (optional)
  • Company/organisation name
  • Trading address and registration details
  • Role (supplier, buyer, administrator)
  • Password (encrypted, never stored in plain text)

Supplier Profile Information (optional)

  • Company description and services offered
  • Industry and service categories
  • Operating provinces/regions
  • Website and social media links
  • Company logo

Compliance and Verification Documents (suppliers)

  • CSD registration report
  • B-BBEE certificate or sworn affidavit
  • SARS tax clearance certificate or TCS PIN
  • Bank letter (account holder name, number, branch code)
  • CIDB grading certificate (if applicable)
  • COIDA letter of good standing (if applicable)
  • Company registration certificate (CIPC)
  • Directors' identification numbers and names
  • Insurance certificates (if applicable)
  • Professional qualifications and memberships
  • UIF registration confirmation
  • Any supporting documents you upload

RFQ and Procurement Information (buyers)

  • Procurement specifications and requirements
  • Budget and tender values
  • Closing dates and delivery locations
  • Documents and attachments related to opportunities
  • Buyer organisation details and approver information

Communication

  • Messages, enquiries, and support requests sent via the platform
  • Email communications
  • Feedback, complaints, and suggestions

Payment Information (if/when subscriptions begin)

  • Payment method (debit/credit card, bank transfer)
  • Billing address
  • Transaction history
  • Invoice records

2.2 Information Collected Automatically

Usage Data

  • Pages you visit and time spent on each
  • Links you click
  • Searches you perform
  • Profile views and interactions
  • RFQs viewed, opportunities saved, quotes submitted
  • Login dates and times
  • Device type, browser, operating system
  • IP address
  • Approximate location (from IP)

Cookies and Tracking

  • Session cookies (necessary for login)
  • Analytics cookies (Google Analytics)
  • Preference cookies (language, layout settings)
  • Third-party cookies (e.g., social media, payment processors)

2.3 Information from Third Parties

Verification Sources

  • SARS (tax compliance status via TCS PIN lookup)
  • National Treasury CSD database
  • CIPC (company registration checks)
  • Central Bank (banking verification)
  • CIDB (construction grading checks)

Payment Processors

  • Transaction data from payment gateways
  • Fraud detection signals

Publicly Available Sources

  • National Treasury eTenders (for opportunity aggregation)
  • Government business registries
  • Public procurement data

3. Why We Collect This Information (Lawful Basis)

3.1 Performance of Contract

We collect information to:

  • Set up and manage your account
  • Provide the platform and services you request
  • Process payments and manage subscriptions
  • Execute RFQs, quotes, and procurement workflows
  • Deliver customer support

Legal Basis: Necessary to perform the contract with you (POPIA section 11(a))

3.2 Compliance with Law

We collect information to:

  • Verify your identity and eligibility
  • Check supplier compliance (CSD, BBBEE, tax)
  • Detect and prevent fraud
  • Maintain audit trails for procurement decisions
  • Comply with tax, financial, and regulatory obligations

Legal Basis: Compliance with legal obligation (POPIA section 11(b))

3.3 Legitimate Interests

We collect information to:

  • Improve platform security and prevent abuse
  • Understand how users interact with AiForm
  • Develop new features and services
  • Conduct market research and analytics
  • Detect patterns indicating fraud or misuse
  • Protect AiForm's legal and business interests

Legal Basis: Legitimate interests pursued by AiForm (POPIA section 11(c))

3.4 Consent

We collect information (such as marketing communications) only where you have explicitly consented.

Legal Basis: Your consent (POPIA section 11(d))

4. How We Use Your Information

4.1 Core Platform Functions

  • Account Management: Create, maintain, and manage your account
  • Verification: Check CSD, BBBEE, tax, banking, and other compliance documents
  • Supplier Profiles: Display your information to potential buyers
  • RFQ Workflows: Match suppliers to opportunities and manage quotes
  • SmartScore: Calculate your compliance and activity score
  • Opportunity Matching: Recommend opportunities based on your profile
  • Payments: Process fees and manage billing

4.2 Communication

  • Service Updates: Notify you of platform changes, maintenance, or security issues
  • Support: Respond to your questions and resolve issues
  • Transactional Emails: Send confirmations, deadlines, and urgent notifications
  • Legal Notices: Provide changes to terms, policies, or compliance requirements

4.3 Analytics and Improvement

  • Usage Analytics: Understand how the platform is used
  • Performance: Identify and fix technical issues
  • Feature Development: Develop new features based on user needs
  • Fraud Detection: Identify suspicious patterns or misuse
  • Market Research: Analyse trends in procurement and supplier markets

4.4 Safety and Compliance

  • Fraud Prevention: Detect fraudulent documents or accounts
  • Security: Monitor for unauthorised access or data breaches
  • Abuse Prevention: Enforce platform rules and investigate violations
  • Legal Obligations: Comply with tax, regulatory, and law enforcement requests

4.5 Marketing (with Consent Only)

  • Newsletters: Procurement tips, platform updates, industry news
  • Product Announcements: New features or service offerings
  • Targeted Communications: Opportunities matched to your profile
  • Surveys: Feedback on your experience

You can opt out of marketing at any time via email or account settings.

5. Data Processors and Third-Party Sharing

5.1 Data Processors (Services We Use)

Supabase (Database & Hosting)

  • What: Cloud database, authentication, storage
  • Where: EU (Ireland)
  • Data: User accounts, profiles, documents, RFQs, quotes, contracts
  • Contract: Data Processing Agreement in place
  • Rights: Encrypted at rest; access restricted to authorised staff

OpenAI (AI Services)

  • What: Thuso AI assistant, text summarisation, content generation
  • Where: USA
  • Data: Tender documents, RFQ content, user queries (NOT stored long-term)
  • Contract: Data Processing Agreement in place
  • Rights: Content used for improvements; not stored on OpenAI servers beyond processing

Resend (Email Service)

  • What: Transactional email delivery
  • Where: USA
  • Data: Email addresses, notification content
  • Contract: Data Processing Agreement in place
  • Rights: Used only to deliver emails; not used for marketing

Google Analytics (Analytics)

  • What: Website usage and performance analytics
  • Where: USA
  • Data: Anonymised usage data, page views, device types, IP addresses (anonymised)
  • Contract: Data Processing Agreement in place
  • Rights: Used only for platform improvement

Payment Processors (if/when subscriptions begin)

  • What: Payment processing, billing, invoicing
  • Where: Various jurisdictions (TBD at launch)
  • Data: Payment method, billing address, transaction history (NOT full card details; PCI-DSS compliant)
  • Contract: Data Processing Agreements in place
  • Rights: Used only for payment processing; card data never stored on AiForm servers

Cloud Provider (Vercel)

  • What: Application hosting, CDN, deployment
  • Where: Global (primarily USA)
  • Data: Logs, analytics, performance data
  • Contract: Data Processing Agreement in place

5.2 Who Else Can See Your Information

Buyers (Supplier Information Only)

  • What: Your name, company, profile information, verification badges, SmartScore, uploaded documents (if applicable)
  • When: When you respond to an RFQ or when a buyer searches suppliers
  • Control: You control which information is public vs. hidden in your profile settings
  • Limited to: Information necessary for procurement purposes

Administrators and Support Staff

  • Access: AiForm staff may view account information to provide support, investigate fraud, or resolve disputes
  • Confidentiality: Staff are bound by confidentiality agreements
  • Limited Access: Access is role-based and logged

Law Enforcement / Government

  • When: In response to valid legal requests (court order, subpoena, regulatory inquiry)
  • What: AiForm will disclose only what is legally required
  • Notification: Where legally permitted, we will notify you of legal requests

Business Partners (if applicable)

  • Strategic Partners: If AiForm partners with other organisations, data sharing will be governed by separate agreements; you will be notified

NOT Sold or Shared for Marketing

  • We do NOT sell your personal information
  • We do NOT share data with third-party marketers
  • We do NOT rent your contact details

6. How Long We Keep Your Information

6.1 Active Accounts

While your account is active, we retain all information needed to provide the service.

6.2 After Account Closure

Personal Account Data

Retained for 90 days after account closure to allow data recovery requests. Deleted thereafter (except as required by law).

Compliance Documents

Retained for 3 years after account closure (for audit and regulatory purposes). Extended retention if disputes, legal claims, or investigations are ongoing.

Transaction and Contract Records

Retained for 7 years (tax and regulatory requirements).

Logs and Analytics

Retained for 12 months (security and performance purposes).

6.3 Legal and Security Holds

Information may be retained longer if:

  • Required by law (tax, regulatory, financial records)
  • Needed for legal proceedings or investigations
  • Involved in a fraud or security investigation
  • Required to protect AiForm's legal interests
  • You have requested data preservation

7. Your Rights Under POPIA

Under the Protection of Personal Information Act, you have the right to:

7.1 Access Your Information

  • What: Request a copy of all personal information AiForm holds about you
  • How: Email privacy@aiformstudio.com with "Data Access Request" in the subject line
  • Timeline: AiForm will provide a response within 20 business days
  • Cost: Free for reasonable requests

7.2 Correct Inaccurate Information

  • What: Request correction of inaccurate, incomplete, or outdated information
  • How: Update your account directly, or email privacy@aiformstudio.com with specific corrections needed
  • Timeline: AiForm will correct within 10 business days
  • Cost: Free

7.3 Request Deletion ("Right to Be Forgotten")

  • What: Request deletion of your personal information

Limitations:

  • Cannot delete information required by law (e.g., transaction records for 7 years)
  • Cannot delete information needed to fulfil contracts
  • Cannot delete information involved in disputes or investigations
  • How: Email privacy@aiformstudio.com with "Data Deletion Request"
  • Timeline: AiForm will respond within 20 business days

7.4 Restrict Processing

  • What: Request that AiForm restrict how your data is used
  • Example: Stop receiving marketing communications, restrict analytics
  • How: Email privacy@aiformstudio.com with specific restrictions
  • Timeline: Implemented within 10 business days

7.5 Object to Processing

  • What: Object to processing on grounds of legitimate interest
  • Example: Object to marketing, analytics, or fraud detection on your data
  • How: Email privacy@aiformstudio.com stating your objection
  • Timeline: AiForm will review and respond within 20 business days

7.6 Data Portability

  • What: Request your data in a portable, machine-readable format
  • Scope: Information you provided directly (not derived data like SmartScore)
  • How: Email privacy@aiformstudio.com with "Data Portability Request"
  • Timeline: Within 20 business days
  • Format: CSV, JSON, or other standard format

7.7 Complain to the Information Regulator

8. Data Protection Measures

8.1 Security Standards

  • Encryption in Transit: HTTPS/TLS for all data in motion
  • Encryption at Rest: Sensitive data (passwords, banking details) encrypted in database
  • Access Control: Role-based access; staff can only access necessary information
  • Authentication: Multi-factor authentication available for high-security accounts
  • Regular Audits: Security assessments and penetration testing

8.2 Staff Training

  • All AiForm staff handling personal information receive data protection training
  • Confidentiality agreements are signed by all staff
  • Access logs are maintained

8.3 Vendor Management

  • All data processors have Data Processing Agreements in place
  • Regular security assessments of third-party services
  • Data is not processed outside of Europe/USA without explicit justification

8.4 Incident Response

  • Detection: AiForm monitors for unauthorised access or breaches
  • Notification: If a breach is detected, affected users will be notified within 3 business days
  • Reporting: Serious breaches will be reported to the Information Regulator
  • Remediation: AiForm will take steps to prevent recurrence

9. Special Categories of Data

9.1 Sensitive Information (POPIA Section 14)

Director Identification Information

  • Director name, ID number, date of birth
  • Used for: Verification and fraud prevention
  • Protection: Stored encrypted; shared only with verification services
  • Right: You can request suppression of director ID numbers from public profile

Banking Details

  • Account holder name, number, branch code
  • Used for: Payment processing and fraud detection
  • Protection: Never stored in plain text; PCI-DSS compliant payment processing
  • Right: Bank details are NEVER publicly visible

Health/Safety Information (if applicable)

  • Worker compensation claims, health certificates
  • Used for: Compliance verification
  • Protection: Encrypted; shared only with verification services

Criminal History (if applicable, e.g., in compliance documents)

  • Used for: Regulatory compliance
  • Protection: Accessed only by authorised staff
  • Right: Can request suppression from public view

Lawful Basis for Processing Sensitive Data

  • Necessity: Required for performance of contract or compliance
  • Legitimate Interests: Fraud prevention, security
  • Explicit Consent: Where you have explicitly consented

10. Children's Privacy

AiForm Procure is intended for users aged 18 and older. We do not knowingly collect information from children under 13.

If we become aware that a child has provided personal information, we will delete the information promptly. Parents/guardians can contact privacy@aiformstudio.com.

For users 13–17, parental/guardian consent is required for account creation, with limited data sharing and additional protections applied.

11. Cross-Border Data Transfers

11.1 Where Your Data Is Processed

South Africa (Primary)

AiForm operational data and accounts

European Union (EU)

Supabase database hosting (Ireland); GDPR adequacy applies

United States (USA)

OpenAI (AI processing), Google Analytics, Resend (email), Payment processors (TBD)

11.2 Lawful Basis for Transfers

  • EU Adequacy Decision: EU data is protected under adequacy decision standards
  • Standard Contractual Clauses (SCC): USA-based processors are bound by SCCs; Data Processing Agreements include transfer safeguards
  • Necessity: Transfers are necessary for service delivery; No practical alternative with equivalent security

11.3 Your Rights Regarding Transfers

  • You can request that data be processed only in South Africa (may limit functionality)
  • You can object to transfers to specific jurisdictions
  • Contact privacy@aiformstudio.com for options

12. Challenging Information & Corrections

12.1 If You Believe Information Is Inaccurate

Supplier Verification Dispute

If AiForm's verification of your document is incorrect, email privacy@aiformstudio.com with: your profile, document reference, what is inaccurate, evidence of correct information. AiForm will review within 10 business days and correct if warranted.

SmartScore Dispute

If you believe your SmartScore is based on inaccurate information, request a review via your dashboard or email privacy@aiformstudio.com. AiForm will recalculate based on corrected data.

Compliance Information Dispute

If government verification data (SARS, CIPC, etc.) is shown incorrectly on your profile, AiForm can request live re-verification from authorities. Email privacy@aiformstudio.com to request re-verification.

13. Marketing Communications

13.1 What We Send

  • Platform updates and service announcements (transactional — not optional)
  • New features and maintenance notifications
  • Opportunity matches (if you opt in)
  • Procurement tips and industry insights (if you opt in)
  • Surveys and feedback requests (if you opt in)

13.2 Opt-Out

How to Unsubscribe:

  1. Click "Unsubscribe" link in any marketing email
  2. Go to Account Settings → Communication Preferences
  3. Email privacy@aiformstudio.com

What You Can't Unsubscribe From:

  • Transactional emails (order confirmations, password resets, legal notices)
  • Security alerts and fraud notifications

14. Policy Updates

14.1 Changes to This Policy

  • AiForm may update this policy from time to time
  • Significant changes will be notified via email or platform announcement
  • Continued use of AiForm after changes constitutes acceptance
  • Material adverse changes will provide at least 30 days' notice

14.2 Version History

DateChanges
1 Nov 2026Initial production version

15. Contact Us

Questions About This Policy

Email: privacy@aiformstudio.com

Subject: "Privacy Policy Question"

Data Subject Access Requests

Email: privacy@aiformstudio.com

Subject: "Data Access Request" or "Data Deletion Request" or "Data Portability Request"

Report a Privacy Breach

Email: privacy@aiformstudio.com

Subject: "Security Incident Report"

Response Time: Within 3 business days

Information Regulator (SA)

If you have concerns that cannot be resolved through AiForm:

Status: PRODUCTION — Effective 1 November 2026

Privacy Policy | AiForm Procure