Privacy Policy
How we collect, use, and protect personal information โ written to comply with South Africa's Protection of Personal Information Act, 2013 (POPIA). We use personal information to run the platform. We do not sell it.
On this page
- Who we are
- Our two roles under POPIA
- What we collect
- Why we process it
- We do not sell your data
- Who we share it with
- Meta and WhatsApp
- Payments
- Cross-border transfers
- Direct marketing
- How long we keep it
- Security safeguards
- Security compromises
- Your rights
- Children's information
- Cookies and analytics
- Contact our Information Officer
- Complaints to the Regulator
- Changes to this policy
1. Who we are
Keychat is a managed WhatsApp commerce platform operated by Keychat Solutions (Pty) Ltd, registration number 2025/898497/07, a company incorporated in the Republic of South Africa ("Keychat", "we", "us", "our").
We build and run WhatsApp-based ordering, reservations, ticketing, loyalty, delivery scheduling, and customer support for South African food, retail, and service businesses. This policy explains what personal information passes through that platform, why, and what you can do about it.
This policy is issued in terms of POPIA and should be read together with our PAIA manual, published in terms of section 51 of the Promotion of Access to Information Act, 2000. The manual describes the records we hold, the procedure for requesting access to them, the applicable fees, and the remedies available if a request is refused.
2. Our two roles under POPIA
This is the most important section to understand, because your rights differ depending on which relationship you have with us.
When we are the Responsible Party
We decide the purpose and means of processing โ and are therefore the responsible party โ for:
- Personal information of the business owners, managers, and staff who hold a Keychat account.
- Personal information of prospective clients who contact us, book a call, or request a demo.
- Technical and analytics information collected from visitors to keychat.co.za.
For this information, direct your requests to us using the details in section 17.
When we are an Operator
When a restaurant, butchery, bakery, or other merchant uses Keychat to serve their customers, that merchant remains the responsible party for their customers' personal information. We act as an operator under sections 20 and 21 of POPIA โ we process that information only on the merchant's documented instruction, under a written agreement, and we do not use it for our own purposes.
In practice this means the merchant owns their customer list. We do not repurpose it, resell it, or use it to market to their customers on anyone else's behalf.
3. What we collect
We collect the minimum needed to operate the platform, in line with the processing limitation and minimality principles in section 10 of POPIA.
3.1 Merchant account information
- Name, job title, business email address, and mobile number of the account holder and authorised users.
- Trading name, registered name, business address, business category, VAT and company registration details.
- Login credentials, and records of actions taken in the dashboard.
- Billing records, invoices, and settlement information.
3.2 End-customer information processed for merchants
When a customer transacts with a merchant over WhatsApp, we process, as operator:
- Mobile number โ the WhatsApp number the customer messages from. This is the primary identifier.
- Name โ as given to the merchant or shown on the WhatsApp profile.
- Delivery and collection addresses, including any delivery notes or location pins shared in chat.
- Order history โ items, quantities, values, timestamps, order status, and store or branch.
- Reservation, booking, and ticket details โ date, time, party size, seating or event references.
- Loyalty information โ points balances, rewards issued and redeemed, visit frequency.
- Subscription and scheduled-order details, where the merchant offers these.
- Conversation content โ messages exchanged with the merchant's WhatsApp channel, including messages handled by our AI support assistant.
- Marketing preferences โ opt-ins, opt-outs, and suppression records.
3.3 Payment information
Payments are processed by our payment partners. We do not collect, see, or store full card numbers, CVV codes, or bank credentials. We receive only a transaction reference, amount, status, and a masked payment identifier so the merchant can reconcile the order.
3.4 Website and technical information
- IP address, browser type, device type, operating system, and referring page.
- Pages viewed, time on page, and interactions, collected through Google Analytics 4.
- Information submitted through contact forms or the booking calendar.
3.5 What we do not collect
We do not intentionally collect special personal information as defined in section 26 of POPIA โ religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour. Merchants must not configure Keychat to collect it, and customers should not send it to a merchant's WhatsApp channel.
4. Why we process it
Every processing activity has a specific, explicitly defined, lawful purpose as required by section 13 of POPIA. We rely on the following justifications from section 11:
| Purpose | Lawful basis (POPIA s.11) |
|---|---|
| Taking, confirming, and fulfilling an order, booking, or ticket purchase | Necessary to perform a contract โ s.11(1)(b) |
| Arranging delivery or collection, including passing an address to a driver | Necessary to perform a contract โ s.11(1)(b) |
| Processing payment and reconciling settlement | Contract, and legal obligation โ s.11(1)(b) and (c) |
| Answering support queries, including via AI assistant | Contract, and legitimate interests โ s.11(1)(b) and (f) |
| Running loyalty programmes and issuing rewards | Consent, and contract โ s.11(1)(a) and (b) |
| Sending marketing campaigns and promotions | Consent, or the existing-customer exception โ s.69 |
| Fraud prevention, abuse detection, and platform security | Legitimate interests โ s.11(1)(f) |
| Keeping tax, accounting, and audit records | Legal obligation โ s.11(1)(c) |
| Aggregated, de-identified reporting on platform performance | Legitimate interests, on de-identified data โ s.11(1)(f) |
We do not process personal information for a further purpose that is incompatible with the purpose it was collected for, as required by section 15 of POPIA.
5. We do not sell your data
To state it plainly and without qualification:
- We do not sell personal information to any third party.
- We do not rent, trade, or licence customer lists, phone numbers, or order histories.
- We do not share one merchant's customer data with another merchant.
- We do not use a merchant's customer data to build advertising audiences or data products for our own benefit.
Personal information is shared only with the service providers listed in section 6, and only to the extent needed to make the platform work for the merchant whose customers they are.
7. Meta and WhatsApp
Keychat is built on the WhatsApp Business Platform. We operate in accordance with Meta's terms and policies, including the WhatsApp Business Messaging Policy, the WhatsApp Business Solution Terms, and Meta's Platform Terms and Developer Policies.
Practically, this means:
- Merchants must obtain opt-in before messaging a customer, and that opt-in must be clear about who is messaging and what for.
- We honour opt-outs promptly and maintain suppression lists so a customer who opts out stays opted out.
- We do not use WhatsApp to send prohibited content or to message people who have not opted in.
- Message content passes through Meta's infrastructure and is subject to Meta's own privacy practices, described in the WhatsApp Privacy Policy.
Each merchant connects their own WhatsApp Business Account to Keychat through Meta's Embedded Signup. The merchant remains the owner of that account and of the customer relationships on it.
8. Payments
Card and electronic payments are handled by Paystack and Yoco, both PCI-DSS compliant payment providers. We operate in accordance with their acceptable use and data handling policies.
When a customer pays, they are directed to the payment provider's secure environment. Card details are entered there and are never transmitted to or stored on Keychat systems. We receive back only what is needed to mark the order as paid: a transaction reference, the amount, the status, and, where the provider supplies it, a masked card identifier.
Refunds, chargebacks, and payment disputes are handled through the same provider and are subject to that provider's privacy policy โ Paystack and Yoco.
9. Cross-border transfers
Keychat hosts platform data in South African and European Union data centres. Some of our service providers โ notably Meta, Google, and Cloudflare โ operate global infrastructure and may process personal information outside South Africa.
Where personal information is transferred across a border, we do so only on a basis permitted by section 72 of POPIA, namely:
- the recipient is subject to a law, binding corporate rules, or a binding agreement that upholds principles for lawful processing substantially similar to POPIA; or
- the transfer is necessary for the performance of a contract with the data subject, or for a contract concluded in the data subject's interest; or
- the data subject has consented to the transfer.
We put written data processing agreements in place with providers who process personal information outside South Africa.
10. Direct marketing
Campaigns are a core part of what Keychat does, so we hold this to a strict standard under section 69 of POPIA.
- Merchants may send electronic direct marketing to a customer only where the customer has consented, or where the customer is an existing customer of that merchant, the contact details were obtained in the course of a sale, and the marketing relates to similar products or services.
- Every marketing message identifies the sender and provides a free, simple way to opt out.
- A customer may opt out at any time by replying STOP to the merchant's WhatsApp channel, or by asking the merchant directly.
- Opt-outs are recorded on a suppression list and applied immediately. We do not require a reason and we do not ask twice.
- A person who is not an existing customer will be approached for consent only once, as section 69(2) permits.
Merchants are contractually responsible for the lawfulness of the audiences they upload and the consent behind them. We provide the tooling, opt-out handling, and suppression enforcement.
11. How long we keep it
In line with section 14 of POPIA, we do not keep personal information longer than necessary for the purpose it was collected, unless a law requires longer retention or the data subject has consented.
| Information | Retention period |
|---|---|
| Merchant account and contract records | Duration of the agreement, then 5 years (tax and company record-keeping obligations) |
| Transaction and invoice records | 5 years from the end of the relevant tax year, per the Tax Administration Act |
| End-customer profiles and order history | While the merchant's account is active; deleted or returned within 90 days of termination, on the merchant's instruction |
| WhatsApp conversation logs | 12 months on a rolling basis, unless a merchant instructs a shorter period |
| Marketing opt-out and suppression records | Retained indefinitely โ we must keep these to honour the opt-out |
| Website analytics | 14 months (Google Analytics 4 default) |
| Prospect and enquiry records | 24 months from last contact, unless a relationship begins |
When a retention period expires, we delete the information or de-identify it so that it can no longer be linked to a person.
12. Security safeguards
Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. Ours include:
- Encryption of data in transit using TLS, and encryption of data at rest on our database infrastructure.
- Role-based access control, so staff and merchant users see only what their role requires.
- Network protection and denial-of-service mitigation at the edge.
- Logging and monitoring of access to personal information, with audit trails.
- Regular backups, tested restores, and a documented recovery process.
- Confidentiality obligations in staff contracts, and written processing agreements with every operator.
- Periodic review of our safeguards against reasonably foreseeable risks, as section 19(2) requires.
No system is perfectly secure. We do not claim otherwise. What we commit to is proportionate protection, honest disclosure, and prompt action when something goes wrong.
13. Security compromises
If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, section 22 of POPIA obliges us to act. We will:
- notify the Information Regulator as soon as reasonably possible after discovering the compromise;
- notify affected data subjects โ or, where we act as operator, notify the responsible party immediately so they can notify their customers;
- describe what happened, what information was involved, the likely consequences, and what we are doing about it; and
- recommend practical steps affected people can take to protect themselves.
14. Your rights
Sections 5, 23, 24, and 25 of POPIA give you the following rights. Exercising them is free, except that a prescribed fee may apply to a request for a copy of the information held.
- To be notified that your personal information is being collected, and if it has been accessed by an unauthorised person.
- To access โ to confirm, free of charge, whether we hold information about you, and to request a copy of it.
- To correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
- To object, on reasonable grounds, to the processing of your information under section 11(3).
- To object to direct marketing at any time, without giving a reason.
- Not to be subject to a decision based solely on automated processing that has legal or substantially similar consequences for you. Our AI assistant answers queries and takes orders; it does not make decisions of that kind.
- To complain to the Information Regulator, and to institute civil proceedings.
How to make a request
Send your request to our Information Officer using the details in section 17, on the prescribed Form 2 where applicable. We will verify your identity before acting, to make sure we are not disclosing your information to someone else. We aim to respond within 30 days.
If your request concerns information we hold as an operator for a merchant, we will forward it to that merchant and support them in responding, but the merchant makes the decision.
15. Children's information
Keychat is built for business-to-consumer commerce among adults. We do not knowingly process the personal information of a child under 18 without the consent of a competent person, as section 34 of POPIA requires.
Merchants must not use the platform to market age-restricted products โ alcohol in particular โ to minors, and must apply age verification where the law requires it. If you believe we hold a child's information without proper consent, contact us and we will delete it.
16. Cookies and analytics
keychat.co.za uses a small number of cookies and similar technologies:
- Essential cookies โ needed for the site and the booking calendar to function.
- Analytics cookies โ Google Analytics 4, to understand which pages are useful and where visitors come from. This data is aggregated and we do not use it to identify individuals.
You can block or delete cookies in your browser settings. Blocking analytics cookies will not affect your ability to use the site. You can also opt out of Google Analytics using Google's browser add-on.
We do not run third-party advertising trackers or cross-site advertising pixels on this website.
17. Contact our Information Officer
We have designated an Information Officer in terms of section 55 of POPIA. For any question about this policy, or to exercise a right under section 14:
Regardt Nel โ Information Officer
Keychat Solutions (Pty) Ltd
Email: regardt@keychat.co.za
WhatsApp: +27 69 027 7170
Or use our contact page.
18. Complaints to the Regulator
If you are not satisfied with how we have handled your information or your request, you have the right to lodge a complaint with the Information Regulator of South Africa.
- Website: inforegulator.org.za
- Complaints: complaints.IR@justice.gov.za
- General enquiries: enquiries.IR@justice.gov.za
We would appreciate the chance to resolve the matter first, but you are under no obligation to come to us before approaching the Regulator.
19. Changes to this policy
We review this policy at least annually and whenever we materially change how we process personal information. The effective date and version at the top of this page always reflect the current version.
Where a change materially affects your rights, we will notify merchants by email and, where appropriate, in the dashboard before the change takes effect. Continued use of the platform after that date constitutes acceptance of the updated policy.