Legal

Privacy notice

POPIA notice · version 1.0 · effective 2026-09-28

  1. Who is responsible
  2. Information Officer
  3. What we collect
  4. Why we process it, and on what basis
  5. Special personal information about your health
  6. Who else processes it
  7. Sending information outside South Africa
  8. How long we keep it
  9. Security
  10. Your rights
  11. Cookies and analytics
  12. Complaints

1. Who is responsible

The responsible party for your personal information, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA), is GOLDMIND AI CONSULTING - FZCO, registration number Licence No. 67869 (Dubai Integrated Economic Zones Authority), of IFZA Business Park, DDP, Premises No 67869-001, Dubai Silicon Oasis, Dubai, United Arab Emirates. We operate Sibona.

POPIA applies to us because we process personal information of people in South Africa using automated means.

2. Information Officer

Information Officer: Daria Saveleva, Director. Email: support@sibona.co.za. Postal address: IFZA Business Park, DDP, Premises No 67869-001, Dubai Silicon Oasis, Dubai. Requests under POPIA and the Promotion of Access to Information Act 2 of 2000 (PAIA) go to that address — see our PAIA manual.

3. What we collect

Categories of personal information we process
CategoryExamplesWhere it comes from
AccountEmail address, password (stored only as a cryptographic hash), the date you joined, the age confirmation and consents you gave, with the time and IP address of eachYou
ConversationsThe messages you write, the answers generated for you, and anything you choose to include in themYou
PaymentsSubscription status, plan, renewal dates, invoice records, the last four digits and brand of the cardStripe. We never receive your full card number
TechnicalIP address, browser and device type, pages visited, timestamps, error recordsYour browser, automatically
Marketing attributionWhich advert, link or search brought you here, and the page you landed onYour browser, on your first visit
SupportEmails you send us and our repliesYou

We do not ask for your identity number, your address or your medical aid details, and you should not send them to us.

4. Why we process it, and on what basis

  • To give you the service — creating your account, generating answers, keeping your history. Basis: performance of our agreement with you.
  • To keep the service safe — automated checks that look for signs that someone is in danger, and controls against abuse and fraud. Basis: our legitimate interest in a safe service, and our obligations to users.
  • To take payment — subscriptions, renewals, refunds, invoice records. Basis: our agreement with you, and legal obligations to keep financial records.
  • To improve the product — aggregated usage statistics, error reports. Basis: legitimate interest. We use aggregated counts, not the content of your conversations.
  • To answer you — support email. Basis: our agreement with you.
  • To understand where visitors come from — analytics, only after you allow it. Basis: your consent.

We do not sell personal information, we do not share it with advertisers, and we do not use your conversations to train our own models.

5. Special personal information about your health

When you write about how you feel, about sleep, about what a doctor has told you, or about anything to do with your physical or mental health, that is special personal information under section 26 of POPIA. Section 27 allows us to process it only with your explicit consent.

That is why we ask you separately, before your first message, to consent to us processing what you write about your health or state of mind so that we can generate your replies, keep your history and run our safety checks. We record the version of the consent text, the date, the time and the IP address. You can withdraw that consent at any time — see the health-data consent. Withdrawing it means we can no longer run the service for you, so the account is closed and the conversations deleted.

6. Who else processes it

We use a small number of operators, each under a written contract that limits them to our instructions and requires appropriate security:

Operators and where they process data
OperatorWhat it doesWhere
Google Cloud (Johannesburg, South Africa)Servers and databaseSouth Africa
OpenRouter, and the model providers it routes toGenerates the answers you readEuropean Union and United States
StripeCard payments, subscriptions, invoicesUnited States, Ireland
ResendAccount and billing emailUnited States
Google (Analytics)Visitor statistics, only with your consentUnited States, European Union

We may also disclose information if the law requires it, or to establish or defend a legal claim.

7. Sending information outside South Africa

Our servers and our operators are outside South Africa, so your personal information is transferred to and processed in the European Union and the United States. Section 72 of POPIA permits this where the recipient is subject to a law, binding corporate rules or a contract that provides an adequate level of protection, comparable to POPIA. We rely on contracts with each operator containing those protections, and, where the operator offers them, the European Commission’s standard contractual clauses. Your consent to the health-data processing described above is also your consent to this transfer.

8. How long we keep it

  • Conversations — until you delete them, or until your account is deleted.
  • Inactive accounts — if you do not sign in for 24 months, we delete the account and its conversations. We email you before we do.
  • Backups — deleted data disappears from backups within 30 days.
  • Invoices and payment records — kept for as long as tax and company law require, separately from your conversations.
  • Consent records — kept while the account exists and for 3 years after it closes, as evidence that consent was given and withdrawn. When you delete your account we keep only what the answer was, which wording you saw and when — the IP address and browser details recorded alongside it are erased, and the record of where you first came to us from (the referring page and any advertising click identifiers) is deleted.

9. Security

Traffic is encrypted in transit (TLS). Data is encrypted at rest by our hosting provider. Passwords are stored only as hashes. Access to production systems is limited to the few people who need it, with multi-factor authentication and a duty of confidentiality. If a breach affects your personal information, we will notify you and the Information Regulator as section 22 of POPIA requires.

10. Your rights

Under POPIA you may:

  • ask what personal information we hold about you, and get a copy;
  • ask us to correct or delete information that is wrong, misleading or no longer needed;
  • object to processing based on our legitimate interest;
  • withdraw a consent you gave, at any time, without affecting what was lawful before;
  • ask us not to send you marketing email — every email has an unsubscribe link.

Most of this you can do yourself from the account page. For anything else, email support@sibona.co.za from the address on your account. We answer within 30 days. Requests for records follow the procedure in our PAIA manual.

11. Cookies and analytics

We set one strictly necessary cookie that keeps you signed in, and we store your choice about analytics in your browser’s local storage. Neither needs your consent.

Google Analytics 4 loads only if you choose “Allow analytics” in the notice at the bottom of the page. Until then no analytics cookie is set and nothing is sent to Google. Analytics never includes the content of your conversations. To change your mind, clear this site’s data in your browser and answer the notice again.

On your first visit we record which advert, link or search brought you here, together with the page you landed on. That record is about the visit, not about you, and it does not use an advertising cookie.

12. Complaints

Tell us first — support@sibona.co.za — and we will try to put it right. You may also complain to the Information Regulator of South Africa:

Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001. Email: complaints.IR@justice.gov.za. Website: inforegulator.org.za.


Questions about this document: support@sibona.co.za.