Privacy notice
- Who is responsible
- Information Officer
- What we collect
- Why we process it, and on what basis
- Special personal information about your health
- Who else processes it
- Sending information outside South Africa
- How long we keep it
- Security
- Your rights
- Cookies and analytics
- Complaints
1. Who is responsible
The responsible party for your personal information, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA), is GOLDMIND AI CONSULTING - FZCO, registration number Licence No. 67869 (Dubai Integrated Economic Zones Authority), of IFZA Business Park, DDP, Premises No 67869-001, Dubai Silicon Oasis, Dubai, United Arab Emirates. We operate Sibona.
POPIA applies to us because we process personal information of people in South Africa using automated means.
2. Information Officer
Information Officer: Daria Saveleva, Director. Email: support@sibona.co.za. Postal address: IFZA Business Park, DDP, Premises No 67869-001, Dubai Silicon Oasis, Dubai. Requests under POPIA and the Promotion of Access to Information Act 2 of 2000 (PAIA) go to that address — see our PAIA manual.
3. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account | Email address, password (stored only as a cryptographic hash), the date you joined, the age confirmation and consents you gave, with the time and IP address of each | You |
| Conversations | The messages you write, the answers generated for you, and anything you choose to include in them | You |
| Payments | Subscription status, plan, renewal dates, invoice records, the last four digits and brand of the card | Stripe. We never receive your full card number |
| Technical | IP address, browser and device type, pages visited, timestamps, error records | Your browser, automatically |
| Marketing attribution | Which advert, link or search brought you here, and the page you landed on | Your browser, on your first visit |
| Support | Emails you send us and our replies | You |
We do not ask for your identity number, your address or your medical aid details, and you should not send them to us.
4. Why we process it, and on what basis
- To give you the service — creating your account, generating answers, keeping your history. Basis: performance of our agreement with you.
- To keep the service safe — automated checks that look for signs that someone is in danger, and controls against abuse and fraud. Basis: our legitimate interest in a safe service, and our obligations to users.
- To take payment — subscriptions, renewals, refunds, invoice records. Basis: our agreement with you, and legal obligations to keep financial records.
- To improve the product — aggregated usage statistics, error reports. Basis: legitimate interest. We use aggregated counts, not the content of your conversations.
- To answer you — support email. Basis: our agreement with you.
- To understand where visitors come from — analytics, only after you allow it. Basis: your consent.
We do not sell personal information, we do not share it with advertisers, and we do not use your conversations to train our own models.
5. Special personal information about your health
When you write about how you feel, about sleep, about what a doctor has told you, or about anything to do with your physical or mental health, that is special personal information under section 26 of POPIA. Section 27 allows us to process it only with your explicit consent.
That is why we ask you separately, before your first message, to consent to us processing what you write about your health or state of mind so that we can generate your replies, keep your history and run our safety checks. We record the version of the consent text, the date, the time and the IP address. You can withdraw that consent at any time — see the health-data consent. Withdrawing it means we can no longer run the service for you, so the account is closed and the conversations deleted.
6. Who else processes it
We use a small number of operators, each under a written contract that limits them to our instructions and requires appropriate security:
| Operator | What it does | Where |
|---|---|---|
| Google Cloud (Johannesburg, South Africa) | Servers and database | South Africa |
| OpenRouter, and the model providers it routes to | Generates the answers you read | European Union and United States |
| Stripe | Card payments, subscriptions, invoices | United States, Ireland |
| Resend | Account and billing email | United States |
| Google (Analytics) | Visitor statistics, only with your consent | United States, European Union |
We may also disclose information if the law requires it, or to establish or defend a legal claim.
7. Sending information outside South Africa
Our servers and our operators are outside South Africa, so your personal information is transferred to and processed in the European Union and the United States. Section 72 of POPIA permits this where the recipient is subject to a law, binding corporate rules or a contract that provides an adequate level of protection, comparable to POPIA. We rely on contracts with each operator containing those protections, and, where the operator offers them, the European Commission’s standard contractual clauses. Your consent to the health-data processing described above is also your consent to this transfer.
8. How long we keep it
- Conversations — until you delete them, or until your account is deleted.
- Inactive accounts — if you do not sign in for 24 months, we delete the account and its conversations. We email you before we do.
- Backups — deleted data disappears from backups within 30 days.
- Invoices and payment records — kept for as long as tax and company law require, separately from your conversations.
- Consent records — kept while the account exists and for 3 years after it closes, as evidence that consent was given and withdrawn. When you delete your account we keep only what the answer was, which wording you saw and when — the IP address and browser details recorded alongside it are erased, and the record of where you first came to us from (the referring page and any advertising click identifiers) is deleted.
9. Security
Traffic is encrypted in transit (TLS). Data is encrypted at rest by our hosting provider. Passwords are stored only as hashes. Access to production systems is limited to the few people who need it, with multi-factor authentication and a duty of confidentiality. If a breach affects your personal information, we will notify you and the Information Regulator as section 22 of POPIA requires.
10. Your rights
Under POPIA you may:
- ask what personal information we hold about you, and get a copy;
- ask us to correct or delete information that is wrong, misleading or no longer needed;
- object to processing based on our legitimate interest;
- withdraw a consent you gave, at any time, without affecting what was lawful before;
- ask us not to send you marketing email — every email has an unsubscribe link.
Most of this you can do yourself from the account page. For anything else, email support@sibona.co.za from the address on your account. We answer within 30 days. Requests for records follow the procedure in our PAIA manual.
11. Cookies and analytics
We set one strictly necessary cookie that keeps you signed in, and we store your choice about analytics in your browser’s local storage. Neither needs your consent.
Google Analytics 4 loads only if you choose “Allow analytics” in the notice at the bottom of the page. Until then no analytics cookie is set and nothing is sent to Google. Analytics never includes the content of your conversations. To change your mind, clear this site’s data in your browser and answer the notice again.
On your first visit we record which advert, link or search brought you here, together with the page you landed on. That record is about the visit, not about you, and it does not use an advertising cookie.
12. Complaints
Tell us first — support@sibona.co.za — and we will try to put it right. You may also complain to the Information Regulator of South Africa:
Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001. Email: complaints.IR@justice.gov.za. Website: inforegulator.org.za.
Questions about this document: support@sibona.co.za.