Last updated: 12 March 2026

POPIA Compliance

AmbitX.ai (Pty) Ltd is committed to full compliance with the Protection of Personal Information Act, 2013 (Act 4 of 2013) ("POPIA"). This page describes how Conversio meets each of the eight conditions for lawful processing as defined in Chapter 3 of POPIA, and outlines your rights as a data subject.

Our Commitment

POPIA is not an afterthought for Conversio — it is embedded in our architecture. Every database table enforces Row Level Security. Every contact interaction records consent. Every data flow is audited. We believe that respecting the privacy of your contacts is not just a legal requirement, but a competitive advantage.

The 8 Conditions for Lawful Processing

1.Accountability

AmbitX.ai has appointed an Information Officer who is responsible for ensuring compliance with POPIA across all our products, including Conversio. We maintain internal policies, conduct regular compliance reviews, and ensure all staff who handle personal information are trained in data protection principles. Our Information Officer can be reached at privacy@ambitx.ai.

2.Processing Limitation

We collect only the personal information that is necessary to provide the Conversio service. Contact data (names, phone numbers, emails) is collected because it is essential for lead management and WhatsApp messaging. We do not collect sensitive personal information such as race, health data, or political opinions. All processing is based on a lawful ground: contractual necessity, legitimate interest, or explicit consent.

3.Purpose Specification

Personal information is collected for clearly defined purposes: CRM functionality, lead qualification, message delivery, sales pipeline management, and billing. These purposes are communicated to data subjects through our Privacy Policy at the point of data collection. Data is not retained longer than necessary to fulfil these purposes.

4.Further Processing Limitation

We do not use personal information for purposes beyond those for which it was originally collected, unless we obtain additional consent from the data subject. We do not sell, rent, or share personal information with third parties for their marketing purposes. If we ever need to process data for a new purpose, we will seek explicit consent before doing so.

5.Information Quality

We take reasonable steps to ensure that personal information is complete, accurate, and not misleading. Users can view and correct contact information directly within the Conversio dashboard. Data subjects can request corrections by contacting us at privacy@ambitx.ai. We process correction requests within 30 days.

6.Openness

We are transparent about our data processing practices. This POPIA Compliance page, our Privacy Policy, and our Cookie Policy are publicly accessible and written in plain language. We have registered with the Information Regulator as required by POPIA Section 55.

7.Security Safeguards

We implement appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, or unlawful processing:

  • Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Row Level Security: Database-level isolation ensures each organisation can only access its own data
  • Access controls: Role-based permissions limit what each user can view and modify
  • Audit logging: All data access, modifications, and deletions are logged with immutable timestamps
  • Infrastructure: Data is hosted by Supabase in the af-south-1 (Cape Town) region, within South African borders
  • Regular reviews: We conduct periodic security audits and vulnerability assessments

8.Data Subject Participation

Data subjects have the right to access, correct, and delete their personal information. These rights can be exercised by contacting our Information Officer at privacy@ambitx.ai. We respond to all requests within 30 days. We also provide data export functionality so that data subjects can receive their information in a structured, machine-readable format.

Consent Management

Conversio tracks consent at every stage of the customer journey:

  • Opt-in: Contacts must explicitly opt in before receiving WhatsApp messages through Conversio. We record the timestamp, method (web form, WhatsApp reply, API), and the policy version accepted.
  • Consent storage: Consent records are stored in an immutable audit table that cannot be modified or deleted
  • Re-consent: When material changes are made to data processing practices, we prompt affected contacts for re-consent

Opt-Out Mechanisms

We provide multiple ways for contacts to opt out of communications:

  • WhatsApp: Reply "STOP" to any Conversio message to immediately opt out
  • Dashboard: Account administrators can toggle opt-out status for any contact via the Conversio dashboard
  • Email: Send an opt-out request to privacy@ambitx.ai

Opt-out requests are processed immediately. No further messages will be sent to an opted-out contact unless they explicitly opt back in.

Data Subject Access Requests (DSARs)

Any data subject may submit a request to access, correct, or delete their personal information. The process is as follows:

  1. Submit your request to privacy@ambitx.ai with proof of identity
  2. We will acknowledge receipt within 5 business days
  3. We will process and respond to your request within 30 days, as required by POPIA
  4. If we are unable to fulfil your request (e.g. due to legal retention obligations), we will provide a written explanation

There is no fee for submitting a DSAR. We may charge a reasonable fee only if requests are manifestly unfounded or excessive, as permitted by POPIA.

Data Breach Notification

In accordance with POPIA Section 22, in the event of a data breach that compromises personal information, we will:

  • Notify the Information Regulator within 72 hours of becoming aware of the breach
  • Notify affected data subjects as soon as reasonably possible
  • Provide details of the nature of the breach, the personal information affected, and the steps taken to mitigate harm
  • Document the breach in our internal incident register, including remedial actions taken

Information Officer

  • Organisation: AmbitX.ai (Pty) Ltd
  • Location: Johannesburg, South Africa
  • Email: privacy@ambitx.ai

Complaints

If you are not satisfied with our response to a privacy-related query or request, you have the right to lodge a complaint with the Information Regulator of South Africa: