Legal
Privacy Notice
How KRAGOS handles personal information, under POPIA and, where it applies, the GDPR. Written to be checked, not to be skimmed.
The short version
We are the responsible party for information about visitors to our website and about people who ask us for a quote. We are the operator, not the responsible party, for the data inside our customers' products. That distinction runs through this whole notice and clause 4 explains it.
We do not use anyone's data to train an artificial intelligence model. We do not run analytics, advertising pixels or third party fonts on the public site.
Some of the services we depend on are outside South Africa. Clause 19 lists every one of them, with what it does and where it sits.
One thing that is not yet done
Registration of the Information Officer with the Information Regulator is required under section 55 of the Protection of Personal Information Act 4 of 2013 and the Regulator's registration process. We record it here as an outstanding action rather than stating that it is complete. It will be completed and this notice updated with the date and reference when it is.
1. Who we are
Ecopackaging (Pty) Ltd, registration number 2014/032538/07, VAT registration number 4530265216, trading as KRAGOS, of 750 Nieuwhout Street, Garsfontein, Pretoria, 0081, South Africa.
In this notice we, us and KRAGOS mean that company. You means the person whose personal information we process.
Information Officer: Francois Petrus Heunis. Write to ops@kragos.app and mark the message for the Information Officer. This is the sole contact address for privacy matters, including access requests, objections, complaints and breach reports.
Registration with the Information Regulator. Section 55 of the Protection of Personal Information Act 4 of 2013 (POPIA) requires the Information Officer to register with the Information Regulator before taking up duties. This registration is an outstanding action. We flag it here rather than assert that it is done. This notice will be updated with the registration date and reference on completion.
A manual under section 51 of the Promotion of Access to Information Act 2 of 2000 is available from ops@kragos.app on request.
2. What this notice covers
This notice applies to:
- the public website at kragos.ai, including the free compliance calendar, the assistant, the booking page and the enquiry forms;
- the authenticated products at kragos.app, being STEMPA, MakTy, HELM and Pulse;
- email, WhatsApp, voice and Teams correspondence with us;
- personal information we hold about prospects, customers, suppliers and their people.
It does not cover a third party website you reach from a link on ours. Those sites have their own notices.
It is written to POPIA, and where it names a right or a basis that comes from the General Data Protection Regulation (EU) 2016/679 (GDPR) it says so. Clause 12 and clause 16 give the GDPR position for visitors outside South Africa.
3. The words we use
- Personal information
- Information relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person. POPIA protects both. GDPR protects natural persons only.
- Processing
- Anything done with personal information, including collecting, storing, using, sharing, changing and deleting it.
- Responsible party
- The person who determines the purpose of and means for processing. Called a controller under GDPR.
- Operator
- A person who processes personal information for a responsible party, under that party's authority, without controlling it. Called a processor under GDPR.
- Data subject
- The person the personal information is about.
- Customer
- A business that has a KRAGOS subscription.
- Customer end user data
- Personal information inside a customer's tenant, about that customer's own employees, clients, suppliers and contacts.
4. The critical distinction: responsible party, and operator
Read this before anything else
For our own visitors and prospects, KRAGOS is the RESPONSIBLE PARTY. We decide why and how we process your information when you browse our site, use the free calendar, talk to the assistant, book a meeting, or ask us for a quote. Your rights under clause 16 run against us, and you complain about us to the Regulator.
For data inside our customers' products, KRAGOS is the OPERATOR. Our customer decides why and how that data is processed. We process it on their documented instruction and for no other purpose. If you are an employee, client or supplier of a KRAGOS customer and your information is in their tenant, your rights run against that customer, not against us. Ask them for their privacy notice. If you approach us we will refer you to them and assist them in answering you.
The distinction matters because it decides who owes you the duty, who you exercise your rights against, and who answers to the Regulator.
Which capacity applies
| Situation | KRAGOS acts as | Responsible party is |
|---|---|---|
| You visit kragos.ai | Responsible party | KRAGOS |
| You use the free compliance calendar | Responsible party | KRAGOS |
| You use the assistant on the public site | Responsible party | KRAGOS |
| You book a meeting with us | Responsible party | KRAGOS |
| You submit a quote request or an industry brief | Responsible party | KRAGOS |
| You are a billing or account contact of a customer | Responsible party | KRAGOS |
| You are an authorised user signing in to a customer tenant | Operator, except for the sign-in and seat records we keep to run and secure the service, where we are responsible party | The customer, and KRAGOS for those records |
| Your details sit in a customer's tenant because you are their client, employee or supplier | Operator | The customer |
| A customer's system sends you a message through Pulse or the WhatsApp rail | Operator | The customer |
Where we are the operator, our undertakings are set out in clause 18 of the Terms of Service and in any signed operator agreement. We process only on the customer's instruction, we keep the data confidential, we secure it, and we notify the customer of a compromise so that the customer can meet its own section 22 duty.
5. What we process, per surface
The table below is the whole picture. Each row says what we collect, why, and on what lawful basis. Clause 12 gives the full basis table.
The public website
| What | Why | Basis |
|---|---|---|
| Server log data: IP address, request time, page requested, user agent, referring page, response status. | To serve the page, to keep the site available, and to detect and investigate abuse. | POPIA s11(1)(f), legitimate interests. GDPR Art 6(1)(f). |
| Nothing else. The site sets no cookies, uses no local storage, loads no third party fonts, analytics or trackers, and makes no request to any host other than its own. | Not applicable. | Not applicable. |
The free compliance calendar
| What | Why | Basis |
|---|---|---|
| The business details you enter to generate a calendar: entity type, sector, registration status, financial year end and similar. | To produce the calendar. | POPIA s11(1)(b), performance of a contract at your request. GDPR Art 6(1)(b). |
| Your name and email address, if you choose to have the calendar sent to you or to receive reminders. | To send you the calendar and, if you ask for them, the reminders. | POPIA s11(1)(a), consent. GDPR Art 6(1)(a). |
| Your consent to receive direct marketing, if you tick the box. The box is not pre-ticked. | To send you marketing about KRAGOS products. Clause 15 explains this and how to stop it. | POPIA s69, consent. GDPR Art 6(1)(a). |
The assistant, and its three exits
| What | Why | Basis |
|---|---|---|
| What you type into the assistant, and the assistant's replies. | To answer your question and to improve how the assistant answers. Do not type anything into it that you would not put in an email to a stranger. | POPIA s11(1)(f), legitimate interests. GDPR Art 6(1)(f). |
| Exit one, a booking. Your name, email address, chosen time and any note you add. | To make and keep the appointment. Handled in Microsoft Bookings. | POPIA s11(1)(b). GDPR Art 6(1)(b). |
| Exit two, a written enquiry. Your name, business, email address, telephone number if you give it, and your message. | To answer you. It reaches ops@kragos.app. | POPIA s11(1)(b) and s11(1)(f). GDPR Art 6(1)(b) and 6(1)(f). |
| Exit three, the free compliance calendar. As set out in the row above. | To produce the calendar. | POPIA s11(1)(b) and, for marketing, s11(1)(a). |
Bookings
| What | Why | Basis |
|---|---|---|
| Name, email address, the meeting time, the agenda note, and the record of attendance. | To schedule, hold and follow up the meeting. | POPIA s11(1)(b). GDPR Art 6(1)(b). |
| Where a meeting is held in Teams and is recorded, the recording and any transcript. We record only with the express agreement of everyone present, asked for at the start of the meeting. | To keep an accurate note. | POPIA s11(1)(a), consent. GDPR Art 6(1)(a). |
Quote and industry brief forms
| What | Why | Basis |
|---|---|---|
| Contact name, business name, business size, email address, telephone number if given, industry, the lines you select or write, and what you tell us is hurting most. | To scope and price what you are asking for, and to answer you. | POPIA s11(1)(b), steps at your request before a contract. GDPR Art 6(1)(b). |
| The record of the enquiry and its outcome, kept in our own systems. | To run our sales pipeline and to know what we quoted and why. | POPIA s11(1)(f). GDPR Art 6(1)(f). |
The authenticated products
| What | Why | Basis |
|---|---|---|
| Authorised user records: name, work email address, seat, release authority, bounds, and the sign-in record. | To issue and secure the seat, to enforce authority, and to keep the STEMPA record of who released what. We are responsible party for these records. | POPIA s11(1)(b) and s11(1)(f). GDPR Art 6(1)(b) and 6(1)(f). |
| Billing and account contacts: name, role, email address, telephone number. | To invoice, to give notice, and to run the account. We are responsible party for these. | POPIA s11(1)(b) and s11(1)(c). GDPR Art 6(1)(b) and 6(1)(c). |
| The STEMPA journal: authority, bounds, act, outcome and inputs for every released act. | To keep an append-only record of what was done, by whom, under what authority. | POPIA s11(1)(b) and s11(1)(f). GDPR Art 6(1)(b) and 6(1)(f). |
Customer end user data, where we are operator
| What | Why | Basis |
|---|---|---|
| Whatever the customer puts in its tenant. That may include names, contact details, identity numbers, employment records, financial records, supplier records, documents and correspondence. | Only to provide the service to that customer, on that customer's documented instruction. | The customer's basis, not ours. We hold no independent basis and take no independent purpose. |
Paying an invoice
| What | Why | Basis |
|---|---|---|
| The name and email address on the quote, the amount, and the merchant reference, sent to our merchant provider so that the payment can be raised and identified. | To take payment for work you have ordered. | POPIA s11(1)(b). GDPR Art 6(1)(b). |
| The signed notification the provider sends back: its own payment reference, the amount that arrived, the payment method and the time. Every notification is stored exactly as received, accepted or refused. | To know that a payment arrived, to issue the tax invoice for it, and to be able to answer 'I paid, what happened?' with a record rather than a recollection. | POPIA s11(1)(b) and s11(1)(c). GDPR Art 6(1)(b) and 6(1)(c). |
| Card number, expiry, security code and any 3-D Secure step: we never receive these. They are entered on the provider's own page after you leave our site. | Not applicable. There is no field for them anywhere in our system. | Not applicable. |
| The link that reaches the payment page is a single-use random token that expires. We store only a one-way hash of it, so we cannot reproduce your link and neither can anyone who obtained our records. | To make a payment link unguessable and short-lived. | POPIA s19 security safeguards. GDPR Art 32. |
We do not knowingly collect special personal information under section 26 of POPIA through the public surfaces. A customer may load special personal information into its own tenant, in which case clause 18.8 of the Terms of Service applies and the customer must tell us first.
6. Where the information comes from
We collect personal information directly from you wherever we can, as section 12 of POPIA requires.
We also receive it from a customer or a prospect who gives us the details of a colleague, from a public source such as the Companies and Intellectual Property Commission or a public website, and from a corporate funder where an enterprise and supplier development programme refers a supplier to us.
Where we receive your information from someone else and you have not dealt with us before, we will tell you at first contact where we got it, unless one of the exceptions in section 18(4) of POPIA applies.
7. Condition 1: Accountability
Section 8 of POPIA makes us responsible for giving effect to all eight conditions. We have appointed an Information Officer, we keep this notice current, and we hold our operators and sub-processors to written terms.
Where we are the operator, accountability for the eight conditions sits with our customer as responsible party. We support the customer in meeting it.
8. Condition 2: Processing limitation
Lawfulness and minimality, sections 9 and 10. We process lawfully, in a way that does not intrude unreasonably on your privacy, and we collect only what is adequate, relevant and not excessive for the purpose in clause 5.
Justification, section 11. Every processing operation has a ground in section 11. Clause 12 sets them out per activity.
Consent, and withdrawing it, section 11(2). Where we rely on consent you may withdraw it at any time by writing to ops@kragos.app. Withdrawal does not affect the lawfulness of what we did before you withdrew, and it does not affect processing we do on another ground.
Objection, section 11(3). Where we rely on legitimate interests you may object to the processing on reasonable grounds, at any time, by writing to ops@kragos.app. We will stop unless the law requires us to continue. You do not have to give a reason to object to direct marketing, and we stop that on request without exception.
Collection directly from you, section 12. Clause 6 explains where information comes from and what we do when it does not come from you.
9. Condition 3: Purpose specification
Specific purpose, section 13. We collect for the specific, explicitly defined and lawful purposes set out in clause 5, and we tell you the purpose at the point of collection.
Retention, section 14. We do not keep records that identify you for longer than is necessary for the purpose, unless the law requires us to keep them, a contract requires it, or you have consented. Clause 21 gives the period for each category.
When a period ends we delete the record or de-identify it so that it can no longer be linked to you. Where a record sits in an encrypted backup, deletion follows the backup cycle in clause 21.
10. Condition 4: Further processing limitation
Section 15 requires further processing to be compatible with the purpose of collection. We do not repurpose your information.
In particular, and to be explicit: information collected through the free compliance calendar is not sold, is not rented, is not shared with a third party for that third party's own marketing, and is not used to train any artificial intelligence model. It is used to produce your calendar, and, if you asked for it, to send you KRAGOS marketing under clause 15.
11. Condition 5: Information quality
Section 16 requires us to take reasonably practicable steps to keep your information complete, accurate, not misleading and up to date.
You can ask us to correct anything that is wrong. Clause 16 gives the route. We would rather you told us than that we kept it wrong.
12. The lawful basis, in full
Section 11(1) of POPIA lists six grounds. We rely on four of them. The two we do not rely on are section 11(1)(d), protection of a legitimate interest of the data subject, and section 11(1)(e), performance of a public law duty by a public body, which does not apply to us.
POPIA section 11 grounds, and where we rely on them
| Ground | Where we rely on it |
|---|---|
| s11(1)(a), consent | Sending you the free calendar and its reminders. Direct marketing under section 69. Recording a meeting. Any processing where we ask you and you say yes. |
| s11(1)(b), necessary to conclude or perform a contract with you | Producing the free calendar you asked for. Answering a quote request. Making a booking. Issuing and running a seat. Invoicing. Delivering the products. |
| s11(1)(c), obligation imposed by law | Keeping accounting records under section 24 of the Companies Act 71 of 2008 and section 29 of the Tax Administration Act 28 of 2011. Issuing tax invoices under the Value-Added Tax Act 89 of 1991. Responding to a lawful demand. |
| s11(1)(f), legitimate interests of KRAGOS or of a third party | Serving and securing the website. Detecting and investigating abuse. Running the sales pipeline and knowing what we quoted. Keeping the STEMPA record. Business to business relationship contact where you are a contact at a customer or supplier. |
Where we rely on legitimate interests we have weighed our interest against your rights and freedoms, and we will give you the outcome of that assessment on request.
For visitors and customers outside South Africa, the parallel GDPR bases are:
GDPR Article 6, parallel table
| POPIA ground | GDPR Article 6(1) | Applies to |
|---|---|---|
| s11(1)(a) consent | Art 6(1)(a) consent | Free calendar delivery, reminders, marketing, meeting recording. |
| s11(1)(b) contract | Art 6(1)(b) contract or pre-contractual steps | Calendar generation, quote requests, bookings, seats, billing, delivery of the products. |
| s11(1)(c) legal obligation | Art 6(1)(c) legal obligation | Accounting, tax and company law record keeping. Note that these are South African obligations; Article 6(3) requires the obligation to be one of Union or Member State law, so for an EU data subject we rely on Article 6(1)(f) for the same retention, with our interest being the ability to defend a claim and to meet our own law. |
| s11(1)(f) legitimate interests | Art 6(1)(f) legitimate interests | Site security, abuse detection, pipeline records, the STEMPA record, business contact. |
| No POPIA equivalent relied on | Art 6(1)(d) vital interests, Art 6(1)(e) public task | Not relied on. |
We do not rely on Article 9 of the GDPR, and we do not seek special category data through the public surfaces.
Where a customer is established in the European Union or the United Kingdom and we act as processor for it, Articles 28 and 32 of the GDPR apply to us in that capacity and we will conclude the required processor terms. Clause 23 records the representative position.
13. Condition 6: Openness
Documentation, section 17. We maintain documentation of our processing operations, and a manual under section 51 of the Promotion of Access to Information Act 2 of 2000, available from ops@kragos.app.
Notification, section 18. This notice is the notification. It is published on kragos.ai, is linked from the footer of every page, and is given to you before or at the time of collection.
14. Condition 7: Security safeguards
What we actually do, section 19. We describe this honestly. We do not claim a certification we do not hold.
- Encryption in transit. All traffic to and from our surfaces uses TLS. Traffic between our systems and our sub-processors uses TLS.
- Access control by seat. Access is granted to a named natural person against a seat, with least privilege, and with explicit release authority and bounds. Administrative access to production is restricted to a small number of named people.
- An append-only journal. STEMPA records every released act, the authority relied on, the bounds in force, the act, the outcome and the inputs. Journal entries are not editable.
- Offsite backup. Encrypted backups are held offsite with Backblaze in EU Central, on the rolling retention stated in clause 21.
- Segregation. Each customer's data sits in its own tenant.
- Review. We keep our safeguards under review, and we take account of generally accepted information security practices as section 19(3) of POPIA requires.
What we do not claim. We hold no ISO 27001 certification and no SOC 2 report. We do not claim that our systems cannot be breached. No system can be guaranteed secure, and we do not warrant that ours is.
Operators, sections 20 and 21. Each sub-processor in clause 19 is engaged under written terms that require it to process only on our instruction, to keep the information confidential, and to secure it.
Breach notification, section 22. Where there are reasonable grounds to believe that personal information for which we are the responsible party has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering it, unless the identity of the data subjects cannot be established. Notification will be in writing and will describe, as far as we know it, the possible consequences, the measures we intend to take or have taken, what you can do to protect yourself, and, where the Regulator tells us the identity of the unauthorised person, that identity. We may delay only where a public body responsible for detection of offences tells us that notification will impede a criminal investigation.
Where we are the operator and the compromise affects a customer's tenant, we notify the customer immediately under section 21(2), so that the customer can meet its own section 22 duty. For an EU or UK customer, we will assist within the 72 hour window in Article 33 of the GDPR.
15. Direct marketing
Section 69 of POPIA prohibits direct marketing by electronic communication unless you have consented, or unless you are an existing customer and the conditions in section 69(3) are met.
Consent, section 69(1)(a). Where you are not an existing customer we send you electronic marketing only if you have opted in. The opt-in box is never pre-ticked and is never bundled with acceptance of anything else. We ask you once. If you do not respond we do not ask again, as section 69(2) requires.
Existing customers, section 69(3). Where you are an existing customer we may market our own similar products to you, using the contact details you gave us in the course of a sale, and we give you the opportunity to object at the time of collection and in every message.
The free compliance calendar. This is worth being explicit about. Giving us your email address so that we can send you the calendar is not consent to marketing. Marketing consent is a separate, unticked box on the same form, described in plain words. If you do not tick it we send you the calendar and nothing else. If you tick it we may send you information about KRAGOS products, and you can stop it at any time under clause 15.5.
Opting out. Every marketing message carries an unsubscribe link that works without you having to sign in or explain yourself. You can also write to ops@kragos.app. We action an opt-out within 5 business days and keep a suppression record so that we do not contact you again by mistake. That suppression record is kept for exactly that purpose.
We do not sell, rent or otherwise make your contact details available to a third party for that third party's marketing.
WhatsApp messages sent through the Pulse rail on a customer's behalf are the customer's marketing, not ours. The customer is the responsible party for them, and the opt-out runs to that customer. We maintain the technical opt-out list on the customer's instruction.
16. Condition 8: Your rights, and how to use them
Section 5 of POPIA gives you the rights below. Where the GDPR applies to you, it gives you two more, marked in the table.
Your rights
| Right | What it means | Source |
|---|---|---|
| To be notified | To be told that your information is being collected, and to be told if it has been accessed by an unauthorised person. | POPIA s5(a), ss18 and 22. GDPR Arts 13, 14 and 34. |
| Access | To ask whether we hold information about you, and to be given the record or a description of it. | POPIA s5(b), s23. GDPR Art 15. |
| Correction | To ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. | POPIA s5(c), s24. GDPR Art 16. |
| Deletion | To ask us to destroy or delete a record we are no longer authorised to retain. | POPIA s5(c), s24(1)(b). GDPR Art 17, right to erasure. |
| Objection | To object, on reasonable grounds, to processing based on legitimate interests, and to object to direct marketing at any time without giving a reason. | POPIA s5(d), s11(3), s69. |
| Not to be subject to a decision based solely on automated processing | See clause 20. | POPIA s5(g), s71. GDPR Art 22. |
| Portability (GDPR only) | To receive the information you gave us in a structured, commonly used, machine readable format, and to have it sent to another controller where technically feasible. POPIA has no equivalent right, but we will do this for anyone who asks. | GDPR Art 20. |
| Restriction (GDPR only) | To ask us to pause processing while a dispute about accuracy or lawfulness is resolved. POPIA has no equivalent right, but we will do this for anyone who asks. | GDPR Art 18. |
| To complain | To the Regulator, and to a court. | POPIA s5(h) and s5(i). GDPR Art 77. |
How to make a request. Write to ops@kragos.app and mark it for the Information Officer. Tell us what you want and give us enough to identify you and to find the record. A POPIA access request under section 23 must be made on Form 2 of the POPIA regulations; we will send you the form if you ask, and we will not refuse a request merely because it did not arrive on the form.
What it costs. Correction, deletion, objection and opt-out are free. A request for access to a record may attract the prescribed fee under section 23(3) of POPIA and the PAIA fee regulations. We will tell you the fee before we do the work, and we will not charge for a simple confirmation of whether we hold information about you.
How long we take. We acknowledge within 5 business days. We respond to a POPIA access request within 30 days of receiving it, extendable once by a further 30 days where the request is complex, in which case we tell you before the first 30 days is up and say why. Where the GDPR applies we respond within one month, extendable by two further months under Article 12(3), with the same notification.
If we say no. We will tell you in writing which ground we rely on, and we will tell you how to complain. We may refuse where the law requires or permits refusal, including where a record is subject to legal privilege, where disclosure would reveal another person's personal information, or where a ground of refusal in the Promotion of Access to Information Act 2 of 2000 applies.
If you are in a customer's tenant. Where we hold your information as operator, we cannot act on your request without our customer's instruction. We will tell you so, tell you who the responsible party is if we may, and pass your request to them promptly.
17. Complaints
Please raise it with us first, at ops@kragos.app. We would rather fix it.
You may complain to the Information Regulator at any time, whether or not you have come to us first. A POPIA complaint is made on Form 5 of the POPIA regulations.
The Information Regulator (South Africa)
| Physical address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Postal address | P.O. Box 31533, Braamfontein, Johannesburg, 2017 |
| Telephone | 010 023 5200 |
| General enquiries | enquiries@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| Website | inforegulator.org.za |
Where the GDPR applies to you, you may also complain to the supervisory authority of the Member State where you live, work, or where the alleged infringement happened, under Article 77 of the GDPR.
Nothing in this notice limits your right to approach a court.
18. Who we share information with
We share personal information with the sub-processors in clause 19, each for the purpose stated there and for no other.
We also share it with our professional advisers, our auditors and our bankers where they need it, under a duty of confidence; and with a law enforcement agency, a regulator or a court where the law requires it.
If our business or a part of it is sold, transferred or reorganised, personal information may transfer with it. The acquirer becomes bound by this notice until it gives you a new one.
We do not sell personal information.
19. Cross-border transfers, and the sub-processor schedule
Section 72 of POPIA prohibits transferring personal information out of South Africa unless one of five grounds applies. The grounds are: the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection with principles substantially similar to POPIA's, including provisions substantially similar to section 72 for onward transfer; the data subject consents; the transfer is necessary for the performance of a contract between the data subject and the responsible party, or for pre-contractual steps at the data subject's request; the transfer is necessary for the conclusion or performance of a contract concluded in the data subject's interest between the responsible party and a third party; or the transfer is for the data subject's benefit and consent is not reasonably practicable but would probably be given.
The ground we rely on. For each transfer below we rely on section 72(1)(a), a binding written agreement with the recipient that requires an adequate level of protection and that binds onward transfer, and, where the transfer is needed to deliver something you asked for, additionally on section 72(1)(b) or 72(1)(c). Where the GDPR applies, transfers out of the European Economic Area are made on the European Commission's standard contractual clauses under Article 46(2)(c).
What we hold today, said plainly rather than assumed
Section 72(1)(a) is discharged by an instrument we hold and can produce, not by a processor publishing terms on its own website. For several of the recipients below we do not yet hold a signed data processing agreement. We record that here rather than implying otherwise, and completing that set is an open action.
Where a location cell reads not established, it means the location of processing is not recorded in our own dependency register. We will not state a country we have not verified.
The primary is in South Africa. The live data for the products sits with Xneelo in Johannesburg, and Xneelo and VALR are South African. Everything else in table A is a transfer out of South Africa and is treated as one.
Two tables, because they are two different things. Table A is the sub-processors we engage to deliver the Services. Table B is services reached only because you connected an account of your own. For table B you are the controller of that account and of what it publishes; we act on your release and pass nothing to it that you did not put there.
A. Sub-processors KRAGOS engages
| Sub-processor | Where it processes | Purpose | Personal information it may touch |
|---|---|---|---|
| Omnea (Pty) Ltd | South Africa | Merchant provider. KRAGOS collects payment on its own invoices through Omnea under a contract held by Ecopackaging (Pty) Ltd, routing code ECO. | The payer's name and email address as they appear on the quote, the amount, the merchant reference, the payment method used and Omnea's own payment reference. No card data. |
| InstaPay WebPay (an Omnea (Pty) Ltd product) | South Africa | Hosted checkout and payment redirect. This is the page a payer is taken to when they press Pay, and where card details are entered. | Card number, expiry, security code and any 3-D Secure step, entered by the payer directly with InstaPay and never with KRAGOS; the payer's name, email address and, if given, mobile number. |
| Anthropic PBC | United States | Large language model inference for the AI capabilities in the Products. | Prompt content, which may include Customer Data placed in a prompt by a released or proposed act. |
| Microsoft Ireland Operations Limited | Ireland and the European Union | Identity and sign-in, mail, file storage, Bookings and Teams, across the KRAGOS tenant and a client tenant. | Names, email addresses, calendar and booking details, message and document content, sign-in records. |
| Backblaze B2 | Netherlands, European Union (bucket kragos-backup, region eu-central-003) | Encrypted offsite backup of the whole server, nightly. | Encrypted copies of every category held in the Products and in mail. This is the single largest transfer KRAGOS makes. |
| Xneelo (Pty) Ltd | Johannesburg, South Africa | Hosting. This is the South African resident primary; it is where the live data sits and it is not a cross-border transfer. | All categories held in the Products and on the public site. |
| Namecheap, Inc. | United States | Domain registration and authoritative DNS for kragos.ai and kragos.app. | Registrant and technical contact details of KRAGOS's own officer. No end user or Customer Data. |
| GitHub, Inc. | United States | Source control for the KRAGOS codebase and its build pipeline. | Source code and configuration. Customer Data is not committed to it by design; KRAGOS's own audit has found identifier-bearing filenames in repository history and that is being cleared. |
| ElevenLabs, Inc. | United States | Voice synthesis and music generation behind the voice and music capabilities. | The text to be spoken, which may include Customer Data placed in it by a released act. |
| Meta Platforms | Ireland and the United States | WhatsApp Business messaging on approved templates. | Recipient phone numbers and message content. |
| ntfy | NOT ESTABLISHED in KRAGOS's own records | Operational push alerts to the operator's own device: build failures, verdicts and dead-man beacons. | Alert text. KRAGOS's own rule limits these to names and shapes; the register records that whether this is the public hosted service or a self-hosted one is not established. |
| ClamAV, by Cisco Talos | United States (database.clamav.net) | Malware signature database, downloaded so that uploaded documents can be refused before they are parsed. | None. Signatures are downloaded to KRAGOS; no document is uploaded to ClamAV. |
| Xero Limited | NOT ESTABLISHED in KRAGOS's own records | Accounting integration. | Contact, invoice and ledger records for the businesses whose books are connected. |
| Stability AI | NOT ESTABLISHED in KRAGOS's own records | Audio and music generation, behind a vendor-swappable seam. Recorded in the estate as deferred rather than in use. | The prompt text submitted for generation. |
| Healthchecks.io | NOT ESTABLISHED in KRAGOS's own records | Dead-man monitoring: a scheduled job pings it, and its silence is the alarm. | A check identifier and a status. No personal information identified, and that is a claim to verify rather than to trust. |
| VALR (Pty) Ltd | Johannesburg, South Africa | A read-only market and account feed for the owner's own portfolio rail. It is not on any customer path. | None belonging to a customer. |
B. Services your own configuration engages
| Service | Where it processes | Purpose | Personal information it may touch |
|---|---|---|---|
| Google Ireland Limited / Google LLC | NOT ESTABLISHED in KRAGOS's own records | Google Ads campaign data, and Google sign-in where a customer connects a Google account. | Campaign, audience and performance parameters for the customer's own advertising account. KRAGOS's own adapter reads reporting; it does not send customer contact lists. |
| YouTube (Google) | NOT ESTABLISHED in KRAGOS's own records | Publishing video to, and reading analytics from, a customer's own YouTube channel. | The content published, and the channel's own performance figures. |
| TikTok | NOT ESTABLISHED in KRAGOS's own records | Publishing video to, and reading analytics from, a customer's own TikTok account. | The content published, and the account's own performance figures. |
| LinkedIn Ireland Unlimited Company | NOT ESTABLISHED in KRAGOS's own records | Publishing to a customer's own LinkedIn page. | The content published, and the identity of the page it is published to. |
| Meta Platforms (Facebook and Instagram pages) | Ireland and the United States | Publishing to a customer's own Facebook or Instagram page. | The content published, and the identity of the page it is published to. |
Payments. Omnea and its InstaPay WebPay product are in table A because we use them to collect payment on our own invoices, under a merchant contract held by Ecopackaging (Pty) Ltd with the routing code ECO. Both are South African, so paying us is not a cross-border transfer. Card data never reaches us. The payment page is InstaPay's. Clause 7 of the Terms of Service sets out what we do and do not handle, and clause 13 of the Terms of Service records the processor disclosure.
C. Named, but not engaged
| Service | Status | Why it appears here | Personal information |
|---|---|---|---|
| OpenAI | Not engaged | Image generation. Named in KRAGOS's own design record as the leading candidate for a not-yet-chosen image vendor. | None. No adapter exists, no key is wired, and the seam refuses with a plain message rather than generating anything. |
| Cloudflare, Inc. | Not engaged | None. This entry exists to refuse a recurring assumption: KRAGOS has no Cloudflare account, zone or bill. DNS is at Namecheap. | None. |
| Plausible Analytics | Not engaged | Web analytics. It appears in the estate only as an unactioned suggestion to register an account; no analytics package runs on either surface. | None. |
Analytics. There are none. We run no analytics package, no tag manager and no advertising pixel on either surface. If that changes, this notice will be updated and its version number raised before the change goes live, and the Cookie Notice will be updated at the same time.
No third party fonts, analytics or trackers on the site. The public site loads its typeface from our own server. It makes no request to any host other than its own. This was verified in a browser against the built site, on every page, and the result is recorded in the build proof.
What changed at this version. Omnea, InstaPay WebPay, ClamAV, VALR, Xero, Stability AI and Healthchecks.io were added to table A, and the whole of table B and table C are new. They were found by reading our own code for every outbound connection it makes, rather than by copying the previous list forward.
These tables are current at the version date of this notice. We will update them before adding a sub-processor that processes personal information, and clause 18.5 of the Terms of Service gives customers 30 days notice and a right to object.
20. Automated decision making
No decision that matters is made by a machine alone
Section 71 of POPIA and Article 22 of the GDPR both address decisions made solely by automated means that have a legal effect on you or that affect you to a substantial or similarly significant degree.
The KRAGOS architecture is built so that this does not happen. The system proposes. A named person holding release authority releases. Nothing that spends, sends, signs or files happens without that release. So there is a human in the loop, with authority and with the ability to decide otherwise, on every act that could have a legal or similarly significant effect.
Section 71(1) of POPIA prohibits a decision that results in legal consequences for a data subject, or that affects the data subject to a substantial degree, being based solely on the automated processing of personal information intended to provide a profile.
We do not make such a decision solely by automated means. Where AI Output informs a decision, the decision is made by a natural person who holds release authority, who sees what is proposed, and who may refuse it. That person's release is recorded in STEMPA together with the authority relied on.
Because a human makes the decision, the exceptions in section 71(2) are not the basis on which we operate. We do not rely on them, and we do not need to.
Under the GDPR, Article 22(1) gives the same right. Our position is the same: there is meaningful human involvement by a person with the authority and competence to change the outcome, so Article 22(1) is not engaged. Where a customer configures its tenant so that this is no longer true, that customer is the controller of that decision and takes on the Article 22 obligations.
If you believe a decision affecting you was made about you solely by automated means in a KRAGOS product, write to ops@kragos.app. We will tell you what happened, who released it, and on what authority, and if we are the operator we will refer you to the responsible party.
21. How long we keep things
Section 14 of POPIA requires us to keep a record no longer than is necessary. These are the periods.
Retention
| Category | Period | Why |
|---|---|---|
| Server log data | 90 days | Enough to investigate an incident, not enough to build a profile. |
| Assistant conversations | 12 months from the last message | To answer follow-ups and to improve how the assistant answers. |
| Free compliance calendar records, no marketing consent | 24 months from generation, then deleted | To reproduce your calendar if you ask, and to answer a query about it. |
| Free compliance calendar records, with marketing consent | Until you opt out, and then 36 months in the suppression list | To honour the consent while it lasts, and then to make sure we do not contact you again. |
| Enquiry, quote and industry brief records that do not become a customer | 24 months from the last contact | To answer a returning prospect and to know what we quoted. |
| Bookings records | 24 months | To keep an accurate meeting history. |
| Meeting recordings and transcripts | 12 months, unless the parties agree otherwise in writing | To keep an accurate note of what was agreed. |
| Customer account, billing and authorised user records | The term, then the export window, then deleted from the live systems within 90 days of the end of the export window | Clause 20 of the Terms of Service. |
| Customer end user data in a tenant | On the customer's instruction. Absent a different instruction, as for the row above | We are the operator. The customer sets the period. |
| The STEMPA journal | 7 years from the date of the act | It is an accounting and governance record. Section 24 of the Companies Act 71 of 2008 requires seven years for company records. |
| Accounting records, invoices, tax records | 5 years from the date of submission of the relevant return, and 7 years where the Companies Act requires it | Section 29 of the Tax Administration Act 28 of 2011 and section 24 of the Companies Act 71 of 2008. |
| Email correspondence | 7 years | It is often the record of an agreement or an instruction. |
| Encrypted offsite backups | Rolling cycle, purged within 12 months | Deletion from live systems is followed by expiry from backup on the cycle. |
| Records needed for a live or anticipated legal claim | Until the claim is resolved and any appeal or prescription period has run | Establishment, exercise or defence of a legal claim. |
Where two periods apply to the same record, the longer applies, and only for the purpose that justifies it.
22. Children
The services are not directed at children. We do not knowingly collect the personal information of a child, as defined in section 1 of POPIA, through the public surfaces, and we do not market to children.
Section 34 of POPIA prohibits processing the personal information of a child except in the circumstances in section 35, including with the consent of a competent person. We do not rely on section 35 for the public surfaces.
If you believe a child has given us personal information, write to ops@kragos.app and we will delete it.
A customer may hold the personal information of a child in its own tenant, for example a non-profit that runs a programme for children. Where it does, that customer is the responsible party, clause 18.8 of the Terms of Service applies, and the customer must comply with sections 34 and 35 itself.
23. The European Union and the United Kingdom
KRAGOS is established in South Africa and does not currently target the European Union or the United Kingdom market. We do not offer the products in a Union or United Kingdom currency or language, and we do not monitor behaviour in those territories.
A representative is an outstanding action, not a claim. If and when we accept a customer established in the European Union or the United Kingdom, and Article 3(2) of the GDPR or the United Kingdom GDPR applies to us as a result, we will appoint a representative under Article 27 before that customer goes live, and we will publish that representative's name and address in this notice. We have not appointed one, and we do not claim to have one.
The GDPR rights and bases set out in this notice are given voluntarily to any visitor who wants them, whether or not the GDPR applies to that visitor.
24. Cookies
The Cookie Notice is a separate document, linked from the footer. In short: the public site sets no cookies at all, and uses no local or session storage.
25. Changes to this notice
We will update this notice when our processing changes. Every version carries a version number and a last updated date at the top.
Where a change materially affects you, and in particular where we add a sub-processor that processes personal information, add analytics or advertising, or change a retention period, we will raise the version number and, where we have your contact details and the change is material, tell you before it takes effect.
We keep the superseded versions and will provide one on request.
Privacy Notice, version 1.1, last updated 5 September 2026. Published by Ecopackaging (Pty) Ltd (registration number 2014/032538/07, VAT registration number 4530265216) trading as KRAGOS, 750 Nieuwhout Street, Garsfontein, Pretoria, 0081, South Africa. All enquiries and notices to ops@kragos.app. Information Officer: Francois Petrus Heunis. Governed by the law of the Republic of South Africa; the parties consent to the jurisdiction of the Gauteng Division of the High Court of South Africa, Pretoria.