Our privacy policy
Last updated: 04 August 2026
This Privacy Notice explains how Dataseka (Pty) Limited (Dataseka, we, us or our) collects, uses, discloses, stores and otherwise processes Personal Information when you visit our website, communicate with us, create or use a Dataseka account, use the Dataseka data analytics and visualisation platform, use Seeka or another artificial-intelligence feature, receive Professional Services, or otherwise interact with us.
This Notice should be read with our Terms of Service, any applicable Order, our Data Processing Addendum (DPA), the cookie information in section 10 and any service-specific privacy information presented when Personal Information is collected.
1. Important information about this Notice
1.1 Scope
This Notice applies to Personal Information that Dataseka processes for its own purposes, including information about:
- website visitors, prospects and business contacts;
- customers, account administrators and authorised users;
- users of Seeka and other AI Features;
- people who contact support or receive Professional Services;
- people who view publicly shared Dataseka content where Dataseka collects technical or security information; and
- suppliers, partners and other people who interact with our business.
1.2 Customer Data
Customers may connect, upload, analyse and share data through the Services (Customer Data). Where Dataseka processes Personal Information contained in Customer Data only on a customer’s documented instructions, the customer is ordinarily the responsible party or controller, and Dataseka is ordinarily the operator or processor.
The customer’s privacy notice governs why the customer collects and uses that Customer Data. Dataseka’s processing obligations are governed by the customer agreement and DPA. If your request relates to Personal Information held in a customer’s Dataseka workspace, you should normally contact that customer first. We will assist the customer as required by applicable law and the DPA.
1.3 This Notice is not consent or a contract
This Notice provides information about our processing practices. It does not itself create consent, and your continued use of the Services does not replace any consent or other lawful basis required by law.
2. Who we are and how to contact us
Dataseka (Pty) Limited is a company incorporated in South Africa.
- Registration number: 2026/292616/07
- Principal or registered address: V & A Waterfront, Cape Town, South Africa
- Privacy and Information Officer enquiries: hello@dataseka.com
- Website: https://dataseka.com
- Contact page: https://dataseka.com/contact
- Registered Information Officer: Chantel Boris, Compliance Officer
Under POPIA, Dataseka is the responsible party for Personal Information that it determines how and why to process. Under the GDPR, UK GDPR and similar laws, Dataseka is the controller for that information.
Where required by applicable law, details of Dataseka’s representative in the European Union or United Kingdom will be published here before the relevant Services are offered or monitored in a manner requiring such an appointment:
- EU representative: Chantel Boris, Compliance Officer
- UK representative: Chantel Boris, Compliance Officer
3. Key definitions
AI Feature means Seeka or another feature that uses artificial intelligence or machine learning.
AI Input means a prompt, instruction, question, schema, query, data sample, Customer Data or other material submitted to an AI Feature.
AI Output means a response, explanation, query, code, dataset, chart, dashboard, summary or other result generated through an AI Feature.
Authorised User means an individual whom a customer authorises to use the Services.
Customer-Managed Environment means a private-cloud or on-premises environment supplied, funded and controlled by a customer in which Dataseka software is deployed.
Personal Information has the meaning given by applicable law. Under POPIA, it may relate to an identifiable natural person or an identifiable existing juristic person. Under the GDPR and similar laws, personal data generally relates to an identifiable natural person.
Professional Services means implementation, integration, migration, configuration, deployment, dashboard development, training, support or advisory services supplied by Dataseka.
Usage Data means technical, operational and statistical information about the use, performance, security and administration of the Services. Usage Data may include Personal Information such as user identifiers, IP addresses and activity records, but does not include Customer Data except for limited metadata or diagnostic information reasonably necessary to operate, secure or support the Services.
4. Personal Information we collect
The information we collect depends on how you interact with Dataseka, the deployment model selected by the customer and the features used.
4.1 Account, identity and organisation information
We may collect:
- name, business email address, telephone number and job title;
- employer or organisation name, department and business address;
- username, user identifier, workspace, role and permissions;
- account preferences and profile information;
- administrator details and invitations; and
- information used to verify that a person is authorised to act for an organisation.
Where Dataseka manages password authentication, passwords are stored using one-way security techniques rather than in readable form. Where you use single sign-on or social login, we may receive identifiers, profile information, authentication tokens and other information authorised by you or your organisation.
4.2 Billing, subscription and transaction information
We may collect:
- billing contact and address;
- tax and company information;
- plan, creator subscriptions, licensed environment and contract details;
- invoices, payments, credits, refunds and transaction history;
- payment-provider references and limited payment-method details; and
- AI task type, displayed price, confirmation, completion status, charge and spending-limit records.
Payment providers process card and bank details under their own terms. Dataseka does not intend to store complete payment-card numbers or security codes.
4.3 Technical, security and Usage Data
We may collect:
- IP address, approximate location derived from IP, device, browser and operating-system information;
- login times, authentication events, session and device identifiers;
- pages and features accessed, actions taken, dashboards viewed, queries executed and exports performed;
- workspace, role and permission changes;
- performance measurements, error reports, diagnostics and support identifiers;
- security events, suspected abuse, malware or fraud signals; and
- cookie and similar-technology identifiers, subject to applicable consent requirements.
4.4 Connected data sources and integrations
When a customer connects a database, spreadsheet, cloud service or business system, we may process:
- source-system name and connection metadata;
- database, table, field and schema information;
- OAuth tokens, API keys or other connection credentials;
- data-refresh settings and connection logs;
- query text, query status and limited result samples needed to perform the requested function; and
- information returned by the connected service according to the permissions authorised by the customer.
Credentials and tokens are used only to provide the configured connection and are subject to access controls and security measures appropriate to their sensitivity.
4.5 Seeka and other AI Features
When an AI Feature is used, we may process:
- prompts, questions and instructions;
- relevant schemas, metadata, business definitions and permissions;
- data or query-result excerpts needed to perform the task;
- AI Outputs and user-requested revisions;
- task type, model or route selected, timestamps, user and workspace identifiers;
- safety, validation, error and retry information; and
- feedback, ratings and corrections submitted by users.
AI Inputs and Outputs may contain Personal Information or confidential information if a user or customer includes it or if it appears in the connected data. Users should avoid submitting Personal Information that is not reasonably necessary for the task.
4.6 Communications and Professional Services
We may collect information contained in:
- support requests, emails, chat messages and meeting notes;
- Google Chat, WhatsApp or other customer-selected communication channels;
- product demonstrations, consultations, surveys and feedback;
- implementation documentation, configuration records and testing results;
- training attendance and recordings, where recording is disclosed and lawful; and
- data samples or system information provided for troubleshooting or Professional Services.
Third-party communication tools process information under their own privacy terms. Customers should not send sensitive Customer Data through informal support channels unless Dataseka has expressly approved the method.
4.7 Sales, marketing and relationship information
We may collect business contact information, correspondence, event participation, referral source, stated interests, communication preferences and information from public professional sources, partners or referrals where lawful.
4.8 Customer Data
Customer Data may include ordinary Personal Information, special or sensitive Personal Information, financial information, employment information, health information, children’s information or information about a customer’s clients and suppliers. Dataseka does not determine the contents of Customer Data. The customer is responsible for ensuring that its collection and use are lawful and appropriate for the selected Services and deployment.
5. How we collect Personal Information
We collect Personal Information:
- directly from you when you register, subscribe, communicate, make a payment or use the Services;
- from a customer or administrator who creates or manages your account;
- automatically through the Services, logs, cookies, security tools and analytics;
- from connected data sources and services at the customer’s direction;
- from identity, payment, communications, support, cloud and AI providers;
- from business partners, referrals, events and public professional sources; and
- through Professional Services and customer-authorised access to systems or data.
If you provide Personal Information about another person, you must be authorised to do so and provide any notice required by law.
6. Why we process Personal Information and our lawful bases
The lawful basis depends on the information, purpose and applicable law. Under POPIA, we rely on consent or another justification permitted by section 11. Under the GDPR and UK GDPR, we rely on one or more of the bases described below.
| Purpose | Examples | Typical lawful basis where applicable |
|---|---|---|
| Provide and administer the Services | Create accounts, authenticate users, operate workspaces, provide dashboards, process AI tasks, manage subscriptions and deliver support | Performance of a contract; steps requested before entering a contract; legitimate interests; customer instructions where we act as processor |
| Process Customer Data | Connect, store, query, transform, visualise and share Customer Data as configured by the customer | Customer’s documented instructions under the DPA; the customer determines its own lawful basis |
| Provide AI Features | Prepare context, transmit inputs to approved model providers, generate and validate outputs, execute tools and record task charges | Performance of a contract; customer instructions; legitimate interests in safe and reliable operation |
| Billing and records | Process payments, issue invoices, maintain tax and accounting records and prevent payment fraud | Performance of a contract; legal obligation; legitimate interests |
| Security and abuse prevention | Authenticate users, detect unauthorised activity, investigate incidents, enforce permissions and protect systems and people | Legitimate interests; legal obligation; protection of rights and safety |
| Support and Professional Services | Troubleshoot, configure, migrate, train, test and implement customer requirements | Performance of a contract; legitimate interests; customer instructions |
| Improve Dataseka | Measure performance, understand feature use, correct errors and improve workflows using Usage Data, feedback and appropriately de-identified information | Legitimate interests, balanced against privacy rights; consent where required |
| Communicate about the Services | Send invoices, security notices, administrative messages, product changes and support communications | Performance of a contract; legal obligation; legitimate interests |
| Sales and marketing | Respond to enquiries and send permitted product, event or educational communications | Consent; legitimate interests; existing-customer exception or other basis where permitted by law |
| Legal and corporate purposes | Comply with law, respond to lawful requests, establish or defend claims, complete audits and manage a corporate transaction | Legal obligation; legitimate interests; establishment or defence of legal claims |
Where we rely on legitimate interests, those interests may include operating and securing the Services, responding to customers, improving reliability, developing our business and protecting Dataseka, customers and users. You may request information about a relevant balancing assessment where applicable.
We do not use Customer Data, identifiable AI Inputs or identifiable AI Outputs for unrelated advertising or to train a general-purpose or foundation model unless the customer gives a separate, express and informed opt-in under written terms.
7. Customer Data and data-protection roles
7.1 Dataseka as operator or processor
When Dataseka processes Personal Information in Customer Data only to provide the Services on a customer’s documented instructions, Dataseka acts as operator or processor. The DPA addresses, among other things:
- documented processing instructions;
- confidentiality and authorised personnel;
- security measures;
- subprocessors;
- international transfers;
- assistance with data-subject requests and impact assessments;
- security-incident notification;
- deletion or return of Customer Data; and
- audits and compliance information.
7.2 Dataseka as responsible party or controller
Dataseka acts as responsible party or controller for Personal Information used to manage accounts, billing, security, product administration, marketing, legal compliance and Dataseka’s business operations. Dataseka may also independently determine limited processing necessary to prevent fraud, investigate abuse, protect the Services and comply with law.
7.3 Customer responsibilities
Customers are responsible for:
- providing lawful instructions and an appropriate lawful basis for Customer Data;
- giving required privacy notices and obtaining required permissions;
- configuring permissions, sharing, retention and data connections;
- ensuring that the Services are appropriate for the sensitivity and regulated nature of the data;
- responding to data-subject requests concerning Customer Data; and
- complying with laws applicable to the customer’s use of analytics and AI Outputs.
7.4 Professional Services access
Dataseka personnel do not routinely inspect Customer Data. Authorised personnel may access it where reasonably necessary to provide customer-requested support or Professional Services, investigate a security or abuse issue, comply with law, or perform another activity authorised by the customer. Access is limited to personnel and service providers subject to confidentiality and appropriate access controls.
8. Seeka, AI privacy and automated processing
8.1 AI providers and subprocessors
Dataseka may use enterprise cloud AI providers to provide AI Features. Current providers and material subprocessors are identified in the Subprocessors section of our Trust page. Additional information about Seeka is available in the AI section.
A selected AI provider may temporarily process or retain AI Inputs and Outputs for service delivery, caching, security, safety or abuse prevention under its enterprise terms. Dataseka contractually requires selected providers not to use Customer Data or AI content to train their general-purpose models except where the customer has expressly instructed or opted in to that use.
8.2 No general model training without opt-in
Dataseka does not use Customer Data, identifiable AI Inputs or identifiable AI Outputs to train a general-purpose or foundation model and does not permit a Dataseka-selected AI provider to do so, unless the customer expressly opts in under separate written terms or a clear, specific Platform control.
Dataseka may use:
- aggregated or de-identified Usage Data;
- task-performance measurements;
- non-confidential feedback;
- user-provided ratings and corrections; and
- reusable workflow patterns that do not identify a customer or individual,
to evaluate and improve Seeka, routing, prompts, validation, automation and the Services. Dataseka will not attempt to re-identify properly de-identified information.
Where a design partner permits Dataseka to use identifiable examples or confidential workflow information for product development, the permitted purpose, access, retention, ownership and safeguards must be agreed separately in writing.
8.3 Customer-managed AI provider accounts
A customer may connect its own AI-provider account where supported. In that case:
- the customer contracts with and pays the provider directly;
- the customer controls the provider account, region, retention settings and enabled models;
- the customer’s agreement with that provider governs the provider’s processing;
- Dataseka transmits the information reasonably necessary to perform the requested task; and
- Dataseka may retain task, orchestration, security and billing records as described in this Notice.
8.4 Human review
Dataseka does not routinely use human reviewers to read AI conversations. Limited authorised access may occur when a user requests support, a customer expressly authorises review, Dataseka investigates a security or abuse concern, or access is required by law. Where feasible, Dataseka minimises the data exposed and uses redaction, sampling or de-identification.
8.5 Automated decision-making
Dataseka may use automated signals to detect fraud, spam, security threats, prohibited use or service errors. Dataseka does not use account, marketing or Usage Data to make a decision about an individual that is based solely on automated processing and produces legal or similarly significant effects, except where lawful safeguards and any required human review are in place.
Seeka provides analytical assistance and does not independently make employment, credit, insurance, medical, legal or other high-impact decisions about individuals. Customers are responsible for ensuring that any use of Customer Data or AI Output in such decisions is lawful, transparent, accurate, appropriately validated and subject to meaningful human oversight.
9. How we disclose Personal Information
Dataseka may disclose Personal Information only as reasonably necessary for the purposes described in this Notice.
9.1 Service providers and subprocessors
We may use providers for:
- cloud hosting, storage, databases and monitoring;
- AI models, orchestration and safety services;
- identity, single sign-on and authentication;
- payment processing, billing and accounting;
- email, support and communications;
- analytics, error reporting and performance monitoring;
- security, fraud prevention and incident response; and
- Professional Services and technical support.
Providers receive only the information reasonably necessary for their functions and are subject to contractual privacy, confidentiality and security obligations appropriate to their role.
9.2 Customers, administrators and other users
A customer’s administrators may access and control an Authorised User’s account, workspace activity, permissions, content and usage. Information may be disclosed to other users or external recipients when a customer or user shares dashboards, links, exports or other content.
9.3 Connected services and customer-selected providers
When a customer enables an integration, customer-managed AI account or other third-party service, Dataseka discloses the information needed to perform the instruction. The third party may independently process information under its own terms where it is selected and controlled by the customer.
9.4 Public and external sharing
If a customer makes a dashboard, link or other content public or accessible to external recipients, those recipients may view, copy or redistribute the information. Customers are responsible for ensuring that public or external sharing is lawful and properly configured.
9.5 Legal, safety and corporate purposes
We may disclose information:
- to comply with applicable law, court orders or lawful regulatory requests;
- to protect rights, safety, security and property;
- to investigate fraud, abuse or unlawful activity;
- to professional advisers, auditors, insurers and financiers under confidentiality obligations; and
- in connection with a merger, financing, reorganisation, sale of assets or similar transaction, subject to appropriate confidentiality and notice where required.
9.6 No sale or targeted advertising using Customer Data
Dataseka does not sell Personal Information or Customer Data for money. Dataseka does not share Personal Information for cross-context behavioural advertising and does not use Customer Data, AI Inputs or AI Outputs to target advertising.
10. Cookies, analytics and similar technologies
Dataseka uses essential cookies and similar technologies required for authentication, security, session management and core functionality.
Where required by law, non-essential analytics, preference or marketing technologies are used only after valid consent. You can manage available choices through Dataseka’s cookie banner when it is displayed. Withdrawing consent does not affect prior lawful processing.
Information presented in the cookie banner identifies the available technologies, providers, purposes and durations. Browser settings may also block or delete cookies, although essential features may stop working.
Where applicable, Dataseka will recognise legally required opt-out preference signals, such as Global Privacy Control, for the processing to which those signals apply. Because browser “Do Not Track” signals are not governed by a single global standard, Dataseka responds to them only where required by law.
11. International transfers and data location
Dataseka is established in South Africa and uses service providers that may process information in South Africa and other countries. Data location depends on the purchased deployment model, connected providers and the applicable Order.
An overview of the available hosting models is provided in the Deployment section of our Trust page.
11.1 Dataseka Cloud
For shared or Dataseka-managed dedicated hosting, Customer Data is stored in the region stated in the Order or Documentation, if a specific region is committed. Support, security, billing, identity, diagnostic or subprocessor data may be processed from other locations unless the Order expressly provides otherwise.
11.2 Customer-Managed Environments
For private-cloud and on-premises deployments, the customer generally controls where Customer Data is hosted. Dataseka may still process account, licence, support, telemetry, security or Professional Services information outside that environment as described in this Notice and the Order. A customer can control or restrict optional telemetry where the Documentation permits.
11.3 Transfer safeguards
Where required, Dataseka uses a lawful transfer mechanism, which may include:
- a finding that the recipient country provides adequate protection;
- the European Commission’s Standard Contractual Clauses;
- the UK International Data Transfer Agreement or UK Addendum;
- contractual protections satisfying section 72 of POPIA;
- another approved transfer mechanism; or
- a lawful exception that applies to the specific transfer.
Dataseka may also use supplementary technical and organisational measures appropriate to the transfer risk. Security certifications and encryption support data protection but do not, by themselves, replace a legally required transfer mechanism.
You may request information about the applicable safeguards by contacting hello@dataseka.com, subject to confidentiality and security limitations.
12. Security
Dataseka maintains technical and organisational measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature of the Services, deployment, information and risk and may include access controls, encryption, secrets management, logging, backups, vulnerability management, secure development practices and incident-response procedures.
No system can be guaranteed to be completely secure. Customers and users must protect credentials and devices, configure access appropriately, maintain secure source systems and promptly report suspected unauthorised access.
Current security information is available on our Trust page. Suspected vulnerabilities can be reported using the security-reporting guidance. Public statements about specific certifications, algorithms, audit frequency, recovery periods or monitoring should be treated as commitments only where Dataseka has verified and can maintain them.
13. Security incidents
Where Dataseka acts as an operator or processor and becomes aware of a Personal Information breach affecting Customer Data, Dataseka will notify the affected customer without undue delay and provide information reasonably available to support the customer’s legal obligations, as described in the DPA.
Where Dataseka acts as responsible party or controller, it will notify the South African Information Regulator, affected data subjects and other competent authorities as required by applicable law. Different laws use different thresholds and deadlines; no single 72-hour rule applies to every incident or role.
14. Retention and deletion
Dataseka retains Personal Information only for as long as reasonably necessary for the purpose collected, to provide the Services, comply with law, resolve disputes, enforce agreements, protect security and maintain required records. Retention may be extended where information is subject to a legal hold, investigation or unresolved claim.
The following are Dataseka’s standard retention periods unless an Order, DPA, workspace setting or legal requirement provides otherwise:
| Information | Standard retention |
|---|---|
| Account, subscription and contract records | While the relationship is active and generally up to 5 years afterwards |
| Billing, invoice and tax records | Generally 7 years from the relevant transaction or financial period |
| Sales enquiries and prospect records | Generally 24 months after the last meaningful interaction, unless a longer relationship exists or you opt out |
| Marketing consent and suppression records | As needed to demonstrate consent or honour an opt-out, generally up to 5 years after the last communication |
| Security, authentication and Usage Data logs | Generally up to 12 months, or longer where required for an incident, investigation or legal claim |
| Support and Professional Services records | Generally up to 3 years after the matter closes, subject to contract and legal needs |
| AI task history and AI Outputs visible in a workspace | Until deleted by an authorised user, the applicable workspace retention period expires, or the customer relationship ends |
| Operational AI logs used for safety, validation or troubleshooting | Generally up to 90 days, unless retained longer for an incident, dispute, legal obligation or customer-authorised support |
| AI task billing records | Generally 7 years as part of transaction and accounting records |
| Customer Data in Dataseka Cloud | During the Subscription Term and then deleted or returned according to the DPA and Order; ordinarily removed from active systems within 30 days and aged out of backups within 90 days |
| Customer Data in a Customer-Managed Environment | Controlled by the customer; Dataseka retains only information separately provided or generated for support, licensing or Professional Services |
Dataseka may retain aggregated or properly de-identified information that is no longer Personal Information, provided it does not attempt to re-identify it.
15. Your choices and rights
Your rights depend on your location, the law that applies and whether Dataseka is responsible party/controller or operator/processor for the relevant information.
You may have the right to:
- request confirmation that Dataseka processes your Personal Information;
- request access to or a copy of it;
- request correction, completion or updating;
- request deletion or destruction where legally available;
- object to certain processing, including direct marketing;
- request restriction of processing;
- receive certain information in a structured, commonly used and machine-readable format;
- withdraw consent where processing is based on consent;
- object to or request safeguards concerning certain solely automated decisions;
- opt out of a sale, sharing, targeted advertising or qualifying profiling where applicable; and
- lodge a complaint with a competent regulator.
15.1 How to exercise a right
Contact hello@dataseka.com and describe the right and information concerned. Dataseka may request information reasonably necessary to verify your identity, authority and jurisdiction. An authorised agent may submit a request where permitted by law, subject to verification.
Dataseka will respond within the period required by applicable law. We may refuse or charge a reasonable fee for requests that are manifestly unfounded, excessive, repetitive or not legally required, where the law permits. We will explain a refusal and available appeal or complaint rights where required.
Exercising a privacy right will not result in unlawful discrimination. Some rights are subject to exceptions, including legal retention, security, confidentiality, the rights of others and the establishment or defence of legal claims.
15.2 Requests involving Customer Data
If Dataseka holds information only on behalf of a customer, we may refer the request to that customer. The customer is responsible for deciding the request, and Dataseka will provide reasonable assistance under the DPA.
15.3 Marketing choices
You may unsubscribe from marketing emails using the link in the message or by contacting us. Dataseka may continue to send essential service, security, billing and contractual communications.
For electronic direct marketing subject to POPIA, Dataseka will seek consent where required or rely on the existing-customer exception only within its legal limits, identify itself and provide a functional method to opt out.
16. Additional regional information
16.1 South Africa
Under POPIA, Personal Information may include information about identifiable existing juristic persons. You may request access or correction, object to certain processing and lodge a complaint with the Information Regulator. Prescribed forms may be required in some cases.
Information Regulator (South Africa)
- Website: https://inforegulator.org.za
- Complaints portal: https://eservices.inforegulator.org.za
- POPIA complaints email: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191, South Africa
Requests for access to company records under the Promotion of Access to Information Act, 2 of 2000 (PAIA) are governed by Dataseka’s PAIA Manual.
16.2 European Economic Area, United Kingdom and Switzerland
Where the GDPR, UK GDPR or comparable Swiss law applies, you may have rights of access, correction, erasure, restriction, objection, portability and withdrawal of consent, as well as rights concerning qualifying automated decisions. You may lodge a complaint with the supervisory authority in the country where you live or work or where an alleged infringement occurred.
If Dataseka is required to appoint an EU or UK representative, the representative’s contact details must be inserted in section 2 before publication to affected individuals.
16.3 California and other United States jurisdictions
If a United States state privacy law applies to Dataseka’s processing, residents may have additional rights to know, access, delete, correct, opt out of qualifying sale, sharing, targeted advertising or profiling, limit certain uses of sensitive Personal Information, use an authorised agent and appeal a decision.
Dataseka does not sell Personal Information and does not share it for cross-context behavioural advertising. If Dataseka becomes subject to a statutory obligation to provide a “Do Not Sell or Share” mechanism or recognise an opt-out preference signal, Dataseka will provide the required method and disclosures.
The categories of Personal Information collected, sources, purposes and recipient categories are described in sections 4, 5, 6 and 9 of this Notice.
16.4 Other jurisdictions
Dataseka will honour additional rights and restrictions required by privacy laws that apply to a particular individual or processing activity. A jurisdiction-specific notice or contractual addendum may supplement this Notice where necessary.
17. Children and special or sensitive information
The Services are designed for business users and are not directed to people under 18. Dataseka does not knowingly permit a child to create an account. If we learn that a child has created an account without lawful authorisation, we will take appropriate steps to close the account and delete or restrict the information, subject to legal requirements.
Customers must not include children’s Personal Information or special, sensitive or regulated information in Customer Data unless they have a lawful basis, provide required notices, obtain required authorisations and select appropriate technical, organisational and contractual safeguards. Dataseka may require a security review, additional terms or a particular deployment model for high-risk data.
If Dataseka learns that Customer Data may contain children’s or special Personal Information in circumstances not authorised by the customer agreement or law, Dataseka may restrict processing and notify the customer.
18. Third-party services, integrations and links
The Services may link to or interoperate with third-party websites, data sources, identity providers, payment providers, communication tools, customer-managed AI providers and other services. A third party selected or controlled by a customer may process information as an independent controller or responsible party under its own terms.
Dataseka is not responsible for a third party’s independent privacy practices. Before enabling an integration, customers should review its permissions, data location, retention, security and privacy terms.
19. Changes to this Notice
Dataseka may update this Notice to reflect changes in the Services, processing practices, laws or organisational structure. The “Last updated” date shows when the Notice was revised.
We will provide reasonable advance notice of material changes where appropriate, for example by email, an account notification or a prominent website notice. If a change requires consent, we will seek consent rather than treating continued use as consent. Previous versions will be made available on request or through an archive where reasonably practicable.
20. Contact and complaints
For questions, complaints or privacy-right requests, contact:
Dataseka Privacy and Information Officer
Email: hello@dataseka.com
Address: V & A Waterfront, Cape Town, South Africa
Website: https://dataseka.com/contact
Please include enough information for us to understand the request, but do not send passwords, complete payment-card details or unnecessary Customer Data by email.
If you are not satisfied with our response, you may lodge a complaint with the South African Information Regulator or another competent supervisory authority. We encourage you to contact us first so that we can try to resolve the matter.