Legal

Privacy Policy

Woblar (Pty) Ltd·Effective 26 July 2026

1. Who We Are

This Privacy Policy applies to Woblar (Pty) Ltd, a South African private company registered under number 2026/589740/07.

Woblar is an AI consulting and implementation service for small and medium-sized businesses. We help clients design, implement, govern, and improve client-specific AI and agentic workflows. Our website is woblar.com.

We handle personal information in compliance with the Protection of Personal Information Act, 4 of 2013 (“POPIA”).

Woblar (Pty) Ltd

Registered address: 18 Spantou Avenue, Wapadrand, Pretoria, Gauteng, 0051

Registration: 2026/589740/07

Telephone: +27 83 418 5501

2. Information We Collect

Website visitors

If you consent to analytics cookies, we collect website usage and device data via Google Analytics (see Section 8). This may include pages viewed, time on site, approximate geographic region, device type, and referral source. We do not collect your name or contact details simply because you browse the site.

Contact and enquiry leads

If you fill out a contact or “Deploy” enquiry form, or email us directly, we collect your name, email address, business name, and any information you choose to share in your message. This information is used to respond to your enquiry, assess a potential engagement, and, where permitted, follow up with you.

Business contacts and applicants

During a client engagement we may collect the contact, role, billing, and communication details of client representatives. If we invite applications for a role, we may collect the information in an application, such as contact details, work history, and any material you choose to provide.

Client business data

When we provide custom AI solutions on behalf of a client business, we may process personal information belonging to that client's end-customers (for example, names, phone numbers, order details, or support queries). In this context we act as an operator under POPIA - we process that data on instruction from the responsible party (our client) and not for our own purposes. Our data processing agreements with clients govern these arrangements.

3. Sources and Sensitive Information

We usually collect information directly from you, from your organisation, or through our website and communications with us. We may receive information from a client when acting as its operator, from service providers working for us, or from publicly available professional sources where lawful.

Please do not send special personal information, such as health, biometric, religious, political, trade-union, criminal, or financial information, through a general website enquiry. We do not intentionally collect children's information through this website. Where a client asks us to process special personal information or children's information as part of an engagement, the client remains responsible for the required POPIA authority, notices, and safeguards, and our written data-processing agreement applies.

4. Cookies and Similar Technologies

We use a small number of first-party cookies to run the site and, only with your consent, to understand how it is used. You can accept, reject, or change your choice at any time by .

Necessary

Always active and cannot be switched off. A single first-party cookie (woblar_consent) remembers your cookie choice for 12 months so we don't ask you again on every visit. It does not track you for advertising or analytics purposes.

Analytics

Only set if you accept them. We use Google Analytics (see Section 8) to understand aggregate traffic and behaviour on woblar.com. Google Analytics does not load, and no analytics cookies are set, until you consent - and it stops running immediately if you later withdraw consent.

Marketing

We do not currently use any advertising or marketing cookies. This category is shown in our preferences dialog for transparency and future-proofing; if that changes, we will update this policy and ask for your consent before any such cookies are set.

5. How We Use Your Information

  • -To respond to enquiries and communicate with prospective or current clients.
  • -To understand how our website is used and improve its content and performance.
  • -To deliver and maintain AI solutions and services we have contracted to provide.
  • -To manage our client relationships, invoices, records, and service administration.
  • -To protect our website, systems, and services from fraud, misuse, and security threats.
  • -To comply with our legal and regulatory obligations under South African law.
  • -We do not sell, rent, or trade your personal information to third parties.
  • -We do not send unsolicited electronic direct marketing without the consent or other basis required by POPIA, and you can opt out at any time.

6. Lawful Grounds for Processing

Under POPIA, we process personal information on the following grounds:

  • -Contractual necessity: processing required to fulfil a service agreement with a client.
  • -Legitimate interest: to operate and protect our business, website, and services, provided your privacy rights are not unfairly affected.
  • -Consent: where POPIA requires it, including analytics cookies and certain direct marketing.
  • -Legal obligation: where we are required to retain or disclose information by law.
  • -Client instruction: where we act as an operator and process client data only on the responsible party’s documented instruction.

7. Data Retention

We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law.

Enquiry and lead information is retained for a maximum of 24 months from last contact, after which it is securely deleted or de-identified unless a formal engagement has commenced or another lawful retention requirement applies. Client data processed as an operator is retained and returned, deleted, or de-identified in accordance with the relevant client agreement and documented instructions.

Anonymised, aggregated website analytics data (collected via Google Analytics) does not contain personal information in a form that can identify you and is retained indefinitely for trend analysis.

8. Recipients and Third-Party Services

We may share personal information with authorised team members, contractors, professional advisers, and service providers who need it to perform work for us; with a client when we act on that client's instruction; or where disclosure is required by law, a court, regulator, or to protect rights, safety, and security. We require service providers to process information only for authorised purposes and to apply appropriate safeguards.

Our website may link to third-party websites or services. Their privacy practices are governed by their own notices, and we encourage you to review those notices before providing them with personal information.

Google Analytics

Our website uses Google Analytics (Google LLC, USA) to collect aggregate usage statistics, but only once you have accepted analytics cookies (see Section 4). No analytics cookies are set, and analytics does not load, until you consent. Google may transfer data to servers outside South Africa. You can withdraw consent at any time by or by installing the Google Analytics Opt-out Browser Add-on.

AI model providers

Our AI solutions run on large language model providers such as Anthropic, OpenAI, Google or others. In some instances, when an agent handles a conversation for a client, those messages pass through these providers for processing. Provider use, permitted data categories, retention, and any model training settings are addressed in the applicable client agreement and implementation design.

WhatsApp Business API

For WhatsApp-channel deployments, messages are transmitted through the WhatsApp Business Platform (Meta Platforms, Inc.). Meta's own data processing terms and privacy policy apply to messages in transit. Our clients are responsible for ensuring their end-customers are aware that a WhatsApp Business account is operated on their behalf.

Hosting and infrastructure

Our website is hosted on Vercel (Vercel Inc., USA). Application and agent infrastructure may run on cloud platforms including AWS, Azure, Google Cloud, or on-premise. We select infrastructure appropriate to the engagement and require providers to handle data under applicable contractual and security safeguards.

9. Automated Decision-Making

We do not use website visitor or enquiry information to make solely automated decisions that have legal consequences for you or otherwise significantly affect you. Client-specific AI workflows may generate responses, recommendations, or operational actions for a client. The client is responsible for deciding whether and how to use those workflows and for providing any notices, human review, or other safeguards required by law.

10. Your Rights Under POPIA

As a data subject under POPIA, you have the right to:

  • -Request access to the personal information we hold about you.
  • -Request correction of inaccurate, irrelevant, or outdated information.
  • -Request deletion of your personal information, subject to our legal retention obligations.
  • -Object to the processing of your personal information on grounds of legitimate interest.
  • -Withdraw consent at any time where we rely on consent; this does not affect processing already carried out lawfully.
  • -Object at any time to direct marketing and unsubscribe from marketing communications.
  • -Lodge a complaint with the Information Regulator of South Africa.

To exercise any of these rights, contact us at hello@woblar.com. We will respond within 30 days.

Contact the Information Regulator at: inforegulator.org.za

11. Information Officer and Complaints

In terms of POPIA, every responsible party must designate an Information Officer. Direct privacy queries, access requests, correction or deletion requests, objections, and complaints to Woblar's Information Officer using the details below. We may ask for information needed to verify your identity and process a request securely.

Woblar (Pty) Ltd

Information Officer

Email: hello@woblar.com

Registration: 2026/589740/07

Telephone: +27 83 418 5501

12. Cross-Border Data Transfers

Some of the third-party services we use process data outside South Africa, including in the United States. Before transferring personal information, we assess the destination and put safeguards in place as required by POPIA, such as a binding agreement that requires an adequate level of protection or, where applicable, the data subject's consent or another lawful transfer ground.

13. Security and Security Compromises

We use reasonable technical and organisational safeguards: HTTPS/TLS for all data in transit, access controls on internal systems, and infrastructure providers with their own security certifications.

No system is perfectly secure. If you believe your personal information has been compromised in connection with our services, please notify us immediately at hello@woblar.com.

If Woblar, as a responsible party, has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects as required by POPIA. When we act as an operator for a client, we will notify the client without undue delay in accordance with our agreement so that the responsible party can meet its notification obligations.

14. Changes to This Policy

We may update this policy as our services, processing activities, or legal requirements change. The effective date at the top identifies the current version. Where a change is material, we will take reasonable steps to bring it to affected people's attention and obtain consent where POPIA requires it.

15. Contact Us

Questions about this policy or how we handle your data:

hello@woblar.com

Telephone: +27 83 418 5501

Stop working in your business.

LET'Stalk.

Ready to make AI practical for your business? Let's start with the work that matters most.