Privacy Policy
This policy explains what personal information Minibytez handles, why, for how long, and what you can ask us to do about it. It covers both our own business activity and the systems we build and operate for clients.
1. Who this policy covers
This policy is issued by Minibytez Consulting (“Minibytez”, “we”, “us”), a company registered in South Africa with regional operations in Saudi Arabia. It applies to:
- Visitors to www.minibytez.com and to our product demonstrations atdemo.minibytez.com, and anyone who contacts us through them
- Client and prospective client contacts we deal with commercially
- Personal information contained in systems we build, host or operate on behalf of our clients, where we act on their instructions
Where a client operates a platform we built for them, that client's own privacy notice governs how they use the data in it. This policy explains our role in that arrangement.
2. Our two roles: controller and processor
Minibytez handles personal information in two distinct capacities.
As a controller
For our own business, covering website enquiries, marketing to businesses, client relationships, contracts, invoicing, recruitment and internal administration, we decide why and how the information is used, and we are responsible for it.
As a processor (service provider)
When we design, build, integrate, host or operate a platform for a client, any personal information inside that platform belongs to the client, who remains the controller. We process it only to deliver the services they have instructed, under a written agreement. We do not use client platform data for our own purposes, do not sell it, and do not use it to market to the individuals in it.
Client authorisation. Where we connect a client's systems to third-party platforms such as payment providers, messaging platforms including the WhatsApp Business Platform, advertising platforms, accounting systems or hardware, we do so on that client's authorisation and on their accounts, for their business purposes.
3. Information we collect
Information you give us directly
- Enquiry details: name, company, work email address, phone number, the type of project you select and the description you write
- Correspondence: emails, WhatsApp or phone conversations, meeting notes and documents you send us during an engagement
- Contract and billing details: the business, contact and payment information needed to enter into and administer an agreement
Information collected automatically
- Technical request data: IP address, approximate country, browser and device type, and the pages requested. This is generated by our hosting and security infrastructure for delivery, abuse prevention and diagnostics.
- Security signals: where bot protection is enabled on a form, the challenge provider processes a token and technical signals to distinguish people from automated traffic.
Information we receive as a processor
Client platforms may contain information about that client's customers, members, staff or suppliers: for example contact details, membership or account status, transactions, communications history, attendance or access events. The categories are determined by the client and set out in our agreement with them.
4. How we use information
- To respond to enquiries and provide the information or proposal you asked for
- To deliver, support, secure and improve the services and systems we are engaged to build
- To administer contracts, invoicing and our business records
- To keep our website and our clients' platforms available, secure and free of abuse
- To meet legal, regulatory, tax and accounting obligations
- To communicate relevant business information to client and prospective client contacts, where they can opt out at any time
We do not sell personal information. We do not share enquiry data with third parties for their own marketing.
5. Messaging and WhatsApp
We build and operate communications infrastructure, including integrations with the official WhatsApp Business Platform, on behalf of clients and on their authorised accounts.
- Conversations are handled for the business purposes the client has defined, for example service, support, notifications and account communication
- Opt-out requests are honoured, and consent and opt-out status is recorded against the contact
- Message content, delivery status and related metadata are stored so that the business has a record of its own customer communication
Retention principle for message content: our intended standard is that message content is retained for up to 24 months from a contact's most recent interaction, unless a longer period is required for legal, regulatory, tax, dispute or other legitimate business reasons, or unless a specific client agreement sets a different period. Retention periods for a given platform are defined with the client who controls it.
We do not claim that deletion at the end of a retention period is fully automated in every system. Where automated deletion is implemented for a platform, it is described in that platform's own documentation and agreement. Otherwise deletion is performed on request or on a defined review cycle.
6. Legal basis for processing
Where South African law applies, we process personal information under the Protection of Personal Information Act (POPIA). Where the UK or EU GDPR applies to a specific engagement, or Saudi Arabia's Personal Data Protection Law applies to our regional operations, we apply the corresponding requirements. Our bases are typically:
| Activity | Basis |
|---|---|
| Responding to a business enquiry | Steps prior to entering a contract, and our legitimate business interest |
| Delivering an engagement | Performance of a contract |
| Processing client platform data | On the client's documented instruction, under their legal basis |
| Security, abuse prevention and diagnostics | Legitimate interest in keeping systems available and secure |
| Financial and statutory records | Legal obligation |
8. International transfers
We operate from South Africa and Saudi Arabia and use infrastructure providers that may process data in other countries. Where information is transferred across borders, we take reasonable steps to ensure it remains protected to a standard comparable to that required by applicable law, including through contractual safeguards with providers, and, for client platforms, the arrangements agreed with the client.
9. How long we keep information
| Category | Retention |
|---|---|
| Website enquiries that do not become engagements | Up to 24 months from last contact |
| Client relationship and correspondence records | For the engagement and a reasonable period afterwards |
| Contracts, invoices and financial records | As required by tax and company law |
| Messaging content in platforms we operate | Up to 24 months from the contact's most recent interaction, subject to section 5 |
| Technical and security logs | Short retention, typically measured in days to months |
| Client platform data | As instructed by the client in their agreement |
When an engagement ends, we return or delete client platform data according to the terms of that agreement, subject to any legal obligation to retain it.
10. How we protect information
- Encryption in transit, and encryption at rest on the platforms we operate
- Role-based access control, applied on the principle of least privilege
- Credentials and API keys held in managed secret storage, never in front-end code
- Separation between development, staging and production environments
- Audit logging of consequential actions in the systems we build
- Backups, with restore procedures that are tested rather than assumed
- Data minimisation: we design systems to collect what the process needs
No system can be guaranteed absolutely secure. If a breach affecting personal information occurs, we will act on it, notify the affected client or individuals, and report to the relevant regulator where required.
11. Your rights
Subject to applicable law, you may ask us to:
- Confirm whether we hold personal information about you, and provide a copy
- Correct information that is inaccurate or incomplete
- Delete information we no longer have a lawful reason to keep
- Restrict or object to certain processing, including direct marketing
- Provide certain information in a portable format
- Withdraw consent, where processing is based on consent
Contact us at info@minibytez.com. We will respond within the period required by applicable law. Requests relating to data deletion are handled through our Data Deletion process.
If your information sits inside a platform operated for a client, we will refer your request to that client as the controller and assist them in responding. You also have the right to complain to a supervisory authority. In South Africa, that is the Information Regulator.
13. Children's information
Our website and services are directed at businesses, not children, and we do not knowingly collect information from children through this site. Where a client platform we operate handles information about minors, for example a membership system with junior members, that processing is governed by the client's instructions and the additional protections applicable law requires.
14. Changes to this policy
We update this policy when our practices change. The version number and effective date at the top of this page indicate the current release. Material changes affecting client engagements are communicated directly to the client.
15. Contacting us
Privacy questions, requests and complaints:
- Email: info@minibytez.com
- Phone: +966 56 516 6085
- Entity: Minibytez Consulting, Durban, South Africa
- Regional operations: Riyadh, Saudi Arabia
Need something clarified?
If any part of this is unclear, or you need a data processing agreement for a project, contact us and we will deal with it directly.