Legal
Privacy Policy
SaintsLink is a South African technology company that builds software, cloud applications, AI systems, business platforms, and digital services for global customers.
This Privacy Policy explains how we collect, use, share, and protect personal information when you engage with our websites, products, services, applications, APIs, marketplaces, portals, and future offerings.
Scope
This policy applies to all SaintsLink products and services, including Flow CRM, Bookly, Sentinel Nexus ERP, SaintsLink Business OS, POS systems, AI applications, customer portals, internal dashboards, APIs, mobile apps, client portals, marketplace services, Academy, research platforms, and any future products or releases.
It covers data processed through our websites, marketing, sales, support, subscription services, and customer deployments, regardless of whether the information originates from South Africa, the EU, the UK, or other jurisdictions.
Key Definitions
Personal Information means any information that identifies an individual, such as name, email address, phone number, login credentials, or device identifiers.
Customer Data means information that our customers provide through our products or services, including business records, transaction details, contact lists, sales data, operational information, and user-generated content.
Service Data means metadata, usage details, diagnostics, logs, analytics, cookies, device information, and support interactions that help us operate and improve our products.
Information We Collect
Information You Provide
We collect information that you or your organization provide directly, such as when you register for an account, subscribe to a service, complete a request form, contact support, or use a customer portal.
- Contact details: name, email address, phone number, company name, job title, and billing address.
- Account information: usernames, passwords, authentication credentials, recovery information, security questions, and multi-factor authentication data.
- Payment information: cardholder name, billing address, transaction references, subscription plan, and other payment-related details; payment card data is generally processed by trusted third-party payment providers.
- Customer business data: records, files, invoices, CRM entries, product catalogs, orders, messages, reports, and other information entered into SaintsLink products by our customers.
- Communications: inquiry text, support requests, meeting notes, feedback, user surveys, chat transcripts, emails, and other correspondence.
- Uploaded files: documents, images, spreadsheets, attachments, and content you or your users upload to our platforms.
Information Collected Automatically
When you use our platforms, we automatically collect information about your device, browser, network, and interactions.
- Device information: device type, operating system, browser version, screen resolution, and preferred language.
- Log data: IP address, access times, page requests, errors, system events, and service performance data.
- Usage analytics: feature usage, session duration, click paths, API requests, and product telemetry.
- Cookies and similar technologies: cookies, local storage, pixel tags, and web beacons used to support authentication, personalization, analytics, advertising, and security.
- Location data: country-level location inferred from IP address or mobile device settings.
AI Services and Automated Processing
We may collect and process data to support AI services, model training, analytics, behavior patterns, and automation. We treat personal information used in these contexts with the same protections as other data and apply safeguards to prevent unauthorized use.
How We Use Information
We use personal information to deliver and improve our products, keep our systems secure, and communicate with customers and prospects.
- Operate and personalize services, manage accounts, authenticate users, and provide access to features.
- Process transactions, manage subscriptions, and support billing, collections, and refunds.
- Respond to support requests, provide customer service, and resolve issues.
- Detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity.
- Monitor, analyze, and improve product performance, reliability, usability, and customer experience.
- Communicate service updates, product announcements, marketing messages, and legal notices.
- Comply with legal obligations, enforce our terms, and protect our rights, customers, and third parties.
Legal Bases for Processing
For South African residents, our processing is based on POPIA-compliant grounds such as contract performance, legitimate interest, consent, compliance, and protection of rights.
For European and UK residents, we also rely on GDPR legal bases including contract performance, legitimate interests, consent, legal obligation, and vital interests.
Where required, we will ask for your consent before collecting personal information for specific purposes beyond the scope of providing our services.
Sharing Information
We do not sell personal information. We share data only to operate our services, support customers, comply with law, or protect rights.
- Service providers: trusted vendors that help us host, operate, secure, analyze, and improve our platforms, including cloud infrastructure, payment processors, analytics platforms, marketing providers, and customer support tools.
- Cloud providers: global infrastructure partners that store and process data on our behalf.
- Payment providers: payment gateways and processors that handle financial transactions.
- Analytics providers: services that help us understand product usage and improve performance.
- Marketing providers: tools that support our communications and advertising when we have a lawful basis.
- Third-party integrations: services you connect to SaintsLink products, where you choose to share data with those providers.
- Legal and safety: authorities, advisors, and other parties when required by law, to respond to legal requests, or to protect our customers, users, or business.
- Business transfers: potential buyers, investors, or partners in connection with mergers, acquisitions, reorganizations, or asset sales, provided they agree to protect the data.
International Data Transfers
SaintsLink operates globally and may transfer personal information across borders. When data moves outside South Africa, the European Union, or the UK, we use appropriate safeguards such as standard contractual clauses, binding corporate rules, and approved transfer mechanisms to protect it.
Data Storage and Retention
We store information on secure servers operated by our cloud providers and protect it through technical and organizational controls.
We retain personal information only as long as needed to meet the purposes described in this policy, comply with legal obligations, resolve disputes, and support our services. Retention periods vary by data type and product context.
Security Measures
We implement administrative, technical, and physical measures to protect information, including encryption, access controls, network protections, logging, and regular security reviews.
No system is completely secure. We monitor our systems for vulnerabilities and respond to incidents based on established breach procedures.
User Rights
Under POPIA and GDPR, you may have rights including access, correction, deletion, objection, restriction, portability, and withdrawal of consent. We respond to requests in accordance with applicable law.
- Access: request confirmation of whether we hold your personal information and receive a copy of it.
- Correction: ask us to update or correct inaccurate or incomplete information.
- Deletion: request removal of personal information when we no longer need it or when processing is unlawful.
- Restriction: ask us to limit how we use your personal information in certain circumstances.
- Portability: request a copy of your data in a machine-readable format where applicable.
- Objection: object to processing based on legitimate interests or direct marketing.
- Withdraw consent: withdraw any consent you previously gave for specific uses of your personal information.
Marketing Preferences
You may opt out of marketing messages at any time by following the instructions in the message or contacting us at hello@saintslink.com. We may still send you transactional or service-related messages related to your account.
Children's Privacy
Our services are not intended for children under 13. We do not knowingly collect personal information from children without parental consent. If we learn that we have collected such information, we will take steps to delete it.
Third Party Services
We use third-party services and integrations that may have their own privacy practices. This policy does not apply to those third parties. We encourage you to review their privacy policies before sharing information.
AI Services and Automated Decision Making
SaintsLink may use artificial intelligence and automated tools to improve products, analyze trends, and automate workflows. We do not rely solely on automated decision-making for high-risk decisions affecting individuals without appropriate human review and safeguards.
Data Breach Procedures
If we identify a security incident involving personal information, we will investigate promptly, contain the incident, notify affected parties as required by law, and take corrective action.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our services or legal obligations. We will publish the revised policy on this page and update the effective date. Significant changes will be communicated as appropriate.
Contact Information
If you have questions, requests, or concerns about this Privacy Policy, contact us at:
contact Ops: +27 68 554 7675
Address: SaintsLink, South Africa