PRIVACY POLICY
Effective Date: 24 August 2026
Version: 2
This Privacy Policy must be read with the Terms of Service, Operator Agreement, Henry Consumer Privacy Notice, Customer Acceptable Use Policy, Service Level Agreement, Cookies Policy, Suboperator List, Security and Incident Schedule, Retention, Deletion and De-identification Schedule, International Transfer and Recipient Register and applicable Henry Ingest, Henry Insights or Henry Exchange Product and Processing Schedule. The Operator Agreement incorporates the applicable provisions of this Policy and is the written agreement contemplated by section 21 of the Protection of Personal Information Act 4 of 2013 (POPIA) whenever Henry or a Tenant acts as Operator for the other.
Henry takes privacy seriously. This Policy explains the purposes and grounds on which personal information is processed. It is not blanket consent; specific consent must be obtained where law requires it.
Standard and Enterprise arrangements: The standard position described in this document applies unless a signed Enterprise Annex expressly varies an eligible, identified contractual matter. Where legally and operationally available, any enhanced or non-standard scope, service level, support, infrastructure, assurance, reporting, implementation or other commitment must be separately requested, assessed, approved and priced under the Enterprise Agreement. An Enterprise Annex cannot alter statutory rights or mandatory legal obligations.
1. Henry and This Policy
1.1. Henry AI (Pty) Ltd, registration number 2023/620906/07, trading as Henry, Henry AI, Henry Ingest, Henry Insights and Henry Exchange (Henry, we, us or our), is the entity responsible for the Henry-controlled processing described in this Policy.
1.2. To provide clear and transparent information, this Policy explains how Henry collects, receives, stores, uses, analyses, links, shares, de-identifies, retains and protects personal information under POPIA. It applies to website visitors; Tenant administrators and Users; business contacts; applicants and customers in Henry-enabled workflows; persons whose information a Tenant submits; and persons whose information Henry processes for legitimate business purposes.
1.3. Our details are:
| Item | Details |
|---|---|
| Legal name | Henry AI (Pty) Ltd |
| Registration number | 2023/620906/07 |
| Trading names | Henry; Henry AI; Henry Ingest; Henry Insights; Henry Exchange |
| Address | Great Westerford, 240-221, M4, Rondebosch, Cape Town, 7700, South Africa |
| legal@henryai.co.za | |
| Website | https://henryai.co.za |
| Application | https://app.henryexchange.ai |
1.4. Our role depends on the processing. A Tenant is generally the Responsible Party and Henry its Operator when Henry processes information only for Tenant-determined purposes. Henry is the Responsible Party for Personal Information that it sources or collects directly, or receives from a source organisation and thereafter controls for Henry-determined preliminary matching, product presentation, routing or an authorised ecosystem workflow (Henry Lead Data); a Tenant receiving that information acts as Henry's Operator only while following Henry's documented instructions without independently determining a product purpose or decision.
1.5. Henry is also an independent Responsible Party for account administration, authentication, billing, security, fraud prevention, legal compliance, business operations, Service Usage Data and lawfully De-identified Data, and may be an independent or joint Responsible Party where it determines a workflow's purpose or essential means. A recipient Tenant may become a Responsible Party for distinct processing it independently determines, such as underwriting, contracting, legal compliance or separately authorised marketing. The Operator Agreement Section 1 applies roles per processing activity.
1.6. Where a Tenant determines why information is processed, its privacy notice also applies and requests should ordinarily be directed to it. Capitalised terms not defined here have the meanings given in the Terms of Service.
1.7. As between Henry and a Tenant, the Tenant retains its rights in Tenant Data. Henry's authority to process that data is limited to the Agreement, documented instructions, the applicable Product and Processing Schedule and law; processing does not transfer ownership of identifiable information to Henry.
1.8. Henry supplies technology, data processing, preliminary eligibility matching, product presentation, routing and workflow support. Henry may determine potential relevance, participant-network selection, ranking and routing but, unless an applicable product notice expressly states otherwise, does not make the participant's final regulated eligibility, affordability, underwriting, advice, product-term or approval decision. The licensed participant that determines those matters, statutory disclosures or contract conclusion is the Responsible Party for those activities. A workflow must identify that participant and Henry's role before the relevant processing or communication.
1.9. This Policy regulates lawful processing and does not determine ownership of intellectual property. A Tenant's privacy rights and rights in unchanged source Tenant Data do not give it ownership of Henry's enrichment, compilation, structure, relationships, scores, insights, Henry Outputs, Henry Technology or Proprietary Methodology. Conversely, Henry's ownership of those items never gives Henry ownership of a Data Subject's Personal Information or authorises processing beyond this Policy, the Operator Agreement, documented instructions and law.
2. Information We Process
2.1. To provide the selected Service and support the authorised workflow, the information processed may include:
- account and authority information: identity and business contacts, employer, Tenant details, authority, settings, subscription, billing and acceptance records;
- applicant and financial information: contact and residential details, identifiers, verification, consent, employment, income, expenses, affordability, bank statements and bank-account details, finance applications and outcomes;
- vehicle and transaction information: VIN, registration number, microdot PIN, make, model, derivative, colour, licence-disc or vehicle-status information, third-party data source identity and risk results, valuations, pricing, participant details, matches, referrals, funding and Fee records;
- communications and connected sources: emails, attachments, files, images, extracted text, authorised Microsoft and Google integration content (including Microsoft 365, Google Drive, Gmail and Google Calendar), calls, messages, CRM records, support correspondence and authorised API or database data;
- technical and security information: IP, device, browser, authentication, integration, usage, performance, audit, security and cookie data; and
- derived information: classifications, structured records, links, digital twins, indicators, scores, recommendations, reports, analytics and De-identified Data.
2.2. We receive information directly from individuals, including through Henry lead-generation forms or campaigns; from Tenants, referral partners and authorised transaction participants; through enabled email, document, CRM, database, Microsoft and Google integrations; from authorised data, validation, valuation, bureau or bank-statement providers; from public or lawfully licensed sources; and automatically through use of the website, application, API or integrations.
2.3. Connected-source information may be processed in real time, temporarily cached, stored as a production record or audit trail, replicated and backed up, depending on the configured feature. The applicable Product and Processing Schedule describes the product-specific data path. These operations are necessary cloud-service processing and remain subject to purpose, access, retention, security and deletion limits.
2.4. Henry uses Paystack for subscription-payment processing. Paystack hosts the payment-card credentials. Henry may retain or access customer name and email, Paystack customer and transaction identifiers, payment reference and status, amount, currency, timestamps, invoice records, card brand, masked last four digits and expiry metadata, but does not receive or store the full card number or CVV. Henry may store bank-account information for authorised customer, commission-recipient, dealer, lender, supplier, personnel and related payment purposes in access-controlled Supabase and Zoho records.
2.5. To protect privacy and security, do not submit payment-card security codes or another person's passwords or authentication secrets. Categories requiring a custom workflow are identified in Section 13.
2.6. This Policy and, for consumer journeys, the Henry Consumer Privacy Notice provide Henry's standard privacy notification. Henry will add a brief contextual statement only where reasonably necessary to identify an indirect source or to explain a material new purpose, information category, recipient, international transfer, consequence or legally required choice that those documents do not already make clear.
2.7. For direct collection, the applicable notice or an immediately accessible link must be provided before collection unless the person is already aware of the required information. For indirectly sourced information, Henry must make the applicable notice and source information readily accessible as soon as reasonably practicable after receipt, unless a documented section 18(4) exception applies. Henry retains proportionate evidence of any notice or consent on which it relies. A new purpose or recipient is not authorised merely because a general privacy notice exists.
2.8. The Henry Consumer Privacy Notice is the plain-language notice for a Henry-enabled product, matching or transaction journey. It explains direct and referred entry, preliminary matching, displayed product categories, Henry-controlled routing, participant handover, operational communications and the limits of Henry's correction and deletion control.
2.9. Before a Tenant or other source organisation supplies a lead to Henry, that organisation remains responsible for its own collection, lawful basis, notice, information quality and authority to disclose the information. It must provide Henry with its applicable privacy notice or identify a current public version and warrant that its disclosure and instructions are lawful. Henry does not control or assume responsibility for that organisation's independent conduct before receipt. Henry may request evidence and restrict, quarantine, reject or stop affected processing where Henry reasonably suspects missing authority, unlawful processing, inaccurate provenance or a material privacy or security risk.
3. Purposes of Processing
3.1. To provide a useful, reliable and secure Service, Henry may process information, depending on its role and the authorised workflow, to:
- verify authority and identity; administer accounts, access, billing, contracts and communications; and provide support;
- connect authorised sources; receive and store records; perform OCR, extraction, transcription, classification, redaction, validation, enrichment, linking and deduplication; and operate configured workflows;
- create structured records, digital twins, reports, dashboards, analytics, scores, predictions, recommendations and decision-support insights;
- source, qualify, match and route leads, applicants, vehicles, dealers, lenders and other participants; verify vehicle identity, originality, microdot, police or insurance interest, theft/cloning risk and valuation through an approved third-party data source; manage consent, communications, bids, referrals and transactions; and reconcile outcomes and Fees;
- secure the Service, preserve Tenant isolation, monitor performance and usage, prevent fraud and abuse, investigate incidents and enforce legal rights;
- comply with binding legal and regulatory obligations and manage advisers, insurers, financing or corporate transactions; and
- test and improve service reliability, security, performance and generic features; create reusable integrations; and create and use De-identified Data and aggregate service benchmarks under Section 4.
3.2. Henry does not sell Tenant Data or identifiable personal information, use it for targeted advertising, disclose it to data brokers, or create unrelated user profiles. Participation in one workflow does not authorise unrelated marketing, onward sale, customer-specific competitive intelligence or unrestricted access.
3.3. Henry may send necessary account, support, security, transaction and contractual communications. Direct marketing is governed by Section 12.
3.4. Henry may monitor logs, metadata, usage and the minimum content reasonably necessary to provide or secure the Service, investigate misuse, comply with law or enforce the Agreement. Content access must be need-based, confidential and logged where the relevant system supports it. Henry has no general obligation to monitor all Tenant content.
3.5. Henry may perform limited preliminary validation, eligibility screening and matching before a Henry product choice where the source organisation's warranted authority expressly covers disclosure to Henry for that preliminary activity or another documented lawful ground applies. The activity is limited to identifying potentially relevant displayed categories or materially consistent alternatives and does not authorise disclosure to a product provider for an unselected product.
3.6. A displayed product-category choice may cover a materially consistent alternative that the category clearly describes, including a Financing category that expressly includes identified vehicle-finance, asset-based or personal-loan alternatives. A materially different product, purpose, information requirement or recipient category requires a new choice. Operational follow-up about a selected product is distinct from promotion and may not be used to conceal direct marketing.
4. AI and Automated Processing
4.1. To offer AI-assisted features responsibly, Henry may use AI, machine learning and automation for classification, OCR, extraction, redaction, data structuring, validation, natural-language interaction, summaries, analytics, matching, recommendations and anomaly or risk indicators.
4.2. AI-provider identities, purposes, information categories, locations, training restrictions, safety monitoring and provider-retention qualifications are stated in the Suboperator List Section 2.2, International Transfer and Recipient Register and applicable Product and Processing Schedule.
4.3. Henry will not use identifiable Tenant Data to train a general-purpose or shared foundation model, or permit a model provider to do so, except on the Tenant's separate documented instruction. Processing an input to generate an output, perform retrieval, classify content or run a configured workflow is not model training. Provider safety retention, automated abuse monitoring or authorised human review may occur only as disclosed for the selected feature.
4.4. The standard Service is not intended to make a solely automated decision producing legal or similarly substantial effects without a lawful exception, safeguards, human intervention and an opportunity to make representations. General AI-output and decision responsibility is governed by the Terms of Service Section 5.
4.5. The applicable Responsible Party must determine lawfulness, maintain required human review, explain outcomes where required and prevent unfair discrimination.
4.6. Henry may use De-identified Data to evaluate and improve models, workflows, products and aggregate benchmarks. Pseudonymised information and data capable of singling out a person or Tenant remain protected and are not De-identified Data. Henry will apply the de-identification and re-identification controls in the Retention, Deletion and De-identification Schedule.
4.7. Each production model or material automated rule must have a recorded provider, version, purpose, information categories, training setting, risk tier, evaluation, approved outputs, human-review rule and monitoring owner. For a consequential output, the applicable workflow must record available provenance, material input or source references, confidence or limitations, output, reviewer and override. Meaningful review requires a suitably authorised person who can understand the output's material limitations, consider contrary information and change the result.
4.8. A person affected by a solely automated or materially AI-influenced consequential outcome may use the rights channel in Section 11 to request available information about the outcome, human review, an opportunity to make representations and correction of material inputs, subject to law and another person's rights. A low confidence score is not the only trigger for human review; consequence, data sensitivity and foreseeable harm must also be considered.
5. Lawful Basis, Minimality and Quality
5.1. Processing may be based on contract; protection of a legitimate interest of the data subject; legal obligation; proper performance of a public-law duty; Henry's or a third party's legitimate interests where not overridden; or consent.
5.2. The applicable Responsible Party must establish, document and communicate the lawful basis. Technical ability to process does not validate an unlawful instruction. An Operator may request evidence of consent, prior authorisation, sector permission or other authority and may handle invalid or unverified instructions under the Operator Agreement Section 3.3.
5.3. Before processing subject to sections 57 and 58 of POPIA, the Responsible Party must obtain required prior authorisation, including where applicable to new-purpose linking of unique identifiers or credit-reporting activities.
5.4. Information may be contractually or legally required for an account, Service, application or transaction. Failure to provide required information may prevent access, assessment, routing, communication or completion.
5.5. To support privacy by design, Henry and each Tenant must limit processing to adequate, relevant and non-excessive information for an authorised purpose, apply appropriate access and retention controls, and take reasonably practicable steps to ensure quality before material decisions. Further processing must be compatible with the original purpose or independently authorised.
5.6. The applicable Responsible Party must record the lawful basis for each material workflow stage. Contract, legitimate interests or technical capability must not be used as a generic label: the record must identify whose contract or interest, the relevant purpose, necessity and any balancing or additional condition. Consent must be specific, informed, voluntary where required, evidenced and withdrawable. A regulated participant remains responsible for the ground supporting its underwriting, advice, statutory compliance, customer contract and separately determined marketing.
5.7. For material fields and outputs, Henry will preserve available source, receipt or extraction time, transformations, model or rule version, confidence or exception information, linked records, correction history and recipient history where the Product Schedule requires it. A person may dispute information without proving manifest error. While a material accuracy dispute is investigated, the Responsible Party must restrict consequential use where appropriate; verified corrections must be propagated to affected active linked records and relevant recipients where reasonably practicable and legally required.
5.8. Where Henry receives a failed loan application and relies on legitimate interests for limited internal matching and neutral presentation of potentially relevant alternatives, Henry must document the purpose, necessity, expected benefit, reasonably foreseeable impact and safeguards before that processing begins. This ground does not extend to an incomplete application merely because it is incomplete and does not by itself authorise unsolicited electronic direct marketing, an undisclosed materially different product or disclosure to a product provider before the applicable product-category choice or other authority is recorded.
6. Sharing and Providers
6.1. Henry shares information only where lawful and necessary for the authorised purpose. Recipients may include: a Tenant and its Users acting as Henry's Operator for Henry Lead Data; a Tenant for which Henry acts as Operator; an independent Responsible Party such as a lender, dealer, insurer, product provider or other participant acting for its own underwriting, contracting, legal or fulfilment purposes; a Suboperator providing hosting, database, AI, analytics, integration, messaging, support, payment, vehicle verification or security services only on instructions; an independent validation, bureau, bank-statement, third-party data source or valuation provider where it determines its own purpose; professional advisers, auditors, insurers, financiers and transaction counterparties under confidentiality; regulators, courts and law enforcement; and another recipient directed by the Responsible Party or data subject.
6.2. Provider identities, purposes, safeguards, change notices, Tenant objections and contractual remedies are governed by the Suboperator List.
6.3. Henry may make a limited disclosure where reasonably necessary for law, rights protection, misuse investigation, emergency response or a confidential corporate transaction.
6.4. Unless prohibited by law, Henry will notify the applicable Responsible Party of a compulsory request for Tenant Data and, where appropriate, direct the requester to that party. Henry will obtain legal review, seek to narrow or challenge a disproportionate request where reasonable, and disclose only the minimum information legally required.
7. Processing Roles and Assurance
7.1. The Operator Agreement governs appointment, documented instructions and responsibilities where Henry processes Tenant Data as Operator or a Tenant processes Henry Lead Data as Operator.
7.2. Sections 1 to 5 describe the roles, Data Subjects, information, purposes and operations incorporated into that Agreement. Sections 6 and 8 to 11 provide the applicable recipient, provider, transfer, retention, security, notification and rights detail.
7.3. Each Responsible Party remains accountable for the processing it determines, including its lawful basis, notices, instructions and data-subject or regulatory notifications. Each Operator must follow the confidentiality, security, assistance, incident and deletion duties in the Operator Agreement Sections 3 to 9.
7.4. Once in 12 months, a compliant Tenant may request Henry's then-current standard documentary assurance, which may include this Policy, the Operator Agreement, supporting schedules, a questionnaire, available independent report or remote meeting. Henry does not represent that it holds a certification unless an applicable document or signed Enterprise Annex expressly confirms the current certification and scope.
7.5. Standard evidence and reasonable written questions must be used first. If they cannot reasonably demonstrate compliance with a material Operator obligation, or after a material Security Compromise affecting the Tenant, the parties may agree a focused independent audit during ordinary hours, subject to confidentiality, protection of other tenants and security, reasonable scope and fair cost allocation. The standard Service excludes source-code access and unrestricted raw vulnerability data. Henry may request proportionate assurance about a Tenant's Operator handling of Henry Lead Data. Additional assurance may be requested under the Enterprise Agreement.
7.6. The following matrix is the master allocation framework. The applicable Product and Processing Schedule and approved workflow record must supply the specific organisation, source, ground and period before activation:
| Processing stage | Typical role allocation | Ground and notice owner | Request, incident and retention owner |
|---|---|---|---|
| Tenant onboarding, account, billing and security | Henry as independent Responsible Party | Henry records the applicable contract, legal duty or legitimate-interest ground and provides the onboarding notice | Henry |
| Tenant-selected source ingestion, extraction and write-back | Tenant as Responsible Party; Henry and listed providers as Operator/Suboperators | Tenant establishes the ground and approves the connector/upload notice; Henry presents and records it where instructed | Tenant, with Henry assistance; each party remains responsible for its security duties |
| Henry-sourced lead collection and initial routing | Henry as Responsible Party; receiving Tenant as Operator while following Henry instructions | Henry establishes the ground and gives the lead/source/routing notice | Henry, with receiving-Tenant assistance |
| Tenant collection and disclosure before Henry receives a lead | Tenant or source organisation as Responsible Party | Source organisation establishes and evidences its lawful basis, gives its notice, identifies Henry and preliminary matching where applicable, and warrants lawful disclosure | Source organisation |
| Tenant-sourced lead received for tenant-determined processing only | Tenant as Responsible Party; Henry as Operator | Tenant establishes the ground, provides or identifies its current privacy notice and gives lawful documented instructions | Tenant, with Henry assistance |
| Henry-controlled preliminary matching, product presentation and routing | Henry as Responsible Party | Henry records the source authority or other lawful ground, makes the Henry Consumer Privacy Notice available and records the displayed product-category choice before further product processing or disclosure | Henry, with participant assistance where required |
| Tenant-controlled own-product evaluation through Henry | Tenant as Responsible Party; Henry as Operator where Henry follows the Tenant's rules without independently determining the product decision | Tenant establishes the product and sector grounds, approves its notice and determines eligibility, decision and retention | Tenant, with Henry assistance |
| Independent provider evaluation, underwriting, affordability, advice, regulated disclosure, product conclusion and fulfilment | Licensed participant as independent Responsible Party from the stage at which it independently determines those activities, whether or not direct contact details have been released | Licensed participant establishes the sector and POPIA grounds and gives its notice | Licensed participant |
| Separately determined direct marketing | Sender/determining organisation as Responsible Party | Sender establishes section 69 authority, notice and suppression check | Sender |
| Henry support, service security, fraud prevention, compliance and narrow Service Usage Data | Henry as independent Responsible Party | Henry records the applicable legal duty or legitimate-interest assessment and provides notice where required | Henry |
| Termination export, legal hold and deletion | Role follows the underlying record; Henry acts as Operator for Tenant Data and Responsible Party for Henry-controlled records | Applicable Responsible Party sets the lawful retention instruction; Henry's Schedule supplies defaults | Applicable Responsible Party, with Henry/Suboperator execution and evidence |
7.7. A configuration label does not override the actual conduct. A role transition must be recorded before information is disclosed or a participant begins independent processing. If a new workflow would cause Henry to determine a regulated purpose or perform a regulated decision, it must be paused for specialist South African legal review.
7.8. A new or materially changed purpose, role, source, data category, AI use, recipient, provider, country, transfer, retention rule, regulated workflow or customer-specific privacy representation requires Henry's documented internal compliance approval and review by appropriately qualified external legal or compliance counsel before it is represented as approved, demonstrated as available, or enabled. A customer instruction, meeting statement, email, demonstration or individual representative's approval does not replace that review or authorise a new processing purpose.
8. International Transfers
8.1. Current principal or expected processing locations, recipients, data categories, purposes and transfer qualifications are stated in the Suboperator List, International Transfer and Recipient Register and applicable Product and Processing Schedule.
8.2. The relevant Responsible Party must satisfy section 72 of POPIA. Safeguards may include adequate foreign law, binding corporate rules, an agreement providing substantially similar protection, necessity for a contract in the data subject's interest, consent or another permitted ground.
8.3. To protect personal information across borders, Henry uses reasonable contractual, organisational or technical measures for transfers it controls. A primary storage or data-at-rest location does not by itself prohibit remote support, transient processing, security operations, network transit or backups in another listed country. A Tenant remains responsible for transfers it directs through its sources, recipients or configuration. Country-exclusive processing applies only where a signed Enterprise Annex identifies the covered data, service and processing state.
9. Retention and Deletion
9.1. Henry applies the record-class periods and deletion events in the Retention, Deletion and De-identification Schedule. Identifiable information is kept no longer than those periods unless a shorter Tenant instruction applies or longer retention is required or permitted by law, contract, consent, security, fraud prevention, audit, dispute, claim or proof-of-compliance need.
9.2. During an active paid subscription, Tenant-directed content remains available according to product capability and configured settings. Following termination, Henry ordinarily provides a 90-day limited-function export period, disables access at its end, and deletes remaining Tenant Data from active production systems and protected backups within the following 90 days. Tokens are disabled promptly when an integration ends and deleted from active systems within 30 days. Logs, transaction, consent, support, security, financial and suppression records follow their stated record-class periods. Provider copies must follow the applicable provider contract and Henry's deletion instruction.
9.3. During an active subscription, the applicable Responsible Party controls available settings for Operator data, subject to product capability, legal holds and minimum security or audit records. A Tenant must stop using and return or delete Henry Lead Data when Henry instructs or authorised access ends, as stated in the Operator Agreement Section 8.
9.4. The contractual export right is governed by the Terms of Service Section 9. Deletion-pending backups are isolated from ordinary use and used only for security or recovery. If restored, the applicable deletion instruction is reapplied. Restricted records retained for law, security, fraud prevention, billing, consent proof, disputes or claims are access-limited and deleted when the exception ends.
9.5. Information on legal hold is exempt from ordinary deletion. Where deletion is required, Henry will take reasonable steps intended to prevent reconstruction in intelligible form.
9.6. On reasonable written request after a contractual deletion deadline, Henry will provide a deletion confirmation covering Henry-controlled systems and available Suboperator confirmations, together with any limited legal-hold or independent-retention exception and review trigger. A deletion or correction must be propagated to affected active linked records and instructed providers where reasonably practicable.
10. Security and Compromise Notification
10.1. To protect customer information, Henry maintains the risk-based measures in the Security and Incident Schedule, designed to prevent loss, damage, unauthorised access or processing and to address reasonably foreseeable risks.
10.2. Measures include governance and confidentiality; unique identities; least-privilege and role-based access; multi-factor authentication for privileged Henry access; protected credentials; encryption over public networks and at rest in covered provider systems; logical Tenant separation; change, vulnerability, logging and monitoring controls; protected backups; supplier review; and incident response. Product-specific or customer-controlled exceptions are described in the Security and Incident Schedule, Online Order Record or signed Enterprise Annex.
10.3. Controls may vary by Service, architecture, data and provider and may be replaced where the overall security posture is not materially reduced. Henry is working toward ISO/IEC 27001 certification but does not represent that it is presently certified or promise a completion date.
10.4. Henry may replace a control with one that does not materially reduce the overall protection of Tenant Data. The standard plan does not include customer-managed keys, dedicated infrastructure or a customer-selected algorithm unless stated in a signed Enterprise Annex. No internet or cloud service is completely secure, and a Security Compromise does not by itself prove a failure to use reasonable safeguards. Continuity and recovery commitments are governed by the Service Level Agreement and Security and Incident Schedule.
10.5. Tenant account-security and access-control duties are governed by the Terms of Service Section 3. Tenants and Users must report suspected Security Compromises and cooperate with investigation, including immediately notifying Henry where Henry Lead Data may be affected.
10.6. A Security Compromise exists where there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person. The affected Operator must notify the Responsible Party immediately once it has such grounds. The Responsible Party will make notifications required by section 22 of POPIA as soon as reasonably possible, subject to lawful delay or exception.
10.7. Notifications may be phased so that Henry can communicate promptly as facts become available. Henry may protect information that would compromise security, another customer, privilege or a lawful investigation, but may not withhold information required by POPIA, the Information Regulator or an affected Responsible Party to assess and perform its legal duties. A notification provides transparency and is not an admission of fault or liability.
11. Data-Subject Rights
11.1. Subject to POPIA, identity verification and lawful refusal grounds, a data subject may request confirmation and access; information about recipients; correction, deletion or destruction of inaccurate, excessive, outdated, incomplete, misleading or unlawfully obtained information; object on recognised grounds; withdraw consent; object to unlawful direct marketing; seek applicable safeguards and review of a solely automated substantial decision; and complain to the Information Regulator or pursue another lawful remedy.
11.2. Henry's secure privacy and rights channel is legal@henryai.co.za, using the subject Privacy request; Henry may provide a secure upload route for identity evidence. Please provide sufficient identity, contact, Tenant, account or workflow information and the requested action, but do not send unnecessary identity documents or secrets by unsecured email. Henry will acknowledge a request within five Business Days and state the responsible handler or referral, without extending a statutory period. Henry will handle requests concerning Henry Lead Data as Responsible Party. Where Henry acts as Operator, it will promptly relay the request to the Tenant and provide available assistance within the Operator Agreement's five-Business-Day target or a shorter stated legal deadline. A Tenant receiving a request concerning Henry Lead Data must promptly relay it to Henry.
11.3. Rights are not absolute. A request may be limited, deferred or refused where law permits or requires, including to protect another person, security, an investigation, privilege, retention obligations, Henry Technology or confidential information. Access may be subject to a prescribed fee.
11.4. The statutory rights in this Section do not create a general data-portability right equivalent to every foreign privacy regime.
11.5. Henry will accept the prescribed form or a reasonable electronic equivalent containing the necessary information where law permits and will help a requester correct a material deficiency before refusing solely for form. Identity verification must be proportionate to the information and risk. Verified corrections will be recorded and propagated under Section 5.7, and the requester will be informed of the outcome and available complaint route.
12. Consent, Marketing and Cookies
12.1. Accepting the Terms or acknowledging this Policy is not consent to every purpose. For a Henry consumer funnel, the interface may record one consent event covering one, several or all displayed and meaningfully described product categories. The record must preserve the selected categories, notice and version, time, source, purpose and applicable recipient set. A category choice does not cover a materially different or undisclosed product, purpose, information requirement or recipient category merely because Henry later uses the same label. Separate unselected affirmative choices must apply to operational contact by Henry and approved participants, Henry direct marketing, and any other purpose for which separate consent is required; further choices may apply to connecting a source, optional AI or analytics, regulated data access or communication channels.
12.2. Consent records may include the person, notice, purpose, recipients, date, channel, technical evidence, workflow, duration and withdrawal history. Consent may be withdrawn through the stated interface or legal@henryai.co.za. Withdrawal does not invalidate prior lawful processing, override legal retention, prevent another lawful basis or cancel contractual Fees.
12.3. Henry conducts direct marketing only as permitted by POPIA, including section 69. The marketing record must identify the source, notice, purpose, sender, goods or services, recipient category, authorised channel, consent or existing-customer ground, consent-request date, expiry, withdrawal and suppression result. Where consent is required from a person who is not an existing customer, Henry may approach that person only once, only if the person has not previously withheld consent, and must use the prescribed Form 4 or a substantially similar, free and readily accessible form containing the required information. An electronic form must identify Henry, the specified goods or services and each selected communication method; a telephone consent request must communicate the required Form 4 content and be recorded. Repeated consent requests are prohibited. Existing-customer marketing is limited to Henry's own similar products or services where Henry obtained the contact details in the context of a sale and gave the legally required free opportunity to object at collection and in every marketing communication. Every marketing communication must identify the sender and provide a free, functional cessation route. A person may also opt out by email; this does not stop necessary service, security, support or requested transaction communications.
12.4. By affirmatively accepting the Agreement and participating in an authorised application, request or transaction, a Tenant agrees that Henry and the approved Tenants and other participants involved in that workflow may contact the Tenant and its Authorised Users through the channels selected in the Service. The Tenant may communicate with those participants where reasonably necessary to source, assess, administer, fulfil, reconcile or support the same request or transaction. When communicating through Henry as Operator, the Tenant may use only the authorised sender identity, channel, selected product, purpose, template, recipient set and period and must promptly relay a withdrawal, opt-out or objection to Henry. Access must be conversation-specific, limited to authorised participants, attributable to the actual sender and proportionate to the active purpose. Tenants remain responsible for communications they determine and send as Responsible Party. Acceptance by a Tenant representative does not provide direct-marketing consent on behalf of an identifiable individual where that person's separate consent is required. An alternative provider or product may be pursued without a new choice only where the recorded category and notice genuinely and clearly cover that materially consistent product, purpose and recipient category; otherwise a new choice is required before further processing or disclosure.
12.5. Before Henry or an approved participant contacts a person to assist with a selected product journey, the interface must obtain an unselected affirmative choice that meaningfully describes Henry and the participant categories, purpose and selected channels. Permitted contact is limited to what is reasonably necessary to understand or assist with the request, verify or complete information, provide a quotation or decision, answer questions, arrange fulfilment, give status or outcome information, or complete or support the selected transaction. The actual sender must be identified and Henry must identify the actual participant in the application before or when that participant first communicates. This operational contact choice is not direct-marketing consent. An invitation concerning an unselected or materially different product is not ordinary administration. Henry's separate marketing authority identifies Henry as sender; each dealer, lender or other product provider remains responsible for its independently determined marketing and cannot rely on the operational contact choice, Henry's marketing consent or a general reference to the Henry ecosystem.
12.6. Henry may use cookies and similar technologies for authentication, security, sessions, preferences, product analytics and performance. The categories, purposes, current services, retention approach and available choices are described in the Cookies Policy. Blocking strictly necessary technologies may impair the Service. Optional analytics, replay, personalisation and chat may not activate before the applicable choice. Analytics-provider and configuration details are stated in the Suboperator List Section 2.4, and additional information or consent will be provided where required.
13. Children and Special Personal Information
13.1. The Service is intended for adult business Users and adult applicants and is not intentionally designed to process Children's Information, health information, biometric information, religious or political information, legally privileged communications or another person's passwords, tokens or secret keys. Supabase Auth processes application-user authentication credentials. Connected mailboxes, documents, calls and archives may contain prohibited or highly confidential information even when the configured workflow does not request it. Police-interest, insurance-interest, stolen, wanted, illegal, suspect or cloning results received from a third-party data source describe vehicle risk and are not treated as criminal-behaviour information about a person unless the result is linked to an identifiable owner, driver, suspect, complainant or other person.
13.2. A workflow involving those categories requires Henry's prior written approval, a recorded lawful basis and additional condition, specific notice, source and field minimisation, restricted access, redaction or quarantine, a defined retention period, and any sector requirement, approval or prior authorisation required by POPIA, including sections 27 to 35, 57 and 58 and the 2026 Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties where applicable. Relevant assessments include new-purpose linking of unique identifiers with information from another Responsible Party, actual credit-reporting activity, criminal-behaviour processing for third parties and transfer of special or Children's Information to a country without adequate protection.
13.3. Henry may quarantine, restrict, redact, return or delete prohibited or incidentally received information and will continue to protect it while held. A contractual prohibition does not remove security, incident or deletion duties after receipt. Concerns should be reported to legal@henryai.co.za.
14. Information Officer, Complaints and Changes
14.1. Henry's registered Information Officer is Ian Fourie, contactable using the details in Section 1.3. Ian Fourie also serves as Henry's internal Data Protection Officer and Information Security Officer. Henry retains the Information Regulator registration and applicable PAIA authority record in its internal compliance file. Henry intends to hire an Operations and Security Manager; the position is vacant and no person is a Deputy Information Officer unless formally designated and registered. Each Tenant remains responsible for appointing and registering its own Information Officer where required.
14.2. Privacy and PAIA requests, complaints, formal legal notices, security incidents and urgent security reports may be sent to legal@henryai.co.za. Do not send unnecessary identity documents, passwords or secrets by unsecured email.
14.3. A data subject may complain to the Information Regulator at https://inforegulator.org.za, POPIAComplaints@inforegulator.org.za, 010 023 5200 or 0800 017 160.
14.4. Changes to this Policy and their contractual acceptance are governed by the Terms of Service Section 11. The version applicable to a paid fixed Subscription Period will not be materially changed to the Tenant's disadvantage during that period except for law, urgent security or a Tenant-requested new feature. Henry will provide any additional privacy notice or consent required by law. A new purpose is not lawful merely because this Policy is changed.
14.5. Contractual governing law is stated in the Terms of Service Section 12. The Information Regulator retains its statutory powers.
END OF PRIVACY POLICY