HENRYEXCHANGE
How it worksTrustInsightsFor partnersCapabilitiesCommunicationsIntegrations
Join the Exchange
Legal/Privacy Policy

Privacy Policy

Effective Date: February 26, 2026
Last Updated: February 26, 2026
Version: 3.0

Related Documents: This Privacy Policy forms part of and is incorporated into our Terms of Service. It is the authoritative document for all data protection, privacy, AI processing, security, and breach notification matters. It should be read together with the Acceptable Use Policy, Service Level Agreement, and Sub-Processor List.


1. Introduction

1.1 This Privacy Policy is to be read as if specifically incorporated into the Terms of Service, located at https://henryexchange.ai/legal/terms-of-service.

1.2 This Privacy Policy complies with the Protection of Personal Information Act 4 of 2013 ("POPI Act") and explains how Henry AI (Pty) Ltd ("we," "us," "our") collects, uses, stores, and protects your personal information.

1.3 READ THIS POLICY CAREFULLY BEFORE BROWSING THIS WEBSITE OR USING ANY OF THE SERVICES. Your continued use of this website indicates that you have both read and agree to the terms of this Privacy Policy. You cannot use this website if you do not accept this policy.

2. Information We Collect

2.1 Personal Information Definition: For the purposes of this policy, "Personal Information" means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person, as defined in the POPI Act.

2.2 Information You Provide Directly:

  • Registration Information: First name, surname, email address, phone number, company name, company registration number
  • Account Information: Gender, language preferences, physical address
  • Authorization Credentials: When you configure integrations, you provide OAuth authorization to connect external services
  • Communication Data: Information you provide when contacting us for support or inquiries
  • Configuration Preferences: Email classifications, document classes, flow rules, and other settings you define

2.3 Information Collected Automatically:

  • Usage Data: IP address, browser type, device information, pages visited, time spent on pages
  • Log Data: Access times, referring URLs, operating system, language settings
  • Cookies and Tracking: Session identifiers, preference cookies (see Section 13)

2.4 Information from Third Parties:

  • Microsoft Graph API: Email content, attachments, calendar events, contact details, SharePoint documents, OneDrive files, Microsoft Teams messages and files (only with your explicit authorization)
  • OAuth Tokens: Access and refresh tokens for Microsoft integration (encrypted and stored securely)

2.5 Sensitive Information: We will not collect, use, or disclose sensitive information (such as racial or ethnic origins, political or religious beliefs, health information) except with your specific consent or in circumstances permitted by law.

2.6 Payment Information: Payments are not accepted directly on the Website. Payment information is not retained on behalf of our users.

2.7 Analytics Data Sources:

  • User-Provided Data: When you use our Analytics tool's Data Sources import functionality, you may explicitly provide us with access to external data sources (including but not limited to Outlook, SharePoint, OneDrive, Teams, databases, or custom API endpoints)
  • Real-Time API Calls: We do not permanently store data imported through Data Sources on our servers. Instead, we make real-time API calls to the original source each time an analytics page is loaded
  • Temporary Processing: Data retrieved from your sources is temporarily processed in memory for display and analysis purposes only
  • Encrypted Storage (Special Cases): In special circumstances where data must be stored on our servers (such as for caching, performance optimization, or when explicitly configured by you), we encrypt all personal information fields using industry-standard encryption (AES-256)
  • Access Controls: Data Source permissions are granular and controlled at the tenant level, with separate access controls for different mailboxes, folders, calendars, and document libraries

3. How We Use Your Information

3.1 We process your personal information for the following purposes:

  • Service Delivery: Provide and maintain Henry AI services, process and route emails, classify documents, manage your account
  • AI/ML Processing: Process email content, document text, and user queries using third-party AI providers to automatically classify content, extract text from documents, answer questions about your data, and redact sensitive information (see Section 3A for details)
  • Analytics Data Processing: Retrieve, temporarily process, and display data from your connected Data Sources to generate insights, charts, and reports within the Analytics tool
  • Service Improvement: Analyze usage patterns, develop new features, improve user experience
  • Communication: Respond to inquiries, provide customer support, send service notifications
  • Security: Prevent fraud, protect against security threats, maintain system integrity
  • Legal Compliance: Comply with legal obligations, tax requirements, regulatory reporting
  • Usage Analytics: Understand user trends and patterns (aggregated and anonymized where possible)

3.2 No Marketing: We do not use your contact details for unsolicited marketing purposes. Any emails sent will only be in connection with service delivery or important service notifications.

3.3 Content Monitoring: We reserve the right, but are not obliged, to monitor information and materials you publish or submit through our services. You are solely responsible for the content you publish.


3A. AI and Automated Processing

3A.1 AI Models and Providers: We use the following third-party AI models and providers to deliver our services:

Provider Models Processing Purpose
Google Gemini models Email classification, document classification, text extraction, PII redaction, conversational queries ("Chat with Data"), insight generation
Mistral AI Mistral models Document text extraction, OCR processing

3A.2 Types of AI Processing:

  • Email Classification: Automated categorisation of incoming emails based on your configured email classes
  • Document Classification: Automated categorisation of uploaded documents based on your configured document classes
  • Text Extraction (OCR): Extraction of text content from scanned documents and images
  • PII Redaction: Automated detection and redaction of sensitive personal information in documents
  • Conversational Queries: "Chat with Data" allows you to ask natural language questions about your data, with AI-generated responses
  • Insight Generation: AI-powered analysis and summary of data patterns and trends

3A.3 No Training on Your Data: Your data is not used to train or fine-tune any third-party AI models. All AI processing is performed via inference-only API calls. Each AI provider's terms prohibit training on customer data submitted through their API services.

3A.4 Data Sent to AI Providers: When AI processing occurs, the following data may be sent to the relevant provider:

  • Email subject lines and body text (for email classification)
  • Document text content and attachment content (for document classification and OCR)
  • User queries and relevant data context (for "Chat with Data")
  • Personal information may be included in the above data; PII redaction is applied where configured

3A.5 AI Provider Data Retention: Third-party AI providers may temporarily retain input and output data for abuse monitoring purposes (typically up to 30 days), after which it is deleted. AI providers do not use this data for model training.

3A.6 Accuracy and Limitations: AI-generated outputs, including classifications, text extraction, summaries, and conversational responses, are provided for informational purposes and may contain errors, omissions, or inaccuracies. You should review important AI-generated outputs before relying on them for critical business decisions.

3A.7 Core vs. Optional AI Processing:

  • Core: Email classification and document classification are core features of the service and are necessary for service delivery
  • Optional: "Chat with Data" and insight generation are optional features that you may choose not to use

3A.8 Human Oversight: You may review AI-generated classifications, manually override them, and disable automated classification for specific data types where available.


4. Lawful Basis for Processing

4.1 We process your personal information based on the following lawful grounds under POPI:

Processing Activity Lawful Basis
Account creation and management Contract Performance - Necessary to provide services
Email and document processing Contract Performance - Core service functionality
AI classification and text extraction Contract Performance - Core service functionality
"Chat with Data" and insight generation Consent - You explicitly initiate these queries
Microsoft integration (Outlook, SharePoint, OneDrive, Teams) Consent - You explicitly authorize access
Analytics Data Sources (import and processing) Consent - You explicitly configure and authorize data source connections
Security and fraud prevention Legitimate Interest - Protect our services and users
Analytics and usage tracking Legitimate Interest - Cookieless, anonymized product analytics
Audit logs and compliance records Legal Obligation - Required by law
Customer support communications Contract Performance - Service support
Tax and business records Legal Obligation - Tax laws and business record requirements

4.2 Where we rely on consent, you may withdraw consent at any time (see Section 9).

4.3 Where we rely on legitimate interests, we have balanced our interests against your rights and determined processing is necessary and proportionate.


5. Data Minimization

5.1 Principle: We only collect and process personal information that is adequate, relevant, and not excessive for the purposes specified in this policy (POPI Section 10).

5.2 Implementation:

  • We request only the minimum information necessary for account creation
  • Microsoft integrations access only the folders, calendars, sites, drives, and teams you explicitly select
  • Analytics Data Sources retrieve only the specific tables, columns, and records you configure in your datasets
  • Analytics usage data is aggregated and anonymized where possible
  • Optional fields are clearly marked during registration

5.3 Regular Review: We regularly review the data we collect to ensure it remains necessary for stated purposes.


6. Data Sharing and Third-Party Processors

6.1 No Sale of Data: We will not sell, share, or rent your personal information to third parties for their marketing purposes.

6.2 Third-Party Processors: We engage sub-processors to provide our services. The complete and authoritative list of all current sub-processors, including the services they provide, data they process, and their locations, is maintained at henryexchange.ai/legal/subprocessors.

6.3 Data Processing Agreements: We have executed POPI-compliant Data Processing Agreements with all sub-processors.

6.4 DPA Availability: Copies of our Data Processing Agreements are available upon request at privacy@henryapi.ai

6.5 Sub-Processor Changes: We will notify tenants of any changes to the sub-processor list at least 30 days in advance. You may object to a new sub-processor by contacting privacy@henryapi.ai within that period.

6.6 Employee Access: Personal information is accessed by our employees, representatives, and consultants only on a need-to-know basis, subject to confidentiality obligations.

6.7 Legal Disclosure: We may disclose personal information if required by law, court order, regulatory investigation, or to protect our legal rights.


6A. Data Processing on Behalf of Tenants

6A.1 Dual Role: When you upload personal information of third parties to our platform (e.g., CRM contacts, customer documents, email correspondence), you are the Responsible Party (data controller) for that information, and we act as the Operator (data processor) on your behalf.

6A.2 Your Responsibilities as Responsible Party: You are responsible for:

  • Ensuring you have a lawful basis (such as consent or legitimate interest) to collect and process the personal information you upload
  • Providing appropriate privacy notices to the individuals whose data you upload
  • Honouring data subject rights requests from your customers and contacts
  • Ensuring the data you upload complies with the POPI Act

6A.3 Our Obligations as Operator: When acting as Operator, we:

  • Process data only in accordance with your lawful instructions and the purposes set out in these terms
  • Implement appropriate technical and organisational security measures (see Section 11)
  • Assist you with data subject requests upon your instruction
  • Notify you of any data breaches affecting your data (see Section 12)
  • Delete or return data upon termination of your account (subject to legal retention requirements)
  • Only engage sub-processors as listed in Section 6.2

6A.4 Data Subject Requests from Your Customers: If we receive a data subject request directly from one of your customers or contacts, we will redirect them to you as the Responsible Party. We will assist you in fulfilling such requests upon your instruction.


7. International Data Transfers

7.1 Transfer Locations: Your personal information may be transferred to and processed in:

Country Providers Safeguards
United States Supabase, Microsoft, Google, PostHog, Zoho Standard Contractual Clauses, Data Processing Agreements
South Africa AWS Local processing, POPI applies directly
France Mistral AI Standard Contractual Clauses, Data Processing Agreement
India Zoho Standard Contractual Clauses, Data Processing Agreement

7.2 Safeguards for International Transfers (POPI Section 72):

  • Standard Contractual Clauses: We use internationally recognized Standard Contractual Clauses with all international processors to ensure adequate protection
  • POPI-Compliant Safeguards: All processors are contractually obligated to maintain POPI-equivalent data protection standards
  • Data Processing Agreements: Comprehensive agreements ensuring appropriate technical and organizational measures

7.3 Your Rights: You may object to international transfers by contacting privacy@henryapi.ai. Note that objecting may limit service functionality.

7.4 No Prohibited Transfers: We do not transfer data to countries without adequate safeguards or subject to international sanctions.


8. Your Rights Under POPI

8.1 Right to Access (POPI Section 23): You have the right to request a copy of all personal information we hold about you. We will provide this within 30 days of a verified request.

8.2 Right to Correction (POPI Section 24): You may request correction of inaccurate or incomplete personal information. We will correct or update information within 30 days.

8.3 Right to Deletion (POPI Section 24): You may request deletion of your personal information, subject to:

  • Legal retention requirements (tax records, audit logs)
  • Ongoing legal proceedings or regulatory investigations
  • Contractual obligations requiring data retention

8.4 Right to Object (POPI Section 25): You may object to processing of your personal information for:

  • Direct marketing (though we do not engage in unsolicited marketing)
  • Processing based on legitimate interests
  • Automated decision-making (see Section 3A and Terms of Service Section 20)

8.5 Right to Data Portability: You may request your personal information in a structured, commonly used, machine-readable format.

8.6 How to Exercise Your Rights:

  • Email: privacy@henryapi.ai

8.7 Identity Verification: We may request proof of identity before processing your request to protect against unauthorized access.

8.8 Response Time: We will respond to all requests within 30 days as required by POPI. If we need additional time, we will notify you and explain the reason.

8.9 No Fee: Exercising your rights is free of charge. We may charge a reasonable fee for manifestly unfounded or excessive requests.

8.10 Restrictions: We may refuse requests that:

  • Are manifestly unfounded or excessive
  • Would adversely affect the rights of others
  • Are prohibited by law
  • Would compromise ongoing investigations

9. Consent and Preferences

9.1 Granular Consent: We request your explicit consent for:

  • Microsoft Integrations: Access to specific mailboxes, folders, calendars, SharePoint sites, OneDrive files, and Teams channels
  • Analytics Data Sources: Configuration and connection of external data sources for analytics purposes
  • Optional Features: Features requiring additional data access

9.2 Consent Mechanism: You can manage your consent preferences via:

  • Initial Registration: Consent screen during account creation
  • Integration Settings: Settings → Integrations

9.3 Withdrawal of Consent: You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal. To withdraw consent:

  • Email: privacy@henryapi.ai

Note: Withdrawal of consent may affect service functionality (e.g., withdrawing Microsoft integration consent will disable email and document processing features; withdrawing Analytics Data Sources consent will disable access to imported data and analytics features).

9.4 Third-Party Services: We use Microsoft 365 and Zoho services for internal business operations and productivity tools.

9.5 Consent Records: We maintain records of your consent preferences, including date, time, and scope of consent.


10. Data Retention

10.1 Retention Principle: Personal information will be deleted in accordance with the purposes described in this policy or as required by applicable legislation (POPI Section 14). However, we may retain aggregate and non-personal information indefinitely, including vehicle data, insights, usage metrics, analytics data, and statistical information that cannot be used to identify individuals.

10.2 Retention Periods:

Data Category Retention Period Legal Basis
Account data Duration of account + 30 days Contract
Email content Configurable per tenant (default: 12 months) Contract
Documents and attachments Configurable per tenant (default: 24 months) Contract
WhatsApp messages Configurable per tenant (default: 6 months) Contract
CRM contact records Duration of account + 30 days Contract
Audit logs 5 years Tax Administration Act
Product analytics/telemetry 90 days Legitimate interest
OAuth tokens Duration of integration + immediate deletion on disconnect Contract
Backup data 30 days after source deletion Legitimate interest
AI processing logs 30 days (AI provider retention for abuse monitoring) Legitimate interest

10.3 Automated Deletion: We have implemented automated processes to delete data after retention periods expire.

10.4 Exceptions: Some data may be retained longer if required by:

  • Applicable laws and regulations
  • Ongoing legal proceedings or disputes
  • Regulatory investigations
  • Tax audits or inquiries

10.5 Account Deletion: When you delete your account:

  • Account data is marked for deletion and removed within 30 days
  • Personal identifiers are anonymized where possible after 30 days
  • You can request immediate anonymization (subject to legal retention requirements)

11. Security Measures

11.1 Commitment: We take the security of your personal information seriously and have implemented up-to-date, reasonable technical and organizational security measures (POPI Section 19).

11.2 Technical Measures:

  • Encryption at Rest: All personal information fields encrypted using AES-256 (pgcrypto)
  • Encryption in Transit: All data transmitted over TLS 1.2 or higher
  • Database Security: Row Level Security (RLS) policies enforce tenant isolation
  • Password Security: Passwords hashed using industry-standard algorithms (bcrypt)
  • Token Security: OAuth tokens encrypted and stored securely
  • API Security: API key authentication, rate limiting, request validation
  • Multi-Tenant Isolation: Each tenant's data is logically separated and enforced at the database level

11.3 Organizational Measures:

  • Access Controls: Need-to-know basis, role-based access controls
  • Employee Training: Regular security and privacy training for staff
  • Confidentiality Agreements: All employees sign confidentiality agreements
  • Vendor Management: Security assessments of all third-party processors
  • Incident Response Plan: Documented breach response procedures

11.4 Regular Reviews: We continuously monitor and improve security measures in line with legal and technological developments.

11.5 Security Limitations: While we implement robust security measures, absolute security cannot be guaranteed on the internet. We cannot ensure or warrant 100% security of personal information you provide.

11.6 Your Responsibility: You are responsible for:

  • Maintaining the confidentiality of your account credentials
  • Using strong, unique passwords
  • Reporting suspected security incidents to security@henryapi.ai
  • Keeping your devices and software updated

12. Data Breach Notification

12.1 Our Commitment: In the event of a data breach that compromises your personal information, we will comply with POPI Section 22 requirements.

12.2 Notification to Regulator: We will notify the Information Regulator of South Africa as soon as reasonably possible after discovering a breach that compromises personal information.

12.3 Notification to Users: We will notify affected users if the breach is likely to cause harm, including:

  • Timeframe: Within 72 hours of breach discovery
  • Method: Email to registered address, in-app notification, website notice
  • Content: Nature of breach, data affected, potential consequences, remedial actions taken, steps users can take to protect themselves

12.4 Breach Information: Notifications will include:

  • Description of the breach and how it occurred
  • Type of personal information compromised
  • Potential consequences and risks
  • Measures taken to contain and remediate the breach
  • Measures taken to prevent future breaches
  • Contact information for further inquiries

12.5 Breach Response Plan: We maintain an incident response plan including:

  • Immediate Containment: Isolate affected systems, revoke compromised credentials
  • Forensic Investigation: Determine scope, cause, and impact of breach
  • Remediation: Fix vulnerabilities, restore services securely
  • Notification: Timely communication with affected parties and regulator
  • Post-Incident Review: Learn from incidents, improve security measures

12.6 Your Rights After a Breach: If you are affected by a breach, you have the right to:

  • Receive detailed information about the breach
  • Request additional security measures for your account
  • Lodge a complaint with the Information Regulator
  • Pursue legal remedies for damages

12.7 Breach Reporting: If you suspect a data breach, report it immediately to security@henryapi.ai

12.8 Tenant Notification: Where we act as Operator for tenant-uploaded data, we will notify the affected tenant as soon as reasonably possible (and in any event within 72 hours) so that the tenant may fulfil its own notification obligations as Responsible Party.


13. Cookies and Tracking Technologies

13.1 What are Cookies: A cookie is a small text file stored on your device by your web browser. We use cookies to enhance your experience and provide certain functionalities.

13.2 Cookies We Use:

Cookie Name Type Purpose Duration Provider
session_token Essential User authentication, session management Session (expires on browser close) HenryAPI
user_preferences Functional Store UI settings, language, theme For contract duration HenryAPI

13.3 Cookie Categories:

  • Essential Cookies: Required for the website to function. These include authentication and security cookies. You cannot disable these cookies.

Note: Disabling essential cookies will prevent login and core functionality.

13.4 Product Analytics: We use PostHog for product analytics. PostHog is configured to operate in a cookieless mode and does not place tracking cookies on your device. Usage data collected through PostHog is anonymized and aggregated.


14. Children's Privacy

14.1 Age Restriction: Our services are not intended for individuals under 18 years of age. By using our services, you represent that you are at least 18 years old.

14.2 No Knowingly Collected Data: We do not knowingly collect personal information from children under 18.

14.3 Parental Consent: If we discover we have collected information from a child under 18 without verifiable parental consent (as required by POPI Section 11), we will delete it immediately.

14.4 Parent/Guardian Rights: Parents or legal guardians may request:

  • Access to their child's information
  • Correction or deletion of such information
  • Verification of consent provided

14.5 Reporting: If you believe we have collected information from a child under 18, please contact us immediately at privacy@henryapi.ai


15. Information Officer

15.1 Responsible Party: Henry AI (Pty) Ltd (Registration Number: 2023/620906/07) is the Responsible Party as defined in the POPI Act.

15.2 Information Officer: We have designated an Information Officer to oversee POPI compliance as required by POPI Sections 55-56:

  • Name: Ian Fourie
  • Email: privacy@henryapi.ai
  • Address: Lewis Drive, Constantia, Cape Town, 7806

15.3 Responsibilities: Our Information Officer handles:

  • Data subject requests (access, deletion, correction, objection)
  • Privacy complaints and concerns
  • POPI compliance monitoring and reporting
  • Liaison with the Information Regulator
  • Privacy impact assessments
  • Data breach management and notification
  • Staff training on data protection

16. Changes to This Policy

16.1 Right to Modify: We reserve the right to modify this Privacy Policy at any time to reflect:

  • Changes in our services or business practices
  • Legal or regulatory requirements
  • Technological developments
  • User feedback and best practices

16.2 Notification of Changes:

  • Email Notification: We will notify all users via email when these changes occur.

16.3 Re-Consent: Where changes materially affect the purposes or scope of data processing, we may require you to re-confirm your consent before continuing to use the service.

16.4 Your Acceptance: Continued use of our services after the effective date constitutes acceptance of the updated policy. If you do not agree with changes, you may delete your account.


17. How to Contact Us

17.1 Privacy Inquiries: For any questions, concerns, or requests regarding this Privacy Policy or your personal information:

  • Email: privacy@henryapi.ai
  • General Inquiries: info@henryapi.ai
  • Legal Inquiries: legal@henryapi.ai
  • Security Issues: security@henryapi.ai

17.2 Response Time: We aim to respond to all privacy inquiries within 5 business days.

17.3 Company Information:

  • Legal Name: Henry AI (Pty) Ltd
  • Registration Number: 2023/620906/07
  • Website: https://henryexchange.ai/
  • Application: https://app.henryexchange.ai/

18. Complaints and Disputes

18.1 Internal Complaint Process: If you have a complaint about how we handle your personal information:

Step 1: Submit a complaint to our Information Officer at privacy@henryapi.ai

Step 2: We will acknowledge your complaint within 5 business days

Step 3: We will investigate and respond within 30 days

Step 4: If you are not satisfied, you may escalate internally

18.2 Information Regulator: You have the right to lodge a complaint with the Information Regulator of South Africa:

  • Website: https://www.justice.gov.za/inforeg/
  • Email: inforeg@justice.gov.za
  • Phone: +27 10 023 5200
  • Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
  • Postal Address: P.O Box 31533, Braamfontein, Johannesburg, 2017
  • Complaint Form: Available at https://www.justice.gov.za/inforeg/docs/InfoRegSA-ComplaintForm.pdf

18.3 No Retaliation: We will not retaliate against you for lodging a complaint or exercising your POPI rights.

18.4 Good Faith Resolution: We are committed to resolving complaints in good faith and improving our practices based on feedback.


19. Legal Framework

19.1 Governing Law: This Privacy Policy is governed by:

  • Protection of Personal Information Act 4 of 2013 (POPI Act)
  • Electronic Communications and Transactions Act 25 of 2002 (ECT Act)
  • Regulation of Interception of Communications and Provision of Communication-Related Information Act 70 of 2002 (RICA)
  • Companies Act 71 of 2008 (record retention requirements)
  • Tax Administration Act 28 of 2011 (tax record retention)

19.2 Electronic Communications (ECT Act):

19.2.1 Data Messages (as defined in the ECT Act) will be deemed to have been received by us if and when we respond to the Data Messages.

19.2.2 Data Messages sent by us to you will be deemed to have been received by you in terms of the provisions specified in section 23(b) of the ECT Act.

19.2.3 You acknowledge that electronic signatures, encryption, and/or authentication are not required for valid electronic communications between you and us.

19.2.4 You warrant that Data Messages sent to us from any electronic device used by you, or owned by you, were sent and/or authorized by you personally.

19.2.5 This Website is owned and operated by Henry AI (Pty) Ltd, Registration Number 2023/620906/07, with physical address at Lewis Drive, Constantia, Cape Town, 7806.

19.2.6 Contact Number: +27 73 585 4895.

19.2.7 Website URL: https://henryexchange.ai/

19.2.8 Application URL: https://app.henryexchange.ai/

19.2.9 Email address: info@henryapi.ai

19.3 Jurisdiction: This Privacy Policy and any disputes arising from it are subject to the laws of South Africa. You consent to the jurisdiction of South African courts.

19.4 Severability: If any provision of this policy is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect.

19.5 Entire Agreement: This Privacy Policy, together with our Terms of Service, constitutes the entire agreement regarding our privacy practices.


20. Links to Third-Party Websites

20.1 Our services may contain links to third-party websites, including:

  • Social media platforms
  • Microsoft Outlook and SharePoint
  • Payment gateways (external processors)
  • Business productivity platforms (Microsoft 365, Zoho)

20.2 Not Under Our Control: If you select a link to any third-party website, you may be subject to such third-party websites' terms and conditions and/or other policies, which are not under our control or responsibility.

20.3 No Endorsement: Hyperlinks are provided "as is." We do not necessarily agree with, edit, or sponsor the content on third-party websites.

20.4 No Responsibility: We do not monitor or review the content of third-party websites. We are not responsible for their privacy practices or content.

20.5 Your Caution: You should evaluate the security and trustworthiness of any third-party websites before disclosing personal information to them. We do not accept responsibility for any loss or damage resulting from your disclosure to third parties.


END OF PRIVACY POLICY

HENRYEXCHANGE

One marketplace connecting demand, data and partners across the South African motor industry.

Platform

  • How it works
  • Trust and controls
  • Insights
  • Partner roles
  • Capabilities
  • Communications
  • Integrations

Get started

  • Join the Exchange
  • See how your business fits
© 2026 Henry AI (Pty) Ltd. All rights reserved.
LegalPrivacy policyTerms of serviceAcceptable use policy