Legal
Privacy policy
How personal information is handled at Indigo Collective, under the Protection of Personal Information Act, 2013. The short version: your data is yours, and we claim nothing in it.
Last updated 1 September 2026
1. Who this policy is from
Indigo Collective is the trading name of Indigo Haddington, a sole proprietor established in the Republic of South Africa. In this policy, we and us mean Indigo Collective, and the Act means the Protection of Personal Information Act, 2013.
- Responsible party
- Indigo Haddington, trading as Indigo Collective
- Information Officer
- Indigo HaddingtonUnder section 56 of the Act, the head of a private body is its Information Officer.
- indigo@indigocollective.ai
2. Two roles, and why the difference matters
We hold personal information in two different capacities. Which one applies changes who is answerable for it.
For our own business we are the responsible party. That covers enquiries, correspondence, client records, invoicing and this website. It is what the rest of this policy describes.
For work we do inside a client's business we are an operator. The client stays the responsible party for their own customer, staff and supplier information. We process it only on their documented instructions, only for that engagement, and never for our own purposes.
3. Your data and your systems stay yours
Data you put into a system we build, and the data that system produces, belong to you. We do not own it, we do not sell it, we do not share it with another client, and we do not use it to train any model or product of our own.
The configuration we deploy in your own accounts is yours to keep and to run, under the licence set out in the terms of service. It stays yours if you stop working with us and it transfers with the business if you sell it.
At the end of an engagement we return or delete the personal information we hold as your operator, whichever you choose, except where the law requires us to keep a copy. Credentials and access are revoked and not retained.
4. What we collect
- Contact and business details you give us: your name, your email address, your telephone number where you provide it, the organisation you work for and your role in it.
- What you type into a form on this site. The contact form takes a name, an email address and a message. The audit intake form takes the business information you choose to enter.
- Correspondence. If you email, call or message us, we keep the thread and any notes made from it.
- Meeting and engagement records: notes, findings and the documents produced for a piece of work.
- Recordings and transcripts, where a call is recorded. We tell you before a call is recorded and you may decline.
- Voice demonstration audio, where you choose to use the voice demo on this site, processed so the system can answer you.
- Billing information: what was invoiced, what was paid and when. Card details are entered with our payment provider and are never seen or stored by us.
- Technical records kept by our hosting provider, including IP addresses, for security and reliability.
5. How we collect it
Directly from you in almost every case: a form on this site, an email, a message, a call or a meeting.
We also use information that is publicly available or that a business has published about itself, such as a company website or a public professional profile, to work out whether what we do is relevant to that business before we make contact.
6. Why we have it, and on what basis
We process personal information to answer an enquiry, to prepare and deliver work you have asked for, to run and support what we have built, to invoice and take payment, to keep proper accounting records, and to meet obligations placed on us by law.
Section 11 of the Act requires a justification for each of those. We rely on your consent where you submit a form or agree to a call being recorded, on the performance of a contract with you once we are working together, on obligations imposed by law for tax and accounting records, and on our legitimate interests in running and protecting the business. Where we rely on consent you may withdraw it at any time.
7. Who else sees it
Personal information is shared only where it is needed to run the business or to deliver the work, and each provider is bound by its own data protection terms and processes information on our instructions.
We deliberately do not publish a list of named providers here. The list changes as the work changes, and a page naming today's tools is wrong the moment one is added. The categories are these:
- Hosting
- Running this website and the applications and databases a system needs
- Email and documents
- Correspondence, scheduling and file storage
- AI providers
- Generating, structuring and classifying text inside a system
- Automation
- Orchestrating the steps a system runs through, and storing enquiry and client records
- Messaging
- Delivering messages, calls and forms on a connected channel
- Payments
- Invoicing, taking payment, banking and accounting
- Advisers
- Legal and accounting advice, where it is needed
The providers used in a particular engagement, and where they are established, are named in that client's own agreement. If you want to know which providers hold information about you, ask us and we will tell you. We do not sell personal information, we do not rent it, and we do not share it for anyone else's marketing. Where we use a subcontractor they are bound by equivalent obligations and we stay responsible for what they do.
8. Where it goes
Some of the providers described above are established outside South Africa, so personal information may be transferred and stored in another country.
Section 72 of the Act allows a transfer of that kind where the recipient is bound by rules providing an adequate level of protection, where you have consented, or where the transfer is necessary to perform a contract with you. We only use providers that are contractually bound to protect personal information to a standard comparable to the one the Act requires, in most cases under standard contractual clauses offered by that provider.
9. How long we keep it
- Enquiries
- 24 months from the last contact, where the enquiry does not become work
- Client records
- For the engagement, then 5 yearsMatching the contractual prescription period.
- Invoices
- 5 years, or longer where tax law requires it
- Credentials
- Revoked at the end of the engagement and not retained
- Client data
- As set out in that client's own agreement, where we hold it as an operator
When a retention period ends the information is deleted, or de-identified where a record of the work itself has to be kept.
10. How we protect it
Section 19 of the Act requires reasonable technical and organisational measures. Access is limited to the people who need it for the work, accounts use multi-factor authentication where the provider supports it, connections to the services we use are encrypted, and access granted for an engagement is revoked when it ends.
No system is completely secure. If a breach compromises your personal information we will notify you and the Information Regulator, as section 22 of the Act requires.
11. Marketing
We contact businesses directly about what we do. If you would rather we did not, reply to the message or email us and we will stop, and we keep a record of that so you are not contacted again by mistake.
We do not sell or rent contact details to anyone else, and we do not add you to a newsletter because you enquired about a piece of work.
12. Cookies and tracking
This site uses no analytics, advertising or tracking cookies. We do not build advertising profiles, we do not run a pixel for anyone else, and we do not track you across other sites.
13. Automated decision making
We build systems that classify, route, draft and prioritise. Under section 71 of the Act you have the right not to be subject to a decision that has legal consequences for you, or affects you substantially, taken solely by automated processing.
Nothing we run for ourselves makes a decision of that kind about you without a person involved. Where a system we build for a client could do so, it is the client's responsibility as responsible party to keep a person in that decision, and we say so when we design it.
14. Your rights
Under the Act you may ask us to confirm whether we hold personal information about you and to give you a copy of it, ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date or held without a proper basis, object to processing we are carrying out on the basis of legitimate interests, withdraw a consent you have given, and object to receiving direct marketing.
Email indigo@indigocollective.ai. We will acknowledge the request and respond within 30 days. We may need to confirm your identity first, so that we do not disclose someone's information to the wrong person. A request for access to a record may also be made under the Promotion of Access to Information Act, 2000, and is handled in the manner that Act requires.
Where we hold the information as an operator for a client, we will pass your request to that client, who is the responsible party for it, and tell you that we have done so.
15. Complaints
If you are not satisfied with how we have handled your personal information, tell us first and we will try to put it right.
You may also complain to the Information Regulator of South Africa, which supervises the Act. Its complaint procedure and current contact details are published at inforegulator.org.za.
16. Changes to this policy
We may update this policy as the business changes or the law does. The date at the top of this page is the date of the version currently in force, and it is the version that applies to information we hold when you read it.
Questions about any of this go to indigo@indigocollective.ai.