Legal

Privacy policy

How personal information is handled at Indigo Collective, under the Protection of Personal Information Act, 2013. The short version: your data is yours, and we claim nothing in it.

Last updated 1 September 2026

1. Who this policy is from

Indigo Collective is the trading name of Indigo Haddington, a sole proprietor established in the Republic of South Africa. In this policy, we and us mean Indigo Collective, and the Act means the Protection of Personal Information Act, 2013.

Responsible party
Indigo Haddington, trading as Indigo Collective
Information Officer
Indigo HaddingtonUnder section 56 of the Act, the head of a private body is its Information Officer.
Email
indigo@indigocollective.ai

2. Two roles, and why the difference matters

We hold personal information in two different capacities. Which one applies changes who is answerable for it.

For our own business we are the responsible party. That covers enquiries, correspondence, client records, invoicing and this website. It is what the rest of this policy describes.

For work we do inside a client's business we are an operator. The client stays the responsible party for their own customer, staff and supplier information. We process it only on their documented instructions, only for that engagement, and never for our own purposes.

3. Your data and your systems stay yours

Data you put into a system we build, and the data that system produces, belong to you. We do not own it, we do not sell it, we do not share it with another client, and we do not use it to train any model or product of our own.

The configuration we deploy in your own accounts is yours to keep and to run, under the licence set out in the terms of service. It stays yours if you stop working with us and it transfers with the business if you sell it.

At the end of an engagement we return or delete the personal information we hold as your operator, whichever you choose, except where the law requires us to keep a copy. Credentials and access are revoked and not retained.

4. What we collect

5. How we collect it

Directly from you in almost every case: a form on this site, an email, a message, a call or a meeting.

We also use information that is publicly available or that a business has published about itself, such as a company website or a public professional profile, to work out whether what we do is relevant to that business before we make contact.

6. Why we have it, and on what basis

We process personal information to answer an enquiry, to prepare and deliver work you have asked for, to run and support what we have built, to invoice and take payment, to keep proper accounting records, and to meet obligations placed on us by law.

Section 11 of the Act requires a justification for each of those. We rely on your consent where you submit a form or agree to a call being recorded, on the performance of a contract with you once we are working together, on obligations imposed by law for tax and accounting records, and on our legitimate interests in running and protecting the business. Where we rely on consent you may withdraw it at any time.

7. Who else sees it

Personal information is shared only where it is needed to run the business or to deliver the work, and each provider is bound by its own data protection terms and processes information on our instructions.

We deliberately do not publish a list of named providers here. The list changes as the work changes, and a page naming today's tools is wrong the moment one is added. The categories are these:

Hosting
Running this website and the applications and databases a system needs
Email and documents
Correspondence, scheduling and file storage
AI providers
Generating, structuring and classifying text inside a system
Automation
Orchestrating the steps a system runs through, and storing enquiry and client records
Messaging
Delivering messages, calls and forms on a connected channel
Payments
Invoicing, taking payment, banking and accounting
Advisers
Legal and accounting advice, where it is needed

The providers used in a particular engagement, and where they are established, are named in that client's own agreement. If you want to know which providers hold information about you, ask us and we will tell you. We do not sell personal information, we do not rent it, and we do not share it for anyone else's marketing. Where we use a subcontractor they are bound by equivalent obligations and we stay responsible for what they do.

8. Where it goes

Some of the providers described above are established outside South Africa, so personal information may be transferred and stored in another country.

Section 72 of the Act allows a transfer of that kind where the recipient is bound by rules providing an adequate level of protection, where you have consented, or where the transfer is necessary to perform a contract with you. We only use providers that are contractually bound to protect personal information to a standard comparable to the one the Act requires, in most cases under standard contractual clauses offered by that provider.

9. How long we keep it

Enquiries
24 months from the last contact, where the enquiry does not become work
Client records
For the engagement, then 5 yearsMatching the contractual prescription period.
Invoices
5 years, or longer where tax law requires it
Credentials
Revoked at the end of the engagement and not retained
Client data
As set out in that client's own agreement, where we hold it as an operator

When a retention period ends the information is deleted, or de-identified where a record of the work itself has to be kept.

10. How we protect it

Section 19 of the Act requires reasonable technical and organisational measures. Access is limited to the people who need it for the work, accounts use multi-factor authentication where the provider supports it, connections to the services we use are encrypted, and access granted for an engagement is revoked when it ends.

No system is completely secure. If a breach compromises your personal information we will notify you and the Information Regulator, as section 22 of the Act requires.

11. Marketing

We contact businesses directly about what we do. If you would rather we did not, reply to the message or email us and we will stop, and we keep a record of that so you are not contacted again by mistake.

We do not sell or rent contact details to anyone else, and we do not add you to a newsletter because you enquired about a piece of work.

12. Cookies and tracking

This site uses no analytics, advertising or tracking cookies. We do not build advertising profiles, we do not run a pixel for anyone else, and we do not track you across other sites.

13. Automated decision making

We build systems that classify, route, draft and prioritise. Under section 71 of the Act you have the right not to be subject to a decision that has legal consequences for you, or affects you substantially, taken solely by automated processing.

Nothing we run for ourselves makes a decision of that kind about you without a person involved. Where a system we build for a client could do so, it is the client's responsibility as responsible party to keep a person in that decision, and we say so when we design it.

14. Your rights

Under the Act you may ask us to confirm whether we hold personal information about you and to give you a copy of it, ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date or held without a proper basis, object to processing we are carrying out on the basis of legitimate interests, withdraw a consent you have given, and object to receiving direct marketing.

Email indigo@indigocollective.ai. We will acknowledge the request and respond within 30 days. We may need to confirm your identity first, so that we do not disclose someone's information to the wrong person. A request for access to a record may also be made under the Promotion of Access to Information Act, 2000, and is handled in the manner that Act requires.

Where we hold the information as an operator for a client, we will pass your request to that client, who is the responsible party for it, and tell you that we have done so.

15. Complaints

If you are not satisfied with how we have handled your personal information, tell us first and we will try to put it right.

You may also complain to the Information Regulator of South Africa, which supervises the Act. Its complaint procedure and current contact details are published at inforegulator.org.za.

16. Changes to this policy

We may update this policy as the business changes or the law does. The date at the top of this page is the date of the version currently in force, and it is the version that applies to information we hold when you read it.

Questions about any of this go to indigo@indigocollective.ai.