Privacy Policy
Last updated: 15 June 2026
This Privacy Policy explains how iAutomateDev (“Vantage”, “we”, “us”) collects, uses, shares and protects personal information in connection with the Vantage platform (the “Service”). It is written to align with the South African Protection of Personal Information Act, 2013 (“POPIA”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).
For data you connect or upload (“Customer Data”), your organisation is the responsible party / controller and Vantage acts as an operator / processor, handling that data only on your documented instructions.
1. Who we are & how to contact us
iAutomateDev is the responsible party for personal information processed about visitors and account holders. Our Information Officer can be reached at privacy@iautomatedev.com for any privacy question, access request, or to exercise the rights described below. You may also use the contact form on our website.
2. Personal information we collect
We collect only what we need:
Account & enquiry data — name, work email, company, role, team size and any message you send us. Usage & technical data — log data, IP address, browser/device type and approximate location, collected to operate and secure the Service. Customer Data — the business data your organisation connects from its sources, which remains under your control. We do not deliberately collect special-category data or data relating to children; please do not upload it without a lawful basis.
3. Why we process it (lawful basis)
Performance of a contract — to provide the Service, run system updates and handle billing. Legitimate interests — analytics, error monitoring, platform security and product improvement, balanced against your rights. Consent — for non-essential marketing or telemetry, which you may withdraw at any time. Legal obligation — to meet tax, accounting and lawful-request requirements.
4. Cookies & tracking
We use essential cookies to authenticate sessions and keep the Service secure. Any non-essential analytics cookies are used only where permitted, and you can manage non-essential cookies without losing access to the app. We honour browser “do not track” signals where required.
5. How we share information & our sub-processors
We do not sell personal information. We share it only with vetted sub-processors who help us run the Service under binding data-processing agreements, including our hosting and application platform (Vercel), our database and authentication provider (Supabase), and our automation/notification provider (n8n). We will give reasonable notice before adding or changing a material sub-processor, and may also disclose information where required by law.
6. International transfers
Your information may be processed outside South Africa or the EU. Where it is, we rely on lawful transfer mechanisms — such as transfers to countries with adequate protection, EU Standard Contractual Clauses, or the conditions for cross-border transfer under POPIA section 72 — to ensure an equivalent level of protection.
7. How long we keep it
We keep account and Customer Data for as long as your organisation uses the Service. After termination, Customer Data is deleted or securely anonymised within 90 days, except where we must retain certain records (for example financial and tax records, typically for 5–7 years) to meet legal obligations.
8. Your rights
Subject to applicable law, you may access the personal information we hold, request a correction or deletion, object to or restrict certain processing, withdraw consent, and request a portable export of your data. To exercise any right, contact privacy@iautomatedev.com. You also have the right to lodge a complaint with the South African Information Regulator or, in the EU, your local supervisory authority.
9. Security & breach notification
We protect data with organisation-scoped access, role-based permissions, row-level security and encryption in transit. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify the relevant regulator and affected users as soon as reasonably possible (and, where GDPR applies, the supervisory authority within 72 hours of becoming aware), in line with POPIA section 22.
10. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children.
11. Changes & contact
We may update this Policy and will revise the date above; material changes will be notified to account holders. For any privacy matter, contact privacy@iautomatedev.com.