Privacy Policy
This Privacy Policy explains how the BizGo Platform operated by GoSoftSolutions (Pty) Ltd, collects, uses, shares, and protects personal information in connection with the BizGo platform, websites, and related services. It forms part of our Terms of Service.
It covers two distinct relationships:
- The first: Account holders — the businesses and individuals who sign up for and use BizGo. For this data we are the responsible party or controller.
- The second: End users / your customers — the people our account holders communicate with or whose details they store in the Service. For this data the account holder is the responsible party or controller, and we act as the operator or processor on their behalf and instructions.
This policy is written to align with the Protection of Personal Information Act, 4 of 2013 (POPIA) and, where it applies, the EU/UK GDPR.
1. Definitions
- 1.1 “Account” — the organisation account you create to use the Service.
- 1.2 “BizGo” — refers to “we”, “us”, “our”, “the service”.
- 1.3 “Customer Data” — data you or your End Users put into the Service, including contact details, messages, quotes, invoices, and job records.
- 1.4 “End User” / “Your Customers” — the people you communicate with or whose details you store and process through the Service.
- 1.5 “EEA” — Refers to the European Economic Area.
- 1.6 “GDPR” — Refers to the General Data Protection Regulation. A Privacy and Security law passed by the European Union (EU) and the United Kingdom (UK).
- 1.7 “Payment Processor” — PayFast, the third-party payment gateway that processes card payments and securely stores your card credentials on our behalf.
- 1.8 “Plan” — a tier of the Service, such as the free trial or a paid monthly plan, with its bundled modules and limits, as shown on our pricing page at sign-up.
- 1.9 “POPIA” — Refers to the Protection of Personal Information Act 4 of 2013.
- 1.10 “Subscription” — your chosen plan and the recurring fees payable for it.
- 1.11 “Terms” — Refers to “Terms of Service”.
- 1.12 “You” — Refers to “you”, “your”, the “Customer”.
2. Who we are and how to contact us
Responsible party: GoSoftSolutions (Pty) Ltd
Registration number: 2026 / 409253 / 07
Email: info@gosoftsolutions.co.za
3. The personal information we process
- 3.1 Account data — information you provide when you register and use the Service: name, email address, business name, location (country and city), login credentials (stored hashed), and your in-app settings and preferences.
- 3.2 Payment data — when you subscribe to a paid plan, card payments are processed by PayFast. Your full card details are entered on and stored by PayFast and are never stored on BizGo’s own servers. We retain only a reference token and limited metadata (e.g. card brand and last four digits, and payment/invoice records) needed to manage your subscription and issue tax invoices.
- 3.3 Customer data (processed on your behalf) — the contact details and content that account holders put into the Service about their own customers, including names, phone numbers, email addresses, message history (WhatsApp and email), quotes, invoices, jobs and bookings, and any attachments. For this category the account holder is the controller and we are the processor.
- 3.4 Staff and payroll data — where an account holder uses the staff/payroll features, we process the employee information they enter (which may include bank details where that feature is enabled) as their processor.
- 3.5 Technical and usage data — information generated automatically when you use the Service, such as IP address, device and browser information, log data, and feature-usage metrics used for security, support, billing, and improving the Service.
- 3.6 Support and communications data — messages you send us and records of our correspondence and support access.
4. How we use personal information, and our lawful basis
We process personal information to:
- 4.1 Provide, operate, and maintain the Service (including sending WhatsApp and email messages on your instruction, and storing conversation history);
- 4.2 Create and manage your account and authenticate you;
- 4.3 Process subscriptions, take payment, and issue invoices;
- 4.4 Provide support and respond to your requests;
- 4.5 Monitor, secure, and improve the Service, and prevent abuse and fraud;
- 4.6 Comply with legal obligations and enforce our Terms.
Where POPIA/GDPR requires a lawful basis, we rely on: performance of a contract (to provide the Service you signed up for), legitimate interests (to secure, support, and improve the Service and prevent abuse), consent (where required, e.g. certain marketing), and compliance with a legal obligation (e.g. tax records). For customer data we process on an account holder’s behalf, the account holder is responsible for establishing the lawful basis for their processing.
We do not sell personal information, and we do not use customer data to train AI models.
5. Cookies and similar technologies
We use cookies and similar technologies that are required for the Service to work. Because these cookies are essential to core features, we do not offer an in-app option to switch them off, and the Service may not function correctly without them. We use them for the following purposes:
- 5.1 Strictly necessary cookies — to operate the Service, for example to keep you signed in and to keep the Service secure. These are always on.
- 5.2 WhatsApp / Meta connection cookies — when you connect your WhatsApp account, we load Meta’s (Facebook’s) sign-up and login tools, which set their own cookies. These are required by Meta to complete and secure the connection, and are subject to Meta’s own privacy policy. Because this integration depends on them, they cannot be disabled while using this feature.
- 5.3 Product-analytics cookies — to understand how our websites and app are used (such as which features are used and how visitors move through the product) so we can improve it. We use these for our own internal product analytics only: we do not use them for advertising, we do not share them with advertising networks, and we never sell your data. These cookies are set by Microsoft Azure Application Insights and include identifiers such as
ai_userandai_session, which let us count returning users and stitch together a visit.
When you first use the Service we show a short notice that cookies are used and links to this policy. As these cookies are required to provide the Service, the notice is informational only and does not offer an opt-out. You can still control or clear cookies through your browser settings, but doing so may prevent parts of the Service — including WhatsApp connection and staying signed in — from working.
6. Who we share personal information with
We share personal information only as needed to run the Service, with the following categories of recipients (“operators” / sub-processors):
- 6.1 Meta / WhatsApp — WhatsApp messages you send and receive through the Service travel over WhatsApp’s network and are subject to Meta’s own privacy policy.
- 6.2 Mailgun — to deliver email messages on your behalf.
- 6.3 PayFast — to process payments and securely store card credentials.
- 6.4 Cloud hosting and storage providers — to host the platform and store data and file attachments.
We may also disclose personal information where required by law, to protect our rights, safety, or property, or in connection with a merger, acquisition, or sale of assets (subject to this policy). We do not otherwise sell or rent personal information.
7. Where your information is stored (international transfers)
- 7.1 Where personal information is stored. Personal information is stored in the European Union (Microsoft Azure, West Europe region — the Netherlands). This covers account data, Customer Data, message content, files you upload and documents the Service generates for you such as quote and invoice PDFs, and the product-analytics data described in clause 5.3.
- 7.2 Basis for the transfer out of South Africa. Storing personal information in the European Union is a cross-border transfer under section 72 of POPIA. We make that transfer on the basis that the recipient is subject to a law that provides an adequate level of protection — EU data protection law (the GDPR), which upholds principles for the lawful processing of personal information that are substantially similar to those in POPIA and includes provisions restricting onward transfer to a third country. That protection is reinforced by a written data processing agreement with our hosting provider on terms that bind it to equivalent protection and restrict onward transfer. Where you are an account holder, the transfer is in addition necessary for the performance of the contract between you and us, and your acceptance of our Terms is your instruction to store and process the data in that region.
- 7.3 Other recipients. The operators listed in clause 6 may process personal information outside South Africa and outside the EEA. Where that happens we take steps to ensure it receives an adequate level of protection as required by POPIA and, where it applies, the GDPR — including standard contractual clauses where appropriate.
- 7.4 Changes to storage location. If we change the region in which personal information is stored, we will update this policy and give notice in the manner set out in clause 16 of our Terms of Service.
8. How long we keep personal information
- 8.1 We keep account and customer data for as long as your account is active.
- 8.2 After a paused, cancelled, or terminated account, your data is retained for 90 days so you can reactivate or export it, after which it may be permanently deleted.
- 8.3 We keep payment and invoice records for as long as required by tax and accounting law.
- 8.4 We keep limited log and security data for as long as needed for security and legal purposes.
You can export your data from the app at any time before deletion.
9. Security
We apply appropriate technical and organisational measures to protect personal information, including encryption in transit (TLS 1.2+) and at rest, access controls, and audit logging. No method of transmission or storage is perfectly secure; you are responsible for keeping your own credentials safe and for controlling who has access to your account.
10. Operator (staff) access
For support and to operate the Service, our staff may access account and customer data where reasonably necessary. Every such access is recorded in an audit log that is available to you on request.
11. Your rights
Subject to POPIA/GDPR and applicable law, you have the right to:
- 11.1 Access the personal information we hold about you;
- 11.2 Correct inaccurate or incomplete information;
- 11.3 Delete your information (subject to legal retention obligations);
- 11.4 Object to or restrict certain processing;
- 11.5 Withdraw consent where we rely on it;
- 11.6 Data portability (receive your data in a portable format); and
- 11.7 Lodge a complaint with a supervisory authority.
To exercise these rights, contact us at GoSoftSolutions (Pty) Ltd. In South Africa, you may also complain to the Information Regulator (South Africa) (enquiries@inforegulator.org.za / inforegulator.org.za). If the GDPR applies to you, you may complain to your local EU/UK data protection authority.
12. Your customers’ rights
If you are an end user / customer of a business that uses BizGo, that business — not BizGo — is the responsible party for your data. Please direct any privacy request (access, correction, deletion, opt-out) to that business. As their operator, we will assist them in fulfilling valid requests. You can opt out of a business’s messages at any time using the unsubscribe link or STOP keyword, which we handle automatically.
13. Minors
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal information from minors. Account holders are responsible for any personal information of minors they choose to process through the Service and for having a lawful basis to do so.
14. Changes to this policy
We may update this policy from time to time. For material changes we will give notice by email and/or in-app. The “Last updated” date at the top shows when the policy was last revised. Your continued use of the Service after changes take effect constitutes acceptance.