Privacy Policy
Plain-language summary: We collect only what you give us — through the booking form, a calendar booking, a paid scan, or a payment. We use it to respond to you and run your project, store it in Google Workspace, process card payments through Peach Payments (we never see your card number), never sell anything, and delete it when you ask.
1. Who is responsible for your information
The responsible party under the Protection of Personal Information Act (POPIA) is KTH Tech, trading as ARTEFX, South Africa. Contact for all privacy matters: enterprise@kth-tech.com.
2. What we collect and why
| Information | Where from | Why we use it |
|---|---|---|
| Name, email, company, industry | Booking / contact form | To respond to your enquiry and prepare your consultation |
| Project details, budget range | Booking form | To scope and quote your project accurately |
| Your chosen consultation slot | Google Calendar booking page | To hold the appointment and send you a calendar invite |
| Website address you submit for a scan | AI Readiness Snapshot form | To run the scan and produce your report |
| Email address and payment confirmation | Peach Payments checkout | To take payment, issue a receipt, and start your work. We never receive or store your card number |
| Client access code and project status | Client Portal | To show you your own project's progress and files |
| Correspondence | Email with us | To manage your project and keep records of agreements |
| Basic technical data (browser type, device) | Your browser | To make sure the site works correctly |
We collect personal information directly from you, process it only for the purposes above, and collect nothing more than we need (POPIA minimality principle). We do not process special personal information or children's information, and we do not use your information for automated decision-making.
3. Cookies & local storage
This site uses no advertising or tracking cookies. It does use your browser's own storage for a few practical things, all of which stay on your device and can be cleared in your browser settings at any time:
- Booking confirmations — a copy of your submission so the form can confirm it back to you.
- Discount codes — if you arrive via a promotional QR code or link, the code is remembered so it can be applied to your booking.
- Client Portal session — your access code is held for the duration of your visit so you don't have to re-enter it.
4. ARIA, our on-site assistant
ARIA is the chat assistant on our website. It runs entirely inside your own browser — your messages are matched against a fixed set of answers on your device and are not sent to us, stored, or shared with any AI provider. Nothing you type into ARIA reaches our systems unless you go on to submit the booking form yourself.
5. Where your information is stored
- Booking submissions are delivered to our Google Workspace environment (Google Sheets and Gmail), protected by access controls and Google's security infrastructure.
- Consultation appointments are held in Google Calendar. When you book a slot, Google processes the details you enter on their booking page under their own privacy terms.
- Card payments are processed by Peach Payments, a licensed South African payment provider. Card details are entered directly into their secure checkout — they are never transmitted to or stored by us. We receive only a confirmation, a reference, and the email you supplied.
- Google and Peach Payments may store data on servers outside South Africa; such transfers are protected by those providers' contractual safeguards, consistent with section 72 of POPIA.
- Access is limited to KTH Tech personnel who need it to serve you.
- We keep enquiry information for up to 24 months after last contact, and project and payment records for 5 years for legal and tax purposes, after which they are deleted.
6. Who we share it with
We never sell or rent your personal information. We share it only with the service providers that make our operations possible — Google Workspace (bookings, email), Google Calendar (appointments), Peach Payments (card payments), and our hosting provider — each acting as an operator on our instructions; and with authorities where the law requires it. That is the full list.
7. Security
We apply reasonable, appropriate technical and organisational measures as required by section 19 of POPIA: encrypted connections (SSL/TLS) on this site, hardened forms, access-controlled storage, and two-factor authentication on our systems. If a data breach ever affects you, we will notify you and the Information Regulator as required by section 22 of POPIA.
8. Your rights under POPIA
- Access — ask what personal information we hold about you.
- Correction — ask us to fix inaccurate or outdated information.
- Deletion — ask us to delete your information (subject to legal retention duties).
- Objection — object to processing, or withdraw consent, at any time.
- Complaint — lodge a complaint with the Information Regulator of South Africa: inforegulator.org.za · complaints.IR@inforegulator.org.za.
To exercise any of these rights, email enterprise@kth-tech.com — we respond within a reasonable time and at most within the periods POPIA allows.
9. Client projects
Where we build a product that processes your customers' personal information, we act as your operator under POPIA: we process that information only on your documented instructions, secure it as required by section 21, and it remains your data throughout — governed by your project agreement, not this policy.
10. Changes to this policy
If we change this policy, we update the date at the top of this page. Material changes affecting active clients are notified by email.