Privacy policy

Last updated 26 August 2026

This policy explains what Connect24 does with personal information — both the information we hold about our own customers, and the information our customers ask us to process on their behalf. Those are two different roles under the Protection of Personal Information Act, and this policy keeps them apart because your rights differ depending on which one applies to you.

The two roles, and which one applies to you

If you are a Connect24 customer, we are the responsible party for the information we hold about you and your account. This policy describes what we do with it.

If you received a message sent through Connect24, we are only the operator. The business that sent it is the responsible party — they chose to contact you, they hold your details, and they decide what happens to them. We process your information solely on their instruction. If you want your information corrected or deleted, that request goes to them, and we will help you identify who they are if you ask us. Your opt-out, however, we honour immediately and permanently, and it cannot be undone by the sender.

What we collect about customers

  • Account details — name, email address, password (stored only as a hash), business name and physical address.
  • Usage and billing — messages sent, delivery outcomes, what each cost, and every movement of your credit balance.
  • Technical records — IP addresses, timestamps and request logs, kept to investigate faults and abuse.
  • Connected accounts — access and refresh tokens for social accounts you connect, held encrypted and used only to read comments and reply as you instructed. You can disconnect at any time, which revokes them.

What we process on our customers’ behalf

  • Recipient email addresses and phone numbers, and the contact details our customers upload.
  • The content of messages sent, and replies where a conversation exists.
  • Delivery events reported by providers — delivered, bounced, complained, opened where measured.
  • Consent records: what a person agreed to, when, and where the contact details came from.

We do not use any of this for our own purposes. We do not sell it, we do not use it to build profiles, and we do not use one customer’s recipients to market to anyone.

Why we may hold it

We process customer information to provide the service and because it is necessary to perform our contract with you; to comply with legal obligations including tax and record keeping; and for our legitimate interest in keeping the platform secure and its delivery reputation intact. We process recipient information only under our customers’ instructions, as their operator.

Where it is kept, and who else sees it

Connect24 runs on Microsoft Azure and delivers messages through Amazon Web Services. Some personal information is therefore stored and processed outside South Africa, including in the European Union. Section 72 of POPIA permits this where the receiving country or the recipient is bound by comparable protection; both providers are contractually bound to standards at least equivalent to POPIA’s.

Beyond those infrastructure and delivery providers, we share personal information only where the law requires it, or where a regulator or network operator investigating a complaint requires it.

How long we keep it

  • Account records — while the account is open, and for five years afterwards where tax and company law require.
  • Message content and delivery events — as long as the account holds them, so a customer can answer a dispute about what was sent.
  • Suppressions and opt-outsindefinitely. Deleting an opt-out record would mean losing the fact that someone said no, so these outlive the campaigns and lists they came from, deliberately.
  • Technical logs — a limited period sufficient to investigate faults and abuse.

Security

Passwords are stored hashed and never in a form we can read. Sessions are short-lived and renewed rather than long-lived. API keys are stored hashed — we can show you a key once, when it is created, and never again. Access tokens for connected accounts are encrypted. Access to production data is limited to those who need it.

If a breach occurs that creates a real risk to your information, we will notify you and the Information Regulator as POPIA requires.

Your rights

Under POPIA you may:

  • ask what personal information we hold about you, and be given a copy;
  • ask us to correct information that is wrong, or complete information that is missing;
  • ask us to delete information we no longer have grounds to keep;
  • object to processing, and withdraw consent you previously gave;
  • complain to the Information Regulator.

Requests go to privacy@connect24.co.za and we answer within the period POPIA allows. Where you are a recipient rather than a customer, most of these requests belong with the business that messaged you, and we will tell you who that is.

Cookies

The portal stores your session in your browser so that you stay signed in, and remembers small preferences such as which tab you last had open. We do not use advertising cookies and we do not track you across other websites.

Complaints

If you are unhappy with how we have handled your information, tell us first at privacy@connect24.co.za. You may also complain directly to the Information Regulator of South Africa at inforegulator.org.za.