Privacy Policy
Last Updated: September 3, 2026
This policy explains what information QAI collects, why we collect it, and the choices and rights you have. We have tried to write it so you can actually read it.
1. Who We Are and What This Policy Covers
1.1 Who We Are
QASSETI (Pty) Ltd ("QAI", "we", "us") is a South African company that provides an asset management, maintenance, and inspection platform available at qasseti.com and through our mobile applications (together, the "Services"). This policy explains how we handle personal information when you visit our website, create an account, or use the Services.
1.2 Two Roles, Two Responsibilities
We handle data in two distinct capacities. For your account information, billing details, and website activity, QAI decides how and why the data is processed — under South Africa’s Protection of Personal Information Act (POPIA) we are the "responsible party" (a "controller" under GDPR). For the data your organisation puts into its QAI workspace — assets, work orders, inspections, photos, team members — your organisation decides how that data is used, and we process it only on its instructions as an "operator" (a "processor" under GDPR).
1.3 Data Your Organisation Controls
If you use QAI as a member of an organisation’s workspace, your administrator controls that workspace and its contents, including data about you within it. Requests to access, correct, or delete data inside a workspace should go to your administrator first; we will support them in fulfilling those requests. This policy governs everything else.
2. Information We Collect
2.1 Information You Give Us
When you create an account, request a demo, subscribe, or contact us, we collect information such as your name, work email address, company name, phone number, and role. Payment card details are collected and processed by our payment processor — we do not store full card numbers on our systems.
2.2 Workspace Content
When your organisation uses the Services, its workspace contains the content it chooses to add: asset records, work orders, inspection checklists and results, meter readings, maintenance history, documents, photos, QR code scans, technician activity, and location data captured during field work (where enabled). We process this content to run the Services, as described in section 1.2.
2.3 Information Collected Automatically
When you use the website or Services we automatically collect technical data: IP address, browser and device type, operating system, pages viewed, referring URLs, timestamps, and interaction events. We use this to keep the Services secure, diagnose problems, and understand how features are used.
2.4 Mobile App Data
Our mobile apps request permissions only where a feature needs them: camera access for photo capture and QR scanning, GPS location for geotagging field work (with your permission), and local storage for offline mode, which keeps data on your device and syncs it when connectivity returns. You can revoke these permissions in your device settings at any time.
2.5 Business Contact Information from Other Sources
If you are not yet a customer, we may obtain limited business contact information about you (such as your name, role, company, and work email) from public sources like your company website or professional profiles, and use it to contact you about QAI where the law permits. You can opt out at any time, and we honour every opt-out.
2.6 Sensitive Information
We do not ask for, and the Services do not require, special categories of personal information — such as health data, biometric data, government ID numbers, or information about race, religion, or political views. Please do not upload such information to the Services.
2.7 Aggregated and De-Identified Data
We may create aggregated or de-identified data (for example, feature usage statistics across all customers) that can no longer be linked to you or your organisation. We use this to improve the Services and may use it for benchmarking and analytics. We do not attempt to re-identify de-identified data.
3. How We Use Information and Our Lawful Bases
3.1 Providing the Services
We use your information to operate, maintain, and improve QAI: authenticating you, syncing your data across devices, generating reports, sending service notifications, processing payments, and providing support. Lawful basis: performance of our contract with you or your organisation.
3.2 Communication
We send service-related messages (security alerts, billing notices, changes to the Services) that are necessary to your use of QAI, and — separately — product news and marketing you can opt out of at any time. Lawful basis: contract performance for service messages; consent or legitimate interest, as applicable, for marketing.
3.3 Improving and Securing the Services
We analyse usage patterns to find bugs, prioritise features, and detect fraud, abuse, and security incidents. Lawful basis: our legitimate interest in providing a secure, reliable product.
3.4 Legal Compliance
We process information where necessary to comply with applicable law, respond to lawful requests from authorities, enforce our Terms of Service, and establish or defend legal claims. Lawful basis: legal obligation and legitimate interest.
4. AI Features
4.1 What Our AI Features Do
QAI includes AI-assisted features such as generating checklists from photos or text, extracting data from PDF documents, and answering questions from your uploaded manuals and SOPs. When you use these features, the content you submit (for example, a photo or document) is processed to generate the output you requested.
4.2 Third-Party AI Providers
AI features are powered by third-party AI model providers acting as our service providers. Content submitted to AI features is processed under agreements that restrict the provider from using your content to train their general-purpose models.
4.3 Your Choice
AI features only process content when you actively use them — we do not run AI over your workspace in the background. If you prefer not to have particular content processed by AI features, simply don’t use those features with that content.
6. Cookies and Analytics
6.1 Cookies We Use
We use essential cookies for sign-in and security, preference cookies to remember settings like language, and analytics cookies to understand how the website is used. Where consent is required for non-essential cookies, we ask for it. Our Cookie Policy, available on our website, lists every cookie category and third-party provider we use.
6.2 Managing Cookies
You can control or delete cookies through your browser settings. Blocking essential cookies may prevent sign-in and other core functionality from working.
6.3 App Stores and External Links
If you install our mobile apps, the app store you use (Apple App Store or Google Play) collects its own data about the download and your device under its own privacy policy — we do not control that collection. Likewise, our website may link to external sites we do not operate; their privacy practices are their own.
7. How We Protect Your Data
7.1 Security Measures
We protect data with encryption in transit (TLS) and at rest, role-based access controls, authentication requirements for all system access, audit logging, and automated backups. Our staff access customer data only when needed to provide support or operate the Services.
7.2 Infrastructure
The Services run on established cloud infrastructure providers with redundancy, monitoring, and physical security controls maintained by those providers.
7.3 Incident Response
If a security compromise affects your personal information, we will notify you and the relevant regulator as required by applicable law — including notification to the Information Regulator and affected data subjects as required by section 22 of POPIA — and act promptly to contain and investigate the incident.
7.4 Your Part
No system is perfectly secure. Use a strong, unique password, enable available security features, and tell us immediately at [email protected] if you suspect unauthorised access to your account.
8. How Long We Keep Data
8.1 Active Accounts
We keep your information for as long as your account is active or as needed to provide the Services to your organisation.
8.2 After Deletion or Termination
When you delete your account, or when a subscription ends, workspace data is retained for 30 days so it can be exported or the account reactivated, and is then deleted from our production systems. Residual copies may persist in encrypted backups for up to 90 days before being overwritten in the normal backup cycle.
8.3 What We Keep Longer
We retain limited records beyond these periods where the law requires it (for example, tax and accounting records) or where reasonably necessary to resolve disputes, enforce agreements, or maintain security logs.
9. International Data Transfers
9.1 Where Data Is Processed
QAI is based in South Africa and our Services are primarily hosted in the European Union. Depending on where you are, your information may therefore be stored and processed outside your own country. Some of our service providers (such as AI model providers and support tooling) may process data in other regions.
9.2 Transfer Safeguards
Where we transfer personal information across borders, we do so in accordance with section 72 of POPIA — ensuring the recipient is subject to laws, binding corporate rules, or contracts that provide substantially similar protection. For data of individuals in the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
10. Your Rights
10.1 Rights Under POPIA
You have the right to know whether we hold personal information about you, to access it, to request correction or deletion of information that is inaccurate, outdated, or unlawfully held, and to object to processing — including objecting to direct marketing at any time. To exercise these rights, contact our Information Officer at [email protected]. We respond within the timeframes POPIA requires.
10.2 Rights in the EEA, UK, and Elsewhere
If the GDPR or similar laws apply to you, you additionally have rights to data portability, to restrict processing, and to withdraw consent where processing is based on consent. We honour these requests regardless of where you are located, to the extent the relevant law applies.
10.3 Exporting Your Data
You can export your workspace data in common formats (CSV, PDF) at any time through the platform, or by asking our support team for a data export.
10.4 How We Handle Requests
Exercising your rights is free of charge, unless a request is clearly unfounded or excessive. To protect your data, we may ask you to verify your identity before we act on a request. We respond within one month, or sooner where the applicable law requires; if a request is complex we will tell you and keep you updated.
10.5 Complaints
If you believe we have processed your personal information unlawfully, you may lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za, or with your local supervisory authority if you are outside South Africa. We would appreciate the chance to address your concern directly first.
11. Children
11.1 Not for Children
QAI is a business tool and is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at [email protected] and we will delete it.
12. Changes to This Policy
We may update this policy as our practices, the Services, or the law change. If a change is material, we will notify you by email or through the Services before it takes effect, and we will always update the "Last Updated" date above.
Continued use of the Services after a change takes effect means the updated policy applies to you.
13. Contact Us
For questions, requests, or complaints about this policy or our data practices, contact us:
QASSETI (Pty) Ltd
Republic of South Africa
Twoje zaufanie jest dla nas ważne
Your asset and inspection data is the core of your operations. We treat it that way. If anything in this policy is unclear, ask us — we will give you a straight answer.