Data Processing & POPIA
Last updated: August 2026
These policies are published by Triligy Systems and apply to all Triligy services. They are general terms, not legal advice, and do not replace a signed order form, statement of work or Data Processing Agreement, which prevail where they conflict.
1. Roles
When operating an assistant, website or ad account for a client, the client is the Responsible Party (POPIA) / Data Controller (GDPR). Triligy is the Operator / Data Processor and acts only on the client's documented instructions, unless required otherwise by law.
2. Scope of processing
- Subject matter: delivery of AI voice assistant, website and advertising services.
- Duration: for the term of the subscription plus the agreed deletion window.
- Categories of data subject: callers, website visitors, enquirers and client personnel.
- Categories of data: contact details, call audio, transcripts, summaries, booking and enquiry records, technical and log data.
3. Posture
Triligy maintains a GDPR- and POPIA-aligned posture. This page sets out the practices we apply. It is a summary and not a substitute for a signed Data Processing Agreement (DPA), which is provided with the order form on request. Where a signed DPA exists, it prevails over this page.
4. Security measures
- Encryption of data in transit (TLS) and at rest.
- Role-based access controls, scoped on a least-privilege basis.
- Audit logging on administrative actions.
- Backup, recovery and documented incident-response procedures.
- Confidentiality obligations on all personnel with access.
Measures may be updated over time provided the overall level of security is not reduced.
5. Sub-processors
We use vetted infrastructure, telephony, speech, AI and integration providers to deliver the service. A current list, including provider name, role and hosting region, is provided on request. We give reasonable advance notice of new sub-processors, and clients may object on reasonable data-protection grounds — in which case we will propose an alternative or the client may terminate the affected service without penalty. Sub-processors are bound to equivalent obligations.
6. Retention and deletion
Retention windows for recordings, transcripts, notes and enquiry records are configurable per client. On termination, data is exported on request and then deleted according to the agreed schedule, except where retention is required by law.
7. Assistance, requests and audits
We will assist the client, at the client's cost where the effort is material, with data-subject requests, impact assessments and regulator engagement. We will make available the information reasonably necessary to demonstrate compliance, and will support audits no more than once per year (or after a material incident) on reasonable notice and under confidentiality.
8. Incident notification
We will notify the client without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a personal-information breach affecting their data, and will provide the information reasonably available to support the client's own notification duties.
9. International transfers
Where personal information is transferred across borders, we rely on recognised lawful mechanisms (such as Standard Contractual Clauses or an equivalent safeguard), documented in the DPA.
10. AI model use
Client call content is not used to train third-party foundation models without explicit written consent. We select providers offering no-training or zero-retention options where reasonably available.
11. Contact
Privacy enquiries: privacy@triligysystems.com