Privacy Policy
Last updated: August 2026
These policies are published by Triligy Systems and apply to all Triligy services. They are general terms, not legal advice, and do not replace a signed order form, statement of work or Data Processing Agreement, which prevail where they conflict.
1. Who we are
Triligy Systems ("Triligy", "we", "us") provides AI voice-assistant, website and paid advertising services to businesses. This policy explains how we handle personal information processed through our website and through services we operate on behalf of our clients.
For our own website and enquiries we act as Responsible Party (Controller). For assistants, websites and ad accounts we operate for a client, that client is the Responsible Party and we act as Operator/Processor on their documented instructions — see Data Processing & POPIA.
2. What we collect
- Contact details you submit via forms (name, business, phone, email, message).
- Call audio, transcripts, summaries and call metadata generated by assistants we operate for clients.
- Booking, enquiry and CRM records created by the assistant on a client's behalf.
- Standard server and security logs (IP address, timestamps, user agent).
- Website analytics and marketing-attribution data (see section 8).
- Billing information required to invoice clients. We do not store full card numbers.
3. How we use it
- To respond to demo requests, quote, and run discovery conversations.
- To deliver, configure, monitor, support and secure the services we provide.
- To detect and prevent fraud, abuse and security incidents.
- To meet legal, tax, accounting and record-keeping obligations.
- To send service updates and, where permitted or consented to, relevant marketing. You can opt out at any time.
We do not sell personal information. We do not use client call data to train third-party foundation models without explicit written consent.
4. Lawful basis
We rely on legitimate interest for website enquiries, service security and business administration; contract performance for client services; legal obligation for tax and record-keeping; and consent where required (for example, certain marketing communications and call recording).
5. Sharing and sub-processors
We share personal information only with vetted providers who need it to deliver the service — including hosting and database providers, telephony, speech and AI model providers, CRM and calendar platforms you ask us to integrate, email and analytics providers, advertising platforms, and our professional advisers. We may also disclose information where required by law or to protect our legal rights. A current sub-processor list is available on request and maintained via the Data Processing page.
6. International transfers
Some providers process data outside South Africa or the EEA. Where this happens we rely on recognised lawful transfer mechanisms (such as Standard Contractual Clauses or an equivalent safeguard) and document this in the Data Processing Agreement.
7. Storage, retention and deletion
Personal information is encrypted in transit and at rest. Retention windows are configurable per client and documented in the order form. Website enquiry data is retained for up to twenty-four (24) months from last contact unless you ask us to delete it sooner. Records we must keep for tax or legal reasons are retained for the statutory period. Request export or deletion by emailing privacy@triligysystems.com.
8. Cookies, analytics and advertising tags
Our website uses strictly necessary cookies to function, and may use analytics, visitor-identification and advertising tags (for example Google, Meta and lead-attribution scripts) to understand traffic and measure campaigns. These may set cookies or similar identifiers and may share limited technical data with those providers under their own privacy policies. You can block or delete cookies in your browser settings; some features may then not work as intended.
9. Security
We apply role-based access control, encryption, audit logging, least-privilege administration, backups and incident-response procedures. No system can be guaranteed completely secure. If a breach affecting your personal information occurs, we will notify affected parties and the relevant regulator as required by law and without undue delay.
10. Children
Our services are for businesses and are not directed at children. We do not knowingly collect personal information from children. If you believe a child's information has been submitted to us, contact us and we will delete it.
11. Your rights
Depending on your jurisdiction (including under GDPR and POPIA), you may have rights to access, correct, delete, restrict, object to, or port your personal information, and to withdraw consent. Contact us at the address below to exercise these rights. We may need to verify your identity first.
Where the personal information relates to a call handled by an assistant we operate for a client, we will route your request to that client as the Responsible Party and support them in responding.
12. Complaints
If you are unhappy with how we handle your information, contact us first. You also have the right to complain to a supervisory authority — in South Africa, the Information Regulator; in the EU/UK, your local data protection authority.
13. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with a revised "last updated" date.
14. Contact
Triligy Systems · privacy@triligysystems.com