Privacy Policy & Data Sovereignty Framework
Table of Contents
Introduction & Scope
IntelliAI Group (Pty) Ltd ("IntelliAI Group", "we", "us", "our") is committed to protecting the privacy and data sovereignty of all individuals and enterprises that interact with our sovereign AI platform, the Solomon Execution Engine (SEE). This Privacy Policy (the "Policy") sets out the basis on which any personal information we collect from you, or that you provide to us, will be processed, stored, shared, and protected.
This Policy applies to all users of the IntelliAI Group platform, including enterprise operators, division administrators, API consumers, and visitors to our website at https://intelliaigroup.co.za (the "Platform"). It covers all nine operational divisions: IntelliTax SA, IntelliLegal AI, IntelliFinance AI, IntelliSupply AI, Kalahari Mineral Dynamics, IntelliProperty AI, IntelliHealth AI, CreditorFlow AI, and Platform Governance.
This Policy is designed to comply with the Protection of Personal Information Act, 2013 (POPIA) of the Republic of South Africa, and incorporates principles from the General Data Protection Regulation (GDPR) of the European Union where they provide enhanced protections for data subjects. The Policy is enforced through the SEE Constitutional Governance Framework, specifically Constitutional Rules R4 (Temporal Binding), R6 (No Forgetting), R7 (Rights Guard), and R8 (Transparency).
Constitutional Foundation: This Privacy Policy is a direct expression of SEE Constitutional Rule R7 (Rights Guard), which mandates automated enforcement of data subject rights under POPIA. All data processing operations on the Platform are bound by this Policy and auditable under R8 (Transparency).
Data Controller Identification
IntelliAI Group (Pty) Ltd is the responsible data controller for all personal information processed through the Solomon Execution Engine (SEE) and its operational divisions. As the data controller, we determine the purposes and means of processing personal information and are accountable for compliance with POPIA and this Policy.
- Registered Name: IntelliAI Group (Pty) Ltd
- Registration Number: 2026/429045/07
- Registered Address: 8431 Ketting Road, Devland Ext 36, Johannesburg, Gauteng, 1811, South Africa
- Physical Address: 14th Floor, The Marc, 129 Rivonia Rd, Sandton, 2196, Gauteng, South Africa
- Email: dso@intelliaigroup.co.za (Data Sovereignty Office)
- Telephone: +27 66 148 3731
The Data Sovereignty Officer (DSO) is responsible for overseeing compliance with POPIA and this Policy. The DSO operates independently within the Platform Governance division and reports directly to the Office of the CEO. All data protection inquiries should be directed to the DSO at dso@intelliaigroup.co.za.
Information We Collect
We collect only data that is necessary for Platform operation and workload execution. Our data collection is governed by the principle of data minimization under POPIA Section 10, and we implement a zero-retention-by-default architecture where data is automatically deleted once the lawful processing purpose is fulfilled.
3.1 Information You Provide Directly
- Operator Account Information: Full legal name, enterprise email address, phone number, role title, division assignment, and company name. This information is collected during the account registration process and is necessary for identity verification under R5 Verification Gate protocols.
- Authentication Credentials: Hashed passwords (salted SHA-256 with bcrypt rounds), multi-factor authentication tokens, SAML assertions, and OAuth provider identifiers. We never store plain-text passwords.
- Profile Information: Optional profile details including biography, professional certifications, division preferences, and notification settings.
- Communications Data: Support tickets, inquiry forms, correspondence with our team, and voluntary feedback submissions.
- Workload Data: Data submitted for processing through the SEE engine, which varies by division. Workload data is governed by division-specific Data Processing Addenda (DPAs) and is subject to the same privacy protections outlined in this Policy.
3.2 Information Collected Automatically
- System Telemetry: IP addresses, browser type and version, device fingerprints, operating system, session duration, and page interaction data. This data is collected for security monitoring and platform optimization.
- Usage Analytics: Workload execution metrics, API call patterns, feature usage statistics, and performance data. All analytics data is anonymized at the point of collection.
- Log Data: Access logs, audit trails, and operational logs maintained under R6 (No Forgetting) for security and compliance purposes.
3.3 Information We Do NOT Collect
We do not collect sensitive personal information (as defined in POPIA Section 26) beyond what is strictly required for specific authorized workloads processed through designated divisions. For example, health records processed through IntelliHealth AI are subject to strict POPIA Section 26 safeguards, including explicit consent and purpose limitation. We do not collect or process:
- Biometric data for purposes other than authentication (fingerprint, facial recognition)
- Political opinions, religious beliefs, or trade union membership
- Genetic data or criminal records (except where authorized by law and processed through IntelliLegal AI)
- Children's data without verified parental consent (see Section 13)
Lawful Processing Bases
All data processing conducted through the IntelliAI Group Platform is performed under one or more lawful bases as defined by POPIA Section 11:
- (a) Consent of the Data Subject: Obtained at account registration and for each workload submission. Consent is specific, informed, and freely given. Data subjects may withdraw consent at any time through the Sovereignty Controls panel.
- (b) Performance of a Contract: Processing necessary for the performance of the Platform Subscription Agreement between the operator and IntelliAI Group, including workload execution, billing, and technical support.
- (c) Compliance with Legal Obligations: Processing required to comply with applicable laws and regulations, including SARS tax regulations (IntelliTax SA), FSCA financial reporting (IntelliFinance AI), HPCSA health data requirements (IntelliHealth AI), and DMRE mining regulations (Kalahari Mineral Dynamics).
- (d) Legitimate Interests: Processing necessary for the legitimate interests of IntelliAI Group or the data subject, including security monitoring, fraud prevention, and platform improvement, provided such interests are not overridden by the data subject's privacy rights.
- (e) Public Law Duty: Processing necessary for the performance of a public law duty by a public body, where IntelliAI Group acts as a data processor for government entities.
We maintain a Register of Processing Activities (ROPA) that documents the lawful basis for each processing activity. This register is available for inspection by the Information Regulator (South Africa) upon request.
Purpose of Processing
We process personal information for the following purposes, each mapped to a specific lawful basis and constitutional rule:
- Platform Operation & Workload Execution: To provision operator accounts, authenticate access through R5 Verification Gate, route workloads to appropriate divisions under R3 Division-Aware Routing, and execute processing requests. Lawful basis: Contract performance (POPIA Section 11(1)(b)).
- Security & Compliance: To monitor platform security, detect and prevent unauthorized access, maintain audit trails under R6 No Forgetting, and comply with SOC 2 Type II control objectives. Lawful basis: Legitimate interests (POPIA Section 11(1)(f)).
- Communication & Support: To respond to inquiries, provide technical support, send platform notifications, and deliver service-related communications. Lawful basis: Contract performance and consent.
- Billing & Account Management: To process subscription payments, generate invoices, manage usage-based billing, and maintain account records. Lawful basis: Contract performance and legal obligations.
- Product Improvement: To analyze anonymized usage patterns, identify platform enhancements, and develop new features. All data used for this purpose is aggregated and de-identified. Lawful basis: Legitimate interests.
- Legal & Regulatory Compliance: To comply with POPIA, tax laws, financial regulations, health data requirements, and other applicable legal obligations. Lawful basis: Legal obligations (POPIA Section 11(1)(c)).
We do not process personal information for purposes incompatible with those for which it was collected, unless we have obtained your consent or are required by law.
Data Storage & Retention
IntelliAI Group implements a zero-retention-by-default architecture under Constitutional Rule R4 (Temporal Binding). Data is retained only for as long as necessary to fulfill the purpose for which it was collected, in accordance with applicable legal requirements:
- Operator Account Data: Retained for the duration of the subscription plus 12 months following account closure or termination, to allow for data portability requests and regulatory inquiries.
- Tax Records (IntelliTax SA): 5 years from the date of submission, as required by the South African Revenue Service (SARS) under the Tax Administration Act, 2011.
- Health Records (IntelliHealth AI): 6 years from the date of last processing, in accordance with HPCSA guidelines and the National Health Act, 2003.
- Financial Records (IntelliFinance AI): 5 years under the Companies Act, 2008 and Financial Advisory and Intermediary Services Act, 2002.
- Legal Documents (IntelliLegal AI): 5 years post-matter closure, or longer where required by a court order or legal hold notice.
- Platform Telemetry: 2 years for operational analysis and security monitoring, after which data is anonymized or securely destroyed.
- Communications & Support Tickets: 3 years from the date of resolution, unless otherwise required for legal proceedings.
Upon expiration of the applicable retention period, data is securely destroyed under POPIA Section 28 with verified destruction certificates. Destruction methods include cryptographic erasure (for encrypted data) and physical shredding (for hardware). The R5 Verification Gate logs all destruction events in the immutable audit trail maintained under R6 No Forgetting.
Zero-Retention-by-Default: Our default architecture automatically deletes data once the lawful processing purpose is fulfilled, unless a specific legal retention requirement applies. Operators can configure retention preferences through the Sovereignty Controls panel.
Data Sharing & Disclosure
IntelliAI Group does not sell personal information to third parties. We do not share personal information with third parties for their direct marketing purposes. Data may be shared only in the following circumstances, each governed by a binding data processing agreement that complies with POPIA Section 21:
- Division-Specific Regulatory Authorities: As required by law, we may share data with regulatory bodies including SARS (tax data), FSCA (financial data), HPCSA (health data), DMRE (mining data), and the Companies and Intellectual Property Commission (CIPC). All such disclosures are logged under R6 No Forgetting.
- Trusted Third-Party Service Providers: We engage carefully vetted third-party processors who process data on our behalf under binding data processing agreements. These include cloud infrastructure providers (South African-hosted), identity verification services, monitoring tools, and email delivery services. All processors are subject to:
- POPIA-compliant data processing agreements with mandatory R5 Verification Gate auditing
- Data localization requirements (all primary data remains within South Africa)
- Annual SOC 2 Type II certification requirements
- Right of audit and inspection by IntelliAI Group
- Law Enforcement Agencies: We may disclose personal information to law enforcement agencies pursuant to a valid court order, warrant, or subpoena issued by a South African court. We will notify affected operators of such disclosures where legally permitted.
- Corporate Transactions: In the event of a merger, acquisition, or sale of assets, personal information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this Policy. Operators will be notified of any such transfer.
A current list of sub-processors is maintained by the Data Sovereignty Office and is available upon request. Operators will be notified 30 days in advance of any new sub-processor engagement.
International Data Transfers
Under POPIA Section 72, personal information processed by IntelliAI Group may not be transferred outside the Republic of South Africa unless the recipient country ensures an adequate level of protection for personal information. Our data sovereignty architecture is designed to ensure that:
- Primary Data Processing: All primary data processing occurs within our Johannesburg Sovereign HPC Cluster, located at a Tier III-equivalent data center in Gauteng, South Africa. Data never leaves South African jurisdiction during primary processing.
- Limited Exceptions: Limited technical data (anonymized telemetry, aggregated error logs without personal identifiers) may be processed in jurisdictions with equivalent data protection laws, including the European Union (GDPR adequacy decision) and the United Kingdom (UK GDPR adequacy regulations).
- Cross-Border Workloads: For enterprise customers operating across SADC borders, workload data may be processed through division-specific nodes located in Namibia, Botswana, and Mozambique. Each node operates under a binding intra-group data transfer agreement that incorporates standard contractual clauses approved by the Information Regulator.
- Explicit Consent: Any cross-border transfer of personal information requires explicit Operator consent and R5 Verification Gate approval. Operators can restrict cross-border processing through the Sovereignty Controls panel.
Data Sovereignty Guarantee: As a sovereign AI infrastructure provider, IntelliAI Group guarantees that your data remains under South African jurisdiction and is protected by POPIA. We do not route data through jurisdictions with inadequate data protection frameworks.
Data Subject Rights (POPIA)
Under POPIA Sections 23-26 and 71, data subjects have the following rights regarding their personal information. These rights are enforced automatically through the SEE Constitutional Rule R7 (Rights Guard):
9.1 Right to Confirmation
You have the right to request confirmation from IntelliAI Group as to whether we hold personal information about you. This request can be made through the Sovereignty Controls panel or by contacting the Data Sovereignty Office.
9.2 Right of Access (Subject Access Request)
You have the right to request access to the personal information we hold about you. Subject access requests (SARs) will be processed within 30 calendar days of receipt, as required by POPIA Section 23. We may require verification of identity before processing the request. To submit a SAR, use the Data Subject Access Request form in the Sovereignty Controls panel or email dso@intelliaigroup.co.za.
9.3 Right to Correction
You have the right to request correction of inaccurate or outdated personal information. You can update most information directly through your Operator Profile settings. For corrections requiring verification, contact the Data Sovereignty Office.
9.4 Right to Deletion (Right to Erasure)
You have the right to request deletion of personal information where it is no longer required for the lawful purpose for which it was collected, or where you withdraw consent and no other lawful basis exists. Deletion requests will be processed within 30 days, subject to legal retention requirements. Note that certain data may need to be retained for legal compliance (e.g., tax records, audit logs).
9.5 Right to Object to Processing
You have the right to object to the processing of your personal information for direct marketing purposes. You may also object to processing based on legitimate interests, providing grounds relating to your particular situation. Objections can be registered through the Sovereignty Controls panel.
9.6 Right to Data Portability
You have the right to receive your personal information in a structured, commonly used, machine-readable format and to transmit that data to another data controller. Data portability requests are processed within 30 days.
9.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. Consent can be managed through the Sovereignty Controls panel.
9.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Regulator (South Africa) if you believe that we have violated your rights under POPIA. See Section 16 for contact details.
Automated Rights Enforcement: All data subject rights are enforced through the R7 (Rights Guard) constitutional rule, which automatically processes rights requests within statutory timeframes. The Rights Guard operates independently of human operators to ensure impartiality and timeliness.
Security Measures
IntelliAI Group implements comprehensive technical and organizational security measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures are verified annually through SOC 2 Type II audits and are enforced through the SEE Constitutional Framework:
10.1 Technical Security Measures
- Encryption at Rest: AES-256-GCM encryption for all data at rest, with hardware security module (HSM) key management. Encryption keys are rotated every 90 days.
- Encryption in Transit: TLS 1.3 for all data in transit across internal and external networks. Certificate pinning and HSTS enforcement.
- Access Controls: Biometric and hardware security key access controls at Tier III-equivalent data centers. Role-based access control (RBAC) with principle of least privilege for all platform operators.
- Network Security: Micro-segmentation, intrusion detection/prevention systems (IDS/IPS), Web Application Firewall (WAF), and DDoS protection.
- Authentication: Mandatory multi-factor authentication (MFA) for all operator accounts. Support for TOTP, FIDO2/WebAuthn hardware security keys, and biometric authentication.
- Audit Logging: Immutable audit trails maintained under R6 No Forgetting with tamper-evident distributed ledger technology.
10.2 Organizational Security Measures
- Constitutional Governance: All security controls are enforced through the SEE Constitutional Framework (R1-R8), which operates at the engine level rather than as policy documents.
- Security Awareness: Mandatory security awareness training for all employees and contractors, with quarterly phishing simulations and annualSOC 2 Type II audits.
- Vendor Risk Management: All third-party processors undergo security assessments, including SOC 2 review and R5 Gate compliance verification.
- Incident Response: 24/7 security operations center (SOC) with automated incident detection, response, and escalation procedures.
- Data Protection Impact Assessments (DPIA): Conducted for all new processing activities that may result in high risk to data subjects.
Our security program is independently verified through annual SOC 2 Type II audits conducted by AICPA-accredited auditors. The most recent audit (June 2026) confirmed 100% compliance across 312 control objectives with zero exceptions.
Cookie Policy
IntelliAI Group uses cookies and similar tracking technologies to enhance platform functionality, improve user experience, and support security monitoring. This section explains what cookies we use, why we use them, and how you can control them.
11.1 Types of Cookies We Use
- Essential Cookies (Strictly Necessary): Required for the platform to function. These include session cookies for authentication, load balancing cookies, and security cookies. Lawful basis: Legitimate interests (platform operation). No consent required.
- Functional Cookies: Enable enhanced functionality and personalization, such as remembering your division preferences and language settings. Lawful basis: Consent (POPIA Section 11(1)(a)).
- Analytics Cookies: Collect anonymized data about how users interact with the platform, including page visits, feature usage, and error rates. We use first-party analytics only. Lawful basis: Consent.
- Security Cookies: Used for threat detection, fraud prevention, and R5 Verification Gate monitoring. These cookies are essential for platform security. Lawful basis: Legitimate interests.
11.2 Cookie Management
When you first visit our platform, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You can change your cookie preferences at any time through the Sovereignty Controls panel. Essential cookies cannot be disabled as they are necessary for platform operation.
Most web browsers also allow you to control cookies through browser settings. Please note that disabling certain cookies may affect platform functionality and user experience.
11.3 Third-Party Cookies
We do not use third-party advertising cookies or social media tracking cookies. Our platform uses only first-party cookies, and we do not allow third-party cookies to be placed on our domain.
Breach Notification
In the event of a personal information breach (as defined in POPIA Section 1), IntelliAI Group has implemented a comprehensive breach response protocol governed by Constitutional Rule R5 (Verification Gate) and R6 (No Forgetting):
- Detection & Assessment: Automated breach detection through R5 Gate monitoring, with initial assessment completed within 1 hour of detection.
- Containment: Immediate containment measures activated within 2 hours, including isolation of affected systems and suspension of compromised access credentials.
- Regulator Notification: Notification to the Information Regulator (South Africa) within 72 hours of breach confirmation, as required by POPIA Section 22. The notification includes a description of the breach, categories of data affected, number of data subjects affected, and containment measures implemented.
- Data Subject Notification: Affected data subjects will be notified within 48 hours of regulator notification, including a description of the breach, categories of personal information affected, recommended mitigation steps, and contact information for the Data Sovereignty Office.
- Investigation & Remediation: Full investigation conducted under R5 Verification Gate with findings documented in the immutable audit trail under R6 No Forgetting. Remediation measures implemented within 30 days.
Our breach notification protocol is tested quarterly through tabletop exercises and integrated into our annual SOC 2 Type II audit scope.
Children's Privacy
IntelliAI Group is an enterprise platform designed for commercial use by organizations and their authorized representatives. The platform is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18 without verified parental or guardian consent.
If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact the Data Sovereignty Office immediately. We will take steps to delete that information within 48 hours of receiving your request and verifying your identity.
Where IntelliAI Group processes personal information of children under 18 as part of an authorized enterprise workload (e.g., educational records processed through IntelliLegal AI or health records processed through IntelliHealth AI), such processing is governed by:
- Explicit consent from a competent person (parent, guardian, or authorized representative) as required by POPIA Section 35
- Strict purpose limitation and data minimization
- Enhanced security measures proportional to the sensitivity of the data
Changes to This Policy
IntelliAI Group reserves the right to update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or constitutional governance framework. Material changes will be notified through:
- Platform notification banner visible on all pages for at least 30 days before the changes take effect
- Email notification to all active operator accounts at least 30 days before the changes take effect
- Version history maintained in the footer of this page with a changelog
We encourage operators and data subjects to review this Policy periodically. Continued use of the Platform after the effective date of changes constitutes acceptance of the updated Policy. If you do not agree with the changes, you may close your account and request deletion of your personal information as outlined in Section 9.
Version History
- Version 2.1 (Current): Effective 1 June 2026. Updated sub-processor list, enhanced cookie policy, clarified international transfer safeguards, and added automated R7 Rights Guard enforcement details.
- Version 2.0: Effective 1 January 2026. Comprehensive rewrite to align with SEE Constitutional Governance Framework v2.0. Added R4-R8 constitutional mapping.
- Version 1.0: Effective 30 May 2025. Initial privacy policy published at platform launch.
Contact Data Protection Officer (DPO)
The Data Sovereignty Officer (DSO) oversees POPIA compliance and data protection for IntelliAI Group. The DSO operates independently within the Platform Governance division and reports directly to the Office of the CEO.
Data Sovereignty Officer
IntelliAI Group Data Sovereignty Office
Physical Address
14th Floor, The Marc,
129 Rivonia Rd, Sandton,
2196, Gauteng, South Africa
Response Time
72 hours (initial acknowledgment)
30 days (full response)
Telephone
Operating Hours
08:00 - 17:00 SAST, Monday - Friday
For general privacy inquiries, data subject access requests, or questions about this Policy, please contact the Data Sovereignty Office using the details above. All inquiries will be acknowledged within 72 hours and fully responded to within 30 calendar days.
Complaints & Regulatory Authority
If you are not satisfied with our response to a privacy-related inquiry or believe that we have violated your rights under POPIA, you have the right to lodge a complaint with the Information Regulator (South Africa). The Regulator is the statutory body responsible for enforcing POPIA and protecting data subject rights.
Regulatory Authority
Information Regulator (South Africa)
Website
Physical Address
JD House, 27 Stiemens St,
Braamfontein, Johannesburg,
2001, South Africa
We encourage you to contact our Data Sovereignty Office first so that we can address any concerns directly. However, you are entitled to lodge a complaint with the Information Regulator at any time without first contacting us.
Governance: This Privacy Policy is governed by the laws of the Republic of South Africa. Any disputes arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the courts of South Africa. This Policy is a living document maintained under SEE Constitutional Rule R8 (Transparency) and is subject to regular review and improvement.
Subscribe to Intelligence Briefings
Receive weekly telemetry reports and constitutional governance updates from the SEE.