Privacy Policy
Vastrix
Effective date: 16 May 2026
Last updated: 16 May 2026
This Privacy Policy explains how Vastrix ("we", "us", "our") collects, uses, stores, and protects your personal information when you use the Vastrix OPS service via WhatsApp. We are committed to protecting your privacy and complying with the Protection of Personal Information Act, 2013 (POPIA) of South Africa.
1. Who We Are
Vastrix is a partnership owned and operated by Bossman Dapaah and Siya Radebe, based in South Africa.
Business contact: info@vastrix.co.za
For all privacy-related inquiries, data subject requests, or to exercise your rights under POPIA, email info@vastrix.co.za.
2. What Vastrix Does
Vastrix OPS is a WhatsApp-based AI executive assistant that helps business owners and professionals manage their day. Clients send commands or natural-language requests via WhatsApp to a registered Vastrix business number. Vastrix processes those requests using AI models and connected services (email, calendar, contacts, cloud storage) to return summaries, reminders, drafts, task confirmations, meeting bookings, and similar productivity outputs.
3. Information We Collect
3.1 Information you provide directly via WhatsApp:
- Your WhatsApp phone number
- Your WhatsApp display name
- The text content of every message you send to Vastrix
- Voice notes you send
- Documents you send (PDFs, Word documents, images, other files)
3.2 Information accessed via integrations you authorize:
- Google Gmail — email subjects, senders, recipients, message content, attachments, thread metadata
- Google Calendar — event titles, dates, times, attendees, locations, descriptions
- Google Contacts — contact names, email addresses, phone numbers, organization names
- Google Drive — files you save via the Vastrix "save attachments" feature
3.3 Operational and usage data:
- Counters of how often you use each Vastrix feature
- Logs of commands and replies for service operation and troubleshooting
- Pending action records (draft emails, pending tasks, pending bookings)
3.4 Information collected for billing:
- Information shared during onboarding calls, emails, and contracts confirming your subscription (name, business name, billing details, payment confirmation)
- We do not store credit card or bank account details within Vastrix systems. Payment is handled via direct email and contract outside the WhatsApp service.
3.5 What we do not collect:
- Location data
- Other apps on your device
- WhatsApp messages from people other than Vastrix
- Biometric data
- Data from anyone under 18
4. How We Use Your Information
4.1 Service delivery:
- Processing the commands you send and returning AI-generated replies
- Reading your email, calendar, contacts, and Drive only at the moment you request an action that requires it
- Storing your tasks, reminders, drafts, and bookings so you can manage them across days
- Tracking your monthly usage against your subscription tier limits
4.2 Service improvement:
- Aggregated, anonymized usage analytics
- Debugging when something goes wrong
4.3 Communication:
- Sending the AI replies and confirmations you request via WhatsApp
- Reminders you have explicitly set
- Daily morning briefings (if your subscription tier includes them and you have configured a briefing time)
We do not use your data for advertising. We do not sell your data to third parties. We do not use your data to train AI models.
5. Legal Basis for Processing (POPIA)
We process your personal information on the following legal grounds:
- Performance of contract — to deliver the service you subscribed to
- Your consent — for optional integrations (Gmail, Calendar, Contacts, Drive)
- Legitimate interest — for service improvement, security, and fraud prevention
- Legal obligation — for tax and accounting record-keeping
6. Third Parties We Share Data With
We share the minimum necessary data with the following processors strictly to operate the service. We do not sell your data.
- Meta Platforms — to send and receive WhatsApp messages
- Anthropic — to process AI requests using the Claude model
- OpenAI — to transcribe voice notes via the Whisper model
- Google — Gmail, Calendar, Contacts, Drive, Gemini AI when you authorize these
- Notion — to store your tasks, reminders, drafts, contacts, and usage logs
- n8n — to run the workflow automation that connects everything
Each processor has its own privacy policy. We have configured them to access only the data necessary for the requested feature.
7. International Data Transfers
Some processors listed in Section 6 are based outside South Africa, primarily in the United States and European Union. Your data may be transferred internationally. These transfers comply with POPIA Section 72. By using Vastrix you consent to these international transfers.
8. Data Retention
We retain your data for:
- Conversation logs, tasks, reminders, drafts, bookings — for the duration of your active subscription plus one month thereafter
- Billing records — seven years, as required by South African tax law
- Aggregated, anonymized usage analytics — indefinitely
You may request earlier deletion at any time by emailing info@vastrix.co.za. See Section 9.
9. Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Be notified that we are collecting your data (this policy)
- Access your personal information we hold
- Request correction or deletion of your personal information
- Object to processing of your personal information
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, email info@vastrix.co.za. We will respond within 30 days. For account deletion specifically, see our User Data Deletion page.
You may also lodge complaints with: Information Regulator, JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001. POPIAComplaints@inforegulator.org.za.
10. How We Protect Your Data
- All data in transit is encrypted via TLS/HTTPS
- API tokens and credentials are stored encrypted in n8n
- Access to Vastrix systems is restricted to the two partners
- Notion workspace access is restricted via OAuth integration
- We follow industry-standard security practices
No system is 100% secure. If a data breach affecting your personal information occurs, we will notify you and the Information Regulator within 72 hours, as required by POPIA.
11. Children's Privacy
Vastrix is intended only for users 18 years and older. We do not knowingly collect data from minors. If you believe a minor has registered, email info@vastrix.co.za and we will delete the account.
12. Cookies and Tracking
Vastrix operates via WhatsApp and does not use website cookies. Our marketing website (vastrix.co.za) may use basic analytics cookies. See the website's separate cookie policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted at the same URL with the "Last updated" date at the top reflecting the latest revision. We encourage you to review this policy periodically.
14. Contact Us
For any questions, requests, or complaints about this Privacy Policy or your data:
Email: info@vastrix.co.za
Based in: South Africa