Skip to content

Legal

Privacy notice

Last updated 14 September 2026.

This notice explains how BreachAgent.AI handles personal information, in line with South Africa's Protection of Personal Information Act (POPIA) and, where it applies, the GDPR.

Who we are

BreachAgent.AI is the responsible party. Our information officer can be reached at admin@breachagent.ai.

What we collect

  • Contact details you send us — name, email, company and anything you write when you email us or use the contact form.
  • Engagement data — the scope, targets and findings from work we do for you, under the contract we agree.

This website sets no cookies and runs no analytics or third-party trackers. We do not build a profile of your visit.

How the contact form works

The contact form does not send anything to a server. It opens your own email application with the details you typed, and you choose to send the email. We only receive what you send.

Why we process it

To reply to you, to scope and carry out engagements you ask for, and to meet legal and regulatory obligations. Our lawful bases are your consent, the performance of a contract, and our legitimate interest in running the business.

Where it lives and how long

Engagement data is processed and stored in South Africa, encrypted at rest. We keep it for the period agreed in your contract and delete it on request, unless the law requires us to keep it longer.

Sharing

We do not sell personal information. We share it only with service providers who help us operate, under confidentiality obligations, and where the law requires.

Your rights

Under POPIA you may ask what we hold about you, ask us to correct or delete it, and object to processing. You may also complain to the Information Regulator of South Africa. To exercise any of these, email admin@breachagent.ai.

Changes

We will update this notice as our practices change and revise the date above.