POPIA Statement
The Protection of Personal Information Act (POPIA) governs how personal information is handled in South Africa. Municate is built for South African businesses, so POPIA is not an afterthought here. This statement explains the roles, the safeguards, and your rights in plain language.
The roles
For conversations Municate answers on behalf of a client business, that business is the responsible party: the customer relationship and its data belong to them. Municate acts as an operator, processing personal information on the business's instructions to answer, capture, and route conversations.
For our own website and client accounts, Municate is the responsible party.
What we process
Answering a conversation involves the caller's number or handle, what they say, and the details they choose to share, such as a name for a booking. Depending on the client's settings this may be held as a recording, a written transcript, a short summary written after the call, and a record of anything done during it, such as an appointment booked or a ticket raised.
This is processed to do exactly what the caller asked: make the booking, take the message, answer the question, or hand over to a person.
Minimality and purpose
Municate answers from an approved playbook and captures only what the conversation needs. We do not mine conversations for advertising, we do not sell personal information, we do not use it to train generative AI or machine learning models, and we do not process it for purposes beyond running the front desk.
One rule is worth naming: a South African ID number is never stored, in any column, in any form. Where a caller has to be checked against their own record, the most that is kept is an irreversible one-way value derived from the last four digits, held separately per business, which cannot be turned back into an ID number.
Where processing happens
The service runs on servers we operate in Johannesburg. Conversation records, recordings, transcripts, summaries, knowledge base content, and the vault holding access to connected accounts stay in South Africa.
Speech and language processing is done by specialist providers outside South Africa, so fragments of audio and text cross the border for that purpose. Our transactional email provider is also outside South Africa, which sends a recipient address, a business name and an invoice total across the border. Both are covered by our agreements with those providers, and neither is used to train their models. We treat provider choice as configuration rather than architecture, so moving to an in-region provider does not require rebuilding the service.
Operators we use
Municate uses a small number of outside providers to run the service: speech and language providers, a payment gateway, a transactional email provider, a credential vault for connected accounts, and a telecommunications carrier. A current list, with what each one receives, is available for your compliance review on request.
Security safeguards
Conversations are protected with encryption in transit. Each client's data is separated inside the database and that separation is enforced by the database itself, so one client cannot read another's. Access to connected accounts is held in a vault rather than in our tables, and Municate never holds the password to a connected account.
Access to transcripts and recordings is limited by role, changes that matter are written to an audit record, and support access to a client workspace is logged against the person who opened it. Retention settings are the client's to set, inside ceilings we enforce. We review these safeguards as the service grows.
Retention and deletion
Each client sets how long their conversation data is kept, within limits: recordings up to a year, transcripts and records of actions up to two years, summaries up to three. The defaults are 30 days, 90 days, and one year. When the setting expires, or when a client asks, the data is deleted. Clients leaving the service can request an export first.
Data subject rights
If Municate has processed your personal information, you may request access to it, ask for corrections, or ask for deletion. Where a client business is the responsible party, we will route your request to them and help them honour it.
Two limits on deletion, stated rather than buried. A request not to be contacted is kept as a scrambled record that survives the deletion of everything else, because otherwise erasing your details would clear the way to contact you again. It is pseudonymised, not anonymous. And where a summary has already fed a client's historical totals, the personal details in it are removed while the record itself remains, so those totals are not rewritten.
Requests can be sent to hello@municate.co.za. If you are not satisfied with how a request is handled, you may complain to the Information Regulator of South Africa.
Questions
POPIA questions, operator agreements, or security detail for your compliance review: hello@municate.co.za. We would rather answer a hard question before you sign than after.