1. Purpose of this notice
This notice is written for Messaging Participants: people who send or receive messages through WhatsApp, Meta or another communication channel connected to BotHub. It explains how information passes through BotHub, the roles of the organisations involved, the purposes for which Bvelaphanda processes information, and how to exercise privacy rights.
The Client you are communicating with must also provide information about its own purposes, lawful basis, decisions, retention and business practices. This notice does not replace the Client’s privacy notice. It should be read together with our Privacy Policy.
2. Who provides BotHub
Bvelaphanda Business Solutions (Pty) Ltd (“Bvelaphanda”, “we”, “us”) is a South African company that develops and operates BotHub, a platform used by Clients to manage communications with Messaging Participants, workflows, integrations and authorised automated assistance.
- Registered name — Bvelaphanda Business Solutions (Pty) Ltd
- Registration number — 2006/009107/07
- Address — 202 Lourensford Road, Somerset West, 7130
- Information Officer — Mr Bertus Botha
- Privacy contact — policy@bvelaphanda.co.za
- Websites — bvelaphanda.co.za and hub.botsvm.com
3. The organisations involved
| Party | Usual role | What that means |
|---|---|---|
| Client | Responsible Party | The organisation you are communicating with usually decides why information is collected, what messages are sent, what business action is taken and how long its records are needed. |
| White-Label Platform Operator, where applicable | Operator or Responsible Party depending on its activity | May administer a branded BotHub environment or support the Client. Its role depends on whether it follows Client instructions or independently decides how information is used. |
| Bvelaphanda / BotHub | Operator for Client conversations; Responsible Party for limited own purposes | Processes messages and related information to deliver the service. Separately controls limited account security, abuse prevention, support and legal-compliance records. |
| Meta / WhatsApp and other channel providers | Role determined by their terms and activity | Transmit messages and process information under their own terms, privacy documents and platform rules. |
A party’s role is assessed for each processing activity. A label in this notice does not override POPIA or another applicable law.
4. Information processed through BotHub
- Message content — text, images, documents, voice notes, video, interactive replies and other content you choose to send.
- Contact and profile information — your name, telephone number, messaging identifier, profile information made available by the channel, tags and Client-provided records.
- Message metadata — message identifiers, timestamps, sender and recipient details, delivery, read, failure and interaction status, and media metadata.
- Conversation and workflow information — conversation history, routing, assignment, categories, support outcomes and actions taken by approved workflows.
- Derived information — transcripts, summaries, classifications, intent, sentiment indicators, suggested replies and other outputs where an enabled feature performs that processing.
- Technical and security information — API and webhook events, IP or network information where available, error records, fraud or abuse signals and audit logs.
- Connected-system information — records retrieved from or sent to systems selected by the Client, such as CRM, billing, support, payment, scheduling, inventory or identity services.
5. Where information comes from
- Directly from your messages and interactions.
- From the Client and its authorised systems, staff and records.
- From Meta, WhatsApp or another communication-channel provider.
- From a White-Label Platform Operator administering the environment.
- From Client-selected integrations and authorised service providers.
- Automatically from platform security, delivery and operational logs.
6. Why Bvelaphanda processes it
- Receive, route, display, store and deliver communications for the Client.
- Run approved workflows, integrations, assignments, notifications and support processes.
- Provide enabled transcription, search, classification, summarisation or response-assistance features.
- Maintain security, verify webhooks, prevent abuse, investigate incidents and protect the service.
- Provide support, restore service, migrate data and diagnose errors.
- Comply with law, enforce platform rules and maintain evidence relating to complaints, abuse or security incidents.
- Use aggregated or de-identified operational information to improve reliability and performance where reasonably possible.
Bvelaphanda does not sell Messaging Participant information. Bvelaphanda does not use Client conversation content to train its own general-purpose artificial-intelligence models.
7. AI, automation and transcription
A Client may enable features that transcribe voice notes, classify messages, detect intent, search a knowledge source, summarise a conversation, prioritise a case or suggest a response. The Client is responsible for deciding whether a feature is suitable, what human review is required and whether a consequential business decision may be made.
- AI output may be incomplete, inaccurate or inappropriate and should not be treated as professional advice or a guaranteed decision.
- BotHub should not be used to make a solely automated decision with a legal or similarly significant effect unless the Client has confirmed that the use is lawful and appropriate safeguards, including meaningful human review, are implemented.
- Where an external provider is enabled, the relevant message, audio, prompt, document or output may be sent to that provider. The provider and processing location will be identified to the Client before the feature is enabled.
- Messaging Participants may request available information about a materially consequential automated process through the Client or Bvelaphanda’s privacy contact.
8. Meta, WhatsApp and communication channels
WhatsApp messages are transmitted through the official WhatsApp Business Platform operated by Meta. Information therefore passes through Meta’s systems and is subject to Meta and WhatsApp terms, privacy practices and platform rules. Meta may process information outside South Africa. Other channels may operate similarly under their own terms.
The Client is responsible for ensuring that it has the required WhatsApp opt-in before initiating messages, identifies itself properly, sends only permitted content and honours requests to stop messages.
9. Service providers and Client-selected integrations
Bvelaphanda uses a limited number of providers for infrastructure, communications, security, support and optional features. Providers acting for Bvelaphanda must be contractually restricted and subject to appropriate safeguards. Current providers and processing regions are identified in the subprocessor register, available on request from the Information Officer using the contact details in section 2.
A Client may connect its own third-party services. Those services may process information under the Client’s agreement with them and may not be controlled by Bvelaphanda. The Client must assess and disclose those integrations.
10. Cross-border processing
Meta and other approved providers may process information outside South Africa. Where Bvelaphanda arranges a cross-border transfer, it uses a permitted basis under section 72 of POPIA, such as adequate protection under law, binding agreements, consent where appropriate, or contractual necessity. The Client is responsible for transfers it independently causes through its systems and integrations.
11. Special personal information and children
Messages may contain health, biometric, religious, political, criminal, financial or other sensitive information, or information relating to a child. Do not send sensitive information unless it is necessary and you are comfortable providing it to the Client.
The Client is responsible for having a lawful authorisation to process special personal information or children’s information. Bvelaphanda processes such information only to provide the service, maintain security, comply with law or follow lawful instructions. BotHub accounts may not be administered by persons under 18.
12. Direct marketing and stopping messages
A Client that sends direct marketing is responsible for having consent or another permitted basis, keeping evidence of that basis, identifying itself and providing a free and practical way to stop further marketing. You may object to direct marketing at any time by using the Client’s stated opt-out method or contacting the Client.
BotHub may maintain a suppression record so that an opt-out is not accidentally reversed. Bvelaphanda may restrict or suspend a Client that repeatedly ignores valid opt-outs or sends unlawful messages.
13. Retention and deletion
- Client-controlled records — kept according to the Client’s documented instructions and selected retention settings. Clients should not retain all conversations indefinitely.
- After service termination — ordinarily available for a 90-day export and wind-down period, unless a different signed period, legal hold or verified limitation applies, and then removed from active production use.
- Backups and replicas — deleted information may remain in encrypted or restricted backups until the applicable rotation cycle ends and is not returned to ordinary use.
- Security and abuse records — ordinarily up to 12 months, or longer where reasonably needed for an incident, claim, legal obligation or enforcement matter.
- Opt-out records — may be retained as a minimal suppression record to ensure that a request not to receive marketing is respected.
14. Security
Bvelaphanda applies safeguards appropriate to messaging information, including secure transmission, access controls, logical Client separation, logging, backups, incident handling and confidentiality obligations. These measures are described further in section 15 of our Privacy Policy, and details are available to Clients on request. No system is completely secure.
15. Security compromises
If Bvelaphanda is the Responsible Party for affected information, it will assess and notify the Information Regulator and affected people as POPIA requires. If Bvelaphanda is acting as the Client’s Operator, it will notify the Client immediately after becoming aware of the compromise and provide reasonable assistance so that the Client can meet its duties.
16. Your rights
- Ask whether relevant personal information is held and request access.
- Ask for inaccurate, incomplete, excessive, outdated, unlawfully obtained or no-longer-authorised information to be corrected or deleted.
- Object on reasonable grounds to certain processing and object at any time to direct marketing.
- Withdraw consent where processing depends on consent.
- Ask about safeguards for a regulated solely automated decision.
- Complain to the Client, Bvelaphanda or the Information Regulator.
Where your request concerns a Client conversation, contact the Client first. Bvelaphanda will assist and may route the request to the Client as Responsible Party. Identity and authority may be verified before information is released.
17. Contacts and complaints
- Bvelaphanda privacy contact — policy@bvelaphanda.co.za
- Client privacy contact — Ask the Client or use its linked Client-specific privacy notice.
- Information Regulator POPIA complaints — POPIAComplaints@inforegulator.org.za
- Information Regulator website — inforegulator.org.za and eservices.inforegulator.org.za
- Telephone — 010 023 5200 or toll-free 0800 017 160
18. Changes and Client-specific information
We will update the version and effective date when this notice changes and will retain prior versions where reasonably available. A Client may publish a Client-specific notice that describes its own purposes, retention, industry obligations, integrations and contact details. If that notice conflicts with this notice regarding the Client’s independent business processing, the Client’s notice governs that processing, subject to law.
