AOne·The Enterprise Digital Experience Platform of AO Group

Privacy and information governance

Responsible handling of information, wherever we operate.

AO Group operates through affiliated legal entities across Africa and Europe. We are committed to handling personal information responsibly, transparently and securely in accordance with the laws applicable to each entity and processing activity.

Select a country or region below to understand the relevant privacy framework, identify the responsible AO entity, access supporting documents or submit a privacy request.

Select your country or region

Country and regional privacy information

Each AO entity operates under the privacy framework applicable to its jurisdiction and processing activities.

  • South Africa

    Applicable framework
    POPIA and PAIA
    Relevant AO entity
    AO South African affiliated entities
  • Mauritius

    Applicable framework
    Data Protection Act 2017
    Relevant AO entity
    AO Group Holdings Limited
  • Zambia

    Applicable framework
    Data Protection Act 2021
    Relevant AO entity
    Accelerated Orbit Technologies Zambia Limited
  • Botswana

    Applicable framework
    Applicable Botswana data-protection and privacy requirements
    Relevant AO entity
    AOBots Proprietary Limited
  • EuropeEuropean Economic Area

    Applicable framework
    GDPR, where applicable
    Relevant AO entity
    Relevant European entity — to be confirmed
Legal entities

Who is responsible for your information?

“AO Group” is a collective brand used by affiliated legal entities operating in different jurisdictions. The legal entity responsible for personal information will depend on the company with which you interact, the service involved and the relevant processing activity.

The applicable entity may normally be identified from your agreement, invoice, employment documentation, supplier record, application or correspondence.

For assistance, contact info@aogroup.co.za.

AO Connect Holdings (Pty) Ltd

CIPC registration number
2023/772549/07
Information Officer
Pieter Hendrik du Toit
Contact email
info@aogroup.co.za

AO Connect Solutions (Pty) Ltd

CIPC registration number
2023/845987/07
Information Officer
Pieter Hendrik du Toit
Contact email
info@aogroup.co.za

AO Digital Solutions (Pty) Ltd

CIPC registration number
2025/250438/07
Information Officer
Pieter Hendrik du Toit
Contact email
info@aogroup.co.za

AO Software Solutions (Pty) Ltd

CIPC registration number
2025/259939/07
Information Officer
Pieter Hendrik du Toit
Contact email
info@aogroup.co.za

The correct responsible party or controller depends on the relevant entity and processing activity. Where the applicable entity is unclear, AO will assist in identifying it.

POPIA

Our approach to POPIA

POPIA establishes eight conditions for the lawful processing of personal information. AO seeks to apply these principles throughout the lifecycle of personal information, from collection and use through storage, sharing, retention and secure disposal.

01

Accountability

We assign responsibility for privacy governance and the management of personal information.

02

Processing limitation

We seek to process information lawfully, reasonably and only to the extent appropriate for the purpose.

03

Purpose specification

We seek to collect personal information for specific and defined purposes.

04

Further processing limitation

We assess whether any new use of information is compatible with the original purpose or otherwise legally permitted.

05

Information quality

We take reasonable steps to maintain relevant, complete and accurate information.

06

Openness

We aim to explain what information is collected, why it is used and who is responsible for it.

07

Security safeguards

We apply organisational and technical safeguards appropriate to the information and risk.

08

Data subject participation

We provide channels through which individuals can exercise applicable privacy rights.

These summaries describe AO's approach. They are not the complete legal text of POPIA and do not replace the Act or any entity-specific privacy notice.

GDPR

When GDPR may apply

GDPR may apply where an AO entity processes personal data in connection with an establishment in the European Economic Area, or where relevant processing relates to offering goods or services to individuals in the European Union or monitoring their behaviour there.

Where GDPR applies, AO's approach is guided by principles including:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

GDPR does not necessarily apply to every interaction with every AO entity. The applicable law depends on the entity, location, processing activity and relationship involved.

Information

Information we may process

Depending on the relationship and the relevant AO entity, personal information may include:

Customers and prospects

  • Contact details
  • Communications
  • Requirements and service records
  • Account and contract information

Employees, contractors and applicants

  • Contact and identity information
  • Qualifications and employment history
  • Payroll and statutory information
  • Performance, leave and operational records

Suppliers and partners

  • Contact details
  • Contracts
  • Compliance and onboarding records
  • Invoices and payment information

Technology and security

  • User accounts
  • System access records
  • Device and network information
  • Support and audit information
  • Credentials where operationally necessary and contractually authorised

Website and marketing

  • Website interactions
  • Form submissions
  • Communication preferences
  • Consent and unsubscribe records
  • Relevant analytics information

Finance and governance

  • Billing and banking details
  • Tax and corporate records
  • Legal and regulatory correspondence
  • Risk and compliance records

AO aims to collect only information that is relevant and reasonably necessary for a defined business, legal, contractual or operational purpose.

Purposes

Why we use personal information

  • To provide contracted services
  • To communicate with customers, suppliers and partners
  • To manage projects, support and service delivery
  • To recruit, employ and manage people
  • To process invoices and payments
  • To operate and secure AO systems
  • To meet legal, regulatory and contractual duties
  • To manage risk, fraud prevention and business continuity
  • To improve services and customer experience
  • To send permitted business communications
  • To maintain records and defend legal rights

The specific purpose and legal basis depend on the relevant processing activity, relationship and jurisdiction.

Sharing

When information may be shared

Personal information may be shared with:

  • Authorised AO employees and contractors
  • Other AO entities where required for legitimate group operations
  • Approved technology, hosting and service providers
  • Professional advisers
  • Customers or partners where contractually necessary
  • Regulators, courts or public authorities where legally required
  • Lawful transaction parties during a corporate transaction

AO does not sell personal information.

Where third parties process information on AO's behalf, AO seeks to use appropriate contractual, confidentiality and security arrangements.

Business systems

How our business systems support privacy controls

AO uses Odoo as a core enterprise resource planning and business-management platform for selected operational processes.

Odoo includes configurable user roles, access rights and record rules that can be used to limit access to applications, records and functions. AO uses these capabilities as part of its broader approach to role-based access, segregation of duties and controlled information handling.

Depending on the relevant AO environment and approved configuration, supporting controls may include:

  • Role-based user permissions
  • Application-level access restrictions
  • Record-level access rules
  • Controlled administrative permissions
  • User deactivation and access review
  • Multi-company access separation
  • Audit and activity records
  • Authentication and session controls
  • Document and communication controls
  • Data export restrictions
  • Retention and deletion workflows
Important

Technology alone does not establish legal compliance. The effectiveness of these controls depends on correct configuration, governance, contracts, staff training, monitoring and ongoing review.

Third-party documentation

Supporting platform documentation

These links lead to documentation published by Odoo. They describe Odoo platform capabilities and legal resources, but do not replace AO's own policies, agreements or compliance responsibilities.

Security

How we protect personal information

AO applies organisational and technical safeguards appropriate to the nature of the information, the systems involved and the risks presented. Depending on the entity and system, these may include:

  • Role-based access controls
  • Authentication and account-management controls
  • Encryption and secure communications where appropriate
  • Endpoint and infrastructure security
  • Backup and recovery processes
  • Monitoring and incident-management processes
  • Supplier and operator due diligence
  • Confidentiality obligations
  • Staff awareness and training
  • Secure document and record management
  • Retention and disposal procedures
  • Periodic access and control reviews

Safeguards are applied where appropriate to the relevant system and risk. Implementation may differ between entities, environments and services.

Transfers

International processing and transfers

AO operates across multiple jurisdictions and may use systems, service providers or group resources located outside the country in which personal information was collected.

Where personal information is transferred internationally, AO seeks to apply appropriate contractual, legal and security safeguards required by the applicable law.

Where GDPR applies, international transfers may require an adequacy decision, appropriate safeguards or another legally recognised transfer mechanism.

Retention

How long we keep information

AO retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by legal, regulatory, contractual, operational or evidential obligations.

Retention periods may differ according to:

  • The type of information
  • The relevant AO entity
  • The customer or employment relationship
  • Contractual commitments
  • Tax, labour or corporate requirements
  • Litigation or dispute requirements
  • Security and audit needs

When information is no longer required, AO seeks to delete, destroy, anonymise or securely archive it as appropriate.

Automation

AI and automated processing

AO may use automation and artificial intelligence to support selected business processes, analysis, service delivery and decision support.

Where personal information is involved, AO seeks to ensure that:

  • There is a defined and lawful purpose
  • Access is appropriately controlled
  • Information is relevant and proportionate
  • Material decisions receive appropriate human oversight
  • Security and confidentiality requirements are considered
  • Customers are informed where contractually or legally required

AO does not rely solely on automated decision-making that produces significant legal or similarly important effects unless the processing is legally permitted and appropriate safeguards are in place.

Your rights

Your privacy rights

Depending on the applicable law and circumstances, you may have the right to:

  • Ask whether AO holds personal information about you
  • Request access to that information
  • Request correction of inaccurate or incomplete information
  • Request deletion or destruction where legally permitted
  • Object to certain processing
  • Request restriction of processing where GDPR applies
  • Withdraw consent where processing relies on consent
  • Request data portability where GDPR applies
  • Object to direct marketing
  • Lodge a complaint with the relevant supervisory authority

These rights are not absolute and may be limited by legal, contractual, regulatory or evidential requirements.

Process

How to submit a privacy request

  1. 01

    Contact AO

    Email info@aogroup.co.za using the recommended subject line "Privacy Request — [Your Name]".

    info@aogroup.co.za
  2. 02

    Explain the request

    Provide enough context for AO to route and assess the request:

    • Your relationship with AO
    • The relevant AO entity, if known
    • The right you wish to exercise
    • Enough detail to identify the information
  3. 03

    Identity verification

    AO may request reasonable proof of identity or authority before acting on the request. Do not attach identity documents until AO confirms a secure channel for them.

  4. 04

    Assessment

    AO will assess the request under the applicable law and may contact the requester for clarification.

Please do not attach identity documents to an initial email. AO will confirm how to provide any required proof of identity or authority through an appropriate channel.

Document centre

Privacy and compliance documents

Filter by country or region. Only approved documents may be downloaded as current documents; pending and expired items are labelled and their download controls are disabled.

Showing 22 documents.

Kenya Data Controller Registration Certificate

Registration certificate issued by Kenya's Office of the Data Protection Commissioner.

Country or region
Kenya
Legal entity
AO Technology Group Limited
Document type
Registration Certificate · Data Controller
Serial number
08218
Valid from
3 December 2024
Valid until
3 December 2026
Status
Published

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Kenya Data Processor Registration Certificate

Registration certificate issued by Kenya's Office of the Data Protection Commissioner.

Country or region
Kenya
Legal entity
AO Technology Group Limited
Document type
Registration Certificate · Data Processor
Serial number
08317
Valid from
9 December 2024
Valid until
9 December 2026
Status
Published

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Kenya Data Protection Statement

Entity-specific privacy statement for Kenya operations.

Country or region
Kenya
Legal entity
AO Technology Group Limited
Document type
Privacy Statement
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Kenya Data-Subject Request Guide

Guidance on submitting a privacy request relating to Kenya.

Country or region
Kenya
Legal entity
AO Technology Group Limited
Document type
Request Guide
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Mauritius Privacy Statement

Entity-specific privacy statement for Mauritius operations.

Country or region
Mauritius
Legal entity
AO Group Holdings Limited
Document type
Privacy Statement
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Mauritius Data-Subject Request Guide

Guidance on submitting a privacy request relating to Mauritius.

Country or region
Mauritius
Legal entity
AO Group Holdings Limited
Document type
Request Guide
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Zambia Data Protection Statement

Entity-specific data protection statement for Zambia operations.

Country or region
Zambia
Legal entity
Accelerated Orbit Technologies Zambia Limited
Document type
Privacy Statement
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Zambia Data-Subject Request Guide

Guidance on submitting a privacy request relating to Zambia.

Country or region
Zambia
Legal entity
Accelerated Orbit Technologies Zambia Limited
Document type
Request Guide
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Botswana Privacy Statement

Entity-specific privacy statement for Botswana operations.

Country or region
Botswana
Legal entity
AOBots Proprietary Limited
Document type
Privacy Statement
Status
Pending legal review

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Botswana Data-Subject Request Guide

Guidance on submitting a privacy request relating to Botswana.

Country or region
Botswana
Legal entity
AOBots Proprietary Limited
Document type
Request Guide
Status
Pending legal review

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

GDPR Privacy Notice

Full privacy notice for processing to which the GDPR applies.

Country or region
Europe
Legal entity
Relevant AO entity — to be confirmed
Document type
Privacy Notice
Status
Pending legal review

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

European Data-Subject Request Guide

Guidance on exercising GDPR rights where they apply.

Country or region
Europe
Legal entity
Relevant AO entity — to be confirmed
Document type
Request Guide
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Data-Processing Addendum

Contractual data-processing terms for European customers.

Country or region
Europe
Legal entity
Relevant AO entity — to be confirmed
Document type
Contractual Addendum
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Subprocessor List

List of subprocessors, if AO decides to publish one for European processing.

Country or region
Europe
Legal entity
Relevant AO entity — to be confirmed
Document type
Subprocessor List
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

POPIA Compliance Statement

AO's statement of approach to the conditions for lawful processing.

Country or region
South Africa
Legal entity
AO South African entities
Document type
Compliance Statement
Status
Published

PAIA Manuals

Entity-specific PAIA manuals and the access-to-information process.

Country or region
South Africa
Legal entity
AO South African entities
Document type
PAIA Manual
Status
Published

POPIA Objection Form

The prescribed form for objecting to processing.

Country or region
South Africa
Legal entity
AO South African entities
Document type
Prescribed Form
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

POPIA Correction or Deletion Form

The prescribed form for requesting correction or deletion.

Country or region
South Africa
Legal entity
AO South African entities
Document type
Prescribed Form
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

AO Privacy Notice

AO's general privacy notice describing how information is processed.

Country or region
Group-wide
Legal entity
AO Group affiliated entities
Document type
Privacy Notice
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Cookie Policy

How cookies and similar technologies are used across the AO website.

Country or region
Group-wide
Legal entity
AO Group affiliated entities
Document type
Website Policy
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Information Security Overview

A customer-facing, non-sensitive overview of AO's security approach.

Country or region
Group-wide
Legal entity
AO Group affiliated entities
Document type
Security Overview
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Supplier Data-Processing Requirements

Data-protection requirements applicable to AO suppliers and operators.

Country or region
Group-wide
Legal entity
AO Group affiliated entities
Document type
Supplier Requirements
Status
Pending approval

Final approved document pending publication. For assistance, contact info@aogroup.co.za.

Cookies and third parties

Third-party content on the AO website

AO embeds independent recognition and review content from Clutch and Bark. These embeds load only after you allow them.

Third-party embed

Clutch

Displays AO's independently verified Clutch award badges as embedded frames on the homepage and About page.

Origins contacted
https://clutch.co, https://static.clutch.co
Clutch privacy policy

When live Clutch content is loaded, your IP address, browser information and referring origin may be transmitted to those providers. No Clutch content is requested until consent is granted; until then AO shows locally hosted placeholders and plain links.

Current preference: not allowed
FAQs

Frequently asked

Need help with a privacy matter?

Contact AO if you have a question about personal information, wish to exercise a privacy right or need help identifying the relevant legal entity.

info@aogroup.co.za

A discovery session is a working conversation about scope, constraints and what a credible first release looks like.