South Africa
- Applicable framework
- POPIA and PAIA
- Relevant AO entity
- AO South African affiliated entities
AOne·The Enterprise Digital Experience Platform of AO Group
AO Group operates through affiliated legal entities across Africa and Europe. We are committed to handling personal information responsibly, transparently and securely in accordance with the laws applicable to each entity and processing activity.
Select a country or region below to understand the relevant privacy framework, identify the responsible AO entity, access supporting documents or submit a privacy request.
Each AO entity operates under the privacy framework applicable to its jurisdiction and processing activities.
“AO Group” is a collective brand used by affiliated legal entities operating in different jurisdictions. The legal entity responsible for personal information will depend on the company with which you interact, the service involved and the relevant processing activity.
The applicable entity may normally be identified from your agreement, invoice, employment documentation, supplier record, application or correspondence.
For assistance, contact info@aogroup.co.za.
The correct responsible party or controller depends on the relevant entity and processing activity. Where the applicable entity is unclear, AO will assist in identifying it.
POPIA establishes eight conditions for the lawful processing of personal information. AO seeks to apply these principles throughout the lifecycle of personal information, from collection and use through storage, sharing, retention and secure disposal.
We assign responsibility for privacy governance and the management of personal information.
We seek to process information lawfully, reasonably and only to the extent appropriate for the purpose.
We seek to collect personal information for specific and defined purposes.
We assess whether any new use of information is compatible with the original purpose or otherwise legally permitted.
We take reasonable steps to maintain relevant, complete and accurate information.
We aim to explain what information is collected, why it is used and who is responsible for it.
We apply organisational and technical safeguards appropriate to the information and risk.
We provide channels through which individuals can exercise applicable privacy rights.
These summaries describe AO's approach. They are not the complete legal text of POPIA and do not replace the Act or any entity-specific privacy notice.
GDPR may apply where an AO entity processes personal data in connection with an establishment in the European Economic Area, or where relevant processing relates to offering goods or services to individuals in the European Union or monitoring their behaviour there.
Where GDPR applies, AO's approach is guided by principles including:
GDPR does not necessarily apply to every interaction with every AO entity. The applicable law depends on the entity, location, processing activity and relationship involved.
Depending on the relationship and the relevant AO entity, personal information may include:
AO aims to collect only information that is relevant and reasonably necessary for a defined business, legal, contractual or operational purpose.
The specific purpose and legal basis depend on the relevant processing activity, relationship and jurisdiction.
Personal information may be shared with:
AO does not sell personal information.
Where third parties process information on AO's behalf, AO seeks to use appropriate contractual, confidentiality and security arrangements.
AO uses Odoo as a core enterprise resource planning and business-management platform for selected operational processes.
Odoo includes configurable user roles, access rights and record rules that can be used to limit access to applications, records and functions. AO uses these capabilities as part of its broader approach to role-based access, segregation of duties and controlled information handling.
Depending on the relevant AO environment and approved configuration, supporting controls may include:
Technology alone does not establish legal compliance. The effectiveness of these controls depends on correct configuration, governance, contracts, staff training, monitoring and ongoing review.
Official guidance on configuring user and group access permissions.
Official technical documentation on Odoo access-control and security mechanisms.
Odoo's published legal agreements, privacy policy and compliance resources.
Odoo's own guidance concerning GDPR and the Odoo platform.
These links lead to documentation published by Odoo. They describe Odoo platform capabilities and legal resources, but do not replace AO's own policies, agreements or compliance responsibilities.
AO applies organisational and technical safeguards appropriate to the nature of the information, the systems involved and the risks presented. Depending on the entity and system, these may include:
Safeguards are applied where appropriate to the relevant system and risk. Implementation may differ between entities, environments and services.
AO operates across multiple jurisdictions and may use systems, service providers or group resources located outside the country in which personal information was collected.
Where personal information is transferred internationally, AO seeks to apply appropriate contractual, legal and security safeguards required by the applicable law.
Where GDPR applies, international transfers may require an adequacy decision, appropriate safeguards or another legally recognised transfer mechanism.
AO retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by legal, regulatory, contractual, operational or evidential obligations.
Retention periods may differ according to:
When information is no longer required, AO seeks to delete, destroy, anonymise or securely archive it as appropriate.
AO may use automation and artificial intelligence to support selected business processes, analysis, service delivery and decision support.
Where personal information is involved, AO seeks to ensure that:
AO does not rely solely on automated decision-making that produces significant legal or similarly important effects unless the processing is legally permitted and appropriate safeguards are in place.
Depending on the applicable law and circumstances, you may have the right to:
These rights are not absolute and may be limited by legal, contractual, regulatory or evidential requirements.
Email info@aogroup.co.za using the recommended subject line "Privacy Request — [Your Name]".
info@aogroup.co.zaProvide enough context for AO to route and assess the request:
AO may request reasonable proof of identity or authority before acting on the request. Do not attach identity documents until AO confirms a secure channel for them.
AO will assess the request under the applicable law and may contact the requester for clarification.
Please do not attach identity documents to an initial email. AO will confirm how to provide any required proof of identity or authority through an appropriate channel.
Filter by country or region. Only approved documents may be downloaded as current documents; pending and expired items are labelled and their download controls are disabled.
Showing 22 documents.
Registration certificate issued by Kenya's Office of the Data Protection Commissioner.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Registration certificate issued by Kenya's Office of the Data Protection Commissioner.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Entity-specific privacy statement for Kenya operations.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Guidance on submitting a privacy request relating to Kenya.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Entity-specific privacy statement for Mauritius operations.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Guidance on submitting a privacy request relating to Mauritius.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Entity-specific data protection statement for Zambia operations.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Guidance on submitting a privacy request relating to Zambia.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Entity-specific privacy statement for Botswana operations.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Guidance on submitting a privacy request relating to Botswana.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Full privacy notice for processing to which the GDPR applies.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Guidance on exercising GDPR rights where they apply.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Contractual data-processing terms for European customers.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
List of subprocessors, if AO decides to publish one for European processing.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
AO's statement of approach to the conditions for lawful processing.
Web page
Entity-specific PAIA manuals and the access-to-information process.
Web page
The prescribed form for objecting to processing.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
The prescribed form for requesting correction or deletion.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
AO's general privacy notice describing how information is processed.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
How cookies and similar technologies are used across the AO website.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
A customer-facing, non-sensitive overview of AO's security approach.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
Data-protection requirements applicable to AO suppliers and operators.
Final approved document pending publication. For assistance, contact info@aogroup.co.za.
AO embeds independent recognition and review content from Clutch and Bark. These embeds load only after you allow them.
Displays AO's independently verified Clutch award badges as embedded frames on the homepage and About page.
When live Clutch content is loaded, your IP address, browser information and referring origin may be transmitted to those providers. No Clutch content is requested until consent is granted; until then AO shows locally hosted placeholders and plain links.
Contact AO if you have a question about personal information, wish to exercise a privacy right or need help identifying the relevant legal entity.
A discovery session is a working conversation about scope, constraints and what a credible first release looks like.