POPIA Compliance Statement
AO Group is committed to processing personal information responsibly and to applying the conditions for lawful processing established by the Protection of Personal Information Act, 2013.
This statement describes AO's general privacy approach. It does not replace any entity-specific privacy notice, contract, operator agreement, PAIA Manual or other legal document.
Purpose
This statement explains how AO Group and the applicable affiliated legal entity approach the processing of personal information under POPIA. It is intended to give customers, employees, suppliers, partners and other individuals a clear view of AO's privacy approach and the channels available to them.
This statement is a general description of approach. It is not a legal opinion, a certification, or a warranty of compliance in respect of any particular processing activity.
Relevant AO entities
“AO Group” is a collective brand used by a number of affiliated legal entities. The entity that determines why and how personal information is processed will ordinarily be the responsible party under POPIA. The applicable entity may be identified from the relevant agreement, invoice, employment documentation, application, website interaction or correspondence.
- AO Connect Holdings (Pty) LtdCIPC registration number: 2023/772549/07
- AO Connect Solutions (Pty) LtdCIPC registration number: 2023/845987/07
- AO Digital Solutions (Pty) LtdCIPC registration number: 2025/250438/07
- AO Software Solutions (Pty) LtdCIPC registration number: 2025/259939/07
Information Officer
Pieter Hendrik du Toit — Information Officer. Registered Information Officer for the AO South African entities listed on this page.
Email: info@aogroup.co.za
Conditions for lawful processing
AO seeks to apply POPIA's eight conditions for lawful processing across the lifecycle of personal information:
- 01Accountability. We assign responsibility for privacy governance and the management of personal information.
- 02Processing limitation. We seek to process information lawfully, reasonably and only to the extent appropriate for the purpose.
- 03Purpose specification. We seek to collect personal information for specific and defined purposes.
- 04Further processing limitation. We assess whether any new use of information is compatible with the original purpose or otherwise legally permitted.
- 05Information quality. We take reasonable steps to maintain relevant, complete and accurate information.
- 06Openness. We aim to explain what information is collected, why it is used and who is responsible for it.
- 07Security safeguards. We apply organisational and technical safeguards appropriate to the information and risk.
- 08Data subject participation. We provide channels through which individuals can exercise applicable privacy rights.
These summaries are not the complete legal text of POPIA and do not replace the Act.
Information that may be processed
Depending on the relationship and the relevant AO entity, personal information may include:
- Customers and prospects: Contact details, Communications, Requirements and service records, Account and contract information.
- Employees, contractors and applicants: Contact and identity information, Qualifications and employment history, Payroll and statutory information, Performance, leave and operational records.
- Suppliers and partners: Contact details, Contracts, Compliance and onboarding records, Invoices and payment information.
- Technology and security: User accounts, System access records, Device and network information, Support and audit information, Credentials where operationally necessary and contractually authorised.
- Website and marketing: Website interactions, Form submissions, Communication preferences, Consent and unsubscribe records, Relevant analytics information.
- Finance and governance: Billing and banking details, Tax and corporate records, Legal and regulatory correspondence, Risk and compliance records.
AO aims to collect only information that is relevant and reasonably necessary for a defined business, legal, contractual or operational purpose.
Purposes of processing
- To provide contracted services
- To communicate with customers, suppliers and partners
- To manage projects, support and service delivery
- To recruit, employ and manage people
- To process invoices and payments
- To operate and secure AO systems
- To meet legal, regulatory and contractual duties
- To manage risk, fraud prevention and business continuity
- To improve services and customer experience
- To send permitted business communications
- To maintain records and defend legal rights
The specific purpose and legal basis depend on the relevant processing activity, relationship and jurisdiction.
Sharing and operators
Personal information may be shared with:
- Authorised AO employees and contractors
- Other AO entities where required for legitimate group operations
- Approved technology, hosting and service providers
- Professional advisers
- Customers or partners where contractually necessary
- Regulators, courts or public authorities where legally required
- Lawful transaction parties during a corporate transaction
AO does not sell personal information.
Where third parties process information on AO's behalf as operators, AO seeks to use appropriate contractual, confidentiality and security arrangements.
Security safeguards
AO applies organisational and technical safeguards appropriate to the nature of the information, the systems involved and the risks presented. Depending on the entity and system, these may include:
- Role-based access controls
- Authentication and account-management controls
- Encryption and secure communications where appropriate
- Endpoint and infrastructure security
- Backup and recovery processes
- Monitoring and incident-management processes
- Supplier and operator due diligence
- Confidentiality obligations
- Staff awareness and training
- Secure document and record management
- Retention and disposal procedures
- Periodic access and control reviews
International transfers
AO operates across multiple jurisdictions and may use systems, service providers or group resources located outside the country in which personal information was collected. Where personal information is transferred internationally, AO seeks to apply the appropriate contractual, legal and security safeguards required by the applicable law.
Retention
AO retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by legal, regulatory, contractual, operational or evidential obligations. Retention periods may differ according to:
- The type of information
- The relevant AO entity
- The customer or employment relationship
- Contractual commitments
- Tax, labour or corporate requirements
- Litigation or dispute requirements
- Security and audit needs
When information is no longer required, AO seeks to delete, destroy, anonymise or securely archive it as appropriate.
Data-subject rights
Depending on the applicable law and circumstances, a data subject may have the right to:
- Ask whether AO holds personal information about you
- Request access to that information
- Request correction of inaccurate or incomplete information
- Request deletion or destruction where legally permitted
- Object to certain processing
- Request restriction of processing where GDPR applies
- Withdraw consent where processing relies on consent
- Request data portability where GDPR applies
- Object to direct marketing
- Lodge a complaint with the relevant supervisory authority
These rights are not absolute and may be limited by legal, contractual, regulatory or evidential requirements.
Privacy requests
Privacy requests may be submitted by email to info@aogroup.co.za using the subject line “Privacy Request — [Your Name]”. AO may request reasonable proof of identity or authority before acting on a request, and may contact the requester for clarification. Requests for access to records under PAIA follow a separate prescribed process.
Complaints and regulatory contact
Contact info@aogroup.co.za so that AO can investigate any privacy concern. A data subject may also have the right to lodge a complaint with the relevant privacy regulator or supervisory authority.
Document ownership, version and approval
Owner: Information Officer, AO Group and the applicable affiliated legal entity.
Version and effective date: pending formal approval. This web statement is published as AO's general description of approach. The formally approved, versioned PDF will be published in the privacy document centre once approved.
Questions about this statement?
Contact the Information Officer for information relevant to a specific AO entity, service or processing activity.
