What we collect
Enough to understand and respond.
Contact details, project information and any optional supporting files you choose to provide.
Privacy
We collect only the information we need to understand your enquiry, protect the service and communicate with you about the work you asked us to consider.
What we collect
Contact details, project information and any optional supporting files you choose to provide.
Why we use it
To assess the request, communicate with you, protect the service and decide the practical next step.
Default retention
The enquiry system has defined cleanup rules rather than keeping enquiry data indefinitely.
01 · Responsible party
RouteFoundry Technologies (Pty) Ltd (Registration No. 2026/600853/07) is the responsible party for the personal information processed through this website and the RouteFoundry project-enquiry service.
20977 Toad StreetLion Pride EstateNietgedacht 535GautengSouth Africa1739Privacy enquiries and requests may be sent tohello@routefoundry.co.za or made by telephone at065 337 4693.
The acknowledgement on our Contact form confirms that you have been shown how the enquiry information will be handled. It does not give RouteFoundry unrestricted permission to use your information for unrelated purposes.
02 · Information collected
When you submit a project enquiry, we may receive:
Website, hosting and security providers may also process technical information such as IP address, browser or device information, request headers and security signals where this is necessary to deliver or protect the service.
RouteFoundry uses a derived identifier rather than storing the visitor's raw IP address as part of the enquiry record for its application-level rate limiting. Cloudflare may still process the originating IP address when delivering and protecting the service and when validating Turnstile.
03 · Required and optional
The Contact form requires your name, email address, phone number, preferred contact method, service category, project description and Privacy Policy acknowledgement. A successful security check is also required before the enquiry can be submitted.
Business name, budget, preferred timing and supporting files are optional. If required information is not provided, the online enquiry cannot be completed because we would not have enough information to process or respond to it safely.
04 · Purpose
We use information for limited business and operational purposes, including to:
Depending on the circumstances, processing may be necessary to take steps at your request before entering into an agreement, to perform an agreement, to comply with a legal obligation, to pursue legitimate business or security interests, or because consent has been obtained where consent is legally required.
05 · Supporting files
Supporting files are optional. The Contact form currently permits up to three approved files, with a maximum of 10 MB per file and 20 MB in total.
If a file or enquiry contains another person's personal information, you must be authorised to share that information with RouteFoundry for the stated purpose.
Files upload directly to private Cloudflare R2 object storage through short-lived, signed upload authorisations. They do not pass through the public website hosting account.
The production R2 bucket is configured with Cloudflare's European Union jurisdiction restriction. Upload sessions are short-lived, and abandoned staging data is subject to automated cleanup.
Email copies and business correspondence held in RouteFoundry's domain mailboxes are managed separately from the automated D1 and R2 cleanup process. Unsuccessful genuine enquiry correspondence is reviewed for deletion 90 days after the latest meaningful communication, while spam and irrelevant correspondence is removed within 30 days or sooner. If an enquiry becomes an accepted project, relevant correspondence is retained only for as long as required for project delivery, contracts, payments and lawful business recordkeeping.
An authorised RouteFoundry operator performs a monthly mailbox retention review. A justified legal, privacy, investigation or operational hold may delay deletion until the hold is released or expires.
Please do not upload passwords, banking credentials, API keys, private access details, unnecessary identity documents, medical information or other sensitive information unless it is genuinely required and you have first confirmed that it is appropriate to send.
06 · Providers
RouteFoundry currently uses Afrihost, Cloudflare and Resend to operate the public website and project-enquiry service. Umami Cloud is separately disclosed below as RouteFoundry's active analytics provider using the selected European Union data region.
Hosts the public static RouteFoundry website and RouteFoundry's domain mailboxes used to receive internal enquiry notifications and business correspondence. Technical web-server, connection and mailbox information may therefore be processed on Afrihost infrastructure.
Afrihost has confirmed to RouteFoundry that information associated with the current shared-hosting and hosted-mailbox service is not presently transferred outside South Africa. Afrihost has also confirmed that it will not initiate a cross-border transfer for this service without RouteFoundry's prior written approval.
If Afrihost proposes a future change that would involve processing outside South Africa, RouteFoundry will assess the proposed processing against section 72 of POPIA before approving the change and will update this policy where required.
Provides the enquiry Worker, D1 database, private R2 file storage, Turnstile security checks and protected internal-access infrastructure.
The production D1 database and R2 file bucket are configured with Cloudflare's European Union jurisdiction restriction. Persistent enquiry database records and uploaded files are therefore stored under that EU jurisdiction configuration. Cloudflare Worker requests may still be processed through Cloudflare's global network.
Delivers transactional enquiry emails. Email addresses, message content and delivery metadata may therefore be processed by Resend and its authorised subprocessors. Resend states that its primary processing operations and customer data storage are in the United States.
Resend's current documentation states that email data is retained for 30 days across its plans, with different retention arrangements available for Enterprise. This provider-side retention is separate from RouteFoundry's own enquiry-retention lifecycle.
RouteFoundry uses an EU-region Umami Cloud account for privacy-conscious website analytics. Production analytics is active using this approved configuration.
RouteFoundry's approved implementation limits custom event data to safe service and source categories and does not send enquiry field values, contact details, project descriptions, filenames, file contents, raw errors, tokens or internal enquiry identifiers to Umami.
Umami Software, Inc. is based in the United States. Its Data Processing Agreement is incorporated automatically into RouteFoundry's service agreement, and Umami's published Subprocessor register includes providers in the United States and European Union. The selected EU data region therefore describes RouteFoundry's analytics account configuration and is not a promise that every supporting operation is performed only within the European Union.
If you choose to contact RouteFoundry through a third-party service such as WhatsApp or Facebook, that service will also process information under its own terms and privacy practices.
07 · Retention
The enquiry system applies defined retention rules:
Final privacy cleanup removes customer personal fields, stored provider payloads, filenames, file metadata and storage-object references from the enquiry system. Minimal non-personal or de-identified integrity and audit records may remain where needed to demonstrate system state and prevent records from being recreated incorrectly.
Where an enquiry becomes active project work, relevant information may form part of the project or business record and may need to be retained for the justified contractual, operational, legal or dispute-related period applicable to that work.
08 · Cookies and analytics
RouteFoundry does not currently use advertising cookies or cookie-based production analytics.
RouteFoundry uses Umami Cloud through an EU-region account for production website analytics. The tracker is configured with RouteFoundry's approved privacy controls and is used for aggregate website and enquiry-funnel measurement.
Umami's tracker operates without analytics cookies. Umami may derive session and location information from technical data such as IP address, user agent and website identifiers. Umami states that the IP address may be used for location processing but is not stored as an analytics value.
RouteFoundry's implementation additionally excludes page query strings and URL fragments, removes referrer metadata before transmission, respects browser Do Not Track and restricts custom analytics data to an approved allowlist.
Security and hosting providers may use technical mechanisms necessary to deliver, protect or operate their services. Those mechanisms are not used by RouteFoundry for behavioural advertising.
09 · Marketing
No. Submitting a project enquiry does not automatically add you to a newsletter or unrelated marketing list.
We may contact you about the enquiry, a related quotation, project scope or the business relationship that follows from your request. If RouteFoundry later conducts direct electronic marketing, it will be handled under the applicable legal requirements and with an appropriate way to object or opt out.
10 · Cross-border processing
Yes. Some providers process information outside South Africa. Resend states that its primary processing operations are in the United States. RouteFoundry's production D1 database and R2 file storage are configured with Cloudflare's European Union jurisdiction restriction, while Cloudflare Worker requests may still be processed through Cloudflare's global network. RouteFoundry's Umami Cloud analytics account is configured for the European Union data region. Afrihost has confirmed that information associated with RouteFoundry's current shared-hosting and hosted-mailbox service is not presently transferred outside South Africa.
Cloud infrastructure and other operators may process technical or service data in other jurisdictions according to their infrastructure and contractual arrangements. RouteFoundry therefore does not promise that every item of personal information is processed only in South Africa.
For Cloudflare processing that may occur outside South Africa, RouteFoundry relies on the Cloudflare Data Processing Addendum incorporated into RouteFoundry's service agreement with Cloudflare as the binding contractual protective arrangement. The agreement limits Cloudflare's processing of personal information to the agreed services and documented instructions, requires appropriate security and confidentiality safeguards, and requires subprocessors to be bound by written data-protection terms that are no less protective than Cloudflare's own obligations.
RouteFoundry relies on this binding-agreement safeguard under section 72(1)(a) of POPIA for applicable cross-border processing performed by Cloudflare.
For Resend's United States processing, RouteFoundry relies on the Resend Data Processing Addendum incorporated into RouteFoundry's service agreement with Plus Five Five, Inc. as the binding contractual protective arrangement for the transfer. That agreement limits Resend's processing of customer personal information to the agreed services and documented instructions, requires confidentiality and appropriate security safeguards, and requires authorised subprocessors to be subject to comparable data-protection obligations.
RouteFoundry relies on this binding-agreement safeguard under section 72(1)(a) of POPIA for personal information transferred to Resend.
For Umami processing that may occur outside South Africa, RouteFoundry relies on the Umami Data Processing Agreement incorporated automatically into RouteFoundry's service agreement as a binding contractual protective arrangement. The agreement limits processing to the agreed services and documented instructions, requires confidentiality and appropriate security safeguards, and requires authorised subprocessors to be subject to written data-protection obligations that are no less protective in substance than Umami's own obligations.
Umami's Data Processing Agreement also provides recognised transfer mechanisms, including the EU Standard Contractual Clauses where they apply to a qualifying restricted transfer. RouteFoundry treats the binding DPA as a contractual safeguard when assessing applicable cross-border processing under section 72 of POPIA. The EU Standard Contractual Clauses apply where the DPA says they apply, but RouteFoundry does not present them as a general statement of POPIA compliance.
Other cross-border processing will only take place where an applicable condition permitted by section 72 of POPIA is satisfied.
11 · Security
RouteFoundry uses technical and operational safeguards designed around the enquiry lifecycle. These include:
No internet-connected system can guarantee absolute security. If RouteFoundry becomes aware of a security compromise that triggers legal notification duties, we will follow the applicable POPIA notification requirements.
12 · Your rights
Subject to the circumstances and applicable law, you may contact RouteFoundry to:
We may need to verify your identity before acting on a privacy request. A request may also be limited where continued retention or processing is required or permitted by law.
Send privacy requests tohello@routefoundry.co.za.
13 · Children and sensitive information
RouteFoundry's project-enquiry process is directed at businesses and people seeking business technology services. It is not designed to intentionally collect personal information from children.
Please do not submit children's personal information, special personal information or highly sensitive material unless it is genuinely necessary, legally appropriate and you have confirmed the correct way to provide it.
14 · Complaints
Please contact RouteFoundry first if you have a question or concern so that we can investigate it.
You also have the right to lodge a POPIA complaint with the Information Regulator (South Africa).
15 · Changes
RouteFoundry may update this policy when its services, providers, legal obligations or information-processing practices change.
The current version and last-updated date will be shown on this page. A material change to the enquiry-processing notice may also require a new Privacy Policy version to be recorded with future enquiries.
This is Privacy Policy Version v1, last updated on19 August 2026.