Skip to content

Privacy

Privacy Policy

We collect only the information we need to understand your enquiry, protect the service and communicate with you about the work you asked us to consider.

Version v1Last updated: 19 August 2026

Privacy summary

What we collect

Enough to understand and respond.

Contact details, project information and any optional supporting files you choose to provide.

Why we use it

For the enquiry you started.

To assess the request, communicate with you, protect the service and decide the practical next step.

Default retention

90 days for an ordinary enquiry.

The enquiry system has defined cleanup rules rather than keeping enquiry data indefinitely.

01 · Responsible party

Who is responsible for your information?

RouteFoundry Technologies (Pty) Ltd (Registration No. 2026/600853/07) is the responsible party for the personal information processed through this website and the RouteFoundry project-enquiry service.

20977 Toad StreetLion Pride EstateNietgedacht 535GautengSouth Africa1739

Privacy enquiries and requests may be sent tohello@routefoundry.co.za or made by telephone at065 337 4693.

Privacy acknowledgement is not blanket consent.

The acknowledgement on our Contact form confirms that you have been shown how the enquiry information will be handled. It does not give RouteFoundry unrestricted permission to use your information for unrelated purposes.

02 · Information collected

What information do we collect?

When you submit a project enquiry, we may receive:

  • your name;
  • email address;
  • phone or WhatsApp number;
  • preferred contact method;
  • business or organisation name, if supplied;
  • the service category you select;
  • your description of the problem or project;
  • budget and timing information, if supplied;
  • supporting files that you deliberately upload;
  • the approved source that brought you to the enquiry form, where available;
  • the Privacy Policy version acknowledged when the enquiry was submitted; and
  • timestamps and operational records required to process and protect the enquiry.

Website, hosting and security providers may also process technical information such as IP address, browser or device information, request headers and security signals where this is necessary to deliver or protect the service.

RouteFoundry uses a derived identifier rather than storing the visitor's raw IP address as part of the enquiry record for its application-level rate limiting. Cloudflare may still process the originating IP address when delivering and protecting the service and when validating Turnstile.

03 · Required and optional

What do you have to provide?

The Contact form requires your name, email address, phone number, preferred contact method, service category, project description and Privacy Policy acknowledgement. A successful security check is also required before the enquiry can be submitted.

Business name, budget, preferred timing and supporting files are optional. If required information is not provided, the online enquiry cannot be completed because we would not have enough information to process or respond to it safely.

04 · Purpose

Why do we process the information?

We use information for limited business and operational purposes, including to:

  • receive, assess and understand a project enquiry;
  • contact you about the enquiry;
  • clarify scope, requirements, pricing or possible next steps;
  • deliver supporting files securely to our internal review process;
  • send an enquiry confirmation and internal notification;
  • protect the service against spam, abuse, automated submissions and fraud;
  • maintain appropriate operational and audit records;
  • deal with privacy, legal or security obligations; and
  • measure aggregate website and enquiry-funnel performance if the approved analytics system is activated.

Depending on the circumstances, processing may be necessary to take steps at your request before entering into an agreement, to perform an agreement, to comply with a legal obligation, to pursue legitimate business or security interests, or because consent has been obtained where consent is legally required.

05 · Supporting files

How are uploaded files handled?

Supporting files are optional. The Contact form currently permits up to three approved files, with a maximum of 10 MB per file and 20 MB in total.

If a file or enquiry contains another person's personal information, you must be authorised to share that information with RouteFoundry for the stated purpose.

Files upload directly to private Cloudflare R2 object storage through short-lived, signed upload authorisations. They do not pass through the public website hosting account.

The production R2 bucket is configured with Cloudflare's European Union jurisdiction restriction. Upload sessions are short-lived, and abandoned staging data is subject to automated cleanup.

Email copies and business correspondence held in RouteFoundry's domain mailboxes are managed separately from the automated D1 and R2 cleanup process. Unsuccessful genuine enquiry correspondence is reviewed for deletion 90 days after the latest meaningful communication, while spam and irrelevant correspondence is removed within 30 days or sooner. If an enquiry becomes an accepted project, relevant correspondence is retained only for as long as required for project delivery, contracts, payments and lawful business recordkeeping.

An authorised RouteFoundry operator performs a monthly mailbox retention review. A justified legal, privacy, investigation or operational hold may delay deletion until the hold is released or expires.

Only send what we need.

Please do not upload passwords, banking credentials, API keys, private access details, unnecessary identity documents, medical information or other sensitive information unless it is genuinely required and you have first confirmed that it is appropriate to send.

06 · Providers

Which providers are involved?

RouteFoundry currently uses Afrihost, Cloudflare and Resend to operate the public website and project-enquiry service. Umami Cloud is separately disclosed below as RouteFoundry's active analytics provider using the selected European Union data region.

Afrihost

Hosts the public static RouteFoundry website and RouteFoundry's domain mailboxes used to receive internal enquiry notifications and business correspondence. Technical web-server, connection and mailbox information may therefore be processed on Afrihost infrastructure.

Afrihost has confirmed to RouteFoundry that information associated with the current shared-hosting and hosted-mailbox service is not presently transferred outside South Africa. Afrihost has also confirmed that it will not initiate a cross-border transfer for this service without RouteFoundry's prior written approval.

If Afrihost proposes a future change that would involve processing outside South Africa, RouteFoundry will assess the proposed processing against section 72 of POPIA before approving the change and will update this policy where required.

Cloudflare

Provides the enquiry Worker, D1 database, private R2 file storage, Turnstile security checks and protected internal-access infrastructure.

The production D1 database and R2 file bucket are configured with Cloudflare's European Union jurisdiction restriction. Persistent enquiry database records and uploaded files are therefore stored under that EU jurisdiction configuration. Cloudflare Worker requests may still be processed through Cloudflare's global network.

Resend

Delivers transactional enquiry emails. Email addresses, message content and delivery metadata may therefore be processed by Resend and its authorised subprocessors. Resend states that its primary processing operations and customer data storage are in the United States.

Resend's current documentation states that email data is retained for 30 days across its plans, with different retention arrangements available for Enterprise. This provider-side retention is separate from RouteFoundry's own enquiry-retention lifecycle.

Umami Cloud

RouteFoundry uses an EU-region Umami Cloud account for privacy-conscious website analytics. Production analytics is active using this approved configuration.

RouteFoundry's approved implementation limits custom event data to safe service and source categories and does not send enquiry field values, contact details, project descriptions, filenames, file contents, raw errors, tokens or internal enquiry identifiers to Umami.

Umami Software, Inc. is based in the United States. Its Data Processing Agreement is incorporated automatically into RouteFoundry's service agreement, and Umami's published Subprocessor register includes providers in the United States and European Union. The selected EU data region therefore describes RouteFoundry's analytics account configuration and is not a promise that every supporting operation is performed only within the European Union.

If you choose to contact RouteFoundry through a third-party service such as WhatsApp or Facebook, that service will also process information under its own terms and privacy practices.

07 · Retention

How long do we keep enquiry information?

The enquiry system applies defined retention rules:

  • an ordinary accepted enquiry is initially scheduled for cleanup 90 days after submission;
  • when meaningful contact occurs, the retention date may move to 90 days after that contact;
  • an enquiry classified as spam uses a 30-day retention period;
  • incomplete or abandoned upload staging data is handled by a shorter automated cleanup process;
  • information may be retained longer where an active retention hold, legal obligation, dispute, security requirement or legitimate project-record need requires it; and
  • verified privacy cleanup may remove personal information earlier where appropriate and legally permitted.

Final privacy cleanup removes customer personal fields, stored provider payloads, filenames, file metadata and storage-object references from the enquiry system. Minimal non-personal or de-identified integrity and audit records may remain where needed to demonstrate system state and prevent records from being recreated incorrectly.

Where an enquiry becomes active project work, relevant information may form part of the project or business record and may need to be retained for the justified contractual, operational, legal or dispute-related period applicable to that work.

08 · Cookies and analytics

How do we measure website use?

RouteFoundry does not currently use advertising cookies or cookie-based production analytics.

RouteFoundry uses Umami Cloud through an EU-region account for production website analytics. The tracker is configured with RouteFoundry's approved privacy controls and is used for aggregate website and enquiry-funnel measurement.

Umami's tracker operates without analytics cookies. Umami may derive session and location information from technical data such as IP address, user agent and website identifiers. Umami states that the IP address may be used for location processing but is not stored as an analytics value.

RouteFoundry's implementation additionally excludes page query strings and URL fragments, removes referrer metadata before transmission, respects browser Do Not Track and restricts custom analytics data to an approved allowlist.

Security and hosting providers may use technical mechanisms necessary to deliver, protect or operate their services. Those mechanisms are not used by RouteFoundry for behavioural advertising.

09 · Marketing

Does an enquiry subscribe me to marketing?

No. Submitting a project enquiry does not automatically add you to a newsletter or unrelated marketing list.

We may contact you about the enquiry, a related quotation, project scope or the business relationship that follows from your request. If RouteFoundry later conducts direct electronic marketing, it will be handled under the applicable legal requirements and with an appropriate way to object or opt out.

10 · Cross-border processing

Can information be processed outside South Africa?

Yes. Some providers process information outside South Africa. Resend states that its primary processing operations are in the United States. RouteFoundry's production D1 database and R2 file storage are configured with Cloudflare's European Union jurisdiction restriction, while Cloudflare Worker requests may still be processed through Cloudflare's global network. RouteFoundry's Umami Cloud analytics account is configured for the European Union data region. Afrihost has confirmed that information associated with RouteFoundry's current shared-hosting and hosted-mailbox service is not presently transferred outside South Africa.

Cloud infrastructure and other operators may process technical or service data in other jurisdictions according to their infrastructure and contractual arrangements. RouteFoundry therefore does not promise that every item of personal information is processed only in South Africa.

For Cloudflare processing that may occur outside South Africa, RouteFoundry relies on the Cloudflare Data Processing Addendum incorporated into RouteFoundry's service agreement with Cloudflare as the binding contractual protective arrangement. The agreement limits Cloudflare's processing of personal information to the agreed services and documented instructions, requires appropriate security and confidentiality safeguards, and requires subprocessors to be bound by written data-protection terms that are no less protective than Cloudflare's own obligations.

RouteFoundry relies on this binding-agreement safeguard under section 72(1)(a) of POPIA for applicable cross-border processing performed by Cloudflare.

For Resend's United States processing, RouteFoundry relies on the Resend Data Processing Addendum incorporated into RouteFoundry's service agreement with Plus Five Five, Inc. as the binding contractual protective arrangement for the transfer. That agreement limits Resend's processing of customer personal information to the agreed services and documented instructions, requires confidentiality and appropriate security safeguards, and requires authorised subprocessors to be subject to comparable data-protection obligations.

RouteFoundry relies on this binding-agreement safeguard under section 72(1)(a) of POPIA for personal information transferred to Resend.

For Umami processing that may occur outside South Africa, RouteFoundry relies on the Umami Data Processing Agreement incorporated automatically into RouteFoundry's service agreement as a binding contractual protective arrangement. The agreement limits processing to the agreed services and documented instructions, requires confidentiality and appropriate security safeguards, and requires authorised subprocessors to be subject to written data-protection obligations that are no less protective in substance than Umami's own obligations.

Umami's Data Processing Agreement also provides recognised transfer mechanisms, including the EU Standard Contractual Clauses where they apply to a qualifying restricted transfer. RouteFoundry treats the binding DPA as a contractual safeguard when assessing applicable cross-border processing under section 72 of POPIA. The EU Standard Contractual Clauses apply where the DPA says they apply, but RouteFoundry does not present them as a general statement of POPIA compliance.

Other cross-border processing will only take place where an applicable condition permitted by section 72 of POPIA is satisfied.

11 · Security

How do we protect information?

RouteFoundry uses technical and operational safeguards designed around the enquiry lifecycle. These include:

  • TLS-protected network connections;
  • Cloudflare Turnstile and rate limiting for public enquiry submissions;
  • private object storage for uploaded files;
  • short-lived signed upload authorisations;
  • protected internal review and attachment-download routes;
  • restricted operator access to enquiry information;
  • automated staging, failure and personal-data cleanup processes;
  • bounded request sizes and strict server-side validation; and
  • controlled retention and de-identification procedures.

No internet-connected system can guarantee absolute security. If RouteFoundry becomes aware of a security compromise that triggers legal notification duties, we will follow the applicable POPIA notification requirements.

12 · Your rights

What can you ask us to do?

Subject to the circumstances and applicable law, you may contact RouteFoundry to:

  • ask whether we hold personal information about you;
  • request access to personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • request deletion or destruction where we are no longer authorised to retain it;
  • object to qualifying processing on reasonable grounds;
  • request restriction of qualifying processing where applicable;
  • ask for information about relevant third parties that have had access to your personal information;
  • withdraw consent where processing actually depends on your consent; or
  • raise a concern about how your information has been handled.

We may need to verify your identity before acting on a privacy request. A request may also be limited where continued retention or processing is required or permitted by law.

Send privacy requests tohello@routefoundry.co.za.

13 · Children and sensitive information

Please avoid unnecessary sensitive information.

RouteFoundry's project-enquiry process is directed at businesses and people seeking business technology services. It is not designed to intentionally collect personal information from children.

Please do not submit children's personal information, special personal information or highly sensitive material unless it is genuinely necessary, legally appropriate and you have confirmed the correct way to provide it.

14 · Complaints

How can you raise a privacy concern?

Please contact RouteFoundry first if you have a question or concern so that we can investigate it.

You also have the right to lodge a POPIA complaint with the Information Regulator (South Africa).

Information Regulator (South Africa)Woodmead North Office Park54 Maxwell Drive, WoodmeadJohannesburg, 2191POPIA complaints:POPIAComplaints@inforegulator.org.zaGeneral enquiries:enquiries@inforegulator.org.zaTelephone: 010 023 5200Toll-free: 0800 017 160

15 · Changes

What happens when this policy changes?

RouteFoundry may update this policy when its services, providers, legal obligations or information-processing practices change.

The current version and last-updated date will be shown on this page. A material change to the enquiry-processing notice may also require a new Privacy Policy version to be recorded with future enquiries.

This is Privacy Policy Version v1, last updated on19 August 2026.