Privacy Policy

Last updated: 26 July 2026. Working draft pending counsel sign-off before public launch.

Working draft — pending professional legal review

This page shows Chikmah's working legal text, prepared for counsel sign-off before public launch. Final wording needs review by a lawyer familiar with South African and UK law (including POPIA and UK consumer / data protection rules). Do not treat this text as final or binding until that review is complete.

1. Introduction

This Privacy Policy explains how Chikmah ("Chikmah," "we," "us," "our") collects, uses, discloses, and protects personal information when you use our voice-first business management platform (the "Service"). This policy is designed to meet the requirements of South Africa's Protection of Personal Information Act ("POPIA") and the UK General Data Protection Regulation ("UK GDPR"), given Chikmah's user base across Southern Africa and the United Kingdom.

Chikmah is the "responsible party" under POPIA and the "data controller" under UK GDPR for the personal information described in this policy.

2. Information We Collect

2.1 Information you provide directly:

  • Account details — name, email address, phone number, business name and details, chosen language.
  • Voice recordings you submit, and the transcripts generated from them.
  • Business content — documents, contacts, invoices, business plans, and other content you create or upload.
  • Payment display information, processed via Stripe Connect (Chikmah does not store full payment card numbers).

2.2 Information collected automatically:

  • Usage data — features accessed, session duration, interaction patterns.
  • Device and technical data — device type, operating system, IP address, browser type.
  • Error and performance data, collected via Sentry and PostHog.

2.3 Sensitive information. Voice recordings may incidentally capture tone, accent, or background speech beyond their transcribed content. We treat voice recordings with the same heightened care as special/sensitive personal information under POPIA and UK GDPR, applying the safeguards described in Section 7, even though voice content itself (absent biometric voiceprint matching, which Chikmah does not perform) is not automatically classified as special category data under UK GDPR.

3. How and Why We Use Your Information

Provide the Service (generate documents, plans, content) Information used: Voice/text input, business content. Legal basis (UK GDPR): Performance of a contract.

Maintain and secure your account Information used: Account details, usage data. Legal basis (UK GDPR): Performance of a contract; legitimate interest (security).

Improve the Service (aggregated analytics) Information used: Usage data (de-identified). Legal basis (UK GDPR): Legitimate interest.

Communicate with you about your account Information used: Account details. Legal basis (UK GDPR): Performance of a contract.

Comply with legal obligations (e.g. tax, fraud prevention) Information used: Account and billing details. Legal basis (UK GDPR): Legal obligation.

Model improvement using your content (opt-in only) Information used: Voice/text input, business content. Legal basis (UK GDPR): Consent.

Under POPIA, the equivalent bases are: consent, necessity for performance of a contract to which you are a party, and necessity for compliance with a legal obligation, applied consistently with the purposes above.

4. Third-Party AI Processing

To provide the Service, we share the minimum necessary data with the following processors under data processing agreements requiring appropriate confidentiality and security safeguards:

  • OpenAI (Whisper) — voice transcription.
  • Anthropic (Claude) — Validation and Blueprint-related processing.
  • Google (Gemini) — Studio and content-related processing.

These providers act as our processors/operators and are contractually prohibited from using your data to train their own general-purpose models, except where you have separately opted in under Section 3's "model improvement" purpose.

5. International Data Transfers

Because Chikmah operates across Southern Africa and the United Kingdom, and uses AI processors based in the United States, your personal information may be transferred internationally. Where we transfer personal information from the UK or South Africa to a jurisdiction not deemed to provide adequate protection, we rely on Standard Contractual Clauses (or the UK International Data Transfer Addendum, as applicable) with the receiving party, together with supplementary technical and organizational safeguards including encryption in transit and at rest.

6. Data Retention

We retain personal information only for as long as necessary for the purposes described in this policy:

  • Account and business content — retained for the life of your account, and for 12 months after account closure to allow for account recovery, after which it is deleted or anonymized, unless a longer period is required to comply with a legal obligation (e.g. tax record-keeping requirements in your jurisdiction).
  • Voice recordings — the underlying audio file is retained for 30 days after transcription to allow for quality correction, then deleted; the resulting transcript is retained as part of your account content per the above.
  • Technical/error logs — retained for 90 days.

You may request earlier deletion at any time as described in Section 8.

7. How We Protect Your Information

We apply technical and organizational measures appropriate to the sensitivity of the data, including:

  • Encryption of data in transit and at rest.
  • Row-level security in our database, ensuring you can only access your own data.
  • Access controls limiting internal staff access to personal information on a need-to-know basis.
  • Monitoring and alerting for unusual access patterns (Sentry, PostHog).
  • Regular security review of third-party processors.

No system is completely secure, and we cannot guarantee absolute security, but we will notify you and any applicable regulator without undue delay in the event of a data breach affecting your personal information, as required under POPIA and UK GDPR.

8. Your Rights

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request correction of inaccurate or incomplete information.
  • Deletion — request deletion of your personal information, subject to legal retention requirements.
  • Objection/restriction — object to or request restriction of certain processing, including processing based on legitimate interest.
  • Portability — request your data in a structured, commonly used, machine-readable format.
  • Withdraw consent — where processing is based on consent (e.g. model-improvement opt-in), withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Complain — lodge a complaint with the relevant supervisory authority: the Information Regulator (South Africa) for POPIA matters, or the Information Commissioner's Office (ICO) for UK GDPR matters.

You can exercise most of these rights directly through account settings (data export and account deletion tools are built into the Service) or by contacting us at the details in Section 12.

9. Automated Decision-Making

Chikmah uses AI to generate assessments such as Cofounder's Expert Readiness Scorecard, Academy's Mastery Map, and Validation verdicts. These are decision-support tools intended to inform your own choices — they do not automatically restrict your access to the Service or make a final decision about you without your ability to review, question, or disregard the output. Where any future feature would involve automated decision-making with legal or similarly significant effect on you without human involvement, we will provide specific notice and a mechanism to request human review, consistent with UK GDPR Article 22.

10. Children's Privacy

The Service is not directed at children, and we do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from a child without appropriate consent, we will delete it promptly.

11. Cookies and Similar Technologies

We use cookies and similar technologies for authentication, session management, and analytics. Where required by law, we will present a cookie consent mechanism allowing you to accept or reject non-essential cookies.

12. Contact Us

Information Officer (POPIA): Contact privacy@chikmah.com (named Information Officer pending counsel confirmation).

Data Protection Contact (UK GDPR): Contact privacy@chikmah.com (named contact pending counsel confirmation).

General privacy inquiries: privacy@chikmah.com

You may also write hello@chikmah.com with "Privacy" in the subject line.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes by email and/or in-app notification at least 30 days before they take effect.

Counsel note

Working draft — not final until signed off.

Prepared as Chikmah's working Privacy Policy. Recommended for a final compliance pass by a data protection specialist qualified in POPIA and UK GDPR before public launch, particularly to confirm the named Information Officer/contact details, retention periods against actual operational practice, and the international transfer mechanism against current adequacy decisions at time of launch.