Skip to content
Legal · draft, pre-launch

Privacy statement

What personal information the platform processes, on what basis, who it is shared with, and how long it is kept — under South Africa's POPIA and, where relevant, the UK and EU GDPR.

This is a pre-launch draft. It describes the platform’s actual data handling accurately and has not yet been through legal review. It is published in this state because it is more useful to you as a draft than as a blank page, and because the alternative — a boilerplate statement that does not describe this system — would be worse. The reviewed version, and the data-processing agreement that accompanies it, are executed at contract.

Who we are

RhinocerosAI operates an AI-search visibility monitoring platform sold to marketing agencies. For most of the data described here we are an operator under POPIA and a processor under the GDPR: the agency is the responsible party, and it decides what brands and prompts are configured. For our own account and billing records we are the responsible party ourselves.

What we process

CategoryExamplesWhy
Account dataName, work email address, role, agency membership, authentication recordsTo provide the service and control access
Usage dataSign-in events, pages requested, API calls, correlation identifiersSecurity, abuse prevention, and diagnosing failures
Configuration dataBrands, owned-domain sets, aliases, competitor sets, prompt textIt is the measurement configuration — supplied by the agency
Captured answersVerbatim AI engine output and its provenanceProvenance and auditability. Answers are about public brands, but AI output is unpredictable and may incidentally name individuals
Billing dataAgency legal entity, billing contact, invoicesContract performance and tax obligations

We do not collect data about your clients' website visitors, we install nothing on your clients' sites, and we operate no tracking pixels.

Lawful basis

  • Contract performance — account, configuration and billing data. We cannot provide the service without them.
  • Legitimate interest — usage and security logging, and retaining captured answers as the evidence base for figures already delivered. A balancing assessment is maintained for this and is available to an agency on request.
  • Legal obligation — financial records retained for statutory periods.

Sharing and cross-border transfer

Sub-processors are listed in full, with region, on our security page. Three of them — answer acquisition, worker orchestration and log storage — process data in the United States. That is a cross-border transfer under POPIA section 72 and under Chapter V of the GDPR, and it is disclosed rather than buried. We do not sell data, and we do not share it with anyone outside that list.

Prompts, configuration, captured answers and results are never used to train AI models — ours or a vendor's. Vendor arrangements are selected on that basis.

Retention

DataKept for
Result rows — scores, counts, classificationsThe life of the account. They are the trend line; deleting them retroactively invalidates reports already delivered.
Captured answer payloads12 months on a rolling window, or until erasure is requested — whichever is sooner. A tombstone remains.
Application logs30 days
Account recordsLife of the account, then 90 days
Billing recordsAs required by law

Your rights

Under POPIA and the GDPR you may request access to your personal information, correction of it, deletion, restriction of processing, portability, and you may object to processing carried out on legitimate-interest grounds.

Where we act as operator or processor, requests from an agency's own client should be directed to the agency, and we will support them in answering it. Requests about your own account data can be sent directly to privacy@rhinoceros.africa. We respond within 30 days.

You may also complain to the Information Regulator of South Africa, or to your own supervisory authority in the UK or EU.

Security

Tenant isolation is the platform's critical control and is described in detail on the security page, together with an honest list of what we have not yet done — including the absence of a SOC 2 or ISO 27001 certification, which we are not going to imply we hold.

Changes

Material changes to this statement are notified to agencies on the platform before they take effect, and appear in the public changelog with a date.

Contact

privacy@rhinoceros.africa for privacy matters; security@rhinoceros.africa for vulnerability reports.