Governance, Privacy & Data Protection Framework
TFI's integrated framework covering privacy and data protection, cookies, access to information (PAIA), AI ethics, and data processing obligations.
1. Introduction
TFI ("TFI", "we", "us", "our") is committed to safeguarding personal information, ensuring transparency, and maintaining the highest standards of data governance across all digital, AI, telecom, and platform services.
This document integrates:
- Privacy and data protection principles
- Access to information processes
- Ethical AI commitments
- Data processing obligations
2. Organisational Overview
TFI is an end-to-end technology solutions provider delivering digital transformation platforms, AI and automation solutions, telecom and contact centre services, and systems integration and data ecosystems. TFI enables seamless, modular, and scalable digital services across industries.
Section A: Privacy & Data Protection
3. Personal Information We Collect
3.1 Information provided by users: name and surname, email address, contact details, company and role, enquiry or service requirements.
3.2 Automatically collected information: IP address, device and browser data, website usage behaviour, cookies and tracking identifiers.
3.3 Advanced data (platform & AI services): transactional data, customer interaction data (chat, voice, digital channels), AI inputs and outputs, integration and API data.
4. Purpose of Processing
- Deliver services — respond to enquiries, provide solutions, and manage contracts
- Enable technology platforms — operate AI, automation, and telecom solutions; facilitate system integrations
- Improve services — analytics, optimisation, and AI model enhancement
- Marketing & communication — share insights and offerings (with consent)
- Legal & compliance — meet regulatory obligations, prevent fraud, and ensure security
5. Legal Basis for Processing
TFI relies on: consent, contractual necessity, legitimate interest, and legal obligations.
6. Data Sharing & Disclosure
TFI does not sell personal data. Data may be shared with internal entities, trusted service providers within the TFI ecosystem, integration partners, and regulatory authorities where required.
7. International Data Transfers
Personal data will not be processed outside South Africa without signed consent, adequate safeguards, contractual protections, and secure hosting environments.
8. Data Retention
TFI retains data only as long as necessary and in line with legal and contractual requirements. Data is anonymised or securely deleted where possible.
9. Data Subject Rights
Individuals have the right, via email request, to access their data, correct inaccuracies, request deletion, object to processing, and withdraw consent.
10. Data Security
TFI implements encryption, access controls, monitoring and detection systems, and secure infrastructure.
Section B: Cookie Policy
11. Cookie Usage
TFI uses cookies to enhance website functionality and user experience.
12. Types of Cookies
- Essential cookies — required for core functionality
- Performance cookies — track usage and analytics
- Functional cookies — store user preferences
- Marketing cookies — enable targeted content and advertising
13. Advanced Tracking
TFI platforms may include behavioural analytics, session tracking, API-level monitoring, and AI-driven interaction tracking.
14. Cookie Management
Users can accept or reject cookies via the banner, adjust browser settings, and delete stored cookies.
Section C: PAIA Manual (Access to Information)
15. Purpose of the Manual
This section enables access to information in accordance with the Promotion of Access to Information Act (PAIA).
16. Records Available Without Request
Website content, marketing materials, and public documentation.
17. Records Available Upon Request
- Internal records — policies and governance documents
- Client records — contracts and service documentation
- Technology records — system logs, platform and AI processing data
18. Request Procedure
To request access: complete the PAIA request form, submit online via email, pay applicable fees, and await a response within statutory timelines.
19. Grounds for Refusal
Requests may be denied if privacy is compromised, confidential or proprietary data is involved, or security risks arise.
20. Remedies
Requesters may lodge internal appeals (if applicable) or escalate to the Information Regulator.
Section D: AI Ethics & Responsible AI
21. AI Ethics Principles
- Transparency — clear disclosure of AI usage
- Fairness — bias detection and mitigation
- Accountability — human oversight and governance
- Privacy — compliance with POPIA
- Security — protection against AI threats
22. Responsible AI Use Cases
Customer engagement (chatbots, call centres), fraud detection, predictive analytics, and process automation.
23. Prohibited Uses
TFI prohibits discriminatory profiling, unlawful surveillance, and manipulative AI practices.
24. Human-Centric AI
AI supports human decision-making and does not replace critical judgement.
Section E: Data Processing Agreement (DPA)
25. Parties
TFI (Processor) and Client (Controller).
26. Scope of Processing
Applies to digital platforms, AI services, telecom and contact centre solutions, and data integration services.
27. Data Types
Personal data, contact information, behavioural and interaction data, and transactional data.
28. Processing Activities
Collection, storage, analysis, transmission, and AI-driven processing.
29. Security Measures
Encryption, access control, monitoring and logging, and incident response.
30. Subprocessors
TFI may engage third parties subject to contractual safeguards and compliance requirements.
31. Cross-Border Transfers
Handled with legal safeguards, secure frameworks, and regulatory adherence.
32. Data Breach Management
TFI will notify clients promptly, provide full incident details, and support remediation.
33. Data Retention & Deletion
Data is retained only as necessary and deleted securely upon termination.
34. Audit Rights
Clients may request audits and review compliance evidence.
35. Liability & Termination
Each party is responsible for its own compliance. Data is returned or deleted upon termination.
36. Updates to This Framework
TFI may update this document periodically to reflect regulatory changes, technology advancements, and business evolution.
37. Conclusion
This integrated framework reflects TFI's commitment to trust and transparency, responsible innovation, regulatory compliance, and secure, ethical, and scalable digital services.
Privacy queries: legal@technologyfrontierinternational.com