1. Introduction
Thank you for using EngageNow.
This Privacy Policy explains how personal information is collected, used, stored, shared and protected when you access or use the EngageNow mobile application, website, organisational workspaces, features and related services.
EngageNow is provided by AI Campus (Pty) Ltd.
When personal information is processed within an organisation’s EngageNow workspace, the relevant organisation will generally be the Responsible Party, as defined by the Protection of Personal Information Act 4 of 2013 (“POPIA”). AI Campus will generally act as the Operator, processing personal information according to the organisation’s documented instructions.
AI Campus acts as the Responsible Party when it processes personal information for its own purposes, including account administration, contracting, billing, technical support, platform security, product improvement, website enquiries and business operations.
This Privacy Policy does not replace any organisation-specific privacy notice, consent form, programme notice or collection notice that an organisation may be required to provide.
2. Who This Privacy Policy Applies To
This Privacy Policy applies to personal information relating to:
- organisation administrators and authorised representatives;
- organisation employees, contractors and team members;
- registered members and invited members;
- community members, citizens, stakeholders and programme participants;
- event attendees and applicants;
- survey, poll and discussion participants;
- donors, campaign supporters, customers and marketplace users;
- persons submitting complaints, incidents, enquiries or service requests;
- suppliers, service providers and business partners;
- visitors to EngageNow websites and applications; and
- persons who communicate directly with AI Campus.
3. Definitions
For purposes of this Privacy Policy:
“Data Subject” means the person to whom personal information relates and includes a juristic person where applicable under POPIA.
“Organisation” means a private body, public body, community, company, non-profit organisation, government body or other entity that uses EngageNow.
“Operator” means a person or entity that processes personal information for a Responsible Party under a contract or mandate.
“Personal Information” means information relating to an identifiable person or, where applicable, an identifiable existing juristic person.
“Platform” means the EngageNow application, website, organisational workspaces, modules, integrations, APIs, infrastructure and related services.
“Processing” includes collecting, receiving, recording, storing, organising, updating, retrieving, using, sharing, restricting, deleting or destroying personal information.
“Responsible Party” means the person or organisation that determines why and how personal information is processed.
“Special Personal Information” includes information concerning health, race or ethnic origin, religious or philosophical beliefs, political persuasion, trade-union membership, sex life, biometric information or criminal behaviour.
“Sub-Operator” means a third-party service provider engaged to process personal information in connection with EngageNow.
4. Personal Information We May Process
The information processed through EngageNow depends on the features enabled by the relevant organisation and how the Platform is used.
4.1 Registration and Profile Information
We may process:
- first name and surname;
- username;
- email address;
- telephone number;
- profile photograph;
- date of birth, where required for a lawful purpose;
- organisation, department, team, position or job title;
- membership number or reference number;
- user role and permissions;
- language and communication preferences;
- account status; and
- authentication and login information.
Passwords are not stored in readable form and are protected using appropriate security methods.
4.2 Organisation and Membership Information
Organisations may process:
- organisation name and registration information;
- organisation type and description;
- address and contact details;
- logos, branding and organisational colours;
- administrator and representative information;
- member records;
- membership categories and statuses;
- invitation records and invitation links;
- QR-code invitation activity;
- member roles, positions and permissions;
- joining, approval, suspension or removal records; and
- membership payment or subscription information, where applicable.
4.3 Posts, Discussions and Community Engagement
When users interact through EngageNow, we may process:
- posts and announcements;
- comments, replies and reactions;
- discussion contributions;
- likes, shares and reposts;
- images, videos, documents and other attachments;
- mentions and tags;
- moderation reports;
- content visibility settings; and
- the date and time of user activity.
Content may be visible to the relevant organisation, selected teams, authorised members or the public, depending on the organisation’s settings and the selected visibility option.
4.4 Surveys, Polls and Feedback
We may process:
- survey and poll responses;
- ratings and feedback;
- questionnaire responses;
- demographic information requested by the organisation;
- respondent identity, where responses are not anonymous;
- submission dates and times; and
- aggregated participation and response statistics.
The organisation must clearly indicate when a survey or poll is anonymous.
4.5 Events and Attendance
We may process:
- event registrations;
- RSVP responses;
- attendance and check-in records;
- ticket or booking information;
- event preferences;
- dietary, accessibility or special requirements where voluntarily provided;
- QR-code attendance records;
- event photographs or recordings where appropriate notice has been provided; and
- event-related communication.
4.6 Incident Reports, Complaints and Service Requests
Where EngageNow allows users to report incidents, complaints, concerns or service-delivery issues, we may process:
- the incident or complaint description;
- incident category and priority;
- location information;
- photographs, videos, voice recordings or supporting documents;
- date and time of the incident;
- reference and tracking numbers;
- assigned department or responsible official;
- comments and status updates;
- contact information of the reporting person;
- information about witnesses or other affected persons; and
- resolution, escalation and audit records.
Users should avoid including unnecessary personal information about other people when submitting a report.
Certain incident reports may be transferred to an authorised third-party incident-management platform used by the relevant organisation.
4.7 Marketplace, Products and Orders
Where marketplace functions are enabled, we may process:
- product and service listings;
- seller or organisation information;
- customer contact details;
- order details and transaction history;
- delivery or collection information;
- billing details;
- payment status and transaction references;
- refund, cancellation and dispute information;
- ratings and reviews; and
- communication between authorised buyers and sellers.
Payment-card information may be processed directly by an authorised payment-service provider and may not be stored by EngageNow.
4.8 Donations and Campaigns
Where fundraising or donation features are enabled, we may process:
- donor identity and contact information;
- donation amount and date;
- payment status and transaction reference;
- selected campaign;
- recurring-donation preferences;
- donor messages;
- anonymous-donation preferences;
- campaign updates and supporter activity; and
- records required for financial, legal or audit purposes.
4.9 Advertisements and Promotional Content
Where advertisements or promotional content are available, we may process:
- advertisement content;
- campaign start and end dates;
- target audience settings;
- budget and placement information;
- impressions, clicks and interactions;
- general location or organisation membership; and
- campaign-performance statistics.
We will not use personal information for direct electronic marketing without an appropriate lawful basis or consent where consent is required.
4.10 Location Information
EngageNow may process location information when:
- a user submits an incident or service request;
- location is required to identify the relevant organisation or service area;
- a user checks in at an event;
- the user chooses to attach a location to content; or
- a location-based feature has been enabled.
Precise device location will only be accessed when the user grants the required device permission.
Users may disable location permissions through their device settings, although certain features may then be unavailable.
4.11 Device and Technical Information
We may process:
- device type and model;
- operating system;
- browser information;
- application version;
- device identifiers;
- IP address;
- network information;
- login records;
- system and application logs;
- crash reports;
- API and integration logs;
- performance and diagnostic information; and
- security-monitoring records.
4.12 Support and Communication Records
We may process:
- support requests;
- emails and messages;
- telephone-call information;
- troubleshooting information;
- feedback and complaints;
- account-recovery records; and
- communication preferences.
4.13 AI Campus Business Records
Where AI Campus acts as Responsible Party, we may process:
- customer and supplier contact details;
- contracts and correspondence;
- billing, tax and payment information;
- sales and account-management records;
- support and service-management records;
- website enquiries;
- recruitment information;
- job applications and interview records; and
- security and access-control records.
5. Special Personal Information
AI Campus does not intentionally require users to provide special personal information unless it is necessary for an authorised and lawful purpose.
However, users or organisations may upload content containing special personal information, particularly through incident reports, surveys, complaints, events or supporting documents.
The relevant organisation is responsible for ensuring that it has a lawful basis and any required authorisation to process special personal information.
Users should not upload special personal information unless it is necessary and authorised.
7. Sources of Personal Information
Personal information may be collected:
- directly from the Data Subject;
- from the relevant organisation;
- from an organisation administrator or authorised team member;
- from another user who is authorised to provide the information;
- through invitation, registration and membership processes;
- through posts, forms, surveys, polls, events and incident reports;
- through integrations configured by an organisation;
- from payment providers and authorised service providers;
- automatically through use of the Platform;
- through support and security processes; and
- from public or official sources where lawfully permitted.
When information is not collected directly from the Data Subject, the relevant Responsible Party must meet any applicable notification requirements.
10. Mandatory and Voluntary Information
Some information is required to:
- register an account;
- verify a user;
- join an organisation;
- perform an organisational process;
- submit or manage a transaction;
- comply with legal requirements; or
- provide a requested service.
Where required information is not provided, the user may be unable to create an account, access an organisation, complete a transaction or use a particular feature.
Optional fields will generally be identified as optional.
11. Data Minimisation and Information Quality
We aim to ensure that personal information is adequate, relevant and not excessive for its intended purpose.
Organisations are responsible for configuring EngageNow appropriately and deciding what information they require from users.
Users and organisations must take reasonable steps to ensure that personal information is accurate, complete, not misleading and updated where necessary.
8. Why We Process Personal Information
Personal information may be processed to:
- create and manage user accounts;
- verify identity and authenticate users;
- create and administer organisation workspaces;
- manage members, invitations, roles and permissions;
- provide organisation-specific content and services;
- publish posts, announcements and notifications;
- facilitate discussions, surveys, polls and feedback;
- create and manage events and attendance;
- receive and track incidents, complaints and service requests;
- manage products, orders, donations, campaigns and advertisements;
- process payments through authorised payment providers;
- communicate with users;
- provide technical and customer support;
- maintain audit trails and activity histories;
- monitor security and prevent fraud or misuse;
- diagnose errors and improve system performance;
- generate reports, analytics and aggregated statistics;
- comply with legal, contractual and regulatory obligations;
- enforce platform rules and organisational policies; and
- protect the rights, safety and property of users, organisations and AI Campus.
9. Lawful Grounds for Processing
Depending on the circumstances, personal information may be processed:
- with the Data Subject’s consent;
- to perform a contract;
- to comply with a legal obligation;
- to protect a legitimate interest of the Data Subject;
- to pursue the legitimate interests of the Responsible Party or a third party;
- to perform a public-law duty; or
- under another lawful basis permitted by POPIA.
Where consent is relied upon, it may be withdrawn, subject to legal or contractual limitations and the consequences of withdrawal.
18. Automated Processing and Analytics
EngageNow may generate automated indicators, summaries and analytics, including:
- participation statistics;
- engagement levels;
- event-attendance statistics;
- survey and poll summaries;
- incident volumes and response times;
- task or workflow completion indicators;
- marketplace and order statistics;
- campaign and donation statistics; and
- system-usage and performance reports.
These outputs are generally intended to assist authorised users with reporting and decision-making.
EngageNow will not make a decision that produces legal or similarly significant effects solely through automated processing unless the processing is lawful and appropriate safeguards are in place.
19. Notifications and Direct Marketing
EngageNow may send:
- account and security notifications;
- organisation announcements;
- membership invitations;
- event reminders;
- incident or complaint status updates;
- order or payment updates;
- service notifications; and
- other communications related to the user’s use of the Platform.
Users may manage certain notification preferences through the Platform or device settings.
Essential account, security, legal and transactional communications may still be sent even where optional notifications are disabled.
Marketing communications will be sent only where permitted by law.
Users may opt out using the unsubscribe method provided in the communication.
20. Cookies and Similar Technologies
The EngageNow website or web-based services may use cookies, local storage and similar technologies to:
- keep users signed in;
- remember preferences;
- support security;
- understand Platform usage;
- diagnose technical issues; and
- improve functionality.
Users may control cookies through browser settings, although disabling required cookies may affect Platform functionality.
12. Information Sharing
Personal information may be shared with:
- the relevant organisation;
- organisation administrators;
- authorised employees, contractors or team members;
- other users, according to content and visibility settings;
- approved service providers and Sub-Operators;
- hosting and cloud-infrastructure providers;
- email, SMS and notification providers;
- payment-service providers;
- analytics, monitoring and security providers;
- incident-management or service-delivery platforms;
- professional advisers, auditors and insurers;
- law-enforcement bodies, regulators or courts where legally required; and
- a successor or purchaser in connection with a lawful business transfer.
Service providers are only authorised to process personal information for agreed purposes and must implement appropriate privacy and security protections.
We do not sell personal information.
13. Organisation Visibility and Public Content
Information submitted within a private organisation workspace will generally be accessible only to authorised members of that organisation.
However, certain information may be made public where:
- the user selects a public-posting option;
- the organisation publishes public content;
- an event, campaign, product, advertisement or portal is publicly accessible; or
- public visibility is clearly indicated before submission.
Users should review the selected audience before publishing content.
14. International Transfers
Some service providers or hosting systems may process information outside South Africa.
Where personal information is transferred outside South Africa, the Responsible Party will take reasonable steps to ensure that the transfer complies with POPIA, including using appropriate contractual protections or transferring information to a recipient subject to an adequate level of protection.
25. Third-Party Services and Links
EngageNow may contain links to or integrations with third-party services.
Those third parties may process personal information under their own privacy policies.
AI Campus is not responsible for the privacy practices of independent third parties.
Users should review the privacy notices of third-party services before providing information to them.
15. Data Security
Reasonable technical and organisational safeguards are used to protect personal information against loss, damage, unauthorised access, interference, misuse, alteration or disclosure.
Measures may include:
- access controls;
- role- and permission-based restrictions;
- password protection;
- encryption where appropriate;
- secure network communication;
- audit logging;
- backups;
- vulnerability management;
- security monitoring;
- incident-response procedures; and
- contractual confidentiality and security obligations.
No electronic system can be guaranteed to be completely secure.
Users must keep their login details confidential and immediately report suspected unauthorised access.
16. Security Compromises
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, AI Campus will notify the relevant Responsible Party as soon as reasonably possible.
The Responsible Party will be responsible for notifying the Information Regulator and affected Data Subjects where required by law.
Where AI Campus is the Responsible Party, AI Campus will make the required notifications.
17. Data Retention
Personal information will be retained only for as long as reasonably necessary to:
- provide the Platform and requested services;
- fulfil the purpose for which it was collected;
- comply with legal, regulatory, contractual and audit obligations;
- resolve disputes;
- enforce agreements;
- maintain security records; or
- establish, exercise or defend legal claims.
Retention periods may differ depending on the type of information and the organisation’s requirements.
When information is no longer required, it may be deleted, destroyed, anonymised or de-identified, subject to legal and technical limitations.
Organisation administrators may determine retention periods for information within their workspaces.
21. Data-Subject Rights
Subject to POPIA and any applicable limitations, Data Subjects may have the right to:
- request confirmation that their personal information is being processed;
- request access to their personal information;
- request correction or updating of inaccurate information;
- request deletion or destruction of information that may no longer lawfully be retained;
- object to certain processing;
- withdraw consent where consent is the basis for processing;
- object to direct marketing;
- request information about third parties who have had access to their information;
- lodge a complaint with the Responsible Party; and
- lodge a complaint with the Information Regulator.
Requests concerning information controlled by an organisation should ordinarily be directed to that organisation.
AI Campus may refer a request to the relevant organisation where AI Campus acts only as the Operator.
Identity verification may be required before a request is completed.
22. Correcting Personal Information
Users may be able to update certain profile information directly through their accounts.
For information that cannot be changed through the Platform, users should contact their organisation administrator or the EngageNow support team.
Certain historical, transaction, security or audit records may not be editable but may be supplemented with a correction record where appropriate.
24. User Responsibilities
Users must:
- provide accurate information;
- protect account credentials;
- use the Platform only for authorised and lawful purposes;
- avoid uploading unnecessary personal information;
- obtain permission before submitting another person’s information where required;
- respect the privacy of other users;
- avoid publishing confidential information in public areas; and
- report suspected misuse or security incidents.
6. Children’s Personal Information
EngageNow is not intended for use by children without appropriate authorisation and supervision.
Where an organisation uses EngageNow for programmes involving children, the organisation is responsible for:
- establishing a lawful basis for processing children’s information;
- obtaining consent from a competent person where required;
- providing an appropriate privacy notice;
- limiting access to authorised persons;
- implementing suitable security measures; and
- ensuring that only necessary information is collected.
AI Campus may remove or restrict access to children’s information where it has been processed without appropriate authority.
Steps to Deactivate Your Account
- Log in to your account.
- Navigate to your profile icon (in the top-right corner).
- Click on the profile icon to open the menu.
- Select Deactivate Account.
- Follow any confirmation prompts to complete the process.
27. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- changes to EngageNow;
- new features or integrations;
- changes to legal or regulatory requirements;
- changes to our business practices; or
- improvements to privacy and security procedures.
The updated policy will be made available through the Platform and will indicate the latest revision date.
Where material changes affect users’ rights or the way personal information is processed, reasonable steps will be taken to provide notice.