Protoworks Group (Pty) Ltd, registration number 2026/556877/07
Protoworks Defence (Pty) Ltd, registration number 2026/524692/07
Version 1.0, 25 September 2026.
This notice tells you what personal information we process, why, who sees it, and what you can do about it. It is written to meet section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). For people in the European Union, the European Economic Area and the United Kingdom, it is also written to meet Articles 13 and 14 of the General Data Protection Regulation (GDPR) and of the UK GDPR. POPIA says "personal information" where the GDPR says "personal data". In this notice they mean the same thing.
1. Who we are
Both companies are private companies registered in South Africa. Protoworks Group (Pty) Ltd is the holding company of the Protoworks group. Protoworks Defence (Pty) Ltd is a subsidiary that owns and licenses the Panoptes platform. Each is the responsible party under POPIA, and the controller under the GDPR, for its own processing:
| Processing | Responsible party and controller |
|---|---|
| The protoworks.dev website, including the notify form | Protoworks Group (Pty) Ltd |
| Email to general protoworks.dev addresses, such as hello@, legal@ and privacy@ | Protoworks Group (Pty) Ltd |
| The defence.protoworks.dev and secops.protoworks.dev websites | Protoworks Defence (Pty) Ltd |
| Email to defence@ and secops@, and all client correspondence about Panoptes | Protoworks Defence (Pty) Ltd |
| Information the Panoptes platform collects from public sources (Part B) | Protoworks Defence (Pty) Ltd |
In this notice "we" means whichever of the two companies is responsible for the processing concerned.
Richard Peters is the Information Officer of both companies and handles every privacy question and request. Write to privacy@protoworks.dev.
Part A: People who visit our websites or contact us
2. What we collect and where it comes from
| Information | Where it comes from | When |
|---|---|---|
| IP address, browser type, the page you asked for, the time, and whether our firewall allowed or blocked the request | Your browser, recorded by our hosting provider | Every time you load a page |
| Your name and email address as your mail program sends them, and what you write | You | When you email us |
| Your email address, the time you sent it, and the browser description your browser sent with it (the user agent) | You and your browser | When you use the "Get notified" form on protoworks.dev |
Our websites set no cookies and store nothing on your device. They run no analytics, advertising or tracking code, and load nothing from third-party servers. Because nothing is stored on your device, we do not ask for cookie consent.
Giving us information is voluntary. No law or contract requires you to. If you do not, we cannot reply to you or send you the notes you asked for. You can read the websites without giving us anything beyond what your browser sends with every request.
Our websites are not aimed at children, and we do not knowingly collect information from children through them.
3. Why we use it
- To deliver the websites and keep them secure. Request records let us block attacks, investigate incidents and prove what happened.
- To reply to you and keep a record of what we said to each other.
- To send you the occasional notes you asked for through the notify form, when the studio opens an engagement window, publishes notes, or ships a venture. We send nothing else to that address and give it to no one else.
4. Our lawful basis
| Purpose | POPIA | GDPR |
|---|---|---|
| Request and firewall records | Legitimate interest, section 11(1)(f) | Legitimate interests, Article 6(1)(f) |
| Replying to your email | Your consent, section 11(1)(a), or steps you asked for before a contract, section 11(1)(b) | Steps you asked for before a contract, Article 6(1)(b), where you ask about working with us; otherwise legitimate interests, Article 6(1)(f) |
| The notify form | Your consent, section 11(1)(a) | Your consent, Article 6(1)(a) |
Our legitimate interests here are keeping the websites available and secure, finding and stopping attacks on them, and answering the people who write to us. We have weighed these against your interests. Request records are kept for a short time, only named staff can see them, and we use them for nothing else. You can object to this processing (section 15).
You can withdraw your consent to the notify form at any time by replying to any email we send you with the word unsubscribe, or by writing to privacy@protoworks.dev. We then delete your address. Withdrawing does not make anything we did before unlawful.
5. Who sees it
We use these operators, which the GDPR calls processors. Each processes the information only on our instructions and under written terms that require it to keep the information secure (POPIA sections 20 and 21, GDPR Article 28).
| Operator | What it does for us | Where the information is held |
|---|---|---|
| Google Cloud | Hosts the websites, runs the firewall, stores request records | Johannesburg, South Africa |
| Google Workspace | Google data centres, which may be outside South Africa |
We do not sell personal information and we do not share it for marketing. We give it to a public body only where a law requires us to.
6. Information sent outside South Africa
Email may be stored in Google data centres outside South Africa. Google processes it under its data processing terms, which bind it to protection substantially similar to POPIA. That is the basis for the transfer under section 72(1)(b). Website hosting and request records stay in Johannesburg.
If you are in the EU, the EEA or the UK, the information you send when you visit our websites or write to us comes to us in South Africa. The European Commission and the UK have not found that South African law gives adequate protection. We protect it in the ways this notice describes. Where Google holds email outside South Africa, its data processing terms include the European Commission's standard contractual clauses and the UK addendum to them. You can ask privacy@protoworks.dev for a copy of these safeguards.
7. How long we keep it
| Information | Kept for |
|---|---|
| Request and firewall records | 30 days in the hosting project, and 90 days in our central log store, then deleted automatically |
| As long as the conversation needs, then deleted, unless a law requires us to keep it longer | |
| Notify form address | In our mailbox until you unsubscribe or ask us to delete it. It is not written to our logs |
8. How we protect it
Every connection to our websites is encrypted (TLS, with HSTS). A web application firewall screens every request. Only named people can reach the information, each with two-step verification, and every access to our cloud systems is logged.
If a security compromise affects your information, we tell you and the Information Regulator as POPIA section 22 requires. Where the GDPR applies, we also tell the supervisory authority within 72 hours of becoming aware of it, and we tell you without undue delay if the compromise is likely to put your rights at high risk (GDPR Articles 33 and 34).
Part B: Information our platform collects about people from public sources
9. What the platform is
We build Panoptes, an intelligence platform. Security providers and law-enforcement clients use it to investigate organised crime, fraud and threats to people and property.
10. What it collects and where it comes from
The platform collects information that has been made public. Its sources include:
- news reports and other published articles;
- company, court and other public registers;
- public websites and public forums;
- public social media posts and profiles; and
- data that others have already published, including data released after security breaches.
From these sources it records details that identify people and link them to one another: names and aliases, usernames, email addresses, phone numbers, physical addresses, company roles, and published allegations or records of criminal conduct. Where a source reveals special categories of information, such as political opinions, religious beliefs or health, the platform records what the source contains. We record the source of every item.
We do not collect this information from you directly, so you did not give it to us voluntarily and there is no form you were asked to fill in.
11. Why
To help our clients detect, investigate and prevent crime, fraud and threats to the safety of people and property, and to support due diligence on companies and the people behind them. These are our legitimate interests, and those of our clients.
12. Who sees it
- Clients who use the platform under a written contract that limits them to lawful use.
- Public bodies, where a law requires us to disclose information.
- Operators that work for us under written terms, in these categories: hosting and storage providers, providers of automated text analysis, and providers that collect public web and social media content. Our own servers and our stored source documents are in South Africa. Some operators are outside South Africa, including in the European Union and the United States. We send information to them only as POPIA section 72 allows and, for information about people in the EU or the UK, under a safeguard that GDPR Chapter V recognises.
We describe our operators and sources by category, and do not name them. A list of the suppliers, feeds and methods the platform uses would show the people it helps investigate how to hide from it, and would expose the platform to attack. POPIA section 18(4)(c)(i) and (d) and GDPR Article 14(5)(b) allow us to withhold detail that would prejudice the prevention and detection of crime or seriously impair the purpose of the processing.
13. Lawful basis
Under POPIA we rely on the legitimate interests in section 11 (section 11(1)(f)). We process information about criminal behaviour under section 33(1), because we obtain it lawfully from public sources. Where a person has deliberately made special personal information public, we rely on section 27(1)(d).
Under the GDPR our basis is legitimate interests (Article 6(1)(f)). Where a person has manifestly made special category information public themselves, we rely on Article 9(2)(e).
14. How the platform uses software, how long it keeps information, and why we did not tell you directly
The platform uses software, including machine-learning models, to read text, pick out names and other identifiers, and link records that appear to concern the same person. The GDPR calls this profiling. The platform does not make decisions about you. It gives its output to people at our clients, who decide what to do with it. Every claim the platform records carries a status. A claim from one source is marked as reported. It moves up only when independent sources agree, and a person must approve it before the platform names anyone as a suspect or perpetrator.
We keep an item while it stays relevant to a purpose in section 11. We delete or correct it when it is no longer needed for one, when it is shown to be wrong, or when a successful objection or deletion request requires it.
The GDPR normally requires us to tell you, within a month, that we hold information about you that we did not get from you. The platform collects from public sources at a scale where we usually have no reliable way to contact the people named, and telling a person that they appear in an investigation can defeat the purpose of preventing crime. For both reasons we publish this notice instead of writing to each person, as GDPR Article 14(5)(b) and POPIA section 18(4)(c)(i), (d) and (e) allow, and we protect the information as section 8 describes.
Your rights (Parts A and B)
15. Your right to object
You can object at any time, for reasons that relate to your own situation, to processing that we base on legitimate interests. That covers our request records (Part A) and the platform (Part B). When you object, we stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or we need the information to establish, exercise or defend a legal claim (POPIA section 11(3)(a), GDPR Article 21(1)).
If we ever use your information for direct marketing, you can object at any time, without giving a reason, and we will stop (POPIA section 11(3)(b), GDPR Article 21(2)).
To object, email privacy@protoworks.dev.
16. What else you can ask us to do
You have the right to:
- ask whether we hold personal information about you, and for a copy of it (POPIA section 23, GDPR Article 15);
- ask us to correct information that is inaccurate, out of date or incomplete (POPIA section 24, GDPR Article 16);
- ask us to delete information that is misleading, unlawfully held, or no longer needed (POPIA section 24, GDPR Article 17);
- ask us to restrict processing while we check a complaint about accuracy or an objection (GDPR Article 18);
- receive the information you gave us, in a machine-readable format, where our basis is your consent or a contract (GDPR Article 20). In practice this is the address you gave the notify form; and
- withdraw your consent, where consent is our basis (GDPR Article 7(3)).
Neither company makes decisions about you based only on automated processing that have legal effects for you or affect you in a similarly significant way (GDPR Article 22).
Email privacy@protoworks.dev. You do not have to use a prescribed form; an email that tells us who you are and what you want is enough. If you prefer the forms, they are POPIA Form 1 (objection) and Form 2 (correction or deletion), and PAIA Form 2 for a copy of records. We may ask you to prove your identity before we act, so that we never give your information to someone else.
We answer within one month. If a request is complex, or you send us several, we may take up to two more months, and if so we tell you why within the first month. We do not charge for this, unless a request is clearly unfounded or excessive. If we refuse a request, we tell you why and how to challenge the decision.
17. Complaints
If you are not satisfied with how we handle your information, tell our Information Officer first, at privacy@protoworks.dev. We acknowledge a complaint within 30 days and tell you the outcome without undue delay.
You also have the right to complain to a regulator at any time.
In South Africa:
Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone 010 023 5200, toll free 0800 017 160
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
https://inforegulator.org.za
In the EU and the EEA, the data protection authority of the country where you live or work, or where you believe the problem happened. The European Data Protection Board lists them at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
In the UK, the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/
18. Changes to this notice
When this notice changes, we publish the new version here with a new version number and date. Each company's PAIA manual, published beside this notice, lists the records it holds and explains how to ask for access to them.