Protoworks / Legal / Privacy

Privacy notice

Protoworks Group (Pty) Ltd, registration number 2026/556877/07
Protoworks Defence (Pty) Ltd, registration number 2026/524692/07

Version 1.0, 25 September 2026.

This notice tells you what personal information we process, why, who sees it, and what you can do about it. It is written to meet section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). For people in the European Union, the European Economic Area and the United Kingdom, it is also written to meet Articles 13 and 14 of the General Data Protection Regulation (GDPR) and of the UK GDPR. POPIA says "personal information" where the GDPR says "personal data". In this notice they mean the same thing.

1. Who we are

Both companies are private companies registered in South Africa. Protoworks Group (Pty) Ltd is the holding company of the Protoworks group. Protoworks Defence (Pty) Ltd is a subsidiary that owns and licenses the Panoptes platform. Each is the responsible party under POPIA, and the controller under the GDPR, for its own processing:

Processing Responsible party and controller
The protoworks.dev website, including the notify form Protoworks Group (Pty) Ltd
Email to general protoworks.dev addresses, such as hello@, legal@ and privacy@ Protoworks Group (Pty) Ltd
The defence.protoworks.dev and secops.protoworks.dev websites Protoworks Defence (Pty) Ltd
Email to defence@ and secops@, and all client correspondence about Panoptes Protoworks Defence (Pty) Ltd
Information the Panoptes platform collects from public sources (Part B) Protoworks Defence (Pty) Ltd

In this notice "we" means whichever of the two companies is responsible for the processing concerned.

Richard Peters is the Information Officer of both companies and handles every privacy question and request. Write to privacy@protoworks.dev.

Part A: People who visit our websites or contact us

2. What we collect and where it comes from

Information Where it comes from When
IP address, browser type, the page you asked for, the time, and whether our firewall allowed or blocked the request Your browser, recorded by our hosting provider Every time you load a page
Your name and email address as your mail program sends them, and what you write You When you email us
Your email address, the time you sent it, and the browser description your browser sent with it (the user agent) You and your browser When you use the "Get notified" form on protoworks.dev

Our websites set no cookies and store nothing on your device. They run no analytics, advertising or tracking code, and load nothing from third-party servers. Because nothing is stored on your device, we do not ask for cookie consent.

Giving us information is voluntary. No law or contract requires you to. If you do not, we cannot reply to you or send you the notes you asked for. You can read the websites without giving us anything beyond what your browser sends with every request.

Our websites are not aimed at children, and we do not knowingly collect information from children through them.

3. Why we use it

4. Our lawful basis

Purpose POPIA GDPR
Request and firewall records Legitimate interest, section 11(1)(f) Legitimate interests, Article 6(1)(f)
Replying to your email Your consent, section 11(1)(a), or steps you asked for before a contract, section 11(1)(b) Steps you asked for before a contract, Article 6(1)(b), where you ask about working with us; otherwise legitimate interests, Article 6(1)(f)
The notify form Your consent, section 11(1)(a) Your consent, Article 6(1)(a)

Our legitimate interests here are keeping the websites available and secure, finding and stopping attacks on them, and answering the people who write to us. We have weighed these against your interests. Request records are kept for a short time, only named staff can see them, and we use them for nothing else. You can object to this processing (section 15).

You can withdraw your consent to the notify form at any time by replying to any email we send you with the word unsubscribe, or by writing to privacy@protoworks.dev. We then delete your address. Withdrawing does not make anything we did before unlawful.

5. Who sees it

We use these operators, which the GDPR calls processors. Each processes the information only on our instructions and under written terms that require it to keep the information secure (POPIA sections 20 and 21, GDPR Article 28).

Operator What it does for us Where the information is held
Google Cloud Hosts the websites, runs the firewall, stores request records Johannesburg, South Africa
Google Workspace Email Google data centres, which may be outside South Africa

We do not sell personal information and we do not share it for marketing. We give it to a public body only where a law requires us to.

6. Information sent outside South Africa

Email may be stored in Google data centres outside South Africa. Google processes it under its data processing terms, which bind it to protection substantially similar to POPIA. That is the basis for the transfer under section 72(1)(b). Website hosting and request records stay in Johannesburg.

If you are in the EU, the EEA or the UK, the information you send when you visit our websites or write to us comes to us in South Africa. The European Commission and the UK have not found that South African law gives adequate protection. We protect it in the ways this notice describes. Where Google holds email outside South Africa, its data processing terms include the European Commission's standard contractual clauses and the UK addendum to them. You can ask privacy@protoworks.dev for a copy of these safeguards.

7. How long we keep it

Information Kept for
Request and firewall records 30 days in the hosting project, and 90 days in our central log store, then deleted automatically
Email As long as the conversation needs, then deleted, unless a law requires us to keep it longer
Notify form address In our mailbox until you unsubscribe or ask us to delete it. It is not written to our logs

8. How we protect it

Every connection to our websites is encrypted (TLS, with HSTS). A web application firewall screens every request. Only named people can reach the information, each with two-step verification, and every access to our cloud systems is logged.

If a security compromise affects your information, we tell you and the Information Regulator as POPIA section 22 requires. Where the GDPR applies, we also tell the supervisory authority within 72 hours of becoming aware of it, and we tell you without undue delay if the compromise is likely to put your rights at high risk (GDPR Articles 33 and 34).

Part B: Information our platform collects about people from public sources

9. What the platform is

We build Panoptes, an intelligence platform. Security providers and law-enforcement clients use it to investigate organised crime, fraud and threats to people and property.

10. What it collects and where it comes from

The platform collects information that has been made public. Its sources include:

From these sources it records details that identify people and link them to one another: names and aliases, usernames, email addresses, phone numbers, physical addresses, company roles, and published allegations or records of criminal conduct. Where a source reveals special categories of information, such as political opinions, religious beliefs or health, the platform records what the source contains. We record the source of every item.

We do not collect this information from you directly, so you did not give it to us voluntarily and there is no form you were asked to fill in.

11. Why

To help our clients detect, investigate and prevent crime, fraud and threats to the safety of people and property, and to support due diligence on companies and the people behind them. These are our legitimate interests, and those of our clients.

12. Who sees it

We describe our operators and sources by category, and do not name them. A list of the suppliers, feeds and methods the platform uses would show the people it helps investigate how to hide from it, and would expose the platform to attack. POPIA section 18(4)(c)(i) and (d) and GDPR Article 14(5)(b) allow us to withhold detail that would prejudice the prevention and detection of crime or seriously impair the purpose of the processing.

13. Lawful basis

Under POPIA we rely on the legitimate interests in section 11 (section 11(1)(f)). We process information about criminal behaviour under section 33(1), because we obtain it lawfully from public sources. Where a person has deliberately made special personal information public, we rely on section 27(1)(d).

Under the GDPR our basis is legitimate interests (Article 6(1)(f)). Where a person has manifestly made special category information public themselves, we rely on Article 9(2)(e).

14. How the platform uses software, how long it keeps information, and why we did not tell you directly

The platform uses software, including machine-learning models, to read text, pick out names and other identifiers, and link records that appear to concern the same person. The GDPR calls this profiling. The platform does not make decisions about you. It gives its output to people at our clients, who decide what to do with it. Every claim the platform records carries a status. A claim from one source is marked as reported. It moves up only when independent sources agree, and a person must approve it before the platform names anyone as a suspect or perpetrator.

We keep an item while it stays relevant to a purpose in section 11. We delete or correct it when it is no longer needed for one, when it is shown to be wrong, or when a successful objection or deletion request requires it.

The GDPR normally requires us to tell you, within a month, that we hold information about you that we did not get from you. The platform collects from public sources at a scale where we usually have no reliable way to contact the people named, and telling a person that they appear in an investigation can defeat the purpose of preventing crime. For both reasons we publish this notice instead of writing to each person, as GDPR Article 14(5)(b) and POPIA section 18(4)(c)(i), (d) and (e) allow, and we protect the information as section 8 describes.

Your rights (Parts A and B)

15. Your right to object

You can object at any time, for reasons that relate to your own situation, to processing that we base on legitimate interests. That covers our request records (Part A) and the platform (Part B). When you object, we stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or we need the information to establish, exercise or defend a legal claim (POPIA section 11(3)(a), GDPR Article 21(1)).

If we ever use your information for direct marketing, you can object at any time, without giving a reason, and we will stop (POPIA section 11(3)(b), GDPR Article 21(2)).

To object, email privacy@protoworks.dev.

16. What else you can ask us to do

You have the right to:

Neither company makes decisions about you based only on automated processing that have legal effects for you or affect you in a similarly significant way (GDPR Article 22).

Email privacy@protoworks.dev. You do not have to use a prescribed form; an email that tells us who you are and what you want is enough. If you prefer the forms, they are POPIA Form 1 (objection) and Form 2 (correction or deletion), and PAIA Form 2 for a copy of records. We may ask you to prove your identity before we act, so that we never give your information to someone else.

We answer within one month. If a request is complex, or you send us several, we may take up to two more months, and if so we tell you why within the first month. We do not charge for this, unless a request is clearly unfounded or excessive. If we refuse a request, we tell you why and how to challenge the decision.

17. Complaints

If you are not satisfied with how we handle your information, tell our Information Officer first, at privacy@protoworks.dev. We acknowledge a complaint within 30 days and tell you the outcome without undue delay.

You also have the right to complain to a regulator at any time.

In South Africa:

Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone 010 023 5200, toll free 0800 017 160
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
https://inforegulator.org.za

In the EU and the EEA, the data protection authority of the country where you live or work, or where you believe the problem happened. The European Data Protection Board lists them at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en

In the UK, the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/

18. Changes to this notice

When this notice changes, we publish the new version here with a new version number and date. Each company's PAIA manual, published beside this notice, lists the records it holds and explains how to ask for access to them.