1. Who we are
This website, www.canvas.africa, is operated by Canvas dot Africa (Pty) Ltd (registration number 2019/592441/07), a technology advisory and execution firm headquartered in Cape Town, South Africa (“Canvas • Africa”, “we”, “us”). For the purposes of the Protection of Personal Information Act, 4 of 2013 (“POPIA”), Canvas dot Africa (Pty) Ltd is the responsible party for personal information processed through this website.
2. What personal information we collect
2.1 Information you give us through forms
When you request a confidential briefing through our contact form, we collect: your name, work email address, organisation, your role, the service area you select, a description of the decision or risk on the table, your decision timeframe, and (optionally) your country or market. When you request our Board AI Governance framework download, we collect: your full name, work email address, and organisation. Both forms also offer an optional, separate checkbox to consent to marketing communications (see section 4) — this is never a condition of submitting the form itself, except where section 4 says otherwise for the gated download.
2.2 Information collected automatically (website analytics)
With your consent (see section 7), we use behavioral analytics tools that record how visitors interact with this website: pages and page sections viewed and time spent in them; mouse clicks and taps; scrolling behavior and depth; zooming and pinch gestures; text selection/highlighting; and anonymised session replays of these interactions. The tools we use are configured to strictly mask all text entered into any form field before it reaches processing servers. These tools also process technical data such as device type, browser, screen size, approximate (city-level) location derived from IP address, and referring pages.
3. Why we process this information (purpose and lawful basis)
- Responding to briefing and download requests. We process form data to respond to your enquiry, schedule briefings, deliver requested materials, and manage our commercial relationship with you. Lawful basis: necessary to take steps at your request prior to, or in performance of, a contract, and/or our legitimate interests in responding to enquiries you initiate.
- Sales and relationship management. Form submissions are stored as leads in our CRM, including which page and call-to-action you submitted from. Lawful basis: legitimate interests.
- Marketing communications. Where you separately opt in via the optional marketing-consent checkbox, we use your name and email to send technology insights, industry updates, and consulting offers. Lawful basis: your explicit, separately given consent (see section 4).
- Internal training and development. Website interaction data (clicks, highlighting, scroll and zoom behavior, section engagement) is analysed to understand how visitors use the site, for our internal training and development purposes. Lawful basis: your consent via the cookie banner.
- Funnel and conversion measurement. Aggregated analytics to understand which pages lead to enquiries. Lawful basis: your consent.
We do not sell personal information. We do not use this data for third-party advertising.
4. Marketing communications and consent
Submitting a briefing request or downloading our framework does not, by itself, sign you up for marketing communications. Where our forms include an optional “keep me updated” checkbox, ticking it is a separate, deliberate act of consent to receive technology insights, case studies, and consulting offers by email — it is never bundled with, or required for, the underlying service enquiry. For our gated framework download specifically, a separate, required checkbox confirms you agree to this Privacy Policy so we can deliver the resource; the marketing-updates checkbox on that same form remains optional and un-ticked by default. You can withdraw marketing consent at any time via the unsubscribe link in any marketing email, or by contacting our Information Officer — this does not affect any other correspondence relating to a briefing or engagement already in progress.
5. Third-party processors and cross-border transfers
We share personal information with the following service providers (“operators” under POPIA), who process it on our instructions:
- Zoho Corporation (Zoho CRM) — stores and manages lead and contact records submitted via our forms, under a Data Processing Agreement incorporating Standard Contractual Clauses. Zoho hosts data in data centres that may be located outside South Africa. Where personal information is transferred outside South Africa, we rely on section 72 of POPIA together with the Zoho DPA/SCCs as the contractual mechanism providing an adequate level of protection substantially similar to POPIA.
- Microsoft Corporation (Microsoft Clarity) — processes website interaction data (session recordings, heatmaps, click/scroll/zoom/selection data, with form-field text masked before it reaches Microsoft). Data may be processed outside South Africa.
- Google LLC (Google Analytics 4) — processes aggregated website usage data. Data may be processed outside South Africa.
- This website is hosted in South Africa.
6. Retention
We retain personal information only for as long as necessary for the purposes described above, using the following documented retention periods:
- Active client relationships: 7 years from the end of the engagement. Rationale: aligns with standard South African tax, accounting, and contractual limitation-period practice for a professional-services engagement, and supports audit/compliance evidence if a dispute arises after the relationship ends.
- Leads and enquiries that do not convert: 2 years from the date of enquiry. Rationale: B2B board/ExCo decision cycles routinely span 12–24 months (reflected in our own intake form’s timeframe options), so a shorter window would discard genuinely live prospects; after 2 years a cold lead no longer serves a legitimate business purpose and is deleted or anonymised.
- Google Analytics 4 event-level data: 14 months. Rationale: matches GA4’s own configurable retention ceiling, balancing useful year-over-year comparison against not holding usage data indefinitely.
- Microsoft Clarity session recordings: 30 days. Rationale: recordings are used for short-cycle usability review, not long-term storage — this mirrors Clarity’s own short-lived default for raw recordings.
- Microsoft Clarity anonymised heatmap/aggregate data: 9 months. Rationale: aggregated, de-identified heatmaps no longer identify an individual visitor, so they are kept longer than raw recordings, refreshed periodically as the site’s content and layout change.
We may retain information for longer where required by law (e.g. financial record-keeping obligations) or while necessary to establish, exercise, or defend a legal claim.
7. Cookies and consent
Analytics and session-recording scripts do not run until you give consent via the cookie banner presented on your first visit, powered by Complianz — these tools only activate if you give explicit consent. You may decline; the website remains fully functional without analytics cookies. You can withdraw consent at any time via the cookie settings link in the footer, after which no further interaction data is collected. Strictly necessary cookies (if any) are used only to operate the site and remember your consent choice.
8. Your rights under POPIA
You have the right to: request confirmation of whether we hold personal information about you; request access to it; request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, or unlawfully obtained; object to processing based on legitimate interests; withdraw consent where processing is based on consent (including marketing consent under section 4); and lodge a complaint with the Information Regulator (South Africa) — www.inforegulator.org.za, [email protected].
To exercise any of these rights, contact our Information Officer at [email protected]. We will respond within a reasonable time and in accordance with POPIA’s timeframes.
9. Security
We apply appropriate, reasonable technical and organisational measures to secure personal information, including access controls on our CRM, encrypted transmission (HTTPS) of form submissions, and least-privilege access for our team. No internet transmission is entirely secure; we cannot guarantee absolute security but we take the protection of your information seriously and will notify you and the Information Regulator of any compromise as required by section 22 of POPIA.
10. Children
This website is directed at business decision-makers and is not intended for children. We do not knowingly process children’s personal information.
11. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the current version. Material changes will be highlighted on this page.
12. Contact
Canvas dot Africa (Pty) Ltd · Cape Town, South Africa · Registration 2019/592441/07 · [email protected] · www.canvas.africa