Last updated: 21 June 2026
GRAFT.TODAY respects your privacy and is committed to protecting the personal information you share with us. This policy explains what data we collect, why we collect it, how we protect it, and what rights you have as a data subject.
GRAFT.TODAY is operated by Jacob Kotzee trading as GRAFT.TODAY, a sole proprietor registered in the Republic of South Africa. We are the “responsible party” for the personal information of our subscribers and website visitors, as defined by the Protection of Personal Information Act 4 of 2013 (“POPIA”).
This Privacy Policy covers our website at https://graft.today, the subscriber dashboard, any embedded chatbot widgets delivered through our service, and all related GRAFT.TODAY products.
Because GRAFT.TODAY is a multi-tenant platform, we process personal information in two distinct capacities:
Responsible party (for our subscribers)
When you create an account and use GRAFT.TODAY, we determine the purpose and means of processing your personal information — your account details, billing data, and platform usage. We are the responsible party under POPIA for this data.
Operator (for your customers’ data)
When your customers interact with your embedded chatbot widget, youare the responsible party for their personal information and GRAFT.TODAY acts as your operator (processor), handling that data only on your instructions. Your end-users’ rights are primarily exercised through you. If you deploy GRAFT.TODAY services to your own customers, you should disclose GRAFT.TODAY as a sub-processor in your own privacy notices.
We collect the following categories of personal information when you register for and use GRAFT.TODAY:
Account and identity
Billing and subscription
All payment card data is processed exclusively by Paddle (our Merchant of Record). GRAFT.TODAY never stores or has access to your card number, CVV, or full payment details.
Usage and technical data
When you use GRAFT.TODAY’s products to serve your own customers, we process the following categories of data as your operator:
You are responsible for ensuring you have a lawful basis to collect and process your own customers’ data, and for complying with applicable data protection law in your jurisdiction.
We process your personal information only for the following purposes:
We do not sell your personal information to third parties, and we do not use your data for targeted advertising.
Under POPIA, all processing of personal information must be lawful. The table below sets out the legal grounds we rely on:
| Processing activity | Legal basis |
|---|---|
| Account registration and authentication | Contractual necessity |
| Subscription and billing management | Contractual necessity |
| Transactional service communications | Contractual necessity |
| Security monitoring and fraud prevention | Legitimate interest |
| Anonymised analytics for service improvement | Legitimate interest |
| Compliance with legal or regulatory obligations | Legal obligation |
We share your personal information only with trusted third-party service providers who process it on our behalf and under our instructions. Below is our current list of sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Clerk (clerk.com) | User authentication and identity management | United States |
| Paddle (paddle.com) | Payment processing and subscription management — Merchant of Record | United Kingdom / United States |
| Vercel (vercel.com) | Application hosting and global content delivery | United States (global CDN) |
| Google (Gemini, Stitch, Jules) | AI model inference, design generation, and code generation | United States |
| Inngest (inngest.com) | Background job orchestration | United States |
| Resend (resend.com) | Transactional email delivery | United States |
| Cal.com | Appointment and booking scheduling | United States |
| Cloud database (PostgreSQL) | Encrypted relational data storage (TLS in transit) | Cloud-hosted |
All sub-processors are contractually required to process data in accordance with our instructions and applicable data protection law. We review our sub-processor list regularly and will update this policy if it changes.
We keep your personal information for as long as your account is active or as otherwise required by law. Specifically:
We implement reasonable technical and organisational measures to protect your personal information against unauthorised access, accidental loss, alteration, or destruction. These measures include:
No method of transmission over the internet or electronic storage is completely secure. If we become aware of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Regulator as required by POPIA Section 22.
Under POPIA (Sections 23–25), you have the following rights in relation to your personal information:
To exercise any of these rights, contact our Information Officer at hello@graft.today. We will respond within a reasonable time, and in any event within the timeframes required by POPIA.
Information Regulator of South Africa
If you believe we have handled your personal information unlawfully, you may lodge a formal complaint with the Information Regulator at inforegulator.org.za.
GRAFT.TODAY serves customers globally. Your personal information may be processed by our sub-processors on servers located outside South Africa — primarily in the United States and European Union. In these cases, we take reasonable steps to ensure that cross-border transfers are subject to appropriate safeguards, consistent with POPIA Section 72.
By using GRAFT.TODAY, you acknowledge that your personal information may be transferred to and processed in jurisdictions outside South Africa.
We will only send you marketing communications if you have opted in, or where we have an existing business relationship that permits it, in compliance with POPIA Section 69. You may opt out of marketing emails at any time by clicking the unsubscribe link in any email or contacting us at hello@graft.today.
Note for GRAFT.TODAY subscribers: If you use the services to communicate with your own customers ortriaged initiated enquiries you are responsible for ensuring those communications comply with applicable electronic direct marketing laws in your jurisdiction (including POPIA Section 69 in South Africa, CAN-SPAM in the United States, and the GDPR in the European Union).
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Where changes are material, we will notify active subscribers by email at least 30 days before they take effect. Continued use of GRAFT.TODAY after the effective date constitutes acceptance of the revised policy.
For any privacy-related questions, data subject access requests, or to reach our Information Officer:
This policy is a good-faith effort to comply with POPIA and applicable international data protection law.