Last updated: 2026-08-23
AEONSYNC BI (PTY) LTD ("AeonSync", "we", "us", "our"), a private company registered in the Republic of South Africa under Registration No. 2026/402687/07.
Registered office: 105 Rand Street, Oudtshoorn, 6620, South Africa.
Contact for privacy matters: hello@aeonsync.io
For the purposes of POPIA we are the Responsible Party. AeonSync is a South African company serving South African clients, and POPIA is the operative law for this policy. Where a client engages us to process personal data on their behalf, that client is the Responsible Party and we act as their Operator, processing data only on their documented instruction. Where such data includes individuals in the EU or EEA, we support our client in meeting their obligations under applicable data protection law.
Depending on how you interact with us, we may collect:
We do not sell your personal data. We share it only with:
Our infrastructure is hosted in Germany and Finland (Hetzner Online GmbH). For visitors and clients in the European Union, this means your data does not leave the EEA in normal operation. AI processing performed by Anthropic involves transfers to the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses.
We retain your data only as long as it is necessary for the purposes set out above, or as required by law. Outreach contact data is retained for up to 24 months from last engagement, after which it is anonymized or deleted. Client conversation transcripts are retained per the data retention term in the client contract.
Under POPIA (South Africa) and GDPR (EU/EEA) you have the right to:
To exercise any of these rights, email hello@aeonsync.io. We respond within 30 days.
Every marketing email we send contains a one-click List-Unsubscribe header (RFC 8058) and a visible unsubscribe link. You can also email unsubscribe@aeonsync.io at any time. We action requests within 48 hours.
aeonsync.io uses minimal first-party cookies for session continuity. We use a transparent 1x1 pixel in marketing emails to record open events and rewritten links to record click events; both are tied to a per-message UUID and used solely to measure outreach effectiveness, not to build cross-site profiles.
We maintain technical and organizational measures appropriate to the risk, including TLS in transit, encryption at rest for credential stores, principle-of-least-privilege access, and DKIM/DMARC/SPF email authentication. In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify you directly.
Where a client authorises us to manage their business listings, we use the Google Business Profile APIs and comparable platform APIs to read and update that client's own listing information on their behalf. We access only the profiles and locations we have been explicitly granted access to by the profile owner or an authorised manager, and we use that access solely to manage and improve that client's listing — business details, categories, hours, photos, posts, questions and reviews. We do not use data obtained through these APIs to build advertising or marketing profiles, and we do not sell, rent or transfer it to third parties. Such data is retained only for as long as needed to perform the service, and our access is removed when an engagement ends or on request. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The same principles apply to any other platform we operate on a client's authorisation, including Meta and WhatsApp Business, booking engines and social publishing tools.
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated by email where we hold your contact details.
AEONSYNC BI (PTY) LTD
105 Rand Street, Oudtshoorn, 6620, South Africa
hello@aeonsync.io
+27 (62) 059 0595