PRIVACY & DATA PROTECTION

Privacy Policy

This policy explains how Over To AI handles personal information across our website, business workspaces, public customer chat and connected services.

Effective 18 August 2026

1. Who we are

Over To AI is a South African AI workforce platform for service businesses and a product and trading name of Flowclick AI (Pty) Ltd, a private company registered in South Africa under registration number 2026/656214/07. In this policy, “Over To AI”, “Flowclick AI”, “we”, “us” and “our” refer to Flowclick AI (Pty) Ltd as the operator of the Over To AI service.

Flowclick AI (Pty) Ltd is the responsible party for personal information processed for its own platform, account, security, support and marketing purposes. Keenan Hanmer is the Information Officer. For privacy, POPIA or PAIA questions and requests, contact support@overtoai.com or telephone +27 84 770 9645.

2. Where this policy applies

This policy applies when you visit our public website, create or use an Over To AI workspace, interact with a public Nandi customer chat, upload information, or connect a third-party service such as Google Calendar or Gmail.

A business using Over To AI is generally responsible for deciding why and how its own customer information is processed. In that situation, the business is the responsible party and Over To AI processes that information as its operator and service provider. Over To AI is the responsible party for account, platform, security and direct support information that we collect for our own purposes.

3. Information we collect

Account and workspace information

Names, email addresses, authentication identifiers, organisation membership, business contact details, preferences and workspace settings.

Website enquiries

If you submit our public contact form, we collect your email address and its follow-up status. We use it to respond and contact you about Over To AI services. We do not add you to unrelated mailing lists without a separate choice.

Business and customer records

Customer names and contact details, addresses, registration and VAT details, notes, project information, photos, leads, booking requests, calendar event details, follow-ups, quotes, invoices and email drafts.

Conversations and AI activity

Messages sent to AI employees or through public customer chat, prompts, generated responses, tool actions, escalations, approvals and related audit records.

Files and knowledge

Documents, spreadsheets, stationery and images uploaded to a workspace, together with searchable information extracted from them.

Connected-service data

When Google Calendar is connected, we receive the connected account identifier, calendar list, selected calendar, availability and event information needed to provide calendar features. When Gmail is connected, we process mailbox identifiers, message headers, sender and recipient details, subjects, message text, thread and label identifiers, reply drafts and sent replies needed to triage customer mail and provide the visible mailbox-assistant features. Supported customer attachments may be securely imported, analysed and linked to customer work so they can be routed to the appropriate assistant. We also store encrypted access and refresh tokens.

Technical and usage information

Request identifiers, timestamps, security and error logs, feature activity, model usage, token counts and estimated service cost. We do not currently use advertising cookies or sell behavioural profiles.

4. How and why we use information

We process information only when there is a lawful reason to do so, including performing our agreement with a user or customer, following a workspace customer's lawful instructions, pursuing legitimate interests such as service security and improvement, complying with legal duties, or acting with consent where consent is required.

  • Provide and personalise workspaces and AI employee features.
  • Answer enquiries, prepare drafts, organise leads and bookings, and carry out user-approved actions.
  • Authenticate users, isolate organisations and protect accounts.
  • Deliver emails, files, calendar invitations and customer notifications.
  • Diagnose errors, prevent misuse, maintain audit records and measure service usage.
  • Respond to support, privacy and legal requests.

5. AI processing and human review

Relevant conversation text, instructions, supported customer attachments and business knowledge may be sent to an AI service provider to generate a response, summary or structured draft. Users should not submit passwords, banking credentials, identity documents or unnecessary sensitive information.

AI output can be incomplete or incorrect. Routine messages may be sent automatically when a workspace enables that workflow, while complaints, payments, legal requests and other sensitive topics are held for human approval. Important business actions such as approving sales documents and calendar changes remain under human control. Workspace users remain responsible for configuring and supervising these workflows.

6. Google user data

Over To AI accesses Google data only after an authorised workspace user chooses to connect a Google account. Calendar permissions support the visible booking features. The separate Gmail permission allows the mailbox assistant to read customer messages and supported attachments, maintain thread context, suggest and apply staff-approved labels, and send replies under the workspace's configured approval rules.

  • We use Google data only to provide or improve the connected calendar and Gmail features shown to the user.
  • Relevant Gmail message and attachment content may be processed by our AI service provider solely to classify a message, summarise an attachment and prepare the assistant output requested by the workspace. We do not use Google user data to train a general-purpose AI model.
  • We do not sell Google user data, use it for advertising, or use it to determine creditworthiness.
  • We do not allow people to read Google user data except with the user's permission for support, when necessary for security, or when required by law.
  • Google tokens are encrypted at rest. Disconnecting a Google integration revokes future access. Imported business records and audit history may remain until deleted under the retention process below.

Over To AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

7. When we share information

We do not sell personal information. We share it only as needed to operate the service, follow an authorised instruction, protect rights and security, comply with law, or complete a business transfer subject to appropriate safeguards.

Service providers may include Clerk for authentication, Railway for application hosting, databases and file storage, OpenAI for AI and transcription functions, Google for connected calendar and Gmail functions, and Resend for email delivery. Each provider processes only the information needed for its role and is subject to its own terms and privacy commitments.

8. Cross-border processing

Some service providers and infrastructure may process information outside South Africa. Where personal information crosses borders, we take reasonable steps to use providers and arrangements that offer an appropriate level of protection, and we handle transfers in accordance with applicable law.

9. Security

We use reasonable technical and organisational safeguards appropriate to the service, including authenticated access, organisation-level data separation, encryption of integration credentials and stored uploads, audit records and restricted administrative access. No internet service is completely secure, so we cannot guarantee that a security incident will never occur.

10. Retention and deletion

We retain information only for as long as reasonably needed to provide the service, maintain security and audit records, resolve disputes and meet legal obligations. Retention depends on the type of record and the customer's instructions.

Users can remove some records and disconnect integrations in the product. To request account or workspace deletion, Google-derived data deletion, or another deletion not available in the interface, email support@overtoai.com. We will verify the request and act within a reasonable period, subject to legal duties, legitimate security needs and technically necessary backup cycles.

11. Your rights

Subject to POPIA and other applicable law, you may ask whether we hold your personal information and request access, correction or deletion. You may also object to certain processing, ask us to restrict unlawful processing, or withdraw consent where processing is based on consent.

Start by contacting support@overtoai.com. You may also lodge a complaint with South Africa's Information Regulator if you believe your personal information has been handled unlawfully.

12. Children

Over To AI is a business service and is not directed to children. We do not knowingly create accounts for children or intentionally collect children's personal information without the authorisation required by law.

13. Changes to this policy

We may update this policy as the service, providers or law change. We will publish the revised policy here and update its effective date. Where a material change affects how previously authorised Google user data is used, we will provide appropriate notice and obtain renewed consent where required.