PRIVACY & DATA PROTECTION

Privacy Policy

This policy explains how Over To AI handles personal information across our website, business workspaces, public customer chat and connected services.

Effective 14 August 2026

1. Who we are

Over To AI is a South African AI workforce platform for service businesses. In this policy, “Over To AI”, “we”, “us” and “our” refer to the operator of the Over To AI service.

For privacy questions or requests, contact support@overtoai.com.

2. Where this policy applies

This policy applies when you visit our public website, create or use an Over To AI workspace, interact with a public Nandi customer chat, upload information, or connect a third-party service such as Google Calendar.

A business using Over To AI is generally responsible for deciding why and how its own customer information is processed. In that situation, the business is the responsible party and Over To AI processes that information as its operator and service provider. Over To AI is the responsible party for account, platform, security and direct support information that we collect for our own purposes.

3. Information we collect

Account and workspace information

Names, email addresses, authentication identifiers, organisation membership, business contact details, preferences and workspace settings.

Business and customer records

Customer names and contact details, addresses, registration and VAT details, notes, project information, photos, leads, booking requests, calendar event details, follow-ups, quotes, invoices and email drafts.

Conversations and AI activity

Messages sent to AI employees or through public customer chat, prompts, generated responses, tool actions, escalations, approvals and related audit records.

Files and knowledge

Documents, spreadsheets, stationery and images uploaded to a workspace, together with searchable information extracted from them.

Connected-service data

When Google Calendar is connected, we receive the connected account identifier, calendar list, selected calendar, availability and event information needed to provide calendar features. We also store encrypted access and refresh tokens.

Technical and usage information

Request identifiers, timestamps, security and error logs, feature activity, model usage, token counts and estimated service cost. We do not currently use advertising cookies or sell behavioural profiles.

4. How and why we use information

We process information only when there is a lawful reason to do so, including performing our agreement with a user or customer, following a workspace customer's lawful instructions, pursuing legitimate interests such as service security and improvement, complying with legal duties, or acting with consent where consent is required.

  • Provide and personalise workspaces and AI employee features.
  • Answer enquiries, prepare drafts, organise leads and bookings, and carry out user-approved actions.
  • Authenticate users, isolate organisations and protect accounts.
  • Deliver emails, files, calendar invitations and customer notifications.
  • Diagnose errors, prevent misuse, maintain audit records and measure service usage.
  • Respond to support, privacy and legal requests.

5. AI processing and human review

Relevant conversation text, instructions and business knowledge may be sent to an AI service provider to generate a response or structured draft. Users should not submit passwords, banking credentials, identity documents or unnecessary sensitive information.

AI output can be incomplete or incorrect. Over To AI is designed to keep important business actions—such as approving sales documents and calendar changes—under human control. Workspace users remain responsible for reviewing output before relying on it or sending it to a customer.

6. Google user data

Over To AI accesses Google Calendar data only after an authorised workspace user chooses to connect a Google account. We request calendar permissions to list calendars, read availability and create, update or cancel calendar events that support visible booking features.

  • We use Google data only to provide or improve the connected calendar features shown to the user.
  • We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train a general-purpose AI model.
  • We do not allow people to read Google user data except with the user's permission for support, when necessary for security, or when required by law.
  • Google tokens are encrypted at rest. Disconnecting Google Calendar revokes future access and removes stored connection tokens. Business records already created in Over To AI may remain until deleted under the retention process below.

Over To AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

7. When we share information

We do not sell personal information. We share it only as needed to operate the service, follow an authorised instruction, protect rights and security, comply with law, or complete a business transfer subject to appropriate safeguards.

Service providers may include Clerk for authentication, Railway for application hosting, databases and file storage, OpenAI for AI and transcription functions, Google for connected calendar functions, and Resend for email delivery. Each provider processes only the information needed for its role and is subject to its own terms and privacy commitments.

8. Cross-border processing

Some service providers and infrastructure may process information outside South Africa. Where personal information crosses borders, we take reasonable steps to use providers and arrangements that offer an appropriate level of protection, and we handle transfers in accordance with applicable law.

9. Security

We use reasonable technical and organisational safeguards appropriate to the service, including authenticated access, organisation-level data separation, encryption of integration credentials and stored uploads, audit records and restricted administrative access. No internet service is completely secure, so we cannot guarantee that a security incident will never occur.

10. Retention and deletion

We retain information only for as long as reasonably needed to provide the service, maintain security and audit records, resolve disputes and meet legal obligations. Retention depends on the type of record and the customer's instructions.

Users can remove some records and disconnect integrations in the product. To request account or workspace deletion, Google-derived data deletion, or another deletion not available in the interface, email support@overtoai.com. We will verify the request and act within a reasonable period, subject to legal duties, legitimate security needs and technically necessary backup cycles.

11. Your rights

Subject to POPIA and other applicable law, you may ask whether we hold your personal information and request access, correction or deletion. You may also object to certain processing, ask us to restrict unlawful processing, or withdraw consent where processing is based on consent.

Start by contacting support@overtoai.com. You may also lodge a complaint with South Africa's Information Regulator if you believe your personal information has been handled unlawfully.

12. Children

Over To AI is a business service and is not directed to children. We do not knowingly create accounts for children or intentionally collect children's personal information without the authorisation required by law.

13. Changes to this policy

We may update this policy as the service, providers or law change. We will publish the revised policy here and update its effective date. Where a material change affects how previously authorised Google user data is used, we will provide appropriate notice and obtain renewed consent where required.