What we collect, why, and what you can ask us to do about it.
This notice explains how we handle personal information submitted through cipherwyze.com. It covers the enquiry form and the limited technical information the site records to keep that form working.
Last updated 22 August 2026. This notice applies to the cipherwyze.com website only. The Navigator application at navigator.cipherwyze.com is governed by the agreement between us and the customer organisation that licenses it.
The organisation responsible for this information.
Wyzetree Holdings (Pty) Ltd, trading as CipherWyze, registration number 2019/164685/07, of 21c Marais Road, Cape Town, 7806, South Africa, is the responsible party under the Protection of Personal Information Act, 2013 (POPIA) and the controller under the UK and EU General Data Protection Regulation for the information described in this notice.
Privacy enquiries of any kind — including a request to see, correct or delete what we hold about you — should go to privacy@wyzetree.com, or to our registered address marked for the attention of the Information Officer.
Two things: what you type, and what the form needs to work.
When you submit the enquiry form we collect the information you enter — your name, your work email address, your organisation if you choose to give it, and the content of your message.
Alongside that submission we record a small amount of technical information, because a public form on the internet cannot be operated safely without it:
- IP addressUsed to apply rate limits and detect abuse. We store it only as a keyed cryptographic hash. The address itself is never written to our database or to our logs.
- Page and referral informationThe page you submitted from, the page you first arrived on, the referring website if any, and any campaign parameters in the link you followed.
- Which button you clickedThe label of the call-to-action that took you to the form, so we can respond in the right context.
- A message fingerprintA hash of your message, used to recognise an accidental double submission within ten minutes so you are not contacted twice.
Your browser also stores two small values on your own device for the duration of your visit — the page you first landed on and any campaign parameters — so that they survive navigation between pages. These are held in session storage, are cleared when you close the tab, and are never read by anyone other than the form on this site.
We do not use advertising cookies, analytics cookies, tracking pixels, session recording, fingerprinting or third-party embeds anywhere on this site. We do not build profiles, we do not run automated decision-making, and we do not enrich what you give us with data bought from anyone else.
Four purposes, and the legal basis for each.
- Responding to your enquiryLegitimate interests (EU and UK GDPR Article 6(1)(f)) — responding to a business enquiry a person has chosen to send us. Where the exchange leads towards a contract, Article 6(1)(b). Under POPIA, section 11(1)(f).
- Keeping a record of the conversationLegitimate interests — maintaining an accurate record of who we have spoken to and what was discussed, in our customer relationship records.
- Preventing abuse of the formLegitimate interests — rate limiting, duplicate detection and spam prevention, without which a public form cannot be operated. This is the only purpose for which the hashed IP address is used.
- Meeting our own legal obligationsLegal obligation, where we are required to retain records or respond to a lawful request.
We do not use your information for any purpose other than these. We will not add you to a marketing list on the strength of an enquiry, and we do not send unsolicited marketing from this site.
Four service providers, each processing on our instructions.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose it to anyone for their own purposes. We do rely on the following providers to operate the site and handle enquiries:
- LovableHosting and delivery of the website itself.
- SupabaseThe database in which the enquiry record, the hashed IP address and the abuse-prevention records are stored.
- NotionOur customer relationship records, into which the enquiry is written so that we can respond and keep track of the conversation.
- Our email providerDelivery of the internal notification that tells us your enquiry has arrived, and of our reply to you.
Each of these acts as a processor — an operator, in POPIA's language — under a written agreement that permits them to process the information only on our instructions. We may also disclose information where we are required to do so by law, or where it is necessary to establish, exercise or defend a legal claim.
Transfers outside South Africa, the UK and the EEA.
We are a South African organisation, and the providers listed above operate infrastructure in the United States and the European Union. Personal information submitted through this site will therefore be processed outside the country in which you are located.
Where information is transferred out of the EEA or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses and, for the United Kingdom, the International Data Transfer Addendum, together with the technical measures described below. Where information is transferred out of South Africa, we rely on section 72 of POPIA, on the basis that the recipient is bound by an agreement that upholds principles of processing substantially similar to those in the Act. You can request a copy of the relevant safeguards from privacy@wyzetree.com.
Enquiries for two years. Abuse records for ten minutes.
- Enquiry recordsTwenty-four months from our last substantive contact with you, after which the record is deleted. If the enquiry leads to a contract, the record is retained under that contract instead and this notice stops applying to it.
- Rate-limiting and duplicate-detection recordsTen minutes, then automatically expired. These contain only keyed hashes, never an address or a message.
- Customer relationship recordsTwenty-four months from last contact, aligned to the enquiry record above.
- Session storage in your browserUntil you close the browser tab. It never reaches us as a separate record.
What you can ask us to do, wherever you are.
Whoever you are and wherever you are, you may ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. We will not treat you differently for asking. Write to privacy@wyzetree.com and we will respond within thirty days.
If you are in the EEA or the United Kingdom, you additionally have the right to restrict or object to our processing, the right to data portability, and the right to object at any time to processing carried out on the basis of our legitimate interests. You may lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office.
If you are in South Africa, you have the rights set out in sections 23, 24 and 11(3) of POPIA, including the right to object to processing and the right to lodge a complaint with the Information Regulator (South Africa).
If you are a California resident, you have the right to know what personal information we have collected, the right to delete it, the right to correct it, and the right to non-discrimination for exercising those rights. We have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months, and we do not offer financial incentives for personal information. We do not collect sensitive personal information as that term is defined in the CCPA.
What protects the information while we hold it.
The site is served only over HTTPS. The enquiry endpoint validates and bounds every field it accepts, applies rate limits, and rejects submissions from unexpected origins. Your IP address is hashed with a secret key before storage, so the stored value cannot be reversed to an address. Access to the database and to our customer relationship records is restricted to the people who need it.
No system is perfect. If we become aware of a compromise affecting your personal information, we will notify you and the relevant regulator where the law requires it.
Children, changes, and what happens if the business changes hands.
This site is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under the age of eighteen.
CipherWyze is being established as a separate legal entity. If the operation of this site and the records described in this notice transfer to that entity, or to any successor as part of a reorganisation, merger or sale of the business, the information will transfer with it and will remain subject to a notice at least as protective as this one. We will update the details in the first section of this notice when that happens.
We may update this notice from time to time. The date at the top of the page tells you when it last changed materially. If a change affects how we use information you have already given us, we will tell you directly.
How to reach us about any of this.
Email privacy@wyzetree.com, or write to Wyzetree Holdings (Pty) Ltd at 21c Marais Road, Cape Town, 7806, South Africa, marked for the attention of the Information Officer.
If you are not satisfied with our response, you may complain to the Information Regulator (South Africa), to the UK Information Commissioner's Office, or to the supervisory authority in your EEA member state.
