Strata Hub
Privacy Terms

Privacy Policy

Last updated 1 October 2026 · Governed by the Protection of Personal Information Act 4 of 2013 (POPIA), Republic of South Africa.

Strata Automation ("Strata", "we") operates the Strata Hub and the AI receptionists deployed for our clients. This policy explains what personal information we process, why, for how long, and what you can ask us to do about it.

1. Who is responsible

For information about our own clients — account holders who sign in to this Hub — Strata is the responsible party. For information about a client's customers captured by a deployed receptionist, the client is the responsible party and Strata is an operator processing on their documented instructions.

Information Officer: Mohammed Luay Saib, luaysaib786@gmail.com. Write here with any question or request about personal information, including the requests in section 8.

2. What we collect

Account information
Name, business name, email address, hashed password, tier and billing status. Passwords are stored only as a bcrypt hash — we cannot read yours.
Conversation content
Messages exchanged with a receptionist, call transcripts and call metadata (time, duration, outcome), and any details a visitor volunteers: name, contact number, email, and the enquiry itself.
WhatsApp conversation counts
To bill for WhatsApp conversations we also keep a record of each 24-hour conversation: when it opened, how many messages and replies it held, and the customer's number held only as a keyed one-way code, not as a readable number. The code lets us tell one customer's conversation from another's; it cannot be turned back into a number without a secret key we hold separately. In the message history, any other kind of non-text message appears as a short placeholder such as [document]; see voice notes and photos below.
Call recordings
When a business's receptionist answers a call, the call is recorded; callers are told at the start of the call. We keep an encrypted copy on our own servers so that the business's owners and managers can listen to it in their Hub. Other staff accounts cannot. Strata staff may play the recordings of calls made during a business's Leakage Audit to walk it through the results, and every play is logged.
Voice notes and photos
On WhatsApp, a customer can send a voice note or a photo to a business's receptionist. A voice note is turned into text so it can be answered, and that text is kept like any other message; the audio itself is not kept. A photo is described in words, and the description is kept like any other message. Photos that look like an identity document, a bank card or another sensitive document are never kept; we keep only a note that one was received. Location and device details are removed from a photo before it is kept. A business's owners and managers can see its kept photos in their Hub. Other staff accounts cannot.
Messages after a call

If you phone a business that uses Strata and the call ends without your details being taken or a booking being made, we may send you one SMS or WhatsApp message about that call. If you book during the call, we send you a confirmation. We use your number only for that message.

Reply STOP and that business will not message you first again. You'll still get confirmations for anything you book. If you message them, they will still reply. We keep your number on that business's do-not-message list for as long as the business uses Strata, so that we can honour your request.

We also keep a scrambled record that a message was sent — never your number — for 90 days, so that we do not message you twice.

Booking information
Appointment times and the calendar events created for them, where a client has connected a calendar.
Technical information
Session cookies required to keep you signed in, a CSRF token, and server logs. We do not run advertising or cross-site tracking on this Hub.

3. Why we process it

  • To provide the service you or our client has contracted for — answering, capturing, qualifying, booking and delivering enquiries.
  • To authenticate you and keep the account secure.
  • To bill for the service and to compute the reporting our clients rely on.
  • To meet legal obligations, including records we are required to keep.

4. Who else touches it

We use a small, fixed set of operators. Each receives only what its function requires:

Language model provider
Google, via the Gemini API on a paid tier. Generates the receptionist's replies for the chat and messaging channels. Receives conversation text, and the audio of voice notes and the images of photos customers send on WhatsApp, to transcribe or describe them. See section 5.
Voice platform
Retell AI. Runs the phone channel. Receives call audio and produces transcripts. See section 5.
Messaging and SMS carriers
Deliver WhatsApp messages and alert SMS. Receive message content and phone numbers.
Payment processor
Handles subscriptions and activation fees. Receives billing details; card data never reaches Strata's systems.
Calendar and email providers
Google Calendar, where a client has connected one, to read free/busy availability and to create booking events — the scopes and their limits are set out in section 5. Email providers deliver the confirmations and notifications the booking generates.

Some of these operators process information outside South Africa. Where they do, the transfer is made on the basis permitted by section 72 of POPIA. We do not sell personal information, and we do not share it for anyone else's marketing.

5. Google Calendar, and what reaches an AI model

Where a client connects a Google Calendar, we request exactly two scopes and no others:

calendar.freebusy
Read. Returns only the intervals in which the business is already busy — a start time and an end time. Event titles, descriptions, attendees, guest lists and locations are never requested and never returned.
calendar.events
Write only. Creates the booking events our own system generates, under an event identifier we generate ourselves. We never read events back.

Availability data read via calendar.freebusy is processed on Strata's own servers to compute a list of bookable time slots. Only that computed list of times is passed to our AI receptionist. Google Calendar event content — titles, attendees, descriptions and guest lists — is never transmitted to any AI model or third-party AI provider.

Two third-party AI providers are involved and no others; we run no self-hosted and no offline models. Google provides the Gemini API model gemini-3.5-flash-lite for the chat and messaging channels, accessed on a paid tier under our own billing account. Google receives conversation text, and the audio of voice notes and the images of photos customers send on WhatsApp, to transcribe or describe them. Every photo is sent to be described, including one that is then recognised as an identity document or a bank card and not kept. Under Google's paid-tier terms for the Gemini API, prompts and responses, that audio and those images included, are not used to train or improve Google's models. Retell AI runs the voice channel as a gateway, receiving call audio, the transcripts it produces and the fields the agent collects; it operates the conversational model under its own contract with the upstream model provider rather than under ours, and is engaged by us under a signed Data Processing Addendum.

Strata's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Raw and derived user data received from Google Workspace APIs is never used to develop, improve or train generalised or foundational AI/ML models.

6. How long we keep it

We keep the information described above for as long as the account it relates to is open. We do not currently delete or anonymise lead and conversation records on a fixed schedule.

The one-way code that stands in for a WhatsApp number is meant to be cleared 90 days after the conversation ends, keeping only the counts, which identify nobody. That clean-up is part of the automatic clean-up described above, which is not switched on today, so at present the code is kept until we clear it on request.

Call recordings are kept until we delete them on request.

Kept photos are kept until we delete them on request.

If you want information about you deleted sooner, ask us — see section 8 — and we will confirm what was removed. Account and billing records are kept for as long as the account is active and thereafter for the period South African tax and company law requires.

7. How it is protected

  • Transport is encrypted end to end; session cookies are HTTP-only and same-site.
  • Tenant data is isolated at the application layer and enforced again by row-level security in the database, so a scoping mistake returns nothing rather than another tenant's data.
  • Third-party credentials, including calendar refresh tokens, are encrypted at rest.
  • The public-facing conversational runtime holds no database credentials at all.

No system is perfectly secure. If a breach affects your personal information we will notify you and the Information Regulator as section 22 of POPIA requires.

8. Your rights

You may ask us to confirm what we hold about you, to correct it, to delete it, or to stop processing it, and you may object to processing. Write to the Information Officer above; we will respond as soon as reasonably possible, and within the period POPIA allows. If a receptionist deployed by one of our clients captured your details, we will route your request to that client, who is the responsible party for it.

You may also complain directly to the Information Regulator (South Africa) at inforegulator.org.za.

9. Changes

We will post any material change to this policy here and update the date at the top. Continued use of the Hub after a change means you accept the revised policy.

Strata Automation // Gauteng, ZA

support@strataautomation.tech