Privacy Policy

Last updated: June 2026

Tellexa (Pty) Ltd. (“we”, “us”, “our”) is committed to protecting personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA). This Privacy Policy explains how personal information is processed when you use Tellexa’s services.

1. Our Role in Data Processing

For the purposes of POPIA:

You (the customer) are the Responsible Party in respect of personal information processed using Tellexa’s services.

Tellexa acts as an Operator, processing personal information solely on your documented instructions and only for the purpose of providing the services.

Tellexa does not determine the purpose for which personal information is processed through the platform, except where required to operate, secure, and improve the service in a lawful and aggregated manner.

You warrant that you have a lawful basis to collect, use and submit personal information to the Services and that you have provided any required notices to data subjects. Tellexa does not independently verify the legality, accuracy, or completeness of personal information submitted by customers.

Tellexa has no obligation to monitor, review, or verify the legality, accuracy, or completeness of personal information submitted by users and shall not be deemed to have knowledge of any unlawful processing carried out through the Services.

2. Information We Process

We process the following categories of information, depending on how you use the services:

2.1 Account Information

Name, email address, phone number, company details, and login credentials provided when registering or administering an account.

2.2 Customer Content

Messages, commands, documents, files, and other content submitted to or generated through Tellexa’s AI Assistants via Telegram, WhatsApp, web interfaces, or integrations.

2.3 Usage and Technical Information

Information about how the services are used, including feature usage, timestamps, device information, IP addresses, and browser type. This information is processed primarily for security, reliability, and service performance.

2.4 Billing Information

Billing and payment details processed securely by authorised third-party payment providers. Tellexa does not store full payment card details.

2.5 Location Information (Mobile App)

The Tellexa mobile application can collect precise and approximate device location data, including GPS coordinates, in order to power optional features such as travel-time and “leave by” estimates, trip and driving insights, mileage and activity tracking, and location-based reminders or geofences.

Location collection is entirely under your control and is disabled by default. Tellexa does not access or collect any location data unless you explicitly grant the relevant operating-system permission and turn the feature on within the app. You can turn location off at any time — both inside the app and through your device settings — and you may revoke the permission entirely. When location is disabled, no location data is collected.

Where you enable background location (for example, automatic trip detection), the app may collect location while it is running in the background, and only for as long as the feature remains enabled. Location data is used solely to provide these features to you, is processed and stored on the same logically isolated, encrypted basis as your other customer content, is never sold, and is not used for advertising or shared with third parties for their own purposes. To minimise data collection and battery use, the app processes location on-device and pauses location collection when your device is stationary.

2.6 Other Mobile Device Permissions (Opt-In)

The mobile app may, with your separate permission, access the following on-device data. Each is disabled until you grant the operating-system permission and use the feature it powers, and each can be revoked at any time in your device settings:

Contacts — read only when you use a contact-aware feature (e.g. resolving a name you mention, building your on-device VIP/context list, or saving a contact). Your address book stays on your device; only the specific details required to fulfil an action you request are sent to your assistant.

Photos and images — accessed only when you choose to attach an image in chat. The selected image is sent to your assistant’s AI provider for processing; generated images are saved back to your library only when you tap Save. We do not access your wider camera roll. The camera itself is used only to scan the sign-in QR code; no photos or video are recorded.

Calendar — read on-device to prepare meeting briefings, and written to when you ask the assistant to add an event.

Motion and activity data — device motion sensors are used, with the relevant feature enabled, to detect driving or activity and switch to a hands-free interface. This is processed on-device; only derived trip and activity summaries are synced.

Microphone — used only while you are recording a voice memo or using voice features. The app does not collect SMS messages or call logs.

3. Lawful Basis for Processing

Tellexa processes personal information on the following lawful bases under POPIA:

performance of a contract with you;

compliance with legal obligations;

legitimate interests, including securing, maintaining and improving the Services, provided such processing does not override data subject rights; and

consent, where required and explicitly obtained.

Where Tellexa acts as an Operator on customer instructions, the customer determines and warrants the applicable lawful basis for processing personal information.

Where Tellexa relies on legitimate interests, such processing relates solely to securing, maintaining and improving the Services and does not alter Tellexa’s role as Operator in respect of customer content.

4. How We Use Personal Information

Personal information is processed only to the extent necessary to:

Provide, operate, and maintain the Tellexa services

Process transactions and manage subscriptions

Respond to enquiries, support requests, and communications

Deliver system notifications, updates, and security alerts

Monitor service usage and performance in an aggregated and non-identifying manner

Provide optional location-based features (such as travel-time estimates, trip and driving insights, and geofenced reminders) where you have enabled them — see section 2.5

Detect, prevent, and investigate security incidents, fraud, or misuse

Tellexa does not use identifiable customer data to train general-purpose AI models.

5. AI Processing and Model Use

Customer content is processed by AI systems only to deliver the requested service outputs.

Customer data is logically isolated between customers.

Customer data is not used to train AI models for other customers.

Where third-party AI providers are used, they act as sub-operators and process data under contractual confidentiality and security obligations.

Tellexa does not permit third-party AI providers to use customer data for their own model training.

AI-generated outputs may contain personal information derived from customer inputs. Customers remain solely responsible for reviewing outputs before distribution or reliance.

6. Data Storage and Security

Tellexa implements appropriate technical and organisational measures to safeguard personal information, including:

Encryption in transit using TLS 1.3

Encryption at rest using AES-256

Role-based access controls and multi-factor authentication

Audit logging and access monitoring

Regular security assessments

While Tellexa implements appropriate safeguards, no method of transmission or storage is completely secure.

Further details are available in our Security Policy.

7. Data Retention

Personal information is retained only for as long as necessary to provide the services.

Upon cancellation or termination, customer data is retained for up to 90 days, after which it may be permanently deleted or anonymised in Tellexa’s discretion, unless retention is required by law.

Backup data is subject to controlled retention schedules and secure deletion processes.

8. Sharing of Personal Information

Tellexa does not sell personal information.

Personal information may be shared only with:

Service providers and sub-operators (e.g. cloud hosting, payment processing, AI providers) acting under written agreements

Legal or regulatory authorities, where required by law

Successors in business transfers, subject to equivalent data protection safeguards

All sharing is limited to what is necessary to provide the services.

9. International Data Transfers

Personal information may be processed in countries outside South Africa where Tellexa or its sub-operators operate. In such cases, Tellexa ensures that appropriate safeguards are in place in accordance with section 72 of POPIA.

By using the Services, you acknowledge and accept that processing may occur in jurisdictions with different data protection standards, subject to appropriate safeguards.

10. Data Subject Rights

Data subjects have the right to:

Request access to personal information

Request correction or deletion

Object to certain processing

Withdraw consent where applicable

Lodge a complaint with the Information Regulator

Requests may be subject to identity verification and lawful limitations under POPIA.

Where Tellexa processes personal information as an Operator on customer instructions, we may refer requests to the relevant customer (as Responsible Party) where appropriate. We may require sufficient information to verify identity and locate the relevant data.

11. Children’s Privacy

Tellexa’s services are not intended for individuals under 18 years of age. We do not knowingly process personal information relating to children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the website or other appropriate channels.

13. Contact Details

For privacy-related enquiries or requests:

Tellexa – Privacy & Data Protection

Email: privacy@tellexa.ai