Skip to content
  • KAIRO The GRC hub
  • KNECT Onboarding, KYC and AML
  • CORA Revenue operations
Platform
  • Risk & compliance Continuous governance, risk and compliance
  • Customer onboarding KYC and AML at the front door
  • Sales & revenue Pipeline to signed renewal
  • Procurement & supplier Supplier vetting and purchasing
  • Reporting & analytics Board-ready reporting and analytics
  • Talent management Measure capability, grow your people
  • Data solutions The unified data foundation
  • Small business The governed team you don't hire
  • Medium business A counterpart for every seat
  • Enterprise One thread across every entity
  • Consulting firms Govern client engagements
Trust
Live calendar · 30 min Book a demo

Products

KAIRO KNECT CORA
Platform

Solutions

Risk & compliance Customer onboarding Sales & revenue Procurement & supplier Reporting & analytics Talent management Data solutions

For your business

Small business Medium business Enterprise Consulting firms
Trust
Legal

Privacy policy

This notice covers the RUBIQ marketing website only: the information you give us when you book a demo, request a quote, or contact us, and what we do with it. The RUBIQ product application is governed separately under its own agreement.

Version
1.0
Effective
29 July 2026
Last updated
29 July 2026

On this page

  1. Who we are
  2. What we collect
  3. Why we use it, and our lawful basis
  4. Who we share it with
  5. Where your data is processed
  6. How long we keep it
  7. How we protect it
  8. Your rights
  9. Automated decisions
  10. Complaints
  11. Changes to this notice

Who we are

The responsible party (controller) for this website is Guideline BizTech (Pty) Ltd, registration number 2012/018904/07, the company behind RUBIQ. Our registered address is Block B, Ground Floor, Spaces Steyn City, Capital Park, Central Ln, Riverglen, Johannesburg, 2191.

Our Information Officer, registered with the Information Regulator of South Africa, is Werner Wilmot. For anything about your personal information or this notice, contact us at privacy@rubiqbiz.com.

What we collect

We only collect what a sales conversation needs. We do not ask for identity numbers, and we do not collect special-category information through this site.

Information you give us

When you submit a demo, quote, or contact form, we collect your name, work email, company name, phone number (optional), and the message you write, plus whether you opted in to marketing.

Information collected automatically

Our host (Vercel) keeps standard server logs (IP address, browser type, pages requested, timestamp) to operate and secure the site. We do not use cookies or any non-essential device storage, and we do not run advertising or cross-site tracking. See our cookie notice for detail.

We use Plausible for privacy-friendly, cookieless analytics: it sets nothing on your device, does not identify you, and processes data on EU-based infrastructure. If our analytics approach changes, we will update this notice and the cookie notice first.

Why we use it, and our lawful basis

We process your information for clearly defined purposes, each with a lawful basis under POPIA and (for visitors in the EU/UK) the GDPR.

  • To respond to your enquiry and arrange your demo or quote. Lawful basis: steps taken at your request before entering a contract, and our legitimate interest in replying to people who ask to hear from us (POPIA s11(1)(b) and s11(1)(f); GDPR Art 6(1)(b) and 6(1)(f)).
  • To send you marketing, only if you ask us to. Lawful basis: your consent, given through the separate, unticked checkbox on our forms (POPIA s69; GDPR Art 6(1)(a)). Booking a demo does not sign you up for marketing, and you can withdraw consent at any time.
  • To run, secure, and improve the website. Lawful basis: our legitimate interest in keeping the site available and protected from abuse (POPIA s11(1)(f); GDPR Art 6(1)(f)).

Who we share it with

We do not sell your personal information. We share it only with the service providers (operators / processors) that help us run the site and follow up on your enquiry, each under a written agreement that limits them to acting on our instructions:

  • Website hosting: Vercel, Inc. (United States), which hosts the marketing site and processes server log data;
  • CRM, for managing your enquiry: CORA by Guideline BizTech (cora.rubiqbiz.com). We use our own CORA product internally to record and follow up on sales enquiries; Guideline BizTech is both the controller and the operator of this data, and it is not shared with a third party;
  • Transactional email and calendar: Microsoft 365 (Microsoft Corporation, United States), which delivers booking confirmations, demo calendar invites, and form acknowledgement emails through Microsoft Exchange Online and Microsoft Bookings.

We may also disclose information where the law requires it, or to establish, exercise, or defend a legal claim. A current list of our operators is available on request.

Where your data is processed

Some of our operators process data outside South Africa. Where they do, we put a safeguard in place before any data flows: a written operator agreement imposing protection comparable to POPIA, together with the relevant standard contractual clauses for transfers from the EU or UK (POPIA s72; GDPR Chapter V). South Africa is not on the EU's list of countries with "adequate" protection, so for any EU or UK personal data we rely on those clauses and a short transfer assessment rather than adequacy.

The operators and destinations are:

  • Vercel, Inc. (United States). Vercel's data processing addendum and standard contractual clauses are in place.
  • Microsoft Corporation (United States and EU data centres; Microsoft 365 regional settings apply). Microsoft's data processing agreement and standard contractual clauses are in place.
  • CORA (Guideline BizTech), South Africa. No cross-border transfer.

This list is also kept on our trust centre, current as our vendors change.

How long we keep it

We keep your information only as long as the purpose needs, then delete or anonymise it:

  • Enquiries that do not progress to a sale: 24 months from last contact, then deleted or anonymised.
  • Active sales conversations and customers: kept under our CRM lifecycle for as long as the relationship is active, plus any period required by law.
  • Server logs (Vercel): 30 days, in line with Vercel's standard log retention.
  • Marketing consent: kept until you withdraw it, plus a record of the consent itself for as long as we may need to demonstrate it.

How we protect it

We apply appropriate, reasonable technical and organisational safeguards to keep your information secure, in line with POPIA Condition 7 (security safeguards) and the GDPR's data-protection-by-design principle (Art 25): encryption in transit (TLS), access on a need-to-know basis, and a site built to minimise the data it holds. Guideline BizTech is ISO 27001:2022 Certification Ready. We describe our wider security posture, and how to report a vulnerability, on our trust centre.

Your rights

You have the right to:

  • Access the personal information we hold about you, and ask where we got it.
  • Correct or delete information that is inaccurate, out of date, or no longer needed.
  • Object to processing based on legitimate interest.
  • Withdraw consent for marketing at any time, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with a regulator (see below).

To exercise any of these, email privacy@rubiqbiz.com. We will acknowledge your request within 2 to 3 business days and respond in full within 30 days, and may need to confirm your identity first. There is no charge for a reasonable request.

Automated decisions

This website does not make any decision about you by automated means, and does not profile you. The enquiry you submit is read and handled by a person.

Complaints

If you are not satisfied with how we have handled your information, you can complain to the regulator:

Information Regulator (South Africa)

Online: inforegulator.org.za. Complaints: PAIAComplaints@inforegulator.org.za.

If you are in the EU or UK, you may also complain to your local supervisory authority (in the UK, the Information Commissioner's Office, ico.org.uk).

Changes to this notice

We update this notice when our practices change. The version and dates at the top of the page tell you which version you are reading. Material changes will be reflected here before they take effect.

This notice covers the marketing website. If you become a RUBIQ customer, the handling of data inside the product is governed by the separate agreement and data-processing terms you sign for the product.

Back to top ↑

RUBIQ

The AI-augmented governance platform that turns fragmented operations and manual compliance into one governed business, in real time.

Products

  • KAIRO
  • KNECT
  • CORA
  • Platform
  • The names

Solutions

  • Risk & compliance
  • Customer onboarding
  • Sales & revenue
  • Procurement & supplier
  • Reporting & analytics
  • Talent management
  • Data solutions

For your business

  • Small business
  • Medium business
  • Enterprise
  • Consulting firms

Company

  • Contact
  • Trust
  • Privacy
  • Terms
  • Cookies
  • PAIA manual

© 2026 RUBIQ · Guideline BizTech (Pty) Ltd

ISO 27001:2022 Certification Ready · POPIA & GDPR aligned