Privacy

Privacy is not a policy. It is an engineering principle.

Insight Keepers combines privacy, data governance, security and artificial intelligence to help organisations build measurable and continuously improving trust in their data environment.

Insight Keepers is designed with privacy and security considerations from the beginning, helping organisations establish governance that is transparent, accountable and proportionate to risk.

Our Privacy Commitments

Privacy commitments behind every release

You remain in control of your data

Customer data stays under the control of the organisation that provides it. We process information only for legitimate purposes connected to providing, securing and improving the platform.

We do not sell customer data

Insight Keepers does not sell customer data to third parties. Customer information is never treated as an asset for advertising or unrelated commercial purposes.

Privacy by design

Privacy considerations are built into our platform, workflows, data architecture and AI capabilities from the beginning.

Transparency

We aim to provide clear information about how information is collected, processed, stored, secured and governed.

Security and privacy work together

Access control, encryption, authentication, monitoring, data minimisation, retention and incident management are core components of responsible privacy governance.

Accountability

Our platform helps organisations establish ownership, assign responsibilities, document decisions, maintain evidence and monitor remediation.

Privacy and Regulatory Frameworks

Governance across multiple privacy and security frameworks

Privacy obligations differ by jurisdiction, information type and activity. Insight Keepers is designed to support governance across the frameworks that matter to your organisation.

POPIA

Protection of Personal Information Act

A foundational privacy framework for organisations operating in South Africa. We help translate privacy requirements into practical governance activities, controls, evidence and remediation workflows.

GDPR

General Data Protection Regulation

Supports data mapping, accountability, assessments, evidence management and privacy risk management for organisations processing personal data within the GDPR scope.

ISO/IEC 27001

Information security management

Provides an important foundation for protecting information and managing information security risk.

ISO/IEC 27701

Privacy information management

Extends information security governance into privacy management and provides a reference point for structured privacy programmes.

AI Governance

Artificial intelligence governance

Brings data usage, automated decision making, transparency, accountability and model risk into the broader governance environment.

How We Protect Information

Security and privacy embedded into the architecture

Our security model is designed around multiple layers of protection.

Identity and access

Authenticated identities, role-based permissions and least-privilege principles. Access rights reflect the responsibilities of each user and organisation.

Encryption

Sensitive information is protected using appropriate encryption mechanisms for data in transit and at rest.

Tenant isolation

Customer environments are logically separated in our multi-tenant architecture to help prevent unauthorised access between organisations.

Auditability

Important activities are recorded to support accountability, investigation and governance, who performed an activity, when it occurred and what action was taken.

Monitoring

Security and operational monitoring help maintain the integrity and availability of the platform as it evolves.

Customer Data Processing

Processing governed by agreement and instruction

Insight Keepers may process information on behalf of customers when providing platform functionality. The specific responsibilities depend on the service, the information involved and the applicable contractual arrangements.

Where Insight Keepers processes personal information on behalf of a customer, our processing is governed by appropriate contractual terms and documented instructions.

Customers remain responsible for determining the lawful basis, purpose and governance requirements applicable to their processing activities. Insight Keepers provides technology to support these responsibilities, it does not replace the legal, compliance or governance responsibilities of the organisation using the platform.

Data minimisation

Organisations should collect and process only the information necessary for legitimate and defined purposes. Insight Keepers supports governance capabilities that help identify what information is processed, why, where it is stored, who can access it, how long it should be retained, which systems process it, which controls protect it and what risks are associated with it.

Data retention and deletion

Data should not be retained indefinitely without a legitimate purpose. Insight Keepers supports retention requirements, identifies information subject to retention obligations and helps establish deletion or disposal workflows. Specific retention periods depend on applicable law, contractual requirements, organisational policies and legitimate business requirements.

Data Subject Rights

Supporting privacy request governance

Privacy regulations may provide individuals with rights relating to their personal information. The organisation responsible for processing remains responsible for determining whether a request is valid and how it should be fulfilled.

AccessCorrectionDeletionObjectionRestriction of processingData portabilityAutomated decision making

Insight Keepers provides governance capabilities that can help organisations identify information, document processing activities, maintain evidence and support responses to privacy requests.

Artificial Intelligence and Privacy

AI governance as part of the broader trust environment

Artificial intelligence can create new opportunities while introducing additional data governance considerations. Our approach connects AI governance with privacy, security, data governance and risk management.

What data is being used?

Where did the data originate?

What purpose is the data being used for?

Does the organisation have an appropriate lawful basis?

Is personal information being processed?

What decisions are being influenced by the system?

What level of human oversight exists?

What evidence supports the governance decision?

What risks could arise from the AI system?

Third Party Providers and Subprocessors

Contractual and governance measures for subprocessors

Modern cloud platforms rely on technology providers that may support infrastructure, security, communications, analytics and other services. Insight Keepers evaluates relevant service providers based on security, reliability, privacy and operational requirements.

Where third parties process information on behalf of Insight Keepers or its customers, appropriate contractual and governance measures are applied based on the nature of the processing. Information about relevant subprocessors and service providers will be made available where appropriate.

International Data Transfers

Cross-border processing considerations

Personal information may be subject to cross-border processing or transfer requirements. Insight Keepers considers applicable data protection requirements when designing services and selecting technology infrastructure.

Where cross-border transfers are relevant, organisations should assess the applicable legal requirements, transfer mechanisms and appropriate safeguards. For South African organisations, this includes the requirements applicable to transborder information flows under POPIA.

Privacy by Design

Privacy should influence architecture from the beginning

Our privacy-by-design approach considers eight interlocking principles.

Data minimisation

Reduce unnecessary collection and processing.

Purpose limitation

Use information for defined and legitimate purposes.

Access control

Limit access to authorised individuals and systems.

Security

Protect information against unauthorised access, loss, alteration and disclosure.

Transparency

Make data processing understandable.

Accountability

Maintain evidence of governance decisions and responsibilities.

Retention

Avoid retaining information longer than necessary.

Human oversight

Keep significant AI-influenced decisions subject to appropriate accountability.

Privacy Governance Through Evidence

A continuous governance cycle, not a once-off exercise

Privacy programmes often fail not because organisations have no policies, but because they cannot demonstrate how those policies operate in practice.

Requirements
Controls
Policies
Data
Evidence
Risk
Remediation
Assurance

Insight Keepers connects requirements, controls, policies, data, evidence, risk, remediation and assurance into a continuous governance cycle.

Privacy Intelligence

From spreadsheets to continuous privacy intelligence

Traditional privacy management often relies on documents and periodic assessments. Insight Keepers is designed to move organisations toward continuous privacy intelligence.

Data

What information exists?

Risk

What could go wrong?

Controls

What safeguards are in place?

Evidence

Can we demonstrate that the controls operate?

Exposure

Where are the highest priority gaps?

Remediation

What needs to change?

Assurance

Can management demonstrate governance requirements are met?

Your Data. Your Governance. Your Trust.

Privacy is ultimately about trust. Trust that information is collected responsibly, used for legitimate purposes, protected, and that people remain accountable for important decisions. Insight Keepers exists to help organisations build that trust through measurable data, privacy, security and AI governance.

Stop chasing screenshots. Run your program.

Pick your frameworks, invite your team, and let AI surface the highest-impact next steps.