ATOM Business Platform
Privacy Policy
How ATOM Business Platform handles personal information, messages and connected-service data.
Effective date: 2026-09-15
1. Who we are
DigiMarkSA operates ATOM Business Platform (ABP), a multi-tenant platform used by businesses to capture, engage, qualify and follow up with leads and customers. This policy explains how ABP processes personal information.
2. Information we process
Depending on how ABP is used, information may include names, telephone numbers, email addresses, business details, lead-source data, message content, conversation history, appointment information, integration identifiers, usage records, audit/security logs and information voluntarily supplied during an enquiry.
3. WhatsApp, Facebook and Instagram
When a business connects Meta services, ABP may receive and process data supplied through Meta APIs, including WhatsApp identifiers, phone numbers, profile names, messages, delivery/status events and Lead Ads information. ABP uses this data to provide the communication and lead-management service requested by the connected business. Meta remains subject to its own terms and privacy practices.
4. ATOM Assistant and service providers
Businesses may enable ATOM Assistant to help classify enquiries, draft or send responses and qualify leads. In production, relevant conversation content may be sent to a configured model provider such as OpenAI for processing. ABP may also use infrastructure, email, SMS, calendar, payment and storage providers where enabled. Only information reasonably required for the requested function should be sent to a provider.
5. Purposes and lawful processing
Information is processed to provide and secure the platform, deliver messages and integrations, manage leads and appointments, provide support, maintain audit records, measure usage, prevent abuse, meet contractual obligations and comply with applicable law. Businesses using ABP are responsible for having an appropriate lawful basis and providing required notices to their own leads and customers.
6. POPIA and South Africa
ABP is designed for use in South Africa and recognises the Protection of Personal Information Act, 2013 (POPIA). Depending on the relationship, a subscribing business will generally determine why its customer information is processed, while the ABP operator processes that information to provide the platform. Cross-border service providers may be used where appropriate safeguards and contractual arrangements apply.
7. Retention
Operational data is retained only for as long as reasonably necessary for the service, contractual, security and legal purposes. The platform default retention setting is currently 365 days where that setting applies; particular records may be retained for a shorter or longer period where configured or legally required.
8. Security
ABP uses access controls, tenant separation, encrypted storage for supported secrets, password hashing, audit logging and other technical and organisational safeguards. No internet service can guarantee absolute security.
9. Your rights and deletion
Subject to applicable law, a person may request access, correction or deletion of personal information. Requests relating to data controlled by an ABP subscribing business may need to be handled by that business. Platform-level deletion instructions are available on our Data Deletion page.
10. Contact
Privacy enquiries: legal@digimarksa.co.za
Information Officer / POPIA: jaco.vermaak@digimarksa.co.za
11. Changes
This policy may be updated as the platform, integrations or legal requirements change. The effective date shown above identifies the current published version.