Current number-linking policy

The WhatsApp ownership-code challenge is temporarily disabled. You must still control or be authorised to enrol the number. Email verification and service consent remain required; adding a number does not prove ownership. Each number can belong to only one account and must be removed before another account can link it. LINK instructions below describe the verification-enabled process, which may be reinstated.

SAYDO

Effective 31 August 2026 · version 2026-08-31.1

SAYDO Privacy Notice

This notice explains how Amax Digital (Pty) Ltd, registration number 2021/365987/07, trading as SAYDO, processes personal information when you visit the SAYDO website, register, use the dashboard, link a WhatsApp number, send content to the official SAYDO WhatsApp account, use AI or search features, pay through PayFast, or contact support. Amax Digital is the responsible party for that processing unless a written business arrangement says otherwise.

1. Responsible party and scope

This notice applies to SAYDO's public website, account registration, customer dashboard, official WhatsApp service, subscription and credit functions, account support, security and administration. It does not govern WhatsApp, OpenAI, PayFast, Google or another provider acting for its own purposes under its own terms. Where a business customer determines why its authorised staff or contacts use SAYDO, the business may also have responsibilities under POPIA and must give those people any notice it is required to give.

Responsible party: Amax Digital (Pty) Ltd, registered in the Republic of South Africa. Registered and legal-service address: 262 Jack Hindon Street, Pretoria, Gauteng, 0182, South Africa. Privacy contact: info@saydo.co.za or +27 12 761 7894.

2. Personal information SAYDO processes

CategoryExamples
Account and identityName, email address, username, password hash, account type and status, chosen settings, verification status, linked-number ownership and consent records.
WhatsApp identity and deliveryNormalised phone number, Meta WhatsApp ID, profile name supplied by WhatsApp, preferred language, inbound and outbound Meta message IDs, delivery state, reply/quoted-message references and timestamps.
Content you submitText, voice notes, forwarded audio, images, documents, filenames, questions, replies, commands and interactive choices sent to SAYDO. This can include information about another person.
Generated and derived contentTranscripts, polished transcripts, AI responses, summaries, drafts, extracted tasks, attachment answers, language indicators, token estimates, content length and message classifications.
Memory and searchEncrypted saved messages and archive entries, date tags, keyed word hashes and frequencies, content fingerprints, encrypted search queries, result rankings and encrypted embedding vectors. Text used to create an embedding is sent to OpenAI.
Usage and entitlementPlan, trial and subscription state, linked-number count, credit buckets and ledger entries, monthly text/voice/attachment totals, token and audio-duration totals, limits, warnings and renewal dates.
Billing and transactionCustomer name and email used for checkout, server-owned order ID, item, final amount, recurring frequency, payment status, provider payment and subscription references, gross/fee/net values, validation results, cancellation and reconciliation state. Acceptance evidence can include the product, amount, allowance, number capacity, frequency, approximate next charge date, until-cancelled duration, applicable legal-document versions, acceptance time, a tracking-only annual reaffirmation due date, and protected IP/browser hashes. A stored reaffirmation due date records an operational follow-up point; it is not itself fresh acceptance, a renewal instruction or authority to charge. PayFast, not SAYDO, collects card number and CVV.
Security and administrationHashed IP address and user-agent values, session and login state, rate-limit events, audit events, support actions, administrator view-as events, job status, error codes and security or incident evidence. SAYDO avoids putting message content and secrets in ordinary logs.
Website and preferencesCookie/consent choice, theme and timezone settings, page interactions, landing page and, when present, campaign parameters such as UTM values, Google or Meta click identifiers, and first-party Meta browser identifiers.
Requests and correspondenceSupport messages and requests to access, correct, object to, export, reset, clear or delete information.
Product feedbackWhether a feedback invitation was offered, accepted or dismissed; delivery status; and feedback text voluntarily submitted through WhatsApp. Feedback text is encrypted at rest and is not sent to the AI merely because it was submitted as feedback.

A voice recording is processed to transcribe it or carry out the requested AI task. SAYDO does not use voice recordings to identify or authenticate people biometrically. Do not submit payment-card details, authentication secrets, government identifiers, health records or other sensitive information unless it is necessary, lawful and permitted by WhatsApp's rules.

3. Where information comes from

Most information comes directly from you: from registration and dashboard forms, the WhatsApp number you link, content sent to the official SAYDO number, checkout choices and support requests. Meta provides message, sender, media and delivery metadata. PayFast provides payment and recurring-subscription notifications and reconciliation information. OpenAI returns transcription, AI, usage and provider-object information. Security, usage and audit data are generated when the service operates. A business account holder or authorised SAYDO administrator may create an invitation or add account details after confirming that the person requested or authorised it.

SAYDO does not scrape WhatsApp Web, import personal chat history, monitor conversations with other contacts or read content that was not sent or deliberately forwarded to the official SAYDO account.

4. Purposes and legal justifications

SAYDO processes personal information only where a justification permitted by POPIA applies. Depending on the activity, this includes your consent; taking steps at your request or performing the service agreement; complying with legal duties; protecting your or another person's legitimate interests; and SAYDO's legitimate interests in supplying, securing, measuring and improving the service without overriding your rights.

5. WhatsApp consent and number linking

Registration asks separately for permission to receive SAYDO account, verification, service, usage, credit and billing messages at the number supplied. A number is not authorised for AI processing merely because it was typed into a form. The person must prove control by sending the displayed, single-use LINK command from that exact number to SAYDO. If an unregistered person first messages SAYDO, the service may send a limited registration or help response.

You can withdraw WhatsApp-service consent by sending STOP, contacting support, closing the account or, for an eligible Business-linked number, having the Business account owner remove it. STOP suspends new WhatsApp processing and cancels eligible queued work for that number; it does not itself delete retained history or close the dashboard account. Reconnection requires fresh consent and a new number-link proof. Service messages outside WhatsApp's user-initiated service window may require a provider-approved template.

6. Content about other people, voice and files

You must have authority and a lawful reason to submit a voice note, image, document, quoted message or other content concerning another person. If notice or consent is required to record, forward, transcribe, summarise, search or otherwise process that content, you are responsible for obtaining it before submission. Forwarding content to SAYDO creates a new disclosure to SAYDO and its operators; it is not made lawful merely because the content already appeared in WhatsApp.

Supported media is downloaded into restricted temporary processing storage and may be sent to OpenAI for transcription or analysis. On the normal job path, the local temporary copy is removed when the processing attempt finishes. A separate bounded worker cleanup recognises only SAYDO's per-job media directories and removes directories that have remained unchanged for 23 hours; it processes at most 100 recognised candidate directories in one run and drains a larger backlog over later runs. A host outage, missed worker run, permission failure or backup can delay removal until the next successful cleanup or backup rotation. Attachment files uploaded to OpenAI are scheduled for provider deletion when the encrypted attachment context expires or the account is deleted. Provider-controlled copies follow the provider's own controls; see the retention schedule.

7. AI, OpenAI conversation state and searchable memory

Each linked WhatsApp sender has a separately routed OpenAI conversation. That conversation supplies short- and longer-term context for AI replies until it is reset, cleared, deleted or becomes invalid. SAYDO may compact long context through the supported OpenAI mechanism; compaction can summarise prior content and may omit detail. The dashboard's saved memory is a separate SAYDO database feature and is not ChatGPT consumer memory.

Searchable memory is enabled by default for newly linked numbers. While it is on, SAYDO stores an encrypted sender-owned record and conversation archive of supported user messages, voice transcripts, attachment questions, selected actions, commands and SAYDO replies. It also stores keyed word hashes and frequencies for private keyword lookup and encrypted vector embeddings for meaning-based search. Search queries and selected results may be sent to OpenAI when an AI or semantic search requires them. A WhatsApp FIND answer that consumes a credit first shows its period and estimated context and requires the user's confirmation.

You can turn memory off, clear saved memory, delete history or reset AI context using the offered dashboard or WhatsApp controls. Turning memory off purges the local saved memory, archive, search sessions and embeddings for the affected linked identity, but does not retroactively erase provider logs, backups or information that another lawful record must retain. AI and transcription can be inaccurate; SAYDO does not use AI output as the sole basis for a decision that produces legal or similarly significant effects about you.

8. Who receives information

SAYDO does not sell personal information. SAYDO does not use customer content to train its own general-purpose model. OpenAI states that API data is not used to train its models by default unless the API customer explicitly opts into data sharing; provider settings, exceptional safety retention and provider terms remain relevant.

9. Business accounts and authorised administration

A business account can link more than one WhatsApp number and uses one shared account and credit pool. The business account holder can view, search, filter and export retained messages, transcripts and AI responses belonging to all numbers linked to that business account. A person using a business-linked number should therefore understand that the business account holder, not only the individual phone user, can access that retained content.

Removing a team number immediately revokes new SAYDO use, suspends its routing and cancels eligible queued work. It does not automatically delete that number's already retained account history; the history remains linked to the business account until its normal expiry or an authorised memory/history/account-deletion process removes it. A business must keep at least one linked number while the account remains in use.

SAYDO administrators can manage account, billing, health and security information. An authorised administrator can enter a clearly marked, audited “view as” mode that exposes the same customer workspace, including decrypted retained content, for support, security and operations. Administrative access is not intended for casual browsing and is recorded in portal audit events.

10. Cookies, local storage and website analytics

The authenticated dashboard uses a secure, HTTP-only session cookie so the service can keep you signed in; JavaScript cannot read that cookie. The marketing website uses browser local storage to remember the cookie-consent choice. It can also retain first-party campaign attribution such as UTM fields, landing page, Google and Meta click identifiers, and Meta _fbp/_fbc identifiers for up to 90 days when the relevant analytics or advertising choice permits that processing.

Non-essential Google Analytics, Google Ads and Meta advertising measurement is controlled through the website preference panel. Rejecting non-essential use leaves those categories denied and prevents the browser Meta Pixel from loading. Accepting advertising measurement permits the Pixel to activate immediately and allows SAYDO to retain attribution across signup, WhatsApp connection and confirmed payment. You can reopen Cookie settings on the marketing site, change the choice and clear site data in your browser. Google and Meta may set or read their own identifiers after the relevant choice is granted and process that information under their own terms. Necessary security, session and preference storage cannot always be switched off while using the affected feature.

11. International processing

Meta, OpenAI, Google, PayFast and infrastructure or email providers may process information in South Africa and other countries through their own facilities and subprocessors. Countries outside South Africa may have different privacy laws. SAYDO must use a transfer ground permitted by section 72 of POPIA or other applicable law, such as adequate protection, a binding operator arrangement, consent where suitable, contract necessity or another authorised basis. Provider terms, data-processing terms and transfer safeguards may change and must be reviewed operationally.

12. Retention and deletion

SAYDO uses category-specific periods instead of keeping every record for the same time. The configured defaults are 30 days for voice and attachment reply context, 90 days for selected completed/rejected operational records, and 365 days for searchable memory/archive, product-feedback text and database audit records, plus the period shown in the account where a contact-specific memory period differs. A never-activated public registration can be removed after 30 days only when it has no linked contact, billing, audit or other ownership record. An unaccepted administrator invitation can be removed after 30 days only when it has no WhatsApp contact, payment-mandate acceptance, validated order or transaction, audit or other ownership evidence; the cleanup may then also remove that invitation's sole suspended phone placeholder and unused internal Trial records. Recent, resumed, accepted, linked, audited or financially referenced identities are preserved. Payment, tax, fraud, dispute and provider-controlled records have different rules. Not every metadata table is covered by the 90-day operational purge, and current protected backups and hosting logs do not expose one universal record-by-record deletion timer.

The complete current schedule, including automatic deletion boundaries, provider retention and known operational exceptions, is published at Data Retention & Deletion. If this notice and that schedule differ, the more specific current schedule applies to retention mechanics, while applicable law always prevails.

13. Account deletion and exports

Self-service account deletion requires the current password and the exact confirmation phrase. The workflow first revokes WhatsApp execution, deletes linked OpenAI conversations, schedules attachment-file deletion, removes the local phone/contact mappings and sender content, cancels recurring billing, removes active credit buckets and sessions, and disables the portal account. The portal identity is pseudonymised rather than removing the database row because validated payment, refund, tax, fraud and dispute evidence can remain linked to a non-identifying internal owner.

If a provider cancellation or deletion fails, the workflow can remain incomplete while the retry or operational investigation runs; it must not silently restore WhatsApp access or credits. A later PayFast notice can be retained for reconciliation but cannot reopen a deleted account. Provider logs, exceptional legal/security holds and protected backups may outlive completion as described in the retention schedule.

The dashboard can generate CSV or Excel exports of the user's current filtered view or retained account memory. Export content is decrypted for the authenticated request and delivered as a download; after download, you or the business account holder is responsible for securing, sharing and deleting the copy on the receiving device.

14. Your POPIA choices and rights

Subject to POPIA and other applicable law, you may ask whether SAYDO holds personal information about you; request access to it; ask that inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information be corrected or deleted; object to processing on a permitted ground; withdraw consent; object to unsolicited electronic direct marketing; and complain to the Information Regulator. A request may be limited where another person's rights, legal privilege, security, fraud prevention, accounting duties or another lawful ground applies.

You can manage some choices directly: use MEMORY OFF, CLEAR MEMORY, RESET, DELETE HISTORY or STOP where offered, use dashboard settings and deletion controls, or contact info@saydo.co.za. SAYDO verifies identity and authority before disclosing, changing or deleting account information. PAIA record-access procedures are in the PAIA Manual.

15. Security and incidents

Current safeguards include HTTPS and HSTS, secure session cookies, password hashing, encrypted private content and vectors at rest, restricted private storage, parameterised database access, sender and tenant ownership checks, signed Meta webhooks, validated PayFast notifications, idempotent provider processing, size and rate limits, bounded job retries, audit events, role checks and scoped administrator view-as access. Card details stay on PayFast's hosted payment surface. No safeguard eliminates all risk.

If SAYDO has reasonable grounds to believe an unauthorised person accessed or acquired personal information, it will investigate, contain and document the incident and notify the Information Regulator and affected people as soon as reasonably possible where POPIA requires it, subject to a lawful delay or regulator/law-enforcement direction. Report suspected compromise promptly to info@saydo.co.za.

16. Children and prohibited use

SAYDO is intended only for people aged 18 or older and does not knowingly offer accounts to children. Do not use SAYDO to collect or submit children's information unless a separately approved lawful workflow and the required guardian or other legal authority exist. If you believe a child supplied information, contact us so the matter can be investigated and handled appropriately.

17. Changes to this notice

SAYDO may update this notice when the product, providers, data practices or law changes. The effective date and version appear above. Where notice is required, SAYDO will use an appropriate operational channel such as the website, dashboard, email or WhatsApp. Where fresh consent is required, the affected new charge or change will not rely on a stored notice version or tracking-only reaffirmation date as if it were fresh acceptance. Earlier versions, communications and acceptance evidence may be retained for contract, audit or dispute purposes.

18. Contact and complaints

Send privacy, access, correction, objection, deletion or incident requests to the Information Officer function at info@saydo.co.za, telephone +27 12 761 7894, or the registered address in section 1. Include enough information to identify the account and request, but do not email passwords, full card details or verification codes.

You may complain to South Africa's Information Regulator using its current published channels, including POPIAComplaints@inforegulator.org.za for POPIA complaints or PAIAComplaints@inforegulator.org.za for PAIA complaints. The Regulator's published contact details and forms should be checked at inforegulator.org.za.