Legal
Privacy Policy
What we collect, why we collect it, where it is stored, how long we keep it, and every right you have over it under the Protection of Personal Information Act.
- Last updated 7 September 2026
- Version 1.2
- Embrisk is operated by Tapnet Solutions (Pty) Ltd.
1. Who we are
Embrisk ("Embrisk", "we", "us", "our") is an AI search and SEO intelligence platform for agencies, operated by Tapnet Solutions (Pty) Ltd, a South African company. Tapnet Solutions (Pty) Ltd is the responsible party as defined in the Protection of Personal Information Act 4 of 2013 ("POPIA"). This policy applies to this website and to any subscription or engagement between Embrisk and a customer.
Responsible party: Tapnet Solutions (Pty) Ltd
Information Officer: Wynand de Beer
Phone: 079 174 8357
Email: wynand@tapnet.co.za
Registered office: 594 Bombani Street, Elarduspark, Pretoria, 0181, South Africa
2. What personal information we collect
2.1 Information you provide directly
- Demo request data (/demo): Your name, work email address, agency name, the number of clients you manage, and anything you write in the notes field.
- Subscription data: For customers on a paid plan, the contact details of the account owner and the users they invite, billing details, and the workspace configuration they create.
- Client data you connect: Where you connect a property such as Google Search Console, we process the data that property returns. That data belongs to you and we process it only to provide the service. See Section 11.
- Correspondence: Emails, call notes and messages exchanged during a demo or an active subscription.
2.2 Information collected automatically
- Server logs: Standard web server and edge logs kept by our hosting provider for security and abuse monitoring, including IP address, user agent, requested path and timestamp. Retained for 30 days.
- No analytics or advertising tags. This website loads no third-party analytics, advertising, remarketing or session-recording script of any kind.
- No cookies. This website sets no cookies and writes nothing to your browser’s local storage. See Section 9.
3. Why we collect your information
| Data | Purpose | Legal basis |
|---|---|---|
| Demo request data | Reply to your request and arrange the call | Consent |
| Subscription and billing data | Provide the service you subscribed to and invoice for it | Contract performance |
| Connected client data | Produce the measurements, reports and recommendations you asked for | Contract performance |
| Correspondence | Support, account management, dispute records | Contract performance and legitimate interest |
| Server logs | Security, abuse prevention, incident investigation | Legitimate interest |
4. Who we share your information with
We share personal information only with the operators listed on our Operator Agreements page, and only to the extent necessary to deliver the service. We do not sell, rent or trade personal information, and we do not share it with advertisers or data brokers.
5. Cross border data transfers
Some of your personal information is stored and processed outside of South Africa. We use international cloud providers because they provide the reliability, edge network and security guarantees the service depends on.
5.1 Where your data is stored
| Processor | Purpose | Location |
|---|---|---|
| Vercel | Website and application hosting, edge delivery, server logs | Global edge, primary compute US and EU |
| Neon | PostgreSQL database for platform accounts and workspace data | Frankfurt, Germany (EU) |
| Upstash | Redis for rate limiting (hashed identifiers only) | Ireland (EU) |
| Google Workspace | Email and calendar for business correspondence and demo requests | US and EU (Google global infrastructure) |
See the Operator Agreements page for the full operator list, the Data Processing Agreements in place, and each operator’s security certifications.
5.2 How we protect data during transfers (Section 72 of POPIA)
POPIA permits the transfer of personal information outside of South Africa where one or more of the conditions in Section 72 are met. We rely on all of the following, collectively, for every transfer:
- Adequate protection (s72(1)(a)): Our database and rate limit infrastructure are hosted in the European Union, which is subject to the General Data Protection Regulation (GDPR). GDPR provides a level of protection substantially similar to, and in many respects stronger than, POPIA, including binding rules on onward transfer, breach notification and data subject rights.
- Binding contractual agreements (s72(1)(a)): Data Processing Agreements with every operator contractually bind them to protection standards equivalent to POPIA. This includes clauses addressing confidentiality, security, sub-processor management, breach notification, and return or deletion on termination.
- Your explicit consent (s72(1)(b)): By submitting the demo request form you explicitly consent to the cross border transfer of the personal information in it to the processors listed in Section 5.1.
- Contract performance (s72(1)(c)): The transfer is necessary to perform the service you are requesting.
5.3 Your right to object
If you object to cross border transfer of your personal information, email wynand@tapnet.co.za. We will explore South African hosting alternatives with you where commercially reasonable. In some cases we may not be able to deliver the service if cross border transfer is refused, and we will tell you before you commit to anything.
6. How long we keep your information
| Data type | Retention period |
|---|---|
| Demo requests that do not become customers | 24 months from submission |
| Subscription account and workspace data | Duration of the subscription, then 90 days for export and recovery |
| Connected client data and generated reports | Duration of the subscription, then deleted within 90 days of closure |
| Correspondence | Duration of the relationship plus 5 years (tax law) |
| Invoices and financial records | 5 years from creation (South African tax law) |
| Rate limit state (Redis) | Up to 24 hours rolling window, automatically expired |
| Server logs | 30 days |
When data is deleted, it is destroyed so that it cannot be reconstructed, in accordance with Section 14(4) of POPIA.
7. Your rights under POPIA
As a data subject, you have the right to:
- Access: Request a copy of all personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information, subject to legal retention requirements
- Object: Object to the processing of your personal information on reasonable grounds
- Withdraw consent: Withdraw any consent you have given, at any time
- Complain: Lodge a complaint with the Information Regulator
To exercise any of these rights, email wynand@tapnet.co.za with the subject line "POPIA request". We respond within 30 days, free of charge.
Information Regulator (South Africa)
Email: enquiries@inforegulator.org.za
Website: https://inforegulator.org.za
8. Security
- All traffic is served over HTTPS, with TLS encryption in transit
- Strict security headers: Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, HSTS
- The platform database (Neon) uses TLS connections with channel binding, encryption at rest, and automated point-in-time backups
- Where an IP address is used for abuse prevention it is passed through a salted SHA-256 hash before storage; the raw address is not persisted
- Public forms are protected by rate limiting, payload length limits and server side validation
- Access to production systems is granted on a need-to-know basis and revoked within one working day of a person leaving the engagement
- Third party operators used for hosting, database and productivity are SOC 2 Type II or equivalent certified
9. Cookies
This website sets no cookies. There is no consent banner because there is nothing to consent to: no analytics cookie, no advertising or remarketing tag, no session-recording script and no third party pixel. Nothing is written to your browser’s local storage either.
The authenticated Embrisk application, once you are a customer, uses a single strictly necessary session cookie to keep you signed in. It is HttpOnly, SameSite=Lax and Secure, it carries no tracking identifier, and it is set only after you sign in. Strictly necessary cookies do not require consent under POPIA.
If we ever introduce analytics, we will add a consent mechanism before any such script loads, and we will update this section first.
10. Direct marketing
We do not run a marketing newsletter and we do not add demo requesters to a mailing list. If that ever changes, we will only send marketing communications to people who have explicitly opted in, and every message will include a one-click unsubscribe. Transactional messages, such as replies to your enquiry, invoices and service notices, are not marketing and are sent as part of the service.
11. Data you connect on behalf of your own clients
Embrisk is sold to agencies, so some of the data in a workspace concerns the agency’s clients rather than the agency itself. For that data:
- You are the responsible party and we are the operator. We process it only on your documented instructions and only to provide the service.
- You are responsible for having a lawful basis to connect a client property and to share that client’s data with us.
- We do not use client data to train models, to build a cross-customer dataset, or for any purpose other than producing your measurements and reports.
- On termination we delete or return the data in accordance with Section 6 and your written instruction.
12. Children
Embrisk is intended for businesses and adults. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will delete it.
13. Data breach notification
If we become aware of a security breach that compromises your personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with Section 22 of POPIA. Notifications will include the nature of the breach, its potential consequences, and the protective measures we recommend.
14. Changes to this policy
We may update this privacy policy from time to time. If we make material changes we will announce them on this page and, where appropriate, by email to active customers. Continued use of the site or the service after an update constitutes acceptance of the updated policy.
15. Contact us
- Responsible party: Tapnet Solutions (Pty) Ltd
- Information Officer: Wynand de Beer
- Phone: 079 174 8357
- Email: wynand@tapnet.co.za
- Registered office: 594 Bombani Street, Elarduspark, Pretoria, 0181, South Africa
Other legal documents