Speak · Ship · Scale
Speak · Ship · Scale
Last updated: 7 September 2026 · Effective: 7 September 2026
Ikigai ADE is the trading name of Mohamed Sidiyot, an individual trading as a sole proprietor in South Africa. Ikigai ADE is not a registered company; there is no separate juristic entity, and Mohamed Sidiyot is personally the contracting party.
Mohamed Sidiyot, a sole proprietor trading as Ikigai ADE is the responsible party (the "controller" under the GDPR) for personal information collected through the Ikigai ADE platform and website.
Information Officer: Mohamed Sidiyot
Email: mohamedsidiyot@gmail.com
Tel: +27 68 695 9713
South Africa
Disclosure on our own compliance status: POPIA section 55 read with Regulation 4 requires an Information Officer to be registered with the Information Regulator. Our registration is not yet complete. We are telling you this rather than implying a compliance status we do not hold. It does not reduce any of your rights below, and it does not affect your right to complain to the Regulator.
We do not currently publish a physical business address. Section 43 of the Electronic Communications and Transactions Act expects an online supplier to do so, and we have not yet met that requirement. Reach us at the email and phone number above.
Account information. Name, email address and authentication data you provide at sign-up. Authentication is handled by Supabase.
Information you volunteer in forms. On our waitlist and contact forms: your name, email, and optionally a phone number, company name and website. Optional fields are labelled optional and you can leave them blank.
Content you put into the product. Prompts, uploaded documents, CRM contacts, brand material and anything else you add to your workspace or your Brain. This is yours. We process it to run the product for you.
Conversation memory. Context from your conversations with S.I.D and the agent team, stored against your account so a conversation can continue where it left off.
Usage data. Pages visited, features used, credits consumed, and which model served a request. We use this to run billing and to see where the product is failing people.
Technical and error data. When a page crashes, your browser sends us the error message, a stack trace, the page you were on, and your IP address is visible to us in that request and in our hosting logs. An IP address is personal information, so we are naming it here rather than hiding it under "technical data". We use it to diagnose faults and to rate-limit abuse.
Payment data. Card details are entered with Paystack and never reach our servers. We receive your name, email, billing country, the last four digits of the card, and whether the payment succeeded.
Third-party contact data you give us. If you upload prospects or contacts into the CRM or outreach tools, you are giving us other people's personal information. You remain the responsible party for that data; we process it on your instruction. You must have a lawful basis for it, and our Terms require you to.
POPIA section 11 and GDPR Article 6 both require a specific ground for every purpose. Ours, purpose by purpose:
| What we do with it | Ground we rely on |
|---|---|
| Create and run your account; deliver the product you subscribed to | Performance of a contract with you |
| Take payment, issue invoices, calculate credits and outcome share | Performance of a contract; compliance with tax law |
| Send transactional email (receipts, password resets, service notices) | Performance of a contract |
| Diagnose crashes, keep logs, rate-limit abuse, investigate security incidents | Legitimate interest in a working and secure service |
| Keep records for tax and accounting | Legal obligation (Tax Administration Act) |
| Waitlist and marketing email you asked for | Your consent, withdrawable at any time |
| Cold outreach to business prospects (email, SMS, voice, Telegram) | Legitimate interest, subject to POPIA s.69 and your right to object at first contact |
| Improve the product using aggregated, de-identified usage patterns | Legitimate interest; the data is no longer personal information |
Where we rely on consent, you can withdraw it at any time and we stop. Where we rely on legitimate interest, you can object and we will either stop or explain why our interest overrides your objection. Withdrawing consent does not undo processing that was lawful before you withdrew it.
We do not sell your personal information, and we do not use it to build advertising profiles. We may create and share aggregated, de-identified statistics that cannot reasonably be traced back to you or any individual. That is not personal information under POPIA or the GDPR. We do not try to re-identify it and we require anyone who receives it not to either.
The product works by sending your prompt and the context it needs to a large language model. That means the content you submit leaves our infrastructure and is processed by the AI provider serving that model. Which providers, and in which countries, is set out in sections 6 and 7.
Do not paste anything into the product that you are not willing to have processed by a third-party AI provider outside South Africa. If that is a problem for your data, use Bring Your Own Key, or ask us to route around a specific provider under section 9.
Some features score or rank people automatically: lead scoring, ICP fit, churn risk and similar. POPIA section 71 and GDPR Article 22 restrict decisions made purely by automated means that have a legal or similarly significant effect on someone.
POPIA section 21 and GDPR Article 28 require us to name our operators (sub-processors). The full, dated and authoritative list lives on the Sub-processors page, which we update before a change takes effect. Summarised:
| Category | Who | What they process |
|---|---|---|
| Hosting and network | Vercel, Cloudflare | Request metadata, IP addresses, logs |
| Database, auth, storage | Supabase | Account, workspace content, CRM, billing records |
| Payments | Paystack | Name, email, billing address, tokenised card |
| AI model providers | Anthropic, OpenAI, Google, Groq, NVIDIA, xAI, Moonshot AI, DeepSeek, Zhipu AI, Alibaba | Your in-flight prompt and its context |
| Resend | Recipient address and message body | |
| SMS and voice | Twilio | Phone numbers, message bodies, call audio |
| Text to speech | ElevenLabs | The text to be spoken |
| Messaging | Telegram | Chat identifiers and message content, if you connect it |
| Lead capture | Google (Apps Script and Sheets) | Waitlist and contact submissions: name, email, phone, country, company, website |
| Logging and uptime | Better Stack | Request metadata, stack traces |
| Source control | GitHub | Code only, no customer data |
We require every one of them to process data only on our instructions, to keep it secure, and to be bound by a data-processing agreement. We will tell active customers at least 30 days before adding a new sub-processor.
Your personal information leaves South Africa. It has to, because the infrastructure and the AI models we use are hosted abroad. POPIA section 72 and Chapter V of the GDPR both require us to say so and to name the basis for it, so here it is plainly.
| Destination | Why it goes there | Safeguard |
|---|---|---|
| United States | Hosting, database, most AI model providers, email, SMS, logging | Contractual terms in each provider DPA imposing protection comparable to POPIA (s.72(1)(a)); GDPR Standard Contractual Clauses |
| European Union | CDN edge, logging (Germany), some Google regions | Adequate protection under POPIA s.72; within the EEA for GDPR |
| Nigeria and South Africa | Payment processing (Paystack) | Provider DPA; Nigeria has the NDPA 2023 |
| Singapore | Alibaba DashScope, only if you select Qwen with your own key | Provider DPA; PDPA applies locally |
| China | Moonshot AI (Kimi), DeepSeek and Zhipu AI (GLM) when those models are selected | Provider terms only. See the warning below. |
| Global CDN edge | Static assets and routing | Request metadata only, no workspace content |
Please read this if you are in the EU or the UK. Three of the model providers we can route to are based in China. There is no adequacy decision for China under the GDPR, and we cannot honestly claim that contractual clauses alone give you protection equivalent to EU law there. If you are subject to the GDPR, or your data is sensitive, either avoid selecting those models, or tell us to exclude them from your account under section 9 and we will. GLM and Qwen have no managed lane at all: they only run on your own key.
| Data | How long we keep it |
|---|---|
| Account and profile | While your account is active, then deleted within 30 days of account deletion |
| Workspace content, Brain, CRM | While your account is active; deleted with the account |
| Conversation memory | While your account is active, or until you clear it |
| Prompt content held by AI providers | Per provider, typically up to 30 days for abuse review, then deleted |
| Billing and tax records | 5 years after the tax year, as the Tax Administration Act requires. We cannot delete these on request. |
| Error logs and security logs | 90 days |
| Waitlist entries | Until you ask us to remove you, or 24 months of no contact |
| Aggregated, de-identified analytics | Indefinitely. It is no longer personal information. |
Whatever your jurisdiction, you can ask us to:
Email mohamedsidiyot@gmail.com. We respond within 30 days. We may ask you to confirm your identity first, because handing your data to someone impersonating you would be worse than a slow reply. Asking costs nothing.
No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal information, POPIA section 22 requires us to notify you and the Information Regulator as soon as reasonably possible; under the GDPR we will notify the relevant authority within 72 hours. Report a suspected vulnerability to mohamedsidiyot@gmail.com.
Ikigai ADE is a business product and is not directed at children. You must be 18 or older to hold an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, email mohamedsidiyot@gmail.com and we will delete it.
We may update this policy. If a change is material, we will email registered users at least 14 days before it takes effect, and we will change the "last updated" date above. We will not apply a materially worse policy to data we already hold without telling you first.
Please raise it with us first at mohamedsidiyot@gmail.com. You do not have to, and you are entitled to go straight to a regulator.
South Africa. Information Regulator (South Africa): inforegulator.org.za
Email: POPIAComplaints@inforegulator.org.za
EU and UK. You may complain to your national data protection authority, or to the Information Commissioner's Office in the UK.