NIATECHBack to site
§ Legal

Privacy Policy

How we collect, use and protect your data.

Last updated: September 24, 2026

01

Introduction

KPRM Consulting (Pty) Ltd (“we”, “us”, or “our”) operates the NiaTech platform at https://niatech.kprmmedia.co.za (the “Service”), a workspace for marketing agencies. This Privacy Policy explains what information the Service collects, why, who it is shared with, and the choices you have.

For your account and usage data, KPRM Consulting (Pty) Ltd is the responsible party (data controller). For the client, lead and contact records an agency enters into its own workspace, the agency is the responsible party and we process that data on its behalf and on its instructions. We process personal information in line with the Protection of Personal Information Act, 2013 (POPIA).

02

Information We Collect

Account information: Your name, email address, profile picture and sign-in details, managed by Clerk, our authentication provider. We never see or store your password.

Workspace data: Clients, leads, pipeline tickets, tasks and checklists, campaigns and their roadmaps, email templates, segments and notes that you and your team enter.

Files: Documents, images and videos you upload to the file workspace or attach to posts.

Team messages: Messages, mentions and reactions sent in the team inbox, plus short-lived typing indicators.

Presence: Whether you are online, away or offline, when you were last active, and any status you set yourself, shown to members of your workspace.

Calendar data: Google Calendar events, when you connect your Google account through the Calendar integration.

Connected social accounts: For Facebook Pages, Instagram professional accounts, YouTube channels, TikTok accounts and LinkedIn profiles you connect: the account identifier, name or username, profile picture, an encrypted access token, and the identifiers and performance figures of posts published through the Service.

Connected Google Ads accounts: The Google Ads account IDs your Google login can reach, which account is linked to each client with its name and billing currency, and an encrypted access token. Draft campaigns you build are stored in the Service. Live campaign results are read from Google when you view them and are not stored by us.

Email activity: For each email sent through the Service: recipient, subject, send time and delivery status, and, where tracking applies, when the email was opened and which links were clicked. Unsubscribe and bounce records are kept so the Service does not email those addresses again.

Early access requests: The name, email, company and message you submit through the early access form on our website.

Technical data: IP address, browser type, pages visited and errors encountered, used for security, rate limiting, audit logs and diagnosing problems.

03

How We Use Your Information

To provide, operate, maintain and improve the Service.

To authenticate users and enforce each workspace's access controls.

To send the emails you compose, and to report on their delivery, opens and clicks.

To show and manage Google Calendar events within the Service.

To publish content you create to the social accounts you connect, at the time you choose, and to show how it performed.

To let you link each client to its Google Ads account, show its campaigns and results, and create or change campaigns when a workspace admin asks.

To send you notifications you have asked for, such as @mentions and ticket assignments.

To keep an audit trail of sensitive actions and to detect, prevent and investigate abuse or security incidents.

We do not sell or rent personal information, we do not use it for advertising, and we do not use data from connected accounts to train artificial intelligence models.

04

Service Providers

We share information only with the providers that run parts of the Service, each bound by its own privacy terms and used only for the purpose listed:

ClerkSign-in, user accounts and organisation membership.
ConvexApplication database, including encrypted integration tokens.
Cloudflare R2Storage for uploaded files and media.
ResendEmail delivery, and delivery, bounce and complaint notifications.
VercelHosting, and privacy-friendly page-view analytics that set no cookies.
SentryError monitoring. Session replays mask all text and inputs and block media.
UpstashRate limiting, which processes IP addresses briefly to stop abuse.
KLIPYGIF search in team messages. Receives only the search terms you type.
GoogleCalendar, YouTube and Google Ads integrations, only when you connect them.
Meta PlatformsFacebook and Instagram publishing and insights, only when you connect them.
TikTokTikTok publishing, only when you connect it.
LinkedInLinkedIn publishing, only when you connect it.

Some of these providers store data outside South Africa. Where they do, we rely on their contractual and security commitments to protect it to a standard comparable to POPIA. We may also disclose information where the law requires it.

05

Google User Data

You can connect up to three Google integrations, each with its own permission request. We only request the scopes each feature needs:

Google Calendar: to show the events on your primary calendar in the Service, and to create, update or delete events you manage there.

YouTube: to show which channel is connected, upload videos you publish through the Service, read their view and engagement figures, and delete a video when you delete its post in the Service. We read only videos published through the Service. Use of this integration means you agree to the YouTube Terms of Service.

Google Ads: to list the Google Ads accounts your login can reach; read the name, currency, campaigns and results of the ones you link to your clients; and, only when a workspace admin confirms it, create campaigns, pause, resume or delete them, or change their daily budgets.

We do not access Gmail, Google Drive, Contacts or any other Google service. Google tokens are encrypted at rest, and Google user data is never sold, never used for advertising, never used to train AI models, and never read by people except with your permission, for security reasons, or where the law requires it.

NiaTech's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See also the Google Privacy Policy. You can disconnect any Google integration in the Service, and revoke access at any time from your Google Account permissions page.

06

Social Platform Data

When you connect Facebook, Instagram, TikTok or LinkedIn, we access only the permissions you approve on that platform's own consent screen. We use them to show you the accounts or Pages you manage so you can choose one, to publish content you created to the account you chose, and to read back performance figures for the posts published through the Service.

We read only the posts we published on your behalf. We do not browse or index your wider content, we do not collect your followers or the people who interact with your content, and we do not access accounts you have not connected.

Access tokens are encrypted at rest, scoped to the workspace that connected them, and never sold, shared or used for advertising or profiling. Disconnecting an account in the Service deletes its stored token. You can also revoke access from the platform itself, for example under Business Integrations in your Facebook settings. To ask us to delete data received from Meta, follow Meta's data deletion flow or contact us below.

07

Google Ads Data

The Google Ads integration is covered by the Google User Data section above. In addition: campaign drafts you build are stored in your workspace and visible to its members. Only workspace admins can create, launch, pause, resume, delete or change the budget of a campaign, each change asks for confirmation first, and every change is recorded in the audit log with who made it. Campaigns launched from the Service are created paused, so nothing runs or spends until an admin resumes them. Campaign results are fetched from Google when you view them and are not stored by us. Signing out of Google Ads deletes the stored token; client links and drafts stay until you remove them.

08

Email Tracking and Unsubscribes

Emails sent through the Service may contain a small tracking image and rewritten links, each tied to one recipient's copy of one email. They tell the sender whether the email was opened and which links were clicked. Mail apps that block images, or that load them automatically, can make these figures approximate.

Every email sent to leads includes a personal unsubscribe link. Once someone unsubscribes, bounces or reports an email as spam, their address is suppressed and the Service refuses to email it again from that workspace. Agencies sending through the Service are responsible for having a lawful basis to email their recipients.

09

Data Retention

We keep workspace data for as long as the workspace is active. Integration tokens are deleted when you disconnect the integration. Suppression (unsubscribe and bounce) records are kept for as long as the workspace exists, so the protection they give recipients does not lapse. Audit logs and error reports are kept for a limited period for security. When a workspace is closed, or you ask us to delete your data, we delete it within a reasonable time, except where the law requires us to keep it.

10

Security

Data is encrypted in transit (TLS). Third-party access tokens are additionally encrypted with AES-256-GCM before they are stored. Every workspace is isolated from every other, access within it is controlled by role, and sensitive actions are audit-logged. We review the Service's security regularly. No system is perfectly secure, and if a breach affects your personal information we will notify you and the Information Regulator as POPIA requires.

11

Your Rights

Under POPIA, and depending on where you live, you have the right to:

Ask whether we hold personal information about you, and get a copy of it.

Have inaccurate or incomplete information corrected.

Have your personal information deleted.

Object to, or ask us to restrict, how we process it.

Withdraw consent, for example by disconnecting an integration or unsubscribing.

Lodge a complaint with the Information Regulator of South Africa.

To exercise any of these rights, contact us at sthabiso@kprmconsult.co.za. If your data sits in an agency's workspace, we may refer your request to that agency. You can reach the Information Regulator at inforegulator.org.za.

12

Cookies

The Service uses only the cookies it needs to work: sign-in session cookies set by Clerk, and short-lived cookies that secure the connection flows for third-party accounts. We do not use advertising or cross-site tracking cookies, and our page-view analytics set no cookies.

13

Children

The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect personal information from children.

14

Changes to This Policy

We update this policy when the Service changes how it handles data. The “Last updated” date at the top shows the latest version. For material changes, we will also make reasonable efforts to let workspace admins know in the Service or by email.

15

Contact Us

Questions about this policy or how we handle data? Contact our information officer:

KPRM Consulting (Pty) Ltd · NiaTech

Website: niatech.kprmmedia.co.za

Email: sthabiso@kprmconsult.co.za

© 2026 NiaTech / KPRM Media
Privacy Policy/Terms of Service