§1 — Tuesday, 16:40, a reminder letter
Someone in your accounts department has a stack of overdue statements and a letter to write. The free AI tool writes beautifully, so they paste in the customer's statement — name, account number, amounts owed, the lot — and ask for a firm-but-friendly reminder. It works. The letter is good. Everyone moves on.
No one was careless on purpose. But a customer's personal and financial information just left your business for servers you don't control, in a country you couldn't name, under terms nobody in the building has read. If your customer asked you tomorrow where their information is held, the honest answer would now be: we're not entirely sure.
This is the quietest data problem in South African business right now — not a breach, not a hack, just a thousand helpful pastes a day.
§2 — What POPIA makes of that paste
The Protection of Personal Information Act doesn't mention AI tools, and it doesn't have to. Its rules are about personal information, wherever it goes. In plain terms, three of them matter here:
- You stay responsible. The business that collected the customer's information remains accountable for what happens to it — including what an employee does with it in a free online tool.
- Anyone processing it for you needs a written agreement. When another company handles personal information on your behalf, POPIA expects a proper agreement and proper security around it. A consumer chatbot's terms of service is not that agreement.
- Sending it out of the country has its own rules. Personal information crossing the border is only allowed under specific conditions. A paste into a tool hosted abroad is exactly that — a cross-border transfer nobody assessed.
None of this makes AI illegal to use. It makes unaccounted-for AI use a liability — one that sits with the owner, not with the staff member who was just trying to get the letters out.
§3 — Why "just ban it" fails
The reflex answer is a memo: no AI tools on company data. We've watched how that plays out. The productivity gain is real, so people keep using it — quietly, on personal phones, where the business has even less visibility than before. The memo doesn't remove the risk; it removes your ability to see it.
The other reflex — buying the enterprise version of a cloud AI tool — is better, but it still means your business's information lives in someone else's system, under someone else's retention rules, with your leverage limited to the contract you signed.
§4 — The private alternative
There is a third option: give the business its own AI. A private system your company owns, running on your hardware, that has read what you already have — files, emails, history — and answers in plain English. The personal information in it stays exactly where POPIA expects you to be guarding it: with you.
The difference in one sentence: instead of your data visiting the AI, the AI lives where your data already is.
What that looks like in practice:
- It runs on your infrastructure. We build it, document it, and hand over the keys. We never hold your data.
- Every answer shows where it came from — which file, which email, which record — so you can check it, and show an auditor you can check it.
- Nothing goes out without a person's signature. The system drafts; your people approve. It cannot email a customer on its own.
- Our work is covered by a written agreement. Every engagement that touches personal information runs under a data processing agreement, with data residency documented.
- For premises-only requirements, BlitzBox — an on-premise AI appliance — arrives as its own machine at your office. Its Sovereign option runs the AI models locally too, so nothing leaves the box at all.
§5 — Honest limits
Private does not mean automatically compliant, and anyone who tells you otherwise is selling too hard. You still need the basics POPIA asks of every business: a reason for holding the information you hold, sensible retention, access limited to the people who need it, and someone accountable for all of it.
What a private system changes is that the answers to those questions become knowable. Where is the customer's information? On that machine, in that room. Who can see it? These accounts. When did the AI last touch it? It's on the record. We hold ourselves to the same standard we sell: our founder serves as the deputy information officer of our own operating company, and the compliance discipline we recommend is the one we run.
§6 — Where to start
Not with a policy document. Start by finding out what an AI system that knows your business would actually do for it — twenty minutes of plain questions, free, no data handed over. From there, prove it on one workflow before you spend real money. Costs are public on the pricing page, and the straight answers to the usual questions — including "is our data safe?" — are on the FAQ.
This essay is general information about how we build systems, not legal advice. For advice on your business's POPIA obligations, speak to your attorney or your information officer.