Last updated: 17 July 2026
Effective date: 17 July 2026
Replaces: the version dated 11 January 2022
This policy explains what personal information Yazi collects, why we collect it, who we share it with, how long we keep it, and what rights you have. It covers our website, our platform, and the surveys and interviews we run on behalf of our clients.
Yazi Research (Pty) Ltd ("Yazi", "we", "us") is a company registered in South Africa, registration number 2020/635132/07. We operate a WhatsApp-native market research platform at askyazi.com and app.askyazi.com (together, the "Service").
We comply with the Protection of Personal Information Act 4 of 2013 ("POPIA") in South Africa, and with the UK GDPR and EU GDPR where those apply to our processing.
| Privacy contact (all enquiries and requests) | accounts+privacy@askyazi.com |
|---|---|
| Information Officer (POPIA s.55) | Timothy Treagus, Chief Executive Officer. Registered with the Information Regulator of South Africa on 28 May 2026, registration number 2026-021094. |
| Privacy & Compliance Lead (day-to-day) | Mzwandile Sotsaka, Chief Technology Officer. |
Please use the email address above rather than any other channel, so that requests are logged and either answered by us or routed promptly to the organisation responsible for them (see section 3).
Personal information (or personal data) means information relating to an identifiable, living, natural person and, under POPIA, also to an identifiable, existing juristic person such as a company.
Special personal information (or special category data) means the categories listed in POPIA s.26 and Article 9 of the GDPR: health, genetic and biometric data, race or ethnic origin, religious or philosophical beliefs, trade union membership, political persuasion, and sex life or sexual orientation. Information about criminal behaviour is treated as special personal information under POPIA s.26(b) and is governed separately by GDPR Article 10.
Responsible Party (POPIA) and Controller (GDPR) mean the party that decides why and how personal information is processed.
Operator (POPIA) and Processor (GDPR) mean a party that processes personal information on behalf of, and on the instructions of, a Responsible Party or Controller.
Data subject means the person the information is about. Respondent or participant means a person taking part in a survey, interview or diary study run through the Service.
This is the most important thing to understand about how Yazi handles personal information, because it determines who you should contact about your data.
Yazi is the Responsible Party / Controller for:
Yazi is the Operator / Processor for:
In that second case our client is the Responsible Party / Controller. They decide what the study asks, who it recruits, what the lawful basis is, and how long the data is kept. We process it only on their documented instructions, under a Data Processing Agreement.
If you took part in a research study and want your data accessed, corrected or deleted, email us at accounts+privacy@askyazi.com. Because we act on the client's instructions, we cannot decide the outcome ourselves. We will route your request to the organisation that commissioned the study, confirm to you that we have done so, and give them the assistance they need to answer you within their deadline. You can also go to that organisation directly. Stopping further messages to you is the one thing we can and will do immediately (see section 8).
Where we got your contact details. We do not usually collect them from you directly. In most studies we receive them from the organisation running the study, from its own customer or member records. In others we receive them from a research panel provider you have registered with, such as PureSpectrum or Prolific. The invitation you receive will tell you which organisation is running the study.
What a specific study collects is set by the client running it and is described in the consent notice you receive before it begins. You are not required to answer any question, and you can stop at any time.
Providing personal information to Yazi is voluntary, but some of it is necessary for us to do anything useful. If you do not give us the information marked as required on an account or enquiry form, we cannot create your account or respond to you. If you decline to answer screening questions in a study, you may not qualify to take part, and may not receive an incentive that depends on completing it. No law requires you to give us your personal information.
Where Yazi is the Responsible Party / Controller, we rely on the following:
| What we do | Lawful basis |
|---|---|
| Respond to enquiries, demo requests and support questions | Legitimate interest in running our business, and steps taken at your request before entering a contract |
| Provide, maintain and secure the platform for account holders | Performance of our contract with the client |
| Billing, invoicing and debt recovery | Contract, and legal obligation under tax law |
| Product analytics to understand how the platform is used and improve it | Legitimate interest, and consent where cookies or similar technologies are used |
| Electronic direct marketing | Consent under POPIA s.69 and the GDPR. Where you are an existing customer and we are marketing similar services, we rely on the limited existing-customer exception, and every message carries an opt-out |
| Website analytics and advertising cookies | Consent, collected through our cookie banner |
| Detect and prevent fraud, abuse and security incidents | Legitimate interest, and legal obligation |
| Comply with law, respond to lawful requests, and establish or defend legal claims | Legal obligation, and legitimate interest |
Where Yazi is the Operator / Processor, the lawful basis for processing research participant data is determined and documented by our client, not by us. For most studies this is the participant's consent, captured before the study begins.
You can withdraw consent at any time. Withdrawing consent does not affect processing that already happened lawfully before you withdrew it.
Some studies run by our clients ask about topics that fall within the special categories described in section 2, for example health, financial hardship, political opinion or ethnicity.
When Yazi processes special personal information on behalf of a client, it does so only where the client has confirmed to us that either the participant's explicit consent has been captured under POPIA s.27(1)(a) or GDPR Article 9(2)(a), or another lawful ground under POPIA s.27 or Article 9(2) applies and has been documented.
Our pre-project intake requires the client to confirm the lawful basis for any special personal information a study will collect, and to provide or approve the participant-facing consent notice. Where a study processes special personal information at a scale likely to result in a high risk to participants, we require the client to have completed a Data Protection Impact Assessment under GDPR Article 35, or a personal information impact assessment under Regulation 4(1)(b) of the POPIA Regulations, and shared it with us before the study launches.
Where special personal information or children's information is to be transferred to a recipient in a country that does not provide comparable protection, POPIA s.57 may require the responsible party to obtain prior authorisation from the Information Regulator. Our intake process checks for this, and we will not launch a study that needs it until the client confirms authorisation is in place.
Yazi uses AI models as part of the Service. This section explains where, and what the limits are.
Where AI is used:
The limits we apply:
Our current AI sub-processors are listed at askyazi.com/sub-processors.
Yazi delivers most studies over the WhatsApp Business Platform, operated by Meta and WhatsApp group companies in Ireland and the United States. Where a client configures it, we also use Telegram.
This means that when you take part in a study over WhatsApp, Meta processes your phone number and message metadata in order to deliver the messages, and Meta's own privacy terms apply to that layer. Message content sent through the WhatsApp Business Platform is delivered to Yazi's platform, where it is stored and processed as described in this policy. Messages to a business on the WhatsApp Business Platform are not protected in the same way as personal WhatsApp chats, because the business receiving them needs to be able to read them.
You can opt out of a study at any time by replying STOP, or by using the opt-out instruction given in the study invitation. Opting out stops further messages immediately. It also deletes your responses where the client's instructions and applicable law permit, and where they do not, we will tell you who to ask.
We use cookies and similar technologies such as tags, pixels and local storage on askyazi.com and app.askyazi.com.
| Type | What it does | Examples | Basis |
|---|---|---|---|
| Strictly necessary | Keeps you signed in, maintains session state, records your cookie choices, protects against abuse | CookieScript, Webflow, AWS Cognito | Necessary for the service, no consent required |
| Preference | Remembers settings and choices | Webflow | Consent |
| Analytics | Tells us how the site and platform are used so we can improve them | Google Tag Manager, PostHog, RankAI | Consent |
| Advertising and conversion measurement | Measures the performance of our advertising and lets us reach relevant audiences | Google Ads, Meta Pixel | Consent |
We use a cookie consent tool on our sites. You can accept, reject or change your choices at any time through the cookie settings link in the banner, or by clearing cookies in your browser. Rejecting non-essential cookies does not affect your ability to use the site. The banner lists the specific cookies in use and their durations, which change more often than this policy does.
Do Not Track and Global Privacy Control. There is no common industry standard for legacy browser Do Not Track signals and Yazi does not respond to them. We do treat the Global Privacy Control signal as a valid request to opt out of the sale or sharing of personal information where California law gives you that right. For everyone else, the cookie banner and your browser's cookie controls are the mechanisms that take effect.
We do not sell your personal information for money. Our use of advertising and analytics cookies may amount to a "sale" or "share" as those terms are defined under California law. Section 14.3 explains how to opt out.
Sub-processors. We use third-party providers to deliver the Service, including cloud hosting, messaging, AI, analytics, panel recruitment and incentive payouts. The full current list, with the role each one plays and the country it processes in, is maintained at askyazi.com/sub-processors. We update that page whenever a sub-processor is added or removed, and we notify client controllers in advance of changes affecting their data. We require a written data processing agreement with every sub-processor that processes personal information on our behalf, restricting them to using it only to provide services to us, and we maintain a register of that agreement status which we review at least annually.
Our clients. Where Yazi is the Operator / Processor, research responses are provided to the client that commissioned the study, in line with what the participant was told at the point of consent.
Advisers. Our auditors, lawyers, accountants and insurers, under confidentiality obligations.
Law and safety. We may disclose personal information where we are required to by law, court order or a valid request from a public authority, or where we reasonably believe disclosure is necessary to investigate suspected illegal activity, prevent harm, or establish, exercise or defend legal claims.
Corporate transactions. If Yazi is involved in a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction. We will notify affected clients and give them the rights set out in their agreements.
Yazi is a South African company serving clients in the United Kingdom, Europe, Africa and elsewhere, so personal information may be processed outside the country where it was collected. Being specific about this matters more than sounding reassuring, so here is the actual picture.
Where personal information leaves the UK or EEA, we rely on one of the following, depending on the recipient: an adequacy decision (including the EU-U.S. Data Privacy Framework and its UK Extension, on which the WhatsApp transfer relies), the UK ICO International Data Transfer Agreement, or EU Standard Contractual Clauses, in each case together with supplementary technical and organisational measures. We maintain a transfer impact assessment for each sub-processor that processes personal information outside the UK or EEA. You can request a copy of the safeguards that apply to a transfer affecting you by emailing accounts+privacy@askyazi.com.
For transfers out of South Africa, we rely on POPIA s.72, which requires the recipient to be subject to a law, binding corporate rules or binding agreement that effectively upholds principles for reasonable processing substantially similar to POPIA's conditions for lawful processing, including provisions substantially similar to s.72 governing onward transfers, or on one of the other grounds in s.72 such as your consent or necessity for a contract.
Research participant data. Retention is set by the client that commissioned the study, in its Data Processing Agreement or Statement of Work. Where a client has not specified a period, we apply a default of 24 months from the close of the project, after which the data is securely deleted. Where the client's agreement permits it, we may keep anonymised or aggregated data for longer to support benchmarking. Anonymised data is data from which individuals can no longer be identified, and it is no longer personal information.
Data we hold as Responsible Party / Controller:
| Category | Retention |
|---|---|
| Website cookies and analytics | Up to 13 months |
| Enquiry and demo request records | 24 months from last contact, unless a contract follows |
| Marketing contact data | Until consent is withdrawn, or 36 months of inactivity, whichever comes first |
| Client account records | Duration of the contract, plus 7 years |
| Billing and invoice records | 7 years from issue, as required by tax law |
| Application access logs | 2 years |
| Security audit trails | 5 years |
| Error and diagnostic logs | 90 days |
| System backups | 30-day rolling cycle |
| Incident and breach records | 6 years from close of the incident |
| Employee records | Duration of employment, plus 6 years |
Deletion is a soft delete followed by permanent deletion after a 30 day grace period, with backups purged on the rolling backup cycle. Where a regulator, court order or pending legal claim requires longer retention, that overrides these periods until the matter is resolved.
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, least-privilege and need-to-know access controls, multi-factor authentication on every system that supports it, network segmentation, logging and monitoring, changes to production made through reviewed code changes wherever practicable, and annual access reviews.
We maintain documented policies covering information security, incident response, breach response, backup and disaster recovery, and business continuity. These are available to clients and prospective clients on request, usually under a non-disclosure agreement.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. What we can commit to is doing this properly and telling you quickly when something goes wrong.
Depending on where you are and which law applies, you have some or all of the following rights.
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, you may ask us to tell you what personal information we have collected about you and the categories of sources, purposes and recipients; to correct inaccurate personal information; to delete personal information we hold about you; to limit the use and disclosure of sensitive personal information; and to opt out of the sale or sharing of personal information. You may use an authorised agent to make a request on your behalf, and we may ask that agent for proof of your authorisation.
In the last 12 months we have collected the categories of personal information described in section 4, from the sources described in sections 4.1 to 4.3, for the purposes in section 5, and disclosed them to the categories of recipient in section 10.
We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. Our use of advertising and analytics cookies on askyazi.com may constitute a "sale" or "share" for cross-context behavioural advertising under California law. To opt out, reject advertising cookies in our cookie banner, send a Global Privacy Control signal from your browser, or email accounts+privacy@askyazi.com. We do not use or disclose sensitive personal information for purposes that require an option to limit it.
We will not discriminate against you for exercising any of these rights.
Email accounts+privacy@askyazi.com. Tell us what you want and, if you can, which study or account it relates to. We may need to verify your identity before we act, and we will only ask for what is necessary to do that. Under POPIA you may also use the prescribed forms (Form 2 for access, Form 3 for correction or deletion, Form 1 for an objection), addressed to the Information Officer, and our PAIA manual sets out the full procedure. We will not turn away a request just because it did not arrive on a form.
| Under | We respond within |
|---|---|
| UK GDPR / EU GDPR | One month, extendable by up to two further months for complex or numerous requests. We will tell you within the first month if we need the extension and why |
| POPIA / PAIA | 30 days, extendable by a further 30 days where the law permits |
| CCPA / CPRA | 45 days, extendable by a further 45 days, with notice to you |
We do not currently charge for a reasonable request, although POPIA and PAIA permit a prescribed fee for access to records. If a fee would ever apply we will tell you before doing the work.
If you took part in a research study, remember that our client is the Controller. Section 3 explains what happens to your request.
Yazi's website and platform accounts are intended for business users and are not directed at children.
Research participation. Under POPIA s.34, processing the personal information of a child (anyone under 18 in South Africa) is prohibited unless one of the grounds in s.35 applies, the most common being the consent of a parent, guardian or other competent person. Yazi does not knowingly allow anyone under 18 to take part in a study unless the client running it has obtained that consent, and any consent required by local law in the participant's country, and confirmed this to us in writing before the study begins. Studies involving under-18s require the prior written approval of Yazi's Chief Executive Officer and additional safeguards documented in the project plan.
In the United Kingdom and European Union, where a study relies on the participant's own consent for an online service, the minimum age is 13 in the UK and between 13 and 16 depending on the member state, under GDPR Article 8. Where a study is run in those jurisdictions we apply the higher of the local requirement and the client's own policy.
If you believe a child has provided personal information to us without the necessary consent, contact accounts+privacy@askyazi.com. We will investigate, tell the client running the study, and have it deleted.
Our site and our messages may contain links to sites we do not operate. We are not responsible for the content or privacy practices of those sites, and we encourage you to read their privacy policies before providing them with information.
We review this policy at least annually and update it when our processing changes. When we make a material change we will update the effective date at the top of this page and, where the change significantly affects you, notify account holders by email or by a prominent notice on the Service before it takes effect.
Contact Yazi first. Email accounts+privacy@askyazi.com, or use the contact form at askyazi.com. We would rather hear about a problem and fix it.
If you are not satisfied with our response, you can complain to a supervisory authority.
| South Africa | Information Regulator (South Africa). POPIA complaints are lodged through the Regulator's eServices Portal at inforegulator.org.za. General enquiries: enquiries@inforegulator.org.za. Toll free: 0800 017 160. |
|---|---|
| United Kingdom | Information Commissioner's Office, ico.org.uk. Helpline: 0303 123 1113. |
| European Union | The data protection supervisory authority in your country of residence, place of work, or where the issue occurred. A list is published by the European Data Protection Board at edpb.europa.eu. |