New Report on SA Gambling Impact
Check It Out

Privacy Policy

Last updated: 17 July 2026
Effective date: 17 July 2026
Replaces: the version dated 11 January 2022

This policy explains what personal information Yazi collects, why we collect it, who we share it with, how long we keep it, and what rights you have. It covers our website, our platform, and the surveys and interviews we run on behalf of our clients.

1. Who we are

Yazi Research (Pty) Ltd ("Yazi", "we", "us") is a company registered in South Africa, registration number 2020/635132/07. We operate a WhatsApp-native market research platform at askyazi.com and app.askyazi.com (together, the "Service").

We comply with the Protection of Personal Information Act 4 of 2013 ("POPIA") in South Africa, and with the UK GDPR and EU GDPR where those apply to our processing.

How to reach us about privacy

Privacy contact (all enquiries and requests)accounts+privacy@askyazi.com
Information Officer (POPIA s.55)Timothy Treagus, Chief Executive Officer. Registered with the Information Regulator of South Africa on 28 May 2026, registration number 2026-021094.
Privacy & Compliance Lead (day-to-day)Mzwandile Sotsaka, Chief Technology Officer.

Please use the email address above rather than any other channel, so that requests are logged and either answered by us or routed promptly to the organisation responsible for them (see section 3).

2. Definitions

Personal information (or personal data) means information relating to an identifiable, living, natural person and, under POPIA, also to an identifiable, existing juristic person such as a company.

Special personal information (or special category data) means the categories listed in POPIA s.26 and Article 9 of the GDPR: health, genetic and biometric data, race or ethnic origin, religious or philosophical beliefs, trade union membership, political persuasion, and sex life or sexual orientation. Information about criminal behaviour is treated as special personal information under POPIA s.26(b) and is governed separately by GDPR Article 10.

Responsible Party (POPIA) and Controller (GDPR) mean the party that decides why and how personal information is processed.

Operator (POPIA) and Processor (GDPR) mean a party that processes personal information on behalf of, and on the instructions of, a Responsible Party or Controller.

Data subject means the person the information is about. Respondent or participant means a person taking part in a survey, interview or diary study run through the Service.

3. Our role depends on whose data it is

This is the most important thing to understand about how Yazi handles personal information, because it determines who you should contact about your data.

Yazi is the Responsible Party / Controller for:

  • Website visitor data: cookies, analytics and contact or demo request forms submitted on askyazi.com.
  • Client account data: the names, work email addresses and account details of people at the businesses that use our platform.
  • Our own employee, contractor and supplier records.

Yazi is the Operator / Processor for:

  • All survey, interview and diary study data collected from research participants through the Service.

In that second case our client is the Responsible Party / Controller. They decide what the study asks, who it recruits, what the lawful basis is, and how long the data is kept. We process it only on their documented instructions, under a Data Processing Agreement.

If you took part in a research study and want your data accessed, corrected or deleted, email us at accounts+privacy@askyazi.com. Because we act on the client's instructions, we cannot decide the outcome ourselves. We will route your request to the organisation that commissioned the study, confirm to you that we have done so, and give them the assistance they need to answer you within their deadline. You can also go to that organisation directly. Stopping further messages to you is the one thing we can and will do immediately (see section 8).

4. What we collect

4.1 If you visit our website

  • Information you give us in a form: name, work email address, company name, phone number if you choose to provide it, and anything you write in a message field.
  • Information collected automatically: IP address, browser type and version, device type, operating system, pages visited, time and date of visit, time spent on pages, referring URL, and similar diagnostic data.
  • Cookie and tag data, as described in section 9.

4.2 If you have a Yazi account

  • Account details: name, work email address, company, role, and authentication data. If you sign in with Google or Microsoft, we receive your name and email address from that provider.
  • Usage data from the platform: features used, surveys created, login times, and error and diagnostic logs.
  • Billing and contract records.

4.3 If you take part in a research study

  • Contact identifiers: WhatsApp or mobile number, and in some studies a name or email address.
  • Your responses: text answers, and any voice notes, photographs, videos or screenshots you choose to send.
  • Screening and demographic information the study asks for, which may include age, gender, location, income band, or product and service use.
  • Technical identifiers such as a WhatsApp contact ID or booking reference.
  • Approximate or precise location, but only where the study asks for it and you provide it.

Where we got your contact details. We do not usually collect them from you directly. In most studies we receive them from the organisation running the study, from its own customer or member records. In others we receive them from a research panel provider you have registered with, such as PureSpectrum or Prolific. The invitation you receive will tell you which organisation is running the study.

What a specific study collects is set by the client running it and is described in the consent notice you receive before it begins. You are not required to answer any question, and you can stop at any time.

4.4 Whether you have to provide information

Providing personal information to Yazi is voluntary, but some of it is necessary for us to do anything useful. If you do not give us the information marked as required on an account or enquiry form, we cannot create your account or respond to you. If you decline to answer screening questions in a study, you may not qualify to take part, and may not receive an incentive that depends on completing it. No law requires you to give us your personal information.

5. Why we use it, and our lawful basis

Where Yazi is the Responsible Party / Controller, we rely on the following:

What we doLawful basis
Respond to enquiries, demo requests and support questionsLegitimate interest in running our business, and steps taken at your request before entering a contract
Provide, maintain and secure the platform for account holdersPerformance of our contract with the client
Billing, invoicing and debt recoveryContract, and legal obligation under tax law
Product analytics to understand how the platform is used and improve itLegitimate interest, and consent where cookies or similar technologies are used
Electronic direct marketingConsent under POPIA s.69 and the GDPR. Where you are an existing customer and we are marketing similar services, we rely on the limited existing-customer exception, and every message carries an opt-out
Website analytics and advertising cookiesConsent, collected through our cookie banner
Detect and prevent fraud, abuse and security incidentsLegitimate interest, and legal obligation
Comply with law, respond to lawful requests, and establish or defend legal claimsLegal obligation, and legitimate interest

Where Yazi is the Operator / Processor, the lawful basis for processing research participant data is determined and documented by our client, not by us. For most studies this is the participant's consent, captured before the study begins.

You can withdraw consent at any time. Withdrawing consent does not affect processing that already happened lawfully before you withdrew it.

6. Special personal information

Some studies run by our clients ask about topics that fall within the special categories described in section 2, for example health, financial hardship, political opinion or ethnicity.

When Yazi processes special personal information on behalf of a client, it does so only where the client has confirmed to us that either the participant's explicit consent has been captured under POPIA s.27(1)(a) or GDPR Article 9(2)(a), or another lawful ground under POPIA s.27 or Article 9(2) applies and has been documented.

Our pre-project intake requires the client to confirm the lawful basis for any special personal information a study will collect, and to provide or approve the participant-facing consent notice. Where a study processes special personal information at a scale likely to result in a high risk to participants, we require the client to have completed a Data Protection Impact Assessment under GDPR Article 35, or a personal information impact assessment under Regulation 4(1)(b) of the POPIA Regulations, and shared it with us before the study launches.

Where special personal information or children's information is to be transferred to a recipient in a country that does not provide comparable protection, POPIA s.57 may require the responsible party to obtain prior authorisation from the Information Regulator. Our intake process checks for this, and we will not launch a study that needs it until the client confirms authorisation is in place.

7. Artificial intelligence

Yazi uses AI models as part of the Service. This section explains where, and what the limits are.

Where AI is used:

  • Helping clients draft and refine survey and interview questions.
  • Generating and adapting the messages sent to participants during a study, including follow-up probes in AI-moderated interviews.
  • Assisting with coding, categorising and summarising open-ended responses.

The limits we apply:

  • AI processing for the research platform runs on infrastructure located in the United Kingdom and the European Union.
  • Our AI sub-processors are contractually prohibited from using client or participant data to train their foundation models, and we do not submit data for that purpose.
  • You are always told when you are speaking with an AI interviewer rather than a person. This is both our policy and, for participants in the European Union, a requirement of Article 50 of the EU AI Act.
  • AI is not used to make automated decisions that produce legal effects. Automated screening against criteria set by the client may determine whether you qualify for a study and therefore whether you receive an incentive. If an automated screening outcome affects you and you want a person to look at it, email accounts+privacy@askyazi.com and we will arrange human review with the client running the study.

Our current AI sub-processors are listed at askyazi.com/sub-processors.

8. Messaging channels

Yazi delivers most studies over the WhatsApp Business Platform, operated by Meta and WhatsApp group companies in Ireland and the United States. Where a client configures it, we also use Telegram.

This means that when you take part in a study over WhatsApp, Meta processes your phone number and message metadata in order to deliver the messages, and Meta's own privacy terms apply to that layer. Message content sent through the WhatsApp Business Platform is delivered to Yazi's platform, where it is stored and processed as described in this policy. Messages to a business on the WhatsApp Business Platform are not protected in the same way as personal WhatsApp chats, because the business receiving them needs to be able to read them.

You can opt out of a study at any time by replying STOP, or by using the opt-out instruction given in the study invitation. Opting out stops further messages immediately. It also deletes your responses where the client's instructions and applicable law permit, and where they do not, we will tell you who to ask.

9. Cookies and similar technologies

We use cookies and similar technologies such as tags, pixels and local storage on askyazi.com and app.askyazi.com.

TypeWhat it doesExamplesBasis
Strictly necessaryKeeps you signed in, maintains session state, records your cookie choices, protects against abuseCookieScript, Webflow, AWS CognitoNecessary for the service, no consent required
PreferenceRemembers settings and choicesWebflowConsent
AnalyticsTells us how the site and platform are used so we can improve themGoogle Tag Manager, PostHog, RankAIConsent
Advertising and conversion measurementMeasures the performance of our advertising and lets us reach relevant audiencesGoogle Ads, Meta PixelConsent

We use a cookie consent tool on our sites. You can accept, reject or change your choices at any time through the cookie settings link in the banner, or by clearing cookies in your browser. Rejecting non-essential cookies does not affect your ability to use the site. The banner lists the specific cookies in use and their durations, which change more often than this policy does.

Do Not Track and Global Privacy Control. There is no common industry standard for legacy browser Do Not Track signals and Yazi does not respond to them. We do treat the Global Privacy Control signal as a valid request to opt out of the sale or sharing of personal information where California law gives you that right. For everyone else, the cookie banner and your browser's cookie controls are the mechanisms that take effect.

10. Who we share information with

We do not sell your personal information for money. Our use of advertising and analytics cookies may amount to a "sale" or "share" as those terms are defined under California law. Section 14.3 explains how to opt out.

Sub-processors. We use third-party providers to deliver the Service, including cloud hosting, messaging, AI, analytics, panel recruitment and incentive payouts. The full current list, with the role each one plays and the country it processes in, is maintained at askyazi.com/sub-processors. We update that page whenever a sub-processor is added or removed, and we notify client controllers in advance of changes affecting their data. We require a written data processing agreement with every sub-processor that processes personal information on our behalf, restricting them to using it only to provide services to us, and we maintain a register of that agreement status which we review at least annually.

Our clients. Where Yazi is the Operator / Processor, research responses are provided to the client that commissioned the study, in line with what the participant was told at the point of consent.

Advisers. Our auditors, lawyers, accountants and insurers, under confidentiality obligations.

Law and safety. We may disclose personal information where we are required to by law, court order or a valid request from a public authority, or where we reasonably believe disclosure is necessary to investigate suspected illegal activity, prevent harm, or establish, exercise or defend legal claims.

Corporate transactions. If Yazi is involved in a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction. We will notify affected clients and give them the rights set out in their agreements.

11. International transfers

Yazi is a South African company serving clients in the United Kingdom, Europe, Africa and elsewhere, so personal information may be processed outside the country where it was collected. Being specific about this matters more than sounding reassuring, so here is the actual picture.

  • Primary hosting is Amazon Web Services in the United Kingdom (London, eu-west-2), with capacity in Ireland (EEA).
  • Some data collected in South Africa is processed in the AWS Cape Town region (af-south-1).
  • Data residency can be pinned to UK and EU regions only for clients that require it, excluding the Cape Town region. Where we have agreed this, it is recorded in that client's agreement.
  • The WhatsApp Business Platform involves Meta and WhatsApp group companies in Ireland and the United States.
  • A number of supporting services process data in the United States: Google and Microsoft sign-in federation, Google Maps, Google Fonts, Google Tag Manager, Google Ads, the Meta advertising pixel, and, where a client uses them, the PureSpectrum panel and Tremendous incentive payouts.
  • Yazi personnel in South Africa access the platform to operate and support it, under access controls and confidentiality obligations.

Where personal information leaves the UK or EEA, we rely on one of the following, depending on the recipient: an adequacy decision (including the EU-U.S. Data Privacy Framework and its UK Extension, on which the WhatsApp transfer relies), the UK ICO International Data Transfer Agreement, or EU Standard Contractual Clauses, in each case together with supplementary technical and organisational measures. We maintain a transfer impact assessment for each sub-processor that processes personal information outside the UK or EEA. You can request a copy of the safeguards that apply to a transfer affecting you by emailing accounts+privacy@askyazi.com.

For transfers out of South Africa, we rely on POPIA s.72, which requires the recipient to be subject to a law, binding corporate rules or binding agreement that effectively upholds principles for reasonable processing substantially similar to POPIA's conditions for lawful processing, including provisions substantially similar to s.72 governing onward transfers, or on one of the other grounds in s.72 such as your consent or necessity for a contract.

12. How long we keep it

Research participant data. Retention is set by the client that commissioned the study, in its Data Processing Agreement or Statement of Work. Where a client has not specified a period, we apply a default of 24 months from the close of the project, after which the data is securely deleted. Where the client's agreement permits it, we may keep anonymised or aggregated data for longer to support benchmarking. Anonymised data is data from which individuals can no longer be identified, and it is no longer personal information.

Data we hold as Responsible Party / Controller:

CategoryRetention
Website cookies and analyticsUp to 13 months
Enquiry and demo request records24 months from last contact, unless a contract follows
Marketing contact dataUntil consent is withdrawn, or 36 months of inactivity, whichever comes first
Client account recordsDuration of the contract, plus 7 years
Billing and invoice records7 years from issue, as required by tax law
Application access logs2 years
Security audit trails5 years
Error and diagnostic logs90 days
System backups30-day rolling cycle
Incident and breach records6 years from close of the incident
Employee recordsDuration of employment, plus 6 years

Deletion is a soft delete followed by permanent deletion after a 30 day grace period, with backups purged on the rolling backup cycle. Where a regulator, court order or pending legal claim requires longer retention, that overrides these periods until the matter is resolved.

13. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, least-privilege and need-to-know access controls, multi-factor authentication on every system that supports it, network segmentation, logging and monitoring, changes to production made through reviewed code changes wherever practicable, and annual access reviews.

We maintain documented policies covering information security, incident response, breach response, backup and disaster recovery, and business continuity. These are available to clients and prospective clients on request, usually under a non-disclosure agreement.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. What we can commit to is doing this properly and telling you quickly when something goes wrong.

Breach notification

  • Where Yazi is the Operator / Processor, we notify the client controller of a confirmed personal information breach within 24 hours, with follow-up updates as the facts develop.
  • Where Yazi is the Responsible Party / Controller and there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we notify the Information Regulator and the affected data subjects as soon as reasonably possible after becoming aware, as POPIA s.22 requires. Notification to data subjects may only be delayed where a public body determines that notice would impede a criminal investigation.
  • Under the GDPR we notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Where a breach is likely to result in a high risk to you, we will tell you without undue delay as well.

14. Your rights

Depending on where you are and which law applies, you have some or all of the following rights.

14.1 Under POPIA (South Africa)

  • To be notified that your personal information is being collected, and if it has been accessed by an unauthorised person.
  • To ask what personal information we hold about you, and to be given a copy.
  • To ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained.
  • To object, on reasonable grounds, to the processing of your personal information.
  • To object to direct marketing at any time.
  • To not be subject to a decision based solely on automated processing that has legal consequences for you.
  • To complain to the Information Regulator, and to institute civil proceedings.

14.2 Under the UK GDPR and EU GDPR

  • Access: to be told whether we process your data and to receive a copy.
  • Rectification: to have inaccurate or incomplete data corrected.
  • Erasure: to have your data deleted in certain circumstances.
  • Restriction: to have processing limited in certain circumstances.
  • Portability: to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another provider where technically feasible.
  • Objection: to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Withdrawal of consent: at any time, without affecting the lawfulness of processing before withdrawal.
  • To not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects.

14.3 If you are a California resident

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, you may ask us to tell you what personal information we have collected about you and the categories of sources, purposes and recipients; to correct inaccurate personal information; to delete personal information we hold about you; to limit the use and disclosure of sensitive personal information; and to opt out of the sale or sharing of personal information. You may use an authorised agent to make a request on your behalf, and we may ask that agent for proof of your authorisation.

In the last 12 months we have collected the categories of personal information described in section 4, from the sources described in sections 4.1 to 4.3, for the purposes in section 5, and disclosed them to the categories of recipient in section 10.

We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. Our use of advertising and analytics cookies on askyazi.com may constitute a "sale" or "share" for cross-context behavioural advertising under California law. To opt out, reject advertising cookies in our cookie banner, send a Global Privacy Control signal from your browser, or email accounts+privacy@askyazi.com. We do not use or disclose sensitive personal information for purposes that require an option to limit it.

We will not discriminate against you for exercising any of these rights.

14.4 How to exercise your rights

Email accounts+privacy@askyazi.com. Tell us what you want and, if you can, which study or account it relates to. We may need to verify your identity before we act, and we will only ask for what is necessary to do that. Under POPIA you may also use the prescribed forms (Form 2 for access, Form 3 for correction or deletion, Form 1 for an objection), addressed to the Information Officer, and our PAIA manual sets out the full procedure. We will not turn away a request just because it did not arrive on a form.

UnderWe respond within
UK GDPR / EU GDPROne month, extendable by up to two further months for complex or numerous requests. We will tell you within the first month if we need the extension and why
POPIA / PAIA30 days, extendable by a further 30 days where the law permits
CCPA / CPRA45 days, extendable by a further 45 days, with notice to you

We do not currently charge for a reasonable request, although POPIA and PAIA permit a prescribed fee for access to records. If a fee would ever apply we will tell you before doing the work.

If you took part in a research study, remember that our client is the Controller. Section 3 explains what happens to your request.

15. Children and young people

Yazi's website and platform accounts are intended for business users and are not directed at children.

Research participation. Under POPIA s.34, processing the personal information of a child (anyone under 18 in South Africa) is prohibited unless one of the grounds in s.35 applies, the most common being the consent of a parent, guardian or other competent person. Yazi does not knowingly allow anyone under 18 to take part in a study unless the client running it has obtained that consent, and any consent required by local law in the participant's country, and confirmed this to us in writing before the study begins. Studies involving under-18s require the prior written approval of Yazi's Chief Executive Officer and additional safeguards documented in the project plan.

In the United Kingdom and European Union, where a study relies on the participant's own consent for an online service, the minimum age is 13 in the UK and between 13 and 16 depending on the member state, under GDPR Article 8. Where a study is run in those jurisdictions we apply the higher of the local requirement and the client's own policy.

If you believe a child has provided personal information to us without the necessary consent, contact accounts+privacy@askyazi.com. We will investigate, tell the client running the study, and have it deleted.

16. Links to other sites

Our site and our messages may contain links to sites we do not operate. We are not responsible for the content or privacy practices of those sites, and we encourage you to read their privacy policies before providing them with information.

17. Changes to this policy

We review this policy at least annually and update it when our processing changes. When we make a material change we will update the effective date at the top of this page and, where the change significantly affects you, notify account holders by email or by a prominent notice on the Service before it takes effect.

18. Contact us and how to complain

Contact Yazi first. Email accounts+privacy@askyazi.com, or use the contact form at askyazi.com. We would rather hear about a problem and fix it.

If you are not satisfied with our response, you can complain to a supervisory authority.

South AfricaInformation Regulator (South Africa). POPIA complaints are lodged through the Regulator's eServices Portal at inforegulator.org.za. General enquiries: enquiries@inforegulator.org.za. Toll free: 0800 017 160.
United KingdomInformation Commissioner's Office, ico.org.uk. Helpline: 0303 123 1113.
European UnionThe data protection supervisory authority in your country of residence, place of work, or where the issue occurred. A list is published by the European Data Protection Board at edpb.europa.eu.

Related documents