Privacy
Privacy policy
Last updated: 14 August 2026
This policy explains what personal information Signalword collects, why, and what we do with it. It is written to be read, not to be survived.
Who we are
Signalword is a trading name of HEZA Consulting (Pty) Ltd, a private company registered in South Africa under registration number 2021/445585/07.
Care of: TaxedUp, 15 Helderberg St, Valmary Park, Cape Town, 7550, South Africa
For the purposes of the UK and EU General Data Protection Regulation we are the data controller for the information described here. For the purposes of South Africa’s Protection of Personal Information Act we are the responsible party.
Our Information Officer is Andrew James Woods Ballard, registered with the Information Regulator of South Africa under registration number 2026-064433. You can reach him through our contact form.
What we collect, and why
We collect very little, and only what you give us.
When you request a free score, we collect your email address, the website address you asked us to check, and your name if you give it. We use these to run the check and send you the result. We keep a record of the request so we know whether we have already replied.
When you use the contact form, we collect your name, email address, your message, and your website if you supply it. We use these to reply to you.
When you become a client, we additionally hold the information needed to deliver and invoice the work — usually a billing contact and the details of the website being audited.
Automatically, our hosting provider records standard technical information for every visit, including your IP address, the pages requested, and the time. This is kept briefly for security and to keep the site working.
How you reached us. When you send us a form, we record which page you arrived on and, if you followed a link from a partner or from an email we sent, a short tag identifying that link. It tells us whether an introduction came from a colleague or whether you found us yourself, and it is stored with your enquiry. It is not used to follow you around other websites, and it is held only in your browser for the duration of your visit.
We do not collect special category data, we do not buy personal data from third parties for our marketing, and we do not track you across other websites.
What we do not do
We do not add you to a mailing list because you asked for a free score. We do not sell, rent or share your details with anyone for their own marketing. We do not use your information to train AI models.
If we ever want to send you something you did not ask for, we will ask first.
Why we are allowed to hold it
Under the UK and EU GDPR we rely on:
- Legitimate interests — to reply to an enquiry you sent us, and to keep a record of having done so. If you write to us asking a question, answering you is the obvious and expected use of your address.
- Performance of a contract — to deliver and invoice work for clients.
- Legal obligation — to keep financial records for as long as tax law requires.
Under POPIA we process this information because you have provided it for a stated purpose, because it is necessary to conclude or perform under a contract with you, or because it protects a legitimate interest.
The websites we audit
Our audit measures technical facts about a website that anyone can observe: what its robots.txt file says, how its server responds to a request, whether its pages can be read without JavaScript. This is information about a website, not about a person, and we collect it by making ordinary web requests of the kind every search engine makes.
We also ask AI assistants publicly answerable questions such as “best safari operators for families” and record which businesses they name. Those are company names, not personal data.
Where we hold a list of organisations we might contact, that list is business contact information — company names, website addresses, and where relevant a generic business address such as info@. If you would rather not be on it, tell us and we will remove you.
Who else sees your information
We use a small number of service providers, each doing one job. They may process your information only on our instructions.
| Provider | What it does | Where |
|---|---|---|
| Lovable | Hosts the website and stores form submissions | EU / United States |
| Resend | Delivers the notification email when you submit a form | United States |
| Cloudflare | DNS, and the Turnstile anti-spam check on our forms | Global |
| Google Workspace | Our own email | Global |
For clients only, and only during a paid audit:
| Provider | What it does | Where |
|---|---|---|
| OpenRouter | Passes our audit questions to the AI assistants we test | United States |
The questions we send to AI assistants are about companies and destinations. We do not send your personal information, or your clients’ personal information, to any AI model.
Because several of these providers are outside South Africa, the UK and the EU, your information may be transferred internationally. Where required, those transfers rely on standard contractual clauses or an equivalent safeguard.
The anti-spam check on our forms
Our forms use Cloudflare Turnstile to tell a person from an automated script. It looks at signals from your browser to make that judgement, and it may store a short-lived token so it does not have to ask twice. It is not used to track you, build a profile, or advertise to you, and we chose it over an image puzzle specifically because it asks less of you.
How long we keep it
- Free score requests and enquiries — up to 24 months from your last contact with us, then deleted. Enough time for a conversation to resume naturally.
- Client records — for the length of the engagement, and then as long as tax and accounting law requires.
- Audit results — technical information about a website, kept while it is useful for comparison. It contains no personal information.
- Server logs — a short period, set by our hosting provider.
Your rights
You can ask us to:
- Show you what we hold about you
- Correct anything that is wrong
- Delete it, where we have no continuing reason to keep it
- Stop using it for a particular purpose
- Send it to you in a portable format
Ask through our contact form and we will reply within 30 days. We will not charge you and we will not make it difficult.
If you are unhappy with how we have handled your information you can complain to:
- The Information Regulator of South Africa — inforegulator.org.za
- The UK Information Commissioner’s Office — ico.org.uk, if you are in the UK
- Your national data protection authority, if you are in the EU
We would rather you told us first, but you do not have to.
Security
Access to form submissions is limited to the person who replies to them. Our own email uses two-factor authentication. API keys are held as environment variables and never appear in the website’s code.
We are a very small operation, which has one honest implication worth stating: we hold little, and the best protection for your information is that there is not much of it.
Children
Our service is sold to businesses. We do not knowingly collect information from anyone under 18. Some of our clients are language schools and educational travel providers whose own customers are young — but we audit their websites, and we never receive their student records.
Changes
If we change this policy we will change the date at the top. If a change materially affects how we use information you have already given us, we will tell the people affected directly rather than quietly updating the page.
Contact
Questions about this policy, or about information we hold: use our contact form. Our PAIA manual sets out how to make a formal request for records.