Privacy Policy
Last Updated: 12 July 2026
This Privacy Policy explains how Govermate, a service operated by Pace Online (Pty) Ltd ("Govermate", "we", "us" or "our"), collects, uses, shares and protects your personal information when you use https://www.govermate.com, the Govermate mobile application, and our related services (the "Service"). We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").
Govermate is an independent aggregator of public South African government opportunity data. We are not a government body and are not affiliated with or endorsed by any organ of state.
1. Responsible party and Information Officer
Pace Online (Pty) Ltd, which operates Govermate, is the "responsible party" for the personal information processed through the Service, as that term is used in POPIA.
Responsible party: Pace Online (Pty) Ltd
Address: Building 10 HQ, 94 Bekker Road, Vorna Valley, Midrand, 1686, South Africa
Information Officer: Xolani Nyuswa
Email: nyuswa@paceonline.co.za
You can contact our privacy office at the address above about anything in this policy, including to exercise your rights or raise a privacy concern.
2. The personal information we collect, and why
We only collect personal information we need to provide and improve the Service. This includes:
Account information — your name and email address, and the password (stored in hashed form) you use to sign in, or the basic profile details supplied by Google or Apple if you choose those sign-in methods. If you use Sign in with Apple, Apple may give us a private-relay email address instead of your direct address. Revocable Apple account credentials needed to honour account deletion are encrypted at rest; we attempt revocation when deletion is confirmed and securely retry a failed revocation. We use this information to create and manage your account, authenticate you, communicate about the Service, and complete deletion obligations.
Subscription and billing information — the plan you choose and records of your payments. Card and payment details are collected and processed directly by our payment partner (Paystack); we do not store your full card number.
Preferences — the opportunity types, sectors, regions or keywords you follow, so we can send you relevant alerts.
Mobile notification information — if you opt in to push alerts in the mobile app, we store your Firebase Cloud Messaging push token, device platform, device identifier, app version and locale so we can deliver alerts to that device. You can turn push alerts off in the app at any time, which disables the device token for alert delivery.
Mobile typed-AI information — before the mobile app sends a typed chat or deep-research request, we ask for explicit consent naming Anthropic and OpenAI. Depending on the action and current provider route, the information sent may include your prompt, relevant conversation history, selected opportunity or source evidence, and the profile, business, preference, or remembered context needed to answer. Anthropic provides routed chat and research models; OpenAI provides supporting model, semantic-embedding, and tool-processing capabilities.
Mobile voice information — if an eligible subscriber starts a voice conversation in the mobile app, the same named-provider disclosure explains that, for voice specifically, live microphone audio and the conversation context needed to answer are sent to OpenAI. The audio is transmitted securely so OpenAI can transcribe speech and return an AI-generated spoken response. Govermate does not store a copy of the raw microphone audio in its databases. We retain the resulting text transcript, model and tool activity, usage totals, and outcome as part of the agent history described below. The microphone is used only during an active voice session, and you can end the session, reset your AI-provider consent in the app, or withdraw microphone permission through your device settings.
Communications and support — messages you send us (for example via the contact form, native support ticket, or support email) and our replies. Mobile support always has a human-only path. If you separately opt in to AI-assisted triage when creating a mobile ticket, we store that versioned choice on the ticket and may send its subject, message, future replies, and relevant ticket or account context to Anthropic and OpenAI to categorize the request and draft a response for human support staff. If you leave the choice off, the server blocks external AI triage for that ticket.
Technical and usage information — your IP address, browser and device type, pages viewed and actions taken, collected through cookies and similar technologies and through analytics, to keep the Service secure, diagnose problems, and improve it. Account-linked route telemetry may retain pseudonymous hashes derived from IP address and user-agent information for security, abuse prevention, auditing and diagnostics; the raw values are not stored in those trace records.
Agent and support history — when Govermate acts on your behalf, we keep logs of the request, surface, context, tools used, support ticket state, and outcome so that the Service can be debugged, audited, improved, and explained. We do not use these logs to hide automated decisions from you.
3. Lawful basis for processing
We process your personal information on one or more of the following lawful bases recognised under POPIA:
with your consent (for example, optional analytics cookies and marketing emails, which you may withdraw at any time);
because processing is necessary to perform our contract with you (providing the Service you signed up for, including billing and alerts);
to comply with a legal obligation that applies to us; and
for our legitimate interests (such as securing the Service and preventing fraud), where these are not overridden by your rights.
4. How we share your information — operators and third parties
We do not sell, rent or trade your personal information.
We share personal information with trusted service providers who process it on our behalf and on our instructions (these are "operators" under POPIA), under agreements that require them to keep it secure and use it only for the purposes we specify:
Paystack — payment processing and subscription management.
Brevo — sending transactional and notification emails (such as sign-in links and alerts).
MongoDB hosting provider — secure database hosting where your account data is stored.
AI providers selected through Govermate's provider catalog — temporary model, OCR, embedding, ranking, and support-assistance capability used to operate agentic features until native Govermate AI replaces them. We send only the context needed for the task and log which provider and model family was used.
Anthropic — routed language-model processing for standard chat, deep research and any support triage that a mobile requester separately authorises. Provider-bound prompts and context are handled under Anthropic's API data-use and retention policies; the applicable retention can depend on provider terms and Govermate's service configuration, so we do not promise a specific Anthropic retention period here.
OpenAI — supporting AI tasks such as semantic embeddings and tool-related processing, any routed synthesis, and realtime speech recognition and AI-generated speech for eligible mobile voice conversations. For voice specifically, OpenAI receives the live microphone audio. OpenAI states that data sent through its API is not used to train or improve its models unless the API customer explicitly opts in. Under OpenAI's default API controls, abuse-monitoring logs may contain prompts and responses and are retained for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect the services or a third party from harm.
Anthropic and OpenAI provider credentials remain on Govermate's server and are never returned to the mobile app. Govermate's server retains control of tools, access rules, consent checks, audit records and usage metering. The mobile app names both providers and asks for explicit consent before provider-bound typed chat; it separately identifies OpenAI's receipt of live microphone audio. Optional mobile support triage has its own ticket-level consent record and does not inherit device-only chat consent.
Apple — Sign in with Apple authentication, including optional private-email relay. We retain only the revocable credential material needed to authenticate and to request Apple-side token revocation when a linked account is deleted, encrypted at rest and subject to secure revocation retry.
Google — authentication, if you choose to sign in with Google.
Firebase Cloud Messaging — mobile push-notification delivery when you opt in to push alerts.
Analytics provider (Google Analytics) — to understand and improve how the Service is used, subject to your cookie consent.
We may also disclose personal information where required by law, to comply with a lawful request from a competent authority, or to protect our rights, users or systems.
5. Cross-border (international) transfers
Some of our operators store or process personal information on servers located outside South Africa. Where we transfer your personal information across borders, we do so in line with section 72 of POPIA — for example, where the recipient is subject to laws or binding agreements that provide an adequate level of protection comparable to POPIA, where the transfer is necessary to perform our contract with you, or where you have consented. By using the Service you acknowledge that your information may be processed in other countries by these operators.
6. Your rights under POPIA
Subject to POPIA, you have the right to:
be told what personal information we hold about you and to request access to it;
request that we correct, update or delete personal information that is inaccurate, irrelevant, excessive, out of date, or unlawfully obtained;
object, on reasonable grounds, to our processing of your personal information;
withdraw consent you previously gave (this will not affect processing already carried out lawfully);
not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you; and
lodge a complaint with the Information Regulator (see section 11).
To exercise any of these rights, contact our privacy office at support@govermate.com. We may need to verify your identity before acting on your request.
7. Retention
We keep your personal information only for as long as necessary to provide the Service, to comply with our legal and tax obligations, to resolve disputes, and to enforce our agreements. Voice transcripts follow the same retention and account-deletion rules as other agent conversation history; raw microphone audio is not retained in Govermate's databases. When information is no longer needed for a lawful purpose, we will delete it or de-identify it. If you close your account, we will delete or de-identify your personal information within a reasonable period after verification, except where we are required or permitted by law to retain certain records (for example, billing records, security logs, or audit records needed to investigate fraud, abuse, support decisions, or system integrity).
8. Security
We apply appropriate, reasonable technical and organisational measures to protect your personal information against loss, unauthorised access, and misuse — including encryption of data in transit, hashed passwords, access controls, and reputable hosting and payment providers. No system is completely secure, but we work to protect your information and, where the law requires it, we will notify you and the Information Regulator of a security compromise affecting your personal information.
9. Cookies and analytics consent
We use cookies and similar technologies that are strictly necessary to run the Service (for example, to keep you signed in), and — only with your consent — optional cookies for analytics that help us understand how the Service is used. You can give or withdraw consent for optional cookies at any time, and you can control or block cookies through your browser settings. Disabling strictly necessary cookies may stop parts of the Service from working.
10. Children
The Service is intended for adults. You must be at least 18 years old to create an account or subscribe. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us with personal information, please contact us at support@govermate.com and we will delete it.
11. Complaints and the Information Regulator
If you have a concern about how we handle your personal information, please contact our privacy office first so we can try to resolve it. You also have the right to complain to the Information Regulator of South Africa:
Information Regulator (South Africa)
Website: https://inforegulator.org.za
Email: enquiries@inforegulator.org.za
Telephone: 010 023 5200
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. When we make material changes we will update the "Last Updated" date above and, where appropriate, notify you. Please review this page periodically.
13. Contact
For any questions or requests relating to this Privacy Policy or your personal information:
Email: support@govermate.com
By using Govermate, you acknowledge that you have read and understood this Privacy Policy.