
062 310 9805
Cenarasoft Marketing and Software Solutions
Website: cenarasoft.org
Privacy Contact: [email protected]
Country of Operation: South Africa (We serve client internationally)
1. Introduction
Welcome to Cenarasoft Marketing and Software Solutions (“Cenarasoft,” “we,” “us,” or “our”).
Cenarasoft provides business software, customer relationship management (“CRM”), websites, automation, artificial intelligence, marketing, communication, and related technology services designed to help businesses operate, market, and grow more effectively.
Our guiding philosophy is:
Built on Love. Guided by Cunning. Outfox the Competition.
We respect the privacy of individuals whose Personal Information we process. This Privacy Policy explains how we collect, use, disclose, retain, protect, and otherwise process Personal Information when you:
-Visit our website;
-Contact us;
-Submit information through our forms;
-Book a meeting or appointment;
-Purchase or enquire about our products or Services;
-Create or use an account provided by Cenarasoft;
-Use our software, CRM, automation, communication, marketing, website, or artificial intelligence Services; or
-Otherwise interact with Cenarasoft.
This Privacy Policy should be read together with our Terms of Service, service agreements, order forms, subscription agreements, data-processing agreements, and any other contractual documents applicable to your relationship with Cenarasoft.
By accessing or using our website or Services, you acknowledge that you have had an opportunity to review this Privacy Policy.
2. Who We Are
Cenarasoft Marketing and Software Solutions is a South African technology and marketing business providing software and technology-enabled Services to businesses.
Our Services may include:
-Business software;
-CRM systems;
-Websites and web applications;
-Marketing automation;
-Artificial intelligence and AI-assisted tools;
-Lead management;
-Appointment scheduling;
-Communication systems;
-Email and SMS functionality;
-Marketing services;
-Advertising services;
-Analytics and reporting;
-Customer support;
-Business automation; and
-Related implementation and consulting Services.
Cenarasoft may use third-party technology providers, cloud infrastructure, application programming interfaces (“APIs”), communication providers, payment processors, analytics providers, advertising platforms, artificial intelligence providers, and other service providers to deliver these Services.
3. Cenarasoft's Role in Processing Personal Information
The role Cenarasoft plays in relation to Personal Information depends on the circumstances in which the information is processed.
3.1 Information We Collect Directly
When you interact directly with Cenarasoft, such as by visiting our website, completing a form, contacting us, purchasing Services, or creating an account, Cenarasoft may determine the purposes and means for which your Personal Information is processed.
Depending on the applicable law, Cenarasoft may therefore act as a:
Responsible party;
Controller;
Data controller; or
Equivalent privacy role.
3.2 Customer and End-User Information
Customers may use Cenarasoft Services to collect and manage Personal Information relating to their own customers, leads, prospects, employees, suppliers, or other contacts.
For example, a customer may use Cenarasoft Services to:
-Store contact information;
-Manage leads;
-Schedule appointments;
-Send communications;
-Manage sales opportunities;
-Run marketing campaigns;
-Manage customer-service processes;
-Operate websites and forms;
-Automate business processes; or
-Use artificial intelligence and automation.
In these circumstances, the customer generally determines why and how the information is collected and used.
Cenarasoft may therefore act as an operator, processor, service provider, or equivalent role processing information on behalf of that customer.
The customer remains responsible for determining the lawful basis for processing its customers' Personal Information, providing appropriate privacy notices, obtaining required permissions, honouring applicable rights, and complying with laws applicable to its business.
4. Third-Party Technology and HighLevel
Certain Cenarasoft Services may be delivered using third-party software and infrastructure, including HighLevel/GoHighLevel and related technology providers.
Depending on the Service being provided, Cenarasoft may configure, provision, manage, support, or integrate third-party technology as part of the Services we provide.
Accordingly, a particular data-processing relationship may involve several parties, for example:
Your Business → Cenarasoft → HighLevel / Other Technology Providers
Depending on the processing activity:
-Your business may act as the controller or responsible party;
-Cenarasoft may act as an operator, processor, service provider, or equivalent role; and
-HighLevel or another third-party provider may act as a processor, sub-processor, or other service provider.
The precise legal roles depend on the specific data, processing activity, contractual relationship, and applicable law.
Cenarasoft is responsible for privacy practices within its own control. Third-party providers remain responsible for the systems, infrastructure, and processing activities under their respective control.
5. Personal Information We Collect
We may collect Personal Information that you provide directly to us, information generated through your use of our Services, and certain information collected automatically.
5.1 Information You Provide
Depending on how you interact with Cenarasoft, we may collect:
-Full name;
-Business name;
-Email address;
-Telephone or mobile number;
-Business or mailing address;
-Billing information;
-Account information;
-Login credentials;
-Information submitted through forms;
-Information provided when booking appointments;
-Customer-support information;
-Information provided during sales discussions;
-Communications between you and Cenarasoft;
-Information relating to Services purchased or requested; and
-Other information you voluntarily provide.
We only seek to collect information that is reasonably necessary for the relevant purpose.
6. Information Collected Automatically
When you visit our website or use certain Services, we may automatically collect technical and usage information.
This may include:
-Internet Protocol (“IP”) address;
-Browser type and version;
-Device type;
-Operating system;
-Approximate geographic location;
-Referring website;
-Pages visited;
-Date and time of access;
-Session information;
-Device identifiers;
-Interaction information;
-Security information;
-Diagnostic information; and
-Other technical information.
We may collect this information through cookies, pixels, logs, analytics technologies, and similar technologies.
7. Cookies and Similar Technologies
Cenarasoft may use cookies and similar technologies to:
-Operate and secure our website;
-Remember preferences;
-Improve website functionality;
-Understand website usage;
-Measure marketing performance;
-Analyse traffic;
-Improve our Services;
-Detect fraudulent or abusive activity;
-Personalise certain experiences; and
-Support advertising and analytics.
Cookies may be placed by Cenarasoft or by third-party providers whose technologies are integrated into our website or Services.
You may control cookies through your browser settings. Where required by applicable law, we will request consent before placing non-essential cookies or similar technologies.
Disabling certain cookies may affect the availability or functionality of parts of our website or Services.
8. How We Use Personal Information
Cenarasoft may use Personal Information for purposes including:
Providing and operating our Services;
Creating and administering accounts;
Provisioning software accounts or sub-accounts;
Configuring and maintaining software;
Processing payments;
Providing customer support;
Responding to enquiries;
Scheduling meetings;
Communicating with customers;
Sending service-related notifications;
Providing information requested by you;
Improving our Services;
Developing products and features;
Analysing usage and performance;
Detecting fraud and abuse;
Maintaining security;
Managing our business;
Conducting lawful marketing activities;
Measuring advertising and marketing performance;
Complying with legal obligations;
Enforcing agreements; and
Protecting our rights, property, users, and legitimate business interests.
We seek to process Personal Information for purposes reasonably connected to the purpose for which it was collected.
9. Lawful Bases for Processing
Where applicable law requires a lawful basis for processing Personal Information, Cenarasoft may rely on one or more of the following:
Your consent;
Performance of a contract;
Taking steps at your request before entering into a contract;
Compliance with a legal obligation;
Legitimate interests;
Protection of rights, property, safety, and security; or
Another lawful basis recognised by applicable law.
Where processing is based on consent, you may withdraw your consent where permitted by law.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
10. Client Responsibilities
If you use Cenarasoft Services to collect or process information about your own customers, prospects, employees, or other individuals, you are generally responsible for ensuring that your processing is lawful.
You are responsible for:
Having an appropriate lawful basis for collecting and using Personal Information;
Providing appropriate privacy notices;
Obtaining required consent or permissions;
Honouring opt-out and unsubscribe requests;
Maintaining appropriate retention periods;
Responding to applicable data-subject requests;
Maintaining appropriate internal security;
Configuring the Services appropriately;
Restricting access to authorised individuals;
Maintaining accurate information; and
Using the Services in compliance with applicable law.
Cenarasoft provides technology and related Services. Our Services do not replace your own legal, regulatory, privacy, or compliance responsibilities.
11. South African Privacy Law - POPIA
Cenarasoft is committed to complying with applicable South African privacy legislation, including the Protection of Personal Information Act 4 of 2013 (“POPIA”), where applicable.
POPIA establishes requirements concerning the lawful processing of Personal Information and governs responsibilities relating to the collection, use, retention, disclosure, security, and protection of Personal Information.
Depending on the circumstances, Cenarasoft may act as the relevant Responsible Party when determining the purposes and means of processing Personal Information collected directly by us.
Where we process Personal Information solely on behalf of a customer, Cenarasoft may act as an Operator.
We seek to process Personal Information responsibly, lawfully, and transparently.
12. GDPR and International Privacy Laws
Where applicable, Cenarasoft seeks to support compliance with privacy laws that may apply to the processing of Personal Information, including:
The European Union General Data Protection Regulation (“GDPR”);
The UK General Data Protection Regulation (“UK GDPR”);
Applicable United States state privacy laws;
Applicable Canadian privacy legislation;
Applicable Australian privacy legislation; and
Other applicable data-protection laws.
The availability and scope of particular privacy rights depend on the applicable law and the circumstances of the processing.
13. Data Subject Rights
Depending on applicable law, individuals may have rights concerning their Personal Information, including:
The right to access;
The right to correction or rectification;
The right to deletion or erasure;
The right to restriction of processing;
The right to object to processing;
The right to data portability;
The right to withdraw consent; and
Other rights provided by applicable law.
If Cenarasoft processes information strictly on behalf of one of our customers, requests relating to that information may need to be directed to the relevant customer.
Where appropriate, Cenarasoft may assist the customer in responding to such requests.
We may require reasonable information to verify your identity before fulfilling certain privacy requests.
14. Requests to Cenarasoft
You may contact Cenarasoft to:
Request access to Personal Information we control;
Request correction of inaccurate information;
Request deletion where applicable;
Withdraw consent;
Object to certain processing;
Ask questions about our privacy practices;
Request information about our processing activities; or
Submit a privacy complaint.
We will assess and respond to valid requests in accordance with applicable law.
Where a request relates to information processed by Cenarasoft on behalf of a customer, we may refer the request to the relevant customer or assist the customer as appropriate.
15. Data Security
Cenarasoft considers information security an essential part of responsible technology management.
We seek to maintain reasonable technical and organisational safeguards designed to protect Personal Information against:
Unauthorised access;
Unauthorised disclosure;
Accidental loss;
Unlawful destruction;
Unauthorised alteration;
Misuse; and
Other reasonably foreseeable security risks.
Our security practices may include:
Access controls;
Authentication;
User permissions;
Account controls;
Monitoring;
Administrative safeguards;
Vendor management;
Security procedures; and
Other safeguards appropriate to the nature and sensitivity of the information.
However, no method of electronic storage or transmission over the Internet can be guaranteed to be completely secure.
16. Shared Responsibility for Security
Security within Cenarasoft Services is a shared responsibility.
Cenarasoft
Cenarasoft is responsible for implementing reasonable safeguards within systems, processes, accounts, and Services under our control.
Third-Party Providers
Third-party providers are responsible for the infrastructure, platforms, and services under their respective control.
Customers
Customers are responsible for security practices under their control, including:
Account credentials;
Passwords;
Multi-factor authentication where available;
User permissions;
Employee access;
Contractor access;
Device security;
Internal security procedures;
Appropriate configuration of Services; and
Lawful use of the Services.
No party should assume that another party's security programme eliminates its own responsibilities.
17. HighLevel Security and Compliance
Where Cenarasoft uses HighLevel or related technology infrastructure, certain security controls may be provided by that third-party platform.
HighLevel publishes information regarding its security programme and compliance activities, which may include security controls relating to:
Encryption;
Access controls;
Authentication;
Logging and monitoring;
Vulnerability management;
Security testing;
Cloud infrastructure;
Backups; and
Other technical and organisational safeguards.
HighLevel has also publicly described SOC 2 Type II assessments and other security and compliance programmes.
These certifications, assessments, attestations, and compliance programmes belong to HighLevel or the applicable third-party provider. They are not certifications of Cenarasoft.
Cenarasoft does not represent that it is independently:
SOC 2 Type II certified;
GDPR certified;
EU-U.S. Data Privacy Framework certified;
HIPAA certified; or
Accredited under another third-party security framework merely because Cenarasoft uses a provider that maintains such certifications or programmes.
18. International Data Transfers
Cenarasoft is based in South Africa but may provide Services to customers internationally.
As a result, Personal Information may be transferred to, stored in, or processed in countries other than the country in which you reside.
Those countries may have privacy laws that differ from those applicable in your jurisdiction.
Where required by applicable law, Cenarasoft seeks to use appropriate safeguards for international transfers, which may include:
Contractual safeguards;
Standard Contractual Clauses;
Adequacy mechanisms;
Data-processing agreements;
Organisational safeguards; or
Other lawful transfer mechanisms.
Where third-party providers are involved, the applicable transfer mechanism may depend on the provider, jurisdiction, data involved, and relevant contractual arrangements.
19. Third-Party Providers and Sub-Processors
Cenarasoft may use third-party providers to provide, support, secure, or improve our Services.
These providers may include:
Cloud infrastructure providers;
CRM providers;
Software providers;
Hosting providers;
Email providers;
Communication providers;
Payment processors;
Analytics providers;
Advertising platforms;
Artificial intelligence providers;
Security providers;
Customer-support providers; and
Other technology providers.
Depending on the circumstances, these providers may act as processors, sub-processors, service providers, or other third parties.
We seek to work with providers that maintain appropriate safeguards for the information they process.
20. Artificial Intelligence
Certain Cenarasoft Services may include artificial intelligence (“AI”) or AI-assisted functionality.
AI functionality may be used for purposes such as:
Content generation;
Customer communication;
Lead management;
Appointment assistance;
Automation;
Data analysis;
Business workflows; and
Other functionality made available through our Services.
AI-generated outputs may be inaccurate, incomplete, outdated, biased, misleading, or unsuitable for a particular purpose.
You are responsible for reviewing and validating AI-generated information before relying upon, publishing, sending, or acting on it.
AI-generated information does not constitute legal, medical, financial, tax, accounting, or other professional advice.
Where third-party AI technology is used, information submitted to the relevant functionality may be processed by the applicable provider according to its terms, privacy policy, and contractual arrangements.
21. Sensitive and Regulated Information
Unless expressly agreed in writing and appropriate safeguards are established, you should not use ordinary Cenarasoft Services to process highly sensitive or regulated information beyond the intended scope of the Service.
This may include:
Health information;
Payment-card information;
Government identification information;
Highly sensitive financial information;
Authentication credentials;
Special categories of Personal Information; or
Other regulated information.
The availability of a technical feature does not automatically mean that using that feature for a particular category of regulated information is legally compliant.
Where a specific regulated use case requires additional agreements, configurations, safeguards, or services, those requirements must be established before the relevant information is processed.
22. Healthcare and HIPAA
Certain third-party technology providers may offer functionality intended to support healthcare-related or HIPAA-related use cases.
Cenarasoft does not represent that all Cenarasoft Services are HIPAA compliant merely because an underlying technology provider offers HIPAA-related functionality.
Healthcare customers are responsible for ensuring that:
The applicable Service is appropriate for the intended use;
Required agreements are in place;
Appropriate configurations are enabled;
Protected Health Information is handled lawfully; and
Applicable healthcare, privacy, security, and contractual requirements are satisfied.
Where a specific healthcare agreement applies, that agreement will govern to the extent of any conflict.
23. SMS, Email, Voice and Other Communications
Cenarasoft Services may provide communication functionality, including:
SMS;
MMS;
Email;
Voice calls;
Appointment reminders;
Automated messages;
AI-assisted communications; and
Other electronic communications.
Customers are responsible for ensuring that communications sent through their accounts comply with applicable laws and provider requirements.
Customers must obtain any required consent or permission before contacting individuals and must honour applicable:
Opt-out requests;
Unsubscribe requests;
Do-not-contact requests;
Consent requirements; and
Other communication restrictions.
Cenarasoft does not assume responsibility for unlawful communications initiated or authorised by customers.
24. Marketing and Advertising Data
Cenarasoft may process information relating to:
Advertising campaigns;
Marketing performance;
Lead generation;
Customer interactions;
Website activity;
Conversion data;
Analytics; and
Campaign performance.
This information may be used to:
Measure campaign performance;
Provide reporting;
Improve marketing systems;
Diagnose technical issues;
Optimise customer experiences; and
Deliver contracted marketing Services.
Where information belongs to a customer and Cenarasoft processes it on that customer's behalf, we generally process that information according to the customer's instructions and applicable agreement.
25. Information Sharing and Disclosure
Cenarasoft may disclose Personal Information where reasonably necessary to:
Provide our Services;
Process payments;
Provide hosting;
Operate software;
Deliver communications;
Provide customer support;
Provide analytics;
Maintain security;
Operate integrations;
Prevent fraud or abuse;
Comply with legal obligations; or
Protect our legal rights.
We may also disclose Personal Information where required or permitted by law, including in response to:
Court orders;
Government requests;
Law-enforcement requests;
Regulatory requirements;
Legal proceedings; or
Other valid legal processes.
26. Business Transfers
If Cenarasoft is involved in a merger, acquisition, financing, restructuring, sale of assets, reorganisation, or similar transaction, Personal Information may be transferred as part of that transaction.
Where required by applicable law, we will provide appropriate notice concerning such a transfer.
Any successor organisation may become responsible for the Personal Information transferred to it, subject to applicable law and any applicable privacy notice.
27. We Do Not Sell Customer Personal Data
Cenarasoft does not sell Customer Personal Data as a standalone commercial product.
We may, however, process Personal Information as reasonably necessary to:
Provide Services;
Operate our technology;
Secure our Services;
Provide customer support;
Improve our Services;
Maintain integrations;
Process payments;
Perform contracted Services; and
Comply with applicable law.
Third-party providers used to deliver our Services may have their own privacy policies and contractual obligations.
28. Data Retention
Cenarasoft retains Personal Information only for as long as reasonably necessary for the purpose for which it was collected or as otherwise required or permitted by law.
Retention periods may depend on:
The nature of the information;
The purpose for which it was collected;
Contractual obligations;
Legal requirements;
Tax and accounting requirements;
Security requirements;
Dispute resolution;
Fraud prevention;
Legitimate business requirements; and
Requirements of third-party infrastructure providers.
Where Cenarasoft processes Personal Information on behalf of a customer, the customer may determine the appropriate retention period, subject to applicable law and the technical capabilities of the relevant Services.
29. Account Termination and Data Deletion
When a Cenarasoft Service is cancelled or terminated, access to the applicable account may cease.
Personal Information may remain temporarily within underlying systems, backups, logs, or third-party infrastructure depending on:
Applicable retention periods;
Backup procedures;
Legal obligations;
Security requirements;
Contractual arrangements; and
Third-party platform policies.
Cenarasoft may retain information where reasonably necessary for:
Legal compliance;
Fraud prevention;
Security;
Accounting;
Tax;
Dispute resolution;
Enforcement of agreements; or
Other lawful purposes.
Where legally required and reasonably possible, Cenarasoft will honour valid deletion requests.
30. Security Incidents and Data Breaches
Cenarasoft maintains processes intended to identify, investigate, respond to, contain, and mitigate security incidents.
If we become aware of a confirmed security incident involving Personal Information under our control, we will take reasonable steps to investigate and respond.
Where applicable law requires notification, we will provide notifications within the timeframe required by that law.
Where Cenarasoft processes Personal Information on behalf of a customer, we may notify the relevant customer so that the customer can assess and satisfy its own legal notification obligations.
Where an incident occurs within a third-party provider's infrastructure, Cenarasoft may rely on that provider's incident-response and notification procedures.
31. Your Right to Delete or Correct Your Information
Subject to applicable law, you may request that Cenarasoft:
Provide access to Personal Information we hold about you;
Correct inaccurate information;
Delete Personal Information;
Restrict certain processing;
Provide information concerning our processing activities; or
Take other actions required by applicable privacy law.
We may need to verify your identity before fulfilling certain requests.
We may also retain information where required or permitted by law.
32. Accuracy of Personal Information
You are responsible for ensuring that Personal Information you provide directly to Cenarasoft is accurate, complete, and current.
If your information changes, you should update your account where functionality permits or contact us.
Where you use Cenarasoft Services to process information relating to your own customers or contacts, you are responsible for maintaining the accuracy of that information.
33. Confidentiality
Cenarasoft seeks to keep Personal Information confidential and limit access to individuals and service providers who reasonably require access to perform legitimate business functions or provide the Services.
Employees, contractors, and service providers who have access to Personal Information may be subject to confidentiality obligations appropriate to their role.
34. Children and Minors
Cenarasoft's Services are primarily intended for businesses, professionals, and commercial users.
Our Services are not directed toward children.
We do not knowingly collect Personal Information from children where doing so is prohibited by applicable law.
If you believe that a child has provided Personal Information to Cenarasoft inappropriately, please contact us so that we can investigate and take appropriate action.
35. Third-Party Websites
Our website and Services may contain links to websites, applications, or services operated by third parties.
Cenarasoft does not control the privacy practices, security practices, content, or policies of third-party websites.
If you follow a third-party link, you should review that third party's privacy policy and terms before providing Personal Information.
Cenarasoft is not responsible for the privacy practices of third-party websites or services that we do not control.
36. United States Privacy Rights
Certain U.S. states provide residents with additional privacy rights.
Depending on the applicable state law, these rights may include:
Access;
Correction;
Deletion;
Data portability;
Opting out of certain processing;
Opting out of certain targeted advertising;
Appeals; and
Other legally recognised rights.
Where applicable law requires Cenarasoft to respond to such requests, we will process valid requests in accordance with the relevant requirements.
37. European Privacy Rights
Where GDPR applies, individuals may have rights including:
The right to be informed;
The right of access;
The right to rectification;
The right to erasure;
The right to restriction of processing;
The right to data portability;
The right to object; and
Rights concerning certain automated decision-making and profiling.
The availability and scope of these rights depend on the particular circumstances and applicable law.
38. United Kingdom Privacy Rights
Where UK GDPR or other applicable UK privacy legislation applies, individuals may have rights similar to those described under the GDPR.
Cenarasoft will process applicable requests in accordance with the requirements of relevant UK privacy law.
39. Other International Jurisdictions
Customers and users located outside South Africa may have additional privacy rights under laws applicable in their jurisdiction.
Where applicable, Cenarasoft seeks to comply with the legal obligations that apply to the relevant processing activity.
Because privacy requirements differ between jurisdictions, businesses using Cenarasoft Services remain responsible for determining which laws apply to their own operations and customers.
40. Your Marketing Preferences
You may unsubscribe from promotional communications by using the unsubscribe mechanism included in the relevant communication or by contacting Cenarasoft.
Opting out of promotional communications does not necessarily prevent us from sending communications that are necessary to provide our Services, including:
Transactional communications;
Account notices;
Security notifications;
Billing communications;
Service notifications;
Legal notices; or
Other operational communications.
41. No Absolute Security Guarantee
Although Cenarasoft takes security seriously, no internet-connected system can guarantee absolute security.
You acknowledge that:
Internet transmissions involve inherent risks;
Third-party providers may experience outages or security incidents;
No software is completely free from vulnerabilities; and
Security also depends on your own practices.
Cenarasoft will continue to review and improve reasonable safeguards as our technology, Services, and business evolve.
42. Complaints
If you believe Cenarasoft has processed your Personal Information in a manner inconsistent with this Privacy Policy or applicable law, we encourage you to contact us first so that we can investigate the matter.
Depending on your jurisdiction, you may also have the right to lodge a complaint with the applicable data-protection or privacy regulator.
For South African matters, this may include the Information Regulator of South Africa.
43. Privacy Request Verification
To protect Personal Information, Cenarasoft may require reasonable verification before fulfilling certain requests.
We may request information necessary to confirm that the person making the request is authorised to receive the requested information.
Where permitted by law, we may decline requests that cannot reasonably be verified or that fall within an applicable legal exception.
44. Changes to This Privacy Policy
Cenarasoft may update this Privacy Policy from time to time.
Changes may be made to reflect:
Changes in our Services;
Changes in technology;
Changes in our business operations;
Changes in third-party providers;
Changes in privacy legislation;
Changes in security practices; or
Other operational or legal developments.
When we update this Privacy Policy, we will update the Last Updated date at the beginning of the document.
Where required by law, we will provide additional notice of material changes.
You are encouraged to review this Privacy Policy periodically.
45. Third-Party Compliance and Security Information
Cenarasoft may reference security, privacy, or compliance information published by third-party technology providers used in connection with our Services.
References to:
SOC 2;
GDPR;
EU-U.S. Data Privacy Framework;
Standard Contractual Clauses;
Encryption;
Security assessments;
Penetration testing;
HIPAA-related capabilities; or
Other compliance frameworks
refer to the applicable third-party provider unless expressly stated otherwise.
Cenarasoft does not adopt a third-party provider's certification, attestation, or compliance status as its own merely because we use that provider's technology.
Customers requiring formal certifications, security reports, Data Processing Agreements, sub-processor information, or other compliance documentation should review the relevant provider's current documentation and obtain appropriate professional advice.
46. Shared Responsibility Model
The privacy and security of information processed through Cenarasoft Services may involve multiple parties.
Cenarasoft
Cenarasoft is responsible for reasonable safeguards within the systems, processes, accounts, and Services under our control.
Third-Party Providers
Third-party providers are responsible for infrastructure, platforms, and services under their respective control.
The Customer
Customers are responsible for:
Lawful collection;
Appropriate privacy notices;
Appropriate consent;
User permissions;
Account security;
Data accuracy;
Data retention;
Responding to their customers' privacy requests;
Marketing compliance;
Communications compliance; and
Lawful use of the Services.
Each party remains responsible for the obligations that apply to it.
47. Privacy by Responsibility
Cenarasoft believes that privacy is part of good business.
Our objective is not simply to provide software. We aim to build technology systems that businesses can use responsibly and confidently as they grow.
We therefore seek to:
Be transparent about the technology providers we use;
Be accurate about certifications and compliance programmes;
Use reputable infrastructure providers;
Protect information within our control;
Encourage customers to implement strong security practices;
Respect applicable privacy laws; and
Continually improve our systems and processes.
We believe transparency is better than making exaggerated security or compliance promises.
48. Contact Cenarasoft
If you have questions regarding this Privacy Policy, Personal Information, privacy rights, data-processing arrangements, security concerns, or privacy complaints, please contact us.
Cenarasoft Marketing and Software Solutions
Website: cenarasoft.org
Privacy Email: [email protected]
When contacting us regarding a privacy request, please provide sufficient information for us to understand the nature of your request and, where necessary, verify your identity.
49. Governing Privacy Framework
Cenarasoft is based in South Africa and seeks to comply with privacy laws applicable to the Personal Information it processes.
South African privacy requirements, including POPIA, may apply to Personal Information processed by Cenarasoft.
Where Cenarasoft provides Services internationally, additional privacy laws may apply depending on the jurisdiction, individuals involved, nature of the information, and processing activities.
Nothing in this Privacy Policy is intended to limit any rights that cannot lawfully be limited under applicable privacy legislation.
50. Final Statement
Cenarasoft is committed to building technology responsibly.
We believe that growth should not come at the expense of trust, and innovation should not come at the expense of responsibility.
Our mission is to help businesses grow through intelligent technology, automation, software, and marketing.
Our vision is to build systems that empower businesses to operate better, serve people better, and create lasting value.
Built on Love. Guided by Cunning. Outfox the Competition.
© 2026 Cenarasoft Marketing and Software Solutions. All rights reserved.
Last Updated: 23 August 2026
Copyrights 2026 | Cenarasoft™ | Terms of Service & Conditions | Privacy Policy