Skip to main content
Last Updated: June 2025

Privacy Policy

Your privacy is important to us. This policy explains how Marqly collects, uses, and protects your personal information in full compliance with POPIA and applicable data protection laws.

1. Information We Collect

Marqly collects and processes the following categories of personal information:

Account Information

  • Identity Data: Full name, email address, phone number, business name, and company registration number when you register.
  • Billing Data: Billing address, VAT number, and payment method details (processed securely through PayStack; Marqly never stores full card details).
  • Profile Data: Username, password, profile picture, and business preferences.

CRM & Business Data

  • Contact Data: Names, email addresses, phone numbers, and notes you store about your customers, leads, and prospects.
  • Deal & Pipeline Data: Deal values, stages, notes, and communication history within your sales pipeline.
  • Communication Data: Email, WhatsApp, and SMS message content and delivery records sent through our platform.
  • Document Data: Invoices, quotes, contracts, and files you upload or generate within the platform.

Website & Marketing Data

  • Website Data: Content you publish through the Marqly website builder, including pages, blog posts, and media.
  • Marketing Data: Campaign performance, email open rates, click-through rates, and subscriber lists.
  • Analytics Data: Visitor behavior on your Marqly-built website, including page views and conversion events.

AI Processing Data

  • AI Input Data: Prompts, instructions, and context you provide to Marqly AI features (e.g., AI drafts, Smart Reply, content generation).
  • AI Output Data: Content generated by AI models based on your instructions and business context.
  • Feedback Data: Your ratings and corrections on AI outputs, used to improve response quality.

Technical Data

  • Usage Data: Pages visited, features used, time spent on platform, and interaction patterns.
  • Device Data: IP address, browser type, operating system, and device identifiers.
  • Log Data: Server logs, error reports, and diagnostic information.

2. How We Use Your Information

We process your personal information for the following purposes based on our legitimate business interests, contractual necessity, or your consent:

  • Service Delivery: To operate, maintain, and provide you with the full Marqly platform including CRM, AI automation, messaging, invoicing, website builder, and marketing tools.
  • AI Processing: To process your AI requests and generate content, drafts, and recommendations. AI models process data in real-time; we do not use your business data to train public AI models without your explicit consent.
  • Messaging: To send emails, WhatsApp messages, and SMS through our platform on your behalf. Message content is stored for delivery tracking and compliance purposes.
  • Payment Processing: To process subscription payments via PayStack and manage billing cycles, invoices, and receipts.
  • Support & Communication: To respond to your inquiries, provide technical support, and send service-related announcements.
  • Improvement & Analytics: To analyze usage patterns, improve platform performance, and develop new features.
  • Security & Compliance: To detect and prevent fraud, abuse, and security incidents, and to comply with legal obligations including POPIA.

3. Legal Basis for Processing (POPIA)

Under the Protection of Personal Information Act (POPIA), Marqly processes personal information on the following lawful bases:

  • Consent: Where you have given clear consent for us to process your personal information for a specific purpose (e.g., marketing communications, AI feature usage).
  • Contractual Necessity: Where processing is necessary to perform our contract with you, including delivering platform services, processing payments, and providing support.
  • Legal Obligation: Where we must process data to comply with legal requirements, including POPIA record-keeping, SARS tax regulations, and lawful requests from authorities.
  • Legitimate Interest: Where processing is necessary for our legitimate business interests, such as improving our platform, ensuring security, and analyzing usage trends — provided these do not override your rights.

Our Role as an Operator

When you (our customer) input data about your own customers, leads, or contacts into Marqly's CRM, you are the responsible party under POPIA, and Marqly acts as the operator processing that data on your behalf. We have a Data Processing Agreement that governs this relationship.

4. Data Security

Marqly implements comprehensive technical and organizational security measures to protect your personal information:

Technical Measures

  • Encryption in Transit: All data transmitted to and from Marqly is encrypted using TLS 1.3 protocol, ensuring secure communication.
  • Encryption at Rest: Data stored on our servers is encrypted using AES-256 encryption.
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and strict session management.
  • Monitoring: 24/7 system monitoring, intrusion detection systems, and automated threat response.
  • Backups: Encrypted daily backups with secure off-site storage and regular disaster recovery testing.

Organizational Measures

  • Regular staff training on data protection and POPIA compliance
  • Strict confidentiality agreements with all employees and contractors
  • Annual security audits and penetration testing by independent third parties
  • Information Security Management System aligned with ISO 27001 principles
  • Designated Information Officer registered with the Information Regulator

5. Data Retention & Deletion

We retain your personal information only for as long as necessary to fulfill the purposes described in this policy:

  • Active Account: Data retained for the duration of your active subscription plus 90 days.
  • After Cancellation: 90-day grace period during which you can export your data or reactivate your account.
  • Permanent Deletion: After the grace period, all personal information is permanently deleted within 30 days, except where retention is legally required.
  • Financial Records: Invoices and transaction records retained for 5 years as required by South African revenue law (SARS).
  • Anonymized Data: Aggregated, anonymized analytics data may be retained indefinitely for product improvement purposes.

You may request early deletion of your personal information at any time by contacting our Information Officer. Such deletion requests will be processed within 30 days, subject to legal obligations to retain certain records.

6. Your Rights Under POPIA

As a data subject under South Africa's Protection of Personal Information Act (POPIA), you have the following rights:

  • Right of Access (Section 23): Request confirmation of whether we hold your personal information and request a copy of that information.
  • Right to Correction (Section 24): Request correction or deletion of inaccurate, irrelevant, or excessive personal information.
  • Right to Deletion (Section 24): Request deletion of your personal information where we are no longer authorized to retain it.
  • Right to Object (Section 11(3)): Object, on reasonable grounds, to the processing of your personal information, including for direct marketing purposes.
  • Right to Portability: Request a copy of your data in a structured, machine-readable format (JSON/CSV) to transfer to another service provider.
  • Right to Complain (Section 74): Lodge a complaint with the Information Regulator if you believe we have violated your rights under POPIA.

To exercise any of these rights, please contact our Information Officer at privacy@marqly.co.za. We will respond to your request within 30 days as required by POPIA.

Information Regulator (SA):
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints@inforegulator.org.za | Web: www.inforegulator.org.za

7. Third-Party Services & Data Sharing

Marqly integrates with trusted third-party service providers to deliver our platform. We only share data necessary for these services to function:

  • PayStack — Payment processing. We share billing amount and transaction reference; no full card details.
  • Supabase — Database and authentication infrastructure. All data is hosted in South Africa.
  • OpenAI / Anthropic — AI model providers for features like Smart Reply, AI drafts, and content generation. Data sent for processing is not used to train their models.
  • WhatsApp Business API (Meta) — WhatsApp messaging. Message content and delivery status are processed through Meta's infrastructure.
  • AWS / Cloudflare — Cloud infrastructure, CDN, and email delivery services.

We do not sell, trade, or rent your personal information to third parties. Where we share data with service providers, we ensure they are contractually bound to protect your information in accordance with POPIA.

8. International Data Transfers

Marqly is a South African company and our primary infrastructure is hosted in South Africa. However, some of our third-party service providers may process data outside of South Africa:

  • AI Processing: AI model inference may occur on servers in the United States or Europe, depending on the provider.
  • Email Delivery: Transactional emails may be routed through infrastructure in the United States or Europe.
  • CDN Services: Content delivery network nodes may be located globally.

Where personal information is transferred across international borders, Marqly ensures appropriate safeguards are in place, including Standard Contractual Clauses and adequacy determinations, to ensure your data receives an equivalent level of protection as required by POPIA Section 72.

9. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to operate, analyze, and improve our platform. These include:

  • Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Functional Cookies: Remember your preferences, theme settings, and language choices.
  • Analytics Cookies: Help us understand how you use our platform to improve performance and user experience.

For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.

10. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Information Officer:

Information Officer: Marqly Compliance Team

Email: privacy@marqly.co.za

Address: Johannesburg, South Africa

Response Time: We aim to respond to all requests within 30 days.