1. About this policy
VNLA Technologies (Pty) Ltd, trading as VNLA.co.za, is the service provider. In this policy, “VNLA”, “we”, “us” and “our” refer to VNLA Technologies (Pty) Ltd and the VNLA service.
VNLA.co.za is operated by VNLA Technologies (Pty) Ltd, a private company registered in the Republic of South Africa under registration number 2026/608517/07, with its registered office at Clearwater Office Park, Building 3, Ground Floor, Millenium Road, Christiaan de Wet Road, Johannesburg, Gauteng, 1735, South Africa.
This policy applies when you visit the public website at https://vnla.co.za, use the SaaS application at https://app.vnla.co.za, submit an enquiry, create or use a VNLA account, contact us, or interact with a VNLA feature through Meta products such as WhatsApp, Facebook or Instagram.
For personal information processed through the website and application for our own account administration, security, service improvement, support and legal compliance, VNLA Technologies (Pty) Ltd is the responsible party under South Africa’s Protection of Personal Information Act 4 of 2013 (“POPIA”), subject to the operator role described below.
A business using VNLA generally decides why and how its own customer, lead and staff information is processed. For that information, the business is normally the responsible party and VNLA processes it as an operator on the business’s instructions. If your information was submitted to VNLA by one of our business customers, that business’s privacy notice may also apply.
2. Information we collect
The information we process depends on how you use VNLA and which features you choose. It may include:
- Identity and contact details: your name, email address, telephone or WhatsApp number, company name, job role and account identifiers.
- Account and organisation details: workspace name, users, roles, preferences, authentication records and connected service settings.
- Customer and workflow information: contacts, leads, enquiries, conversation content, tasks, workflow instructions, products, services, quote information and documents that you or an authorised business user provides.
- Meta product information: information described in section 4 when you communicate with us through, or connect, a Meta product.
- Support and enquiry information: the details and content you provide when you request support, product information or other assistance.
- Technical and usage information: IP address, browser or device information, timestamps, log records, security events, feature usage and diagnostic information.
- Transaction information: plan, subscription, invoice and payment-status information if paid features are enabled. Payment card or bank details may be handled directly by the relevant payment provider rather than stored by VNLA.
We collect information directly from you, from authorised users in your organisation, from businesses using VNLA, automatically when you use our services, and from connected services such as Meta when you authorise the connection or send a message.
Where information is necessary to create an account, authenticate you, provide a requested service or meet a legal requirement, failing to provide it may mean that we cannot provide that part of VNLA. Optional fields may be left blank.
3. How and why we use information
We process personal information only where there is an appropriate basis, including to perform a contract, take steps you request before entering a contract, comply with law, pursue a legitimate business interest that does not override your rights, or act with consent where consent is required.
We use information to:
- provide, configure and operate accounts, workspaces, conversations, workflows, tasks, quotes, integrations and support;
- authenticate users, control access, prevent abuse, investigate incidents and maintain the security and reliability of VNLA;
- send service messages and communications you request;
- connect to Meta products and process messages or business account information as described below;
- diagnose faults, measure service usage and improve the performance and usability of VNLA;
- administer subscriptions and payments where applicable; and
- comply with legal obligations, resolve disputes and enforce our agreements.
Where AI-assisted features are enabled, information submitted to a workflow may be analysed to classify a request, extract relevant details, suggest a response, or prepare a draft action such as a quote or follow-up. VNLA’s AI-assisted features are intended to support business users and are not intended to make legally binding or similarly significant decisions about a person without appropriate human involvement.
4. Meta and WhatsApp data
VNLA may integrate with Meta products, including the WhatsApp Business Platform and, where enabled, Facebook or Instagram business features. We receive only the information made available through the permissions you or an authorised business administrator grants, or the information needed to process a communication you send.
Depending on the feature, this may include:
- your WhatsApp telephone number or Meta user identifier, profile or display name, and message content;
- message identifiers, type, status, routing information and timestamps;
- WhatsApp Business Account, business portfolio, Page or Instagram professional account identifiers and basic business profile details;
- the permissions and connection information needed to operate the integration; and
- information you choose to send in a message or make available through an authorised Meta feature.
We use this information to connect the selected account, route and display messages, create requested contacts or workflow events, send authorised replies, maintain message status, provide support, secure the integration and comply with applicable law and Meta’s platform requirements.
VNLA does not sell Meta user data. We do not use information obtained from Meta for unrelated advertising or to build advertising profiles. Meta processes information under its own terms and privacy policy; VNLA does not control Meta’s independent processing.
Disconnecting a Meta integration: An authorised VNLA user may disconnect an available integration from the relevant workspace settings. You may also remove permissions through your Meta account or business settings. Removing permission stops future access but may not automatically delete information already received by VNLA. Follow the deletion steps in section 10 to request deletion.
5. When we share information
We do not sell or rent personal information. We may make information available only as reasonably necessary to:
- authorised users within the relevant VNLA workspace;
- the business that controls the customer or lead relationship;
- service providers that support hosting, database storage, email delivery, customer support, security, analytics, AI-assisted functions or payment processing;
- Meta, when you or an authorised business connects or uses a Meta product such as the WhatsApp Business Platform;
- professional advisers, auditors, insurers or a purchaser in a legitimate business transaction, subject to appropriate confidentiality safeguards; and
- regulators, courts, law-enforcement bodies or other parties when required by law or necessary to protect rights, safety or security.
Our service providers may process information only for the contracted service and subject to applicable data-protection and confidentiality requirements.
6. International transfers
Some of our service providers, including global cloud, communications, Meta and AI service providers, may process information outside South Africa. Where personal information is transferred across borders, we take reasonably practicable steps to use recipients, contracts or other safeguards that provide an appropriate level of protection as required by POPIA.
7. How long we keep information
We keep personal information only for as long as it is reasonably needed for the purpose for which it was collected, to provide the service, to follow the relevant business customer’s instructions, and to meet legal, accounting, security or dispute-resolution obligations.
- Unverified registration records are normally removed after their short verification and security-retention period.
- Workspace, customer, conversation and workflow information is generally retained while the relevant account is active or as directed by the responsible business customer.
- Security, audit, support and transaction records may be retained after account closure where reasonably required to prevent fraud, establish legal claims, comply with law or resolve a dispute.
- When information is no longer required, we delete, destroy or de-identify it. Limited residual copies may remain temporarily in protected backups until those backups are overwritten in the ordinary cycle.
8. How we protect information
We use reasonable technical and organisational safeguards appropriate to the information and risk. These include access controls, authentication, encryption in transit, role-based permissions, tenant separation, logging, provider credential protection, backups and security monitoring. No internet service can guarantee absolute security, so users should also protect their accounts and promptly report suspected misuse.
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and make notifications to affected parties and the Information Regulator where required by POPIA.
9. Your privacy rights
Subject to applicable law, you may ask us to:
- confirm whether we hold personal information about you and provide access to it;
- correct or update inaccurate or incomplete information;
- delete or destroy information that we are no longer authorised or required to retain;
- object to certain processing or withdraw consent where processing is based on consent;
- stop direct marketing communications; or
- provide information about the identity of third parties that have had access to your information where the law requires this.
To protect you and other users, we may need to verify your identity and authority before completing a request. Where VNLA processes your information only on behalf of a business customer, we may refer the request to that business and assist it in responding.
10. Meta user-data and account deletion
You may request deletion of information received from Meta, WhatsApp or another VNLA interaction at any time. This public section also serves as VNLA’s user-data deletion instructions for Meta.
- Email support@vnla.co.za with the subject Meta data deletion request.
- Include your name, the telephone number or account identifier used with the Meta product, the VNLA workspace or business you interacted with, and a short description of the data you want deleted. Do not send a password, access token or one-time code.
- We will ask for only the information reasonably needed to verify your identity and locate the relevant records.
- After verification, we will delete or de-identify the information from active VNLA systems and instruct applicable service providers to do the same, unless retention is required by law, needed for security or legal claims, or requested by the responsible business customer on another lawful basis. We will explain any applicable exception.
We aim to acknowledge a valid deletion request within five business days and complete it within 30 days. If the request is complex, depends on a VNLA business customer, or law permits more time, we will keep you informed. We will confirm when the request has been completed.
Request deletionDirect link for Meta’s data-deletion instructions field: https://vnla.co.za/privacy_policy.html#data-deletion
11. Cookies and similar technology
Our website and platform may use cookies or browser storage that are necessary for security, session management, preferences and core service operation. We may also collect limited service analytics. We will not use non-essential advertising cookies without providing any notice or choice required by applicable law. You can control cookies through your browser, but blocking essential cookies may prevent parts of VNLA from working.
12. Direct marketing and children
We may send information about VNLA where you requested it, consented to it, or where applicable law otherwise permits it. You can opt out using the unsubscribe option in the message or by contacting us. Service and security messages are not marketing and may still be sent while you use VNLA.
VNLA is a business service and is not directed to children under 18. We do not knowingly invite children to create accounts or intentionally collect their personal information. If you believe a child has provided information to us, please contact us so that we can investigate and take appropriate action.
13. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The current version will remain publicly available at this URL and will show its effective date. If a change materially affects how we use personal information, we will provide additional notice where reasonably practicable or legally required.
14. Contact us or complain
For privacy questions, rights requests or complaints, contact:
VNLA Technologies (Pty) Ltd, trading as VNLA.co.za.
Registration number: 2026/608517/07
Clearwater Office Park, Building 3, Ground Floor
Millenium Road, Christiaan de Wet Road
Johannesburg, Gauteng, 1735, South Africa
Legal email: legal@vnla.co.za
Privacy and support email: support@vnla.co.za
General email: hello@vnla.co.za
Website: https://vnla.co.za
Application: https://app.vnla.co.za
Enquiries must be submitted by email.
Please contact us first so that we have an opportunity to resolve your concern. You may also lodge a POPIA complaint through the Information Regulator (South Africa) or email POPIAComplaints@inforegulator.org.za.