DeltaML
Product How it works Engagement Team Book a demo
Legal

Privacy Policy

Effective date: 24 August 2026 · Version 1.1

This Privacy Policy explains how DeltaML Holdings Ltd (incorporated in Mauritius) and its operating subsidiary DeltaML (Pty) Ltd (incorporated in South Africa) — together “DeltaML”, “we”, “us”, or “our” — collect, use, share, and protect personal information. It applies to our website, our products and services, and our interactions with clients, prospective clients, suppliers, job applicants, and other individuals.

We are committed to protecting your privacy and process personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, and, where applicable to a client engagement, other relevant data protection laws in the jurisdictions we operate.

1. Who we are

DeltaML provides a production-grade machine learning platform for time-series data, and related professional services to enterprise clients across capital markets, banking, mining and manufacturing, retail, healthcare, and industrial infrastructure.

DeltaML (Pty) Ltd (registration number 2025/241203/07) is registered in South Africa and carries out engineering, delivery, and support of our platform.

DeltaML Holdings Ltd (company number 238374) is registered in Mauritius as the group holding company and is the contracting entity for client engagements.

Both entities operate under common ownership and a single information security and privacy management system. References to “DeltaML” in this policy cover both entities unless otherwise stated.

2. Our Information Officer

Our Information Officer is:

Matthew Phillips

Information Officer, DeltaML

Email: matthew@deltaml.co.za

3. Personal information we collect

Depending on how you interact with us, we may collect:

  • Contact and identity information you provide through our website, email, or in person (e.g. name, email address, phone number, job title, company).
  • Information you provide when enquiring about our services, requesting a proof of concept, or engaging us as a client.
  • Information from prospective and current employees, contractors, and consultants, including in connection with recruitment, onboarding, and background screening.
  • Technical information collected from website visits, such as IP address, browser type, and usage data via cookies and analytics (see Section 9).
  • Where we process personal information on behalf of a client as an Operator (POPIA) or Processor, the categories of personal information are set out in the relevant client agreement or Service Order, not in this public policy.

We do not knowingly collect personal information from children without the consent of a competent person, and our services are not directed at children.

4. Why we collect and use it

We use personal information to:

  • Respond to enquiries and provide requested information about our services.
  • Deliver, support, and improve our services to clients under signed agreements.
  • Manage our business relationships with clients, suppliers, and prospective hires.
  • Meet legal, regulatory, tax, and contractual obligations.
  • Maintain the security of our systems and information, including fraud prevention and audit.
  • Improve our website and communications.

Client production data: client data is used solely to develop and operate models for that client. We do not, and do not permit any third party to, use client data to train, fine-tune, develop, validate, benchmark, or improve any DeltaML product, any shared model, or any model provided to any other party. Models derived from one client’s data are not reused across other clients or sectors. This restriction is given contractual effect in our Master Services Agreements.

Deployment model: our preferred production model is to deploy our platform inside a client’s own environment (on-premise, air-gapped, or within the client’s cloud tenancy), so that data, model training, and inference remain within the client’s own control. Under this model, DeltaML does not hold client production data. Where an engagement requires data to be processed on DeltaML infrastructure, that data is transferred via encrypted, authenticated channels and held in a dedicated environment segregated from all other client and internal workloads.

5. Lawful basis for processing

We process personal information only where a lawful basis under section 11 of POPIA applies, which may include:

  • Your consent;
  • Performance of, or steps preliminary to, a contract to which you are a party;
  • Compliance with a legal obligation;
  • Protection of a legitimate interest of yours; or
  • Pursuit of our legitimate interests, provided this is balanced against your rights and interests.

6. How long we keep it

We retain personal information only for as long as necessary for the purpose for which it was collected, or as required by applicable law, in accordance with our internal Data Retention and Disposal Schedule. As a general guide:

  • Enquiry and marketing contact details are kept until you ask us to stop, or up to a reasonable period of inactivity.
  • Client and supplier relationship records are kept for the duration of the relationship and a defined period afterward to meet legal and contractual requirements.
  • Employee and contractor records are kept for the duration of the engagement and a defined statutory period afterward.
  • Client data processed as part of a service engagement is retained only for the duration of that engagement and the purpose for which it was provided. On termination, or earlier on written instruction, all client data and derived artefacts — including copies and backups — are returned or securely destroyed within 30 days, with written certification of destruction provided on request.

Personal information that is no longer needed is securely deleted or anonymised. Deletion procedures are documented and tested.

7. Who we share it with

We may share personal information with:

  • Our service providers (such as cloud infrastructure, productivity, identity, and analytics providers), under written agreements that require them to protect the information and use it only for the purposes we specify.
  • Professional advisors (legal, audit, tax) where necessary.
  • Regulators or authorities where required by law.
  • A prospective acquirer or successor entity, in the event of a corporate transaction, subject to appropriate confidentiality safeguards.

We do not sell personal information. Where we act as an Operator processing personal information on behalf of a client, we act only on that client’s documented instructions and do not share that data with any other party except as the client authorises or as required by law.

8. Cross-border transfers

DeltaML operates across multiple jurisdictions. DeltaML (Pty) Ltd is incorporated in South Africa and carries out engineering, delivery and support. DeltaML Holdings Ltd, our group holding company, is incorporated in Mauritius and is the contracting entity for client engagements. Personal information may therefore be processed in South Africa, in Mauritius, and in the locations of the service providers described in Section 7.

We comply with applicable privacy and data protection law in each jurisdiction in which we operate or process personal information, including the Protection of Personal Information Act, 2013 (South Africa) and the Data Protection Act 2017 (Mauritius), together with any further data protection law applicable to a specific client engagement.

Where personal information is transferred across borders, we disclose the contracting jurisdiction and the place of processing, and rely on a lawful basis under section 72 of POPIA (or the equivalent provision under the applicable law), which may include your consent, contractual necessity, adequate data protection law in the receiving jurisdiction, or recognised contractual safeguards, including model contractual clauses recommended by the relevant data protection authority.

9. Cookies and analytics

Our website uses cookies and similar technologies for essential functionality (such as remembering preferences) and for analytics (to understand how visitors use our site). You can configure your browser to refuse cookies; some website features may not function correctly if you do.

10. Security of your information

We maintain technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, disclosure, alteration, and destruction. These measures include:

  • Encryption at rest using AES-256 across our data stores, and encryption in transit using TLS 1.2 as a minimum (TLS 1.3 preferred).
  • Multi-factor authentication enforced across all systems, including cloud consoles, source control, email, and remote access.
  • Role-based, least-privilege access, with privileged access separately approved and logged.
  • A fully managed corporate device fleet with full-disk encryption, enforced patch baselines, and remote-wipe capability.
  • Centrally collected security logs, retained for at least 12 months, with monitoring and alerting on anomalous activity.
  • Annual security awareness training for all personnel, with additional targeted training for engineering staff.

Our information security management system is documented and structured to ISO/IEC 27001, extended with AI-specific controls structured to ISO/IEC 42001. We do not currently hold ISO 27001 or SOC 2 Type II certification; independent certification is in progress. Our full information security policy and supporting evidence are available to clients under a non-disclosure agreement on request.

11. Your rights

Subject to applicable law, you have the right to:

  • Confirm, free of charge, whether we hold personal information about you.
  • Request access to the personal information we hold about you.
  • Request correction, updating, or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
  • Object, on reasonable grounds, to the processing of your personal information.
  • Withdraw any consent you have given, at any time, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with the Information Regulator of South Africa if you believe your rights have been infringed.

Information Regulator (South Africa)

Website: https://inforegulator.org.za

You may exercise any of these rights, free of charge, by contacting our Information Officer using the details in Section 2, or by any other manner reasonably expedient to you, including by hand, post, email, or SMS. Where a request is made telephonically, we will keep an electronic recording of the request and make it, or a transcription of it, available to you on request.

We will acknowledge requests within 7 working days. For requests to correct or delete personal information, we will advise you of the action taken within 30 days of receipt, in accordance with POPIA.

12. Direct marketing

Where we wish to send you direct marketing communications and you are not an existing customer, we will first obtain your consent, in a manner that is free of charge and reasonably accessible to you, including by email, telephone, SMS, or WhatsApp. If consent is obtained telephonically, we will keep an electronic recording of that consent and make it, or a transcription of it, available to you on request.

Simply providing you with the means to opt out of marketing communications does not, on its own, constitute your consent to receive them; an opt-out mechanism is not a substitute for obtaining your affirmative consent in the first place. Once you have consented, you may withdraw that consent, or object to further direct marketing, at any time, free of charge, using the contact details in Section 2.

13. Access to information (PAIA)

Our PAIA Manual, published in terms of section 51 of the Promotion of Access to Information Act, 2000, explains how you may request access to records we hold, and is available on request from our Information Officer or at https://deltaml.co.za.

14. Changes to this policy

We review this policy at least annually and whenever our practices or applicable law change materially. The current version is always available at https://deltaml.co.za/privacy. We encourage you to review it periodically.

15. Contact us

For any question about this policy or how we handle personal information, contact:

Matthew Phillips, Information Officer, COO

matthew@deltaml.co.za

DeltaML Holdings Ltd (Mauritius, company no. 238374) and DeltaML (Pty) Ltd (South Africa, reg. no. 2025/241203/07)  |  Version 1.1  |  Owner: Information Officer  |  Effective date: 24 August 2026  |  Next review: 24 August 2027
DeltaML
DeltaCore — a unified Python platform for production-grade time-series machine learning.
Product
  • Connectors
  • Documentation
Company
  • Team
  • Engagement
  • Contact
  • Careers
Information
  • Privacy Policy
  • Terms of Service
  • LinkedIn
© DeltaML · All rights reservedCape Town · ZA