This Privacy Policy explains how DeltaML Holdings Ltd (incorporated in Mauritius) and its operating subsidiary DeltaML (Pty) Ltd (incorporated in South Africa) — together “DeltaML”, “we”, “us”, or “our” — collect, use, share, and protect personal information. It applies to our website, our products and services, and our interactions with clients, prospective clients, suppliers, job applicants, and other individuals.
We are committed to protecting your privacy and process personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, and, where applicable to a client engagement, other relevant data protection laws in the jurisdictions we operate.
DeltaML provides a production-grade machine learning platform for time-series data, and related professional services to enterprise clients across capital markets, banking, mining and manufacturing, retail, healthcare, and industrial infrastructure.
DeltaML (Pty) Ltd (registration number 2025/241203/07) is registered in South Africa and carries out engineering, delivery, and support of our platform.
DeltaML Holdings Ltd (company number 238374) is registered in Mauritius as the group holding company and is the contracting entity for client engagements.
Both entities operate under common ownership and a single information security and privacy management system. References to “DeltaML” in this policy cover both entities unless otherwise stated.
Our Information Officer is:
Matthew Phillips
Information Officer, DeltaML
Email: matthew@deltaml.co.za
Depending on how you interact with us, we may collect:
We do not knowingly collect personal information from children without the consent of a competent person, and our services are not directed at children.
We use personal information to:
Client production data: client data is used solely to develop and operate models for that client. We do not, and do not permit any third party to, use client data to train, fine-tune, develop, validate, benchmark, or improve any DeltaML product, any shared model, or any model provided to any other party. Models derived from one client’s data are not reused across other clients or sectors. This restriction is given contractual effect in our Master Services Agreements.
Deployment model: our preferred production model is to deploy our platform inside a client’s own environment (on-premise, air-gapped, or within the client’s cloud tenancy), so that data, model training, and inference remain within the client’s own control. Under this model, DeltaML does not hold client production data. Where an engagement requires data to be processed on DeltaML infrastructure, that data is transferred via encrypted, authenticated channels and held in a dedicated environment segregated from all other client and internal workloads.
We process personal information only where a lawful basis under section 11 of POPIA applies, which may include:
We retain personal information only for as long as necessary for the purpose for which it was collected, or as required by applicable law, in accordance with our internal Data Retention and Disposal Schedule. As a general guide:
Personal information that is no longer needed is securely deleted or anonymised. Deletion procedures are documented and tested.
We may share personal information with:
We do not sell personal information. Where we act as an Operator processing personal information on behalf of a client, we act only on that client’s documented instructions and do not share that data with any other party except as the client authorises or as required by law.
DeltaML operates across multiple jurisdictions. DeltaML (Pty) Ltd is incorporated in South Africa and carries out engineering, delivery and support. DeltaML Holdings Ltd, our group holding company, is incorporated in Mauritius and is the contracting entity for client engagements. Personal information may therefore be processed in South Africa, in Mauritius, and in the locations of the service providers described in Section 7.
We comply with applicable privacy and data protection law in each jurisdiction in which we operate or process personal information, including the Protection of Personal Information Act, 2013 (South Africa) and the Data Protection Act 2017 (Mauritius), together with any further data protection law applicable to a specific client engagement.
Where personal information is transferred across borders, we disclose the contracting jurisdiction and the place of processing, and rely on a lawful basis under section 72 of POPIA (or the equivalent provision under the applicable law), which may include your consent, contractual necessity, adequate data protection law in the receiving jurisdiction, or recognised contractual safeguards, including model contractual clauses recommended by the relevant data protection authority.
Our website uses cookies and similar technologies for essential functionality (such as remembering preferences) and for analytics (to understand how visitors use our site). You can configure your browser to refuse cookies; some website features may not function correctly if you do.
We maintain technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, disclosure, alteration, and destruction. These measures include:
Our information security management system is documented and structured to ISO/IEC 27001, extended with AI-specific controls structured to ISO/IEC 42001. We do not currently hold ISO 27001 or SOC 2 Type II certification; independent certification is in progress. Our full information security policy and supporting evidence are available to clients under a non-disclosure agreement on request.
Subject to applicable law, you have the right to:
Information Regulator (South Africa)
Website: https://inforegulator.org.za
You may exercise any of these rights, free of charge, by contacting our Information Officer using the details in Section 2, or by any other manner reasonably expedient to you, including by hand, post, email, or SMS. Where a request is made telephonically, we will keep an electronic recording of the request and make it, or a transcription of it, available to you on request.
We will acknowledge requests within 7 working days. For requests to correct or delete personal information, we will advise you of the action taken within 30 days of receipt, in accordance with POPIA.
Where we wish to send you direct marketing communications and you are not an existing customer, we will first obtain your consent, in a manner that is free of charge and reasonably accessible to you, including by email, telephone, SMS, or WhatsApp. If consent is obtained telephonically, we will keep an electronic recording of that consent and make it, or a transcription of it, available to you on request.
Simply providing you with the means to opt out of marketing communications does not, on its own, constitute your consent to receive them; an opt-out mechanism is not a substitute for obtaining your affirmative consent in the first place. Once you have consented, you may withdraw that consent, or object to further direct marketing, at any time, free of charge, using the contact details in Section 2.
Our PAIA Manual, published in terms of section 51 of the Promotion of Access to Information Act, 2000, explains how you may request access to records we hold, and is available on request from our Information Officer or at https://deltaml.co.za.
We review this policy at least annually and whenever our practices or applicable law change materially. The current version is always available at https://deltaml.co.za/privacy. We encourage you to review it periodically.
For any question about this policy or how we handle personal information, contact:
Matthew Phillips, Information Officer, COO