Gurrom Flow

Privacy Policy

Last updated: 27 July 2026  |  Gurrom (Pty) Ltd

At Gurrom (Pty) Ltd (“Gurrom”, “we”, “us”, or “our”), we are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Gurrom Flow messaging platform (“Service”). This policy is aligned with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African data protection legislation.

By registering for or using the Service, you acknowledge that you have read and understood this Privacy Policy.


1. Who We Are — Information Officer

The responsible party for the processing of your personal information is:

You may contact our Information Officer at the above email address for any privacy-related queries, access requests, or complaints.

2. Personal Information We Collect

We collect personal information that you provide directly to us and information generated through your use of the Service. This includes:

2.1 Account Registration Information

  • Full name (first name and surname)
  • Email address
  • South African mobile number
  • Password (stored using industry-standard security practices)
  • Company name and VAT registration number (optional)
  • Physical or postal address (optional)

2.2 Payment Information

  • Transaction amounts and credit purchase history
  • Payment reference numbers
  • We do not store your card details — all payment processing is handled by Payfast, our third-party payment processor.

2.3 Usage and Technical Information

  • SMS sending logs (recipient numbers, message timestamps, delivery status, credits used)
  • IP address and browser type when accessing the web platform
  • Login timestamps and session activity
  • API access logs where applicable

2.4 Recipient Data You Provide

When you send SMS messages through the Service, you submit mobile numbers of third-party recipients. You are the responsible party for this data. We process it solely on your instruction to deliver the messages and do not use it for any other purpose.

3. How We Use Your Personal Information

We process your personal information for the following lawful purposes:

  • Service delivery — to create and manage your account, process credit purchases, and send SMS messages on your behalf;
  • Billing and payments — to process transactions, issue invoices, and maintain financial records as required by law;
  • Security and fraud prevention — to verify your identity, detect and prevent unauthorised access, and protect the integrity of the Service;
  • Customer support — to respond to your queries, complaints, and support requests;
  • Service communications — to send you transactional notifications such as credit top-up confirmations, account activation emails, and OTP verification codes;
  • Legal compliance — to comply with our obligations under POPIA, WASPA regulations, the Electronic Communications Act, and other applicable laws; and
  • Service improvement — to analyse usage patterns and improve the functionality and performance of the Service.

We will not use your personal information for purposes incompatible with those listed above without obtaining your prior consent.

4. Legal Basis for Processing

We process your personal information on the following grounds under POPIA:

  • Contract performance — processing necessary to deliver the Service you have contracted for;
  • Legal obligation — processing required to comply with applicable laws and regulations;
  • Legitimate interest — processing for fraud prevention, network security, and service improvement where your interests do not override ours; and
  • Consent — for any marketing communications, which you may withdraw at any time.

5. Sharing Your Personal Information

We do not sell your personal information. We may share it with the following categories of third parties solely to the extent necessary for the purposes described in this policy:

5.1 Service Providers (Operators)

  • SMSPortal — our SMS delivery partner, which processes recipient numbers to route and deliver messages on our behalf;
  • Payfast — our payment gateway, which processes payment transactions. Payfast’s own privacy policy governs data processed through their platform; and
  • Microsoft Azure — our cloud hosting provider, which stores application data in data centres that may be located outside South Africa. We ensure appropriate safeguards are in place for any cross-border transfers.

5.2 Legal and Regulatory Authorities

We may disclose your information to law enforcement agencies, courts, or regulators where required by law or where we have a good-faith belief that disclosure is necessary to protect our rights or the safety of others.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, your information may be transferred to the successor entity, subject to the same privacy protections.

6. Cross-Border Transfers

Some of our service providers process data in countries outside South Africa. When we transfer personal information internationally, we take steps to ensure adequate protection is in place, in compliance with section 72 of POPIA, including entering into appropriate data transfer agreements or relying on equivalent legal mechanisms.

7. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including:

  • Account data — retained for the duration of your account and for a period of 5 years thereafter, as required for legal and financial record-keeping;
  • SMS logs — retained for 12 months from the date of the message for dispute resolution and compliance purposes; and
  • Payment records — retained for a minimum of 5 years as required by South African tax legislation.

When we no longer need your personal information, we will securely delete or anonymise it.

8. Security of Your Information

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

  • HTTPS encryption for all data transmitted to and from the Service;
  • Access controls limiting staff access to personal data on a need-to-know basis;
  • Regular security reviews of our systems and processes; and
  • Secure storage on Microsoft Azure infrastructure.

No method of electronic storage or transmission is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Regulator as required by POPIA.

9. Your Rights Under POPIA

As a data subject under POPIA, you have the following rights:

  • Right of access — you may request a copy of the personal information we hold about you;
  • Right to correction — you may request that we correct inaccurate or incomplete personal information;
  • Right to deletion — you may request the deletion of your personal information, subject to our legal retention obligations;
  • Right to object — you may object to the processing of your personal information on grounds of legitimate interest;
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing; and
  • Right to lodge a complaint — you may lodge a complaint with the Information Regulator of South Africa at www.justice.gov.za/inforeg.

To exercise any of these rights, please contact us at support@gurrom.co.za. We will respond within 30 days in accordance with POPIA.

10. Marketing Communications

We will only send you promotional communications if you have opted in to receive them. You may opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us directly. Opting out of marketing will not affect your receipt of transactional service communications.

11. Cookies and Tracking

The Gurrom Flow web platform uses session cookies strictly necessary for authentication and security. We do not use third-party advertising cookies or tracking pixels. You may configure your browser to refuse cookies, but this may affect the functionality of the Service.

12. Children’s Privacy

The Service is not intended for use by persons under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected such information, we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address or by a prominent notice on the platform at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the revised policy.

14. Contact Us

For privacy-related queries, access or deletion requests, or complaints, please contact our Information Officer:

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa.


© 2026 Gurrom (Pty) Ltd. All rights reserved.  |  Terms & Conditions

Loading...
In Progress...