Start a project

Last updated 29 July 2026

1. Who we are

Kreonovo ("Kreonovo", "we", "us") builds system integrations, workflow automation and custom software. Our operations are based in South Africa and we work with clients internationally.

For the purposes of POPIA we are the responsible party for the personal information described here. Where the European or United Kingdom General Data Protection Regulation applies to you, we act as the controller of that information. You can reach us, including our information officer, at info@kreonovo.com.

2. What this policy covers

It covers this website and the enquiries that reach us through it, by email or by telephone.

It does not cover personal information we handle on behalf of a client while delivering a project. There the client decides how the information is used and we act as an operator, or processor, under a separate written agreement. Systems we integrate for a client stay subject to that client’s own privacy notices.

3. Information we collect

We collect only what we need to respond to you and run the site. That is:

  • Enquiry details you submit: your name, company name, email address, telephone number (optional), the service or project type you select, and the description you write.
  • Correspondence: the content of emails, calls, meetings and messages exchanged while we discuss a possible or active project.
  • Technical information recorded automatically by our hosting provider: IP address, browser and device type, the pages requested, the referring page, and the date and time of each request.

We do not ask for special personal information such as health, biometric, religious or racial information, and no payment card details are collected through this website.

4. Why we use it

  • To reply to your enquiry and discuss the work you are asking about. The details you enter in the enquiry form are used for nothing else.
  • To prepare proposals, estimates and agreements, and to deliver a project once it is agreed.
  • To keep records of business correspondence, quotations and contracts.
  • To keep the website available and secure, and to identify abuse such as automated form submissions.
  • To meet our legal, tax and accounting obligations.

Where the GDPR applies, we rely on your consent when you choose to submit the form, on the need to take steps at your request before entering into a contract, on our legitimate interest in running a secure website and a business, and on legal obligation where record keeping is required. You may withdraw consent at any time, which does not affect processing already carried out.

Enquiries are read by a person. We do not make decisions about you by automated means, and we do not use the content of your enquiry to train artificial intelligence models.

5. Marketing

We do not run newsletters or marketing campaigns from this website, and email addresses given in an enquiry are not added to a marketing list. If that ever changes you will be asked to opt in first, and you will be able to opt out again at any time.

6. Cookies and third-party content

This site sets no advertising, profiling or analytics cookies, and it embeds no social media tracking pixels. Any cookie we do set is strictly necessary for the site to work, such as protecting a form submission.

Pages load the Saira typeface from Google Fonts. That request reaches Google’s servers, which receive your IP address and browser details in order to return the font file, and is governed by Google’s own privacy policy.

If we introduce analytics or any other measurement later, this policy will be updated before it goes live and consent will be requested where the law requires it.

7. Who we share it with

We do not sell personal information and we do not share it for anyone else’s marketing.

  • Service providers who host this website, deliver our email and store our documents, under contracts that limit them to acting on our instructions.
  • Professional advisers such as accountants, auditors and attorneys, where they need it to advise us.
  • A regulator, court or law enforcement agency, where disclosure is legally required.
  • A purchaser or successor, if the business or part of it is ever transferred. You would be told, and this policy would continue to apply to information collected under it.

8. Information that leaves South Africa

Some of our providers store information outside South Africa, including in the European Union and the United States. Where personal information is transferred across a border we satisfy ourselves that section 72 of POPIA is met, normally because the provider is bound by contractual terms and by laws that give comparable protection. Where the GDPR applies, transfers rely on an adequacy decision or on the European Commission’s standard contractual clauses.

9. How long we keep it

  • Enquiries that do not lead to work: up to 24 months from our last contact, so we can pick up the conversation if you come back to us, and then deleted.
  • Client records, contracts and correspondence: for the length of the relationship and then for the period tax and company law require, currently five years.
  • Website and server logs: a short operational period, normally no more than 12 months.

Ask us to delete something sooner and we will, unless we are required to keep it or need it for a legal claim.

10. How we protect it

This website is served over an encrypted connection. Access to enquiry data is limited to the people who need it, the accounts holding it require multi-factor authentication, and access is reviewed when roles change.

No system is completely secure, so we cannot guarantee against every event. If a compromise affects your personal information we will notify you and the Information Regulator as POPIA requires.

11. Your rights

You can ask us to:

  • Confirm what personal information we hold about you and give you a copy of it.
  • Correct information that is inaccurate, misleading or incomplete.
  • Delete information we no longer have grounds to keep.
  • Stop processing that relies on legitimate interest, or act on consent you have withdrawn.
  • Restrict processing, or provide your information in a portable format, where the GDPR gives you that right.

Write to info@kreonovo.com and we will respond within a reasonable period, and in any event within 30 days. We may first ask you to confirm your identity so that information is not disclosed to the wrong person. There is no charge unless a request is repetitive or excessive.

A POPIA access request may be made on Form 2 of the POPIA regulations. If you are not satisfied with how we have handled a request you may complain to the Information Regulator of South Africa at inforegulator.org.za. Visitors in the European Union or the United Kingdom may also complain to their local supervisory authority.

12. Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect information about anyone under 18. If you believe a child has sent us personal information, tell us and we will delete it.

13. Changes to this policy

We may update this policy as our services, our providers or the law change. The current version is always on this page, and the date above shows when it last changed. Material changes will be described here.

14. Contact us

Questions, requests or complaints about privacy can go to info@kreonovo.com, or through the contact page. Operations based in South Africa — serving clients globally.

See also our Terms of Use, which govern your use of this website.