Legal

Privacy policy

Last updated

Send to Site is run by Raimond AI (Pty) Ltd, the responsible party for your personal information under the Protection of Personal Information Act (POPIA). We collect what you give us through our enquiry form, by email or as a client, and use it to answer you, prepare your free website audit and run your website. This website sets no cookies of its own and carries no advertising trackers, and you can ask to see, correct or delete your information at any time, free of charge.

Who is responsible for your information

Raimond AI (Pty) Ltd is the responsible party for your personal information: it decides why and how the information is used. Send to Site is a service of Raimond AI (Pty) Ltd, a private company registered in South Africa under registration number 2025/964604/07.

  • Address: 22 Ashwold Road, Saxonwold, Johannesburg, Gauteng, 2196, South Africa
  • Information Officer: Arno van der Walt, Chief Executive Officer (CEO), [email protected], +27 82 859 3966

Send any privacy question, request or complaint to our Information Officer. A person reads every message.

Who this policy covers

This policy covers anyone whose personal information we handle for Send to Site: visitors to sendtosite.com, people who send us an enquiry or ask for a free website audit, our clients and the people a client authorises to email us, and people who sign up for our occasional emails.

POPIA protects information about businesses as well as people, so this policy also covers information about your company.

The content of a client's website is different. When we rebuild and look after your website, the personal information on it and in the emails and attachments you send us to change it (for example, staff names and photos, or customer reviews) belongs to your business. For that information your business is the responsible party, and we process it on your behalf as your operator, on the terms set out in our terms of service.

What we collect and where it comes from

We collect the information you give us, the technical details every web request carries, and public information about your website; nothing is bought from data brokers.

When you visit this website

Cloudflare, which delivers our pages, receives the technical details that every browser sends with a request: your internet (IP) address, browser type, the page asked for and the time. It uses them to deliver the page and to protect the site from attacks. If we switch on Cloudflare Web Analytics, it counts page views without cookies and without tracking you from visit to visit.

When you use our enquiry or free audit form

The form asks for:

  • your name and email address;
  • your website address;
  • your phone or WhatsApp number (optional);
  • a message or question (optional on the audit form);
  • whether you ticked the box to receive occasional news (it starts unticked).

We also record the date and time you sent it and the country your connection came from, which Cloudflare works out from your internet address. All of this comes from you.

When you ask for a free website audit

To prepare the audit we also look at public information about your website: its pages, speed test results and how it appears in search, which we get from DataForSEO, a search data provider. This is information about your website rather than about you personally, but it relates to your business, so we list it here. Its sources are your public website, speed tests and DataForSEO.

When you phone, email or WhatsApp us

We receive whatever you choose to tell us, along with your number or email address. WhatsApp messages travel through WhatsApp's own service, under WhatsApp's terms.

When you are a client

  • Contact and billing details for your business and the people you name as contacts.
  • The email addresses you authorise to send changes, and the names that come with them.
  • Your emails to [email protected], including attachments such as photos, PDFs and Word documents, and your replies to previews and articles.
  • Your website's content and files, and the history of every change and article: what was asked, what was changed and who approved it.

This information comes from you, from the people you authorise, and from your existing website.

What we do not collect

We do not ask for special personal information, such as health, religion or biometric details, and we ask you not to send it. The service will not put South African ID numbers, card numbers or bank account numbers on a website, even if an email asks it to.

Why we use it

We use personal information only to answer you, to provide the service you signed up for, to run our business lawfully and, if you agree, to send you occasional news. Each use rests on a ground that section 11 of POPIA allows:

  • To answer your enquiry and prepare your free audit, including a call about the audit if you gave us a number. This is a step you asked us to take before any agreement.
  • To provide the service: to rebuild and host your website, make the changes you email, write the articles you approve or decline, and send you previews. This is needed to carry out our agreement with you.
  • To invoice you and keep accounting records. This is needed for our agreement and required by law.
  • To keep the website and service secure, for example by filtering spam from the form and checking that a change request really comes from an authorised address. This is in our legitimate interest and yours.
  • To send you occasional news, only if you ticked the box or otherwise said yes. This rests on your consent.

The service uses artificial intelligence (AI) models to read change requests and to draft changes and articles. No decision about you is made by a machine alone: every change and article waits for a person, you, to approve it.

What you must give us, and what is optional

Giving us personal information is voluntary, but some of it is needed before we can help you. On the enquiry form, your name and email address are required, together with your website address for a free audit, or your question on the contact form. Without them we cannot reply to you or prepare the audit.

Your phone or WhatsApp number, a message and the news box are optional. Leave them out and nothing changes, except that we cannot call you or send you news.

If you become a client, we need a contact name, at least one email address that may send changes, and billing details. Without them we cannot provide the service or invoice you.

Laws that require us to collect information

No law requires you to give us personal information to make an enquiry. If you become a client, tax and company law require us to keep invoices and accounting records, including the names and details on them: the Tax Administration Act 28 of 2011 and the Companies Act 71 of 2008.

Who we share it with

We share personal information only with the people and service providers who need it to do the work described here, and we do not sell or rent it to anyone.

  • Our own team. Enquiries go by email to our sales team and to our CEO.
  • Cloudflare, Inc. (United States). Hosts this website and our clients' websites on Cloudflare Pages, runs the enquiry form, keeps a log copy of each form submission so that an enquiry is not lost if an email fails, and runs Cloudflare Web Analytics if it is switched on.
  • Postmark, run by ActiveCampaign (United States). Delivers our email: your enquiry to our sales team, and the service's acknowledgements, previews and articles to clients.
  • GitHub, Inc. (United States). Stores each client website's files and change history.
  • z.ai. Provides the AI models that read change requests and help prepare changes and articles.
  • DataForSEO OÜ (Estonia). Provides the search data used in free audits and to choose article topics. It receives website addresses and search terms, not your contact details.
  • Professional advisers and authorities. Our accountants, auditors and lawyers when they need it, and the South African Revenue Service (SARS) or another authority when the law requires it.

When you approve a change or an article, it is published on your website, where anyone can read it. That is the point of the service, and it is why nothing is published without your approval.

Information sent outside South Africa

Some of your information is stored or processed outside South Africa, because several of the providers above run their services abroad. Cloudflare, Postmark and GitHub are based in the United States and Cloudflare runs a global network, DataForSEO is based in Estonia, and z.ai may process data outside South Africa.

Section 72 of POPIA allows these transfers when they are needed to carry out our agreement with you, or to take steps you asked for before one, such as answering your enquiry. The protection in place:

  • each provider handles the information only to provide its service to us, under terms that require it to keep the information secure and confidential;
  • we send each provider only what its task needs: DataForSEO, for example, never receives your name or contact details;
  • before an AI model reads a change request, the service removes the quoted text of earlier emails, so the model sees only the new request.

How long we keep it

We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires, and then delete it.

  • Enquiries and free audits that do not lead to an agreement: up to 12 months after our last contact with you.
  • Client records: for as long as you are a client. When your plan ends and we have handed over your website's files, we delete our copies of your website, your change emails and the change history within 90 days, unless you ask us to delete them sooner or the law requires us to keep something.
  • Invoices and accounting records: for as long as tax and company law require, which is currently up to seven years.
  • Our news list: until you unsubscribe. We keep a note that you unsubscribed, so that we do not email you again by mistake.

How we protect it

We protect personal information with technical and organisational measures that fit the risk, as section 19 of POPIA requires:

  • This website and the websites we build are static: there is no database behind the pages and no login page to break into. Pages are served over encrypted connections (HTTPS).
  • Only email addresses a client authorises can ask for changes, and each request is checked to be really from that address.
  • Every change is built on a copy of the website, tested automatically, checked by a separate reviewer that can only read it, and published only when the client approves it. Every change is kept in version history, so it can be undone.
  • The service will not publish South African ID numbers, card numbers or bank account numbers, and it removes quoted email text before an AI model reads a request.
  • Access to client websites and records is limited to the people and systems that need it to do the work.

If we have reasonable grounds to believe that someone has accessed your personal information without authority, we will tell the Information Regulator and you as soon as reasonably possible, as section 22 of POPIA requires.

Marketing emails

We send marketing emails only to people who have said yes, for example by ticking the news box on our form, which always starts unticked. An unticked box, silence or a failure to opt out is never treated as consent; the amended POPIA Regulations (regulation 6.4) are clear that an opt-out is not consent.

Every marketing email says it comes from Send to Site and includes a way to unsubscribe, free of charge, and we act on it. As section 69 of POPIA allows, we may also email existing clients about our own similar services, and you can opt out of those emails in the same way at any time.

Cookies and analytics

This website does not set cookies. It has no advertising or social media trackers, and the enquiry form works without them.

Cloudflare, which delivers the site, may occasionally set a strictly necessary security cookie of its own, for example when it needs to check that a visitor is not a bot. Cloudflare states that these cookies are not used to track people from site to site. If we switch on Cloudflare Web Analytics, it counts visits without cookies or any other stored identifier.

The websites we rebuild for clients keep the analytics their owners already used. Each client's own privacy policy covers those.

Your rights

You have the right to find out what personal information we hold about you, to have it corrected or deleted, and to object to how we use it. In detail, you may:

  • Ask whether we hold information about you, free of charge, and ask for a copy or a description of it (POPIA section 23). We will ask you to prove who you are first. If the Promotion of Access to Information Act allows a fee for a copy, we will give you a written estimate before doing the work.
  • Ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, or to destroy information we are no longer allowed to keep (section 24). This is free, and we will tell you in writing what we have done within 30 days.
  • Object on reasonable grounds to our using your information where we rely on our legitimate interests, and object to direct marketing at any time (section 11(3)). Once you object, we stop.
  • Withdraw your consent at any time, for example to our news emails. Withdrawing does not affect what we did lawfully before.

To use any of these rights, email our Information Officer at [email protected], phone or WhatsApp +27 82 859 3966, or write to 22 Ashwold Road, Saxonwold, Johannesburg, Gauteng, 2196, South Africa. You may use Form 1 (objection) or Form 2 (correction or deletion) from the POPIA Regulations, available on the Information Regulator's website, but a plain message with the same details is just as good.

If your information appears on a client's website, that client is responsible for it. Contact the business first; we will help it answer you.

Complaints to the Information Regulator

You have the right to complain to the Information Regulator if you believe we have handled your personal information unlawfully. We would like the chance to put things right, so please tell us first, but you do not have to.

We checked these contact details on the Information Regulator's website on 29 September 2026.

Children

Send to Site is a service for businesses, so we do not knowingly collect personal information about children, meaning anyone under 18. If you believe a child has sent us personal information, tell us and we will delete it. If a client's website contains information about children, the client is responsible for having the right to publish it.

Changes to this policy

We update this policy when the way we handle personal information changes, and the date at the top of the page always shows the latest version. If a change affects how we use information we already hold about you, we will tell you by email before it takes effect.

Our terms of service and company information are on their own pages.