NoteWaveNoteWaveHelp Center
Home
Updated Jul 18, 2026|4 min read

Privacy Rights & Compliance

Our privacy commitments, data-subject rights, and service-provider safeguards.

Introduction

NoteWave is a South African service committed to handling personal information in accordance with POPIA and other privacy laws that apply to a user or processing activity. This guide summarises practical rights and safeguards; the Privacy Policy is the controlling source for full details.

Privacy Regulations We Are Committed To

The rights and obligations that apply depend on location, the type of information, and the reason it is processed.

GDPR (EU/UK)

We aim to align with the General Data Protection Regulation for users in the European Union and United Kingdom.

  • • Right to access your data
  • • Right to erasure ("right to be forgotten")
  • • Data portability
  • • Rights and breach duties where the GDPR applies
POPIA (South Africa)

We are committed to compliance with the Protection of Personal Information Act for South African users.

  • • Privacy contact designated
  • • Data subject access requests
  • • Processing limitations
  • • Security safeguards
CCPA/CPRA (California)

We aim to honour the rights of California residents under the California Consumer Privacy Act.

  • • Right to know what data we collect
  • • Right to delete personal information
  • • We don't sell your data
  • • Non-discrimination rights

Service-Provider Assurance

NoteWave uses specialist service providers for infrastructure, processing, communications, billing, and native-app purchases. Individual providers may maintain independent certifications or payment-industry controls relevant to their service.

How provider assurance helps:

  • Managed infrastructure - Provides independently assessed security and availability controls
  • Secure content delivery - Protects delivery of the customer-facing application
  • Payment services - Handle secure payment information and applicable payment-industry controls
  • App stores - Apply their own purchase, receipt, and subscription safeguards for native subscriptions
Important Distinction
A certification held by a service provider applies to that provider and its assessed controls. It does not mean NoteWave itself claims the same certification. Contact us if your organisation needs current assurance or subprocessor information.

International Data Transfers

Personal information may be processed outside South Africa or outside your own country when NoteWave's service providers support the product from other jurisdictions.

Safeguards for EU/EEA/UK data:

  • Contractual, organisational, and technical safeguards are used where applicable law requires them
  • Only information reasonably needed for the service should be processed
  • Subprocessor information can be requested where appropriate

For questions about international data transfers, contact us at contact@blazesolutions.ai.

Your Privacy Rights

Depending on your location and applicable law, you may have some or all of the following rights:

  • Access - Request a copy of your personal data
  • Rectification - Correct inaccurate or incomplete data
  • Erasure - Delete your personal data (with certain exceptions)
  • Portability - Export your data in a machine-readable format
  • Object - Object to processing for direct marketing
  • Restrict - Limit how we use your data
  • Withdraw Consent - Withdraw consent at any time

To exercise a privacy right, email contact@blazesolutions.ai with the request type and account email. We will verify the request and respond within the period required by applicable law.

Specialist AI Processing

Your audio recordings are processed by third-party AI services to generate transcripts and summaries.

Purpose-Limited Processing
NoteWave's policy is that customer meeting content should not be used to train unrelated general-purpose AI models for other customers. Provider settings, data-processing terms, access controls, and vendor reviews support that policy where available.

Supervisory Authorities

You have the right to lodge a complaint with your local data protection authority if you believe your privacy rights have been violated.

EU/EEA Residents

Contact your local Data Protection Authority or the European Data Protection Board.

South African Residents

Contact the Information Regulator of South Africa (POPIA).

Was this article helpful?

Your feedback helps us improve our documentation.