SENSEFRAME
SenseFrame legal

Privacy Policy

Schedule E of the SenseFrame Terms of Service. The full Agreement is shown, opened at Schedule E.

Effective 5 October 2026Version 2026-10-05Permanent link to this version

SenseFrame Terms of Service

Effective date: 5 October 2026 Governing law: Republic of South Africa

Contracting entity (SenseFrame):

  • SenseFrame (Pty) Ltd (Registration number: 2025/968958/07)

  • Registered office (domicilium): 21 Tecoma Street, Berea, East London, Eastern Cape, 5214, South Africa

  • Principal place of business: 13 Valley Cul De Sac, Gordon's Bay, 7140, Western Cape, South Africa

  • Legal notices and contractual enquiries: legal@senseframe.ai

  • Support enquiries: support@senseframe.ai

Customer:

  • The organisation that accepts this Agreement through an authorised administrator. Customer’s legal name, notice email and physical address are those recorded in its Account or applicable checkout/Order Form.

IMPORTANT NOTICE (Consumer Protection Act): This Agreement contains provisions that limit SenseFrame’s liability, allocate risk to you, or require you to indemnify SenseFrame. These include the professional‑use and AI disclaimer in clause 11 and the risk and liability provisions in clause 14. Please read them carefully before accepting.

1. Introduction, scope and acceptance

1.1 Nature of this Agreement. This is a single, plain‑English contract for SenseFrame’s subscription services. It combines the master subscription terms, service levels (SLA) and the Acceptable & Fair Use Policy in one document. Schedules form part of this Agreement: (a) Schedule A: POPIA Operator (Data Processing) Annexure; (b) Schedule B: Security Measures (technical and organisational safeguards); (c) Schedule C: Subprocessor Register; (d) Schedule D: Cookie Policy; and (e) Schedule E: Privacy Policy.

1.2 Acceptance and authority. An authorised administrator accepts this Agreement on behalf of Customer: (a) by creating an Account and selecting “I agree” (or similar) during signup; or (b) by signing an Order Form that incorporates this Agreement. By accepting, you confirm you are authorised to bind the Customer, and that Users will comply with this Agreement.

1.3 Electronic transactions. The parties agree this Agreement and any Order Form may be concluded electronically. SenseFrame may keep electronic records of acceptance and transactions (timestamps, user identifiers, versions) consistent with South African law, including the Electronic Communications and Transactions Act, 25 of 2002 (ECTA). An advanced electronic signature is not required unless mandated by law.

1.4 Order of precedence. If there is a conflict: (a) any specifically negotiated enterprise agreement or Order Form (if any); (b) Schedule A (POPIA Operator Annexure) for personal‑information processing matters; (c) this main Agreement body (including the SLA and Acceptable & Fair Use in clauses 9 and 12); (d) the Schedules (B to D); and (e) other referenced online documentation (for clarity or examples).

1.5 Who this Agreement is for. SenseFrame’s platform is designed primarily for attorneys, advocates, law firms, legal departments, government institutions and other professional users in South Africa. You must be at least 18 years old and legally capable of contracting.

2. Definitions and interpretation

2.1 Definitions. In this Agreement: (a) Account means the account(s) created to access the Services. (b) Customer Content means all content, data, documents, matter information, templates, prompts, instructions, metadata and other material uploaded to or generated in the Services by or for Customer, including personal information. (c) Fees means the amounts payable for the Services as shown at checkout, on the pricing page or in an Order Form. (d) Order Form means an order or checkout record describing plan, seats, term and pricing (if applicable for enterprise). (e) Policies means the publicly posted Privacy Policy and any other policy expressly incorporated by reference. (f) Privacy Policy means SenseFrame’s privacy policy incorporated herein as Schedule E. (g) Services means SenseFrame’s AI‑powered legal intelligence and legal‑work platform and related services provided under this Agreement. (h) Subprocessor means a third party engaged by SenseFrame to process personal information in connection with the Services. (i) Trial means the free trial period described in clause 4. (j) User means an individual authorised by Customer to access and use the Services under Customer’s Account.

2.2 Interpretation. Headings are for convenience only. Words in the singular include the plural and vice versa. “Including” means “including without limitation”. References to legislation include amendments and subordinate legislation. If the Consumer Protection Act, 68 of 2008 (CPA) applies, this Agreement is interpreted to give effect to consumer rights.

3. Services and accounts

3.1 What we provide. SenseFrame provides an AI‑assisted legal‑work platform enabling Customers to: (a) establish individual or organisational workspaces; (b) create and manage legal matters; (c) upload documents, correspondence, evidence and other matter artefacts; (d) organise legal authorities, templates and knowledge; (e) ask questions about uploaded content and relevant law and conduct legal research; (f) generate, edit and manage legal drafts; (g) collaborate with authorised team members; and (h) manage firm profiles, user permissions and matter‑level access.

3.2 Changes. We may improve or update features. We will not materially reduce core paid functionality during a committed pre‑paid monthly period without a reasonable remedy (e.g., an alternative, an equitable adjustment, or pro‑rata credit/refund as appropriate).

3.3 Security of accounts. Customer is responsible for safeguarding Account credentials and all activity under its Accounts, managing permissions and Users, and promptly notifying SenseFrame of any unauthorised access or use.

3.4 Eligibility. The Services are not intended for persons under 18.

4. Free trial (14 days; max 5 users)

4.1 Trial period.

i) Your free trial starts when you create your SenseFrame account and lasts 14 days.

ii) No payment details are needed to start a trial. Your trial will not become a paid subscription unless a Firm Administrator explicitly activates their paid plan and provides a valid payment card. If that does not happen, your access ends when the trial ends and you will not be charged.

iii) During the trial, use is limited to 5 users and a reduced usage allowance. A Firm Administrator may end the trial early and start the paid subscription immediately.

4.2 Features and limits. Trials may include reduced features, storage or usage limits and limited support. We may suspend or end a trial where necessary to prevent abuse, unlawful conduct, a security risk or breach of this Agreement.

4.3 No automatic conversion. The trial does not automatically convert into a paid subscription. Billing only begins if Customer actively selects a paid plan and provides the required payment authorisation.

4.4 End of trial. If Customer does not subscribe by the end of the 14‑day trial, access may end or be limited. Export options during trial are subject to available tooling and reasonable technical limits.

5. Subscriptions, seats and plans

5.1 Month‑to‑month subscriptions. Subscriptions are month‑to‑month and billed monthly in advance unless otherwise stated at checkout or in an Order Form.

5.2 Seats (Users). Paid plans are typically billed per User (seat). Administrators may add Users at any time. Additional seats may be pro‑rated for the current billing period with new recurring Fees from the next billing cycle. Reducing seat counts usually takes effect at the next renewal unless otherwise agreed.

5.3 Plan inclusions. Plan tiers, inclusions and limits are shown on the pricing page or at checkout and form part of this Agreement.

5.4 Usage compliance. Customer must remain within plan and technical limits. Systematic extraction or scraping of outputs or platform elements is prohibited (see clause 9).

6. Fees, taxes, billing and price changes

6.1 Fees and currency.

i) Fees reflected on our website, the order form or pricing page exclude Value Added Tax (if applicable) from time to time. Fees shown at checkout are charged in South African Rand unless stated otherwise, and VAT charged (if applicable) will be reflected.

ii) Subscription fees are charged per user per month at the rate for your firm's size. Your monthly fee will never be more than the fee payable at the next pricing tier, so reducing the number of users will never increase your monthly fee.

iii) Legal Assistant and Admin Assistant users are not charged. Users added during a billing month are charged pro rata for the rest of that month.

iv) Reductions take effect from the next renewal date, and no credit is given for the current month.

6.2 Taxes (including VAT). Applicable taxes (including VAT) will be charged as required by law. For consumer‑facing checkout, prices shown include VAT; for invoiced B2B orders, prices are exclusive of VAT and VAT will be added is applicable.

6.3 Billing and payment.

(a) Recurring billing.

i) By purchasing a subscription, Customer authorises SenseFrame (or its payment processor) to charge the Fees for the initial month and each renewal month using the payment method provided.

ii) Payments are processed by our payment service provider, currently Paystack, on its own secure payment page. SenseFrame does not receive or store your full card details. By adding a card you authorise SenseFrame, through Paystack, to charge the applicable subscription fees to that card on each renewal date until your subscription is cancelled. When you add a card, Paystack makes a verification charge of R1.00, which is refunded automatically.

iii) Fees are charged monthly in advance on the anniversary of the date your paid subscription started. If a payment fails, we will notify you and retry the payment during a 7-day grace period, during which you keep full access. If payment has not been received by the end of the grace period, your access will be suspended until payment is made. There is no fee to restore access.

(b) Invoices (if agreed). If invoiced billing is agreed, invoices are due within 30 days from the invoice date unless otherwise stated.

(c) Failed payments. If a charge is declined or an invoice is overdue, we may notify Customer and allow a 7 day grace period. If not remedied, we may suspend or limit access until payment is received.

6.4 Price changes. We may change Fees for future renewals on reasonable advance notice. Changes do not apply retrospectively to a month already prepaid and take effect at the next renewal unless otherwise agreed.

6.5 Refunds.

i) Unless required by law or expressly stated, Fees are non‑refundable.

ii) No refund or credit is given for part of a month, including where you cancel or reduce the number of users during a billing month. SenseFrame may agree to a refund in a particular case at its discretion; any refund will be made to the original payment method through our payment provider.

iii) If SenseFrame terminates prepaid Services without Customer fault or fails to provide material prepaid Services, SenseFrame will provide a pro‑rata refund for the unused prepaid period. Nothing in this clause limits mandatory consumer rights under the CPA where applicable.

7. Renewal and cancellation

7.1 Auto‑renewal.

i) Your subscription runs month to month and renews automatically unless cancelled. There is no minimum term and no cancellation fee.

ii) A Firm Administrator may cancel at any time from the Billing page.

iii) Cancellation takes effect at the end of the current billing month; you keep full access until then and will not be charged again. You may withdraw a cancellation before it takes effect. After cancellation takes effect, your account becomes read-only: you can view and download your existing content, but cannot create new content.

7.2 How to cancel. You may cancel at any time via in‑app billing settings or by the method stated at checkout or in an Order Form. Cancellation takes effect at the end of the current billing month; access continues until that date.

7.3 CPA rights (if applicable). Where the CPA applies and the subscription qualifies as a fixed‑term consumer agreement (not typical for month‑to‑month), statutory renewal and cancellation rights will be observed.

8. Intellectual property, content and outputs

8.1 SenseFrame IP. SenseFrame owns all rights in and to the Services, including software, platforms, interfaces, workflows, models, systems, documentation and branding. No rights are granted except as expressly stated.

8.2 Customer Content. As between the parties, Customer retains ownership of Customer Content. Customer grants SenseFrame a limited, non‑exclusive, worldwide, royalty‑free licence for the duration of the Agreement to host, store, copy, process, transmit and use Customer Content solely as necessary to provide, maintain, secure, support and improve the Services in accordance with this Agreement, Schedule A and the Privacy Policy.

8.3 Confidentiality. We treat Customer Content as confidential and will not access or disclose it except to provide, support, secure or maintain the Services; to comply with law or a binding order (with prior notice where legally permitted); or with Customer’s consent. Our personnel and subprocessors are subject to confidentiality obligations.

8.4 Subscription licence. Subject to this Agreement and payment of Fees, SenseFrame grants Customer a non‑exclusive, non‑transferable, non‑sublicensable, limited licence for its Users to access and use the Services during the subscription term for Customer’s internal professional purposes.

8.5 Outputs. Subject to applicable law and third‑party rights: (a) SenseFrame assigns to Customer any intellectual‑property rights SenseFrame may have in the original text outputs generated for Customer by the Services, to the extent legally possible; and (b) to the extent not assignable, SenseFrame grants Customer a non‑exclusive, worldwide, royalty‑free licence to use, reproduce and adapt such outputs for Customer’s lawful business purposes. Outputs may not be unique and may include or reflect third‑party content or public legal materials subject to their own rights and restrictions. Customer is responsible for reviewing outputs and ensuring lawful use.

8.6 Restrictions. Customer must not (and must not permit others to) copy, modify, create derivative works of, distribute, sell, lease or transfer the Services; reverse engineer except where legally permitted; or remove, obscure or alter proprietary notices.

8.7 Feedback. We may use feedback or suggestions without restriction. Customer assigns any rights it may have in feedback to SenseFrame without obligation.

9. Acceptable & fair use (integrated AUP)

9.1 Prohibited conduct. Customer and Users must not: (a) use the Services unlawfully or fraudulently; infringe privacy, confidentiality, privilege or intellectual‑property rights; or upload material without authority; (b) introduce malware; attempt unauthorised access; or bypass technical, security, billing or usage controls; (c) conduct security testing without prior written permission, or reverse engineer the Services except to the extent such restriction is prohibited by law; (d) scrape, harvest or systematically extract the platform, legal corpus or databases; resell, sublicense or share Accounts contrary to plan limits; (e) impersonate legal practitioners or misrepresent professional qualifications; (f) use the Services for unlawful surveillance, discrimination, harmful automated decision‑making, or to generate deceptive, abusive or illegal content; (g) systematically extract outputs or platform elements to develop a directly competing model or service; or (h) interfere with the integrity, availability or security of the Services.

9.2 Enforcement. SenseFrame may investigate suspected violations and may restrict, suspend or terminate access where reasonably necessary to address material security, legal or operational risks, subject to clause 13.

10. Privacy, POPIA and processors

10.1 Roles. For Customer Content that includes personal information processed on Customer’s behalf, Customer is the “responsible party” and SenseFrame is an “operator” under POPIA. For account, billing, security and administrative personal information, SenseFrame is the responsible party.

10.2 Operator terms. The POPIA Operator (Data Processing) terms in Schedule A apply to SenseFrame’s operator processing of Customer Content and form part of this Agreement.

10.3 Privacy Policy. Our Privacy Policy as per Schedule E of this agreement explains how we process personal information, including categories, purposes, cross‑border transfers, retention, security and data‑subject rights.

10.4 Subprocessors. We use subprocessors to help provide the Services. The current list and details are in Schedule C. Subprocessor changes will be notified as provided in Schedule A.

11. Professional‑use and AI disclaimer

11.1 Not a law firm; no legal advice. SenseFrame is a technology provider, not a law firm, advocate or legal practitioner. We do not provide legal advice or legal representation. Your use of the Services does not create an attorney‑client relationship with SenseFrame.

11.2 AI‑assisted outputs; verification required. The Services may generate or assist in generating outputs using automated systems, including AI models. Outputs may be incomplete, inaccurate, outdated or misleading and may contain incorrect propositions, citations, dates, quotations or references. Customer and its Users must independently review and verify outputs, citations, authorities, deadlines and factual statements and must exercise professional judgment. Only appropriately qualified professionals should make legal judgments or give legal advice. Do not rely on the Services as the sole basis for court filings, legal opinions, high‑impact decisions or advice to clients.

11.3 Model‑training restrictions. SenseFrame will not use Customer Content to train publicly available, general‑purpose or foundation AI models. SenseFrame will not use Customer Content to train SenseFrame’s models without Customer’s express, informed and written opt‑in consent. SenseFrame will contractually prohibit third‑party AI and infrastructure providers from using Customer Content for their own model training, advertising, profiling or unrelated purposes. SenseFrame may use genuinely aggregated and de‑identified operational telemetry to secure, analyse and improve the Services, but only where it cannot reasonably identify a customer, user, client or matter and does not reproduce confidential content.

12. Service operation, SLA and security

12.1 Availability and maintenance. We aim to provide reliable Services but do not guarantee uninterrupted availability. Scheduled maintenance and updates may require downtime. Emergency maintenance may be performed where reasonably necessary.

12.2 Service levels (SLA). Service levels are as follows: (a) Availability target: 24 hours : monthly uptime target 98% per month, excluding scheduled maintenance (announced at least 48 hours ahead). (b) Support hours/channels: Mon-Fri 08h00 - 16h00 SAST via support@senseframe.ai and support channel. (c) Incident response: 4 hours : acknowledgement and initial response targets by severity, other issues within 2 business days. This SLA does not apply to outages or issues caused by factors outside our reasonable control, Customer’s systems or internet connectivity, or breaches of this Agreement.

12.3 Security safeguards. We implement reasonable and appropriate technical and organisational measures to protect the security, confidentiality and integrity of the Services, commensurate with risk. The current measures are described in Schedule B. Customer is responsible for secure configuration of its Accounts, managing permissions and Users, and securing its own systems and endpoints. You are responsible for keeping your login details confidential and for ensuring that each user has their own account. We protect accounts with password-strength requirements, securely hashed password storage, limits on repeated sign-in attempts, and automatic sign-out after a period of inactivity.

12.4 Each Customer's content is kept logically separate from that of other customers, and users can access only their own firm's content, subject to the permissions set by the firm. SenseFrame personnel do not access Customer Content except where needed to provide support the Customer has asked for, to investigate a fault or security issue, or where required by law. Customer Content is encrypted in transit using TLS 1.2 or higher, and encrypted at rest. Access to production systems is restricted to authorised personnel.

12.5 Backups and disaster recovery. We keep backups of Customer Content to protect against accidental loss, corruption and disaster. Backups are encrypted, are stored in South Africa, and are deleted automatically on a fixed schedule, no later than 15 months after they are created. Backups are used only to restore the Service. If we restore the Service from a backup, we re-apply any deletions made after that backup was taken, so that deleted content is not restored.

12.6 Third‑party services and integrations. The Services may interoperate with third‑party services subject to their terms. SenseFrame is not responsible for third‑party services and does not control their content or availability.

12.7 Protective suspension. We may temporarily restrict or suspend the Services where reasonably necessary to address a material security, legal or operational risk, and will restore access when the risk subsides.

13. Term, termination and data exit

13.1 Term. This Agreement starts on acceptance and continues month‑to‑month unless terminated under this clause.

13.2 Termination for breach and non‑payment. (a) Material breach. Either party may terminate for material breach by the other party not remedied within 30 days of written notice describing the breach. (b) Immediate suspension. We may suspend or terminate access immediately where required by law, to prevent harm, for serious misuse or fraud, or for a material security risk. (c) Non‑payment. If Fees remain unpaid beyond the period in clause 6.3(c), we may suspend access. If non‑payment continues for 30 days after suspension notice, we may terminate on written notice.

13.3 Cancellation (no further renewal). Customer may cancel under clause 7.2. Where CPA rights apply, we will honour them.

13.4 Post‑termination access and export.

i) Cancelling your subscription does not immediately purge all of your content. This is to ensure safe restoration of your firm’s data should you decide to restore. After cancellation your account remains available in read-only form for a period of 90 calendar days (including weekends, public holidays etc). A Firm Administrator may ask us in writing at legal@senseframe.ai to delete all of the firm's content, or to provide a copy of it, and we will do so within [30] days, subject to any legal obligation to retain it. You can also download your documents, drafts and chat responses from the Service at any time.

ii) Upon termination or expiry: (a) access to the Services will cease, subject to the read-only form which shall persist for 90 days following cancellation; (b) unpaid Fees remain due and payable.

13.5 Deletion and retention.

i) We retain Customer Content for as long as you keep it in the Service.

ii) Content you delete is removed from the Service immediately and is permanently deleted from our live systems 30 days later. During those 30 days, deleted documents can be restored from the archive.

iii) Deleted content may remain in our secure backups until those backups expire, and is never restored from them.

iv) System logs are kept for up to 30 days.

v) When a user is removed from an account, their personal details are permanently erased 30 days after removal.

vi) After the export period, we will delete or anonymise Customer Content in line with Schedule A and the Privacy Policy, subject to legal retention obligations and reasonable backups..

13.6 Refunds on termination by SenseFrame without fault. If SenseFrame terminates prepaid Services without Customer fault or fails to provide material prepaid Services, we will provide a pro‑rata refund for the unused prepaid period, subject to applicable law.

13.7 Survival. Clauses that by their nature should survive (including clauses 8, 9, 10, 11, 12.4, 13.5–13.7, 14, 15 and accrued payment obligations) survive termination or expiry.

14. Liability and indemnities

14.1 Responsibility for use. Customer uses the Services at its own risk and is responsible for verifying outputs and ensuring compliance with law, professional duties and court rules.

14.2 Exclusions of certain losses (to the extent permitted by law). To the maximum extent permitted by South African law, SenseFrame is not liable for: (a) indirect, special or consequential loss; or (b) loss of profits, revenue, business, goodwill, anticipated savings or data, arising out of or in connection with this Agreement or the use of the Services, even if advised of the possibility of such losses.

14.3 Cap on liability. Subject to clause 14.4, SenseFrame’s aggregate liability for all claims in any 12‑month period is limited to the total Fees paid or payable by Customer for the affected Services during the 12 months preceding the event giving rise to the claim.

14.4 Exceptions. The limitations in clauses 14.2 and 14.3 do not apply to liability for: (a) fraud, wilful misconduct or (where applicable law prohibits limitation) gross negligence; (b) breach of confidentiality (clause 8.3); (c) unlawful processing of personal information in breach of POPIA (to the extent liability cannot lawfully be limited); (d) Customer’s payment obligations; (e) SenseFrame’s IP indemnity obligations (if any are expressly agreed for paid customers); or (f) any liability that cannot be limited or excluded under applicable law, including under the CPA where it applies.

14.5 Free trials. For Customers using only free trials without charge, SenseFrame’s aggregate liability is limited to R10,000, subject to clause 14.4.

14.6 Customer indemnity. Customer will indemnify and hold harmless SenseFrame and its personnel from and against third‑party claims, losses and costs arising from: (a) Customer Content that infringes third‑party rights or is unlawful; (b) Customer’s or a User’s misuse of the Services in breach of this Agreement; or (c) Customer’s breach of applicable law. SenseFrame will promptly notify Customer of the claim, allow Customer to control the defence and settlement, and provide reasonable cooperation at Customer’s expense. This indemnity does not apply to the extent the claim arises from SenseFrame’s breach of this Agreement.

15. Disputes and jurisdiction

15.1 Good‑faith resolution. The parties will try in good faith to resolve disputes through negotiation between authorised senior representatives within 14 days of written notice of the dispute.

15.2 Mediation. If not resolved within 21 days after notice (or as agreed), the parties will consider mediation in South Africa.

15.3 Courts. If mediation is not pursued or fails, either party may institute proceedings in the courts of South Africa, which (subject to mandatory rights to approach another tribunal, ombud, regulator or court) will have exclusive jurisdiction.

15.4 Urgent relief and statutory rights. Nothing in this clause prevents either party from seeking urgent interim relief or exercising statutory rights (including under the CPA or POPIA).

16. Notices and domicilium

16.1 Notices.

i) Notices may be given by email. Legal notices to SenseFrame must be sent to legal@senseframe.ai, with a copy to the registered office above. Customer’s notice details are the physical address and legal‑notice email recorded in its Account or Order Form.

ii) We send service emails, including account, security, billing and invoice emails, to the email address registered on each user's account. Notices to the Customer are validly given when sent to the email address of the Customer's Firm Administrator recorded in the Service. It is the Customer's responsibility to keep that address current.

16.2 Domicilium and deemed receipt. For formal legal notices and service of process, the parties select their addresses above. A party may change its domicilium by written notice. Notices are deemed received: when delivered by hand, on the date of delivery; by prepaid registered post within South Africa, on the 7th business day after posting; and by email, on the business day of transmission if sent before 16:00 SAST, otherwise on the next business day.

17. Acceptance and Changes to this Agreement and schedules

17.1 Acceptance. Registering Administrators accept for the firm and confirm they are authorized to do so. Every user also accepts these Terms when they first sign in and after any material changes. We keep a record of each acceptance, including the version accepted and the date and time.

17.2 Updating this Agreement. We may make reasonable changes to this Agreement. For material changes that adversely affect Customer’s rights, we will provide reasonable advance notice by email or through the Services. Changes apply prospectively and will not deprive Customer of accrued rights for a month already prepaid without a reasonable remedy. If Customer objects to a material change, Customer may terminate before the change takes effect and receive a pro‑rata refund of prepaid Fees for the unused period of that month.

17.3 Updating schedules. Certain schedules (Security Measures, Subprocessor Register, Cookie Policy) may be updated to reflect operational realities, legal requirements or vendor changes, provided we do not materially reduce overall protection. Subprocessor changes will be handled per Schedule A (including notice and any objection rights).

17.4 Re‑acceptance. For certain material updates, we may require Users to re‑accept the updated terms at login after the notice period.

18. General

18.1 Assignment and subcontracting. Customer may not assign or transfer this Agreement without SenseFrame’s prior written consent (not to be unreasonably withheld). SenseFrame may assign this Agreement to an Affiliate or in connection with a merger, acquisition or sale of assets, and may subcontract obligations, remaining responsible for subcontractors’ performance.

18.2 Entire agreement; severability; waiver. This Agreement (including its Schedules) is the entire agreement on its subject matter and supersedes prior proposals or representations. If any provision is unenforceable, it will be enforced to the maximum extent permitted and the remainder remains in effect. A failure to enforce is not a waiver.

18.3 Relationship. The parties are independent contractors. This Agreement does not create a partnership, agency, employment or fiduciary relationship. No third party has rights under this Agreement except as expressly stated.

18.4 No reliance. The parties have not relied on any representation, warranty or statement not expressly set out in this Agreement.

18.5 Language. This Agreement is drafted in plain South African legal English. If translated, the English version prevails unless required by law.

19. Contact

19.1 Legal questions: legal@senseframe.ai 19.2 Support: support@senseframe.ai 19.3 Security (responsible disclosure): legal@senseframe.ai.

Schedule A — POPIA Operator (Data Processing) Annexure

A1. Roles and purpose

A1.1 Roles. Customer is the “responsible party” and SenseFrame is the “operator” (as defined in POPIA) when SenseFrame processes personal information in Customer Content on Customer’s behalf.

A1.2 Purpose and duration. SenseFrame processes personal information only to provide, maintain, secure, support and improve the Services to Customer, for the term of the Agreement, and as otherwise required by law.

A2. Processing details (scope)

A2.1 Subject‑matter: Processing Customer Content and related metadata within the Services under Customer’s instructions.

A2.2 Nature and purpose: Hosting, storage, indexing, retrieval, search, AI‑assisted operations (e.g., embeddings, retrieval‑augmented generation, summarisation and drafting on prompts), collaboration, audit logging, security and support.

A2.3 Categories of data subjects: Customer’s Users and administrators; Customer’s clients and their representatives; opposing parties, counsel, witnesses and experts; other persons whose personal information appears in Customer Content.

A2.4 Types of personal information: Identification and contact details; professional details; matter metadata; documents and correspondence; authentication and access logs; special personal information and children’s information (to the extent Customer uploads them lawfully), all as present in Customer Content.

A2.5 Special categories and children’s information: Processed only on Customer’s documented instructions and subject to POPIA conditions and appropriate safeguards.

A3. Operator obligations

A3.1 Instructions. SenseFrame will process personal information only on documented instructions from Customer (including this Agreement), unless required by law, in which case SenseFrame will inform Customer before processing (unless legally prohibited).

A3.2 Confidentiality. SenseFrame ensures persons authorised to process personal information are bound by confidentiality.

A3.3 Security. SenseFrame implements appropriate technical and organisational measures as required by POPIA section 19, commensurate with risk, as described in Schedule B.

A3.4 Subprocessors. SenseFrame may engage subprocessors to process personal information on its behalf. SenseFrame will: (a) impose obligations on subprocessors that are no less protective than those in this Annexure; (b) remain responsible for subprocessor performance; and (c) maintain a Subprocessor Register (Schedule C) and provide notice of changes as in clause A7.

A3.5 Assistance. Taking into account the nature of processing and available information, SenseFrame will assist Customer in: (a) responding to data‑subject requests under POPIA (Customer is responsible for initiating and directing such requests); (b) meeting security, breach‑notification and impact‑assessment obligations; and (c) complying with section 72 transfer safeguards.

A3.6 Records. SenseFrame will maintain records of processing as required by law.

A4. Cross‑border transfers

A4.1 Locations. Customer Content may be processed primarily in South Africa (e.g., Microsoft Azure South Africa North/West) and, where applicable, in other countries where subprocessors operate as set out in Schedule C.

A4.2 Safeguards. Transfers will comply with POPIA section 72 by ensuring one or more of the following: adequate law or binding agreement substantially similar to POPIA; data‑subject consent; necessity for contract performance or pre‑contract steps; transfer for data‑subject benefit where consent cannot be reasonably obtained; or another lawful ground.

A4.3 Prompts and generated outputs sent to the AI models may be retained by Microsoft for up to 30 days within the Azure EU Data Boundary, solely for automated abuse detection. A limited number of authorised Microsoft personnel may access that content only where automated systems flag a potential policy violation. This content is not used to train or improve any model.

A4.4

Chat Models: Azure EU data zone. The models that answer questions, drafts and revises documents – including a lighter model that generates summaries and titles. Processing happens within the Azure EU Data Boundary — EU member states plus Norway and Switzerland.

Embedding Model: South Africa data zone. Converts document text into vectors for search. Processing happens exclusively within South Africa.

Smart Indexing (AKA Document Intelligence), OCR (optical character recognition), Speech and Search: South Africa data zone. Processing happens exclusively within South Africa.

Front End Application: South Africa data zone. Deployed and served from Cape Town, South Africa.

A5. Security incidents

A5.1 Notice. Upon becoming aware of a security compromise involving personal information processed under this Annexure that may reasonably result in a risk of harm, SenseFrame will notify Customer without undue delay and provide information reasonably available for Customer to meet its obligations under POPIA section 22. Notification shall be made as follows:

Notice shall be in writing and communicated in at least one of the following ways:

  • mailed to the data subject’s last known physical or postal address;

  • sent by email to the data subject’s last known email address;

  • placed in a prominent position on the responsible party’s website;

  • published in the news media; or

  • as directed by the Information Regulator

A5.2 Cooperation. SenseFrame will take appropriate steps to contain and remedy incidents and will reasonably cooperate with Customer.

A6. Data‑subject requests

A6.1 Routing. Where a request is made directly to SenseFrame, SenseFrame will (where appropriate) advise the requester to contact Customer (the responsible party) and will not respond directly except as legally required or on Customer’s documented instructions.

A6.2 Assistance. SenseFrame will assist Customer, taking into account the nature of processing and available technical measures.

A7. Subprocessor changes and objections

A7.1 Notice. SenseFrame will give 30 days advance notice of intended changes to subprocessors by updating Schedule C and, where reasonably practicable, via email or in‑product notice.

A7.2 Objections. Customer may object on reasonable data‑protection grounds within 10 days of notice. The parties will discuss in good faith an alternative. If none is available, Customer may terminate the affected Services and receive a pro‑rata refund for any prepaid, unused period for the terminated Services.

A8. Deletion and return

A8.1 During term. Customer may export Customer Content using available export functionality, subject to technical limits.

A8.2 Post‑termination. Following termination/expiry, SenseFrame will delete or anonymise personal information in accordance with clause 13.5 of the Agreement and the Privacy Policy, subject to legal retention obligations and backup ageing. On request, SenseFrame will confirm deletion steps taken in the ordinary course.

A9. Audits and information

A9.1 Information. SenseFrame will make available information reasonably necessary to demonstrate compliance with this Annexure (e.g., responses to security questionnaires, policy summaries, third‑party audit/certification reports where applicable).

A9.2 Audits. If written information is insufficient, Customer may request a focused audit of relevant controls no more than once in any 12‑month period, subject to reasonable notice, scope, confidentiality, and non‑interference with operations. An independent auditor mutually agreed may perform the audit. On‑site audits of hyperscale providers are not feasible; certification‑based assurance is accepted where applicable.

A10. Training and personnel

A10.1 SenseFrame ensures personnel with access to personal information are trained appropriately in privacy and security and access is limited to those with a need‑to‑know.

A11. Liability

A11.1 Liability and limits under the main Agreement apply to this Annexure, subject to clause 14.4 of the Agreement (exceptions).

Schedule B — Security Measures (technical and organisational safeguards)

1. Applicability and updates 1.1 These measures apply to SenseFrame’s provision of the Services and may be updated without materially reducing overall protection. Nothing here limits SenseFrame’s obligations under POPIA or Schedule A.

2. Governance, policies and training 2.1 Governance. Security governance structure: The Information Officer and Security Lead oversee the information security management system (ISMS); roles and responsibilities are documented; security risk assessments and policy reviews occur at least quarterly; security metrics are reported to senior leadership. 2.2 Policies and standards. Information security, access control, encryption and key management, secure development, incident response, vendor management and acceptable use policies are maintained; policies are reviewed at least annually and upon material change. 2.3 Training. Mandatory privacy and security training is required for all personnel at onboarding and annually thereafter; role-based training is provided for engineering and support; completion is tracked.

3. Authentication and access control 3.1 Mechanisms. Supported authentication includes username/password with strong password requirements. Passwords must be at least 12 characters and comply with complexity and reuse controls. 3.2 Session management. Sessions expire after 48 hours; re-authentication is required for sensitive actions; administrators can revoke user sessions and devices; server-side session invalidation is supported. 3.3 Authorisation. Role-based access control (RBAC) governs access; default roles include Firm Owner, Admin Assistant, Legal Practitioner and Legal assistant; permissions are least-privilege by default and can be configured by customer administrators at workspace and matter level.

4. Administrative and privileged access 4.1 Provisioning/de‑provisioning. Administrative and production access is granted on documented approvals; joiner-mover-leaver processes are enforced, with de-provisioning within 24 hours of termination or role change; access recertification occurs at least quarterly. 4.2 Privileged controls. Privileged access is controlled through with approvals; break-glass accounts are maintained and monitored; administrative sessions are logged; all privileged actions are auditable. 4.3 Segregation of duties. Duties for development, testing and production operations are segregated; production deployments require independent review and approval; direct access to production data is restricted and monitored.

5. Encryption and key management 5.1 In transit. All external connections use TLS 1.2+ (TLS 1.3 preferred) with modern ciphers; HSTS is enabled on web properties; certificates are managed and rotated; insecure protocols are disabled. 5.2 At rest. Customer data at rest is encrypted using AES-256 or stronger; databases, object storage and backups use cloud-provider managed encryption. 5.3 Keys. Cryptographic keys and secrets are stored in Azure Key Vault; access is restricted on a least-privilege basis and audited; provider-managed keys are used by default; key rotation occurs at least annually or as advised by the provider.

6. Data segregation 6.1 Multi‑tenant isolation. Tenant/workspace isolation is enforced at the application and data layers using tenant identifiers and row-level security; per-tenant schemas/namespaces are used where applicable. 6.2 Matter‑level permissions. Per-matter access control lists (ACLs) and sharing controls are supported; inheritance from workspace defaults can be configured by administrators. 6.3 Storage segregation. Storage uses per-tenant prefixes and logical segregation; encryption contexts are segregated by service; cross-tenant access is prevented through identity scoping and service-side policies.

7. Hosting and regions 7.1 Primary regions. Microsoft Azure South Africa North and/or South Africa West. 7.2 DR/secondary regions. Azure South Africa West is designated as the disaster recovery region. 7.3 Network segregation. Environment segmentation separates production, staging and development; virtual networks (VNets) and private endpoints are used to isolate services; ingress is protected by a web application firewall (WAF); egress is restricted and monitored; network security groups and firewall rules enforce least privilege.

8. Logging, monitoring and alerts 8.1 Logging. Authentication events, administrative actions, data access and infrastructure activity are logged; time synchronisation is enforced; logs are tamper-evident and protected from unauthorised changes. 8.2 Monitoring. Centralised monitoring aggregates logs and metrics; alerts are routed to the on-call team; severity thresholds and anomaly detection are defined; critical alerts trigger immediate escalation. 8.3 Retention. Security and administrative logs are retained for 30 days; logs are stored in South Africa regions.

9. Vulnerability management and patching 9.1 Discovery. dependencies and code are scanned for known vulnerabilities and leaked secrets on every change.; results are triaged and tracked. 9.2 Remediation. Remediation targets: Critical within 7 days; High within 14 days; Medium within 30 days; Low within 90 days. Exceptions require documented risk acceptance and a remediation plan. 9.3 Patching. Operating system, container and third-party patches are applied on at least a monthly cadence; critical security patches are applied out-of-band; changes follow change control. 9.4 Dependency management. dependency tracking are maintained; libraries are updated based on risk; known vulnerable components are replaced in line with remediation targets.

10. Secure development and change control 10.1 SDLC. The SDLC incorporates coding standards, threat modelling for significant changes, and security testing (SAST/SCA) integrated into pipelines. 10.2 Code review and CI/CD. All code changes undergo peer review; CI/CD pipelines enforce security gates, artifact integrity and provenance verification. 10.3 Change management. Changes require documented approval; deployments include rollback procedures; emergency changes are reviewed retrospectively. 10.4 Secrets management. Secrets are managed in Azure Key Vault; access is tightly controlled; secrets are rotated at least annually and never committed to source code or stored in plain text.

11. Backups and restoration 11.1 Scope/frequency. Core customer data sets are backed up daily, with additional intra-day snapshots where appropriate. 11.2 Storage/protection. Backups are encrypted at rest and in transit; access to backup repositories is restricted; periodic restore tests validate integrity. 11.3 Retention. Database: continuous backup, restorable to any point in the last 35 days, plus 13 monthly archives. Documents: backed up weekly. Deleted after at most 15 months. 11.4 Restoration. Backup restoration procedures are documented; restoration tests are performed at least annually; typical restoration of core datasets completes within 24 hours. 11.5 RPO/RTO. Target recovery point objective (RPO) is 4 hours; recovery time objective (RTO) is 24 hours.

12. Incident detection and response 12.1 Detection/triage. Detection sources include cloud provider alerts, infrastructure monitoring, application telemetry and user reports; triage follows a documented workflow; monitoring is continuous with business-hours staffing and on-call escalation for critical incidents. Supports timely notification under POPIA and Schedule A. 12.2 Response. SenseFrame will investigate, contain, remediate and notify Customer in accordance with POPIA section 22 and Schedule A. 12.3 Communications. Security contact: legal@senseframe.ai. The Security Lead acts as incident commander; communications use predefined channels (email, ticketing, and, where necessary, customer-specific contacts); initial customer notice target is within 72 hours of becoming aware, subject to investigation and legal advice.

13. Staff and contractor confidentiality 13.1 Obligations. Personnel and subprocessors are bound by confidentiality and process personal information only as authorised. 13.2 Access limitation. Access is limited to authorised personnel with least privilege. Enforcement includes least-privilege role assignments, approval workflows and quarterly access reviews. 13.3 Onboarding/offboarding. Onboarding includes completion of mandatory training and acceptance of policies prior to access; offboarding revokes access, retrieves assets and disables credentials within 24 hours; access changes are tracked.

14. Subprocessor security assessment 14.1 Due diligence. SenseFrame assesses subprocessors prior to onboarding and requires POPIA‑aligned terms. 14.2 Ongoing oversight. Subprocessors are reassessed at least annually and upon material change; security attestations and contract compliance are reviewed. 14.3 Subprocessor List. See Schedule C.

15. Data deletion and disposal 15.1 During term. Customer may export via available functionality. Export mechanisms include in-app export tools for supported formats; additional exports may be provided on request subject to technical limits. 15.2 Post‑termination. Deletion/anonymisation per Agreement clause 13.5. Primary systems are cleared within 30 days after export window closure; backup copies age out per retention; deletion confirmation can be provided on request. 15.3 Backups. Backup copies persist for in terms of 12.5 and are purged in the ordinary course. 15.4 Media disposal. Media and device disposal follow secure sanitisation or destruction methods aligned to cloud provider responsibilities and industry standards.

16. Periodic testing 16.1 Testing programme. The testing programme includes regular vulnerability scans, configuration reviews and an annual third-party penetration test covering application and infrastructure scope. 16.2 Remediation tracking. Remediation is tracked to closure in an issue tracker with ownership and due dates; management receives periodic status reports. 16.3 Management review. Security metrics and risk reports are reviewed at least quarterly by senior leadership.

Schedule C — Subprocessor Register

Introduction SenseFrame engages certain third‑party providers (Subprocessors) to help deliver, maintain, secure and support the Services. A “Subprocessor” is a third party that processes personal information on SenseFrame’s behalf in connection with the Services. Subprocessors that process Customer Content (operator role) are listed in section 1. Providers that process SenseFrame’s own users’ and prospects’ data (responsible‑party role) are listed in section 2 for transparency.

Effective date of this schedule: 5 October 2026 Subprocessor enquiries: legal@senseframe.ai (security contact: legal@senseframe.ai)

Subprocessor register and supplier requirements

1 · SUBPROCESSORS THAT PROCESS FIRM CUSTOMER CONTENT

SenseFrame acts as operator in respect of these. The law firm is the responsible party; these vendors process its clients’ information on our behalf and on the firm’s instructions.

SUBPROCESSORWHAT THEY DO FOR USENTITY / LOCATEDDATA SENT TO THEMPROCESSED IN
Microsoft Azure — core platformHosts the API, database, document storage, search index, cache, key vault and logs.Microsoft (Ireland Operations Ltd for EMEA contracting)Everything: accounts, matters, uploaded documents, chat history, drafts.South Africa North
Azure OpenAI — chat and draftingThe models that answer questions, draft and revise documents, plus a lighter model that generates summaries and titles.MicrosoftUser questions, extracts of matter documents, attachment text, draft text.Azure EU Data Boundary (Data Zone Standard; stored at rest in Sweden)
Azure OpenAI — embeddingsConverts document text into vectors so matter search can find relevant passages.MicrosoftDocument text.South Africa North
Azure AI Document IntelligenceSmart indexing and OCR — reads the layout and text of uploaded documents, including scans.MicrosoftPage images and extracted text.South Africa North
Azure AI SearchThe retrieval index that matter search and the assistant query.MicrosoftDocument chunks and their metadata.South Africa North
Azure SpeechConverts dictated speech to text in the chat input.MicrosoftAudio of dictated input.South Africa North
VercelHosts both web applications. All authenticated traffic routes through its server-side functions, including document files on download and preview.Vercel Inc. (United States)Chat messages, matter data, and document bytes in transit.Cape Town (cpt1 / af-south-1)
Resend (Plus Five Five, Inc.)Sends every transactional email — verification, invitations, password resets, billing notices and invoices.United States (San Francisco)Names, email addresses, organisation names, message content, and invoice PDFs as attachments.United States
Laws.AfricaLegislation and case-law lookup for legal research.Ireland (NGO operates in South AfricaReceives search queries only, with no client personal information. Keeps query text up to 90 days, and billing records (IP address, account, time) for 5 years. Neither is linked to our users.Ireland

Shaded rows process data outside South Africa.

2 · SUBPROCESSORS THAT PROCESS OUR OWN USERS’ AND PROSPECTS’ DATA

SenseFrame acts as responsible party in respect of these, not as operator. They do not touch firm Customer Content. The distinction matters: these belong in the Privacy Policy rather than in the customer-facing subprocessor list under the DPA, though publishing both is the more transparent course.

SUBPROCESSORWHAT THEY DO FOR USENTITY / LOCATEDDATA SENT TO THEMPROCESSED IN
PaystackCard checkout and recurring subscription charges.Paystack (Ireland), Stripe group; operates in South AfricaBilling contact email and our internal subscription identifiers. Card details are entered on Paystack’s own hosted page — SenseFrame never receives or stores a card number.Ireland (private AWS); intra-group transfers under Binding Corporate Rules
Cloudflare TurnstileBot protection on the signup, login, demo-request and early-access forms.Cloudflare, Inc. (United States)IP address and browser / device signals of anyone using those forms. Sets no cookies.Cloudflare global edge network
CalendlyDemo booking for prospective customers.Calendly LLC (United States)Prospect name, email address and meeting time.United States

Not a subprocessor, recorded here so it is not added by mistake: open.er-api.com returns a USD to ZAR exchange rate for internal cost modelling. No personal data and no request content is sent to it.

Notes

  • SenseFrame requires its operators to process personal information only on documented instructions, implement appropriate security measures, and not use personal information for their own purposes.

  • Cross‑border transfers are safeguarded under POPIA section 72 as set out in Schedule A.

Subprocessor changes and customer notifications

  • Maintenance of list: SenseFrame will maintain this Register current.

  • Change notices: SenseFrame will notify Customers of intended changes to Subprocessors by updating this schedule and, where reasonably practicable, via email or in‑product notice at least 30 days in advance.

  • Customer objections: Customers may object on reasonable data‑protection grounds within 10 days of notice. The parties will discuss an appropriate alternative; if none is available, Customer may terminate the affected Services and receive a pro‑rata refund for the unused prepaid period for those Services.

  • Contact for change notifications and objections: legal@senseframe.ai

Company details and contacts

  • SenseFrame (Pty) Ltd (Reg. no. 2025/968958/07)

  • Registered office: 21 Tecoma Street, Berea, East London, Eastern Cape, 5214, South Africa

  • Principal place of business: 13 Valley Cul De Sac, Gordon’s Bay, 7140, Western Cape, South Africa

  • Legal notices and subprocessor enquiries: legal@senseframe.ai

  • Security contact: legal@senseframe.ai

Effective date: 5 October 2026 Version: 1.0

1. Who we are and scope 1.1 This Cookie Policy explains how SenseFrame (Pty) Ltd (registration number 2025/968958/07) (SenseFrame, we, us) uses cookies and similar technologies on: (a) the public website available at www.senseframe.ai; and (b) the web application available at app.senseframe.ai. 1.2 Read this together with our Privacy Policy at Schedule E.

2. What cookies are 2.1 Cookies are small text files placed on your browser or device when you visit a website. They typically contain a unique identifier and basic information about your interaction with the site. 2.2 Cookies can be session (deleted when you close your browser) or persistent (remain for a defined period).

3. Similar technologies 3.1 “Cookies” here includes local/session storage, pixels, tags, web beacons, SDKs, device/browser identifiers and server‑side event logging associated with your device or account events.

4. Legal context 4.1 Use of cookies may involve processing personal information. We implement consent, preference and transparency practices appropriate to the purposes and the nature of the technologies used.

5. Our approach to consent

5.1 Essential cookies. We use strictly necessary cookies to operate our sites and services (e.g., session management, load balancing, security).

5.2 Non‑essential cookies.

i) SenseFrame uses only cookies that are strictly necessary to provide the Service, such as keeping you signed in and protecting against security threats. We do not use analytics, advertising or tracking cookies, and we do not use cookies to profile you. Because these cookies are strictly necessary, they do not require your consent.

ii) Should SenseFrame change it’s policy in respect of analytics, performance measurement and preferences (and any marketing technologies if implemented), we: (a) shall request consent where required by law; and (b) otherwise rely on our legitimate interests in operating, maintaining, securing and improving our sites and services, balanced against your interests and rights.

6. Categories we use

6.1 Strictly necessary (essential): core functions like sign‑in/authentication, load balancing and consent‑preference storage.

6.2 Performance and analytics: understand usage, measure traffic, diagnose errors, improve performance.

6.3 Functionality (preferences): remember choices (e.g., language, UI preferences). 6.4 Security and fraud prevention: detect misuse/abuse; protect accounts; maintain integrity. 6.5 Developer tooling and infrastructure telemetry: hosting/CDN/error tracking to keep the service reliable and secure.

7. Specific cookies and tools

7.1

CookiePurposeDuration
accessTokenKeeps you signed in15 minutes
refreshTokenRenews your sign-in session48 hours
csrfTokenProtects against forged requests24 hours
sf-maintenance-bypassStaff access during maintenance (staff only)12 hours

7.2 All of these cookies are strictly necessary, set by SenseFrame, and cannot be read by other websites. We also store a small number of display preferences in your browser, such as whether you have dismissed a notice. These are not used for tracking.

7.3 To protect our sign-up and demo request forms from automated abuse, we use Cloudflare Turnstile. When you use those forms, Cloudflare receives your IP address and technical information about your browser, which it uses only to check that the form is being completed by a person.

8. Managing your choices 8.1 Consent banner and settings. On first visit (and periodically thereafter), our banner explains use of cookies and allows you to accept, reject or set preferences for non‑essential categories. You can change your choices at any time via: “Cookie settings” link. 8.2 Browser controls. Most browsers let you block/delete cookies, block third‑party cookies and control site data. 8.3 Do Not Track (DNT). We do not use tracking, analytics or advertising cookies, so there is no tracking for a Do Not Track signal to switch off. Our sites therefore do not respond to DNT signals; the only cookies we use are strictly necessary for the service to work.

9. Cross‑border processing 9.1 Service providers may process cookie‑derived information in other countries. We implement POPIA‑compliant safeguards (see Privacy Policy Schedule E and Schedule A).

10. Security 10.1 We apply appropriate technical and organisational measures, including transport encryption, access controls and data minimisation. Our cookies cannot be read by scripts running in the page (HttpOnly). They are sent only over encrypted connections (Secure), and are restricted to requests from our own site (SameSite), which limits cross-site attacks. Forms and other actions that change data are additionally protected against cross-site request forgery (CSRF) with a separate security token checked on every such request.

11. Contact 11.1 For privacy queries: legal@senseframe.ai 11.2 Information Officer: catherine@senseframe.ai

Schedule E – Privacy Policy (contractual annexure)

Effective date of this Schedule: 5 October 2026 Version: 1.0

This Schedule E forms part of, and is incorporated into, the SenseFrame Terms of Service (the “Agreement”).

1. Introduction and scope

1.1 Purpose of this Privacy Policy.

1.1.1 This Privacy Policy explains how SenseFrame (Pty) Ltd (“SenseFrame”, “we”, “us”) collects, uses, discloses and safeguards personal information in connection with the Services described in the Agreement.

1.1.2 It is intended to meet the transparency and information‑provision requirements under the Protection of Personal Information Act, 4 of 2013 (“POPIA”), and to give data subjects clear information about how their personal information is processed.

1.2 Relationship with the Agreement and other Schedules.

1.2.1 This Privacy Policy is a contractual annexure and forms part of the Agreement as Schedule E.

1.2.2 Schedule A (POPIA Operator (Data Processing) Annexure) sets out additional terms applicable where SenseFrame acts as “operator” for Customer Content on behalf of Customer as “responsible party”.

1.2.3 Schedule B (Security Measures (technical and organisational safeguards)) describes in more detail the technical and organisational measures we implement to protect personal information.

1.2.4 Schedule C (Subprocessor Register) lists the third‑party subprocessors we use and the locations in which they process personal information.

1.2.5 Schedule D (Cookie Policy) provides more detail about cookies and similar technologies used on our sites and applications.

1.3 Roles under POPIA.

1.3.1 For Customer Content that includes personal information and that we process on Customer’s behalf, Customer is the “responsible party” and SenseFrame is the “operator”, as described in clause 10 of the Agreement and in Schedule A.

1.3.2 For account, billing, security, administrative and marketing‑related personal information about our own users and prospects (and for certain cookie and device data), SenseFrame is the “responsible party” under POPIA.

1.3.3 This Privacy Policy applies primarily to processing where SenseFrame acts as responsible party. Where we act as operator, this Privacy Policy should be read together with Schedule A and with the responsible party’s own privacy notices.

1.4 Who this Privacy Policy applies to.

1.4.1 This Privacy Policy applies to:

(a) users and administrators of Customer Accounts on the Services;

(b) prospective customers and other individuals who contact us, request a demo or interact with our marketing and sales channels;

(c) visitors to our public website and web application; and

(d) other individuals whose personal information we process in the course of operating our business, except where a different privacy notice is expressly provided.

1.4.2 It does not replace the privacy notices that may be provided by Customers to their own clients and other data subjects whose information is included in Customer Content.

2. Responsible party and contact details

2.1 SenseFrame details.

2.1.1 Contracting entity and responsible party:

(a) SenseFrame (Pty) Ltd (Registration number: 2025/968958/07).

2.1.2 Registered office and domicilium (as per the Agreement):

(a) 21 Tecoma Street, Berea, East London, Eastern Cape, 5214, South Africa.

2.1.3 Principal place of business (as per the Agreement):

(a) 13 Valley Cul De Sac, Gordon’s Bay, 7140, Western Cape, South Africa.

2.2 Contact details for privacy matters.

2.2.1 General privacy enquiries and data‑subject requests:

(a) Email: legal@senseframe.ai

2.2.2 Information Officer.

(a) Information Officer email: catherine@senseframe.ai

(b) Additional details about the Information Officer (name and designation) may be made available on our website or upon request.

2.3 Information Regulator.

2.3.1 You have the right to lodge a complaint with the Information Regulator (South Africa) if you believe your personal information is being processed in a way that infringes POPIA.

2.3.2 Current contact details for the Information Regulator are available on its official website. We encourage you to contact us first so that we can attempt to resolve your concerns.

3. Categories of personal information we process

3.1 Overview.

3.1.1 We process different categories of personal information depending on your relationship with us and how you interact with the Services.

3.1.2 The table below summarises the main categories of data subjects and types of personal information we process as responsible party, and indicates where that information typically comes from.

3.2 Data categories.

3.2.1 The main categories are:

Data subject categoryTypes of personal informationTypical sources
Customer users and administrators (including Organisations, Admin Assistants, Legal Users and Legal Assistants)Identification and contact details (name, surname, email address, organisation, role); account identifiers; authentication data (username, hashed password); organisation affiliation and role; usage data (sign‑in timestamps, session identifiers, in‑app actions and configuration settings); support communications; security and access logs associated with the user.Directly from the user or Customer during signup and account administration; from in‑app activity; from our authentication and logging systems.
Billing contacts and payersContact details (name, email address); billing preferences; subscription plan and seat counts; invoice and payment records (amounts, currency, dates); last four digits and expiry of card (where shown by our payment provider); our internal subscription identifiers. Card details are entered on Paystack’s own hosted page; SenseFrame does not receive or store full card numbers.Directly from Customer; from our payment processor (Paystack) and invoicing systems.
Prospective customers and demo requestersIdentification and contact details (name, email address, organisation, role); meeting times and preferences; any information you choose to provide in free‑text fields; interaction history with our sales or support teams.Directly from you when you complete forms on our website or communicate with us; from Calendly and similar tools as listed in Schedule C.
Website visitors and app users (cookie, device and telemetry data)IP address; device and browser identifiers and characteristics; operating system and version; basic device and network data; identifiers such as accessToken, refreshToken and csrfToken as set out in Schedule D; log data about requests, responses, performance and errors; signals used by Cloudflare Turnstile to distinguish humans from bots.Automatically when you visit our website or use the Services; from cookies and similar technologies as described in Schedule D; from Cloudflare Turnstile and other infrastructure providers listed in Schedule C.
Customer decision‑makers and contactsNames, work contact details (email address, phone number); position and organisational affiliation; communication records (emails, meeting notes); contract‑related information (e.g. orders and negotiations).Directly from you; from your colleagues; from our sales and relationship‑management interactions.
Individuals whose personal information appears in Customer ContentAny personal information embedded in Customer Content (e.g. identification and contact details, professional information, matter information, special personal information and children’s information), as described in Schedule A.Provided by Customer or its users when they upload or generate Customer Content within the Services. For these data subjects, Customer is the responsible party and SenseFrame acts as operator.

3.3 Special personal information and children’s information.

3.3.1 Special personal information and children’s information may be included in Customer Content where Customer uploads it lawfully.

3.3.2 As responsible party we do not intentionally collect special personal information or children’s information about you outside of Customer Content, but such information may appear incidentally in communications or support interactions you have with us.

4. Purposes of processing and POPIA conditions

4.1 General.

4.1.1 We process personal information only for lawful, reasonable and specific purposes related to:

(a) providing, maintaining and improving the Services;

(b) managing our relationship with Customers, users and prospects; and

(c) operating and protecting our business.

4.1.2 We rely on one or more lawful grounds for processing under POPIA, including where processing is:

(a) necessary to carry out actions for the conclusion or performance of a contract with you or your organisation;

(b) required by law;

(c) necessary to pursue our legitimate interests (or those of a Customer or third party) in a manner that does not override your rights; and

(d) based on your consent, where consent is the appropriate ground (e.g. for certain optional communications).

4.2 Purposes and POPIA conditions by category.

4.2.1 The main purposes and POPIA grounds for the categories in clause 3.2 are summarised below.

Data subject categoryMain purposes of processingPrincipal POPIA conditions relied on
Customer users and administratorsTo create and manage Accounts and workspaces; authenticate users and manage sessions; provide access to the Services; manage permissions and security; provide support; send account, billing and service communications; monitor and secure the platform; understand usage to operate and improve core functionality.Necessary to carry out actions for the conclusion or performance of a contract (Agreement with Customer); compliance with legal obligations (e.g. security and record‑keeping duties); legitimate interests in operating and securing the Services, balanced against users’ rights.
Billing contacts and payersTo bill for subscriptions and services; process payments via our payment provider; issue invoices and statements; manage account status and collections; maintain financial records.Necessary for performance of a contract and to take pre‑contract steps; compliance with legal obligations (tax and accounting); legitimate interests in managing our commercial relationship and preventing fraud.
Prospective customers and demo requestersTo respond to enquiries and demo requests; schedule and conduct meetings; evaluate potential Customer fit; send follow‑up communications; keep basic records of interactions.Necessary to take steps at your request prior to concluding a contract; legitimate interests in marketing and growing our business, balanced against your rights; consent where required for certain electronic marketing.
Website visitors and app users (cookie, device and telemetry data)To operate the website and app; maintain secure sessions; protect against abuse (including bot protection via Cloudflare Turnstile); perform load balancing and routing; monitor performance and reliability; diagnose errors and security incidents; comply with legal and security obligations.Legitimate interests in operating, maintaining and securing our website and Services, balanced against your rights; performance of a contract where strictly necessary for core service functionality. Only strictly necessary cookies are used as set out in Schedule D.
Customer decision‑makers and contactsTo negotiate and enter into agreements; maintain records of Customer relationships; send important contractual, legal and operational communications; manage renewals and changes; resolve disputes.Necessary for performance of a contract or to take pre‑contract steps; legitimate interests in managing Customer relationships and our business.
Individuals whose personal information appears in Customer ContentTo host, store, index, retrieve, search, and perform AI‑assisted operations on Customer Content for purposes determined by Customer; to provide support, security, logging and related services to Customer.Customer, as responsible party, determines the lawful basis under POPIA. SenseFrame processes on Customer’s documented instructions as operator, as described in Schedule A.

4.3 Direct marketing.

4.3.1 If we use your contact details for direct marketing (for example, to tell you about new features or services), we will do so in accordance with POPIA and applicable direct‑marketing rules.

4.3.2 You can opt out of direct marketing at any time by using the unsubscribe link in the relevant communication or by contacting us at legal@senseframe.ai.

4.3.3 We will continue to send service and transactional messages (such as security alerts, billing notices and critical updates) where required for the operation of the Services or by law.

5. How we collect personal information

5.1 Information you provide to us.

5.1.1 We collect personal information that you or your organisation provide directly, for example when you:

(a) create or administer an Account;

(b) request a demo or complete a contact form;

(c) subscribe to the Services or update billing details;

(d) communicate with us by email, support ticket or other channels; or

(e) participate in feedback, surveys or similar initiatives.

5.2 Information we collect automatically.

5.2.1 We collect certain information automatically when you visit our website or use the Services, including:

(a) log and telemetry data relating to your use of the Services;

(b) device, browser and network information;

(c) strictly necessary cookies and similar technologies as described in Schedule D; and

(d) signals processed by infrastructure providers such as Cloudflare Turnstile to combat automated abuse.

5.2.2 These processing activities are described in more detail in Schedule B (Security Measures) and Schedule D (Cookie Policy).

5.3 Information from third parties.

5.3.1 We may receive personal information about you from third parties, including:

(a) our subprocessors listed in Schedule C (for example, Paystack, Calendly, Resend or Cloudflare) in the course of providing their services to us;

(b) your employer or colleagues, where they register you as a user or provide your details as a contact; and

(c) public sources or professional platforms where appropriate for B2B relationship management, subject to applicable law.

5.4 Customer Content.

5.4.1 Customer is responsible for ensuring that it has a lawful basis and appropriate notices in place before it uploads or submits Customer Content, including any personal information, to the Services.

5.4.2 As operator, we process Customer Content only on Customer’s documented instructions and as described in the Agreement and Schedule A.

6. Cross‑border transfers

6.1 Where personal information is processed.

6.1.1 Personal information may be processed in:

(a) South Africa, primarily in Microsoft Azure South Africa North and/or South Africa West regions, where we host the core platform, databases, document storage, search index and related services; and

(b) other countries where our subprocessors operate, as set out in Schedule C, including within the Azure EU Data Boundary (for certain AI model processing) and in other jurisdictions (for example, Ireland and the United States) for specific services such as email delivery, payment processing, hosting and bot protection.

6.2 Safeguards for cross‑border transfers.

6.2.1 Cross‑border transfers of personal information will comply with POPIA section 72, including by ensuring that one or more of the following apply:

(a) the recipient is subject to a law, binding corporate rules or a binding agreement that provide an adequate level of protection that effectively upholds principles for reasonable processing of personal information that are substantially similar to POPIA;

(b) the data subject consents to the transfer;

(c) the transfer is necessary for the performance of a contract or for pre‑contractual steps taken at the data subject’s request;

(d) the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject; or

(e) another lawful ground under POPIA applies.

6.2.2 Schedule A and Schedule C provide more detail on locations and safeguards, including for Azure OpenAI services within the Azure EU Data Boundary and for other subprocessors.

6.3 Microsoft Azure OpenAI and content retention.

6.3.1 As described in Schedule A, prompts and generated outputs sent to certain Azure OpenAI models may be retained by Microsoft for up to 30 days within the Azure EU Data Boundary solely for automated abuse detection, and are not used to train or improve any model.

6.3.2 A limited number of authorised Microsoft personnel may access that content only where automated systems flag a potential policy violation, and only for the purpose of investigating such violations.

7. Retention and deletion

7.1 General principle.

7.1.1 We retain personal information only for as long as is reasonably necessary for the purposes set out in this Privacy Policy, to comply with legal obligations, or to protect our legitimate interests, and then delete or anonymise it in accordance with the Agreement, Schedule A and Schedule B.

7.2 Specific retention practices (summary).

7.2.1 The Agreement and Schedules contain detailed retention periods, which include:

(a) Customer Content: retained for as long as Customer keeps it in the Service, with post‑termination export and read‑only periods as described in clause 13 of the Agreement and in Schedule B.

(b) Deleted Customer Content: removed from the Service immediately and permanently deleted from live systems 30 days later, with backup copies ageing out and never being restored except to recover from disaster, as described in clauses 12.5 and 13.5 of the Agreement and in Schedule B.

(c) System logs: kept for up to 30 days, as described in clauses 13.5 and Schedule B (logging and monitoring).

(d) Backup data: backups are encrypted and retained according to fixed schedules and are deleted automatically no later than 15 months after creation, as detailed in Schedule B.

(e) User account data: when a user is removed from an account, their personal details are permanently erased 30 days after removal, as described in clause 13.5 of the Agreement.

(f) Billing and financial records: retained for periods required by tax and financial‑record laws and for legitimate business purposes.

(g) Records of acceptance: when a person accepts the Agreement or this Privacy Policy, we keep a record of who accepted (name, email address and firm), the version accepted, the date and time, the IP address and the device or browser used. We keep these records for five years after the Agreement ends, as evidence of the contract, including after that person’s other personal details are erased under (e).

7.3 Data exit and deletion on termination.

7.3.1 Clause 13 of the Agreement and Schedule A (A8) describe how Customer may export Customer Content during the term and for a defined export period after cancellation or termination.

7.3.2 After the export period, we will delete or anonymise Customer Content in accordance with clause 13.5 of the Agreement, Schedule A and Schedule B, subject to legal retention obligations and backup ageing.

7.3.3 On request, we will confirm the deletion steps taken in the ordinary course, as described in Schedule A and Schedule B.

8. Security safeguards

8.1 Overview.

8.1.1 We implement reasonable and appropriate technical and organisational measures to protect the security, confidentiality and integrity of personal information, commensurate with the risk, as required by POPIA section 19 and as described in clause 12 of the Agreement and in Schedule B.

8.2 Key measures (summary).

8.2.1 Without limiting the detailed measures in Schedule B, our safeguards include:

(a) strong authentication and access control mechanisms, including password‑strength requirements, session management and role‑based access control;

(b) encryption of Customer Content and relevant personal information at rest and in transit (TLS 1.2+ for external connections, AES‑256 or stronger for data at rest);

(c) governance, policies and training programmes for personnel and subprocessors, including confidentiality obligations and least‑privilege access;

(d) secure development practices, change control, vulnerability management and regular patching;

(e) logging, monitoring and incident‑response processes, including escalation and notification practices to support POPIA section 22 requirements; and

(f) backup and disaster‑recovery measures designed to meet defined recovery point and recovery time objectives.

8.3 Security incidents.

8.3.1 If a security compromise involving personal information processed under this Privacy Policy may reasonably result in a risk of harm to data subjects, we will notify the relevant responsible party (Customer or SenseFrame, as applicable) without undue delay and provide information reasonably required to meet obligations under POPIA section 22, as described in Schedule A and Schedule B.

8.3.2 Where SenseFrame is the responsible party, we will notify affected data subjects and the Information Regulator where required by law and in the manner permitted by POPIA.

9. Data‑subject rights

9.1 Your rights.

9.1.1 Subject to POPIA and other applicable law, you may have the following rights in relation to your personal information:

(a) the right to be informed about the collection and processing of your personal information;

(b) the right of access to personal information we hold about you;

(c) the right to request correction or deletion of inaccurate, irrelevant, excessive, out‑of‑date, incomplete or misleading personal information;

(d) the right to object to the processing of your personal information, on reasonable grounds relating to your particular situation, where the law allows such objection;

(e) the right to object at any time to the processing of personal information for purposes of direct marketing, including by way of unsolicited electronic communications;

(f) the right to withdraw consent where processing is based on your consent (without affecting the lawfulness of processing before withdrawal); and

(g) the right to lodge a complaint with the Information Regulator.

9.2 How to exercise your rights where SenseFrame is responsible party.

9.2.1 To exercise your rights in respect of personal information for which SenseFrame is the responsible party (for example, your user account data, billing contact details, or data collected through our website), you may contact us at legal@senseframe.ai or the Information Officer at catherine@senseframe.ai.

9.2.2 We may ask you to verify your identity and provide information to help us locate the personal information concerned.

9.2.3 We will respond to your request in accordance with POPIA and other applicable law, and we may refuse requests that are manifestly unfounded, excessive or clearly without merit, where permitted by law.

9.3 Data‑subject requests relating to Customer Content.

9.3.1 For personal information contained in Customer Content, Customer is the responsible party and is primarily responsible for handling data‑subject requests (for example, access, correction or deletion requests by a client of a law firm).

9.3.2 If we receive a request directly from a data subject relating to Customer Content, we will, where appropriate, advise the requester to contact the relevant Customer and will not respond directly except as legally required or on Customer’s documented instructions, as described in Schedule A.

9.3.3 We will assist Customers with data‑subject requests in accordance with Schedule A, taking into account the nature of processing and available technical measures.

10. Cookies and similar technologies

10.1 Overview.

10.1.1 We use cookies and similar technologies on our public website and web application, primarily to provide and secure the Services.

10.1.2 Our use of cookies and similar technologies is described in more detail in Schedule D (Cookie Policy), which forms part of the Agreement.

10.2 Types of cookies and technologies.

10.2.1 As set out in Schedule D:

(a) we use strictly necessary cookies to operate our sites and Services (for example, to keep you signed in, manage sessions, provide load balancing and support security);

(b) we do not currently use analytics, advertising or tracking cookies, and we do not use cookies to profile you; and

(c) we use Cloudflare Turnstile to protect certain forms from automated abuse, which involves processing IP addresses and browser/device signals; Cloudflare Turnstile sets no cookies.

10.3 Specific cookies.

10.3.1 Schedule D lists the specific cookies we set (including accessToken, refreshToken, csrfToken and sf‑maintenance‑bypass) and the purposes and duration for each.

10.4 Managing your browser and cookie preferences.

10.4.1 Your browser may allow you to block or delete cookies, block third‑party cookies and control site data. Doing so may affect the functionality of the Services, particularly for strictly necessary cookies.

10.4.2 Further information on managing cookies and any consent or preference tools we provide is set out in Schedule D and in the cookie‑related interfaces on our website or app.

11. AI‑assisted processing and model‑training commitments

11.1 AI‑assisted processing.

11.1.1 The Services may use automated systems, including AI models, to:

(a) perform search, summarisation and drafting based on Customer Content and other materials;

(b) generate titles, summaries and similar metadata;

(c) support document analysis and smart indexing; and

(d) provide other AI‑assisted features described in the Agreement.

11.1.2 Outputs may be incomplete, inaccurate, outdated or misleading and may contain incorrect propositions, citations, dates, quotations or references. As stated in clause 11 of the Agreement, Customer and its users must independently review and verify outputs, citations, authorities, deadlines and factual statements and must exercise professional judgment.

11.2 Use of Customer Content for model training.

11.2.1 As stated in clause 11.3 of the Agreement:

(a) SenseFrame will not use Customer Content to train publicly available, general‑purpose or foundation AI models;

(b) SenseFrame will not use Customer Content to train SenseFrame’s own models without Customer’s express, informed and written opt‑in consent; and

(c) SenseFrame will contractually prohibit third‑party AI and infrastructure providers from using Customer Content for their own model training, advertising, profiling or unrelated purposes.

11.2.2 SenseFrame may use genuinely aggregated and de‑identified operational telemetry to secure, analyse and improve the Services, but only where it cannot reasonably identify a customer, user, client or matter and does not reproduce confidential content, as set out in clause 11.3 of the Agreement.

11.3 Responsible use.

11.3.1 The Services are designed for professional users, including corporate legal departments, legal managers in organisations or governmental departments, legal practitioners and legal teams. Only appropriately qualified professionals should make legal judgments or give legal advice based on the outputs.

11.3.2 Customers are responsible for ensuring that their use of the Services complies with law, professional duties and court rules, as described in the Agreement.

12. Changes to this Privacy Policy

12.1 Updating this Privacy Policy.

12.1.1 We may make reasonable changes to this Privacy Policy from time to time, for example to:

(a) reflect changes in the Services or our processing activities;

(b) address legal or regulatory developments; or

(c) update information about our subprocessors or safeguards.

12.1.2 Clause 17 of the Agreement governs how changes to the Agreement and its schedules are made and notified.

12.1.3 For material changes that adversely affect Customer’s rights, we will provide reasonable advance notice in accordance with clause 17 of the Agreement (for example, via email or through the Services), and may require Users to re‑accept updated terms at login where appropriate.

12.2 Effective version.

12.2.1 The effective date and version of this Privacy Policy are set out at the top of this Schedule E.

12.2.2 We keep records of acceptance and versioning consistent with clause 17.1 of the Agreement.

13. Relationship with the Agreement and cross‑references

13.1 Priority and interpretation.

13.1.1 This Privacy Policy forms part of the Agreement. In the event of any conflict between this Schedule E and the main body of the Agreement regarding matters of personal‑information processing where SenseFrame acts as responsible party, this Schedule E will prevail, subject to any overriding statutory provisions.

13.1.2 For matters relating to SenseFrame’s role as operator processing Customer Content on behalf of Customer, Schedule A (POPIA Operator (Data Processing) Annexure) takes precedence over this Privacy Policy to the extent of any conflict.

13.2 References to “Privacy Policy” in the Agreement.

13.2.1 For clarity, references in the Agreement to the “Privacy Policy” are to this Schedule E, including in:

(a) the definition of “Privacy Policy” in clause 2.1(f), which must be read as referring to SenseFrame’s privacy policy incorporated as Schedule E;

(b) clause 10.3, which describes our Privacy Policy and must be read as referring to Schedule E; and

(c) clause A8.2 of Schedule A, which refers to deletion in accordance with the Agreement and the Privacy Policy.

13.2.2 References in Schedule B and Schedule D to “our Privacy Policy” or to “Privacy Policy at Schedule B” must be read as references to this Schedule E.

13.2.3 The list of Schedules in clause 1.1 of the Agreement should be read as including this Schedule E: Privacy Policy (contractual annexure).

13.3 No limitation of other rights and obligations.

13.3.1 Nothing in this Privacy Policy limits:

(a) the rights of data subjects under POPIA or other applicable law; or

(b) SenseFrame’s or Customer’s obligations under POPIA, the Agreement, Schedule A, Schedule B, Schedule C or Schedule D.