Skip to content

Operator agreement

Where you use the assessment on behalf of an organisation and put personal information through it, we act as your operator under section 21 of POPIA. These are the terms of that relationship.

Last updated 24 August 2026

Not yet reviewed by a lawyer

This document must be reviewed by a South African privacy lawyer before it is relied on with real customers. It was drafted to be accurate about what the product actually does and to be POPIA-aware, but it is not legal advice and it carries no professional assurance. If you are evaluating this service for an organisation with meaningful obligations, treat this document as a statement of intent rather than as a warranty.

1. Who acts as your operator

Where this agreement applies, the operator under section 21 of POPIA is the business named below.

Service
aireadiness, at aireadiness.co.za
Operated by
Boondock Labs
Responsible person
Eugene Boondock, whose full legal name is Eugene Loyiso Mzimakhwe
Information Officer
Eugene Boondock
Country
South Africa
Registration number
Not yet published
Business address
Not yet published
VAT
Not registered for VAT. No VAT is charged.
Capacity
Operator under section 21 of POPIA, processing on behalf of your organisation

aireadiness is operated by Boondock Labs, a business conducted by Eugene Boondock (full legal name Eugene Loyiso Mzimakhwe) in South Africa.

Still outstanding before this document is complete: a registration number, a business address, registration of the Information Officer with the Information Regulator. These are stated as missing rather than left out.

2. When this applies

This agreement applies where you use the assessment in the course of an organisation’s activities and, in doing so, cause personal information for which your organisation is the responsible party to be processed by us.

In the ordinary case this is a narrow set: your own name, your email address, and whatever your answers happen to describe. The assessment is deliberately designed so that you never need to submit personal information about customers, staff or patients, and we ask you not to.

For our own processing of your information as a user of this website, we are the responsible party, and the privacy notice governs it.

3. Roles

PartyRoleResponsibility
Your organisationResponsible partyDetermines the purpose and means. Decides what is submitted and holds the lawful basis for it
aireadinessOperatorProcesses only on your documented instruction, which for this service means: conduct the assessment, score it, and produce the outputs you asked for
OpenAI, Cloudflare, PayFastSub-operatorsProcess on our instruction for the specific purposes set out in the trust centre

4. Our obligations as operator

Under section 21 of POPIA and this agreement, we will:

  • Process personal information only for the purpose of providing the assessment and the outputs you requested, and only on your instruction. Using it for our own purposes would make us a responsible party for it, and we do not.
  • Treat the information as confidential and not disclose it except as set out here or where compelled by law.
  • Maintain the security safeguards described in section 5 below and in the trust centre.
  • Notify you without undue delay where we have reasonable grounds to believe the information has been accessed or acquired by an unauthorised person, so that you can meet your own obligation under section 22.
  • Assist you, so far as we reasonably can, in responding to a data subject exercising their rights.
  • Delete the information on request, or at the end of the retention period, except where law requires us to keep it.

5. Sub-operators

We use the sub-operators listed in the trust centre. Each is engaged under terms that impose obligations no less protective than these, and we remain responsible to you for their processing.

Cross-border processing. The assessment conversation is processed by OpenAI in the United States. Records are stored in the European Union. By using the assessment you instruct us to make these transfers. If your organisation cannot lawfully permit them, do not use the assessment.

We will give notice on this page before adding or replacing a sub-operator that processes assessment content.

6. Security measures

  • Encrypted transport for all traffic. No unencrypted path exists.
  • Session-scoped authorisation checked on every read, so an identifier alone does not grant access to an assessment.
  • Private object storage for reports, served only by short-lived signed links.
  • Secrets held in a managed secret store, outside the codebase.
  • Payment notifications verified by signature and confirmed with the provider before any entitlement is granted.

We hold no independent security certification. There is no ISO 27001, no SOC 2 and no third-party penetration test. If your procurement process requires one, we do not currently meet it, and we would rather tell you now than at the end of a questionnaire.

7. Breach notification

We will notify your nominated contact by email as soon as reasonably possible, and in any event within 72 hours of becoming aware. The notification will describe what happened, what categories of information were involved, what we have done, and what we recommend.

We will notify while our understanding is still incomplete rather than wait until the picture is settled, and follow up as we learn more. The obligation to notify the Information Regulator under section 22 remains yours as responsible party, and we will give you what you need to do it.

8. Deletion and return

On written request we will delete the personal information processed under this agreement and confirm when it is done. We aim to complete within 7 working days and will not exceed 30.

The exception is payment records, which we retain for 5 years because South African tax law requires it. These contain the transaction amount, date, reference and the email address the payment was made under.

9. Audit

We will answer reasonable written questions about our processing and provide what documentation we have. We do not currently accommodate on-site audits, and we have no third-party audit report to offer. This is a limitation of a small operator, stated plainly rather than deflected.

10. Liability and term

This agreement takes effect when you first submit an assessment on behalf of an organisation and continues until the information has been deleted. Sections 3, 6 and 7 survive termination.

Liability under this agreement is subject to the limits in the terms of use, except where POPIA does not permit limitation.

11. Contact

For anything under this agreement, including breach notification contacts and deletion requests: hello@aireadiness.co.za.

If your organisation requires a countersigned agreement on your own paper, email us. We would rather sign yours than insist on ours.