Legal · Last updated: July 2026

Privacy policy

This policy explains what personal information Okodi collects when you use our website or contact us, why we collect it, and what you can do about it. It's aligned with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and the General Data Protection Regulation (EU) 2016/679 (GDPR) for visitors in the European Union and United Kingdom.

We've tried to write this in plain language. If something isn't clear, or you'd like more detail on any point, please email us at privacy@okodi.ai.

Who we are

Okodi is a technology studio and product company operating in Namibia and South Africa. In this policy, "Okodi", "we" and "us" refer to Okodi as the data controller (or responsible party under POPIA) for the information described below.

Our operating locations are Windhoek (Namibia), and Gauteng and the Western Cape (South Africa). For all privacy queries, please use the email above.

What we collect and why

Contact form submissions. When you fill in the contact form on okodi.ai/contact, we collect the name, email address, company (optional) and message you provide. We use this information solely to reply to your enquiry and, where relevant, to follow up about a related project.

Direct correspondence. When you email us at hello@okodi.ai, support@okodi.ai or any other Okodi address, we receive your email address and the contents of your message. We use this to answer you.

Basic technical information. Our hosting provider (Vercel) records standard request metadata — the IP address of the request, the browser user agent, the requested URL and the time — as part of running the website. We use this information for security (rate-limiting, abuse prevention) and to keep the site working.

Anonymous usage analytics. We may use Vercel's cookie-less analytics to understand which pages are visited and how the site performs. This does not identify you individually, does not use cookies and does not track you across other websites.

Security check on the contact form. If our contact form is protected by Cloudflare Turnstile, Cloudflare may process technical signals (a challenge token, IP address, browser characteristics) to confirm that the submission comes from a real person and not an automated abuser.

Lawful basis for processing

Under GDPR (and the equivalent POPIA justifications), we rely on the following bases:

Consent — you submit the contact form or email us knowing you will receive a reply. You can withdraw consent at any time (see "Your rights" below).

Legitimate interests — we have a legitimate interest in running our website securely (basic technical logs, rate-limiting, spam prevention) and in understanding what content is useful (anonymous analytics). We balance those interests against your privacy and only collect what is needed.

Legal obligation — we may retain certain records where we're required to do so by law (for example, tax and accounting records for finance-related correspondence).

How long we keep it

Contact form and email correspondence — we retain these for as long as reasonably necessary to complete the conversation and for a further period sufficient to answer follow-up questions. Correspondence not connected to an active relationship is deleted within 24 months.

Server request logs — retained by our hosting provider for a short technical window (typically less than 30 days), used only for troubleshooting and security.

Anonymous analytics — aggregated, non-identifying data may be retained indefinitely; it cannot be traced back to you.

If you want your data deleted sooner, tell us — we'll do it.

Who we share it with

We do not sell your personal information, and we do not share it with anyone who is not directly involved in delivering our service to you. The processors we rely on are:

Vercel Inc. — hosts the website and serves the contact-form serverless function. Vercel processes request metadata (IP, user agent, URL) as part of running the service.

Resend Inc. — sends the transactional email that delivers your contact-form submission to us. Resend processes the name, email address and message you provided.

Cloudflare Inc. — where enabled, provides the Turnstile security check that helps distinguish humans from automated abuse on the contact form.

Google LLC (Google Fonts) — supplies the Poppins, Inter and JetBrains Mono web fonts used by the site. When your browser fetches a font, Google receives standard technical request information (IP, user agent). No account is required and no cookies are set for this.

Each of these providers is subject to their own privacy commitments, and we have chosen them because they publish clear data-processing terms compatible with POPIA and GDPR.

International transfers

Some of our processors (Vercel, Resend, Cloudflare, Google) are based in the United States or process data across multiple regions. Where personal information is transferred outside South Africa or the EU, we rely on those providers' standard contractual clauses, adequacy mechanisms or equivalent protections to ensure the data continues to be treated with the safeguards required by POPIA and GDPR.

Cookies and tracking

At the time of writing, this website does not set any cookies for tracking, advertising or profiling. The Vercel Analytics we use (if enabled) is cookie-less by design. If we ever add functionality that uses cookies, we will update this policy and, where required, ask for your consent.

Your rights

Under POPIA, GDPR and equivalent laws, you have the right to:

Access the personal information we hold about you and receive a copy of it.

Correct information that is inaccurate or out of date.

Delete your personal information, subject to any overriding legal obligations we have to retain it.

Object to our processing where it is based on legitimate interests, and to withdraw any consent you have previously given.

Restrict processing in specific circumstances — for example while we investigate an accuracy complaint.

Portability — receive your data in a common, machine-readable format so you can move it to another provider.

Complain to a supervisory authority: the Information Regulator (South Africa) at inforegulator.org.za, or your local data protection authority if you are in the EU / UK.

To exercise any of these rights, email us at privacy@okodi.ai. We aim to respond within 30 days and will confirm receipt sooner. There's no charge unless a request is unusually onerous, in which case we'll discuss it with you first.

Security

We apply reasonable technical and organisational measures to protect the personal information we hold. These include: HTTPS across the entire site, security response headers (HSTS, CSP, frame protection), server-side rate limiting on our contact endpoint, restricted origin allowlists, honeypot and challenge-based spam protection, and least-privilege access to the tools we use.

No system is perfectly secure. If we ever become aware of a breach affecting your personal information, we will notify you and the relevant supervisory authority in line with our POPIA and GDPR obligations.

Children

This site and our services are aimed at adults working in business. We do not knowingly collect personal information from children. If you believe a child has submitted information to us, please email privacy@okodi.ai and we will delete it.

Changes to this policy

We may update this policy from time to time — for example, if we add a new tool, change how we process something, or if the law changes. The date at the top of this page shows when it was last updated. Material changes will be communicated on this page, and (where we already have a relationship with you) by email.

Governing law

This policy is governed by the laws of the Republic of Namibia. For visitors resident in South Africa, POPIA applies in addition. For visitors in the EU / UK, GDPR and the UK GDPR apply in addition.

Contact

For any privacy-related question, request or complaint, please email privacy@okodi.ai. For general enquiries, use the contact form.

← Back to home