Data Protection FAQ
Frequently Asked Questions About GDPR & POPIA Compliance for Automize RPA Clients.
This FAQ helps clients understand how personal data is handled within the Automize ecosystem, what your responsibilities are as the Data Controller, and how we protect data as your Data Processor (or sub-processor, depending on the implementation).
1. Who is the Data Controller and who is the Data Processor?
Data Controller (You – the Client)
You determine:
- What data is processed
- Why it is processed
- How long it is stored
- Which users may access your systems
Because your Automize bot runs on your own PC, laptop, server, or virtual desktop, you remain the Data Controller at all times.
Data Processor (Automize)
Automize processes limited metadata (audit logs, workflow definitions, bot statistics) on your behalf and never takes custody of your client data unless explicitly required for support.
2. Where is my data stored?
Bot Data (Operational / Runtime Data)
- Stored locally on your machine (PC, laptop, VM, server).
- Includes:
- Logs
- Screenshots (if enabled)
- Temporary files
- Credential vault data
- This information never leaves your internal environment unless you choose to upload it.
Platform Data (Configuration / Process Library)
- Stored securely on AWS (Amazon Web Services).
- AWS regions used: EU (for GDPR alignment) or South Africa (for POPIA alignment), depending on your implementation.
- All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Support Data
Only if you request help:
- You may upload logs or screenshots to the Support Portal.
- These are stored securely in AWS and deleted when no longer required.
3. Does Automize have access to the data my bot processes?
No.
Automize does not have any access to:
- Your files
- Screenshots
- Runtime logs
- End-user systems
- Banking platforms
- Shared drives
- Email systems
- Internal networks
The bot runs entirely on your infrastructure. Nothing is transmitted back to Automize unless you manually send it (e.g., for troubleshooting).
4. How long does Automize keep my data?
System Configurations (Processes, workflows, metadata)
- Retained for the duration of your subscription.
Support Files (logs, screenshots, samples you submit)
- Deleted within 30 days of issue resolution, unless otherwise agreed.
Billing, contract & account data
- Retained according to tax and legal retention rules (typically 5 years).
Automize never stores operational data processed by your bot.
5. What happens to my data if I cancel my subscription?
Upon cancellation:
- Your portal account is disabled.
- Process configurations are stored for 30 days in case reactivation is needed.
- After 30 days:
- All Automize-hosted configuration data is permanently deleted.
- Audit logs, usage metadata and analytics are anonymised (cannot be linked to you).
- Your local bot logs remain on your device, not ours.
We do not retain any personal data processed by your bots.
6. Can Automize assist with Data Subject Requests (DSRs)?
Yes – to the extent our system contains personal data.
DSRs include:
- Access requests
- Rectification
- Erasure
- Restriction of processing
- Objections
We support:
- Deletion or export of any portal-level metadata
- Export and erasure of logs stored on Automize’s servers
- Confirmation of what we do / do not store
We cannot fulfil DSRs for:
- Data on your devices
- Screenshots stored locally
- Files processed by your bot
Those remain your responsibility as the Data Controller.
7. Does the screenshot feature collect personal or sensitive data?
Yes – potentially.
If screenshots are enabled:
- Anything visible on your screen may be captured
- This may include personal information, banking data, IDs, HR data, financial data
Clients must:
- Inform employees (POPIA requirement)
- Confirm purpose and lawful basis for capturing screenshots
- Disable screenshots if processing highly sensitive or regulated data
Automize provides this feature as optional – you control usage.
8. Is the Automize platform GDPR and POPIA compliant?
Yes. Automize follows:
- POPIA (South Africa)
- GDPR (UK & EU where applicable)
- AWS infrastructure compliance standards
- Modern encryption standards (AES-256, TLS 1.2+)
- Access controls, audit logs and role-based permissions
- Secure credential handling (never transmitted to Automize)
9. How secure is my information when using Automize?
Automize uses:
- AES-256 encryption at rest
- TLS 1.2+ in transit
- IAM role-based access controls
- Zero-trust architecture for internal staff
- No access to your bot sessions
- Secure audit logging
- Segregated client environments
Your local machine remains the primary security perimeter.
A separate “Client-Side Security Checklist” (Document #2) is provided to help secure your device.
10. Does Automize use my data to train AI models?
No.
We never use client data, logs, screenshots, or process details to train any AI models.
Automize’s platform is strictly controlled and isolated.
11. Can Automize view or access my credentials?
No.
Credentials stored in:
- Windows Credential Manager
- macOS keychain
- Linux secret stores
- Automize’s local encrypted vault
…are never transmitted to Automize servers.
Your credentials remain yours.
12. What should I do if I experience a potential data breach?
Follow your internal incident response policy, and then:
Notify Automize within 24 hours:
Include:
- Description of the incident
- Systems affected
- Time of detection
- Type of data involved (if known)
- Steps already taken
We will:
- Assist with containment (if platform-related)
- Provide required logs and evidence
- Support regulatory reporting (POPIA requires notification)
13. Are there any client responsibilities under POPIA/GDPR?
Yes – as Data Controller, you must:
✓ Protect endpoints
(antivirus, encryption, screen locks, updates)
✓ Secure the bot environment
(least privilege accounts, proper firewall rules)
✓ Inform your employees
(if screenshots or logs may capture personal data)
✓ Obtain consent where required
(depending on your data processing model)
✓ Ensure lawful basis for processing
(contract, legitimate interest, legal obligation, etc.)
✓ Maintain your own backup and retention policy
✓ Notify regulators if YOU experience a breach
(required under GDPR/POPIA)
Automize can assist but cannot perform these steps on your behalf.
14. Can we process personal data using RPA bots?
Yes – provided you meet your legal obligations under POPIA/GDPR.
RPA does not change your compliance requirements.
Bots simply act as extensions of your employees.
15. How should we handle logs that contain sensitive information?
If logs contain IDs, account numbers, salaries, or health data:
Clients should:
- Restrict access to logs
- Encrypt logs or folders
- Apply proper retention policies
- Delete logs once no longer required
- Disable verbose logging where unnecessary
A full Log File Security Guide accompanies this FAQ.