Mat Hartley

Privacy Policy

Effective date: 14 July 2026
Last updated: 14 July 2026

Mat Hartley Consulting (“MHC”, “we”, “us” or “our”) respects your privacy and is committed to processing personal information lawfully, fairly and transparently. This policy explains how we collect, use, store, share and protect personal information through mathartley.com, Agency Command at clients.mathartley.com, our consulting services, and the marketing systems we operate for clients.

This policy is intended to support compliance with South Africa’s Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable privacy laws. It should be read together with any client agreement, data-processing terms or platform-specific notice that applies to a particular service.

1. Who we are and our role

Mat Hartley Consulting is a sales, marketing and technology consultancy based in Ballito, KwaZulu-Natal, South Africa. Agency Command is our multi-client marketing intelligence and execution platform.

For information collected directly from our website visitors, prospects, customers and platform users, MHC is generally the responsible party. When we process leads, customer records, analytics or marketing data on behalf of a client, the client is generally the responsible party and MHC acts as its operator, following the client’s instructions and agreed approval policy.

2. Information we collect

Depending on how you interact with us, we may process:

  • Identity and contact information: name, business name, job title, email address, telephone number and LinkedIn or other professional profile details.
  • Account information: user ID, access role, authentication events, organisation membership and security records.
  • Enquiry and CRM information: messages, lead source, status, sales stage, follow-up activity, deal value and related business correspondence.
  • Website and analytics information: pages viewed, sessions, referral source, search queries, device and browser information, approximate location, campaign interactions and conversion events.
  • Advertising and social information: campaign, audience, spend and performance data; Page or account identifiers; organic posts, comments and engagement statistics.
  • Connected-platform information: data made available through authorised integrations with services such as Google Analytics, Google Search Console, Google Ads, Meta, LinkedIn, Zoho CRM and WordPress.
  • Content and brand information: brand guidelines, approved assets, product or service information, content drafts and publishing history.
  • Technical and security information: IP address, logs, timestamps, connector status, error records and information needed to prevent fraud or unauthorised access.

We do not intentionally collect special personal information or information about children through Agency Command. Clients must not connect or upload such information unless an appropriate lawful basis and written safeguards have been agreed.

3. How we obtain information

We receive information directly from you; from our clients and their authorised staff; from websites, forms and CRM systems; from cookies and analytics tools; and from third-party platforms that an authorised user chooses to connect. OAuth connections are only made after an authorised user approves the permissions displayed by the relevant platform.

4. Why we process information

We process information where it is necessary to:

  • respond to enquiries and provide requested services;
  • perform a contract or take steps requested before entering a contract;
  • operate, secure, support and improve Agency Command;
  • connect authorised marketing, analytics, CRM and publishing accounts;
  • measure marketing performance, attribute leads and identify commercial opportunities;
  • prepare reports, recommendations, tasks, audience plans and content;
  • create and, where authorised, schedule or publish marketing content;
  • maintain records, prevent misuse and comply with legal obligations;
  • communicate service updates and, where permitted, relevant marketing; and
  • pursue legitimate business interests that do not unjustifiably prejudice a data subject.

Where consent is the appropriate basis, it may be withdrawn at any time. Withdrawal does not affect processing that was lawful before withdrawal.

5. AI-assisted processing and human oversight

Agency Command may use artificial intelligence to summarise performance data, identify patterns, recommend tasks, create drafts and prepare campaign or audience proposals. AI output may be incomplete or incorrect and is subject to the client’s configured approval and autonomy controls.

We do not intend to make decisions that produce legal or similarly significant effects about individuals solely through automated processing. Paid campaign launches, material budget changes, CRM sends and other higher-risk actions require the level of human approval agreed with the client. Clients remain responsible for reviewing output and for the lawfulness and accuracy of instructions, source data and published material.

6. Connected accounts and permissions

Access tokens and connector credentials are encrypted and stored separately from ordinary application records. We request only the permissions reasonably required for the enabled feature. A connection may be revoked through Agency Command or the relevant third-party platform. Revocation stops future access but does not automatically delete information already processed lawfully.

Each connected service is also governed by its own privacy policy and terms. We are not responsible for how an independent platform processes information in its own capacity.

7. When we share information

We do not sell personal information. We may disclose it only as reasonably necessary to:

  • the client that controls the relevant workspace and its authorised users;
  • technology and professional service providers that support hosting, databases, security, analytics, AI processing, communications and authorised publishing;
  • connected platforms at the direction of an authorised user;
  • advisers, auditors, insurers or prospective business successors subject to appropriate confidentiality; or
  • regulators, law-enforcement bodies or other persons where required or permitted by law.

Our principal technology providers may include Vercel, Supabase, OpenAI, Google, Meta, LinkedIn, Zoho and WordPress-related hosting or service providers. Providers are given access only for defined purposes and are expected to apply appropriate safeguards.

8. International transfers

Some providers process or store information outside South Africa. Where personal information is transferred across borders, we take reasonable steps to use providers and contractual or other safeguards that offer an adequate level of protection consistent with POPIA and applicable client obligations.

9. Security

We use reasonable technical and organisational safeguards appropriate to the nature of the information, including tenant separation, role-based access controls, encrypted connector credentials, secure transport, audit records, restricted administrative access and monitoring. No internet service can guarantee absolute security.

If we become aware of a security compromise involving personal information, we will investigate and notify the responsible party, affected persons and/or the Information Regulator where required by law.

10. Retention

We retain personal information only for as long as needed for the stated purpose, to provide the service, to meet contractual or legal requirements, to resolve disputes or to protect legitimate interests. Retention periods vary by record type and client instruction.

Connector credentials are removed or made unusable when a connection is revoked or the service ends, subject to secure backup cycles. Aggregated or de-identified performance information may be retained where it no longer identifies an individual. On termination, client data is returned, deleted or de-identified as agreed and subject to legal retention duties.

11. Cookies and similar technologies

Our websites and platform may use essential cookies for sign-in, security and session continuity, and analytics technologies to understand usage and improve services. Advertising or non-essential technologies will be used in accordance with applicable consent and platform requirements. Browser settings can restrict cookies, although this may affect functionality.

12. Direct marketing

We send electronic marketing only where permitted by POPIA and other applicable rules. You may opt out at any time using the unsubscribe method provided or by contacting us. Service, security and transactional communications are not marketing and may still be sent where necessary.

13. Your rights

Subject to applicable law and verification of your identity, you may ask us to:

  • confirm whether we hold personal information about you;
  • provide access to that information;
  • correct, update or delete inaccurate, excessive, outdated or unlawfully obtained information;
  • object to certain processing or withdraw consent;
  • stop direct marketing; and
  • explain relevant automated processing and request appropriate human review.

Where information is controlled by one of our clients, we may refer the request to that client and assist it as operator. We may retain limited information where required by law or where a recognised legal exception applies.

14. Contact and complaints

Information Officer / privacy contact: Mat Hartley
Organisation: Mat Hartley Consulting
Location: Ballito, KwaZulu-Natal, South Africa
Email: mat@mathartley.com
Telephone: +27 61 523 1804

Please contact us first so that we can investigate and respond. You also have the right to lodge a POPIA complaint with South Africa’s Information Regulator through its eServices portal or at POPIAComplaints@inforegulator.org.za. Current contact details are available at inforegulator.org.za.

15. Changes to this policy

We may update this policy when our services, providers or legal obligations change. The latest version will be published on this page with a revised date. Material changes may also be communicated directly to affected clients or users where appropriate.