Privacy Policy

Last updated: 7 July 2026

HasMyBrandChanged is operated by The Druff Technology Group, based in South Africa. This Privacy Policy explains how we collect, use, store, transfer and protect personal information when you use HasMyBrandChanged.

This policy is written for South African POPIA compliance and is intended to provide GDPR-aligned and international privacy disclosures where applicable. If you have privacy questions, contact us at support@hasmybrandchanged.com.

1. Who we are

HasMyBrandChanged is a software service that checks whether documents, graphics, presentations and marketing assets are still on-brand.

For South African users, The Druff Technology Group is the responsible party under the Protection of Personal Information Act, 2013 (POPIA). For users in the European Economic Area or United Kingdom, we act as the data controller where we determine the purposes and means of processing personal data.

Our privacy contact and Information Officer contact is support@hasmybrandchanged.com.

2. Information we collect

Account information. Name, email address, company or workspace name, password credentials managed by our authentication provider, and user role and workspace permissions. We do not store plain-text passwords.

Brand Blueprint information. Logos, brand colours, font information, brand guidelines, brand reference files, website reference information, and notes or settings added by users.

Uploaded review assets. Documents, graphics, presentations, PDFs, images or other marketing assets uploaded for review. These files may contain personal information or confidential business information if included by the user.

Review results and metadata. Brand Compliance Score, review findings, page-level issue metadata, confidence levels, file name, upload date, the user who created the review, and processing status.

Billing information. When paid subscriptions are enabled, billing will be handled by our payment provider or merchant of record. We do not store full card numbers. We may receive subscription status, plan details, billing contact information, payment status and invoice metadata.

Technical and usage information. IP address, browser type, device information, pages visited, login events, upload events, error logs and security logs. We use this information to operate, secure and improve the Service.

3. How we use information

We use information to:

  • Provide the Service
  • Create and manage accounts
  • Create and manage Brand Blueprints
  • Analyse uploaded assets
  • Generate review results
  • Display review history
  • Provide customer support
  • Send transactional emails
  • Manage subscriptions and billing
  • Monitor security
  • Prevent fraud, abuse and unauthorised access
  • Comply with legal obligations

We do not sell personal information. We do not use customer content for advertising.

4. Legal bases for processing

Where applicable law requires a legal basis, we process personal information on one or more of the following bases:

  • To perform our contract with you or your organisation
  • To operate and secure the Service
  • To comply with legal obligations
  • With your consent where required
  • For legitimate interests, such as fraud prevention, service improvement, support and security

5. AI processing

HasMyBrandChanged uses automated systems, including AI models, to analyse uploaded assets against a customer’s Brand Blueprint. When a review is submitted, relevant uploaded assets and Brand Blueprint information may be sent to an AI provider for analysis. The AI provider processes the information only to return review findings to the Service.

Customer content is not used by HasMyBrandChanged to train AI models. Where we use commercial AI APIs, we rely on provider terms that state API inputs and outputs are not used to train their general models unless separately opted in or otherwise agreed.

AI-generated review results may contain errors, omissions or inaccuracies. Users remain responsible for reviewing results before relying on them.

6. Customer content ownership

You retain all rights to the content you upload, including logos, brand guidelines, documents, graphics, presentations, marketing assets, fonts and related brand material. We do not acquire ownership of your uploaded assets, trademarks, logos, designs, documents or Brand Blueprints.

You grant us a limited licence to host, process, analyse, display and transmit your content solely as necessary to provide the Service.

7. Confidentiality

We treat uploaded customer materials as confidential. Access to customer content is limited to:

  • Providing the Service
  • Troubleshooting support issues
  • Investigating security concerns
  • Preventing abuse
  • Complying with legal obligations
  • Actions authorised by the customer

We do not manually review customer content unless necessary for support, security, abuse prevention or legal compliance.

8. Sub-processors and service providers

We use third-party providers to operate the Service. Current or planned providers may include:

  • Supabase — authentication, database and storage
  • Anthropic — AI analysis
  • Resend — transactional email
  • Payment provider or merchant of record — billing and subscriptions
  • Hosting provider — application hosting

These providers process information only as needed to provide services to us. We may update our providers as the Service evolves.

9. International transfers

We are based in South Africa, but our users and service providers may be located globally. Your information may be processed in countries outside your country of residence, including countries that may not provide the same level of data protection. Where required, we rely on appropriate safeguards, including contractual commitments, data processing agreements and recognised transfer mechanisms.

10. Data retention

Uploaded review asset files are retained according to your workspace retention settings. The default retention period is 90 days, unless configured differently. Review results, scores, findings and metadata may be retained for review history unless deleted by the user or workspace administrator.

If you delete your account, we will delete or anonymise personal information within a reasonable period, except where retention is required for legal obligations, billing records, security logs, fraud prevention, dispute resolution or backup retention.

11. File deletion

When an uploaded file is deleted, the original file is removed from active storage where technically feasible. Review metadata and findings may remain unless the review is also deleted. Backup copies may persist for a limited period before automatic deletion.

12. Security

We use reasonable technical and organisational measures to protect information, including:

  • Encrypted connections
  • Private storage buckets
  • Signed access URLs where required
  • Tenant isolation
  • Row-level security
  • Role-based access controls
  • Restricted production access
  • Server-side validation
  • Audit logging
  • Monitoring for abuse or unauthorised access

No system is perfectly secure. We cannot guarantee absolute security, but we take reasonable steps appropriate to the nature of the information processed. If we become aware of a security incident affecting personal information, we will take reasonable steps to investigate, contain and notify affected parties or regulators where required by law.

13. Multi-tenant data isolation

HasMyBrandChanged is a multi-tenant SaaS application. Each customer workspace is logically separated. Users should only access data belonging to workspaces where they are authorised members.

If you believe you have accessed another customer’s information, or another customer has accessed yours, contact us immediately at support@hasmybrandchanged.com.

14. Cookies

We use essential cookies and similar technologies to keep users signed in, secure sessions, prevent abuse and remember basic preferences. We do not currently use advertising or cross-site tracking cookies. If analytics or marketing cookies are added later, we will update this policy and provide any required consent controls.

15. Your rights

Depending on your location, you may have rights to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Delete information
  • Object to certain processing
  • Restrict processing
  • Request data portability
  • Withdraw consent where processing is based on consent

To exercise these rights, contact support@hasmybrandchanged.com. We may need to verify your identity before responding.

16. South African users

If you are in South Africa and are not satisfied with our response, you may contact the Information Regulator: inforegulator.org.za.

17. EEA and UK users

If GDPR or UK GDPR applies, you may have the right to lodge a complaint with your local data protection authority. You may also contact us first so we can try to resolve your concern.

18. United States and California users

Where applicable United States state privacy laws apply, you may have rights to access, delete, correct or receive a copy of certain personal information. We do not sell personal information. We do not share personal information for cross-context behavioural advertising. To submit a privacy request, contact support@hasmybrandchanged.com.

19. Children

The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 18.

20. Changes to this policy

We may update this Privacy Policy as the Service evolves. If changes are material, we will notify account holders by email or in-app notice where appropriate. The updated version will always show the latest effective date.

21. Contact

For privacy questions, contact support@hasmybrandchanged.com.