[ Anorion OS ]

Privacy
Policy.

Version 1.0  ·  Effective Date: 27 May 2026  ·  Last Updated: 27 May 2026

This Privacy Statement ("Statement") applies to the processing activities for which Anorion Dynamics and its affiliates ("Anorion Dynamics", "we", "us", "our") act as responsible party or data controller on their own behalf. This Statement does not cover the processing of personal information by our clients using Anorion CSIP, as we act solely as operator or data processor for such processing activities.

Anorion Dynamics is incorporated in the Republic of South Africa and subject to the Protection of Personal Information Act 4 of 2013 ("POPIA"). Where our services are accessed by clients or individuals located in the European Union or United Kingdom, the General Data Protection Regulation ("GDPR") and UK GDPR apply to the processing of personal data of individuals in those jurisdictions to the extent applicable.

Where we refer to "Anorion Dynamics", "we", "us", or "our" in this Statement, we are referring to Anorion Dynamics, the entity that determines how and why your personal information is used in the contexts described herein.

01 // RESPONSIBLE PARTY & DATA CONTROLLER

Anorion Dynamics is the responsible party as defined under POPIA and the data controller as defined under GDPR in respect of personal information processed in connection with the operation of our business, including through the Anorion CSIP platform and our corporate website.

In respect of personal information of individuals detected, monitored, or recorded at premises where Anorion CSIP is deployed by our clients, those clients are the responsible party and data controller. Anorion Dynamics processes such information solely as operator and data processor, acting on documented instructions from the client. Individuals seeking to exercise rights in respect of surveillance data collected at a client's premises should direct their requests to the relevant client organisation.

For all privacy-related enquiries, rights requests, or complaints in respect of processing for which Anorion Dynamics is the responsible party, contact our designated Information Officer at privacy@anoriondynamics.com.

02 // SCOPE OF THIS STATEMENT

This Statement governs the collection, use, storage, and disclosure of personal information by Anorion Dynamics in the following contexts:

Platform Subscribers. Individuals and organisations that subscribe to Anorion CSIP through our authorised distribution channels, including the processing of identity and subscription data necessary to provision and manage platform access.

Platform Users. Security operators, team members, and other personnel authorised by a subscriber organisation to access and operate the Anorion CSIP platform.

Website Visitors. Individuals who visit anoriondynamics.com or any other web property operated by Anorion Dynamics.

Business Contacts. Individuals whose contact and professional information we process in the course of business development, sales, and client relationship management.

This Statement does not apply to personal information processed by Anorion Dynamics on behalf of clients as operator. Where we are operator, we process personal information solely on the client's documented instructions, in accordance with the applicable data processing agreement. Clients bear primary legal responsibility as responsible party for the lawfulness of surveillance operations conducted using Anorion CSIP at their premises.

03 // PERSONAL INFORMATION WE COLLECT

A. Subscriber & Identity Data

Upon subscription to Anorion CSIP through an authorised distribution channel, we collect and process identity information transmitted by the identity and subscription management platform used to authenticate the subscribing party. This includes the subscriber's display name, email address, unique identity object identifier, and user principal name, together with subscription identifiers, selected plan type, and organisation name where provided. This information is collected solely for the purpose of provisioning and managing the subscriber's platform account.

B. Platform User Data

We collect and process the name, email address, assigned operational role, and activity records of individuals provisioned as platform users by a subscribing organisation. Where users opt to configure alert notifications, we process the contact details provided for that purpose, including mobile telephone numbers. We maintain access logs and audit records of user activity within the platform for security and governance purposes.

C. Security Detection Data (Processed as Operator)

In our capacity as operator on behalf of subscribing clients, Anorion CSIP processes security event data, detection imagery, and localized biometric templates generated by connected camera and sensor infrastructure at the client’s premises. The processing of this data is governed strictly by the applicable data processing agreement with the client as the responsible party.

The localized biometric templates, used for subject re-identification across the surveillance grid, constitute special personal information under POPIA and sensitive personal data under GDPR. Such data is processed exclusively for the physical security and threat prevention purposes contracted by the client, and is subject to strict operational access, de-identification, and automated pruning controls.

D. Technical & Usage Data

We collect technical data generated through your interaction with the Anorion CSIP platform and our web properties, including device identifiers, IP addresses, browser and operating system information, session data, and usage analytics. This data is used to maintain platform security, diagnose technical issues, and improve platform performance.

E. Business Contact Data

In the course of business operations, we process contact and professional information of individuals at prospective and existing client organisations, including names, job titles, business email addresses, and telephone numbers. This information is collected through direct interaction, business introductions, and publicly available professional sources.

04 // HOW AND WHY WE USE PERSONAL INFORMATION

To provide and manage platform subscriptions

We process subscriber identity and subscription data to provision platform access, authenticate users, manage subscription lifecycle events including activation, renewal, modification, and termination, and to fulfil our contractual obligations to the subscribing organisation.Legal basis: Performance of contract.

To deliver platform services

We process platform user data and, as operator, security detection data to deliver the operational capabilities of Anorion CSIP, including threat detection, intelligence generation, alert distribution, audit trail maintenance, and conversational querying of security data.Legal basis: Performance of contract (platform users); operator instructions (detection data).

To communicate with you

We use subscriber and user contact information to send transactional communications including subscription confirmations, platform notifications, security alerts, support correspondence, and material updates to this Statement or our terms of use.Legal basis: Performance of contract; legitimate interests.

To maintain platform security and integrity

We process technical and usage data to detect, investigate, and respond to security incidents, prevent unauthorised access, monitor for abuse, and maintain the integrity and availability of the platform infrastructure.Legal basis: Legitimate interests.

To improve and develop our platform

We process aggregated and anonymised usage data to analyse platform performance, identify areas for improvement, and develop new capabilities. No identifiable personal information is used for this purpose.Legal basis: Legitimate interests.

To comply with legal obligations

We process personal information as necessary to comply with applicable law, including tax and accounting obligations, responses to lawful regulatory and law enforcement requests, and the fulfilment of data subject rights.Legal basis: Legal obligation.

For sales and business development

We process business contact data to communicate with prospective and existing clients about Anorion CSIP, respond to enquiries, and manage commercial relationships. Where we send marketing communications, we do so on the basis of legitimate interests or, where required by applicable law, with your consent.Legal basis: Legitimate interests; consent where required.

Anorion Dynamics does not use personal information for advertising, does not sell or commercially exploit personal information to third parties, and does not process personal information for purposes beyond those described in this Statement.

05 // AUTOMATED DECISION-MAKING

Anorion CSIP performs automated processing that produces assessments and classifications with potential real-world impact on individuals. The platform's automated processing includes breach classification, threat stage determination, injury risk scoring, behavioural anomaly assessment, watchlist matching, and subject re-identification across camera networks. These automated assessments are generated continuously as part of the platform's core security intelligence function.

All automated assessments produced by the platform are presented to a human security operator who retains sole authority over any consequential intervention decision. The platform does not autonomously direct physical action or dispatch response personnel. Automated classifications serve as intelligence inputs to human decision-making, not as final determinations.

Individuals who are subject to automated processing by the platform may have the right to object to such processing, to request human review of classifications that have affected them, and to receive an explanation of the basis for an automated assessment. Requests should be directed to the client organisation operating the relevant premises as responsible party, or to Anorion Dynamics at privacy@anoriondynamics.com where Anorion Dynamics is the appropriate point of contact.

06 // SPECIAL CATEGORIES OF PERSONAL INFORMATION

In its capacity as operator on behalf of subscribing clients, Anorion CSIP processes categories of personal information that attract heightened protection under applicable data protection law. These include biometric data generated through the platform's subject re-identification capabilities, and visual appearance data produced by AI-assisted analysis of detection imagery. Such data constitutes special personal information under POPIA and sensitive personal data under GDPR.

The processing of special category data through Anorion CSIP is conducted solely for the physical security and threat detection purposes contracted by the client as responsible party. Clients are required under their agreements with Anorion Dynamics to establish and document a lawful basis for the processing of special category data at their premises, including where required a documented legitimate interest assessment, and to ensure that appropriate notices are displayed at all monitored locations.

Anorion Dynamics implements heightened access controls, enhanced audit logging, and accelerated deletion protocols in respect of special category data processed through the platform.

07 // DISCLOSURE OF PERSONAL INFORMATION

Anorion Dynamics does not sell, rent, or commercially exploit personal information. We disclose personal information only in the following circumstances:

Service Providers

We engage third-party service providers to support the delivery of Anorion CSIP and our business operations. These providers process personal information solely on our documented instructions and are contractually bound to maintain confidentiality, implement appropriate security measures, and process personal information only for the purposes for which it was disclosed. Service providers are engaged for functions including infrastructure hosting, email delivery, AI inference processing, and identity authentication. We do not disclose the identities of individual service providers in this Statement, as the specific providers engaged may change from time to time. Material changes to our service provider arrangements that affect the processing of personal information will be communicated to affected subscribers.

Corporate Transactions

In connection with any merger, acquisition, restructuring, sale of assets, or similar corporate transaction involving Anorion Dynamics, personal information may be transferred to the relevant counterparty as part of that transaction, subject to equivalent data protection obligations.

Legal & Regulatory Requirements

We may disclose personal information where required to do so by applicable law, regulation, court order, or lawful request of a regulatory or law enforcement authority. Where legally permissible, we will notify the affected subscriber or individual prior to such disclosure and will limit the scope of any disclosure to what is strictly required.

Protection of Rights

We may disclose personal information where necessary to protect the rights, property, or safety of Anorion Dynamics, our clients, or others, including for the purposes of fraud prevention and the investigation of suspected unlawful activity.

08 // INTERNATIONAL TRANSFERS

Anorion Dynamics operates globally and engages service providers located in multiple jurisdictions. Accordingly, personal information processed by us may be transferred to and stored in countries other than the Republic of South Africa. Where personal information is transferred to a jurisdiction that does not provide an equivalent level of data protection to that afforded under POPIA or GDPR, we implement appropriate safeguards to ensure that the transfer is conducted in accordance with applicable law.

Such safeguards include data processing agreements incorporating standard contractual clauses approved by the applicable regulatory authority, and binding contractual obligations requiring recipient parties to maintain data protection standards consistent with those applicable to us. You may request information regarding the specific safeguards applicable to any international transfer of your personal information by contacting us at privacy@anoriondynamics.com.

09 // RETENTION OF PERSONAL INFORMATION

We retain personal information for as long as is necessary for the purposes for which it was collected, in accordance with this Statement and applicable law. The criteria we apply in determining retention periods include: the duration of an active subscription or business relationship; the period necessary to fulfil contractual obligations; the period required to comply with applicable legal, regulatory, tax, and accounting obligations; the period necessary to resolve disputes, establish legal defences, and enforce our agreements; and our internal risk management and security requirements.

Upon termination or expiration of a subscription, Anorion Dynamics will delete or irreversibly anonymise all personal information associated with the relevant account within the period specified in the applicable subscription agreement, save for information that we are required or permitted to retain under applicable law. Billing records and financial transaction data are retained for the period required under South African tax legislation.

Security detection data processed as operator on behalf of a client is retained in accordance with the retention policy configured by that client as responsible party, subject to the minimum and maximum retention periods specified in the applicable service agreement.

10 // SECURITY

Anorion Dynamics implements and maintains technical and organisational security measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. Our security programme encompasses encryption of personal information in transit and at rest, role-based access controls enforcing the principle of least privilege, multi-factor authentication for administrative access, intrusion detection and prevention systems, continuous security monitoring and logging, vulnerability management, penetration testing in accordance with our annual security assessment policy, and a documented incident response process.

The security of personal information also depends in part on the measures taken by subscribers and users to protect their account credentials and access devices. Subscribers are responsible for maintaining the confidentiality of platform access credentials and for ensuring that access to the platform is restricted to authorised personnel.

In the event of a personal information breach, Anorion Dynamics will notify affected clients and relevant supervisory authorities in accordance with applicable data protection law and will take all steps reasonably necessary to contain and remediate the breach and mitigate its impact on affected individuals.

11 // MINORS

Anorion CSIP is a business-to-business platform not directed at individuals under the age of 18. We do not knowingly collect personal information directly from minors in connection with our own business operations.

In the context of security deployments at commercial premises, minors may be incidentally detected as part of legitimate premises surveillance conducted by the client as responsible party. Such processing is not initiated or directed by Anorion Dynamics. Clients are required under their agreements with Anorion Dynamics to ensure that their surveillance operations, including any incidental processing of data of minors, are conducted on a lawful basis and in compliance with applicable law, including any requirements specific to the processing of personal information of children. The legal basis for such processing is the legitimate security interest of the client organisation, not consent.

12 // YOUR RIGHTS

Depending on the jurisdiction in which you are located, you may have the following rights in respect of personal information processed by Anorion Dynamics as responsible party or data controller. These rights are not absolute and are subject to the limitations and exceptions provided under applicable law, and may be restricted or denied where their exercise would compromise national security, active law enforcement investigations, the prevention and detection of crime, or the physical safety of others.

Right of Access

You may request confirmation of whether we process personal information about you and, where we do, access to that personal information together with information about how it is processed.

Right to Rectification

You may request correction of personal information that is inaccurate, incomplete, or misleading. This right is subject to our ability to verify the accuracy of the information you provide.

Right to Erasure

You may request deletion of your personal information where we no longer have a lawful basis to retain it, where you have withdrawn consent on which processing was based, or where the personal information has been processed unlawfully. This right does not apply where retention is required to comply with a legal obligation, for the establishment, exercise, or defence of legal claims, or on other grounds permitted by applicable law.

Right to Restrict Processing

You may request that we restrict our processing of your personal information in certain circumstances, including while the accuracy of the information is disputed or while an objection to processing is under consideration.

Right to Object

Where we process personal information on the basis of legitimate interests, you may object to that processing. We will honour your objection unless we have compelling legitimate grounds for the processing that override your interests, or where the processing is necessary for the establishment, exercise, or defence of legal claims. You may object to processing for direct marketing purposes at any time and without qualification.

Right to Data Portability

Where processing is based on contract or consent and is carried out by automated means, you may request that we provide your personal information in a structured, commonly used, machine-readable format, or that we transmit it directly to another responsible party where technically feasible.

Right to Withdraw Consent

Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

To exercise any of the above rights, submit a written request to privacy@anoriondynamics.com. We will acknowledge your request promptly and respond within the period required by applicable law. We may require you to verify your identity before processing your request. We will not charge a fee for processing rights requests except where requests are manifestly unfounded or excessive, in which case a reasonable administrative fee may apply.

13 // SOUTH AFRICA — ADDITIONAL DISCLOSURES (POPIA)

Anorion Dynamics is subject to the Protection of Personal Information Act 4 of 2013. Our designated Information Officer, responsible for ensuring compliance with POPIA, may be contacted at privacy@anoriondynamics.com.

If you believe that Anorion Dynamics has interfered with the protection of your personal information as defined under POPIA, you may submit a complaint to the Information Regulator of South Africa at the following address:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street
Braamfontein, Johannesburg, 2001
Email: inforeg@justice.gov.za
Website: www.justice.gov.za/inforeg

We encourage you to contact us directly in the first instance so that we may attempt to resolve your concern before escalation to the Information Regulator.

14 // EUROPEAN UNION & UNITED KINGDOM — ADDITIONAL DISCLOSURES (GDPR / UK GDPR)

Where the EU GDPR or UK GDPR applies to our processing of your personal data, the following additional provisions apply. The rights described in Section 12 of this Statement correspond to the rights afforded under Articles 15 through 22 of the GDPR. These rights are subject to the limitations and derogations provided under the GDPR and applicable national implementing legislation.

Where we transfer personal data from the European Economic Area or the United Kingdom to a third country, we do so only where an adequacy decision applies, or where we have implemented appropriate safeguards in the form of standard contractual clauses adopted by the European Commission or the UK Secretary of State, as applicable. You may request a copy of the applicable transfer mechanism by contacting us at privacy@anoriondynamics.com.

If you are located in the European Economic Area and you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority of the EU Member State in which you are habitually resident, in which you work, or in which the alleged infringement occurred. Details of EU supervisory authorities are available at edpb.europa.eu.

If you are located in the United Kingdom, you may lodge a complaint with the Information Commissioner's Office at ico.org.uk.

15 // UPDATES TO THIS STATEMENT

We may update this Statement from time to time to reflect changes in our processing activities, applicable law, or regulatory guidance. Where we make material changes that affect the rights of individuals whose personal information we process, we will provide notice to affected subscribers by email and will post the updated Statement at anoriondynamics.com/privacy-policy with a revised effective date. Your continued use of Anorion CSIP following notice of a material change constitutes acceptance of the updated Statement. We maintain a version history of this Statement and prior versions are available on request.

16 // CONTACT

For all privacy-related enquiries, rights requests, complaints, or requests for further information regarding this Statement or our data processing activities, contact our Information Officer:

Anorion Dynamics
Information Officer
Cape Town, Western Cape, South Africa
Email: privacy@anoriondynamics.com

Anorion Dynamics  ·  Privacy Policy v1.0  ·  Effective 27 May 2026