1. Scope and accountable parties
PursuitCore is proprietary software owned by Opticore Alliance and stewarded through Opticore Platforms. In the controlled POC, Digital Unbounded (Pty) Ltd is the OEM Operator. The customer organisation ordinarily determines why and how its tenant information is processed and therefore acts as the POPIA Responsible Party and, where applicable, the GDPR Controller. Operator, hosting and software-provider duties are limited by written authority and the deployment processing schedule.
This controlled operating notice describes the PursuitCore model and does not constitute legal advice. Each deployment must be reviewed against its contracts, processing inventory, infrastructure and applicable law.
2. Information processed
- Account identity, role, invitation, authentication and security records.
- Company readiness records, including approved services, capabilities, certifications, people, partners, references, rate cards and evidence.
- Opportunity packs, extracted requirements, buyer facts, decisions, work assignments, response content, commercial records and generated outputs.
- SCOUT Signal public-source identifiers, notice facts, dates, sectors, award fields and original-source links.
- Audit, source-correction, notification, support and operational-health events required to protect and evidence the service.
3. Purpose, authority and minimisation
Processing must be linked to a recorded business purpose and an appropriate lawful basis selected by the Responsible Party or Controller. PursuitCore does not select a lawful basis on behalf of a customer. Collection is limited to information required for the governed opportunity journey, source assurance, security and contractual operation.
- Public procurement information is retrieved only from identified public sources such as the South African National Treasury eTenders OCDS service.
- Private-sector market signals require a licensed feed, a public corporate notice or a tenant-authorised source. Uncontrolled crawling, private-profile scraping and covert monitoring are prohibited.
- Special personal information and children's information require separately approved authority, necessity and controls.
- Credentials and provider secrets are held in the server secret boundary and are not displayed in the workspace.
4. Assisted analysis and human authority
PursuitCore may extract, classify, compare, calculate, draft and recommend. It presents source links, confidence, corrections and reasons so users can challenge the result. The platform does not replace accountable human Bid/No-Bid approval, pricing authority, legal review, signing or external submission. No decision-readiness score is a probability of winning or a buyer evaluation score.
5. Individual rights
Subject to applicable law, an individual may request access, correction, deletion or restriction, object to processing, withdraw consent where consent is relied upon, complain to the relevant authority, or request meaningful information about assisted processing. Requests are routed to the accountable organisation and handled without exposing another tenant's records.
6. Security, retention and incidents
- Forced tenant row-level security and explicit tenant context on controlled tables.
- Separate Showcase and Pilot data, sessions, secrets, storage and configuration.
- Least privilege, attributable approvals, time-bound support access and auditable administrative actions.
- Retention review, controlled export and authorised deletion rather than indefinite accumulation.
- Incident evidence preservation, assessment and notification cooperation under applicable law and contract.
7. Communications, providers and transfers
The installation administrator may configure an authorised SMTP relay, Microsoft 365 / Graph, Google Workspace or an isolated local proof channel in the server secret boundary. No provider is active merely because PursuitCore supports it. Provider identity, processing location, contractual safeguards and cross-border implications must be recorded before live use.
The controlled POC is intended for South African hosting under the authorised OEM Operator. Any cross-border processing, external artificial-intelligence provider, monitoring provider or additional subprocessor requires documented review and authority before activation.
8. Contact
Opticore Alliance (Pty) Ltd, registration number 2023/809498/07, 357 Rivonia Boulevard, Rivonia, Sandton, South Africa. Information Officer: Sam Klaasen, asklaasen@opticoredigital.online, +27 60 977 4256. Privacy and platform requests: platform@opticoredigital.online. Customer data-subject requests should first be directed to the Responsible Party or Controller for the relevant tenant.