Privacy
Privacy policy
What FLOCORE and the Human Seal collect, why, who sees it, how long we keep it, and how to ask us to change or delete it. Effective 4 October 2026.
1. Who we are
FLOCORE / Human Seal (humanseal.world and fo.flocore.tech) is a software service that includes a public MCP server for AI agents. It is run by Floris Olivier, Durban, South Africa, who is the responsible party under the Protection of Personal Information Act 4 of 2013 (POPIA). When the business moves into a company, this page will name it and the change will be dated.
Information Officer and privacy contact: Floris Olivier, florisolivier7@gmail.com.
2. What we collect, and why
- Request logs. For each request we record the method, path, status code, duration and a request id, to run the service, find faults and review abuse.
- A hashed network address. For our pitch tool and support tool we store a keyed hash of the caller's network address, not the address itself, to limit abuse. We treat the hash as personal information.
- Web server logs. Our web server keeps ordinary access logs that contain IP addresses, for security and fault finding.
- The screening tool. Text sent to the free screen is not stored when you call it anonymously. If you pass an agent name, we store that name and the score.
- Support questions. Limited to 500 characters. We send the question to a hosted language model provider, currently Groq in the United States, to write an answer, and keep the answer in a cache for 10 minutes. Please do not put personal information in a question.
- Agent registration. The agent's name, the owner's contact details, the organisation, the intended use, an optional public key and its thumbprint, and who referred you if you say. Giving these is voluntary, but we cannot register an agent without them. We use them to set up the registration and to contact the owner about it.
- Owner confirmation and sign-in. The one-time code your agent shows you proves you control the registration. We store your email address and email you one-time sign-in codes (each valid for 10 minutes).
- Approvals and receipts. We record approvals and signed receipts that name the approving person, as a verifiable record of who approved what.
We do not sell personal information and we do not use it for advertising.
3. Who receives it, and transfers outside South Africa
- Groq (United States), or another hosted language model provider if Groq is unavailable, receives support questions to write answers. This is a transfer outside South Africa, so please do not include personal information in a question. These providers work under their own published terms.
- Email. We send sign-in and approval emails from our own mail server. No outside email delivery company receives your address.
- Our servers are hosted in Johannesburg, South Africa.
- We disclose information where the law requires it, for example to a court or the Information Regulator. We share it with no one else.
4. Security
We take appropriate, reasonable technical and organisational steps to protect personal information. If it is accessed without authority we will tell the Information Regulator and the people affected as soon as reasonably possible.
5. How long we keep it
We keep information only as long as it is needed for its purpose or as the law allows or requires. These periods are our own choices. Where something is not yet automated we say so.
- Sign-in codes: valid for 10 minutes.
- Web server logs: rotated daily and kept for 14 days.
- Support questions: kept only in the 10 minute cache.
- Request logs and the hashed network address: we aim to delete them or reduce them to counts that identify no one within 90 days. This is not yet automated, and until it is we will do it by hand and on request.
- Owner email and registration details: while the registration is active, then deleted or de-identified within 12 months of it ending.
- Approvals, signed receipts and the event log: 5 years, as proof if there is a dispute. After that we remove identifying details. The automatic removal is not yet built; until it is, we do it by hand on request.
6. The append-only event log
Entries in our event log cannot be edited or deleted one at a time. We built it that way so the history can be trusted. This limits your correction and deletion rights, so here is what we do:
- We keep as little personal information in the log as we can.
- If you ask us to delete your information, we delete it everywhere we can. For the event log, we remove the link between entries and your identity where we are able to; where we are not, we restrict the entry to proof-only use and tell you.
- If you say an entry is wrong, we add a correction note linked to it and tell you.
7. Your rights
You may ask us to confirm whether we hold your personal information and give you a copy; to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained; to delete a record we may no longer keep; and you may object to our processing. Email florisolivier7@gmail.com. We reply as soon as reasonably practicable and aim to do so within 30 days.
8. Complaints
Contact us first at florisolivier7@gmail.com. You may also complain to the Information Regulator (South Africa) through eservices.inforegulator.org.za, by email at enquiries@inforegulator.org.za, by phone on 010 023 5200 or 0800 017 160, or at Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191.
9. Changes
We post changes here with a new effective date, and email registered owners about significant changes. This page is a plain statement of our practice and is not legal advice.