Privacy Policy
GMAT Consulting (Pty) Ltd — GMAT Financial Analysis Platform
Last updated: 23 August 2026
1. Who we are
This Privacy Policy explains how GMAT Consulting (Pty) Ltd (“GMAT”, “we”, “us” or “our”) collects, uses, stores, protects and shares information when you use the GMAT Financial Analysis Platform, including the Sushi AI assistant, and related services (the “Services”).
GMAT Consulting (Pty) Ltd is a company registered in South Africa. Our registered address is 7 Carnation Street, Gallo Manor, Sandton, Johannesburg, Gauteng, 2052. For any privacy-related questions or to exercise your rights, you can contact us at legal@gmatconsulting.com.
We are the responsible party (under the Protection of Personal Information Act, 2013 — “POPIA”) and, where applicable, the data controller (under the UK/EU General Data Protection Regulation — “GDPR”) for the personal information described in this policy.
2. What this policy covers
This policy covers the personal information and business financial data we process when you register for and use Sushi, including when you connect your accounting system (such as Xero, QuickBooks or Sage), interact with the Sushi assistant, and use our reporting and analysis features.
Note on financial data from your accounting system: when you connect your accounting platform, we access financial records that may include information about your customers, suppliers, employees and other third parties. You confirm that you are permitted to share this information with us for the purpose of receiving the Services. We process this information only to provide the Services to you, as described below.
3. Information we collect
3.1 Information you give us
- Account and contact information: your name, email address, and login credentials.
- Billing information: your subscription tier, and billing details processed by our payment provider. We do not store full payment card details.
- Your interactions: the questions you ask Sushi and other information you provide during your use of the Services.
3.2 Financial data from your connected accounting system
When you connect Xero, QuickBooks, Sage or another accounting platform, we access and store financial data from that system to provide the Services. This may include your profit and loss statements, balance sheets, invoices, bills, bank transactions, contacts (customers and suppliers) and related financial records.
This financial data is stored securely, encrypted, and is only ever accessible to you and the users you authorise. It is never used to provide services to any other customer in a form that could identify you or your business (see Sections 6 and 7).
3.3 Information we collect automatically
- Usage data: information about how you use the Services, such as features used, pages visited, and general activity, used to operate and improve the platform.
- Technical data: your IP address, browser type, device type and similar technical information, collected to keep the Services secure and functioning.
4. How we use your information
We use your information for the following purposes:
- To provide the Services: to operate the Sushi platform, generate your financial analysis, answer your questions, and produce your reports.
- To manage your account: to manage your account, process your subscription, and communicate with you about the Services (including service and security notices).
- To keep the Services secure: to protect the platform and your data against unauthorised access, fraud and other threats.
- To meet legal obligations: to comply with our legal, tax, regulatory and accounting obligations.
- To improve the Services: to understand how the Services are used and to develop and improve them, including the anonymised insights described in Sections 6 and 7.
5. Artificial intelligence and the Sushi assistant
Sushi uses artificial intelligence to analyse your financial data and answer your questions. To do this, relevant financial data and your questions are processed through third-party AI service providers under contractual terms that require them to process the data only to provide the service to us, and not to use it to train their own models or for their own purposes. We will tell you which providers we currently use if you ask us at legal@gmatconsulting.com.
Sushi’s analysis is intended to support your decision-making. It does not replace professional financial, tax, legal or accounting advice, and you remain responsible for decisions you make based on it.
6. Learning and improvement — anonymised insights
We continuously improve Sushi and the Services by learning anonymised, aggregated trends and insights from how the Services are used. This is central to how Sushi becomes more useful over time.
Importantly:
- What we learn: We may retain anonymised, aggregated statistics and general lessons derived from interactions with the Services — for example, which topics are most commonly asked about in a particular type of business, or common financial patterns and risks seen across industries. These insights are general and are not linked to you.
- What we do not keep:We do NOT retain your personal information, your identifiable business information, or your specific financial figures within these insights. The insights are abstracted so that they cannot be traced back to you, your business, or any individual. Sushi will never disclose one customer’s information, figures or activity to another customer.
- Why we can retain them: Because these insights are anonymised and cannot be linked back to you, they are not personal information, and they may be retained by us on an ongoing basis — including after you stop using the Services — to keep improving the platform. Your identifiable data is deleted as described in Section 9.
7. What we never do with your data
- We never sell, rent or trade your personal information or financial data.
- We never share your identifiable financial data with other customers.
- We never allow one customer to access, see or infer another customer’s data.
- We never use your identifiable financial data to provide services to anyone else.
8. How we share information
We share information only where necessary to provide the Services, and only with:
- Service providers who help us operate the platform — including hosting and database providers, our AI provider(s), and our payment processor — under agreements requiring them to protect your data and use it only to provide services to us.
- Connected platforms only where they are the source or destination of your data at your instruction (for example, your accounting platform).
- Legal and regulatory bodies where we are legally required to disclose information to comply with the law, a court order, or a lawful request from a regulator or authority.
- Business transfers in connection with a merger, acquisition or sale of our business, in which case we will ensure your information remains protected and you are notified.
9. Data retention and deletion
We retain your personal information and financial data for as long as you have an active account with us, and for a limited period afterwards where we have a legal, tax or accounting obligation to keep it.
You may disconnect your accounting platform and request deletion of your data at any time. When you do, we will delete your identifiable financial data — including your connection tokens, imported financial records (accounts, contacts, invoices, transactions and report lines) and your Sushi conversation history — from our active systems, except where we are legally required to retain certain records for a defined period.
As explained in Section 6, anonymised and aggregated insights that cannot be linked back to you are not personal information and may be retained after deletion.
10. How we protect your data
We take the security of your financial data seriously and apply appropriate technical and organisational measures, including:
- Encryption: financial data and access credentials are encrypted in transit and at rest.
- Access controls and data isolation:each customer’s data is strictly isolated. Access is controlled at the database level so that you can only ever access data for businesses you are authorised to view.
- Authentication: access to your account is protected by two-factor authentication.
While we work hard to protect your data, no system can be guaranteed to be completely secure. We will notify you and the relevant authority of any data breach affecting your personal information as required by law.
11. International transfers
Some of our service providers (including hosting and AI providers) may process data outside South Africa. Where your information is transferred to another country, we ensure appropriate safeguards are in place to protect it in accordance with POPIA and, where applicable, GDPR.
12. Your rights
Depending on where you are located, you have rights in relation to your personal information, including the right to:
- request access to the personal information we hold about you.
- correct information that is inaccurate or out of date.
- request deletion of your personal information (subject to legal retention obligations).
- object to or restrict certain processing of your information.
- request a copy of your information in a portable format.
- not be subject to a decision based solely on automated processing that has a significant effect on you, and to request human review.
To exercise any of these rights, contact us at legal@gmatconsulting.com. You also have the right to lodge a complaint with the Information Regulator (South Africa) or, if applicable, your local data protection authority.
13. Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify you by email or through the Services. The “Last updated” date at the top of this policy shows when it was last revised.
14. How to contact us
If you have any questions about this policy or how we handle your information, please contact us at:
GMAT Consulting (Pty) Ltd
7 Carnation Street, Gallo Manor, Sandton, Johannesburg, Gauteng, 2052
legal@gmatconsulting.com
Information Regulator (South Africa) — POPIA complaints: POPIAComplaints@inforegulator.org.za · Website: inforegulator.org.za