Voluntary disclosure
AI use disclosure
Effective 18 May 2026
Draft — pending legal review
This document is a working template based on standard South African consumer-retail and Section 21 cannabis-supply practice. It will be reviewed and signed off by a POPIA- and consumer-law-qualified attorney before public launch.
Cannabuben uses AI tools in narrow, clearly-scoped ways. This page is a voluntary disclosure of every AI use we are aware of, the data each one processes, and the choices you have. POPIA section 71 gives you the right to object to decisions taken about you on a purely automated basis; AI use that does not make decisions about you is also disclosed here for transparency.
1. Editorial hero-image generation
- Where
- Hero images on /guides articles, condition pages, and goal landing pages.
- Provider
- OpenAI (gpt-image-1 / dall-e-3 family)
- Data sent
- Editorial prompt only (e.g. "amber CBD dropper bottle on a mossy stone, Tsitsikamma forest, editorial style"). No customer data, no order data, no account data.
- When
- Offline, in a batch generation script run by an engineer. Generated images are stored as static files on Cannabuben servers and served from there.
- Your choice
- None required — no personal information is processed. Images that were AI-assisted carry an "AI-assisted" pill in the UI where applicable.
2. Error and incident analytics
- Where
- Crash reports and server-side error tracking via Sentry (see sub-processors).
- Data sent
- Stack traces, route accessed, user-agent, masked IP. PII fields (email, ID number, phone) are stripped by a
beforeSendhook before transmission. - AI use
- Sentry uses statistical (non-LLM) grouping to cluster similar errors. No automated decisions about customers are made.
- Your choice
- None required for processing. To request that any specific incident report be removed, email io@cannabuben.co.za.
3. Trust-score risk evaluation (automated decisioning)
- Where
- Checkout. Used to detect fraud and to flag orders that need manual review.
- What it is
- A rule-based scoring system. Not an LLM. Signals include: account age, address validation, blocklist hits, velocity, timezone vs delivery-address mismatch, IP reputation, honeypot fields, and form-completion timing.
- What it decides
- Whether an order can proceed immediately, must go through manual review, or is declined. Section-21 (medical cannabis) orders are additionally reviewed by a HPCSA-registered practitioner.
- Your right to object (POPIA section 71)
- If your order was flagged or declined and you believe the decision was incorrect, you can request a human review at /account/audit-decision.
4. Editorial copy and FAQ generation
Some long-form copy on /guides, /faq, and condition pages was drafted with the assistance of large language models and then reviewed and edited by a human author. Where this applies, the article carries an "AI-assisted" pill in the byline. Medical claims are not made; clinical content on Docto24 is reviewed by HPCSA-registered doctors.
5. Customer-facing chatbots
Cannabuben does not currently operate a customer-facing AI chatbot. If one is introduced, this page will be updated before the chatbot goes live and the chatbot itself will carry a visible "AI-generated response" disclosure on every reply.
6. Training data
We do not provide Cannabuben customer data, order data, or prescription data to any AI provider for training purposes. Our Operator Agreements with AI vendors (see sub-processors) prohibit use of prompts and outputs for model training where the vendor offers that choice.
7. Questions or requests
For any AI-use-related question, including a request to opt out of a specific automated decisioning step, email io@cannabuben.co.za.
More disclosures: all legal documents.
