This Privacy Policy explains how Infotech Solutions collects, uses, protects, retains and discloses personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").
Infotech Solutions, a division of Infotech Enterprise ("Infotech", "we", "us" or "our"), is committed to processing personal information lawfully, reasonably and transparently.
This Privacy Policy explains how personal information may be collected, used, stored, shared, protected and otherwise processed through our website, business operations and service engagements.
Where Infotech determines the purpose and means of processing personal information, we act as the Responsible Party under POPIA. Where we process personal information on behalf of a client, we may act as an Operator subject to the client's instructions, contractual obligations and applicable law.
This Privacy Policy applies to personal information processed in connection with:
Depending on the nature of an interaction or engagement, Infotech may process the following categories of personal information:
Infotech does not intentionally request special personal information through its general website enquiry facilities.
Where special personal information is required for a legitimate business, employment, regulatory or client purpose, it will be processed only where permitted under POPIA and subject to appropriate safeguards.
Personal information may be collected:
Infotech processes personal information only for specific, defined and lawful purposes and where an appropriate justification for processing exists under POPIA.
Personal information may be processed to:
Where consent is relied upon, consent may be withdrawn subject to applicable legal and contractual limitations.
Personal information is collected for a specific purpose and should not be processed in a manner incompatible with that purpose.
Where personal information is subsequently processed for another purpose, Infotech considers whether the further processing is compatible with the original purpose in accordance with POPIA, unless an applicable legal exception permits otherwise.
Infotech seeks to process only personal information that is adequate, relevant and not excessive for the purpose for which it is required.
Access to personal information is restricted according to authorised roles, legitimate business need and appropriate technical and organisational controls.
Infotech Solutions does not sell personal information.
Personal information may be shared where lawful and reasonably necessary with:
Third-party processing relationships are subject to appropriate confidentiality, contractual and security arrangements having regard to the nature and risk of the processing involved.
Where an Operator processes personal information on behalf of Infotech, we require appropriate contractual and security arrangements consistent with POPIA.
These arrangements may include requirements relating to:
Where Infotech acts as an Operator for a client, processing is governed by the applicable client instructions, contractual arrangements and law.
Infotech may use cloud infrastructure, technology providers or other service providers that involve the transfer, storage or processing of personal information outside South Africa.
Cross-border transfers are governed in accordance with Section 72 of POPIA.
Before personal information is transferred to a third party in another country, Infotech considers whether an appropriate transfer basis exists, including whether the recipient is subject to a law, binding corporate rules or binding agreement providing an adequate level of protection, or whether another ground permitted under POPIA applies.
Where Microsoft Azure or other global cloud services form part of an environment, data residency, processing location, administrative access, service architecture and applicable transfer mechanisms may be considered as part of the relevant governance and security requirements.
Infotech applies a risk-based approach to information security and maintains appropriate, reasonable technical and organisational measures designed to protect personal information against loss, damage, unauthorised access, unlawful processing, destruction or disclosure.
Depending on the processing environment and associated risk, safeguards may include:
Security controls are selected having regard to the nature and sensitivity of the information, reasonably foreseeable threats, the processing environment and applicable contractual or regulatory obligations.
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, Infotech will assess and manage the incident in accordance with Section 22 of POPIA.
Where notification is legally required, the Information Regulator and affected Data Subjects will be notified as soon as reasonably possible, subject to any lawful delay permitted under POPIA.
Incident response may include containment, investigation, impact assessment, remediation, evidence preservation and review of relevant security and governance controls.
Infotech takes reasonably practicable steps to ensure that personal information under our control is complete, accurate, not misleading and updated where necessary, having regard to the purpose for which it is processed.
Personal information is retained only for as long as authorised or reasonably necessary for the purpose for which it was collected, unless:
Where personal information is no longer lawfully required, it will be destroyed, deleted or de-identified in accordance with applicable requirements and appropriate information-governance procedures.
Infotech recognises that artificial intelligence and automated processing may introduce additional privacy, security, transparency and accountability risks.
Where personal information is processed using AI or automated systems, appropriate governance measures are considered having regard to the processing purpose, information sensitivity, access controls, security, human oversight and applicable legal requirements.
Infotech will not subject a Data Subject to a decision based solely on automated processing where doing so would contravene the protections applicable under Section 71 of POPIA.
Electronic direct marketing is managed in accordance with POPIA.
Where prior consent is required, marketing communications will only be sent once the necessary consent has been obtained, subject to circumstances where POPIA permits communication with an existing customer.
Recipients may object to or opt out of direct marketing communications at any time.
Our website may use cookies or related technologies where required to operate the website, maintain security, understand website performance or improve the user experience.
Depending on the technologies deployed, these may process information such as browser type, device information, IP address, page interactions and technical performance information.
Users may configure their browser settings to restrict or delete cookies. Certain website functionality may be affected where cookies are disabled.
Subject to POPIA and applicable legal limitations, a Data Subject may:
Privacy and Data Subject requests should be directed to the Information Officer:
Information Officer: Kgaogelo MM Madileng
Information Officer Registration Number: 2026-024619
Company Registration Number: 2020/190559/07
Email:
[email protected]
Infotech may take reasonable steps to verify the identity and authority of a person making a request before disclosing, correcting or deleting personal information.
Requests for access to records that fall within PAIA will be handled in accordance with our PAIA Manual.
A Data Subject who is dissatisfied with the handling of a privacy matter may lodge a complaint with the Information Regulator (South Africa).
Information Regulator (South Africa)
Website:
https://inforegulator.org.za
Telephone: 010 023 5200
This Privacy Policy should be read together with our:
Infotech Solutions may update this Privacy Policy where necessary to reflect changes in law, regulation, organisational practices, processing activities, technology or security requirements.
Material revisions will be published on this page together with an updated revision date.