Privacy Policy
Table of Contents
- Introduction
- Purpose and Scope
- Definitions
- What Personal Information We Collect
- How We Collect Personal Information
- Lawful Basis for Processing
- Purposes of Processing
- Cookies and Tracking Technologies
- Google Analytics
- Direct Marketing
- Disclosure and Sharing of Personal Information
- Data Retention
- Security of Personal Information
- Cross-Border Transfers
- Children's Privacy
- Your Rights as a Data Subject
- How to Lodge a Complaint
- The Information Regulator
- Changes to This Policy
- Contact Information
1. INTRODUCTION
Isango Enterprises (Pty) Ltd ("we", "us", "our", or "Isango") is committed to protecting your privacy and ensuring you have a positive experience on our website.
This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information when you visit our website at https://www.isangoenterprises.co.za (the "Website"), interact with our online services, complete our enquiry forms, request quotations, or communicate with us electronically.
We take your privacy seriously. We operate transparently, communicate clearly about how we handle your information, and comply fully with the Protection of Personal Information Act 4 of 2013 (POPIA) and all applicable South African privacy and data protection legislation.
If you have any questions about this Privacy Policy or our privacy practices, please contact us using the details provided at the end of this document.
2. PURPOSE AND SCOPE
2.1 Purpose
The purpose of this Privacy Policy is to:
(a) Inform you of the personal information we collect from you and why;
(b) Explain how we use, store, and protect that information;
(c) Describe your rights as a data subject under POPIA;
(d) Provide transparent information about our data processing practices;
(e) Comply with POPIA and related South African legislation; and
(f) Demonstrate our commitment to responsible information governance.
2.2 Scope
This Privacy Policy applies to:
(a) All visitors to our Website;
(b) All users of our online forms, enquiry systems, and contact channels;
(c) All persons who request quotations or engage with our services;
(d) All personal information collected through our Website and related digital channels; and
(e) All processing of personal information by Isango Enterprises and our authorized service providers.
2.3 What This Policy Does Not Cover
This Privacy Policy does not apply to:
(a) Information collected offline or through channels other than our Website;
(b) Third-party websites linked from our Website (each third party is responsible for their own privacy practices);
(c) Information about individuals who are not identifiable or personal information that has been anonymized;
(d) Information processed in your capacity as an employee of Isango Enterprises (employment information is governed separately); or
(e) Information subject to a separate written agreement between you and Isango Enterprises.
3. DEFINITIONS
In this Privacy Policy, the following terms have the meanings ascribed to them:
"Cookie" means a small text file stored on your device that contains information about your browsing activity and preferences.
"Data Subject" means any natural person to whom personal information relates and who can be identified from that information alone or in combination with other information.
"Personal Information" means information relating to an identified or identifiable natural person (a Data Subject), including information that is capable of identifying that person directly or indirectly.
"Processing" means any operation performed on personal information, including collection, receipt, recording, organization, storage, updating, use, analysis, transmission, and deletion.
"Responsible Party" means the entity that determines the purpose of and means for processing personal information. For the Website, this is Isango Enterprises (Pty) Ltd.
"Operator" means any entity that processes personal information on behalf of the Responsible Party and in accordance with the Responsible Party's instructions.
"Third Party" means any entity other than the Data Subject, the Responsible Party, or an Operator, including service providers, partner organizations, and government authorities.
"Website" means https://www.isangoenterprises.co.za and all pages, features, and services accessible through this domain.
"POPIA" means the Protection of Personal Information Act 4 of 2013 and the regulations made thereunder.
"Information Regulator" means the office established under POPIA to oversee compliance with the Act and investigate breaches.
4. WHAT PERSONAL INFORMATION WE COLLECT
4.1 Information You Provide Directly
When you interact with our Website, complete forms, or contact us, we may collect the following personal information that you provide:
(a) Identification Information: Your full name, personal identification number (if provided), date of birth (if provided);
(b) Contact Information: Your email address, telephone number, physical address, and company name;
(c) Enquiry and Request Information: Details of your enquiry, the services you are interested in, project information, timelines, budget parameters, and any other information you include in your communication;
(d) Quote Request Information: Details necessary to provide you with an accurate quotation, including scope of work, specifications, location, and any special requirements;
(e) Communication Records: The content of emails, messages, and other communications you send to us, including attachments;
(f) Preference Information: Your communication preferences, dietary requirements (if relevant to our Catering division), accessibility requirements, and other stated preferences.
4.2 Information Collected Automatically
When you visit our Website, we automatically collect certain information about your interaction with it:
(a) Technical Information: - Your Internet Protocol (IP) address - Your device type and operating system - Your browser type and version - The pages you visit and the time spent on each page - Links you click - Referral source (how you arrived at our Website) - Your general geographic location (based on IP address)
(b) Cookie Information: Information stored through cookies and similar tracking technologies (further detailed in Section 8);
(c) Analytics Information: Data collected through Google Analytics regarding your browsing behaviour, user journey through the Website, and interaction patterns (further detailed in Section 9);
(d) Usage Statistics: Information about which features, services, or content you access, how often you visit, and your browsing patterns.
4.3 Information from Third Parties
In limited circumstances, we may receive personal information about you from third parties:
(a) Service Providers: Our hosting provider, email service providers, and other technical partners may provide information necessary to deliver services;
(b) Referral Sources: If you are referred to us by another party, they may provide your contact details with your consent;
(c) Payment and Delivery Partners: When you arrange payment or delivery of services, relevant parties may share information necessary to complete those transactions.
We only accept personal information from third parties where we have a lawful basis to do so and where we have confirmed that the third party has obtained your consent or has a lawful basis to share your information.
4.4 Information You Do Not Need to Provide
Providing personal information through our Website is entirely voluntary. You are never required to provide personal information to visit our Website or access publicly available content. However, if you wish to:
- Request a quotation
- Submit an enquiry
- Use our contact forms
- Receive direct marketing communications
- Access certain services
...then providing the necessary personal information is required for us to respond to you and deliver those services.
5. HOW WE COLLECT PERSONAL INFORMATION
5.1 Collection Methods
We collect personal information through the following methods:
(a) Contact Forms: When you complete our "General Enquiry Form", "Quote Request Form", or other forms on the Website;
(b) Direct Communication: When you email us, telephone us, or send us messages through our Website;
(c) Subscription and Registration: If you subscribe to communications or create a profile (if applicable);
(d) Automatic Collection: Through cookies, analytics tools, and other automated tracking technologies;
(e) File Uploads: If you attach documents or files to your enquiries or communications;
(f) Third-Party Referrals: When other parties refer you to us or share your contact details (with your consent).
5.2 Technical Collection Methods
We use the following technical methods to collect information:
(a) Cookies and Similar Technologies: Small files stored on your device that track your browsing activity (see Section 8 for full details);
(b) Web Beacons and Pixels: Transparent images embedded in web pages that track whether content has been viewed;
(c) Server Logs: Automatic recording of your connection details, requests, and technical information;
(d) Analytics Platforms: Third-party tools (including Google Analytics) that collect and analyze your website usage patterns;
(e) Form Analytics: Tools that track how you interact with our forms, including time spent, fields completed, and submission attempts.
5.3 Passive vs. Active Collection
Passive Collection occurs when you simply visit our Website — your browser and device automatically transmit certain technical information, which we collect through cookies and analytics tools.
Active Collection occurs when you intentionally provide information — by completing a form, sending an email, or uploading a file.
You have control over passive collection through your browser settings (see Section 8.6 for details on managing cookies).
6. LAWFUL BASIS FOR PROCESSING
6.1 POPIA Legal Grounds
Under POPIA, we may only process personal information where we have a lawful basis to do so. Our processing of your personal information is based on one or more of the following lawful bases:
6.2 Consent
Basis: You have given us clear, specific, and voluntary consent to process your personal information for a stated purpose.
When We Use This: - When you complete an enquiry form and consent to us using your information to respond - When you subscribe to receive direct marketing communications - When you agree to our use of non-essential cookies - When you provide information for a specific service request
Your Right: You may withdraw consent at any time by contacting us (see Section 20 for contact details).
6.3 Contractual Performance
Basis: Processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract.
When We Use This: - When you request a quotation and we process your information to prepare and send a quote - When you engage our services and we process information to deliver those services - When we arrange payment, delivery, or service fulfillment
6.4 Legal Obligation
Basis: Processing is necessary to comply with a legal obligation that applies to us in South Africa.
When We Use This: - When we are required to retain records for tax or regulatory compliance - When we must disclose information to government authorities as legally required - When we must comply with court orders or legal process
6.5 Legitimate Interest
Basis: Processing is necessary for our legitimate interests or those of a third party, provided that our interest does not outweigh your right to privacy.
When We Use This: - To improve our Website, services, and user experience - To prevent fraud, abuse, or security threats - To conduct business analytics and understand market trends - To maintain records necessary for business operations - To manage our relationship with service providers
In each case, we have assessed that our legitimate interest does not outweigh your privacy rights, and we have implemented appropriate safeguards.
6.6 Protection of Vital Interests
Basis: Processing is necessary to protect your vital interests or those of another natural person.
When We Use This: In emergency situations where your safety or another person's safety may be at risk, we may process information necessary to protect those interests.
7. PURPOSES OF PROCESSING
7.1 Primary Purposes
We process personal information for the following primary purposes:
7.1.1 Service Delivery and Enquiry Response
(a) To receive and respond to your enquiries about our services;
(b) To understand your service requirements and provide appropriate solutions;
(c) To prepare and send quotations, proposals, and project information;
(d) To communicate with you about your request, including timeline, costs, and next steps;
(e) To perform services you have engaged us to provide;
(f) To track the status of your project or service request;
(g) To invoice you and process payments;
(h) To retain records of the services provided for accountability and compliance.
7.1.2 Website Improvement and Analytics
(a) To analyze how our Website is used and which features are most popular;
(b) To identify technical issues or areas requiring improvement;
(c) To enhance user experience and website functionality;
(d) To understand visitor behavior and optimize our content;
(e) To generate statistical reports about website performance;
(f) To identify trends and patterns that help us serve you better.
7.1.3 Direct Marketing
(a) To send you information about our services, updates, and special offers (only where you have consented);
(b) To notify you of new services or divisions that may be relevant to your needs;
(c) To invite you to events, webinars, or industry updates;
(d) To conduct market research and gather feedback about your needs;
(e) To re-engage with previous enquirers who may be interested in our current services.
7.1.4 Security and Fraud Prevention
(a) To detect and prevent fraud, abuse, or malicious activity on our Website;
(b) To protect the security of our systems and your information;
(c) To investigate unauthorized access or misuse of our Website;
(d) To comply with security and legal obligations;
(e) To identify and block malicious traffic or attacks.
7.1.5 Legal and Regulatory Compliance
(a) To comply with applicable South African legislation, including POPIA, PAIA, ECTA, and the CPA;
(b) To retain records necessary for tax, audit, or regulatory compliance;
(c) To respond to legal inquiries, court orders, or government requests;
(d) To maintain proper records of our business operations;
(e) To comply with B-BBEE reporting requirements and similar regulatory obligations.
7.2 Secondary Purposes
We may also process your personal information for related purposes that are reasonably anticipated:
(a) To contact you in response to your communication;
(b) To send administrative information about our Website, services, or policies;
(c) To enforce our Website Terms & Conditions or other agreements;
(d) To protect our legal rights and interests;
(e) To facilitate the transfer of our business if we are acquired or merged.
7.3 Purposes We Do NOT Use Your Information For
We will not process your personal information for:
(a) Advertising purposes beyond our direct marketing (as described in Section 10);
(b) Behavioral profiling for third-party advertising networks;
(c) Selling, renting, or trading your information for profit;
(d) Purposes beyond those specified in this Privacy Policy;
(e) Any purpose that would violate your privacy rights without your explicit consent.
8. COOKIES AND TRACKING TECHNOLOGIES
8.1 What Are Cookies?
A cookie is a small text file that is stored on your device (computer, tablet, or mobile phone) when you visit a website. Cookies can store information about your preferences, login status, browsing history, and other data relevant to your interaction with the website.
When you revisit the Website, your browser sends the stored cookie back to us, allowing us to recognize you and recall information about your previous visit.
8.2 Types of Cookies We Use
Our Website uses the following categories of cookies:
8.2.1 Essential Cookies
Purpose: These cookies are strictly necessary for the Website to function properly and cannot be disabled without affecting website functionality.
Examples: - Session cookies that maintain your login status (if you access any protected areas) - Cookies that maintain security features - Cookies that remember your form submissions - Cookies that manage your cookie preferences
Duration: Typically deleted when you close your browser, or may persist for a short period (e.g., 24 hours)
Legal Basis: We process these cookies on the basis of our legitimate interest in ensuring our Website functions properly and securely.
8.2.2 Session Cookies
Purpose: These cookies are temporary and maintain information about your current browsing session.
Examples: - Cookies that track which pages you visit within a single session - Cookies that remember your form progress - Cookies that maintain your preferences during your visit
Duration: Automatically deleted when you close your browser
Legal Basis: Legitimate interest in providing you with a smooth, consistent browsing experience.
8.2.3 Persistent Cookies
Purpose: These cookies remain on your device after you close your browser and allow us to recognize you on future visits.
Examples: - Cookies that remember your communication preferences - Cookies that store your browsing history on our Website - Cookies that recognize you as a repeat visitor
Duration: May persist for weeks, months, or years depending on the specific cookie
Legal Basis: Legitimate interest in understanding our audience and improving our services, or your consent for non-essential persistent cookies.
8.2.4 Analytics Cookies
Purpose: These cookies collect information about how visitors use our Website, including which pages are visited, how long you stay, and what actions you take.
Examples: - Google Analytics cookies (see Section 9 for detailed information) - Cookies that track page views, click behavior, and navigation patterns - Cookies that measure website performance metrics
Duration: Typically persist for several months
Legal Basis: Your consent for non-essential analytics cookies (see below), or our legitimate interest in understanding website performance.
8.3 Essential vs. Non-Essential Cookies
Essential Cookies are required for our Website to function properly. These include cookies necessary for security, session management, and basic functionality. We do not require your consent for essential cookies, as they are necessary for you to use the Website.
Non-Essential Cookies (including analytics and persistent tracking cookies) are optional and enhance your experience but are not strictly required for basic functionality. We require your explicit consent before setting non-essential cookies on your device.
When you first visit our Website, you will be presented with a cookie consent banner. You may: - Accept all cookies (including non-essential cookies) - Accept only essential cookies - Customize your preferences
Your cookie preferences are stored in a cookie, allowing us to remember your choice on future visits.
8.4 Google Analytics
See Section 9 for full details about Google Analytics and our use of analytics cookies.
8.5 Third-Party Cookies
Our Website does not use third-party advertising networks or behavioral profiling services. We do not allow third parties to place tracking cookies on our Website for purposes beyond the legitimate functions we have outlined (e.g., website hosting, analytics).
The only third-party cookie provider we use is Google Analytics (a service of Google Inc.), which collects website usage data (see Section 9).
8.6 Managing Your Cookies
You have full control over cookies stored on your device. You can:
(a) Delete Existing Cookies: - Most browsers have a function to clear cookies. Consult your browser's help menu or settings for specific instructions. - Deleting cookies may cause you to lose saved preferences and may affect your user experience.
(b) Control Future Cookies: - Most browsers allow you to control cookie settings. You can: - Block all cookies - Allow only essential cookies - Be prompted each time a cookie is set - Allow cookies from certain sites only
(c) Opt Out on Our Website: - You can adjust your cookie preferences at any time by visiting our cookie preference centre or by clicking the cookie management link on our Website. - Your preferences will be saved in a persistent cookie.
(d) Browser-Level Settings: - Most modern browsers include "Do Not Track" (DNT) features. If you enable DNT, your browser will send a signal requesting that websites not track your behavior. - Our Website respects DNT signals where technically feasible, though we cannot guarantee that all website features will function properly if tracking is disabled.
8.7 Consequences of Disabling Cookies
If you disable or delete cookies:
- The Website may not function as intended
- You may need to re-enter information on each visit
- Your preferences may not be remembered
- Some features may be unavailable
- Analytics data will be less accurate
However, you will still be able to access the basic content and features of our Website.
9. GOOGLE ANALYTICS
9.1 What Is Google Analytics?
Google Analytics is a web analytics service provided by Google Inc. ("Google") that helps us understand how visitors interact with our Website. Google Analytics collects information about your visits, including pages viewed, time spent on each page, navigation patterns, and other usage statistics.
We use Google Analytics to improve our Website, understand our audience, and optimize our content and services.
9.2 Google Analytics Data Collection
When you visit our Website, Google Analytics collects the following information:
(a) Your IP Address: Used to determine your geographic location at a regional level;
(b) Pages Visited: Which pages you view and in what order;
(c) Time on Page: How long you spend on each page;
(d) Click Behavior: Which links you click and what actions you take;
(e) Referral Source: How you arrived at our Website (e.g., search engine, direct, referral from another site);
(f) Device and Browser: Your device type, operating system, and browser;
(g) Conversion Data: Whether you complete key actions (e.g., submitting a form).
9.3 Google Analytics Cookies
Google Analytics uses cookies to collect this information. These include:
_ga: Persists for 2 years and distinguishes unique users_gid: Persists for 24 hours and distinguishes sessions_gat: Persists for 1 minute and throttles request rates
These cookies are set by Google, not by us, and are subject to Google's privacy practices.
9.4 Data Processing
The data collected by Google Analytics is:
(a) Processed by Google on our behalf;
(b) Used to generate reports and analytics that we use to improve our Website;
(c) Retained by Google in accordance with Google's retention policy (typically 13-26 months);
(d) Anonymized at the user level (i.e., we cannot identify individual users from the data, though Google can connect data across multiple visits).
9.5 Your Privacy in Google Analytics
Important: Google Analytics data collection may involve the transfer of your information to Google's servers, which may be located outside South Africa. See Section 14 (Cross-Border Transfers) for details.
Google Analytics does not identify you personally. The data is analyzed in aggregate to generate usage statistics and trends, not to track you as an individual.
9.6 Google Analytics Opt-Out
You can opt out of Google Analytics data collection in several ways:
(a) Browser Add-On: Google provides a browser add-on that prevents Google Analytics from collecting your data. You can download the "Google Analytics Opt-out Browser Add-on" from Google's website.
(b) Cookie Preferences: If you disable Google Analytics cookies (through our cookie consent banner or your browser settings), Google Analytics will not collect your data.
(c) Your Google Privacy Settings: You can control how Google uses data collected from this and other websites through your Google Account settings at https://myaccount.google.com/privacy
9.7 Google's Privacy Policy
For full details about how Google collects and uses information through Google Analytics, see Google's Privacy Policy at https://policies.google.com/privacy
10. DIRECT MARKETING
10.1 Marketing Communications
We may send you direct marketing communications about our services, updates, news, and special offers, but only where we have a lawful basis to do so.
10.2 When We Send Marketing Communications
We may send you direct marketing communications in the following circumstances:
(a) With Your Explicit Consent: If you have specifically consented to receive marketing communications from us (e.g., by opting in during an enquiry or subscription process);
(b) Existing Relationship: If you have previously enquired about our services or engaged with us, we may send you information about related services or updates, provided that: - We give you the option to opt out with each communication - The marketing is not excessive or repetitive - We respect your preferences
(c) Legitimate Interest: We may send you marketing communications where we have assessed that our legitimate business interest in communicating with you is not outweighed by your privacy rights, provided that: - You have the right to opt out easily - We provide clear information about our identity and purposes - We comply with ECTA requirements for electronic marketing
10.3 Opt-In for Email Marketing
As a general rule, we require your explicit opt-in consent before sending you email marketing communications. When you complete a form or enquiry on our Website, you will have the option to:
- Subscribe to our newsletter or marketing communications
- Decline marketing communications
- Select which types of communications you wish to receive (e.g., service updates, new products, industry news)
10.4 Opt-Out from Marketing Communications
You have the right to opt out of marketing communications at any time. Every marketing email we send will include clear instructions for unsubscribing or managing your preferences. You can also:
(a) Unsubscribe: Click the "Unsubscribe" link at the bottom of any marketing email;
(b) Manage Preferences: Update your communication preferences through our Website or by contacting us (see Section 20);
(c) Contact Us Directly: Email us at info@isangoenterprises.co.za requesting to be removed from our mailing list;
(d) Request Deletion: Ask us to delete your contact information entirely (see Section 16 on Data Subject Rights).
Once you unsubscribe, we will remove you from our marketing lists within 10 business days. You will continue to receive transactional communications (e.g., responses to your enquiries) where necessary.
10.5 SMS and Telephone Marketing
We will not send you SMS, telephone, or other unsolicited marketing communications unless we have your explicit consent to do so. If you have consented to receive such communications, you may opt out at any time by:
- Replying "STOP" to SMS messages
- Requesting removal when we call
- Contacting us in writing
10.6 Marketing Through Third Parties
We do not sell, rent, or trade your contact information to third parties for their marketing purposes. Third-party service providers may only use your information to the extent necessary to provide services to us (e.g., email delivery), and they are bound by confidentiality obligations.
11. DISCLOSURE AND SHARING OF PERSONAL INFORMATION
11.1 General Policy
We treat your personal information as confidential and do not disclose it to third parties without a lawful basis and without appropriate safeguards. However, there are limited circumstances in which we must or may disclose your information.
11.2 When We Share Personal Information
11.2.1 Service Providers and Operators
We may disclose your personal information to third-party service providers and operators who process information on our behalf, including:
(a) IT Service Providers: - Email hosting providers - Website maintenance and support services - Technical security services - Data backup and storage services
(b) Website Hosting Provider: - Axxess (our current hosting provider) - These providers have access to server logs and technical information about your visit
(c) Payment and Finance Partners: - Banks and financial institutions (for payment processing) - Accountants and bookkeepers (for financial management) - Audit firms (for compliance and verification)
(d) Professional Advisers: - Legal advisors (for legal compliance and disputes) - Compliance consultants (for regulatory compliance) - Other professional service providers as required
(e) Delivery and Logistics Partners: - Where you request delivery of products or services, we may share delivery address and contact information with courier or logistics providers - These partners are only provided the information necessary to fulfill the delivery
(f) Government Authorities: - Where required by law or legal process (court order, subpoena, regulatory investigation) - To comply with SARS, CIPC, or other statutory obligations
11.2.2 Service Provider Agreements
All service providers who access your personal information are bound by written confidentiality agreements that:
(a) Limit their use of your information to the purposes for which we disclosed it;
(b) Require them to implement appropriate security measures;
(c) Prohibit them from disclosing your information to other third parties without our consent;
(d) Obligate them to return or destroy your information when services end;
(e) Allow us to audit their compliance with these terms.
11.2.3 Legal Disclosure
We may disclose personal information without your consent where:
(a) Required by law (e.g., court order, subpoena, regulatory investigation);
(b) Necessary to protect our legal rights or the rights of others;
(c) Necessary to prevent fraud, abuse, or security threats;
(d) Necessary to enforce our Website Terms & Conditions or other agreements;
(e) Necessary to protect your safety or the safety of others.
In such cases, we will disclose only the minimum information necessary and will, where legally permissible, inform you of the disclosure.
11.3 What We Do NOT Do with Your Information
We will never:
(a) Sell your information to other businesses or organizations;
(b) Rent or lease your information to third parties;
(c) Trade your information for products or services;
(d) Share your information for advertising purposes with third-party advertising networks or marketing agencies;
(e) Use your information for behavioral profiling to sell to other companies;
(f) Combine your information with data from other sources to create detailed profiles about you for sale or trade;
(g) Disclose your information to unrelated third parties without your consent (except as required by law).
11.4 Business Transfers
If Isango Enterprises is acquired, merged, or substantially reorganized, your personal information may be transferred as part of that business transaction. However:
(a) We will notify you of any such change;
(b) Your information will continue to be protected under this Privacy Policy (or an equivalent policy);
(c) You will have the right to opt out or have your information deleted before the transfer.
12. DATA RETENTION
12.1 Retention Principles
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. We do not retain information longer than necessary.
12.2 Retention Periods by Information Type
12.2.1 Enquiry Information
Retention Period: 3 years from the date of the enquiry.
Reason: To enable follow-up with prospective clients, to maintain records of business opportunities, and for accounting and tax compliance purposes.
12.2.2 Quote and Project Information
Retention Period: 7 years from completion of the project (or if not completed, from the date of the quote).
Reason: To maintain records of services provided for accountability, dispute resolution, and tax compliance under South African tax law.
12.2.3 Invoice and Payment Information
Retention Period: 7 years from the date of invoice.
Reason: Required under South African tax and accounting legislation.
12.2.4 Email Communications
Retention Period: 3-7 years depending on the nature of the communication and whether it relates to a specific service.
Reason: To maintain records of agreements, service details, and instructions.
12.2.5 Website Analytics Data
Retention Period: 13-26 months (in accordance with Google Analytics default retention policies).
Reason: To analyze website usage trends and improve user experience. Older data is automatically deleted.
12.2.6 Cookie Data
Retention Period: Varies by cookie type: - Session cookies: Deleted at end of browser session - Essential cookies: 6 months to 2 years - Analytics cookies: 2 years - Persistent tracking cookies: As specified in your cookie preferences
Reason: To maintain necessary functionality and user experience.
12.2.7 Marketing Consent Records
Retention Period: Until you withdraw consent or request deletion, or as required by law.
Reason: To evidence your consent and to comply with direct marketing regulations.
12.3 Deletion and Anonymization
When information reaches the end of its retention period:
(a) We will delete it securely, or
(b) We will anonymize it so that it can no longer identify you.
Information that has been anonymized (i.e., cannot be linked to an identified individual) is no longer "personal information" under POPIA and may be retained indefinitely for statistical and analytical purposes.
12.4 Your Right to Request Deletion
Notwithstanding the retention periods above, you have the right to request deletion of your personal information at any time (see Section 16.3). We will delete your information unless we have a legal obligation to retain it or a legitimate reason to do so.
12.5 Backup Copies
Information may be retained in automated backup systems for a period beyond the standard retention date to ensure data recovery in the event of a system failure or disaster. Backup copies are held securely and are only accessed in the event of a technical emergency.
13. SECURITY OF PERSONAL INFORMATION
13.1 Security Commitment
We are committed to protecting your personal information against unauthorized access, modification, disclosure, or destruction. We implement reasonable technical and organizational security measures appropriate to the sensitivity of the information and the risks involved.
13.2 Security Measures
We have implemented the following security measures:
13.2.1 Technical Safeguards
(a) HTTPS Encryption: Our Website uses Secure Sockets Layer (SSL) encryption to protect information transmitted between your browser and our servers. Look for the padlock icon and "https://" in your browser address bar.
(b) Firewalls: We maintain firewalls and network security controls to prevent unauthorized access to our systems.
(c) Access Controls: Personal information is accessible only to authorized personnel who have a legitimate business need to access it, and access is controlled through authentication (passwords, multi-factor authentication, etc.).
(d) Secure Storage: Personal information is stored on secure servers with restricted physical and electronic access.
(e) Regular Security Updates: Our systems are regularly patched and updated to address known security vulnerabilities.
(f) Data Encryption: Sensitive personal information (including payment details, where applicable) is encrypted both in transit and at rest.
13.2.2 Organizational Safeguards
(a) Data Protection Policies: We maintain comprehensive data protection and information governance policies.
(b) Staff Training: Our staff receive training on data protection, confidentiality, and secure handling of personal information.
(c) Confidentiality Agreements: Staff and service providers are bound by confidentiality obligations regarding personal information.
(d) Access Restrictions: Personal information is compartmentalized, and only staff with a legitimate business need have access.
(e) Incident Response Plan: We have procedures in place to detect, respond to, and report security breaches (see Section 13.3).
13.2.3 Third-Party Security
(a) We carefully select service providers and require them to maintain appropriate security measures.
(b) Service provider agreements include mandatory security requirements and audit rights.
(c) We conduct due diligence on service providers before disclosing personal information.
13.3 Data Breach Notification
In the event of a security breach that compromises your personal information, we will:
(a) Investigate the breach to determine what information was compromised, how the breach occurred, and what measures are needed to prevent recurrence;
(b) Notify affected individuals without unreasonable delay where the breach poses a high risk to your rights and interests (in accordance with POPIA Section 22);
(c) Notify the Information Regulator where the breach is widespread or poses a significant risk, as required by POPIA;
(d) Take corrective action to remediate the breach and prevent recurrence;
(e) Maintain records of the breach, investigation, and remediation steps.
Breach notifications will include information about the nature of the breach, the personal information that was compromised, steps you can take to protect yourself, and contact information for further assistance.
13.4 Limitations on Security
While we implement robust security measures, no security system is completely impenetrable. We cannot guarantee absolute security of your personal information. The Internet is not a completely secure environment, and there is always some risk that information transmitted electronically could be intercepted or accessed by unauthorized parties.
You are responsible for:
(a) Maintaining the confidentiality of your passwords and login information;
(b) Using a secure computer and network connection;
(c) Keeping your device and software up to date;
(d) Being cautious about phishing and social engineering attempts.
14. CROSS-BORDER TRANSFERS
14.1 When Information Is Transferred Outside South Africa
In limited circumstances, your personal information may be transferred to countries outside South Africa. This may occur when:
(a) Service Providers Are Located Abroad: Some of our service providers operate from outside South Africa, and may process your information in their home country or on international servers;
(b) Cloud Storage: Information may be stored on cloud servers that are geographically distributed across multiple countries;
(c) Google Analytics: Google Analytics is a service provided by Google Inc. (USA), and your analytics data is processed on Google's servers, which may be located outside South Africa;
(d) Hosting Infrastructure: Our website hosting provider's servers may be located internationally.
14.2 Protection of Transferred Information
Under POPIA Section 72, personal information can only be transferred outside South Africa if:
(a) The recipient country has been declared by the Information Regulator to have equivalent data protection laws; OR
(b) We have obtained your consent to the transfer; OR
(c) The transfer is necessary for the performance of a contract with you; OR
(d) We have implemented specific contractual safeguards (such as Standard Contractual Clauses or Binding Corporate Rules) to ensure equivalent protection.
14.3 Transfers to Common Destinations
(a) European Union (EU)
The EU has been recognized by the Information Regulator as having data protection laws equivalent to South Africa's (under the General Data Protection Regulation — GDPR). Transfers to EU member states are permitted without additional safeguards.
(b) United States (USA)
The USA has not been declared to have equivalent data protection laws. However:
- Where services are necessary to perform a contract with you (e.g., hosting, email services), we transfer information on the basis of contractual necessity.
- We have implemented Standard Contractual Clauses with our USA-based service providers (including Google for Google Analytics).
- You may opt out of certain non-essential transfers (e.g., analytics) through cookie preferences.
(c) Other Countries
For transfers to other countries not listed above, we rely on: - Contractual necessity (where services require the transfer) - Your explicit consent - Standard Contractual Clauses or equivalent safeguards
14.4 Your Rights Regarding Cross-Border Transfers
You have the right to:
(a) Know where your information is being transferred;
(b) Understand what safeguards protect your information in the destination country;
(c) Request that we do not transfer your information to a particular country (where feasible);
(d) Request that we use alternative service providers or methods that do not require cross-border transfer (where possible).
For more information about cross-border transfers or to raise concerns, contact us at POPIA@isangoenterprises.co.za.
15. CHILDREN'S PRIVACY
15.1 Not Directed to Children
Our Website and services are not directed to children under 18 years of age. We do not knowingly collect personal information from children without parental or guardian consent.
15.2 Children Under 18
If a child under 18 wishes to use our Website or services, they must:
(a) Have parental or guardian consent and supervision;
(b) Provide accurate information;
(c) Not submit personal information without parental knowledge;
(d) Not submit sensitive information (e.g., identification numbers, financial details).
15.3 Parental Rights
Parents and guardians of children under 18 have the right to:
(a) Know what personal information we have collected from their child;
(b) Review and update their child's personal information;
(c) Request deletion of their child's information;
(d) Withdraw consent for collection and processing.
15.4 Special Protections for Children
Personal information of children is subject to additional protections:
(a) We do not engage in direct marketing to known children;
(b) We do not use behavioral profiling or tracking of children;
(c) We do not share children's information with third parties for marketing purposes;
(d) Children's information is deleted promptly when no longer necessary.
15.5 Contact If You Believe Your Child's Information Is Collected
If you believe we have collected personal information from a child without proper consent, please contact us immediately at POPIA@isangoenterprises.co.za so we can investigate and take appropriate action.
16. YOUR RIGHTS AS A DATA SUBJECT
POPIA grants you significant rights regarding your personal information. We are committed to respecting and facilitating these rights. Below is a summary of your key rights and how to exercise them.
16.1 Right of Access
Right: You have the right to know whether we hold personal information about you, and if we do, to request access to that information.
What We Will Provide: Upon request, we will provide you with: - Confirmation of whether we process your personal information - The personal information we hold about you - The categories of personal information - Why we are processing it - Who we may have shared it with - How long we will retain it
How to Exercise: Submit a written request to POPIA@isangoenterprises.co.za or by mail to the address in Section 20. Your request must include: - Your full name and contact details - Clear description of the information you seek - Reasons for your request (if any)
Our Response: We will respond to your access request within 30 days. If we cannot comply within 30 days, we will notify you and provide a revised timeframe (not exceeding 60 days).
Exemptions: We may refuse access in limited circumstances, such as where the information relates to legal proceedings, contains information about third parties, or is subject to legal privilege.
16.2 Right to Correction
Right: You have the right to request correction of personal information about you that is inaccurate, incomplete, misleading, or outdated.
What We Will Do: Upon receiving a correction request, we will: - Review the information you dispute - Correct inaccurate or incomplete information - Update our records - Notify any third parties to whom we disclosed the incorrect information (where practicable)
How to Exercise: Contact us with details of: - The specific information you believe is inaccurate or incomplete - The correct information - Reasons for the correction request
Our Response: We will assess your request and notify you of our decision within 30 days. If we correct the information, we will confirm this to you. If we refuse, we will explain our reasons and inform you of your right to lodge a complaint with the Information Regulator.
16.3 Right to Deletion
Right: In certain circumstances, you have the right to request deletion of personal information about you.
When You Can Request Deletion: - The information is no longer necessary for the purpose it was collected - Your consent is the lawful basis for processing, and you withdraw consent - You object to processing and have a ground for objection - The information was collected unlawfully - Deletion is required by law
When We May Refuse Deletion: - We have a legal obligation to retain the information - Deletion would interfere with our legitimate legal or business interests - You have a contractual obligation with us that requires the information
How to Exercise: Submit a written deletion request to POPIA@isangoenterprises.co.za specifying: - The information you wish to be deleted - Reasons for your request
Our Response: We will respond within 30 days. If we delete your information, we will confirm this. If we refuse, we will explain our reasons and your right to lodge a complaint.
Note: Deletion of information may make it impossible for us to provide certain services to you (e.g., if you request deletion of your contact details, we cannot respond to future enquiries).
16.4 Right to Object
Right: You have the right to object to processing of your personal information in certain circumstances.
When You Can Object: - Processing is based on legitimate interest, and you believe our interest does not outweigh your privacy rights - We are using your information for direct marketing purposes - We are processing your information for profiling, analytics, or automated decision-making
How to Exercise: Contact us at POPIA@isangoenterprises.co.za and specify: - The processing activity you object to - Grounds for your objection - What action you want us to take (cease processing, delete, etc.)
Our Response: We will assess your objection and notify you of our decision within 30 days. If we agree with your objection, we will cease the relevant processing. If we refuse, we will explain our reasons.
16.5 Right to Restrict Processing
Right: In certain circumstances, you have the right to request that we restrict (limit) our processing of your personal information while a request is being considered or investigated.
When You Can Request Restriction: - You believe the information is inaccurate (while we verify it) - Processing is unlawful, but you don't want it deleted - We no longer need the information, but you need us to retain it for a legal claim - You have objected to processing (while we assess your objection)
How to Exercise: Contact us and specify: - The information you wish to restrict processing of - Reasons for the restriction request
Our Response: We will implement restrictions as requested while we investigate your claim.
16.6 Right to Data Portability
Right: In certain circumstances, you have the right to request a copy of your personal information in a structured, commonly used, machine-readable format, so you can transfer it to another service provider.
When You Can Request Data Portability: - We are processing your information based on your consent - We are processing your information for contract performance - We hold structured personal information about you
How to Exercise: Contact us at POPIA@isangoenterprises.co.za and request a data portability export.
Our Response: We will provide your information in a structured, machine-readable format (e.g., CSV, Excel, PDF) within 30 days. Where technically feasible, we can transfer the information directly to another service provider of your choice.
Limitations: We are not required to provide data portability where the information was not actively provided by you, or where providing it would be technically complex.
16.7 Right Not to Be Subject to Automated Decision-Making
Right: You have the right not to be subject to automated decision-making (including profiling) that produces legal or similarly significant effects concerning you.
What This Means: We will not make decisions about you based solely on automated processing without human review, unless: - The decision is necessary to enter into or perform a contract with you - You have consented - The decision is authorized by law
Our Practice: Our Website does not currently employ fully automated decision-making or profiling that produces legal effects. However, if this changes, we will notify you and ensure you have human review rights.
16.8 Right to Lodge a Complaint
Right: If you are dissatisfied with how we handle your personal information or your data subject rights, you have the right to lodge a formal complaint with the Information Regulator (see Section 18).
17. HOW TO LODGE A COMPLAINT
17.1 Internal Complaint Process
If you have a concern about how we handle your personal information, we encourage you to contact us first so we can try to resolve the matter.
Step 1: Contact Us
Submit a written complaint to:
Isango Enterprises (Pty) Ltd Mr Kwakhanya Magutywa Information Officer Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue, Selborne, East London, Eastern Cape, 5201
Include in your complaint: - Your full name and contact details - Clear description of your complaint - Specific details about how we have not complied with this Privacy Policy - What action you are requesting - Supporting documentation (if any)
Step 2: Our Response
We will acknowledge your complaint within 5 business days and will investigate thoroughly. We will provide a substantive response within 30 days. If we require more time, we will notify you of the revised timeframe.
Step 3: Escalation
If you are unsatisfied with our response, you have the right to escalate your complaint to the Information Regulator (see Section 18).
17.2 Complaints to the Information Regulator
See Section 18 below for details on how to lodge a formal complaint with the Information Regulator.
18. THE INFORMATION REGULATOR
18.1 What Is the Information Regulator?
The Information Regulator (officially the "South African Human Rights Commission") is an independent office established under POPIA to:
- Oversee compliance with POPIA
- Investigate complaints about privacy violations
- Enforce data protection rights
- Provide information to the public about their privacy rights
18.2 When to Contact the Information Regulator
You may lodge a complaint with the Information Regulator if:
(a) You have contacted us about a privacy concern and are dissatisfied with our response;
(b) We have refused to grant your data subject rights without valid reason;
(c) You believe we have violated your privacy rights under POPIA;
(d) We have failed to notify you of a security breach.
18.3 How to Lodge a Complaint with the Information Regulator
Contact Details:
Information Regulator (South African Human Rights Commission) Private Bag X2700 Houghton 2041 South Africa
Telephone: +27 (0)10 023 0911 Email: complaint.IR@sahrc.org.za Website: https://www.justice.gov.za/inforeg/
To Lodge a Complaint:
(a) Submit a written complaint form (available on the Information Regulator's website);
(b) Include your full name, contact details, and company name (if applicable);
(c) Provide a clear description of the privacy violation;
(d) Include evidence supporting your complaint (documents, emails, etc.);
(e) Include details of any steps you have taken to resolve the matter with us;
(f) Pay the required complaint fee (currently R100 for South African residents; fees may apply for international complainants).
18.4 Information Regulator's Powers
The Information Regulator may:
(a) Investigate your complaint;
(b) Request information from Isango Enterprises;
(c) Conduct compliance audits;
(d) Issue compliance notices;
(e) Impose administrative fines (up to 10% of annual turnover for serious violations);
(f) Order remedies (correcting information, deletion, compensation);
(g) Refer serious violations to law enforcement.
18.5 Your Rights During an Investigation
While the Information Regulator investigates your complaint, you have the right to:
(a) Participate in the investigation process;
(b) Submit additional evidence or information;
(c) Request updates on the progress of the investigation;
(d) Appeal the Information Regulator's decision.
19. CHANGES TO THIS POLICY
19.1 When We Update This Policy
We may update this Privacy Policy from time to time to reflect:
(a) Changes in applicable legislation or regulatory guidance;
(b) Changes to our data processing practices;
(c) Changes to our services or website features;
(d) Improvements in clarity or transparency;
(e) Feedback from data subjects or the Information Regulator.
19.2 How We Notify You of Changes
When we make material changes to this Privacy Policy:
(a) We will update the version number and effective date at the top of the policy;
(b) We will post the revised policy on our Website;
(c) We will notify existing contacts via email of material changes (if you have provided your email address);
(d) We will highlight the key changes (usually in a summary section);
(e) If changes significantly impact your rights or our processing, we may seek your renewed consent.
19.3 Continued Use Implies Acceptance
Your continued use of our Website after we publish changes to this Privacy Policy constitutes your acceptance of the revised policy. If you do not agree with changes, you have the right to:
(a) Stop using our Website;
(b) Request deletion of your personal information;
(c) Lodge a complaint with us or the Information Regulator.
19.4 Version History
Version 1.0: Effective 19 July 2026 (Initial publication)
20. CONTACT INFORMATION
20.1 Data Subject Requests
If you have questions about this Privacy Policy, wish to exercise your data subject rights, or have privacy concerns, please contact:
Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd
Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa
20.2 Alternative Contact
If you are unable to contact the Information Officer, you may contact:
General Enquiries Isango Enterprises (Pty) Ltd
Email: info@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Website: https://www.isangoenterprises.co.za
20.3 Response Times
We commit to acknowledging your request within 5 business days and providing a substantive response within 30 days (or 60 days in complex cases).
20.4 No Fee for Data Subject Requests
Data subject requests (access, correction, deletion, etc.) are provided at no cost. We will not charge you a fee unless your request is excessive or manifestly unfounded, in which case we will notify you and discuss any fees before proceeding.
21. ACKNOWLEDGMENT
By using our Website, you acknowledge that you have read and understood this Privacy Policy and agree to our collection, use, and processing of your personal information in accordance with its terms.
If you do not agree with our privacy practices, please do not use our Website.
← Back to Isango Enterprises