060 279 5587 info@sitect.co.za 139 Davies Street, Doornfontein, Johannesburg, 2001 Gauteng, SA
Legal · POPIA Notice

Your rights under POPIA

A focused notice on your rights as a data subject under the Protection of Personal Information Act, 4 of 2013 — and how to exercise them with Sitect.

POPIA Act 4 of 2013 Effective 1 May 2026 Information Officer appointed

POPIA in plain English.

POPIA gives you specific rights over your personal information. This notice tells you what those are, what we do with your information, and how to get us to change, share or delete what we hold.

1 What POPIA is

The Protection of Personal Information Act, 4 of 2013 (POPIA) is South Africa's data-protection law. It came into full effect on 1 July 2021 and is enforced by the Information Regulator of South Africa. It gives every data subject (you) specific rights over how organisations collect, use, store, share and dispose of personal information about you.

This notice should be read together with our Privacy Policy and Cookie Policy. Where any of these conflict, the most protective interpretation in your favour applies.

2 Our commitment to POPIA

Sitect is fully committed to POPIA compliance. In practical terms this means:

  • We process personal information only for lawful, specific and explicitly defined purposes.
  • We collect only what's reasonably necessary — no fishing expeditions.
  • We keep your information accurate and up-to-date, and correct it on request.
  • We keep it secure (encryption, access controls, audit logs, training).
  • We don't keep it longer than necessary — every category has a retention period.
  • We share it only with sub-processors who are themselves POPIA-compliant.
  • We notify you (and the Regulator) if a breach occurs.
  • We respond to data-subject requests within 30 days.
  • We have an appointed Information Officer responsible for compliance.

3 Our Information Officer

Under POPIA section 56, every responsible party must designate an Information Officer. Our Information Officer is registered with the Information Regulator and is contactable for any POPIA-related matter:

  • Office: Information Officer, Sitect (Pty) Ltd
  • Email: info-officer@sitect.co.za
  • Postal: 139 Davies Street, Doornfontein, Johannesburg, 2001 Gauteng, South Africa
  • Phone: 060 279 5587
  • Response SLA: within 30 days of a substantive request (typically much faster)

4 Your 8 rights under POPIA

POPIA section 5 gives every data subject the following rights. Each link below jumps to the section of this notice explaining how to exercise that right:

5 Categories of personal information we hold

CategoryExamplesSource
IdentityName, ID/passport, role, companyFrom you / public sources
ContactEmail, phone, addressFrom you
FinancialVAT number, banking, billingFrom you
TechnicalIP, browser, device, cookiesAutomatic
BehaviouralPage views, clicks, search queriesAutomatic
ProjectBusiness info, NDAs, deliverablesFrom you
CommunicationEmails, chat, support ticketsFrom you
MarketingNewsletter status, marketing consentFrom you

We do not deliberately collect special personal information (race, ethnicity, religion, biometrics, health, sexual orientation, political views) under POPIA section 26. If this is required for an engagement, we obtain explicit consent first.

6 Purposes & lawful basis

POPIA permits processing only on specific lawful bases. We rely on:

Lawful basisUsed for
Consent (s.11(1)(a))Newsletter, marketing, optional cookies, special PI
Contract performance (s.11(1)(b))Delivering services you've engaged us for
Legal obligation (s.11(1)(c))Tax records, regulatory reporting
Public interest (s.11(1)(d))Rare — where law specifically authorises
Legitimate interest (s.11(1)(f))Security, fraud prevention, business operation

7 Subject Access Request

You have the right to confirm whether Sitect holds personal information about you, and to receive a copy. Under POPIA section 23:

  1. Send a written request to our Information Officer at info-officer@sitect.co.za using POPIA prescribed Form 2 (we will provide it on request).
  2. Include sufficient information to identify yourself (we may ask for proof of identity to prevent unauthorised disclosure).
  3. Specify what you want: confirmation, a copy, or details of recipients.
  4. We respond within 30 days (usually within a week).
  5. A reasonable fee may apply for excessive or repeated requests; ordinary requests are free.

8 Correction & deletion

Under POPIA section 24, you may ask us to correct or delete personal information that is:

  • Inaccurate, irrelevant, excessive, out-of-date or incomplete.
  • Obtained unlawfully.
  • No longer needed for the purpose it was collected.

Send your request to info-officer@sitect.co.za, specifying clearly what should be changed or deleted. We will action it within 30 days. Where deletion is not possible (e.g. SARS retention requirements), we explain why and propose an alternative (such as restriction or anonymisation).

9 Right to object

Under POPIA section 11(3), you have the absolute right to object to:

  • Direct marketing — withdraw at any time, no questions asked.
  • Processing on legitimate-interest grounds where your fundamental rights or freedoms outweigh our interest.

You may also object to automated decision-making (POPIA s.71) where the decision has a significant effect on you. We currently do not make such fully-automated decisions without human review. If this changes, you will be notified.

10 Operators (sub-processors)

POPIA defines "operators" as third parties who process personal information on our behalf under our instructions. Every operator we use signs a written agreement requiring:

  • Processing only on our documented instructions.
  • Appropriate security measures equivalent to our own.
  • Confidentiality from their staff and contractors.
  • Cooperation with data-subject requests we receive.
  • Breach notification to us within 24 hours.
  • Deletion or return of personal information at end of engagement.

A current list of our operators is in section 6 of our Privacy Policy.

12 Cross-border transfers

Under POPIA section 72, your personal information may be transferred outside South Africa only where:

  • The destination country has substantially similar data-protection laws (e.g. EU/GDPR jurisdictions), or
  • The operator has binding rules or contractual safeguards equivalent to POPIA's protections, or
  • You have consented, or
  • The transfer is necessary for performance of a contract with you.

Our default cloud region is AWS Cape Town (af-south-1) — meaning the bulk of your operational data stays inside South African borders. Cross-border transfers are limited to specific service providers (analytics, email delivery, AI providers) and are governed by standard contractual clauses.

13 Data breach response

If a security compromise occurs where personal information has been (or is reasonably believed to have been) accessed or acquired by an unauthorised person, POPIA section 22 requires us to notify both the Information Regulator and affected data subjects.

Our breach response timeline:

  • Within 24 hours of detection — internal incident response, scope assessment, containment.
  • Within 72 hours — Information Regulator notified with preliminary findings.
  • Within 7 days — affected data subjects notified in writing with: incident description, possible consequences, what we're doing about it, what you can do, contact details of our Information Officer.
  • Within 30 days — full incident report filed with the Regulator including remediation plan.

14 Lodge a complaint

If you believe Sitect has not handled your personal information in line with POPIA, you may complain to:

Sitect first (preferred)

Contact our Information Officer at info-officer@sitect.co.za. We will investigate and respond within 30 days. Most issues are resolved at this stage.

Information Regulator of South Africa

If you are not satisfied with our response, lodge a complaint with the Information Regulator:

The Regulator's complaint form is on its website.

Civil court

You also have a right under POPIA s.99 to institute civil proceedings for damages — separate from any complaint to the Regulator.

15 Contact us

For any POPIA-related matter:

Exercise your rights — any time, no fee for ordinary requests

If you want to know what we hold, correct it, delete it, or just have a conversation about how we handle your information, our Information Officer is the person to ask.