Privacy Policy
1. Introduction
Exponential IT Solutions CC, registration number 1998/040919/23, operating as Exponential IT Solutions] ("we," "us," or "our"), complies with the Protection of Personal Information Act No. 4 of 2013 (POPIA) and other applicable data protection laws. This policy explains how we collect, use, disclose, and protect your personal information.
2. What Personal Information We Collect
We may collect:
- Identifiers: Name, ID number, passport number.
- Contact Details: Email, phone number, physical address.
- Demographic Data: Age, gender, language preferences.
- Financial Data: Bank details, payment history (if applicable).
- Online Data: IP address, device information, cookies, browsing behaviour.
- Sensitive Data: Race, health information (only with explicit consent or legal justification).
3. How we collect information
- Directly: When you contact us, use our services, register on our website, or subscribe to newsletters.
- Automatically: Via cookies, server logs, and analytics tools when you visit our website.
- Third Parties: From partners, public databases, or social media (where legally permitted).
4. Purposes for Processing Personal Information
We use your data to:
- Provide and improve our products/services.
- Process payments and fulfill contracts.
- Communicate with you (e.g., support, updates).
- Comply with legal obligations (e.g., tax, POPIA).
- Send marketing communications (with your consent).
- Protect against fraud and security risks.
5. Lawful Basis for Processing
We process personal information based on:
- Your consent (e.g., for marketing).
- Contractual necessity (e.g., to deliver services).
- Legal obligations (e.g., record-keeping under tax laws).
- Legitimate interests (e.g., improving our website).
6. Sharing of Personal Information
We may share data with:
- Service Providers: Payment processors, IT support, cloud storage providers.
- Legal Authorities: Where required by law (e.g., court orders).
- Business Partners: With your consent (e.g., joint promotions).
- Group Companies: Affiliates within our corporate group.
- We ensure third parties comply with POPIA and confidentiality agreements.
7. Cross-Border Transfers
If data is transferred outside South Africa (e.g., to cloud servers), we will:
- Obtain your consent if required by POPIA.
- Ensure recipients are subject to adequate data protection laws.
8. Data Security
We implement technical and organizational measures to protect personal information, including:
- Encryption, firewalls, and access controls.
- Regular security audits.
- Employee training on POPIA compliance.
9. Data Retention
We retain personal information:
- Only as long as necessary for the purposes stated.
- As required by law (e.g., financial records for 5 years).
- Securely delete/anonymize data afterward.
10. Your Rights Under POPIA
You have the right to:
- Access your personal information.
- Correct inaccurate or incomplete data.
- Delete data (where no legal basis for retention exists).
- Object to processing for direct marketing.
- Withdraw consent (where processing is consent-based).
- To exercise these rights, contact us at [Privacy Contact Email/Address].
11. Cookies and Tracking Technologies
- Our website and applications use cookies to enhance user experience.
- You can manage preferences via your browser settings.
- See our Cookie Policy for details.
12. Marketing Communications
- We send promotional emails/SMS only with your opt-in consent.
- You may unsubscribe anytime using the link in our emails or by contacting us.
13. Children’s Privacy
- We do not knowingly collect data from children under 18 without parental consent.
14. Updates to This Policy
- We may update this policy periodically. The latest version will be posted on our website / application with the effective date.
15. Contact Us
For questions, requests, or complaints:
Information Officer: Michael Caldwell
Email: privacy@exponential.co.za.co.za
Address: 4 Sagewood Close, Kleinbron Park, Brackenfell, 7560, South Africa
Phone: +27 78 456 4523
You may lodge complaints with the South African Information Regulator:
Website: https://www.justice.gov.za/inforeg/
Email: inforeg@justice.gov.za
16. Acknowledgement
- By using our services, you acknowledge reading this policy and consent to the processing of your personal information as described.