Privacy Policy
Last updated: 23 August 2026
HTM LEDGR (“HTM LEDGR”, “the Services”, “we”, “us”) is a product of HTM Legacy (Pty) Ltd, a private company duly incorporated in the Republic of South Africa under registration number 2021/423883/07, of Pretoria, South Africa (“HTM Legacy”, the “Supplier”). This policy sets out, for purposes of compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), what personal information the Supplier collects through htmledgr.com and the HTM LEDGR application, the purposes for and grounds upon which it is processed, the parties to whom it may be disclosed, the periods for which it is retained, and the rights available to data subjects in respect thereof, together with the manner in which such rights are, as a matter of law and administrative process, to be exercised.
Where the Customer uses HTM LEDGR to generate documents addressed to its own clients, the Customer is the responsible party (in the terminology of POPIA, analogous to a “data controller”) in respect of the personal information of those clients, and the Supplier acts solely as the Customer’s operator (analogous to a “data processor”), processing such information exclusively on the Customer’s documented instructions and for no independent purpose of its own. This policy addresses both capacities: the Supplier’s processing of the Customer’s own account information as responsible party, and the Supplier’s processing of information on the Customer’s behalf as operator. To the extent any provision of this policy is inconsistent with the Customer’s obligations as responsible party under clause 5 of our Terms of Service, the Terms of Service shall prevail as between the Supplier and the Customer.
The status of this policy. This policy constitutes, and is intended to operate as: (a) the notification to a data subject contemplated in section 18(1) of POPIA, being the record of the information collected, the purpose of its collection, the recipients to whom it may be supplied, and the further particulars there prescribed; and (b) together with our Terms of Service, the written contract between responsible party and operator required by section 21(1) of POPIA, by which the Supplier, in its capacity as the Customer’s operator, undertakes to establish and maintain the security measures referred to in section 19 of that Act, to process personal information only with the knowledge or authorisation of the Customer as required by section 20(a), to treat that information as confidential and not to disclose it save as required by law or in the course of the proper performance of its duties as required by section 20(b), and to notify the Customer immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, as section 21(2) requires. A Customer requiring a separate, signed operator agreement for its own compliance records may request one at the address in clause 10 below; the absence of such a separate instrument does not affect the operation of this clause.
1. Information we process
1.1 Information provided directly
- Account details — name, email address, phone number, password (accounts created through a third-party sign-in provider do not give us a password), occupation, and a profile photo if you upload one.
- Business details — business or individual trading name, physical/postal address, VAT number, company registration (CIPC) number, financial year-end date, banking details displayed on your invoices (bank name, account holder, account number, branch code), and your logo.
- Client information you enter — the names, contact details, addresses and VAT numbers of the clients you save in your Clients Directory or type directly onto a quote, invoice, receipt or purchase order. The Customer warrants that it holds a lawful basis, within the meaning of section 11 of POPIA, for the processing of any such third-party personal information, in accordance with clause 5 of our Terms of Service.
- Financial records you create — line items, amounts, payment records, refunds, write-offs, expenses and the notes you attach to them. This is the core content of the Services; it is not analysed for any purpose other than operating the Customer’s account and calculating the totals and reports requested.
- Team information — names, emails, phone numbers, job titles and roles of people you invite to your workspace.
- Support correspondence — anything transmitted via the contact form, in-app support widget, or email.
1.2 Information collected automatically
- Device and sign-in security signals — when you sign in, we record a device identifier (so we can recognise browsers you’ve used before) and, if you enable it, alert you the first time your account is accessed from a new device. We keep a short list of your recent devices for this purpose only.
- Trial-abuse prevention signals — to stop the same business claiming a fresh free trial by deleting an account and signing up again, we derive irreversible one-way values from identifiers you have already supplied in the course of registering (including business registration, tax and banking identifiers) together with coarse, non-invasive characteristics of the browser used to sign up. Only these irreversible values are retained — never the underlying details, and they cannot be reversed to reveal your banking, tax or business information by us or by anyone else. We do not employ invasive device-fingerprinting techniques. They serve one purpose, at the point of signup: establishing whether a free trial has already been used. They are never used to identify or track you elsewhere, never disclosed to any third party, and never used to make any decision about your account thereafter. Your IP address is also recorded at signup for the same investigative purpose, but is never on its own a reason to refuse a signup, since South African mobile networks place many unrelated customers behind a single address.
- Local storage — your browser stores a small number of preference values on your own device (see our Cookie Policy for the full list) so things like your theme, font size, and remembered sign-in email persist between visits.
- Usage information — an internal activity log records who on your team performed key actions (created a document, recorded a payment, changed a role) and when, so you have an audit trail. This is visible to your own team, not to us, except as needed to provide support, investigate abuse, or comply with a legal obligation.
1.3 Organisation domain and business-name records
In addition to the signals described at clause 1.2, the Supplier maintains two further registries, distinct from the trial-abuse hashes, existing specifically to prevent one Organisation gaining unauthorised access to another’s workspace:
- Custom email domains. Where an Organisation’s owner signs up using an email address on a custom domain (that is, not a free consumer provider such as Gmail, Outlook, Yahoo, or similar SA webmail services), that domain is automatically recorded against the Organisation the first time it is used to onboard. This is not optional or hidden: it is what allows the Supplier to refuse a later, unrelated signup attempt on the same domain and direct that person to request an invitation instead, rather than allowing anyone who happens to share an employer’s email domain to create a second, unaffiliated Organisation and potentially confuse or defraud the first. An Organisation’s owner or administrator may add further domains it controls, or remove one previously recorded, from Settings → Team → Invitation Policy at any time; doing so does not affect any Organisation’s existing members.
- Business and trading names. The Organisation’s registered business or trading name is likewise recorded in a duplicate-checking registry at the time the Organisation is created, so that the Supplier can flag, and where appropriate decline, an attempt to register a second Organisation under a name already claimed by an existing one.
Both registries are processed on the Supplier’s legitimate interest, within the meaning of section 11(1)(f) of POPIA, in preventing unauthorised access to an Organisation’s workspace and in maintaining the integrity of the Organisation namespace within the Services; that interest is, the Supplier considers, not overridden by the interest or fundamental rights of the data subject, given the narrow and security-driven purpose to which the records are put and the fact that a domain or business name is not, of itself, sensitive personal information. Neither registry is accessible to any Organisation other than the one to which the record belongs, is used for marketing, is sold, or is disclosed to any third party save as described at clause 3.
1.4 Information from third parties
If you choose to sign in using a third-party sign-in provider rather than a password, that provider confirms your identity to us and supplies your name, email address and profile photo. We receive nothing further from it, and it receives nothing about your use of the Services. If you subscribe to a paid plan, our payment gateway provider tells us the outcome of the transaction (success, amount, plan) — we never receive or store your card number, expiry date or CVV; that information is captured directly by the payment gateway under its own terms.
2. Purposes and grounds of processing
Each category of personal information described at clause 1 is processed only for the purposes below, each of which is undertaken on one or more of the grounds set out in section 11(1) of POPIA (consent; necessity for the performance of a contract to which the data subject is party; compliance with a legal obligation; protection of a legitimate interest of the data subject; performance of a public duty; or the Supplier’s own or a third party’s legitimate interest, where not overridden by the data subject’s interests):
- To create and operate your account, workspace and team (contract necessity).
- To generate the quotes, invoices, receipts, purchase orders, statements and reports you create (contract necessity).
- To send transactional email (documents you send to clients, payment reminders, team invitations, receipts, verification and password-reset emails, service and outage notices, and — only where you’ve enabled them in Settings — payment/quote/team notifications) (contract necessity and, for optional notifications, consent).
- To bill your subscription via our payment gateway and keep your plan entitlements up to date (contract necessity).
- To detect and prevent fraud, trial abuse, duplicate-domain and duplicate-business-name registration, and unauthorised account access (see 1.2 and 1.3 above), and to give effect to any suspension or termination for breach as described in clause 8 of our Terms of Service (legitimate interest).
- To provide customer support when you contact us (contract necessity and legitimate interest).
- To meet our own legal, tax and accounting obligations, and to establish, exercise, or defend legal claims (legal obligation and legitimate interest).
- To send product updates or marketing email, but only if you’ve opted in — our newsletter signup is a separate, clearly-labelled action from creating an account (consent, within the meaning of section 69(1)(a) of POPIA). Separately, and in terms of section 69(1)(b) read with section 69(3) of POPIA, the Supplier may direct-market its own similar products or services to a data subject who is already a customer of the Supplier, whose contact details were obtained in the context of the sale of a product or service, and who has been given a reasonable opportunity to object, free of charge and without unnecessary formality, both at the time the information was collected and on the occasion of each communication; every such communication carries an unsubscribe mechanism, and an objection is given effect without charge.
We do not sell personal information, and we do not use your financial data to train any AI or machine-learning model. The Services do not make any decision, solely by automated means, that produces legal effects concerning a data subject or affects them to a similarly significant degree, within the meaning of section 71 of POPIA — every figure, reminder, or countdown the Services produce is, as set out in our Terms of Service, informational only and requires the Customer’s own judgment to act upon.
3. Operators and recipients of information
The Supplier engages a limited number of carefully selected service providers (“operators” as contemplated in POPIA) to perform defined functions in connection with the operation of the Services. Each is bound by written terms requiring it to process personal information only on the Supplier’s documented instructions, to apply appropriate security safeguards, and to treat the information as confidential. Each receives only such personal information as is reasonably necessary for the function it performs, and no more.
- Infrastructure and hosting — provides the secure environment in which your account, documents and files are stored and the Services are made available to you.
- Message delivery — transmits the documents you elect to send, together with reminders, invitations, verification messages and service notices, and, where you have opted in, our newsletter. It receives only the recipient address and the content of the message concerned.
- Payment processing — processes your subscription payment to the Supplier. Your card details are handled by that provider directly and are never received or stored by the Supplier; we are informed only of the outcome of a transaction.
- Aggregate product measurement — compiles statistical measures of how the Services are used, for the Supplier’s legitimate interests in their operation, security and improvement as contemplated in section 11(1)(f) of POPIA. It receives page-level, device-class, approximate-locality and referral-source data only, and receives no identifier of a data subject, no account or workspace identifier, and no element of the financial records, client information, banking particulars or document content processed within the Services. This processing is suppressed in its entirety where a “Do Not Track” or Global Privacy Control signal is transmitted, and no function or entitlement is conditioned upon or degraded by that election. Further particulars, including the trans-border flow contemplated in section 72 and the means of withholding it, appear in our Cookie Policy.
- Your own team members — Authorized Users you invite to your workspace can see the information their role permits, exactly as described in the Services.
Your account records and documents are held in the Republic of South Africa. Certain limited processing incidental to the operation of the Services may be performed outside the Republic. Where that occurs, the Supplier ensures that the recipient is subject to a law, binding agreement or corporate rules affording a level of protection substantially similar to the conditions for lawful processing under POPIA, as required by section 72 of that Act.
The Supplier does not share personal information with data brokers or advertising networks, does not sell personal information within the meaning of any applicable law, and does not disclose to any recipient, for measurement or any other purpose, the financial records, client information, banking particulars or document content processed by the Customer within the Services. The Supplier may disclose information where required or permitted by law, pursuant to a valid order of a court or other competent authority, a lawful direction of the Information Regulator, a request made in terms of the Promotion of Access to Information Act 2 of 2000, or where the Supplier, in its reasonable discretion, considers disclosure necessary to establish, exercise, or defend a legal claim, or to protect the rights, property, or safety of HTM Legacy, its users, or the public.
4. Retention
- Financial documents (quotes, invoices, receipts, purchase orders) are retained for a period determined by the Customer’s subscription plan — currently 12 months on Starter, 24 months on Growth, and an unlimited period on Business — measured from each document’s creation date. Two warnings are emailed in advance of deletion, and the final warning is a precondition of deletion rather than merely an accompaniment to it: clause 6.2 of our Terms of Service states the periods and that mechanism precisely, and is not repeated here. Export functionality remains available, on the terms set out in clause 6.3 of that Agreement, at any time prior thereto.
- The content of a closed Organisation is retained for 30 days following closure, during which the owner may reinstate the Organisation substantially as it stood, after which it is permanently and irrecoverably deleted. Clause 2 of our Cancellation Policy governs.
- Trial-abuse hashes (clause 1.2) are kept indefinitely, because their entire purpose is to remain valid evidence even after an account is deleted. They cannot be reversed into the original email, VAT number or registration number.
- Domain and business-name records (clause 1.3) are kept for as long as the Organisation to which they belong remains registered, and, following closure or termination, for such further period as the Supplier considers reasonably necessary to prevent immediate re-registration of the same domain or name in circumstances that would defeat the purpose described at clause 1.3.
- Account and team information is kept for as long as the account is active, and for a reasonable period thereafter to meet legal and accounting obligations, or, where access has been terminated for breach under clause 8.2 of our Terms of Service, for such further period as the Supplier considers reasonably necessary for evidentiary, legal, or regulatory purposes.
- Support correspondence is kept for as long as reasonably needed to resolve the query and for a record of the interaction.
Personal information is not retained for longer than is necessary to achieve the purpose for which it was collected, as required by section 14 of POPIA, save where a longer period is required or permitted by law, or is reasonably necessary for the Supplier to establish, exercise, or defend a legal claim.
5. Security
The Supplier takes reasonable technical and organisational measures, as contemplated in section 19 of POPIA, to safeguard the integrity and confidentiality of personal information in its possession or under its control, including:
- All data in transit is encrypted (HTTPS/TLS); data at rest is encrypted at the storage layer by our cloud infrastructure provider.
- Every read and write to your data is authorised against access rules scoped to your organisation, independently verified by an automated test suite.
- Optional two-factor authentication for your account, using a standard authenticator app, with single-use backup codes stored in a form we cannot read.
- New-device sign-in alerts and a mandatory email-verification gate.
- Password quality requirements when an account is created, including screening the proposed password against credentials known to have appeared in third-party data breaches — carried out without your password, or anything that could identify it, leaving your browser.
- Automated measures limiting repeated attempts against sign-in, password-reset and enquiry functions.
- Browser-level controls restricting where the application may load code from and where it may transmit information.
- Monitoring and alerting on security events of consequence.
- Role-based access control inside your own workspace, so team members only see what their role allows.
- An immutable, append-only audit trail on financial transactions and administrative changes of consequence, so a record cannot be silently altered after the fact.
No system of technical or organisational safeguards can be guaranteed to be perfectly secure, and the Supplier makes no warranty, representation, or undertaking, express or implied, to that effect. The measures above are those the Supplier considers appropriate and reasonable within the meaning of section 19 of POPIA; they are not, and are not represented to be, a guarantee against unauthorised access, and clause 9 of our Terms of Service applies to any claim arising from a compromise, subject always to the savings at sub-clause 9.5 thereof.
5.1 Notification of a security compromise, and who owes it to whom
The duty to notify upon a security compromise follows the capacity in which the information was held, and the two capacities described in the preamble to this policy produce two different duties. The Customer’s attention is specifically drawn to the second of them:
- Where the Supplier is the responsible party — that is, in respect of the Customer’s own account, business, team and billing information — the Supplier bears the duty under section 22 of POPIA, and will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, in one or more of the forms prescribed by section 22(4), taking into account the legitimate needs of law enforcement and any measures reasonably necessary to determine the scope of the compromise and to restore the integrity of its information systems, and subject to any delay determined under section 22(3).
- Where the Supplier is the Customer’s operator — that is, in respect of the personal information of the Customer’s own clients, and of any other third party whose information the Customer has entered into the Services — the Supplier’s duty is that imposed by section 21(2) of POPIA: to notify the Customer, immediately, where there are reasonable grounds to believe that such information has been accessed or acquired by an unauthorised person. The corresponding duty under section 22 of POPIA to notify the Information Regulator and the affected data subjects in respect of that information is the Customer’s own, as responsible party, and not the Supplier’s, and remains the Customer’s irrespective of the cause of the compromise. The Supplier will furnish the Customer with such information within the Supplier’s possession as the Customer reasonably requires in order to discharge that duty, but does not discharge it on the Customer’s behalf, does not notify the Customer’s clients directly, and gives no advice as to whether or how the duty arises in any particular case. Clause 5 of our Terms of Service records the indemnity the Customer gives in respect of its own non-compliance with POPIA.
Your attention is specifically drawn to the following provisions, which limit the liability of the Supplier and of others, place a risk upon the Customer, and impose an obligation of indemnity upon the Customer — section 49 of the Consumer Protection Act 68 of 2008
In short, and in plain language: we protect your data seriously, but no system is perfectly secure and we do not promise that it is. When you put your own clients’ details into HTM LEDGR, those details remain your responsibility under South African privacy law — we hold them for you, but you are the one the law calls the responsible party. That means you need a lawful reason to enter someone’s information, and if there is ever a breach affecting your clients’ data, telling the Information Regulator and telling your clients is your job, not ours. We will tell you straight away, and give you what we know so you can do it. If you do not do it, and someone claims against us as a result, you agree to cover us. Nothing here takes away a right that South African law does not permit us to take away: your and your clients’ rights under POPIA, including the right to complain to the Information Regulator and to sue for damages, are untouched, and sub-clause (e) says so in terms. The formal wording follows.
- (a) Acknowledgements of fact. The Customer acknowledges, each of these being an acknowledgement of fact within the meaning of section 49(1)(d) of the Consumer Protection Act 68 of 2008 (the “CPA”), that: (i) no system of technical or organisational safeguards can be guaranteed to be perfectly secure, and the Supplier has given no warranty to that effect; (ii) in respect of the personal information of the Customer’s own clients and of any other third party entered into the Services by or on behalf of the Customer, the Customer is the responsible party and the Supplier is its operator, within the meanings given to those terms in POPIA; and (iii) the Supplier neither reviews, verifies, nor advises upon the lawfulness of the Customer’s own collection or use of any such information.
- (b) Assumption of risk by the Customer as responsible party. The Customer assumes the risk of, and bears in full, each of the following, no Indemnified Person (as that term is defined in sub-clause 9.4 of our Terms of Service) bearing any liability in respect thereof: establishing and maintaining a lawful basis, within the meaning of section 11 of POPIA, for every item of third-party personal information it enters into the Services; discharging its own notification duty under section 22 of POPIA in respect of a compromise affecting that information, as set out in clause 5.1 above; responding to any request, objection, or complaint made by a data subject in respect of that information; configuring the roles and permissions of its Authorized Users so that access to that information is confined to those who ought to have it; and securing every file containing that information once it has been exported out of the Services, as clause 6.3 of our Terms of Service records.
- (c) Limitation of liability. Subject in every respect to sub-clause (e) below, and without derogating from clause 9 of our Terms of Service, which applies of its own force, no Indemnified Person shall be liable to the Customer for any indirect, incidental, special, consequential, or punitive loss, or for any loss of profit, revenue, goodwill, business, or reputation, arising out of or in connection with: a security compromise not attributable to a failure by the Supplier to take the measures contemplated in section 19 of POPIA; the Customer’s own act or omission, or that of any Authorized User, in relation to personal information; the Customer’s own non-compliance with POPIA or any other data protection law; or the loss, theft, or unauthorised disclosure of any file after it has been exported out of the Services.
- (d) Indemnity. Subject in every respect to sub-clause (e) below, the Customer indemnifies each Indemnified Person against, and holds each of them harmless from, all claims, demands, regulatory complaints, investigations, enforcement notices, administrative fines, penalties, actions, proceedings, losses, damages, liabilities, costs and expenses (including legal costs upon the attorney-and-own-client scale) of whatsoever nature arising out of or in connection with any matter referred to in sub-clause (b) above, including any claim brought by a client of the Customer, by an Authorized User, by a member, employee or officer of the Customer, or by the Information Regulator. This sub-clause survives the termination or expiry of the Customer’s subscription, howsoever occasioned, and is in addition to, and does not derogate from, clauses 5, 9 and 10 of our Terms of Service.
- (e) Savings: rights that cannot lawfully be excluded. Nothing in sub-clauses (a) to (d) above, or anywhere else in this policy, excludes, limits, waives, deprives any person of, avoids, sets aside, or overrides, or purports to do any of those things in respect of: (i) any right of a data subject under POPIA, including the rights conferred by Chapter 3 thereof, the right to lodge a complaint with the Information Regulator under section 74, and the right to institute a civil action for damages under section 99 — which section renders a responsible party liable for a breach whether or not there is intent or negligence on its part, and admits only the defences enumerated in section 99(2); (ii) any duty imposed upon the Supplier by section 19, 20, 21 or 22 of POPIA in the capacity in which it holds the information concerned; (iii) any right conferred upon the Customer by the CPA, or any obligation or duty imposed upon the Supplier thereby, in a case to which that Act applies, such a provision being prohibited by section 51(1)(b)(i) and (ii) thereof; (iv) any liability of the Supplier, or of any person acting for or controlled by the Supplier, for loss directly or indirectly attributable to gross negligence, nor does anything herein purport to constitute an assumption of risk or liability by the Customer for such loss, such provisions being prohibited by section 51(1)(c)(i) and (ii) of the CPA; (v) any liability for fraud or wilful misconduct; or (vi) any other right, remedy, or protection conferred by South African law which cannot lawfully be excluded, limited, or waived by agreement, including at common law. To the extent that any such provision contravenes section 51 of the CPA, it is void to that extent, and to that extent only, in terms of section 51(3) thereof, and shall be severed, the remainder of this policy continuing in full force and effect.
The Supplier records that the fact, nature, and effect of sub-clauses (a) to (d) above are, by the conspicuous form and manner in which they are here presented, by the plain-language summary with which this panel opens, and by the publication of this policy at a stable public address at which it is continuously accessible before, at, and after the time of registration, drawn to the attention of the Customer in a manner and form intended to satisfy sections 49(3), 49(4), and 49(5) of the CPA, read with section 22 thereof, in every case to which that Act applies.
6. Your rights, and how they are exercised
Subject to the limitations, exemptions, and verification requirements provided for under POPIA, a data subject has the right to:
- request confirmation of, and access to, the personal information the Supplier holds concerning them;
- request correction of inaccurate, outdated, incomplete, or misleadingly recorded information, most of which can be amended directly in Settings;
- request the deletion or destruction of a record of personal information that the Supplier is no longer authorised to retain, subject always to the Supplier’s legal, tax, accounting, and evidentiary retention obligations, including those described in clause 4 above;
- object, on reasonable grounds, to the processing of personal information relating to them, including processing carried out for purposes of direct marketing, and to opt out of marketing communications at any time via the unsubscribe mechanism provided;
- where processing is based on consent, withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal; and
- lodge a complaint with the Information Regulator (inforegulator.org.za) if they consider that the Supplier has processed their personal information otherwise than in accordance with POPIA.
A request to exercise any of the foregoing rights must be submitted in writing to support@htmledgr.com. The Supplier aims to acknowledge a request within a reasonable time and to respond substantively without undue delay, and reserves the right to require such proof of identity as it reasonably considers necessary before acting on the request, to decline a request to the extent permitted by section 23, 25, or any other applicable provision of POPIA, and to levy such fee as may be prescribed for the provision of a copy of a record. Nothing in this clause 6 entitles a data subject to make use of the Services’ self-service functionality otherwise than in accordance with the Customer’s subscription and account status, nor overrides clause 8.2 of our Terms of Service in respect of an account terminated for breach.
7. Children’s privacy
HTM LEDGR is a business tool intended for use exclusively by persons of at least 18 years of age, and is not directed at, marketed to, or knowingly used by children. The Supplier does not knowingly collect personal information relating to a child, as defined in POPIA, and reserves the right to terminate any account it reasonably believes to be held by, or predominantly used by, a person under the age of 18.
8. Relationship to our other policies
This policy should be read together with our Terms of Service, our Cookie Policy (which addresses browser-stored information specifically), and our Service Level Agreement. Where this policy addresses the treatment of personal information and any of those documents addresses a related but distinct matter (for example, the consequences of account termination), both apply, each to the extent of its own subject matter.
9. Changes to this policy
The Supplier may update this policy from time to time as the Services evolve. Material changes will be flagged in-app or by email; the “Last updated” date at the top of this page reflects the version currently in force, which shall apply to the exclusion of any prior version.
10. Contact us / Information Officer
For any privacy-related query or request, including a request to exercise a right described in clause 6, email support@htmledgr.com or use our contact page.
The Supplier’s Information Officer, as contemplated in section 1 read with sections 55 and 56 of POPIA, is Hope T. Madike, Chief Executive Officer of HTM Legacy (Pty) Ltd, who may be reached through the contact details set out above. The responsibilities of that office are those set out in section 55(1) of POPIA, namely the encouragement of compliance by the Supplier with the conditions for the lawful processing of personal information, dealing with requests made to the Supplier pursuant to that Act, working with the Information Regulator in relation to any investigation conducted pursuant to Chapter 6 thereof, and otherwise ensuring the Supplier’s compliance with that Act. A data subject who is dissatisfied with the outcome of a request or complaint dealt with by the Information Officer retains the right, in terms of section 74 of POPIA, to lodge a complaint directly with the Information Regulator, whose particulars appear in clause 6.
Access to records under PAIA. A request for access to a record held by the Supplier, made otherwise than as an exercise of a data subject’s own rights under clause 6 above, falls to be made in terms of the Promotion of Access to Information Act 2 of 2000, and is dealt with in accordance with that Act and the manual compiled by the Supplier in terms of section 51 thereof, a copy of which may be requested at the address in this clause 10. The grounds upon which access to a record may or must be refused are those set out in Chapter 4 of Part 3 of that Act, and the Supplier reserves every such ground, including without limitation the mandatory protection of the privacy of a third party who is a natural person, the mandatory protection of the commercial information of a third party or of the Supplier itself, and the protection of records privileged from production in legal proceedings. Clause 8.2 of our Terms of Service records that, following a termination for breach, a request of the kind there described is to be made through this formal channel and not through the Services’ ordinary self-service functionality.
Questions about any of this? Reach us here: