Protection of personal information
POPIA Notice
VanguardTech is committed to processing personal information responsibly, lawfully and transparently in accordance with the Protection of Personal Information Act 4 of 2013.
Effective date 15 July 2026
1. Scope
This notice applies to personal information processed through VanguardTech’s website, enquiries, quotations, contracts, billing, custom software projects, website projects, API integrations, SQL and reporting work, domain services, managed hosting, website care, software maintenance, cloud infrastructure and technical support.
2. Accountability and processing limitation
VanguardTech aims to process only information that is adequate, relevant and reasonably necessary for a defined business or service purpose. Where we determine the purpose and means of processing, we act as the responsible party. Where a client determines those purposes and we process information only to host, support, maintain or integrate the client’s system, we may act as an operator.
3. Purpose specification
Information is collected for specific purposes such as answering an enquiry, scoping a project, delivering contracted services, managing a domain or hosting account, providing support, monitoring service health, securing infrastructure, maintaining backups, billing and complying with legal obligations. We avoid retaining information longer than necessary for those purposes, subject to contractual, backup, dispute and statutory retention requirements.
4. Further processing and quality
We take reasonable steps to keep personal information complete, accurate, not misleading and updated where necessary. Further processing should remain compatible with the original purpose unless another lawful basis applies. Clients should notify us when account contacts, authorised users or domain information changes.
5. Openness
Our Privacy Policy, Cookie Policy and this POPIA Notice explain the categories of information we process, the purposes, possible recipients, security approach and available rights. Project-specific processing may also be governed by a quotation, service agreement, data-processing terms, SLA or client instruction.
6. Security safeguards
Safeguards are selected according to the service and risk. They may include access restrictions, unique credentials, encryption in transit, secure hosting controls, patching, malware protection, backups, audit or application logs, firewall controls and incident investigation. Clients are responsible for protecting their own passwords, user access and devices, and for promptly reporting suspected compromise.
7. Security compromises
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, VanguardTech will assess the incident and follow the notification duties that apply to its role. When acting as an operator, we will notify the responsible client as soon as reasonably possible so that the client can meet its obligations.
8. Data subject participation
A data subject may request confirmation of whether VanguardTech holds personal information about them and may request access, correction or deletion, subject to lawful limitations. A person may also object to processing in the circumstances allowed by POPIA or withdraw consent where consent is the legal basis. Requests should be sent to info@vanguardtech.co.za.
9. Direct marketing
VanguardTech may communicate with existing clients about relevant services within the limits allowed by law and may contact a prospective client where consent or another lawful basis applies. Marketing messages will provide a reasonable way to opt out. Service notices, security alerts, billing messages and communications required to perform an agreement are not marketing messages.
10. Cross-border processing
Some hosting, cloud, email, domain, security, software or support providers may process information outside South Africa. VanguardTech will use a lawful transfer basis, which may include an adequate level of protection, contractual safeguards, consent where appropriate, or a transfer necessary to perform an agreement.
11. Complaints and regulator
Contact us first at info@vanguardtech.co.za so we can investigate. A data subject may also approach the Information Regulator of South Africa. Nothing in this notice limits rights available under POPIA.
Need clarity?
Send your question to info@vanguardtech.co.za. These website policies are general terms and do not replace a signed project agreement, quotation or SLA.
