Legal

POPIA Notice

A focused notice explaining how we process personal information under the Protection of Personal Information Act 4 of 2013.

Last updated:

Responsible party and Information Officer

Strategic IT Advisory SA is the responsible party for personal information processed through this website and its advisory services.

Our role when processing platform data

Strategic IT Advisory SA generally acts as the responsible party for its own CRM, business administration, communications, account security, and service-management data.

Where we process a client's workforce, cloud-tenant, evidence, or assessment data on that client's documented instructions, the client may be the responsible party and we act as its operator. The engagement terms determine the parties' responsibilities, permitted processing, confidentiality, security, assistance, and deletion or return of information.

Personal information we process

Depending on your relationship with us, we may process:

  • Names, contact details, employer, job title, department, and relationship roles
  • Company identity, registration, tax, address, billing, and business-profile data
  • Enquiries, correspondence, discovery records, meeting notes, and transcripts
  • Engagements, proposals, assessments, answers, scores, findings, recommendations, reports, tasks, and reminders
  • Evidence files, document metadata, and technical information supplied for advisory work
  • Account identifiers, login and session records, security events, activity logs, and email-delivery records
  • Website usage and consent information

Please do not send special personal information or confidential credentials through a general website form unless we specifically request it through an appropriate secure channel.

Authorised cloud integrations

With the client's express authorisation, read-only Microsoft 365 or Google Workspace connectors may process tenant identifiers, domains, licence and service information, and aggregate identity and security-posture metrics. These may include user, guest, group, administrator, MFA, two-step verification, passwordless, self-service password reset, Conditional Access, and audit-report availability counts or signals.

The platform is designed not to retain passwords, email or file contents, or raw cloud directory payloads. It records normalised snapshots, consent and connection status, sync history, detected signals, and advisory review outcomes. The authorising administrator can revoke access through the relevant cloud provider.

Purpose and lawful justification

We process information to respond to enquiries, assess membership applications, deliver and administer services, manage client relationships, maintain records, improve our website, secure our operations, and meet legal obligations.

Processing is based on consent, contractual necessity, legal obligations, or our legitimate interests where those interests do not unjustifiably affect your rights.

Recipients and operators

We may use carefully selected operators for website hosting, email delivery, analytics, professional services, and business administration. They may process information only for authorised purposes and subject to appropriate confidentiality and security obligations.

Current categories of technology operators include cloud hosting, managed database and private storage, transactional email, website analytics, and the Microsoft or Google services a client chooses to connect. Platform application access is limited to the authenticated owner account. Infrastructure providers may nevertheless process data where technically necessary to deliver, secure, support, or maintain their services.

We do not sell personal information. We may disclose it where required by law, to protect legitimate rights, or as part of a properly managed business transaction.

Cross-border processing

Some technology providers may store or process information outside South Africa. Where this occurs, we take reasonable steps to ensure that the recipient is subject to a law, binding agreement, or corporate rules that provide an adequate level of protection as required by POPIA.

Security and retention

We use reasonable technical and organisational safeguards appropriate to the nature of the information and the risks involved. No online system can be guaranteed completely secure.

Safeguards include authenticated owner-only application access, row-level database access controls, private evidence storage, time-limited download links, encrypted integration secrets, activity logging, and read-only cloud connectors.

We retain information only while it is needed for the purpose collected, a legitimate business requirement, dispute management, or a legal retention period. We then delete, destroy, or de-identify it where reasonably practicable.

Your rights

Subject to applicable law, you may ask whether we hold your information, request access or correction, ask for deletion where permitted, object to certain processing, or withdraw consent. You may also complain to the Information Regulator.

Send a request to hello@strategicitadvisory.co.za. We may need to verify your identity before acting.