Legal

Privacy Policy

How Strategic IT Advisory SA collects, uses, protects, and manages personal information.

Last updated:

Information We Collect

We collect personal information that you provide directly to us when you:

  • Fill out a contact form on our website
  • Submit a membership application
  • Subscribe to our newsletter or updates
  • Book a consultation or request our services
  • Correspond with us via email, phone, or LinkedIn

The types of personal information we may collect include your name, company name, email address, telephone number, and any other details you choose to provide. We also collect standard technical data such as IP address, browser type, and pages visited through cookies and analytics tools, but only with your consent.

Private Advisory Platform Data

We use a private advisory platform to manage client work. Depending on the engagement, the platform may contain:

  • Client company, registration, tax, address, billing, business profile, status, notes, and engagement information
  • Contact names, roles, departments, email addresses, telephone numbers, LinkedIn profiles, and communication preferences
  • Discovery notes and transcripts, proposals, assessments, answers, scores, findings, recommendations, reports, tasks, reminders, and correspondence records
  • Evidence files and notes supplied for an engagement, including documents, screenshots, images, PDFs, or technical material
  • Account, login, session, security-event, activity, email-delivery, and change-history records used to operate and protect the platform

Platform records are not public. Ordinary application access is restricted to the authenticated owner account. Contracted hosting, database, storage, and email providers may process limited data as operators where necessary to provide their services, subject to contractual, confidentiality, and security controls.

Microsoft 365 and Google Workspace Data

Where a client expressly authorises a cloud-environment review, the platform may connect to Microsoft 365 or Google Workspace using read-only permissions. We collect and retain normalised or aggregate information relevant to technology and security posture, such as:

  • Tenant identifiers, organisation profile, domains, licence and service information
  • Counts of users, guests, suspended or disabled users, groups, administrators, and privileged roles
  • Aggregated MFA, passwordless, self-service password reset, two-step verification, and Conditional Access posture
  • Availability and summary signals for audit, security, and usage reporting
  • Connection, consent, synchronisation, detected-risk, and review records

The connectors are designed not to retain email or file contents, passwords, or raw directory payloads. They do not permit us to create, edit, or delete users, messages, files, policies, or tenant settings. A client administrator can revoke the relevant authorisation through Microsoft or Google.

How We Use Information

We use the personal information we collect for the following purposes:

  • To respond to your inquiries and provide advisory services
  • To process membership applications and onboarding
  • To communicate updates, newsletters, and service information
  • To improve our website, services, and client experience
  • To document advisory work, generate reports, and maintain an audit trail
  • To assess authorised technology and security posture and track remediation
  • To comply with legal obligations and protect our legitimate interests

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.

Lawful Basis for Processing

Under the Protection of Personal Information Act (POPIA), we process personal information on one or more of the following lawful bases:

  • Consent: where you have explicitly agreed to our processing (e.g., cookie consent, newsletter signup)
  • Contractual necessity: to perform our advisory or membership services
  • Legal obligation: to comply with applicable laws and regulations
  • Legitimate interest: to operate and improve our business, provided your rights and interests are not overridden

Sharing of Information

Strategic IT Advisory SA does not sell, rent, or trade your personal information. We may share information only in the following limited circumstances:

  • With trusted operators who assist with hosting, database and file storage, email delivery, analytics, and platform operations, bound by appropriate obligations
  • When required by law, regulation, or legal process
  • To protect our rights, property, or safety, or that of our clients or the public
  • In connection with a merger, acquisition, or sale of assets, subject to confidentiality

Data Security

We take the security of your personal information seriously. We implement appropriate technical and organisational measures to protect your data, including:

  • Secure data transmission using TLS/SSL encryption
  • Access controls limiting who can view personal information
  • Regular security assessments and monitoring
  • Confidentiality agreements with staff and third-party processors
  • Authenticated access controls and row-level restrictions for platform records
  • Private file storage with time-limited access links for evidence downloads
  • Encrypted storage of cloud-integration credentials and connection secrets

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We encourage you to exercise caution when sharing sensitive information.

Cookies and Analytics

Our website uses cookies and similar technologies to enhance your browsing experience and analyse site traffic. We use:

  • Google Analytics 4: to understand how visitors interact with our website and improve usability
  • Microsoft Clarity: for session recordings, heatmaps, and user behaviour insights

We only load these analytics tools after you have provided explicit consent via our cookie consent banner. You may withdraw or modify your consent at any time by clicking "Cookie preferences" in the footer.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including:

  • Providing advisory and membership services
  • Complying with legal, tax, and regulatory obligations
  • Resolving disputes and enforcing our agreements

When personal information is no longer required, we securely delete or anonymise it in accordance with our data retention schedule and POPIA requirements.

Client engagement records may be retained after an engagement where reasonably required for professional accountability, legal claims, tax, audit, security, or contractual purposes. Cloud-integration data and evidence are removed or de-identified when no longer required, subject to applicable legal holds and agreed client instructions.

Your Rights Under POPIA

As a data subject under the Protection of Personal Information Act (POPIA), you have the following rights:

  • Right to access: request a copy of the personal information we hold about you
  • Right to correction: request that we correct inaccurate or incomplete information
  • Right to deletion: request deletion of your personal information where lawful
  • Right to object: object to the processing of your personal information in certain circumstances
  • Right to withdraw consent: withdraw consent where processing is based on consent
  • Right to lodge a complaint: file a complaint with the Information Regulator of South Africa

To exercise any of these rights, please contact us using the details in the Contact Information section below. We will respond within the timeframes required by POPIA.

Third-Party Websites

Our website may contain links to third-party websites, such as LinkedIn or professional resources. This Privacy Policy applies solely to information collected by Strategic IT Advisory SA. We are not responsible for the privacy practices or content of external websites. We encourage you to review the privacy policies of any third-party sites you visit.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will update the "Last Updated" date at the top of this page.

We encourage you to review this Privacy Policy periodically. Your continued use of our website and services after any changes constitutes your acceptance of the updated policy.

Contact Information

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have concerns about how we handle your personal information, please contact us:

We aim to respond to all privacy-related inquiries within five business days.

Questions about your privacy?

We are committed to transparency. If you have any questions about how we handle your data, please reach out.