Privacy Policy
Vestra One (Pty) Ltd
Effective date: [INSERT DATE] | Last updated: [INSERT DATE]
1. Introduction
Vestra One (Pty) Ltd (“Vestra One”, “we”, “us”, “our”) is committed to protecting personal information. This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal information in connection with our website [INSERT DOMAIN], our client portal, and the professional services we provide (together, the “Services”).
We process personal information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) of South Africa (“POPIA”), and — where applicable — the EU General Data Protection Regulation 2016/679 (“GDPR”) and the UK GDPR and Data Protection Act 2018 (together, “UK GDPR”).
This Policy applies to:
- Clients and their authorised representatives who engage us for professional services;
- Users of our client portal and website;
- Prospective clients and business contacts;
- Suppliers, partners, and their representatives; and
- Job applicants.
A separate section (Section 10) explains the limited circumstances in which we act as a processor / operator on behalf of our clients — for example, where a client provides us with personal information about their own customers, employees, or users so that we can deliver the Services. In those circumstances, our client is the responsible party / controller, and this Policy does not govern that processing.
2. Who we are (Responsible Party / Controller)
For the purposes of POPIA, Vestra One is the Responsible Party in respect of the personal information we collect for our own business purposes. For the purposes of GDPR and UK GDPR, we are the data controller of that personal information.
Contact details:
- Company: Vestra One (Pty) Ltd (held through Vestra Holdings (Pty) Ltd)
- Registration number: [INSERT REGISTRATION NUMBER]
- Registered address: [INSERT ADDRESS]
- Email: privacy@[INSERT DOMAIN]
- Information Officer (POPIA): [INSERT NAME], [INSERT EMAIL]
- EU/UK Representative (GDPR Art. 27 / UK GDPR): [INSERT NAME AND ADDRESS — required if we have no establishment in the EU/UK and offer services to, or monitor, data subjects there]
3. Personal information we collect
3.1 Information you provide directly
When you engage with us, visit our website, use the client portal, or otherwise interact with us, you may provide:
- Identifiers: full name, job title, employer, business email address, business phone number;
- Client account and engagement details: company information, billing details, VAT/tax number, contracting party details, signatories, engagement scope;
- Portal credentials: username, hashed password, multi-factor authentication details;
- Communications: emails, meeting notes, calls, support requests, feedback;
- Payment information: payment instrument details (processed by our payment provider — we do not store full card numbers);
- Marketing preferences and event RSVPs.
3.2 Information collected automatically
- Device and technical data: IP address, browser type and version, operating system, device identifiers, language and time-zone settings;
- Usage data: pages viewed, features used, links clicked, referring URL, timestamps, session duration;
- Cookies and similar technologies: as described in Section 8.
3.3 Information from third parties
- Authentication providers (e.g., Google, Microsoft) where you sign in to the portal via single sign-on;
- Payment processors confirming transaction status;
- Business information sources (e.g., company registries, professional networking sites) for due diligence, know-your-client (KYC), or business-development purposes;
- Referrals from existing clients or partners.
3.4 Sensitive / special personal information
- We do not ordinarily collect special personal information (as defined in POPIA) or special-category data (as defined in GDPR/UK GDPR). Where processing such information is strictly necessary for a specific engagement, we will do so only with an appropriate lawful basis — typically your explicit consent or another basis permitted under POPIA s.26–33 and GDPR Art. 9.
3.5 Children
Our Services are directed to businesses and professionals, not to children. We do not knowingly collect personal information from children under the age of 18. If you believe we have inadvertently done so, please contact us and we will take appropriate steps to delete it.
4. Why we process personal information and our lawful basis
We process personal information only where we have a lawful basis under POPIA, GDPR, and (where applicable) UK GDPR.
- Providing the Services and managing client engagements — contract performance (GDPR Art. 6(1)(b)); conclusion or performance of a contract to which the data subject is a party (POPIA s.11(1)(b)).
- Operating the client portal and verifying identity — contract performance and legitimate interests in securing access (GDPR Art. 6(1)(b) and (f); POPIA s.11(1)(b), (d), (f)).
- Billing, invoicing, and processing payments — contract performance and compliance with legal obligations (GDPR Art. 6(1)(b) and (c); POPIA s.11(1)(b) and (c)).
- Know-your-client, anti–money-laundering, sanctions, and conflicts checks — legal obligation and legitimate interests (GDPR Art. 6(1)(c) and (f); POPIA s.11(1)(c) and (f)).
- Communicating with you, responding to enquiries, and providing support — legitimate interests and, where applicable, contract performance (GDPR Art. 6(1)(b) and (f); POPIA s.11(1)(b) and (f)).
- Website analytics, security, fraud prevention, and improving the Services — legitimate interests (GDPR Art. 6(1)(f); POPIA s.11(1)(d) and (f)).
- Direct marketing to existing clients about related Services — legitimate interests and the “soft opt-in” under applicable e-privacy rules (GDPR Art. 6(1)(f); POPIA s.69 existing-customer exception). You may opt out at any time.
- Direct marketing to prospective clients — consent where required (GDPR Art. 6(1)(a); POPIA s.11(1)(a) and s.69) or legitimate interests where permitted under applicable law.
- Legal, tax, accounting, audit, and regulatory compliance — legal obligation (GDPR Art. 6(1)(c); POPIA s.11(1)(c)).
- Establishing, exercising, or defending legal claims — legitimate interests and, where applicable, legal obligation (GDPR Art. 6(1)(c) and (f); POPIA s.11(1)(c), (d), and (f)).
5. How we share personal information
We share personal information only as described below, and only to the extent necessary:
- Service providers (Operators / Processors) — cloud hosting, IT, client-portal infrastructure, email and document platforms, communications tools, customer-support, accounting, payment processing, identity/authentication, and error-monitoring providers, bound by written contracts requiring appropriate safeguards.
- Group companies and affiliates — Vestra Holdings (Pty) Ltd and any other group entities, where necessary for the purposes set out in this Policy and subject to equivalent protections.
- Professional advisers — lawyers, auditors, insurers, bankers, and accountants, where reasonably necessary.
- Sub-contractors and collaborators — where we engage third-party specialists or partners to deliver part of the Services, under appropriate confidentiality and data-protection terms.
- Law enforcement, regulators, and courts — where required by law, court order, or to protect our or a third party’s rights, property, or safety.
- Corporate transactions — in connection with a merger, acquisition, financing, reorganisation, or sale of assets. We will notify affected individuals where required.
We do not sell personal information for monetary consideration to third parties.
6. International transfers of personal information
Vestra One is based in South Africa and serves clients globally. We, our group companies, and our service providers may process personal information in countries other than your country of residence, including jurisdictions that may not offer the same level of protection.
When we transfer personal information across borders, we put in place appropriate safeguards, which may include:
- Transfers to a country recognised by the relevant authority as providing adequate protection;
- For GDPR/UK GDPR transfers out of the EEA/UK: the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or UK Addendum, or other approved transfer mechanisms, together with any supplementary measures required;
- For POPIA (s.72) transfers out of South Africa: contractual safeguards binding the recipient to principles substantially similar to POPIA, the data subject’s consent where appropriate, or another lawful ground under s.72.
You may request a copy of the relevant safeguards by contacting us at privacy@[INSERT DOMAIN].
7. How long we keep personal information
We retain personal information only for as long as is reasonably necessary for the purposes set out in this Policy, including to comply with legal, accounting, tax, or reporting obligations, to resolve disputes, and to enforce our agreements.
- Client engagement records, contracts, and correspondence — for the duration of the engagement plus a period required by law or by our professional obligations (typically [INSERT e.g., 5–7] years).
- Billing and financial records — typically [INSERT e.g., 5] years after the transaction, to comply with South African tax and accounting laws.
- Client portal accounts — for the duration of the engagement, plus up to [INSERT e.g., 24] months after closure.
- KYC / AML / conflicts records — as required by applicable law (typically at least 5 years after the end of the business relationship).
- Marketing suppression lists — indefinitely, so we can honour opt-outs and objections.
- Job applicant data — typically [INSERT e.g., 12] months after the decision, unless you consent to us keeping your information for future opportunities.
When personal information is no longer needed, we will delete, destroy, or de-identify it in a secure manner.
8. Cookies and similar technologies
We and our service providers use cookies, pixels, local storage, and similar technologies on our website and client portal to operate them, remember your preferences, measure performance, and (where you have consented, or we are otherwise permitted) deliver relevant marketing.
Categories of cookies we use:
- Strictly necessary — required for the site and portal to function (e.g., authentication, security).
- Functional — remember your preferences and settings.
- Analytics / performance — help us understand how visitors use the site.
- Advertising / targeting — set by us or our partners to measure advertising and show relevant content.
Where required by law (including in the EU, UK, and — to the extent applicable — South Africa), we set non-essential cookies only with your consent, obtained via our cookie banner. You can change your preferences at any time by clicking “Cookie settings” in the footer of our website, and you can control cookies through your browser settings.
9. How we protect personal information
We maintain appropriate technical and organisational measures designed to protect personal information against loss, unauthorised access, alteration, disclosure, or destruction, taking into account the nature of the data and the risks involved. These include:
- Encryption in transit (TLS) and encryption at rest for sensitive data stores;
- Role-based access controls, multi-factor authentication on the client portal, and least-privilege principles;
- Network segregation, logging, monitoring, and vulnerability management;
- Contractual obligations on our service providers and sub-contractors to maintain appropriate security;
- Confidentiality obligations on our directors, employees, and contractors;
- Documented incident-response procedures and regular review of our controls.
No method of transmission or storage is completely secure. If we become aware of a security compromise affecting personal information, we will notify the Information Regulator, applicable supervisory authorities, and affected individuals as required by law, and (where we act as a processor / operator) the relevant client in accordance with our contract.
10. When we act as a processor / operator for clients
In the course of delivering the Services, our clients may provide us with, or give us access to, personal information about their own customers, employees, contractors, users, or other individuals (“Client Personal Data”). In relation to Client Personal Data, our client is the responsible party / controller and Vestra One acts as the operator (POPIA) / processor (GDPR / UK GDPR).
When we act in this capacity:
- We process Client Personal Data only on the documented instructions of the relevant client and for the purposes set out in our engagement agreement or a separate data processing agreement (DPA);
- We implement appropriate technical and organisational security measures as required by POPIA s.20–21 and GDPR Art. 28 / UK GDPR Art. 28;
- We impose confidentiality obligations on personnel authorised to access Client Personal Data;
- We engage sub-processors only with the client’s prior general or specific authorisation and under written terms equivalent to those in our DPA;
- We assist the client, so far as possible, in responding to data-subject requests and in complying with their own obligations (including security, breach notification, and data-protection impact assessments);
- We return or delete Client Personal Data at the end of the engagement in accordance with the client’s instructions, subject to any legal retention requirements.
Data subjects whose personal information has been provided to us by a client should direct their privacy queries and rights requests to that client. If we receive such a request directly, we will (where we are able to identify the relevant client) forward it to the client and assist them in responding. This Privacy Policy does not govern the client’s processing of such personal information.
Our standard DPA is available on request or forms part of the master agreement with each client.
11. Your rights
Subject to applicable law, you have the following rights in relation to personal information we hold about you as a controller / responsible party.
11.1 Rights under POPIA
- Access — to confirm whether we hold personal information about you and to request a copy;
- Correction — to request correction of inaccurate, irrelevant, excessive, or outdated information;
- Deletion / destruction — to request deletion or destruction of personal information that is no longer authorised to be retained;
- Objection — to object, on reasonable grounds, to the processing of your personal information, including processing for direct marketing;
- Withdraw consent — where processing is based on consent, at any time (without affecting prior lawful processing);
- Complain — to lodge a complaint with the Information Regulator (South Africa).
11.2 Additional rights under GDPR and UK GDPR
- Restriction of processing — in specified circumstances;
- Data portability — to receive certain personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller;
- Not to be subject to solely automated decision-making that produces legal or similarly significant effects (we do not carry out such decision-making);
- Lodge a complaint with your local supervisory authority in the EU/EEA or with the UK Information Commissioner’s Office.
11.3 How to exercise your rights
Email privacy@[INSERT DOMAIN] with sufficient detail for us to identify you and the personal information concerned. We may need to verify your identity before acting on your request. We will respond within the timeframes required by applicable law (typically within one month under GDPR/UK GDPR and as reasonably practicable under POPIA).
As noted in Section 10, if your request relates to personal information we hold on behalf of a client (i.e., where we act as an operator / processor), we will redirect your request to that client.
11.4 Regulator contact details
Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 | inforeg@justice.gov.za | https://inforegulator.org.za
UK Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF | https://ico.org.uk
EU/EEA: the supervisory authority in your country of residence, work, or the place of the alleged infringement. A list is available at https://edpb.europa.eu.
12. Automated decision-making
We do not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the “Last updated” date above. If the changes are material, we will provide additional notice (for example, by email or an in-portal notification). We encourage you to review this Policy periodically.
14. How to contact us
If you have questions, concerns, or requests about this Policy or our processing of personal information:
- Email: privacy@[INSERT DOMAIN]
- Postal: Vestra One (Pty) Ltd, [INSERT ADDRESS]
- Information Officer (POPIA): [INSERT NAME], [INSERT EMAIL]
- EU/UK Representative: [INSERT NAME AND ADDRESS]