Privacy Policy
Stratafort Cyber, a division of Stratafort (Pty) Ltd (Registration No. 2024/416420/07) ("Stratafort Cyber", "we", "us"), respects the privacy of every person who interacts with us. This policy explains how we collect, use, store, share and protect personal information, in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA") and, where applicable, other data protection laws.
Given the nature of our work, we hold ourselves to the same standard we recommend to clients: collect the minimum, protect it rigorously, and be transparent about both.
1. Who is responsible for your information
The responsible party is Stratafort (Pty) Ltd, of which Stratafort Cyber is a division. Our appointed Information Officer handles all POPIA-related queries at privacy@stratafort.co.za. Enquiries about this website may also be sent to contact@stratafortcyber.com.
2. What we collect
- Enquiry information — name, firm, email address, phone number, sector and the content of your message, when you submit our contact form or reach us by email or WhatsApp.
- Engagement information — information reasonably required to scope, contract and deliver professional services, collected under the applicable engagement terms.
- Technical information — this website does not set analytics or advertising cookies. Our hosting infrastructure may process standard server logs (such as IP address and requested pages) for security and operational purposes.
3. Why we process it
- To respond to your enquiry and communicate with you — on the lawful basis of your consent and/or steps taken at your request prior to entering a contract.
- To scope, conclude and perform an engagement — on the lawful basis of performance of a contract.
- To protect the security and integrity of our own systems and services — on the lawful basis of our legitimate interests.
- To comply with legal and regulatory obligations, where applicable.
We do not sell personal information. We do not use it for third-party advertising.
4. Special personal information
We do not seek special personal information (as defined in POPIA) through this website. If your enquiry volunteers such information, we treat it with heightened care and process it only to the extent necessary to respond appropriately.
5. Sharing
Personal information is shared only with: (a) service providers who process it on our instruction under appropriate confidentiality and security obligations (for example, form-processing and email infrastructure); (b) our professional advisers where reasonably necessary; and (c) authorities where the law requires it. We do not share client or enquirer information for marketing purposes.
6. Cross-border processing
Some infrastructure providers may process information outside South Africa. Where this occurs, we take reasonable steps to ensure the information receives a level of protection consistent with POPIA's conditions for cross-border transfer.
7. Security safeguards
We apply appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access and unlawful processing — including encrypted transmission, access controls, and the security disciplines we practise professionally. No system is invulnerable; our obligation, which we take seriously, is rigorous and continuously maintained safeguards.
8. Retention
We keep personal information only as long as necessary for the purposes above, or as required by law or a legitimate business record-keeping purpose, after which it is deleted or de-identified.
9. Your rights
- To be informed about how your information is processed (this policy).
- To request access to the personal information we hold about you.
- To request correction or deletion of inaccurate, irrelevant, excessive or unlawfully obtained information.
- To object, on reasonable grounds, to processing, and to withdraw consent where processing is based on consent.
- To complain to the Information Regulator (South Africa): POPIAComplaints@inforegulator.org.za · 010 023 5207 · JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · inforegulator.org.za.
To exercise any of these rights, contact our Information Officer at privacy@stratafort.co.za. We respond within a reasonable time and in accordance with POPIA and, where applicable, the Promotion of Access to Information Act ("PAIA").
10. PAIA
Requests for access to records under the Promotion of Access to Information Act may be directed to the Information Officer at privacy@stratafort.co.za.
11. Breach notification
In the event of a security compromise affecting personal information, we will notify the Information Regulator and affected data subjects as required by section 22 of POPIA, as soon as reasonably possible after discovery.
12. Changes to this policy
We may revise this policy from time to time. The current version will always be published on this page with its effective date.
13. Contact
Stratafort Cyber — A Division of Stratafort (Pty) Ltd
Victoria Junction, 57 Prestwich St, De Waterkant, Cape Town, 8001, South Africa
contact@stratafortcyber.com · Information Officer: privacy@stratafort.co.za