Simplict
[ LEGAL ]

POPIA Compliance Policy

Effective date: 1 January 2025

This policy describes how Simplict (Pty) Ltd ("Simplict") complies with the Protection of Personal Information Act, 4 of 2013 (POPIA), South Africa's primary data-protection legislation.

RESPONSIBLE PARTYSimplict (Pty) Ltd is the Responsible Party as defined by POPIA. All data-protection queries and requests should be directed to [email protected].

1. Our commitment

Simplict is committed to lawful, fair and transparent processing of personal information. We collect only what is necessary, for a specific purpose, and we keep it no longer than needed. These principles mirror the eight Conditions for Lawful Processing set out in POPIA.

2. Information Officer

Simplict has designated an Information Officer responsible for ensuring the company's compliance with POPIA. The Information Officer can be reached at [email protected]. The Information Officer's details are registered with the Information Regulator as required by section 55 of POPIA.

3. Lawful bases for processing

We rely on one or more of the following lawful grounds to process personal information:

  • Consent — you have given us specific, informed, and voluntary consent (e.g. requesting a readiness report or signing up for updates).
  • Contractual necessity — processing is necessary to fulfil an agreement with you or your organisation (e.g. delivering a managed-services engagement).
  • Legal obligation — we are required to process information to comply with South African law (e.g. financial record-keeping).
  • Legitimate interest — processing is necessary for a legitimate interest of Simplict or a third party, where that interest is not overridden by your rights (e.g. website security logging).

4. Categories of personal information processed

  • Contact information (name, email, phone number, company name).
  • Website usage logs (IP address, browser, pages visited).
  • Business assessment data from our Copilot Readiness questionnaire.
  • Service-delivery information collected during a client engagement (e.g. system configuration details).

We do not knowingly process special personal information (as defined in section 26 of POPIA), such as health data, political views, or biometrics, unless specifically required for a service and authorised by the data subject.

5. Purpose limitation

Personal information is collected for a specific, explicitly defined purpose and is not further processed in a manner incompatible with that purpose. Purposes are stated at the point of collection (e.g. in the contact form and readiness assessment).

6. Cross-border transfers

Where personal information is transferred outside South Africa (for example, to our email-delivery provider Resend, based in the United States), we ensure such transfers comply with section 72 of POPIA. This includes confirming that the recipient country or third party provides an adequate level of protection or that appropriate contractual safeguards are in place.

7. Your rights as a data subject

Under POPIA you have the following rights, which you may exercise free of charge:

  • Right of access (section 23): to know what personal information we hold about you.
  • Right to correction (section 24): to have inaccurate, incomplete or outdated information corrected.
  • Right to object (section 11(3)): to object to processing based on legitimate interest or for direct marketing.
  • Right to erasure: to request deletion once the purpose has been fulfilled and no retention obligation applies.
  • Right to withdraw consent: to withdraw any consent previously given (this does not affect prior lawful processing).

To exercise your rights, submit a written request to [email protected]. We will acknowledge receipt within 3 business days and respond substantively within 30 days.

8. Security safeguards

We implement appropriate technical and organisational measures to protect personal information against accidental loss, unauthorised access, disclosure, alteration, or destruction. These include HTTPS encryption, access controls, and staff awareness of data-protection obligations.

In the event of a security compromise involving personal information, we will notify affected data subjects and the Information Regulator as required by section 22 of POPIA.

9. Complaints to the Information Regulator

If you believe we have handled your personal information unlawfully, you may lodge a complaint directly with the Information Regulator (South Africa):

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, 2017
Complaints email: [email protected]
General enquiries: [email protected]

You may also refer a matter to the Information Regulator if you are unsatisfied with our response to your request.

10. Updates to this policy

This policy is reviewed at least annually and updated whenever there are material changes to our processing activities or applicable law. The effective date above indicates when this version came into force.

11. Contact us

Simplict (Pty) Ltd — Information Officer
1 Bridgeway Road, Century City, 7441
Western Cape, South Africa
[email protected]
+27 21 201 6824