1. Who is responsible for your information
Auths Digital (Pty) Ltd (registration number 2026/389632/07) is the responsible party for the personal information described in this policy.
Address:
3 Old Kommetjie Road Sunnydale, Cape Town Western Cape, 7975 South AfricaInformation Officer: Johanna Christina Auths, christel@authsdigital.com. Our Information Officer handles all requests and questions about personal information.
This is the notice we are required to give you under section 18 of POPIA. It applies to visitors to this website, people who contact us, prospective and current clients and their staff, people who buy our digital products or use our online services, and our suppliers.
2. What we collect and where it comes from
| Information | Source |
|---|---|
| Contact details such as your name, email address, organisation, role and anything you write to us. | You, when you email us or send an enquiry. |
| Contract and billing details such as legal names, addresses, VAT numbers, invoices and payment records. | You or your organisation, when we agree to work together or you buy from us. |
| Project information such as system access, credentials, code, documents and data that you give us so that we can do the work. This can include personal information about your customers or staff. | You or your organisation. For this information we act as an operator on your instructions. |
| Purchase information for digital products, such as your email address, the product bought and the transaction reference. Card details are handled by our payment provider and never stored by us. | You, and the payment provider you pay through. |
| Technical information such as IP address, browser type, pages visited and timing, recorded in our hosting provider’s server logs. | Your browser, automatically, when you visit this website. |
We do not collect special personal information (such as health, religious or biometric information) or information about children unless a project needs it and you have the lawful basis to give it to us.
3. Why we use it and on what basis
| Purpose | Lawful basis (POPIA section 11) |
|---|---|
| Replying to your enquiry and preparing a proposal. | Steps you ask us to take before a contract, and our legitimate interest in running the business. |
| Doing the work you have engaged us for and delivering products you have bought. | Performance of a contract with you or your organisation. |
| Invoicing, keeping accounting records and paying tax. | Legal obligations under the Companies Act and tax legislation. |
| Keeping this website and our systems secure and detecting abuse. | Our legitimate interest in protecting our systems and clients. |
| Sending you news about our products or services by email. | Your consent, which you can withdraw at any time (section 69). |
Giving us your information is voluntary. If you choose not to, we may not be able to reply to you, send a proposal, do the work or sell you a product.
We do not send direct marketing by email or SMS unless you have opted in, and every marketing message includes a way to unsubscribe. We do not sell personal information and we do not make automated decisions that have a legal effect on you.
4. Who we share it with
We share personal information only with the providers and people we need to run the business:
- Hosting and infrastructure for this website and for project work (for example Vercel, Cloudflare and cloud platforms chosen for a project).
- Email and productivity tools (for example Google Workspace) used to communicate and store documents.
- Payment providers (for example Paystack or Stripe) that process payments for digital products and invoices.
- Accounting and professional advisers such as our accountants and, where needed, our lawyers.
- Authorities, where the law requires us to disclose information or to protect our rights.
Providers that process personal information on our behalf are operators under POPIA. We only use operators that commit, in writing, to keep the information confidential and secure.
5. Transfers outside South Africa
Some of our providers store information in other countries, including the United States and the European Union. Where we transfer personal information across borders we rely on section 72 of POPIA: the recipient is bound by a contract, or by binding corporate rules or laws, that provide a level of protection substantially similar to POPIA. If you would like details of the safeguards for a particular provider, ask our Information Officer.
6. How long we keep it
- Enquiries that do not lead to work: up to 24 months, so that we can pick the conversation up again.
- Contracts, invoices and payment records: at least five years after the engagement ends, as tax legislation requires, and up to seven years where the Companies Act requires it.
- Project information: for the duration of the engagement plus the support period, after which it is deleted or returned unless we agree otherwise.
- Server logs: for a short period set by our hosting provider, then automatically deleted.
Information is deleted or de-identified when it is no longer needed for the purpose it was collected for.
7. How we protect it
We use encryption in transit, multi-factor authentication on our accounts, least-privilege access to client systems, and secure password managers for any credentials you share. If we become aware of a security compromise involving personal information, we will notify the Information Regulator and the people affected as section 22 of POPIA requires.
8. Cookies and tracking
This website does not set advertising or tracking cookies and does not use third-party analytics. If we add analytics in future we will use a privacy-preserving service and update this policy. Our hosting provider may set strictly necessary cookies needed to serve the site securely.
9. Your rights
Under POPIA you have the right to:
- ask whether we hold personal information about you, and to receive a copy (section 23);
- ask us to correct or delete information that is inaccurate, out of date or no longer needed (section 24);
- object to processing that is based on our legitimate interests, or to direct marketing (section 11(3));
- withdraw consent you have given, without affecting processing that happened before you withdrew it;
- lodge a complaint with the Information Regulator if you believe we have not handled your information lawfully.
To exercise any of these rights, email christel@authsdigital.com. We respond within a reasonable time and in any event within 30 days. Requests for access are made under the Promotion of Access to Information Act, and we may ask you to confirm your identity first.
Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Telephone 010 023 5200, toll-free 0800 017 160 Complaints: POPIAComplaints@inforegulator.org.za Enquiries: enquiries@inforegulator.org.za https://inforegulator.org.za10. Children
This website and our products are intended for businesses and adults. We do not knowingly collect personal information from anyone under 18 without the consent of a competent person.
11. Links to other websites
This website may link to other sites. Their privacy practices are their own, and we encourage you to read their policies.
12. Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. If a change materially affects how we use your information, we will tell you by email where we can.
13. Contact
Questions about this policy or about your personal information can be sent to our Information Officer at christel@authsdigital.com. Our Terms of service contain our full company details.