This notice is intended to explain our general personal information practices. It should be read together with our Privacy & Terms page and, where applicable, any engagement-specific notices or agreements.
1. Purpose of this notice
The Protection of Personal Information Act 4 of 2013 (POPIA) regulates the processing of personal information by public and private bodies in South Africa. BeCompliant aims to process personal information in a lawful and responsible manner and to apply appropriate safeguards to information entrusted to us.
2. Who is responsible for your information?
For personal information processed through this website and in connection with BeCompliant's services, BeCompliant acts as the responsible party where it determines the purpose and means of processing.
3. Categories of personal information we may process
Depending on your relationship with us and the services requested, we may process:
- Identity and contact information.
- Organisation, employment, professional and business information.
- Compliance, regulatory, ownership, directorship and risk-related information supplied through our questionnaires or services.
- Correspondence, instructions, enquiries and records of interactions with us.
- Technical and security information generated when you use our website or digital services.
- Other information that is reasonably necessary for a specific compliance engagement or that you choose to provide.
4. Why we process personal information
We may process personal information for purposes including:
- Responding to enquiries and consultation requests.
- Understanding an organisation's compliance position and requirements.
- Providing compliance, documentation, screening, verification, monitoring or related services.
- Managing client relationships, administration and business records.
- Operating, securing and improving our website and systems.
- Meeting contractual, legal, regulatory and professional obligations.
- Protecting our rights, systems, clients and other persons.
- Sending service communications and, where legally permitted, relevant marketing communications.
5. Grounds for processing
Depending on the circumstances, processing may be based on your consent, steps taken at your request before entering into an agreement, performance of an agreement, compliance with a legal obligation, protection of a legitimate interest, or another lawful basis recognised under POPIA.
6. Where information comes from
We generally collect information directly from you or from your organisation. Where appropriate and lawful, information may also be obtained from public records, regulators, professional bodies, verification providers, screening providers, authorised third parties or other sources relevant to the service being provided.
7. Who may receive personal information?
Personal information may be shared where necessary with employees, authorised contractors, professional advisers, technology providers, hosting providers, verification or screening providers, regulators, public authorities or other parties where disclosure is required or permitted by law. Service providers acting on our behalf are expected to process information only for authorised purposes and with appropriate safeguards.
8. Cross-border processing
Some service providers or technology systems may process or store information outside South Africa. Where personal information is transferred across borders, we aim to ensure that the transfer is permitted under POPIA and that appropriate protections are in place.
9. Information security
We take reasonable technical and organisational steps designed to preserve the integrity and confidentiality of personal information and to protect it against loss, damage, unauthorised destruction, unlawful access or unlawful processing.
10. Security compromises
If a security compromise involving personal information occurs, BeCompliant will assess the incident and take appropriate steps in accordance with applicable law, which may include notification to the Information Regulator and affected data subjects where required.
11. Retention and deletion
Personal information is retained only for as long as it is reasonably required for the purpose for which it was collected, for legitimate business or record-keeping purposes, or as required by law. When information is no longer required, we aim to delete, destroy or de-identify it in an appropriate manner.
12. Your rights as a data subject
Subject to POPIA and other applicable law, you may have the right to:
- Ask whether we hold personal information about you.
- Request access to personal information held about you.
- Request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete or unlawfully obtained information where the legal requirements are met.
- Object to certain processing in appropriate circumstances.
- Withdraw consent where processing is based on consent, without affecting earlier lawful processing.
- Object to or opt out of direct marketing as permitted by law.
- Lodge a complaint with the Information Regulator.
13. Direct marketing
Where we send electronic direct marketing, we aim to do so only where permitted by law. You may unsubscribe or object to marketing communications using the method provided in the communication or by contacting us.
14. Special personal information and children's information
Our website is not intended to collect special personal information or personal information about children unless this is necessary for a legitimate service and the processing is lawful. Where such information is required, additional legal requirements and safeguards may apply.
15. Automated decision-making
BeCompliant does not intend to make decisions that produce legal or similarly significant effects based solely on automated processing through this public website. Where technology is used to support compliance services, professional or human review may form part of the relevant process.
16. Access to records and PAIA
Requests for access to records may also be governed by the Promotion of Access to Information Act 2 of 2000 (PAIA). The Information Regulator provides guidance and prescribed forms for access requests.
17. Complaints and the Information Regulator
If you have a privacy concern, we encourage you to contact BeCompliant first so that we can try to resolve it. You may also lodge a complaint with the Information Regulator of South Africa.
Information Regulator, South Africa
Website: inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
18. Changes to this notice
We may update this notice from time to time to reflect changes in our services, systems, legal obligations or privacy practices. The latest revision date will appear at the top of this page.
19. Contact BeCompliant
Official references: Protection of Personal Information Act 4 of 2013 and the Information Regulator of South Africa.