This Privacy Policy explains how Bitlogiq handles personal information in line with the Protection of Personal Information Act 4 of 2013 (POPIA). We do not sell your personal information. Complete the bracketed company, payment-provider and hosting-location fields before publishing.
1. Who we are
[Company Name] (Pty) Ltd, trading as Bitlogiq (registration number [Registration Number]), of [Physical Address], is the responsible party for the personal information described in this policy.
| Contact | Details |
|---|---|
| Information Officer | [Information Officer] |
| info@bitlogiq.co.za (subject line: “Privacy request”) | |
| Telephone and WhatsApp | +27 66 366 8490 |
| Postal and physical address | [Physical Address] |
Data on our platforms. When you store or process personal information about your own customers or staff on our SaaS or hosting platforms, you are the responsible party and we act as your operator. That processing is governed by clause 10 of our Terms and Conditions, not by this policy.
2. Personal information we collect
| Category | Examples | How we get it |
|---|---|---|
| Identity and contact | Name, surname, company name, job title, email, phone number, physical and billing address | From you, when you enquire, sign up or contact us |
| Account | Username, encrypted password, plan, account settings, authorised users | From you, when you create and use an account |
| Billing and transaction | Invoices, payment history, VAT number, the last four digits and expiry date of your card | From you and from [Payment Provider]. We never receive or store your full card number. |
| Domain registrant | Registrant name, organisation, address, email and phone number | From you, as registries require it to register a domain |
| Technical | IP address, browser and device type, operating system, server and access logs, security events | Automatically, when you use our website and Services |
| Usage | Pages visited, features used, time spent, referring site | Automatically, through cookies and similar tools |
| Communications | Emails, WhatsApp messages, support tickets, call notes, project correspondence | From you, when you communicate with us |
| Marketing preferences | Your consent, opt-outs and communication preferences | From you |
We do not intentionally collect special personal information (such as health, religious or biometric information) or the personal information of children. If you are a juristic person (such as a company), POPIA also protects your information, and this policy applies to it.
3. Why we use your personal information
We process personal information only for specific, lawful purposes and only to the extent necessary (POPIA sections 9 to 13).
| Purpose | Lawful basis under POPIA section 11 |
|---|---|
| Set up and manage your account, and provide the Services you order | Performance of our contract with you |
| Register and renew domains with registries | Performance of our contract with you |
| Bill you, process payments and collect overdue amounts | Performance of our contract with you |
| Provide support and respond to enquiries | Contract, or our legitimate interest in answering you |
| Keep our systems and your data secure, and detect and prevent fraud and abuse | Legitimate interest, and legal obligations |
| Keep accounting and tax records | Legal obligation (Tax Administration Act 28 of 2011, Companies Act 71 of 2008) |
| Improve our website and Services using analytics | Legitimate interest, or your consent for non-essential cookies |
| Send you service, billing and security notices | Performance of our contract with you |
| Send you marketing about our products | Your consent, or as permitted for existing customers (see section 5) |
| Comply with court orders, law enforcement requests and the law | Legal obligation |
You do not have to give us your personal information. However, information marked as required on our forms is mandatory: without it, we cannot open an account, register a domain or provide the Service you ask for.
4. Who we share it with
We do not sell your personal information. We share it only when needed, with:
- Our operators (service providers), such as cloud infrastructure and data centre providers, [Payment Provider], email and messaging services, accounting software, customer support tools and analytics providers. They may only process your information on our instructions and must keep it secure (POPIA sections 20 and 21).
- Domain registries and registrars, such as the ZA Central Registry and ICANN-accredited registrars. Some registrant details may appear in public WHOIS records, subject to each registry’s privacy rules.
- Professional advisers, such as our auditors, accountants and attorneys, who are bound by confidentiality.
- Authorities, such as SARS, the Information Regulator, courts and law enforcement, where the law requires it.
- A buyer or successor, if our business or part of it is sold or restructured, under confidentiality and only for the same purposes.
5. Direct marketing
We follow section 69 of POPIA:
- If you are not our customer, we will send you electronic marketing only if you have given your consent.
- If you are our customer, we may send you marketing about our own similar products and services.
- Every marketing message lets you opt out free of charge, and we respect your choice promptly.
Service, billing and security messages are not marketing, and we will keep sending them while you have an account.
6. Sending information outside South Africa
Some of our operators, and some of our infrastructure in [Hosting Locations], may be outside South Africa. We transfer personal information across borders only as allowed by section 72 of POPIA. This means the recipient must be bound by a law, binding corporate rules or a written agreement that gives protection substantially similar to POPIA, or the transfer must be necessary for our contract with you, or you must have consented.
7. How we protect it
We take appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, and unauthorised access or use (POPIA section 19). These include encryption in transit, access controls based on job need, multi-factor authentication for staff, monitoring and logging, regular updates and patching, and confidentiality obligations for staff and operators.
If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible, as required by section 22 of POPIA.
8. How long we keep it
We keep personal information only as long as we need it for the purposes above, or as the law requires (POPIA section 14). After that, we delete, destroy or de-identify it.
| Information | How long we keep it |
|---|---|
| Account and contact information | While your account is active, plus up to 3 years to deal with queries and claims |
| Invoices, payments and accounting records | 7 years after the financial year concerned, as tax and company law require |
| Support tickets and communications | 3 years after the ticket is closed |
| Server, access and security logs | Up to 12 months, unless needed to investigate an incident |
| Website analytics | Up to 26 months |
| Marketing consent and opt-outs | Until you opt out, then a suppression record so we do not contact you again |
| Enquiries that do not lead to a sale | 12 months |
9. Cookies
Our website uses cookies and similar technologies.
- Essential cookies make the website and your account work, such as keeping you signed in and securing forms. They cannot be switched off.
- Analytics cookies help us understand how visitors use the website so we can improve it.
- Marketing cookies help us measure our advertising.
We use analytics and marketing cookies only with your consent, which you give or refuse through our cookie banner. You can change your choice at any time through the cookie settings link in the website footer, or by clearing cookies in your browser.
10. Your rights
Under POPIA you have the right to:
- ask whether we hold personal information about you and request a copy of it (section 23);
- ask us to correct, update or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24);
- object to processing based on our legitimate interests, and object to direct marketing at any time (section 11(3));
- withdraw your consent where we rely on consent, without affecting processing done before the withdrawal;
- not be subject to a decision with legal or similarly significant effects that is based solely on automated processing (section 71); and
- lodge a complaint with the Information Regulator.
To exercise a right, email info@bitlogiq.co.za with the subject “Privacy request”. We will verify your identity before acting and respond within 30 days. Access requests may also be made under the Promotion of Access to Information Act 2 of 2000 (PAIA), which may involve a prescribed fee. Our PAIA manual is available on request.
11. Complaints
Please contact our Information Officer first so we can try to put things right. If you are not satisfied, you may complain to the Information Regulator:
| Information Regulator (South Africa) | Details |
|---|---|
| Website | inforegulator.org.za |
| General enquiries | enquiries@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| Telephone | 0800 017 160 (toll-free) or 010 023 5200 |
12. Children
Our website and Services are not directed at children under 18, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
13. Links to other websites
Our website may link to other websites, such as payment pages and partner sites. We are not responsible for their privacy practices, so please read their privacy policies.
14. Changes to this policy
We may update this policy from time to time. We will publish the updated version on this page with a new effective date, and notify customers by email of material changes.