1. Data Controller
The responsible party (data controller) for the processing of your personal information is:
Vizibiliti IS (Pty) Ltd
Trading as ZA Support
1 Hyde Park Lane, Hyde Park, Johannesburg 2196
VAT: 436-026-0014
Email: courtney@zasupport.com
Phone: 064 529 5863
2. Personal Information We Collect
We may collect the following categories of personal information, depending on the services you use:
- Identity information: full name, email address, telephone number
- Device information: Apple device model, serial number, hardware diagnostics, macOS version, battery health, storage capacity
- Technical data: IP address, browser type, referring URL, pages visited
- Usage data: anonymised analytics collected via Google Analytics 4 (GA4), including page views, session duration, and user flow
- Financial information: payment card details (processed securely by our payment provider; we do not store card numbers)
- Communication records: emails, contact form submissions, and support correspondence
3. Purpose of Collection
We collect and process personal information for the following purposes:
- Service delivery: diagnosing, repairing, and returning your Apple devices
- Device repair tracking: maintaining a record of repairs, diagnostics, and device history for warranty and quality purposes
- SLA management: administering managed IT service agreements, scheduling maintenance, and monitoring device health
- Invoicing and payments: generating quotes, invoices, and processing payments
- Communication: responding to enquiries, providing repair updates, and sending service-related notifications
- Marketing: sending promotional content only where you have opted in; you may withdraw consent at any time
- Website improvement: analysing anonymised usage data to improve our website and services
4. Legal Basis for Processing
Under POPIA, we process your personal information on the following lawful grounds:
- Consent: when you voluntarily submit information via our contact form, book a repair, or opt in to marketing communications
- Contract: where processing is necessary to fulfil a service-level agreement (SLA), repair contract, or invoice
- Legitimate interest: for security monitoring of managed devices, fraud prevention, and improving our services, provided this does not override your rights
- Legal obligation: where we are required by law to retain records (e.g. tax legislation)
5. Third-Party Service Providers
We share personal information only with trusted third-party service providers who assist us in operating our business. Each provider is bound by their own privacy policies and data protection obligations. We never sell your personal information.
| Provider | Purpose | Data Shared |
|---|---|---|
| Resend | Transactional email delivery | Email address, name |
| Vercel | Website hosting and deployment | IP address, usage data |
| Google Analytics (GA4) | Website analytics | Anonymised browsing behaviour, IP (truncated) |
| Peach Payments | Payment processing | Payment card details (directly to Peach, not stored by us) |
| Zoho | CRM, invoicing, and quotes | Name, email, phone, service history |
6. Data Retention
We retain personal information only for as long as necessary to fulfil the purpose for which it was collected:
| Data Category | Retention Period |
|---|---|
| Client records (invoices, contracts, SLA data) | 5 years (in accordance with South African tax legislation) |
| Device diagnostics and repair history | 3 years |
| Contact form submissions | 1 year |
| Website analytics data (GA4) | 14 months (Google default) |
| Marketing consent records | Duration of consent plus 1 year |
Once the retention period has expired, personal information is securely deleted or anonymised.
7. Your Rights Under POPIA
Under Chapter 3 of the Protection of Personal Information Act, you have the following rights as a data subject:
- Right of access: request confirmation of whether we hold personal information about you, and obtain a copy of that information
- Right to correction: request the correction or updating of personal information that is inaccurate, incomplete, or misleading
- Right to deletion: request the deletion or destruction of personal information that is no longer necessary for the purpose for which it was collected
- Right to object: object to the processing of your personal information on reasonable grounds
- Right to restriction: request that we restrict the processing of your personal information in certain circumstances
- Right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing
- Right to lodge a complaint: submit a complaint to the Information Regulator if you believe your rights have been infringed
We will respond to all valid requests within 30 days, as required by POPIA. There is no fee for submitting a request, though we may charge a reasonable fee for manifestly unfounded or excessive requests.
8. How to Exercise Your Rights
To exercise any of your rights under POPIA, please contact us using one of the following methods:
Email: courtney@zasupport.com
Phone: 064 529 5863
Post: Information Officer, ZA Support, 1 Hyde Park Lane, Hyde Park, Johannesburg 2196
Online: Contact form
Please include your full name, contact details, and a clear description of the request. We may need to verify your identity before processing your request.
9. Information Officer
In accordance with POPIA Section 55, ZA Support has appointed the following Information Officer, responsible for ensuring compliance with the conditions of lawful processing:
If you are not satisfied with our response, you may lodge a complaint with the Information Regulator (South Africa):
Information Regulator (South Africa)
Email: enquiries@inforegulator.org.za
Website: inforegulator.org.za
10. Security Measures
We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or damage. These measures include:
- Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.3
- Encrypted storage: sensitive data at rest is encrypted using industry-standard encryption algorithms
- Access controls: strict role-based access controls ensure only authorised personnel can access personal information
- Regular audits: we conduct periodic security audits and vulnerability assessments of our systems
- Secure payments: payment processing is handled entirely by PCI DSS-compliant Peach Payments; we never store card details
- Device security: managed client devices are monitored for security compliance, including FileVault encryption, firewall status, and software updates
12. Breach Notification
In accordance with Section 22 of POPIA, in the event of a data breach that compromises the confidentiality or integrity of personal information, we will:
- Notify the Information Regulator as soon as reasonably possible, and no later than 72 hours after becoming aware of the breach
- Notify all affected data subjects in writing, providing details of the breach, the categories of information affected, and the measures taken to address it
- Take immediate steps to contain and remediate the breach, including forensic investigation where appropriate
- Maintain a breach register documenting all incidents, their impact, and corrective actions taken
13. Children's Privacy
ZA Support does not knowingly collect or process personal information from children under the age of 18 without the consent of a parent or legal guardian. Our services are directed at adults and businesses.
If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take immediate steps to delete that information. If you believe a child's data has been submitted to us, please contact our Information Officer at courtney@zasupport.com.
14. Medical Practice Data (HPCSA)
ZA Support provides managed IT services to medical practices in Johannesburg. Where we process data on behalf of healthcare practitioners, we do so in accordance with both POPIA and the guidelines issued by the Health Professions Council of South Africa (HPCSA).
This includes:
- Ensuring that patient data stored on managed devices is encrypted and access-controlled
- Maintaining strict confidentiality of all medical practice information
- Implementing security measures that align with HPCSA Booklet 5 (Confidentiality: Protecting and Providing Information) guidelines
- Ensuring that no patient data is accessed, copied, or retained by ZA Support during device repair or maintenance unless strictly necessary and authorised by the practice
Medical practice clients operate under their own POPIA and HPCSA obligations as data controllers. ZA Support acts as an operator (data processor) on their behalf and processes data only as instructed.
15. Policy Updates
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page.
We encourage you to review this policy periodically to stay informed about how we protect your personal information. Continued use of our website and services after any changes constitutes acceptance of the updated policy.