Legal · POPIA Compliant

Privacy Policy

ZA Support is committed to protecting your personal information in accordance with the Protection of Personal Information Act (POPIA), 2013. This policy explains what data we collect, why we collect it, and how we safeguard it.

Last updated: 30 March 2026

1. Data Controller

The responsible party (data controller) for the processing of your personal information is:

Vizibiliti IS (Pty) Ltd

Trading as ZA Support

1 Hyde Park Lane, Hyde Park, Johannesburg 2196

VAT: 436-026-0014

Email: courtney@zasupport.com

Phone: 064 529 5863

2. Personal Information We Collect

We may collect the following categories of personal information, depending on the services you use:

  • Identity information: full name, email address, telephone number
  • Device information: Apple device model, serial number, hardware diagnostics, macOS version, battery health, storage capacity
  • Technical data: IP address, browser type, referring URL, pages visited
  • Usage data: anonymised analytics collected via Google Analytics 4 (GA4), including page views, session duration, and user flow
  • Financial information: payment card details (processed securely by our payment provider; we do not store card numbers)
  • Communication records: emails, contact form submissions, and support correspondence

3. Purpose of Collection

We collect and process personal information for the following purposes:

  • Service delivery: diagnosing, repairing, and returning your Apple devices
  • Device repair tracking: maintaining a record of repairs, diagnostics, and device history for warranty and quality purposes
  • SLA management: administering managed IT service agreements, scheduling maintenance, and monitoring device health
  • Invoicing and payments: generating quotes, invoices, and processing payments
  • Communication: responding to enquiries, providing repair updates, and sending service-related notifications
  • Marketing: sending promotional content only where you have opted in; you may withdraw consent at any time
  • Website improvement: analysing anonymised usage data to improve our website and services

5. Third-Party Service Providers

We share personal information only with trusted third-party service providers who assist us in operating our business. Each provider is bound by their own privacy policies and data protection obligations. We never sell your personal information.

ProviderPurposeData Shared
ResendTransactional email deliveryEmail address, name
VercelWebsite hosting and deploymentIP address, usage data
Google Analytics (GA4)Website analyticsAnonymised browsing behaviour, IP (truncated)
Peach PaymentsPayment processingPayment card details (directly to Peach, not stored by us)
ZohoCRM, invoicing, and quotesName, email, phone, service history

6. Data Retention

We retain personal information only for as long as necessary to fulfil the purpose for which it was collected:

Data CategoryRetention Period
Client records (invoices, contracts, SLA data)5 years (in accordance with South African tax legislation)
Device diagnostics and repair history3 years
Contact form submissions1 year
Website analytics data (GA4)14 months (Google default)
Marketing consent recordsDuration of consent plus 1 year

Once the retention period has expired, personal information is securely deleted or anonymised.

7. Your Rights Under POPIA

Under Chapter 3 of the Protection of Personal Information Act, you have the following rights as a data subject:

  • Right of access: request confirmation of whether we hold personal information about you, and obtain a copy of that information
  • Right to correction: request the correction or updating of personal information that is inaccurate, incomplete, or misleading
  • Right to deletion: request the deletion or destruction of personal information that is no longer necessary for the purpose for which it was collected
  • Right to object: object to the processing of your personal information on reasonable grounds
  • Right to restriction: request that we restrict the processing of your personal information in certain circumstances
  • Right to withdraw consent: where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing
  • Right to lodge a complaint: submit a complaint to the Information Regulator if you believe your rights have been infringed

We will respond to all valid requests within 30 days, as required by POPIA. There is no fee for submitting a request, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

8. How to Exercise Your Rights

To exercise any of your rights under POPIA, please contact us using one of the following methods:

Email: courtney@zasupport.com

Phone: 064 529 5863

Post: Information Officer, ZA Support, 1 Hyde Park Lane, Hyde Park, Johannesburg 2196

Online: Contact form

Please include your full name, contact details, and a clear description of the request. We may need to verify your identity before processing your request.

9. Information Officer

In accordance with POPIA Section 55, ZA Support has appointed the following Information Officer, responsible for ensuring compliance with the conditions of lawful processing:

Courtney Bentley

Information Officer

Email: courtney@zasupport.com

Phone: 064 529 5863

If you are not satisfied with our response, you may lodge a complaint with the Information Regulator (South Africa):

Information Regulator (South Africa)

Email: enquiries@inforegulator.org.za

Website: inforegulator.org.za

10. Security Measures

We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or damage. These measures include:

  • Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.3
  • Encrypted storage: sensitive data at rest is encrypted using industry-standard encryption algorithms
  • Access controls: strict role-based access controls ensure only authorised personnel can access personal information
  • Regular audits: we conduct periodic security audits and vulnerability assessments of our systems
  • Secure payments: payment processing is handled entirely by PCI DSS-compliant Peach Payments; we never store card details
  • Device security: managed client devices are monitored for security compliance, including FileVault encryption, firewall status, and software updates

11. Cookies and Analytics

Our website uses cookies to improve your browsing experience and to collect anonymised analytics data.

  • Analytics cookies: we use Google Analytics 4 (GA4) to understand how visitors interact with our website. GA4 collects anonymised data including page views, session duration, and approximate geographic location. IP addresses are truncated before storage.
  • Essential cookies: these are strictly necessary for the website to function correctly (e.g. session management, security tokens).
  • No advertising cookies: we do not use any advertising, tracking, or retargeting cookies.

By continuing to use our website, you consent to the use of analytics cookies as described above. You may disable cookies in your browser settings at any time, though this may affect website functionality.

12. Breach Notification

In accordance with Section 22 of POPIA, in the event of a data breach that compromises the confidentiality or integrity of personal information, we will:

  • Notify the Information Regulator as soon as reasonably possible, and no later than 72 hours after becoming aware of the breach
  • Notify all affected data subjects in writing, providing details of the breach, the categories of information affected, and the measures taken to address it
  • Take immediate steps to contain and remediate the breach, including forensic investigation where appropriate
  • Maintain a breach register documenting all incidents, their impact, and corrective actions taken

13. Children's Privacy

ZA Support does not knowingly collect or process personal information from children under the age of 18 without the consent of a parent or legal guardian. Our services are directed at adults and businesses.

If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take immediate steps to delete that information. If you believe a child's data has been submitted to us, please contact our Information Officer at courtney@zasupport.com.

14. Medical Practice Data (HPCSA)

ZA Support provides managed IT services to medical practices in Johannesburg. Where we process data on behalf of healthcare practitioners, we do so in accordance with both POPIA and the guidelines issued by the Health Professions Council of South Africa (HPCSA).

This includes:

  • Ensuring that patient data stored on managed devices is encrypted and access-controlled
  • Maintaining strict confidentiality of all medical practice information
  • Implementing security measures that align with HPCSA Booklet 5 (Confidentiality: Protecting and Providing Information) guidelines
  • Ensuring that no patient data is accessed, copied, or retained by ZA Support during device repair or maintenance unless strictly necessary and authorised by the practice

Medical practice clients operate under their own POPIA and HPCSA obligations as data controllers. ZA Support acts as an operator (data processor) on their behalf and processes data only as instructed.

15. Policy Updates

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page.

We encourage you to review this policy periodically to stay informed about how we protect your personal information. Continued use of our website and services after any changes constitutes acceptance of the updated policy.