Privacy Policy
How DigiTusk collects, uses, and protects your personal information.
Effective date:
Introduction
This Privacy Policy explains how DigiTusk ("we", "us", "our") collects, uses, stores, shares, and protects your personal information when you visit digitusk.co.za, submit our contact form, book a consultation, or otherwise engage our services.
We are committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA"), and the Electronic Communications and Transactions Act 25 of 2002 ("ECT Act").
By using our website or providing us with your personal information, you confirm that you have read, understood, and consented to the processing of your personal information as described in this policy.
Who we are
Responsible party: DigiTusk, a sole proprietorship registered in South Africa, with its principal place of business in Johannesburg, Gauteng.
Information Officer: Kono Ndlovu (registered with the Information Regulator of South Africa under section 55 of POPIA).
Contact for privacy queries: hello@digitusk.co.za
What personal information we collect
We only collect personal information that is necessary, relevant, and not excessive for the purposes described in this policy. The categories of personal information we may collect include:
3.1 Information you provide directly
- Contact form submissions:
- your name, surname, email address, company name (optional), and the contents of your message.
- Consultation bookings:
- your name, email address, and intake answers submitted through our Cal.com booking widget.
- Email correspondence:
- any information you choose to share when emailing us directly.
- Client engagements:
- information necessary to deliver our services, including business details, project briefs, brand assets, and any personal information about your team or customers that you provide to us during a project.
3.2 Information collected automatically
- Usage analytics:
- we use Vercel Analytics, which collects anonymised data about page views, referrers, country of origin, and device type. This service does not use cookies and does not collect personally identifiable information by default.
- Server logs:
- our hosting provider (Vercel) may automatically log IP addresses, browser type, request times, and pages visited, for security, debugging, and abuse prevention purposes.
3.3 What we do not collect
We do not collect special personal information (as defined in section 26 of POPIA) such as race, ethnicity, religion, health information, sexual orientation, biometric data, or criminal history. We do not knowingly collect personal information from children under the age of 18. If you believe a child has submitted personal information to us, please contact us immediately so we can delete it.
Why we collect your personal information (purpose)
We process your personal information for the following purposes only:
- Responding to enquiries submitted via the contact form or email.
- Scheduling and conducting consultations.
- Quoting, contracting, and delivering web design and development services.
- Sending invoices and processing payment-related correspondence.
- Improving our website performance, security, and user experience.
- Complying with our legal, tax, and regulatory obligations under South African law.
We will not use your personal information for any other purpose without your further consent, unless required or permitted by law.
Legal basis for processing
We process your personal information on one or more of the following lawful bases under section 11 of POPIA:
- Consent:
- when you voluntarily submit our contact form or book a consultation.
- Contract performance:
- when processing is necessary to deliver services to you or a business you represent.
- Legitimate interests:
- to operate, secure, and improve our website and respond to enquiries, balanced against your privacy rights.
- Legal obligation:
- to comply with applicable laws, including tax and accounting record-keeping requirements.
Who we share your personal information with
We do not sell your personal information. We share personal information only with the following categories of operators (third-party service providers), each of whom is contractually or legally required to protect it:
6.1 Operators (sub-processors)
- Vercel Inc. (USA):
- website hosting, server logs, and anonymised analytics. Data may be processed outside South Africa.
- domains.co.za (South Africa):
- domain registration and SMTP email delivery. Contact form submissions are routed through their mail servers to our hello@digitusk.co.za inbox.
- Cal.com Inc. (USA):
- consultation booking. Information you submit to the booking widget is processed on Cal.com infrastructure.
- GitHub Inc. (USA, owned by Microsoft):
- source code hosting. Personal information is not stored in our codebase.
6.2 Other disclosures
- We may disclose your personal information if compelled to do so by a competent court, regulator, or law enforcement authority.
- We may share information with our professional advisors (accountants, attorneys) under strict confidentiality obligations.
Cross-border transfers
Some of our operators (Vercel, Cal.com, GitHub) are based outside South Africa, primarily in the United States and the European Union. Where personal information is transferred outside South Africa, we rely on the lawful grounds under section 72 of POPIA, including:
- The recipient being subject to laws or binding agreements that provide an adequate level of protection.
- Your consent to the transfer.
- The transfer being necessary for the performance of a contract with you or in your interest.
How long we keep your personal information
We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:
- Contact form enquiries:
- up to 12 months from your last interaction, unless a client relationship is established.
- Client records:
- for the duration of our engagement and for at least 5 years after the engagement ends, in line with tax and accounting requirements (Tax Administration Act 28 of 2011 and Companies Act 71 of 2008).
- Server logs:
- typically retained by our hosting provider for up to 30 days.
At the end of the applicable retention period, we will securely delete or anonymise your personal information.
How we protect your personal information
We take reasonable, appropriate technical and organisational measures to safeguard personal information against loss, unauthorised access, modification, and disclosure, in line with section 19 of POPIA. These measures include:
- TLS/HTTPS encryption on all website traffic.
- Secure SMTP (TLS) for contact form email delivery.
- Access controls, strong passwords, and limited access to client data.
- Reputable cloud providers with their own security certifications and obligations.
- Regular review of our processing practices.
Despite these measures, no system is entirely secure. If a security compromise occurs that affects your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.
Your rights as a data subject
Under POPIA, you have the right to:
- Be notified that your personal information is being collected, or has been accessed without authorisation.
- Request access to the personal information we hold about you.
- Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, or no longer necessary.
- Object to the processing of your personal information on reasonable grounds.
- Withdraw your consent at any time, where processing is based on consent.
- Lodge a complaint with the Information Regulator if you believe we have not handled your personal information lawfully.
To exercise any of these rights, email us at hello@digitusk.co.za with the subject line "POPIA request". We may need to verify your identity before responding. We will respond within a reasonable time and at no cost, unless your request is manifestly unreasonable.
Cookies and tracking
Our website uses minimal tracking. Vercel Analytics is cookieless. Embedded third-party widgets, such as Cal.com, may set cookies on your device when you interact with them. For full details, see our Cookie Notice at /cookies.
Complaints
If you have a complaint about how we handle your personal information, please contact us first at hello@digitusk.co.za so we can attempt to resolve it. If you are not satisfied with our response, you may lodge a complaint with:
The Information Regulator (South Africa)JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001PO Box 31533, Braamfontein, Johannesburg, 2017General enquiries: enquiries@inforegulator.org.zaComplaints: POPIAComplaints@inforegulator.org.zaPAIA complaints: PAIAComplaints@inforegulator.org.zaWebsite: https://inforegulator.org.zaChanges to this policy
We may update this Privacy Policy from time to time. The latest version will always be available at digitusk.co.za/privacy with the effective date shown at the top. Material changes will be communicated via the website or by email if appropriate.
Contact us
Questions about this policy or our handling of your personal information:
Email: hello@digitusk.co.zaInformation Officer: Kono Ndlovu