Legal
Privacy policy
How we collect, use and protect personal information, in line with the Protection of Personal Information Act.
On this page
01Who we are
VioletTech Solutions (Pty) Ltd is a technology consultancy registered in South Africa. We build business applications, primarily on Microsoft Power Platform and on ASP.NET and SQL Server, for South African organisations.
For the purposes of POPIA we are the responsible party for the personal information described in this policy — meaning we determine why and how it is processed.
02What information we collect
Information you give us directly
When you complete the contact form on our website, email us, or speak to us about a project, we collect what you choose to provide. Typically that is your name, your email address, your telephone number, your organisation, and whatever you tell us about your business and the problem you want solved.
Information collected automatically
Our website is a set of static pages. We do not operate our own analytics or advertising, and we do not place tracking cookies. However, the services that host and support the site do record technical information as an ordinary part of delivering it — including your IP address, browser type and the pages requested. This is described in section 4.
Our interactive demonstrations
Nothing you type into our product demonstrations is collected. The demonstrations at violettechnologies.co.za/solutions/ run entirely inside your browser. Any values you enter exist only on your device for the length of your visit, are never transmitted to us or anyone else, and are discarded when you close the page. There is no account, no login and no database behind them.
Business contact information
In the course of business development we record contact details for people at organisations we may work with — usually a name, a role, a work telephone number and a work email address, obtained from a public website, a business card, a referral or a conversation with you. Where that information identifies an individual, it is personal information and this policy applies to it.
03Why we process it, and on what basis
POPIA requires us to have a lawful justification for processing personal information. Ours are set out below.
| What we do | Why | Justification |
|---|---|---|
| Respond to an enquiry | To answer your question and, if relevant, propose work | Steps at your request before entering a contract |
| Deliver a project | To carry out the work we have agreed | Performance of a contract |
| Invoice and keep accounting records | To be paid and to meet our tax obligations | Legal obligation |
| Contact a prospective client | To introduce our services where we believe they are relevant | Legitimate interests, balanced against your rights |
| Send electronic marketing | To share updates about our work | Consent, or an existing customer relationship |
| Keep the website available and secure | To operate the site and prevent abuse | Legitimate interests |
We do not sell personal information, and we do not share it with third parties for their own marketing.
If you receive marketing from us and would prefer not to, tell us and we will stop. You will not need to give a reason and it will not affect anything else.
05Information sent outside South Africa
Several of the services above are operated by companies based outside South Africa and store information on servers in other countries, most commonly the United States and the European Union. This means some personal information is transferred across the border.
POPIA permits such transfers in defined circumstances. We rely on the recipient being subject to binding rules or a contract that provides an adequate level of protection, on the transfer being necessary to perform a contract with you, or on your consent, as applicable to each service.
If you would prefer to contact us without your information passing through those services, email or telephone us directly rather than using the website form.
06How long we keep it
- Enquiries that do not become projects — up to two years, in case you come back to us, then deleted.
- Client records, contracts and correspondence — for the life of the relationship and five years afterwards.
- Invoices and accounting records — five years, as required by the Tax Administration Act.
- Business development contacts — until the contact is no longer relevant, or you ask us to remove it, whichever comes first.
Where we are required by law to keep something for a set period, that period applies even if you ask us to delete it. We will tell you if that is the case.
07How we protect it
We take reasonable technical and organisational measures to keep personal information secure, appropriate to the size of our operation:
- Access to systems is restricted to those who need it, protected by strong, unique credentials and multi-factor authentication where available.
- Information is encrypted in transit. This site is served over HTTPS.
- Devices are kept updated and protected.
- Systems we build for clients are designed with role-based access and audit logging, so that who saw what, and when, is recorded.
No system is perfectly secure. If a security compromise occurs in which personal information is accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as soon as reasonably possible, as POPIA requires.
08Your rights
Under POPIA you have the right to:
- ask whether we hold personal information about you, and to be given a copy of it;
- ask us to correct or complete anything that is inaccurate, misleading or out of date;
- ask us to delete information we no longer have a lawful reason to keep;
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent at any time, where we relied on consent;
- ask us not to send you electronic marketing; and
- complain to the Information Regulator.
To exercise any of these, email info@violettechnologies.co.za. We will respond as soon as we reasonably can and within any period the law requires. We may need to verify who you are before acting, to be sure we are not disclosing your information to someone else. A request for access to a record may be subject to the procedures and fees set out in the Promotion of Access to Information Act.
09Client data and our role as operator
When we build or support a system for a client, that system often contains personal information about the client's own employees, customers or suppliers — for example an employee's leave records, or a supplier's banking details.
For that information the client is the responsible party and we are the operator. We process it only on the client's documented instructions, for the purpose of delivering the work, and we do not use it for anything of our own. Our obligations in each case are set out in the agreement we sign with that client, including confidentiality, security measures, and what happens to the information when the engagement ends.
If you are an employee, customer or supplier of one of our clients and you have a question about your information in a system we built, please approach that organisation directly — they are the responsible party and hold the relationship with you. We will support them in responding.
10Children's information
Our services are directed at organisations, not at children. We do not knowingly collect personal information about a child. If you believe we hold information about a child, tell us and we will delete it unless the law requires otherwise.
11Changes to this policy
We will update this policy when our practices, our suppliers or the law change. The effective date at the top of this page shows when the current version took effect. Where a change materially affects how we handle your information, we will take reasonable steps to tell you rather than relying on you noticing.
12Contact and complaints
Please raise anything about this policy, or about how we have handled your information, with us first. We would rather fix it directly.
If you are not satisfied with our response, you may complain to the regulator: