Sefeko (Pty) Ltd · Sefeko Monitoring (Pty) Ltd · Sefeko Solutions (Pty) Ltd
Aligned with the Protection of Personal Information Act, 4 of 2013, and the POPIA Amendment Regulations, 2025
Version 3.0
This Group Privacy Policy applies to the following three South African companies, each of which is a separate juristic person and a separate responsible party under the Protection of Personal Information Act, 4 of 2013 ("POPIA"):
In this policy, "Sefeko", "we", "us", or "our" refers to the company in the group that processes your personal information for the purpose in question. Each company is responsible for its own processing under POPIA. Where a service is delivered jointly, the responsible party is the company that contracts with you or holds the customer relationship.
This policy is governed by the laws of the Republic of South Africa. It complies with:
By using our website, app, or services, you confirm that you have read and understood this policy.
The companies covered by this policy are:
| Sefeko (Pty) Ltd | Sefeko Monitoring (Pty) Ltd | Sefeko Solutions (Pty) Ltd |
|---|---|---|
| Holding company | Subsidiary (50.01% held by Sefeko (Pty) Ltd) | Subsidiary (50.01% held by Sefeko (Pty) Ltd) |
| Reg. No.: 2003/010592/07 | Reg. No.: 2020/597565/07 | Reg. No.: 2020/597636/07 |
| Building D, The Woods, 41 De Havilland Crescent, Persequor Park, 0020, Pretoria, Gauteng | Building D, The Woods, 41 De Havilland Crescent, Persequor Park, 0020, Pretoria, Gauteng | First Floor, False Bay House, Tygerberg Office Park, 163 Uys Krige Drive, Plattekloof, 7500, Cape Town |
| legal@sefeko.co.za | legal@sefeko.co.za | legal@sefeko.co.za |
Each company shares the general phone line +27 86 173 3356 unless a service-specific number is published.
In line with section 55 of POPIA, each company has its own Information Officer registered with the Information Regulator. By default, the Information Officer of each company is its Chief Executive Officer or Managing Director. Deputy Information Officers may be appointed to share the workload.
Information Officer queries for any company in the group: legal@sefeko.co.za. We will route the query to the correct Information Officer.
If you cannot resolve a matter with us, you may lodge a complaint with the Information Regulator (see section 14).
Key terms used in this policy carry the meaning given in POPIA. The most important are:
Section 4 of POPIA sets out eight conditions for lawful processing. Each Sefeko company applies all of them:
Across the group, we collect the following categories of personal information:
We only collect special personal information where we have a lawful basis under section 27 of POPIA, such as your express consent or a legal obligation.
We process personal information for the following purposes, each supported by a lawful basis under section 11 of POPIA:
We do not knowingly process special personal information or the personal information of a child (a person under 18) unless:
If you believe we hold a child's personal information without proper consent, contact us and we will remove it.
Under section 69 of POPIA, as clarified by the POPIA Amendment Regulations, 2025, we may only send you direct marketing by electronic means (email, SMS, WhatsApp, automated calls, or fax) if:
A pre-ticked box or an opt-out option on its own is not valid consent under the 2025 amendments.
You can withdraw consent at any time by emailing legal@sefeko.co.za. We will action this without charge.
Under sections 23, 24, and 25 of POPIA, you have the right to:
To exercise any of these rights, email legal@sefeko.co.za and tell us which Sefeko company holds your information, if you know. If not, we will help you find out. We will respond within a reasonable time and at no cost, in line with the POPIA Amendment Regulations, 2025.
If you are not happy with how we have handled your personal information, you may lodge a complaint with the Information Regulator (South Africa):
Some of our service providers are based outside South Africa. Where we transfer personal information across borders, we comply with section 72 of POPIA. Each Sefeko company relies on one of the following grounds for any given transfer:
In most cases, we rely on written data processing agreements with our service providers that meet the adequacy standard in section 72(1)(a).
Each Sefeko company keeps personal information only for as long as needed for the purpose it was collected, or longer if the law requires it. Common retention periods include:
After the retention period, we will delete or de-identify the information.
In line with section 19 of POPIA, each Sefeko company applies reasonable technical and organisational measures to protect personal information against loss, damage, or unauthorised access. These include access controls, encryption, secure backups, staff training, and contracts with our operators.
No system is 100% secure. While we cannot guarantee absolute security, we work to protect your information and to act quickly if something goes wrong.
If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, the relevant Sefeko company will, in line with section 22 of POPIA:
The notice will include enough detail for you to take protective steps.
The Sefeko group has a single Group PAIA Manual that covers all three companies, prepared in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000. The Manual is available on our website or on request from legal@sefeko.co.za.
We may update this policy from time to time to reflect changes in law or our practices. The latest version will always be on our website with the effective date shown at the top. Where the change is material, we will let you know by email or a notice on the service.
For any questions, requests, or complaints about this policy or your personal information, contact us:
End of policy