Privacy & Data Protection Notice

Sethala (Pty) Ltd · Registration Number: 2012/163091/07

Last updated31 August 2026
Effective date31 August 2026
Version2026.2

1. Purpose and Scope

1.1 This Privacy & Data Protection Notice (“Notice”) explains how Sethala (Pty) Ltd (“Sethala”, “we”, “us” or “our”) collects, uses, stores, shares, retains and protects Personal Information when Sethala acts as a Responsible Party.

1.2 This Notice applies to Personal Information processed by Sethala in connection with the Sethala website, business enquiries, customer and supplier relationships, platform and account administration, support, security, billing, business communications and other ordinary business operations.

1.3 This Notice is intended primarily to meet Sethala’s obligations under the Protection of Personal Information Act 4 of 2013 (POPIA), including the notification requirements in section 18. Where another jurisdiction’s data protection law lawfully applies to Sethala’s processing, additional rights or obligations may apply.

1.4 This Notice does not replace the Sethala Terms of Service and Use, a customer agreement, Data Processing Agreement (DPA), reseller or hosted-partner data-protection addendum, service agreement or other specific contractual privacy terms. Those documents may regulate particular Processing activities in more detail.

1.5 Where Sethala Processes Personal Information directly on behalf of a Customer or other Responsible Party under a contract or mandate with that Responsible Party, Sethala acts as Operator for that Processing and the applicable DPA governs Sethala’s Operator obligations. Where Sethala Processes Personal Information downstream on behalf of a Reseller, Hosted Partner or other Operator, Sethala processes within the Responsible Party’s knowledge or authorisation as contemplated by section 20 of POPIA, and the relevant data-protection addendum and upstream Operator arrangement govern that processing chain.

1.6 This Notice does not govern non-personal machine, device, asset, telemetry, operational or technical data merely because that data is processed through Sethala’s systems. Where such data becomes reasonably linkable to an identifiable natural or juristic person, it may constitute Personal Information and this Notice and POPIA may apply.

1.7 Sethala has a separate Staff Privacy Policy for employees and other HR-related processing. This public Notice is not intended to replace that policy.

1.8 Cookies, browser storage and similar technologies used on Sethala’s public website are addressed separately in Sethala’s Cookie Notice.

2. Who We Are and How to Contact Us

ItemDetails
Responsible PartySethala (Pty) Ltd
Registration number2012/163091/07
Physical address4th Floor, Menlyn Corner, 87 Frikkie de Beer Street, Menlyn, Pretoria, 0181, South Africa
Telephone+27 12 942 4000
General emailinfo@sethala.com
Privacy / POPIA emailadmin@sethala.com
Information OfficerRolf Schurink
Deputy Information OfficerBerdina Schurink

2.1 Routine privacy, POPIA and data-subject requests should be sent to admin@sethala.com so that Sethala can route, log and manage requests appropriately while preserving the statutory functions of the Information Officer and Deputy Information Officer.

3. Personal Information We May Process

3.1 The Personal Information Sethala processes depends on the relationship and context. It may include:

Business and contact information: name, surname, job title or role, company, department or site, business address, work email address and telephone number.

Enquiry and correspondence information: the content of enquiries, emails, meeting records, proposals, quotations, contracts, complaints and other business communications.

Platform and account information: name, surname, username or user identifier, business email address, telephone number where used, role, site or organisational unit, access permissions and account-administration information.

Authentication, security and Service Data that is Personal Information: login and access records, audit logs, session or user identifiers, security events, support records, device or browser information, IP information and other technical information used for administration, troubleshooting, security and platform integrity.

Customer, supplier and commercial information: contract, order, account, billing, invoice, payment, tax or business-administration information relevant to the relationship.

Support and complaint information: support requests, screenshots or supporting material, correspondence, investigation records and outcomes.

Compliance and legal records: information reasonably required for legal, tax, accounting, regulatory, security, fraud-prevention, dispute-resolution or record-keeping purposes.

3.2 Sethala does not intentionally collect more Personal Information than is reasonably necessary for the relevant purpose. Users should not place passwords, private keys, payment-card information, bank-account credentials, Special Personal Information or other unnecessarily sensitive information into free-form fields or general enquiry forms unless the field or process is specifically intended for that information and the disclosure is lawful.

4. How We Collect Personal Information

4.1 Sethala may collect Personal Information:

a. directly from you when you contact us, complete an enquiry form, enter into a business relationship, use an Account, request support or correspond with Sethala;

b. from the organisation you represent, a Customer, Reseller, authorised Account Administrator or other business counterparty where it lawfully provides your information for business or platform purposes;

c. from publicly available business sources or professional channels where lawful and relevant to a legitimate business purpose;

d. from approved suppliers, service providers and business systems used for communication, administration, accounting, security, support or other operational purposes; and

e. automatically through normal website, platform, audit, security, logging or other technical functions. Cookies, browser storage and similar website technologies are described separately in Sethala’s Cookie Notice.

5. Why We Process Personal Information and Our Lawful Grounds

5.1 Sethala may Process Personal Information for purposes including:

  • responding to enquiries and taking steps requested before entering into a business relationship;
  • establishing, managing and supporting customer, reseller, partner, supplier and other business relationships;
  • creating, administering and securing Accounts and User access;
  • authenticating Users, assigning roles and permissions, maintaining audit records and protecting platform integrity;
  • providing support, troubleshooting, investigating complaints and resolving operational issues;
  • preparing proposals, quotations, orders, agreements, invoices and related business documentation;
  • billing, accounting, financial administration and payment management;
  • operating, maintaining, securing, testing, monitoring and improving Sethala’s website, business systems and Services;
  • protecting Sethala, Customers, Users, personnel, systems, intellectual property and legal interests;
  • detecting, preventing and investigating fraud, misuse, unauthorised access, unlawful activity and security incidents;
  • complying with legal, tax, accounting, corporate, regulatory, record-keeping and reporting obligations;
  • establishing, exercising or defending legal claims and resolving disputes;
  • internal governance, reporting, business planning, service quality and business continuity; and
  • direct marketing and business development where permitted by law.

5.2 Depending on the circumstances, Sethala may rely on one or more lawful grounds permitted by POPIA, including consent, the conclusion or performance of a contract, compliance with an obligation imposed by law, protection of a legitimate interest of the Data Subject, or the legitimate interests of Sethala or a third party.

5.3 Where a particular law specifically authorises or requires Sethala to collect Personal Information, Sethala will identify that requirement where reasonably practicable at the relevant collection point or in the applicable business documentation.

6. When Providing Information Is Voluntary or Required

6.1 Providing Personal Information is generally voluntary, but some information is necessary for Sethala to perform a requested action, create or administer an Account, provide or secure a Service, manage a commercial relationship, process payment, respond to a support request or comply with law.

6.2 If required information is not provided, Sethala may be unable to respond to an enquiry, establish or continue the relevant business relationship, create or maintain access, provide support, process a transaction or comply with a legal obligation.

6.3 Where an organisation or Account Administrator requires particular information as a condition of a User’s access to a Customer-controlled environment, that requirement may arise from the Customer’s own policies or relationship with the User rather than from Sethala.

6.4 Where a legal requirement makes provision of information mandatory, the consequences of failing to provide it will depend on the applicable law and the relevant transaction or relationship.

7. Platform Users and Customer-Controlled Personal Information

7.1 Sethala may act as a Responsible Party for limited Personal Information relating to platform Users and business contacts where Sethala determines the purpose of Processing, for example account administration, authentication, security, support administration, billing, legal compliance and business communications.

7.2 Customers and end customers may use Sethala Services to Process Personal Information for their own business purposes. Where that organisation determines why and how the Personal Information is Processed, it is generally the Responsible Party. Sethala may act as that organisation’s directly appointed Operator where a DPA applies, or may perform authorised downstream Processing on behalf of a Reseller, Hosted Partner or other Operator in a processing chain contemplated by section 20 of POPIA.

7.3 Customer-controlled Personal Information may vary significantly between use cases. Sethala does not determine the full scope of Personal Information each Customer chooses to collect or Process through a Service.

7.4 Customers remain responsible for ensuring that their collection, use, disclosure and instructions concerning Customer-controlled Personal Information are lawful, necessary, accurate and appropriately authorised.

7.5 Where a User is required to tick a box acknowledging this Notice before accessing a Service, that acknowledgement confirms that the Notice was made available to the User. It is not blanket consent to every Processing activity described in this Notice.

8. Special Personal Information and Children’s Personal Information

8.1 Sethala does not intentionally collect Special Personal Information or children’s Personal Information through its public website or ordinary business processes unless the Processing is lawful, necessary and appropriate for a specific purpose.

8.2 The Services are intended primarily for business and professional use and are not directed at children. A Customer must not use the Services to Process children’s Personal Information or Special Personal Information unless the Processing is lawful and permitted by the applicable agreement and, where required, Sethala has expressly agreed to the relevant use case.

8.3 Where Sethala itself is the Responsible Party for Special Personal Information or children’s Personal Information, Sethala will apply the additional requirements of POPIA that are relevant to that Processing.

9. Enquiries, Service Communications and Direct Marketing

9.1 Information submitted through a contact or enquiry form is used primarily to respond to the enquiry and manage any resulting business discussion. Submitting an enquiry does not by itself constitute consent to receive direct marketing.

9.2 Operational, administrative, security, billing, contractual and support communications that are reasonably necessary for a Service or business relationship are not treated as marketing merely because they are sent electronically.

9.3 Sethala may send unsolicited electronic direct marketing only where permitted by POPIA, including where the Data Subject has consented or where the existing-customer exception in section 69 applies.

9.4 Where Sethala offers a marketing opt-in, it will be separate from ordinary enquiry submission and platform acceptance. A recipient may withdraw consent or opt out of direct marketing at any time using the unsubscribe method provided or by contacting admin@sethala.com.

10. Sharing of Personal Information and Operators

10.1 Sethala does not sell Personal Information.

10.2 Where lawful and reasonably necessary, Sethala may disclose Personal Information to categories of recipients including:

  • authorised Sethala personnel and contractors who need the information for their functions;
  • hosting, infrastructure, communications, accounting, IT, security, support, analytics and other operational service providers;
  • Customers, Resellers, Account Administrators, suppliers, partners or other business counterparties where disclosure is necessary for the relevant relationship and lawful;
  • professional advisers such as accountants, auditors, tax advisers, legal advisers and insurers;
  • banks and payment or financial-administration providers where relevant;
  • regulators, courts, law-enforcement authorities and other competent authorities where disclosure is required or permitted by law; and
  • a purchaser, investor, funder, successor or adviser in connection with a lawful corporate or financing transaction, subject to appropriate confidentiality and data-protection controls.

10.3 Where a third party Processes Personal Information on Sethala’s behalf as an Operator, Sethala takes reasonable steps to require appropriate confidentiality and security safeguards and to regulate the Processing in writing as required by POPIA. Where a supplier processes customer-controlled Personal Information downstream in an existing processing chain, Sethala also requires appropriate contractual confidentiality, security, access and incident controls.

10.4 Sethala does not publish a detailed public inventory of infrastructure providers, security suppliers or technical architecture where disclosure could create unnecessary operational or cybersecurity risk.

11. International Processing and Transfers

11.1 Sethala is based in South Africa and may interact with Customers, partners, service providers and other organisations in South Africa and other jurisdictions. Personal Information may therefore be accessed, received, stored or Processed outside South Africa in appropriate circumstances.

11.2 Where POPIA applies to a transfer of Personal Information outside South Africa, Sethala will take reasonable steps to ensure that the transfer is permitted under section 72 of POPIA, including where appropriate through adequate protection, contractual safeguards, consent, contractual necessity or another lawful transfer basis.

11.3 Privacy and data-protection laws differ between countries. Sethala does not assume that every foreign jurisdiction provides protection identical to South Africa. Where section 72 requires appropriate protection, Sethala will use the safeguards reasonably applicable to the relevant transfer.

11.4 Where another jurisdiction’s data-protection law applies to Sethala’s Processing, Sethala will take reasonable steps to meet the additional requirements applicable to that Processing.

12. Retention

12.1 Sethala retains Personal Information only for as long as reasonably necessary for the purpose for which it was collected or subsequently lawfully Processed, or for as long as required or permitted by law, contract, legitimate business needs, audit, security, dispute resolution or the establishment, exercise or defence of legal claims.

12.2 When Sethala is no longer authorised or required to retain Personal Information, Sethala will take reasonable steps to delete, destroy, de-identify or otherwise deal with it as permitted by applicable law and Sethala’s retention practices.

12.3 Customer-controlled Personal Information is retained, exported, returned or deleted in accordance with the applicable Customer, reseller or hosted-partner agreement, any applicable DPA or data-protection addendum, lawful instructions, available platform functionality, backup processes and legal retention requirements.

13. Information Security

13.1 Sethala applies appropriate and reasonable technical and organisational measures designed to protect the confidentiality, integrity and availability of Personal Information and reduce the risk of loss, damage, unauthorised destruction, unlawful access or unlawful Processing.

13.2 Measures may include access controls, authentication, role-based permissions, confidentiality obligations, logging, security monitoring, backup and recovery arrangements, system maintenance, incident management, supplier controls and other risk-based safeguards.

13.3 No method of electronic transmission, storage or Processing can be guaranteed to be completely secure. Sethala therefore does not promise absolute security.

13.4 For security reasons, this public Notice does not disclose detailed infrastructure architecture, security configurations, credentials, provider inventories or other information that could reasonably increase operational or cybersecurity risk.

14. Security Compromises

14.1 Where Sethala is the Responsible Party and has reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, Sethala will act in accordance with section 22 of POPIA, including investigation, mitigation and the notifications required by law.

14.2 Where Sethala is directly acting as an Operator and becomes aware of a Security Compromise involving Personal Information Processed for the Responsible Party, Sethala will notify that Responsible Party immediately as required by section 21(2) of POPIA and the applicable DPA. Where Sethala performs downstream Processing on behalf of a Reseller, Hosted Partner or other Operator, Sethala will immediately notify the relevant upstream party under the applicable data-protection addendum so that the statutory notification chain can be followed.

14.3 Where Sethala is the Responsible Party, notification to the Information Regulator and affected Data Subjects will be made as soon as reasonably possible after discovery of the compromise, subject to any delay permitted or required by law.

14.4 Customers and Users should notify Sethala promptly if they become aware of an actual or suspected security incident involving Sethala systems, Accounts, credentials or information Processed through the Services.

15. Your Rights

15.1 Subject to POPIA, other applicable law and lawful limitations, a Data Subject may have the right to:

  • ask whether Sethala holds Personal Information about them and request access to it;
  • request correction, updating or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading or unlawfully obtained Personal Information;
  • request destruction or deletion of records that Sethala is no longer authorised to retain;
  • object to certain Processing on reasonable grounds where POPIA provides that right;
  • withdraw consent where Processing is based on consent, without affecting Processing that was lawful before withdrawal;
  • object to or opt out of direct marketing; and
  • lodge a complaint with the Information Regulator or another competent authority where applicable.

15.2 Requests may be submitted to admin@sethala.com or through another reasonably accessible communication channel Sethala makes available. Sethala may require reasonable proof of identity or authority before disclosing, correcting or deleting Personal Information. Where an objection or correction/deletion request is made telephonically, Sethala will create the electronic record required by the applicable POPIA Regulations and will make the recording or a transcription available free of charge on request.

15.3 Objections under section 11(3) and correction/deletion requests under section 24 may be made using the current prescribed Form 1 or Form 2, or a substantially similar form as permitted by the applicable POPIA Regulations. These requests are handled free of charge, subject to any separate lawful fee that may apply to an access request under PAIA or POPIA.

16. Requests Concerning Customer-Controlled Personal Information

16.1 If a request concerns Personal Information for which a Sethala Customer or end customer is the Responsible Party, the Data Subject should generally direct the request to that organisation.

16.2 Where Sethala receives a request relating to Customer-controlled Personal Information, Sethala may refer the requester to the relevant Responsible Party, notify the appropriate Customer, Reseller or Hosted Partner, assist as required by the applicable DPA, data-protection addendum or agreement, or respond directly where Sethala is legally required or permitted to do so.

16.3 Sethala will not ordinarily disclose, amend, delete or export Customer-controlled Personal Information on an individual’s instruction where Sethala is acting only as Operator or as an authorised person Processing on behalf of an Operator, unless authorised through the applicable Responsible Party / Operator chain, required by law or otherwise permitted by the applicable agreement.

17. Automated Processing and Decisions

17.1 Sethala does not ordinarily use Personal Information, in its own capacity as Responsible Party, to make decisions based solely on automated Processing that produce legal consequences or affect a Data Subject to a substantial degree.

17.2 Sethala’s Services may support automated alerts, workflows, analytics or other automated functions configured or used by Customers. Where a Customer determines the purpose and use of such functionality in relation to Customer-controlled Personal Information, the Customer remains responsible for its own compliance with applicable law.

17.3 If Sethala introduces solely automated decision-making in its own Responsible Party capacity that is regulated by POPIA, Sethala will provide the notices and safeguards required by law.

18. Information Regulator

18.1 A person who believes that Sethala has interfered with the protection of their Personal Information may lodge a complaint with the Information Regulator (South Africa). Current contact details published by the Regulator are:

ItemDetails
Physical addressWoodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191, South Africa
Telephone010 023 5200
Toll-free0800 017 160
General emailenquiries@inforegulator.org.za
POPIA complaintsPOPIAComplaints@inforegulator.org.za
Websitewww.inforegulator.org.za

19. Third-Party Websites and Embedded Content

19.1 The Website may contain links to external websites or embedded third-party content. Sethala does not control the independent privacy practices of those third parties.

19.2 A link, integration or embedded service does not mean that Sethala accepts responsibility for the third party’s independent Processing. Visitors should review the third party’s own privacy notice and terms before providing Personal Information to that service.

19.3 Cookies and similar technologies that may be associated with embedded website content are described in Sethala’s Cookie Notice.

20. Changes to this Notice

20.1 Sethala may update this Notice when its website, Services, technology, processing activities, business operations, service-provider arrangements or legal requirements change.

20.2 The current version will be published on the Sethala website and will state its effective or revision date. Where a material change affects platform Users, Sethala may bring the updated Notice to Users’ attention through the Services or other appropriate communication.

20.3 Sethala may require Users to acknowledge an updated Notice. An acknowledgement records that the Notice was made available and does not convert Processing that requires another lawful basis into consent.

21. Contact

Privacy, POPIA and Data Subject requestsadmin@sethala.com
General business enquiriesinfo@sethala.com
Telephone / Physical address+27 12 942 4000 / 4th Floor, Menlyn Corner, 87 Frikkie de Beer Street, Menlyn, Pretoria, 0181, South Africa
Information Officer / Deputy Information OfficerRolf Schurink / Berdina Schurink