Privacy and POPIA
This page sits alongside our United Kingdom privacy policy and answers the South African questions it does not: what POPIA means for the data you give us, what it means for the stakeholder data we hold on your behalf, and who to write to.
Two different relationships, and they are not the same
When you fill in a form on this site or book a demonstration, you give us your own contact details and we decide what to do with them. That is one relationship.
When you become a client and load your register of interested and affected parties into the platform, you decide what is collected, why, and how long it is kept. We process it on your instruction. In POPIA's language you are the responsible party and we are the operator. That is a different relationship with different duties, and conflating the two is the most common mistake in a security questionnaire answer.
Where we sit under POPIA
Tractivity is a United Kingdom company with no South African entity, office or staff, and the platform runs on Microsoft Azure with the United Kingdom as the default region. Section 3 applies the Act to a responsible party domiciled in the Republic, or to one that is not domiciled there but makes use of automated or non-automated means in the Republic. On that reading we are not a South African responsible party for the data we collect through this site.
We would rather tell you that than let you assume otherwise, and it changes nothing about how we behave. The eight conditions in Chapter 3 of POPIA and the UK GDPR obligations we are already subject to ask for substantially the same things, and we apply them to South African enquirers exactly as we do to British ones.
What we collect when you contact us
Name, organisation, role, email address, telephone number where you give it, and whatever you tell us about your project. We use it to answer you, to prepare a demonstration and, where you have agreed to it, to send you material about stakeholder engagement. You can tell us to stop at any time and we will, on that occasion and on every occasion after it.
We do not sell it, we do not share it with a third party for their own marketing, and we do not enrich it from a data broker. If you ask us what we hold about you, we will tell you, and we will correct or delete it.
When we hold your stakeholder data
Sections 20 and 21 of POPIA require the relationship between a responsible party and an operator to be governed by a written contract, and require the operator to notify the responsible party of a security compromise immediately. We will sign a written agreement covering both, and we will answer a questionnaire on it in writing rather than pointing you at a policy page.
One question in this area we have not finished answering, and we say so here rather than implying otherwise: whether the agreement should be a POPIA specific operator agreement or our standard data processing agreement, and what breach notification window we commit to in hours. Ask, and you will get the current position in writing, including the notification window, before you sign anything. Our wider position is on the security and compliance page.
Cross-border transfer
Section 72 has no adequacy mechanism. The Information Regulator has designated no jurisdictions and issued no adequacy guidance, so a transfer out of South Africa rests on a law, on binding corporate rules, or on a binding agreement providing protection substantially similar to POPIA, including onward transfer provisions. It is built case by case, in the contract.
In practice the default hosting region is the United Kingdom, and European, United States and other regions are available. POPIA does not require local hosting. The National Policy on Data and Cloud and most public sector and state owned enterprise tenders increasingly do, so raise residency early in a procurement rather than at contract stage.
Section 57 requires prior authorisation from the Regulator to transfer special personal information or children's information to a country without adequate protection. Special personal information is prohibited by default under sections 26 to 33 and includes race or ethnic origin, political persuasion and trade union membership, all three of which South African engagement practice routinely records. If your programme records any of them, that is a conversation to have before data moves. POPIA and stakeholder data covers it in full.
Information Officer and access to information
POPIA requires the Information Officer of a South African body to be registered with the Regulator, and section 51 of PAIA requires a private body to have a manual. We have no South African registration and we have not established that either obligation applies to a company in our position, so we will not claim a registered Information Officer or publish a manual we have not written.
What we will do is name a person. Data questions about this site, about an enquiry you have made, or about a client deployment go to Mark Rutter, Director, at mark.rutter@tractivity.co.uk, and we will answer them or tell you plainly that we cannot. If your procurement process requires a registered Information Officer on the supplier side, tell us at the bid stage rather than at contract stage, because the answer may be a South African partner rather than a form.
The rest of it
Our full privacy policy, cookie policy and accessibility statement apply to this site and are linked in the footer. The cookie policy describes the same cookies on the same site, and POPIA has no separate cookie consent regime, so there is no South African version to read. The accessibility statement sets out our WCAG position, which is the standard South African public bodies reference too.
Common questions
Are you POPIA compliant?
Where we act as an operator for a South African client we meet the operator duties in sections 20 and 21, under a written contract. We are not a South African responsible party for the data we collect through this site, and we say so rather than claiming a compliance badge that does not fit.
Do you have a registered Information Officer?
No. We have no South African registration and we have not established that the obligation applies to a company in our position. Data questions go to a named contact instead.
Do you have a PAIA manual?
No, for the same reason. If a bid requires one, raise it early rather than at contract stage.
Can our data stay in South Africa?
Hosting regions are configurable. The default is the United Kingdom, and POPIA does not require local hosting, though most public sector and state owned enterprise tenders increasingly ask about it.
Will you sign an operator agreement?
Yes, and we will answer a questionnaire on it in writing. The choice between a POPIA specific agreement and our standard data processing agreement, and the breach notification window, are not settled yet, and we will tell you the current position before you sign.
Do you use our stakeholder data to train AI models?
No. AI features run in Microsoft Azure in the United Kingdom region, no customer data is used to train models, and every AI feature is switched off by default and activated only with your consent.
Send us the questionnaire
If you are working through a security or POPIA questionnaire, send it. We answer in writing, we say where we are not settled, and we do not fill a box with a claim we cannot support. Contact us, or read our security and compliance position first.