<img src="https://secure.leadforensics.com/85165.png" alt="" style="display:none;">
Skip to content
Everything your engagement programme runs on, in one system, from register to report.
Every feature, mapped to how a South African participation process actually runs.
Log grievances, track issues and commitments, and report them by type.
ISO 27001, Cyber Essentials Plus, and a straight answer on POPIA, hosting and cross-border transfer.
Run comment windows and surveys, with every response held against the person who made it.
150+ pre-built reports and dashboards, including the comments and responses report.
A named Client Success Manager, unlimited support, and a four to six week implementation.
Map interested and affected parties against the categories the law actually names.
The public side of the process: documents, comments and self-registration, priced separately.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Social and labour plan consultation, mine communities, traditional councils, informal rights.
IDP and budget participation, ward committees, and the duty to report back.
Licence participation and a register you keep during processing and for two years after.
Transmission corridors, renewables and community trusts, across project lives measured in decades.
Corridor-scale engagement across rail, ports and third-party network access.
Run every client project from one system, with the evidence pack ready when the authority asks.
The EIA Regulations mapped to the system, from first notice to comments and responses report.
Notice, representations and reasons, recorded well enough to survive a PAJA review.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Read our customer success stories and discover how our clients are delivering impact with Tractivity.
The step-by-step guide to building an effective stakeholder engagement plan, with template.
Views and insights from engagement experts, recorded at our events and free to watch.
Helpful tips, guides and articles about stakeholder engagement, project management and more.
Learn how to identify, categorise and prioritise your stakeholders with our complete guide.
Empower sustainable engagement with AccountAbility's framework and Tractivity's system.
Free guides, whitepapers, templates and more to help you deliver sustainable outcomes.
Understand your stakeholders' needs, interests and influence with our practical framework.
What POPIA means for a register of interested and affected parties, answered in full.
 dropdown-demo-2 
Learn why leading organisations trust Tractivity.
Rate your organisation across five categories in minutes and get an instant, tailored score.
Calculate the time your team loses to manual admin into a defensible number for the board.
What POPIA means for a register of interested and affected parties, answered in full.
A six-part toolkit for planning, running and documenting your stakeholder engagement.
The legal test for fair public participation, and a self-audit to find where yours is weak.
Free, practical resources for managing engagement and running public participation well.
You’re the expert. We’re the software, and the home of stakeholder engagement.
dropdown-demo-2
Learn why leading organisations trust Tractivity.
Our annual Stakeholder Engagement Day, held in the United Kingdom and open to anyone working in engagement.
The 2026 event is coming soon. Held in the United Kingdom, with sessions worth watching wherever you are.
Talks and presentations from the 2025 event, free to watch online.
Keynotes and real-world case studies from the 2024 summit, online.
Sessions and insights from our first live event, online.

Privacy and POPIA

This page sits alongside our United Kingdom privacy policy and answers the South African questions it does not: what POPIA means for the data you give us, what it means for the stakeholder data we hold on your behalf, and who to write to.

 

Two different relationships, and they are not the same

When you fill in a form on this site or book a demonstration, you give us your own contact details and we decide what to do with them. That is one relationship.

When you become a client and load your register of interested and affected parties into the platform, you decide what is collected, why, and how long it is kept. We process it on your instruction. In POPIA's language you are the responsible party and we are the operator. That is a different relationship with different duties, and conflating the two is the most common mistake in a security questionnaire answer.

 

Where we sit under POPIA

Tractivity is a United Kingdom company with no South African entity, office or staff, and the platform runs on Microsoft Azure with the United Kingdom as the default region. Section 3 applies the Act to a responsible party domiciled in the Republic, or to one that is not domiciled there but makes use of automated or non-automated means in the Republic. On that reading we are not a South African responsible party for the data we collect through this site.

We would rather tell you that than let you assume otherwise, and it changes nothing about how we behave. The eight conditions in Chapter 3 of POPIA and the UK GDPR obligations we are already subject to ask for substantially the same things, and we apply them to South African enquirers exactly as we do to British ones.

 

What we collect when you contact us

Name, organisation, role, email address, telephone number where you give it, and whatever you tell us about your project. We use it to answer you, to prepare a demonstration and, where you have agreed to it, to send you material about stakeholder engagement. You can tell us to stop at any time and we will, on that occasion and on every occasion after it.

We do not sell it, we do not share it with a third party for their own marketing, and we do not enrich it from a data broker. If you ask us what we hold about you, we will tell you, and we will correct or delete it.

 

When we hold your stakeholder data

Sections 20 and 21 of POPIA require the relationship between a responsible party and an operator to be governed by a written contract, and require the operator to notify the responsible party of a security compromise immediately. We will sign a written agreement covering both, and we will answer a questionnaire on it in writing rather than pointing you at a policy page.

One question in this area we have not finished answering, and we say so here rather than implying otherwise: whether the agreement should be a POPIA specific operator agreement or our standard data processing agreement, and what breach notification window we commit to in hours. Ask, and you will get the current position in writing, including the notification window, before you sign anything. Our wider position is on the security and compliance page.

 

Cross-border transfer

Section 72 has no adequacy mechanism. The Information Regulator has designated no jurisdictions and issued no adequacy guidance, so a transfer out of South Africa rests on a law, on binding corporate rules, or on a binding agreement providing protection substantially similar to POPIA, including onward transfer provisions. It is built case by case, in the contract.

In practice the default hosting region is the United Kingdom, and European, United States and other regions are available. POPIA does not require local hosting. The National Policy on Data and Cloud and most public sector and state owned enterprise tenders increasingly do, so raise residency early in a procurement rather than at contract stage.

Section 57 requires prior authorisation from the Regulator to transfer special personal information or children's information to a country without adequate protection. Special personal information is prohibited by default under sections 26 to 33 and includes race or ethnic origin, political persuasion and trade union membership, all three of which South African engagement practice routinely records. If your programme records any of them, that is a conversation to have before data moves. POPIA and stakeholder data covers it in full.

 

Information Officer and access to information

POPIA requires the Information Officer of a South African body to be registered with the Regulator, and section 51 of PAIA requires a private body to have a manual. We have no South African registration and we have not established that either obligation applies to a company in our position, so we will not claim a registered Information Officer or publish a manual we have not written.

What we will do is name a person. Data questions about this site, about an enquiry you have made, or about a client deployment go to Mark Rutter, Director, at mark.rutter@tractivity.co.uk, and we will answer them or tell you plainly that we cannot. If your procurement process requires a registered Information Officer on the supplier side, tell us at the bid stage rather than at contract stage, because the answer may be a South African partner rather than a form.

 

The rest of it

Our full privacy policy, cookie policy and accessibility statement apply to this site and are linked in the footer. The cookie policy describes the same cookies on the same site, and POPIA has no separate cookie consent regime, so there is no South African version to read. The accessibility statement sets out our WCAG position, which is the standard South African public bodies reference too.

 

Common questions

Are you POPIA compliant?

Where we act as an operator for a South African client we meet the operator duties in sections 20 and 21, under a written contract. We are not a South African responsible party for the data we collect through this site, and we say so rather than claiming a compliance badge that does not fit.

Do you have a registered Information Officer?

No. We have no South African registration and we have not established that the obligation applies to a company in our position. Data questions go to a named contact instead.

Do you have a PAIA manual?

No, for the same reason. If a bid requires one, raise it early rather than at contract stage.

Can our data stay in South Africa?

Hosting regions are configurable. The default is the United Kingdom, and POPIA does not require local hosting, though most public sector and state owned enterprise tenders increasingly ask about it.

Will you sign an operator agreement?

Yes, and we will answer a questionnaire on it in writing. The choice between a POPIA specific agreement and our standard data processing agreement, and the breach notification window, are not settled yet, and we will tell you the current position before you sign.

Do you use our stakeholder data to train AI models?

No. AI features run in Microsoft Azure in the United Kingdom region, no customer data is used to train models, and every AI feature is switched off by default and activated only with your consent.

 

Send us the questionnaire

If you are working through a security or POPIA questionnaire, send it. We answer in writing, we say where we are not settled, and we do not fill a box with a claim we cannot support. Contact us, or read our security and compliance position first.