Isango Enterprises ← Back to Isango Enterprises

POPIA Compliance Notice

Table of Contents

  1. Introduction
  2. Responsible Party
  3. Operators and Service Providers
  4. Eight POPIA Principles and Our Compliance
  5. Processing Limitation Principle
  6. Purpose Specification Principle
  7. Further Processing Principle
  8. Information Quality and Accuracy Principle
  9. Openness Principle
  10. Security Safeguards Principle
  11. Data Subject Participation Principle
  12. How to Request Access to Your Personal Information
  13. How to Request Correction of Your Personal Information
  14. How to Request Deletion of Your Personal Information
  15. How to Object to Processing
  16. Complaints Procedure
  17. Information Regulator
  18. Contact Details
  19. Document Review

1. INTRODUCTION

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary privacy and data protection legislation. POPIA establishes the rights of individuals (data subjects) regarding their personal information and imposes obligations on organizations (responsible parties) that process that information.

This POPIA Compliance Notice serves to:

(a) Formally confirm our status and responsibilities under POPIA as a Responsible Party;

(b) Outline the eight principles of POPIA and how we comply with each;

(c) Inform you of your rights as a data subject;

(d) Provide clear procedures for exercising your data subject rights;

(e) Explain how to lodge complaints about POPIA violations.

This Notice supplements our Privacy Policy (Document 1) and should be read in conjunction with it. Where there is any inconsistency, this Notice takes precedence on matters of POPIA compliance.

2. RESPONSIBLE PARTY

2.1 Our Status

Isango Enterprises (Pty) Ltd is the Responsible Party for personal information processing conducted through our Website and services.

A "Responsible Party" under POPIA means an entity that determines the purpose of and means for processing personal information. In practical terms, this means:

(a) We decide what personal information to collect;

(b) We decide why we collect it and how long we keep it;

(c) We decide who can access it within our organization;

(d) We decide whether to share it with third parties;

(e) We are accountable for compliance with POPIA.

2.2 Company Details

Particulars Details
Legal Name Isango Enterprises (Pty) Ltd
CIPC Registration Number 2026/472055/07
Type of Entity Private Company
Head Office 3 Connaught Avenue, Selborne, East London, Eastern Cape, 5201
Alternative Office Stand 7776, Roodekop Ext 011, Germiston, Gauteng, 1401
Website https://www.isangoenterprises.co.za
General Email info@isangoenterprises.co.za
Telephone +27 (0)87 801 2919

2.3 Information Officer

We have designated a senior officer responsible for overseeing POPIA compliance and serving as the primary contact for data subject requests:

Mr Kwakhanya Magutywa Information Officer Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919

3. OPERATORS AND SERVICE PROVIDERS

3.1 Definition of Operators

An "Operator" under POPIA is an entity that processes personal information on behalf of a Responsible Party and in accordance with the Responsible Party's instructions. Operators do not make decisions about processing; they simply process information according to our direction.

3.2 Our Operators and Service Providers

We use the following operators and service providers to process personal information on our behalf:

Category Service Provider Purpose Location
Web Hosting Axxess Website hosting and server management South Africa/International
Email Services Microsoft Outlook Email hosting and communication International
Analytics Google Analytics (Google Inc.) Website usage analysis International (USA)
CRM/Database Internal systems + Cloud platforms Customer relationship management South Africa/International
Payment Processing Banks (Nedbank) Payment receipt and processing South Africa
Accounting Software Cloud-based accounting system Financial records management International
Backup Services Third-party backup provider Data backup and recovery International
IT Support Contracted IT service provider Technical support and maintenance South Africa
Courier/Logistics Various delivery partners Order delivery (where applicable) South Africa

3.3 Operator Agreements

Each operator is bound by a written agreement that:

(a) Restricts their use of personal information to purposes specified by us;

(b) Requires them to implement appropriate security measures;

(c) Prohibits them from disclosing personal information to others;

(d) Requires return or deletion of personal information when services end;

(e) Allows us to audit their compliance;

(f) Complies with POPIA Section 20 (Processor Restrictions);

(g) Includes provisions for handling data breaches.

3.4 Sub-Processors

Some of our operators may use sub-processors (third parties they engage on our behalf). We do not authorize use of sub-processors without our prior written consent. Our agreements require that any sub-processor must:

(a) Be approved by us;

(b) Be bound by equivalent confidentiality and security obligations;

(c) Meet our data protection standards.

3.5 Your Right to Information About Processors

You have the right to know which operators and service providers we use to process your personal information. For details, contact our Information Officer at POPIA@isangoenterprises.co.za.

4. EIGHT POPIA PRINCIPLES AND OUR COMPLIANCE

POPIA establishes eight information protection principles that all Responsible Parties must comply with. Below we outline each principle and explain how Isango Enterprises complies with it.

5. PROCESSING LIMITATION PRINCIPLE

5.1 The Principle

The Processing Limitation Principle (POPIA Section 9) requires that personal information may be processed only if:

(a) One of the lawful grounds is satisfied — processing must be based on one of the lawful bases established in POPIA (such as your consent, contractual performance, legal obligation, or legitimate interest);

(b) The processing is not objectionable — the processing must not be manifestly excessive relative to the purpose, and must not otherwise be objectionable.

5.2 Our Compliance

We comply with the Processing Limitation Principle by:

(a) Documenting our lawful basis — For each type of processing we conduct, we have documented our lawful basis (consent, contractual necessity, legal obligation, or legitimate interest);

(b) Obtaining consent where required — We seek your explicit consent before processing personal information where consent is the lawful basis (e.g., for direct marketing or non-essential cookies);

(c) Limiting to necessary information — We collect only the minimum personal information necessary to fulfill our stated purposes;

(d) Assessing proportionality — We assess whether our processing is proportionate to our purpose and not manifestly excessive;

(e) Refusing unreasonable requests — We refuse to process information where the request would be objectionable (e.g., requests to profile you for undisclosed purposes);

(f) Reviewing our practices regularly — We periodically review our processing activities to ensure ongoing compliance.

5.3 Your Rights Under This Principle

You have the right to:

6. PURPOSE SPECIFICATION PRINCIPLE

6.1 The Principle

The Purpose Specification Principle (POPIA Section 10) requires that personal information must be collected for a specific, explicitly stated, and legitimate purpose. The purpose must be communicated to you when the information is collected.

6.2 Our Compliance

We comply with the Purpose Specification Principle by:

(a) Clearly stating purposes — When we collect your personal information, we explicitly inform you of the purposes for which we will use it (through this Notice, our Privacy Policy, and in-form disclosures);

(b) Limiting to stated purposes — We use personal information only for the purposes we have disclosed. We do not use your information for hidden or undisclosed purposes;

(c) Specific and legitimate purposes — Our purposes are specific (e.g., "to respond to your enquiry about catering services"), not vague (e.g., "for business purposes");

(d) Documented purposes — We maintain records documenting the purpose for each category of processing;

(e) No secondary use without authority — We do not use your information for purposes beyond those stated without your consent or a lawful basis.

6.3 Our Stated Purposes

We collect and process your personal information for the following specific purposes:

Primary Purposes: 1. To respond to your enquiry or request 2. To provide quotations and service proposals 3. To deliver services you have engaged 4. To invoice and process payment 5. To maintain records for compliance and accountability 6. To improve our website and services (analytics) 7. To send direct marketing communications (only with your consent)

Supporting Purposes: 8. To detect and prevent fraud or security threats 9. To comply with legal obligations (tax, audit, regulatory) 10. To enforce our terms and agreements 11. To protect our legal rights

6.4 Your Rights Under This Principle

You have the right to:

7. FURTHER PROCESSING PRINCIPLE

7.1 The Principle

The Further Processing Principle (POPIA Section 11) requires that if we want to use personal information for a purpose that is materially different from the purpose for which it was originally collected, we must obtain your consent or establish a new lawful basis.

In other words, we cannot simply collect information for one purpose and then use it for a completely different purpose without notifying you and obtaining consent or establishing another lawful basis.

7.2 What Constitutes "Further Processing"

Further processing occurs when we use information for a purpose that is:

(a) Materially different from the original purpose;

(b) Not reasonably contemplated by you when you provided the information;

(c) Not compatible with the original purpose;

(d) Incompatible with your reasonable expectations.

Examples of further processing:

Examples that are NOT further processing:

7.3 Our Compliance

We comply with the Further Processing Principle by:

(a) Checking compatibility — Before using personal information for a new purpose, we assess whether it is compatible with the original purpose and your reasonable expectations;

(b) Obtaining consent — Where further processing is not compatible, we seek your explicit consent before proceeding;

(c) Establishing lawful basis — If consent is not available, we establish another lawful basis (legal obligation, contractual necessity, or legitimate interest) before further processing;

(d) Notifying you — We inform you of any material change in how we use your information;

(e) Documented assessments — We maintain records of our compatibility assessments.

7.4 Examples of Our Compliance

Example 1 — Related Service Information

You enquire about our catering services. We provide a quotation and, if you don't respond, we may send you information about our supply & delivery services (which may be useful to the same organization). This is not further processing because it is reasonably related to the original enquiry.

Example 2 — Analytics

When you visit our Website, we collect analytics information. We use this to improve the Website's functionality. This is not further processing because analytics improvement is a purpose reasonably expected by website visitors.

Example 3 — Marketing

You enquire about electrical services. We respond to your enquiry. Later, we want to add you to our general marketing list to receive regular updates about all our services. This is further processing. We will seek your consent before doing this.

7.5 Your Rights Under This Principle

You have the right to:

8. INFORMATION QUALITY AND ACCURACY PRINCIPLE

8.1 The Principle

The Information Quality and Accuracy Principle (POPIA Section 12) requires that personal information must be:

(a) Accurate — correct and factually true;

(b) Complete — not misleading due to omissions;

(c) Up to date — current and not obsolete;

(d) Relevant — adequate and not excessive in relation to the purpose.

8.2 Our Compliance

We comply with the Information Quality and Accuracy Principle by:

(a) Accurate collection — We collect information directly from you (where possible) to ensure accuracy. We do not make assumptions or inferences;

(b) Verification practices — Where we collect information from other sources, we verify its accuracy before recording it;

(c) Update mechanisms — We provide you with opportunities to update your information (through contact forms, update requests, or direct communication);

(d) Correction procedures — We have a clear process for you to request correction of inaccurate information (see Section 13 below);

(e) Purging outdated data — We regularly review our records to identify and remove outdated or obsolete information;

(f) Proportionality — We collect only information that is relevant and adequate for our stated purposes, not excessive;

(g) Staff training — Our staff are trained on the importance of data accuracy.

8.3 Your Responsibility

You have a responsibility to:

8.4 Your Rights Under This Principle

You have the right to:

9. OPENNESS PRINCIPLE

9.1 The Principle

The Openness Principle (POPIA Section 13) requires that we must be transparent and open about our information practices. You must be able to:

(a) Know whether we hold personal information about you;

(b) Know what personal information we hold;

(c) Understand how we use that information;

(d) Understand our security measures;

(e) Know who has access to your information.

This principle is about transparency and preventing secret data practices.

9.2 Our Compliance

We comply with the Openness Principle by:

(a) Publishing this Notice — We publicly state our role as Responsible Party and our compliance practices;

(b) Privacy Policy — We have published a comprehensive Privacy Policy explaining our data practices in clear language;

(c) In-form disclosures — Our website forms include clear statements about what information we collect and how we use it;

(d) Accessible contact details — We provide clear contact information for data subject requests;

(e) Responding to access requests — We respond to requests for access to information we hold about you;

(f) Explaining our practices — We explain (in plain language) the purposes of processing, storage periods, and who has access;

(g) Information about processors — We disclose which service providers process your information;

(h) Breach notification — We notify you of security breaches affecting your information.

9.3 Access to Our Practices

Information about our data practices is available:

(a) On our Website: https://www.isangoenterprises.co.za (links to Privacy Policy and this Notice)

(b) In our forms: Disclosure statements appear on data collection forms

(c) Upon request: Contact our Information Officer for specific information about our practices

(d) In this Notice: This document explains our POPIA compliance

9.4 Your Rights Under This Principle

You have the right to:

10. SECURITY SAFEGUARDS PRINCIPLE

10.1 The Principle

The Security Safeguards Principle (POPIA Section 19) requires that we must implement appropriate technical and organizational security measures to protect personal information against:

(a) Unauthorized access — preventing unauthorized people from accessing your information;

(b) Unauthorized modification — preventing unauthorized changes to your information;

(c) Unlawful destruction — preventing unauthorized or accidental loss of your information;

(d) Loss and damage — protecting against damage or loss through negligence.

Security measures must be proportionate to: - The sensitivity of the personal information - The likelihood and severity of potential harms - The state of technological development - Industry best practices

10.2 Our Security Measures

We have implemented the following security measures:

Technical Safeguards:

(a) Encryption: - HTTPS encryption for data transmitted between your browser and our servers - Encryption of sensitive data at rest (in storage) - Encrypted backups

(b) Access Controls: - Role-based access to personal information - Password authentication for staff - Multi-factor authentication where available - Audit logs tracking who accessed what information

(c) Firewalls and Network Security: - Firewalls protecting our networks - Intrusion detection systems - Regular security scanning

(d) System Maintenance: - Regular security updates and patches - Vulnerability assessments - Penetration testing

(e) Backup and Recovery: - Regular automated backups - Secure backup storage - Tested recovery procedures

Organizational Safeguards:

(a) Staff Training: - Data protection training for all staff - Confidentiality obligations - Security awareness programs

(b) Access Policies: - Need-to-know principle (staff access only what they need) - Segregation of duties - Monitoring of access patterns

(c) Confidentiality Agreements: - Written confidentiality obligations for all staff - Confidentiality clauses in service provider agreements

(d) Physical Security: - Secure office locations - Access restrictions to areas containing personal information - Secure disposal of documents containing personal information

(e) Incident Response: - Security breach detection procedures - Incident response plan - Breach notification procedures - Regular reviews and testing of incident response

(f) Third-Party Security: - Security requirements in service provider agreements - Audit rights to verify security measures - Due diligence on new service providers

10.3 Limitations of Security

While we implement comprehensive security measures, we acknowledge that:

(a) No security system is completely impenetrable;

(b) The Internet is not a completely secure medium;

(c) There is always some risk that information transmitted electronically could be intercepted;

(d) You have a responsibility to protect your own devices and passwords.

10.4 Data Breach Notification

If a security breach occurs that compromises your personal information, we will:

(a) Investigate the breach to determine scope and impact;

(b) Notify you without unreasonable delay where the breach poses a high risk to your rights and interests;

(c) Notify the Information Regulator where required;

(d) Take corrective action to remediate the breach and prevent recurrence.

Breach notifications will include: - Nature of the breach - Personal information compromised - Likely consequences for you - Steps we are taking in response - Your contact for further information

10.5 Your Rights Under This Principle

You have the right to:

11. DATA SUBJECT PARTICIPATION PRINCIPLE

11.1 The Principle

The Data Subject Participation Principle (POPIA Section 14-18) recognizes your fundamental rights regarding your personal information. You have the right to:

(a) Access — know what personal information we hold about you;

(b) Correct — request that inaccurate information be corrected;

(c) Delete — request deletion in certain circumstances;

(d) Object — object to certain types of processing;

(e) Restrict — restrict processing while a request is investigated.

These rights are detailed in Sections 12-15 below.

11.2 Exercising Your Rights

You may exercise your data subject rights:

(a) In writing — by emailing or posting your request to our Information Officer;

(b) Free of charge — we will not charge you a fee (except in exceptional circumstances);

(c) Promptly — we will respond within 30 days (60 days in complex cases);

(d) With assistance — if you need assistance exercising your rights, contact us for help.

12. HOW TO REQUEST ACCESS TO YOUR PERSONAL INFORMATION

12.1 Your Right

You have the right to request access to personal information we hold about you. This is called an "access request" or "POPIA Section 14 request."

12.2 What You Will Receive

If we grant your access request, we will provide:

(a) Confirmation of whether we process your personal information;

(b) The personal information we hold about you;

(c) The categories of personal information we hold;

(d) Why we are processing it (the purpose);

(e) Who we may have disclosed it to;

(f) How long we will retain it;

(g) Your rights regarding the information.

12.3 How to Submit an Access Request

Submit your request in writing to:

Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa

Your request must include:

(a) Your full name;

(b) Your contact details (email and/or telephone);

(c) Clear description of the personal information you are requesting;

(d) Reasons for your request (optional but helpful);

(e) Your preferred format for receiving the information (e.g., email, printed document);

(f) Copy of your identification document (to verify your identity).

12.4 Our Response Process

Step 1 — Acknowledgment (within 5 business days)

We will acknowledge receipt of your request and confirm that we have understood what you are requesting.

Step 2 — Verification (within 5 business days)

We will verify your identity by checking your identification document. This is to protect your privacy and ensure we do not disclose your information to someone impersonating you.

Step 3 — Search and Compilation (within 15-25 business days)

We will search our systems for all personal information relating to you and compile it in an accessible format.

Step 4 — Disclosure (within 30 days)

We will provide you with the personal information in the format you requested. We will also include an explanation of what the information means (if necessary) and information about your other rights.

12.5 Extensions

If we cannot comply within 30 days due to complexity or volume, we will:

(a) Notify you before the 30-day deadline;

(b) Explain the reasons for the delay;

(c) Provide a revised timeframe (not exceeding 60 days total);

(d) Keep you updated on progress.

12.6 Possible Refusals or Limitations

We may refuse or limit your access request in the following circumstances:

(a) Identity Verification — If you cannot verify your identity, we may refuse to disclose information;

(b) Third-Party Information — If the information relates to other people, we may redact their names and contact details to protect their privacy;

(c) Privileged Information — If the information is subject to legal privilege (e.g., attorney-client communications), we may refuse to disclose it;

(d) Trade Secrets — If the information contains our trade secrets or confidential business information, we may refuse or limit disclosure;

(e) Ongoing Investigations — If disclosing the information would interfere with an ongoing investigation (internal or law enforcement), we may refuse or delay disclosure;

(f) No Information Held — If we do not hold personal information about you, we will notify you.

If we refuse your request, we will provide written reasons for the refusal and inform you of your right to complain to the Information Regulator.

12.7 Format of Disclosure

We will provide the information in a format accessible to you:

(a) Electronic Format — By email (PDF or other commonly used format);

(b) Printed Format — By post to your address (if requested);

(c) Accessible Format — If you have accessibility needs, we will provide information in an accessible format (e.g., large print, audio format).

12.8 Cost

No Fee — We provide access to your personal information at no cost. You will not be charged a fee for:

(a) Reviewing and compiling the information;

(b) Providing copies (electronic or printed);

(c) Explaining the information.

Exceptional Cases — In exceptional circumstances where your request is excessive or manifestly unfounded, we may charge a reasonable fee covering our costs. We will notify you of any fee before proceeding and discuss the amount.

12.9 Your Appeal

If we refuse your access request, you have the right to:

(a) Request written reasons for the refusal;

(b) Request an internal review of the refusal (we will reconsider);

(c) Lodge a complaint with the Information Regulator;

(d) Seek legal advice.

13. HOW TO REQUEST CORRECTION OF YOUR PERSONAL INFORMATION

13.1 Your Right

You have the right to request correction of personal information about you that is inaccurate, incomplete, misleading, or outdated. This is called a "correction request" or "POPIA Section 15 request."

13.2 What We Will Do

If we agree your information is inaccurate or incomplete, we will:

(a) Correct the information — update our records with accurate information;

(b) Notify third parties — where practicable, notify third parties (including service providers) to whom we disclosed the incorrect information, so they can correct their records;

(c) Confirm the correction — notify you that the correction has been made;

(d) Document the request — maintain a record of the correction request and our action.

13.3 How to Submit a Correction Request

Submit your request in writing to:

Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa

Your request must include:

(a) Your full name and contact details;

(b) Identification of the specific information you believe is inaccurate or incomplete;

(c) Description of why you believe it is inaccurate (e.g., "My email address is no longer valid; the correct address is...");

(d) The correct or updated information;

(e) Supporting evidence (if any) demonstrating the inaccuracy;

(f) Copy of your identification document.

13.4 Our Response Process

Step 1 — Acknowledgment (within 5 business days)

We will acknowledge receipt and confirm that we understand your correction request.

Step 2 — Investigation (within 15-25 business days)

We will investigate your claim by:

(a) Reviewing the information in question;

(b) Checking our records and any source documents;

(c) Considering any evidence you have provided;

(d) Assessing whether the information is inaccurate or incomplete.

Step 3 — Decision (within 30 days)

We will make a decision and notify you:

(a) If we agree — We will confirm that we have corrected the information and notify third parties where relevant.

(b) If we disagree — We will explain why we believe the information is accurate and provide you with your options (see below).

13.5 If We Disagree with Your Correction Request

If we believe the information is accurate and refuse to correct it, we will:

(a) Provide written reasons for our refusal;

(b) Offer you the right to make a statement explaining your position;

(c) If you make a statement, we will add it to our records and disclose it along with the information if we disclose it to third parties;

(d) Inform you of your right to lodge a complaint with the Information Regulator.

13.6 Correction Requests We May Refuse

We may refuse to correct information in limited circumstances:

(a) Accurate Information — If we reasonably believe the information is accurate;

(b) Not Our Information — If the information does not relate to you or was not collected by us;

(c) Privileged Information — If the information is subject to legal privilege;

(d) Legal Obligation — If we are required by law to retain the information in its current form.

13.7 Cost

No Fee — We correct information at no cost to you.

13.8 Your Rights if We Refuse

If we refuse your correction request, you have the right to:

(a) Make a formal statement disputing the information;

(b) Request that we add your statement to our records;

(c) Request an internal review (we will reconsider our decision);

(d) Lodge a complaint with the Information Regulator.

14. HOW TO REQUEST DELETION OF YOUR PERSONAL INFORMATION

14.1 Your Right

You have the right to request deletion of personal information about you in certain circumstances. This is called a "deletion request" or "POPIA Section 16 request."

14.2 When You Can Request Deletion

You can request deletion in the following circumstances:

(a) No Longer Necessary — The information is no longer necessary for the purpose it was collected;

(b) Consent Withdrawn — You have withdrawn consent, and consent was the lawful basis for processing;

(c) Unlawful Processing — The information was collected or processed unlawfully;

(d) Outdated — The information is outdated or obsolete;

(e) Right to Be Forgotten — Your request is based on POPIA Section 16 rights;

(f) Legal Obligation — You are required by law to have the information deleted.

Example scenarios where deletion may be appropriate:

14.3 How to Submit a Deletion Request

Submit your request in writing to:

Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa

Your request must include:

(a) Your full name and contact details;

(b) Specific identification of the information you want deleted;

(c) Reasons for the deletion request (explaining which circumstance applies);

(d) Supporting evidence (if any);

(e) Copy of your identification document.

14.4 Our Response Process

Step 1 — Acknowledgment (within 5 business days)

We will acknowledge receipt of your deletion request.

Step 2 — Assessment (within 15-25 business days)

We will assess whether:

(a) We actually hold the information;

(b) Your deletion request is valid;

(c) We have a lawful reason to retain the information.

Step 3 — Decision (within 30 days)

We will notify you of our decision:

(a) If we agree — We will delete the information and confirm deletion to you.

(b) If we refuse — We will explain our reasons and your appeal options.

14.5 When We May Refuse Deletion

We may refuse to delete information in the following circumstances:

(a) Legal Obligation — We are required by law to retain the information (e.g., tax records must be kept for 7 years under tax law);

(b) Legitimate Interest — Deletion would interfere with our legitimate legal or business interests (e.g., records necessary for dispute resolution);

(c) Contract — The information is necessary to perform a contract with you;

(d) Public Interest — Deletion would interfere with the public interest or official authority functions;

(e) Rights of Others — Deletion would interfere with the rights of other individuals.

Common reasons we may retain information despite deletion requests:

14.6 Partial Deletion

In some cases, we may delete some information but retain other information:

Example: You request deletion of your entire file. However: - Your name and contact details may be retained in a "do not contact" list - Your payment history may be retained for tax compliance - Records of services delivered may be retained for warranty purposes

We will explain which information we are deleting and which we are retaining, and why.

14.7 Notification of Third Parties

If we delete your information, we will:

(a) Notify service providers and third parties (where practicable) that information about you should be deleted;

(b) Note that we cannot guarantee third parties will comply, as they are bound by their own retention obligations;

(c) Inform you that backup copies may retain the information for a limited period (but will be deleted once backups are rotated).

14.8 Cost

No Fee — We delete information at no cost to you.

14.9 Consequences of Deletion

You should be aware that deletion of personal information may:

(a) Make it impossible for us to provide future services to you;

(b) Result in loss of any active customer status or relationship history;

(c) Require you to re-provide information if you engage with us again;

(d) Affect our ability to respond to your enquiries if we have deleted your contact details.

14.10 Your Rights if We Refuse

If we refuse your deletion request, you have the right to:

(a) Request written reasons for the refusal;

(b) Request an internal review (we will reconsider);

(c) Lodge a complaint with the Information Regulator;

(d) Seek legal advice or court intervention if necessary.

15. HOW TO OBJECT TO PROCESSING

15.1 Your Right

You have the right to object to processing of your personal information in certain circumstances. This is called an "objection" or "POPIA Section 17 request."

15.2 When You Can Object

You can object to processing in the following circumstances:

(a) Legitimate Interest Processing — We are processing your information based on our legitimate interest, and you believe our interest does not outweigh your privacy rights;

(b) Direct Marketing — We are using your information for direct marketing purposes (marketing emails, SMS, phone calls, etc.);

(c) Profiling and Automated Decision-Making — We are using your information for automated profiling or decision-making that produces legal or similarly significant effects;

(d) Historical Processing — You are objecting to processing that occurred in the past.

15.3 Effect of an Objection

If you object to processing, we will:

(a) Stop the processing (if we agree your objection is valid);

(b) Assess the objection — evaluate whether our processing can continue on another lawful basis;

(c) Notify you — inform you whether we will cease or continue processing, and why.

15.4 How to Submit an Objection

Submit your objection in writing to:

Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa

Your objection must include:

(a) Your full name and contact details;

(b) Clear description of the processing you are objecting to;

(c) Specific grounds for your objection (which circumstance applies);

(d) Explanation of why you believe the processing should cease;

(e) What action you want us to take (e.g., stop direct marketing, stop profiling, etc.);

(f) Copy of your identification document.

15.5 Our Response Process

Step 1 — Acknowledgment (within 5 business days)

We will acknowledge receipt and confirm we understand your objection.

Step 2 — Investigation (within 15-25 business days)

We will:

(a) Review the processing you are objecting to;

(b) Assess the validity of your objection;

(c) Determine if we have another lawful basis to continue processing.

Step 3 — Decision (within 30 days)

We will notify you:

(a) If we uphold your objection — We will cease the processing and confirm cessation to you.

(b) If we overrule your objection — We will explain why we believe the processing should continue and our reasons.

15.6 Objections to Direct Marketing

Special Rule for Direct Marketing: If you object to direct marketing, we must cease that processing. We do not have the option to continue direct marketing based on another lawful basis.

How to Object to Direct Marketing:

The easiest way is to:

(a) Click "Unsubscribe" in any marketing email we send you;

(b) Reply "STOP" to any SMS we send;

(c) Request removal when we call;

(d) Contact us directly (as per details above).

We will remove you from our direct marketing lists within 10 business days.

15.7 Objections to Legitimate Interest Processing

If you object to processing based on our legitimate interest (e.g., analytics, fraud prevention), we will:

(a) Assess whether your objection is based on reasonable grounds;

(b) Balance your privacy rights against our legitimate interests;

(c) Determine if we can continue processing on another lawful basis (e.g., contractual necessity, legal obligation);

(d) Inform you of our decision and reasons.

Example: You object to Google Analytics on the basis that you don't want your browsing tracked. We will consider your objection. If we determine that analytics is important for website improvement, we might continue collecting analytics data on the basis of legitimate interest, provided it is proportionate and we have implemented appropriate safeguards.

15.8 Cost

No Fee — We process objections at no cost to you.

15.9 Your Rights if We Overrule Your Objection

If we overrule your objection, you have the right to:

(a) Request detailed reasons in writing;

(b) Request an internal review (we will reconsider);

(c) Lodge a complaint with the Information Regulator;

(d) Seek legal advice or court intervention if necessary.

16. COMPLAINTS PROCEDURE

16.1 Our Internal Complaints Process

If you believe we have violated your privacy rights under POPIA, we encourage you to contact us to try to resolve the matter informally before escalating to the Information Regulator.

16.2 How to Lodge an Internal Complaint

Step 1 — Submit Your Complaint

Write to:

Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa

Your complaint should include:

(a) Your full name and contact details;

(b) Clear description of the alleged POPIA violation;

(c) Specific details: - What personal information is involved? - How have we violated POPIA? - What section(s) of POPIA do you believe we have breached?

(d) What outcome are you seeking? (e.g., correction of information, deletion, cessation of processing, compensation);

(e) Copies of any relevant evidence or documentation;

(f) Dates when the alleged violation occurred.

Step 2 — Our Acknowledgment

We will acknowledge receipt of your complaint within 5 business days and provide:

(a) A reference number for your complaint;

(b) Confirmation of what we understand the complaint to be;

(c) Outline of our investigation process;

(d) Expected timeframe for our response.

Step 3 — Our Investigation

We will investigate your complaint thoroughly:

(a) Review the facts and circumstances;

(b) Gather evidence from our systems and staff;

(c) Assess whether POPIA has been breached;

(d) Determine appropriate remedial action (if necessary).

Step 4 — Our Response

Within 30 days of receipt, we will provide you with:

(a) If your complaint is upheld — A detailed explanation of the breach, corrective action we will take, and how we will prevent recurrence.

(b) If your complaint is not upheld — A detailed explanation of why we do not believe we have breached POPIA, with reference to relevant legislation and facts.

(c) If the matter is complex — A revised timeframe (not exceeding 60 days) if we need more time to investigate.

16.3 Remedies We May Offer

If we uphold your complaint, we may:

(a) Correct your information — Update inaccurate or incomplete information;

(b) Delete your information — Remove personal information from our systems;

(c) Cease processing — Stop processing your information for a specified purpose;

(d) Security improvements — Enhance our security measures to prevent recurrence;

(e) Compensation — In some cases, provide compensation for harm you have suffered (we will discuss this with you).

16.4 Your Right to Escalate

If you are dissatisfied with our response to your complaint, you have the right to escalate to the Information Regulator (see Section 17 below).

17. INFORMATION REGULATOR

17.1 What Is the Information Regulator?

The Information Regulator (officially the "South African Human Rights Commission — Information Regulator") is an independent office established under POPIA to:

(a) Oversee compliance with POPIA across South Africa;

(b) Investigate complaints about POPIA violations;

(c) Enforce data protection rights;

(d) Issue compliance orders;

(e) Impose administrative fines;

(f) Provide guidance and education about POPIA.

17.2 When to Contact the Information Regulator

You may lodge a complaint with the Information Regulator if:

(a) You have contacted us about a POPIA violation and are dissatisfied with our response;

(b) We have refused to grant your data subject rights without valid reason;

(c) You believe we have committed a serious or persistent breach of POPIA;

(d) We have failed to notify you of a security breach;

(e) You wish to report us for non-compliance with POPIA.

17.3 How to Lodge a Complaint with the Information Regulator

Contact Details:

Information Regulator South African Human Rights Commission Private Bag X2700 Houghton 2041 South Africa

Telephone: +27 (0)10 023 0911 Email: complaint.IR@sahrc.org.za Website: https://www.justice.gov.za/inforeg/

To Lodge a Formal Complaint:

(a) Obtain the Complaint Form — Download the POPIA complaint form from the Information Regulator's website or request one via email;

(b) Complete the Form — Provide: - Your full name and contact details - Name of the organization you are complaining about (Isango Enterprises (Pty) Ltd) - Clear description of the alleged violation - Evidence supporting your complaint - Details of any attempts to resolve the matter with us - The outcome you are seeking

(c) Pay the Complaint Fee — South African residents must pay a fee (currently R100; fees may vary for international complainants). Include proof of payment.

(d) Submit the Complaint — Submit the completed form with supporting documents and proof of payment to the Information Regulator.

17.4 What the Information Regulator Can Do

The Information Regulator has significant powers to:

(a) Investigate — Conduct a formal investigation into your complaint;

(b) Request Information — Require us to provide information and documentation;

(c) Audit — Conduct compliance audits of our data protection practices;

(d) Conciliation — Facilitate settlement between you and us;

(e) Issue Orders — Issue binding compliance orders requiring us to take specific action;

(f) Impose Fines — Impose administrative fines (up to 10% of our annual turnover for serious breaches);

(g) Refer to Police — In cases of criminal conduct, refer matters to law enforcement;

(h) Appeal — Review decisions on appeal.

17.5 Outcomes of an Information Regulator Investigation

Possible outcomes include:

(a) Complaint Dismissed — The Information Regulator finds no breach of POPIA;

(b) Settlement — We agree to resolve the matter (e.g., correct information, provide compensation);

(c) Compliance Order — The Information Regulator orders us to take specific corrective action;

(d) Administrative Fine — We are required to pay a financial penalty;

(e) Escalation — In serious cases, referral to law enforcement or courts.

17.6 Your Rights During an Investigation

While the Information Regulator investigates:

(a) You have the right to participate in the process;

(b) You can submit additional evidence or information;

(c) You can request updates on progress;

(d) You have the right to appeal any decision;

(e) You can request legal representation.

18. CONTACT DETAILS

18.1 Data Subject Requests and Complaints

For any data subject requests, POPIA-related inquiries, or complaints:

Mr Kwakhanya Magutywa Information Officer Isango Enterprises (Pty) Ltd

Email: POPIA@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Postal Address: 3 Connaught Avenue Selborne East London Eastern Cape 5201 South Africa

18.2 Alternative Contact

For general enquiries:

Isango Enterprises (Pty) Ltd General Inquiries

Email: info@isangoenterprises.co.za Telephone: +27 (0)87 801 2919 Website: https://www.isangoenterprises.co.za

18.3 Response Commitments

We commit to:

(a) Acknowledging all requests and complaints within 5 business days;

(b) Providing substantive responses within 30 days (60 days for complex matters);

(c) Treating all communications respectfully and professionally;

(d) Providing clear explanations for any refusals or limitations;

(e) Assisting you in understanding your rights.

19. DOCUMENT REVIEW

This POPIA Compliance Notice will be reviewed and updated:

(a) Annually — Each year on 19 July 2027 and thereafter;

(b) Upon Regulatory Change — If POPIA regulations or Information Regulator guidance changes;

(c) Upon Operational Change — If our data processing practices materially change;

(d) Upon Request — If you or a data subject raises concerns about accuracy or completeness.

Version Control:

Version Date Changes
1.0 19 July 2026 Initial publication-ready version