Privacy Policy
How LANTEK Computers CC collects, uses, stores and protects personal information, written for South African law rather than adapted from European boilerplate.
Not yet approved for publication
This is a working draft written to the correct POPIA structure. It is not legal advice and must be reviewed and signed off before the site goes live. Highlighted items need real values from LANTEK. A firm selling compliance cannot afford a privacy policy that has not been checked.
1. Who we are
LANTEK Computers CC, registration number CIPC registration number to confirm, trading as LANTEK Computers, is the responsible party for the personal information described in this policy. Our registered address is Suite 15, Second Floor, Warne House, 7 Garlicke Drive, Ballito, 4420, South Africa.
2. The law this policy follows
This policy is written for the Protection of Personal Information Act 4 of 2013, referred to as POPIA. Where we refer to personal information, we mean it as POPIA defines it. This policy also supports our obligations under the Promotion of Access to Information Act 2 of 2000, referred to as PAIA, and our PAIA manual sets out how to request access to a record.
3. What we collect, and why
We collect only what we need for a stated purpose. We do not sell personal information to anybody, and we do not share it for anybody else's marketing.
- Enquiries and forms. Name, company, email address, telephone number and whatever you write in the message. Purpose: to answer you. Lawful basis: your consent, given by submitting the form.
- The free health check. Your company domain name, and the email addresses and breach records our scan returns against it. Purpose: to produce and explain your report. Lawful basis: your consent, and performance of the check you requested.
- Clients under a service agreement. Contact details for named users, and the technical and security data our monitoring produces about managed devices. Purpose: to deliver the contracted service. Lawful basis: performance of a contract.
- Website analytics. Aggregated usage data. Purpose: to understand which pages are useful. Lawful basis: your consent, given through the cookie banner. See our cookie policy.
4. How long we keep it
We keep personal information only for as long as the purpose requires, or for as long as a law requires us to. Enquiry records are kept for retention period to confirm. Health check reports are kept for retention period to confirm. Client records are kept for the duration of the agreement and for retention period to confirm afterwards, to meet tax and contractual obligations. After that they are deleted.
5. Who else sees it
Personal information is shared only with operators who process it on our behalf under a written data processing agreement, and only to the extent needed. That includes our email and cloud hosting providers, our monitoring and security platforms, and our accounting system. Every operator is contractually required to secure the information and to process it only on our instruction.
We may also disclose information where a law requires it, or to establish or defend a legal claim.
6. Where it is stored, and cross border transfer
Some of the services we use store data outside South Africa. POPIA Section 72 permits this where the receiving jurisdiction has comparable protection, where you have consented, or where the transfer is necessary to perform a contract with you. Our current hosting locations are hosting jurisdictions to confirm, and the relevant agreements are in place.
7. How we protect it
We apply the technical and organisational measures POPIA Section 19 requires: access limited to those who need it and reviewed regularly, multi-factor authentication on every account, encryption on devices and in transit, monitored and patched systems, backups that are tested by restoring from them, and a written incident response process.
8. Your rights
Under POPIA you may ask us what personal information we hold about you, ask us to correct or delete it, object to how we process it, withdraw a consent you previously gave, and complain to the Information Regulator.
- To exercise any of these, contact our Information Officer. Details are on the Information Officer page.
- We respond within response period to confirm of receiving a request.
- You may complain directly to the Information Regulator of South Africa at any time. Their contact details are published on their website.
9. If something goes wrong
If personal information in our care is accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as soon as reasonably possible after establishing what happened, in the manner POPIA requires. We will tell you what was affected and what to do about it.
10. Changes to this policy
Where we change this policy we will update the effective date at the top. Material changes affecting how we use information you have already given us will be communicated directly.
This policy is general information about how LANTEK Computers CC handles personal information. It is not legal advice.
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.