Responsible Party
Akha Digital (Pty) Ltd is the responsible party as defined in Section 1 of the Protection of Personal Information Act 4 of 2013 (POPIA).
| Responsible Party | Akha Digital (Pty) Ltd |
| Information Officer | privacy@akhadigital.co.za |
| Registered Address | Cape Town, South Africa |
| PAIA Manual | Available on request |
What is POPIA?
The Protection of Personal Information Act (POPIA) is South Africa's data protection law, effective since 1 July 2021. It regulates how organisations collect, process, store, and share personal information. POPIA gives you rights over your personal information and imposes obligations on responsible parties like Akha.
Information We Process
| Category | Examples | Purpose |
|---|---|---|
| Identity | Name, ID number, company registration | Account creation, verification |
| Contact | Email, phone, address | Communication, notifications |
| Financial | Revenue data, bank statements, tax clearance | Akha Score calculation, funder matching |
| Compliance | CIPC certificates, B-BBEE, BO declarations | Document verification, trust badges |
| Assessment | Questionnaire responses, scores | Readiness scoring, roadmap generation |
| Technical | IP address, device info, session data | Security, performance optimisation |
| Communication | Messages, support tickets | Customer support, service improvement |
Special Personal Information
We do not intentionally collect special personal information as defined in POPIA Section 26 (race, ethnicity, religion, health, sexual orientation, political persuasion, trade union membership, biometric data, or criminal behaviour). Where B-BBEE-related demographic data is voluntarily provided, it is processed solely for compliance scoring purposes with your explicit consent.
Lawful Basis for Processing
We process personal information under the following POPIA Section 11 grounds:
- Consent (s11(1)(a)): You consent when registering, uploading documents, and granting vault access.
- Contract (s11(1)(b)): Processing necessary to perform the services you signed up for.
- Legal obligation (s11(1)(c)): Processing required by FICA, the Companies Act, or tax legislation.
- Legitimate interest (s11(1)(f)): Anonymised analytics to improve the Platform, where this does not prejudice your rights.
POPIA Processing Conditions
We adhere to all eight conditions for lawful processing:
- Accountability: We take responsibility for compliance with POPIA.
- Processing limitation: We collect only what is necessary for defined purposes.
- Purpose specification: Information is collected for specific, lawful purposes disclosed in this notice.
- Further processing limitation: We do not process information for incompatible purposes.
- Information quality: We take reasonable steps to ensure accuracy and completeness.
- Openness: We are transparent about our processing activities through this notice.
- Security safeguards: We implement technical and organisational measures to protect information.
- Data subject participation: You can access, correct, and delete your information.
Trans-border Data Transfers
Our infrastructure is hosted on AWS in regions that may include servers outside South Africa. In accordance with POPIA Section 72, we ensure that any trans-border transfer is to a jurisdiction with adequate data protection, or is subject to binding agreements that provide equivalent safeguards.
Retention Periods
| Data Type | Retention | Basis |
|---|---|---|
| Account data | Active account + 2 years | Contractual |
| Assessment scores | Active account + 5 years | Legitimate interest |
| Vault documents | Until deleted by you | Consent |
| Audit logs | 7 years | FICA / Companies Act |
| Financial records | 5 years | Tax Administration Act |
| Analytics | 24 months (anonymised) | Legitimate interest |
Your Rights Under POPIA
You have the right to:
- Be informed: Know what information we hold and how we process it.
- Access: Request a copy of your personal information.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request destruction of personal information no longer needed.
- Object: Object to processing on reasonable grounds.
- Complain: Lodge a complaint with the Information Regulator.
To exercise any right, email privacy@akhadigital.co.za. We will respond within 30 days as required by POPIA.
Data Breach Notification
In the event of a personal information breach that poses a risk to you, we will notify you and the Information Regulator as soon as reasonably possible after becoming aware of the breach, in accordance with POPIA Section 22.
Our notification will include the nature of the breach, the information affected, measures taken to address it, and recommended steps you can take.
Complaints Procedure
If you believe your POPIA rights have been violated:
- Contact us first: Email privacy@akhadigital.co.za. We aim to resolve complaints within 30 days.
- Escalate to the Regulator: If unsatisfied, lodge a complaint with the Information Regulator of South Africa.
- Legal recourse: You may approach a court for relief under POPIA Section 99.
Information Regulator
Email: enquiries@inforegulator.org.za
Tel: 012 406 4818
Website: inforegulator.org.za
Information Officer
Akha Digital (Pty) Ltd
Information Officer: privacy@akhadigital.co.za
Cape Town, South Africa
Related: Privacy Policy · Terms of Use · Security