1. Personal information:
We collect, hold, process and store personal information about individuals who engage with us (e.g., learners, clients, corporate contacts, website users). This may include, without limitation:
- Names (first name, surname)
- Contact information (email address, telephone number, postal address)
- Employment/organisation details (job title, company, department)
- Training/registration information (course selections, attendance records, certifications, assessment outcomes)
- Payment, billing and invoicing information (where applicable)
- Identification documents (for verification where required)
- Any other information you provide directly or indirectly to us for the purposes of our services
We may also collect special/potentially sensitive personal information in certain training contexts — for example health-/safety status, disability information, biometric data, or criminal behaviour details — only where necessary and subject to additional safeguards. Under POPIA this is regulated under the “special personal information” rules.
We treat all such information as confidential and will hold it securely.
2. Collecting personal information:
We collect personal information in a variety of ways, including:
- Directly from you when you complete registration forms, application forms, feedback/survey forms, or when you otherwise communicate with us (in-person, by phone, email or via our website).
- Indirectly when you use our website, digital learning platform or communicate online (for example via cookies, analytics or user tracking — see further below).
- From third-party sources (with your knowledge or as permitted) such as corporate clients, partners, accreditation bodies or other service-providers, where they supply us with delegate/contact information.
- Where you provide permission, or where the information is publicly available or part of your employment/qualification record.
In collecting your information we will:
- Inform you, at or before collection, of the purpose for which we are collecting the information.
- Collect only what is adequate, relevant and not excessive for that purpose (i.e., minimal-collection principle) in line with POPIA’s “processing limitation” condition.
- Obtain your consent where required (and make sure that consent is voluntary, specific, informed).
- Ensure that you understand that providing some of the information may be optional and the consequences (if any) of not providing it.
3. Using and disclosing your personal information:
We will use your personal information for legitimate purposes including, but not limited to:
- Registering you/enrolling you in training, managing your participation, issuing certificates and keeping attendance/assessment records.
- Communicating with you about our programmes, training schedules, administrative updates, or any changes to our services.
- Billing, invoicing, payment processing and refunds (where applicable).
- Monitoring, evaluating and improving our training programmes (including delegate feedback, outcomes tracking).
- Complying with legal or accreditation/regulatory obligations (for example courses requiring mandated reporting).
- Protecting our rights, investigating misuse or fraud, enforcing our agreements.
Disclosure
We may disclose your personal information in the following ways:
- To our employees, agents, contractors, service-providers or suppliers who assist in delivering our training programmes, administrative or technical operations (e.g., IT service providers, learning-platform partners, accreditation bodies).
- To third parties when required by law, regulation or lawful request (for example regulatory authorities, law-enforcement, accreditation bodies).
- With your consent, or as part of a transaction (for example if we partner with or merge with another organisation, whereby your data may transfer subject to confidentiality/data protection obligations).
- If needed to protect our rights, property or the safety of participants or others.
Security and retention
We will take appropriate, reasonable technical and organisational measures to safeguard your personal information against loss, damage, unauthorised access, alteration or disclosure. This is in accordance with POPIA’s “security safeguards” condition. dataprivacymanager.net+1
We will retain personal information only as long as necessary for the purposes for which it was collected, or as required by law or accreditation standards. Once the information is no longer needed, we will dispose of or anonymise it in a secure manner.
International transfers / cross-border disclosures
Where your personal information is transferred outside South Africa (for example cloud‐based servers in another jurisdiction, or partner organisations overseas), we will ensure that the recipient country has adequate data protection safeguards, or we will use appropriate contractual or binding corporate rules consistent with POPIA’s cross-border transfer requirement.
You will be informed if your data is to be transferred overseas and given appropriate detail in this policy or related notices.
4. Contact by the company:
By providing us with your personal information (such as via registration or enquiry), you agree that we may contact you:
- By email, telephone, SMS or other electronic means regarding services you have chosen, training participation, administrative issues or feedback requests.
- With promotional or marketing material about our training services, workshops, events, updates, unless you choose to opt-out of marketing communications.
You have the right to opt-out of receiving further direct‐marketing communications from us at any time. To do so, please contact us (see Contact details below) and indicate that you do not wish to receive marketing communications. We will update our records and cease such communications as soon as reasonably possible.
5. Individual’s right of access:
Under POPIA you have the following rights (subject to any statutory or legitimate business limitations):
- The right to request access to personal information we hold about you.
- The right to request correction or deletion of your personal information if it is inaccurate, incomplete, misleading or no longer needed for the purpose for which it was collected.
- The right to object to or restrict certain processing of your personal information (for example direct-marketing, profiling, automated decision-making) on reasonable grounds.
- The right to withdraw consent at any time where processing is based purely on your consent — such withdrawal does not affect the lawfulness of processing done before withdrawal.
- The right to lodge a complaint with the relevant regulator (Information Regulator) if you believe your rights have been infringed.
To exercise any of the above rights, please contact us (see Contact details below). We may request proof of identity to verify that the request is made by the correct person, and we will respond within a reasonable timeframe.
In some cases, we may be legally permitted to retain a copy of your personal information, or may decline certain requests where permitted by law (for example archival requirements, legal obligations or public interest).
6. The company and links to other web sites:
Our website and digital services may contain links to external websites, partner platforms, or third-party service-providers. When you click on or link to another site, you may leave our platform—and this Privacy Policy will no longer apply to those external sites or their data-collection practices.
We recommend that you review the privacy policy or notice of any website you visit through our site, and check how your personal information is handled by those third parties.
7. Cookies, tracking and analytics(If applicable) Our website may use “cookies”, web beacons, tracking pixels, analytics or similar technologies to gather usage information (for example IP address, device/browser type, pages visited, time and date of visit).
- We will inform you about the use of cookies/tracking in a cookie banner or notice.
- Where such technologies collect personal information (or uniquely identify you), we will seek your consent in accordance with POPIA and/or other applicable laws.
- You can disable cookies in your browser settings (though this may affect your ability to use certain features of our website).
- These technologies allow us to monitor and improve our website and service-delivery, tailor content and measure usage.
8. Children and special-categories of personal information
If we collect personal information about children (defined under our policy as persons under [insert age, e.g., 18 years] or a legal minor in your jurisdiction), we will do so only with the consent of a parent or legal guardian (or as otherwise permitted by law).
For “special categories” of personal information (e.g., health status, biometric data, race/ethnicity, trade union membership, criminal behaviour), additional safeguards apply. Under POPIA, the processing of special personal information is generally prohibited unless the responsible party demonstrates the required conditions (Sections 26–33) are met.
Where special personal information is collected, we will clearly describe the purpose, obtain explicit consent (or rely on another legal basis), restrict access, and apply heightened security measures.
9. Data breach notification
In the event of a security incident or data breach which results in the unauthorised access or acquisition of personal information which poses a risk of harm to individuals, we will:
- Notify the affected data subject(s) as soon as reasonably practicable and provide: the nature of the breach, likely consequences, and the remedial actions being taken.
- Report the breach to the Information Regulator where required under POPIA.
- Take all necessary steps to mitigate the breach and prevent recurrence (including investigating and implementing additional safeguards).
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time (for example if our practices change, we adopt new technologies or processes, or as law/regulation evolves).
When we make significant changes, we will provide notice by posting the updated version on our website, and indicate the “Last updated” date.
We recommend you review this Privacy Policy periodically.