A
AdventAlis
Back to the site
Legal · AdventAlis

Privacy Policy

We collect very little, we do not track you, and we do not sell anything about you to anyone. This policy sets out exactly what we hold, why we hold it, and what you can ask us to do about it.

Co. Reg. K2022/753000/07, trading as AdventAlis. 210 Main Road, Somerset West, 7130, Western Cape, South Africa.

Effective
1 October 2026
Last updated
1 October 2026
Version
1.0
Applies to
adventalis.com

Section 1Who we are

We are a company registered in South Africa, Co. Reg. K2022/753000/07. We trade as AdventAlis, and that is the name you will see on our website, our proposals and our email. AdventAlis is a trading name only — the legal entity behind it, and the one responsible for the personal information described here, is the company registered as Co. Reg. K2022/753000/07.

In this policy, “we”, “us” and “AdventAlis” all mean that company. Our registered address is 210 Main Road, Somerset West, 7130, Western Cape, South Africa.

This policy covers the personal information we collect through adventalis.com (the Website) and in the ordinary course of working with our clients. Section 7 explains the one situation where it does not apply.

We have kept this short and written it in plain language on purpose. If anything here is unclear, ask us — our details are in section 12.

Section 2The laws this policy follows

The Protection of Personal Information Act 4 of 2013 (POPIA) applies to everything we do, because we are established in South Africa. The EU General Data Protection Regulation (GDPR) applies where we offer services to, or otherwise deal with, people in the European Union and the European Economic Area. Where the two differ, we apply whichever gives you more protection.

The vocabulary differs slightly between them. In this policy, “personal information” and “personal data” mean the same thing. What POPIA calls a responsible party, the GDPR calls a controller; what POPIA calls an operator, the GDPR calls a processor. We use both pairs of terms below so that the position is clear under either law.

Section 3What we do not do

This is the quickest way to tell you where you stand.

  • We do not use advertising, marketing or cross-site tracking cookies.
  • We do not use third-party analytics products, and we do not build profiles of visitors.
  • We do not sell, rent or trade personal information, and we do not share it with data brokers.
  • We do not make decisions about you by automated means that have legal effects for you.
  • We do not seek special personal information, and the Website is not directed at children.

“Special personal information” means data about health, race or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, biometrics, sex life or sexual orientation, and criminal behaviour. We have no business reason to collect any of it.

If any of this changes, we will update this policy before it does, and ask for your consent where the law requires it.

Section 4What we collect and why

4.1  Website enquiries

If you complete an enquiry form on the Website or email us from a link on it, we collect what you choose to give us — your name and email address, and optionally your company, phone number and the content of your message — together with the date and the page you sent it from.

  • Why: solely to answer you and take the steps you asked for before entering into a contract. An enquiry does not put you on a mailing list.
  • Legal basis: POPIA s11(1)(b) and s11(1)(f); GDPR Art. 6(1)(b) and Art. 6(1)(f).
  • How long: up to 24 months after our last contact about the enquiry, unless it becomes a client relationship — in which case 4.2 applies. You can ask us to delete it sooner.

4.2  Clients and prospective clients

When we work with a client we hold the names, work email addresses, phone numbers and roles of the people we deal with, our correspondence with them, and the project records, invoices and payment references that go with the engagement.

  • Why: to deliver the services, run the project, invoice you, and keep the business records we are required by law to keep.
  • Legal basis: POPIA s11(1)(b) and s11(1)(c); GDPR Art. 6(1)(b) and Art. 6(1)(c).
  • How long: for the life of the relationship, then a further five years to meet South African company and tax record-keeping obligations. Correspondence with no record-keeping value goes sooner.

4.3  Email and correspondence

We correspond with you using a standard business email and productivity platform (Google Workspace). Messages sit on that platform under our account and follow the retention periods above.

4.4  Website hosting logs

Our hosting provider (Google Cloud Platform) keeps ordinary server logs — IP address, timestamp, the page requested and the browser identification string — for security and troubleshooting. We do not use these logs to identify visitors or to measure audiences. They are retained for 30 days and then overwritten.

  • Legal basis: POPIA s11(1)(f); GDPR Art. 6(1)(f) — our legitimate interest in keeping the Website available and secure.

Section 5Cookies

We use only cookies that are strictly necessary to make the Website work and keep it secure. These do not require consent under POPIA or the EU ePrivacy rules, which is why you are not being asked to dismiss a banner.

We set no analytics, advertising, personalisation or cross-site tracking cookies. If we ever introduce a non-essential cookie, we will ask for your consent first and list it here.

Section 6Emails we send you

Service and project email. If you are a client, we email you about your work with us. This is not marketing, and it continues for as long as the engagement runs.

Occasional updates to existing clients. We may email existing clients about services similar to those we already provide. Every such message carries a clear way to stop it, and you were given the chance to decline when we took your address. This follows POPIA s69(3) and the equivalent EU soft opt-in.

Everyone else. If you are not a client, we will only send you marketing email if you have asked us to.

You can opt out at any time, by using the unsubscribe link or simply replying to ask us to stop. We act on it promptly and keep a minimal suppression record so that we do not contact you again by mistake.

Section 7When we act for a client rather than for ourselves

AdventAlis is a Build Partner of Alis Exchange (alisx.com). We build and deliver solutions for our own clients on that platform. Where we do, the roles are as follows.

  • Our client is the responsible party / controller for the personal information inside that solution. They decide what is collected and for what purpose.
  • We act as an operator / processor on that client's documented instructions, under a written agreement as required by POPIA s20–21 and GDPR Art. 28.
  • Alis Exchange acts as a further operator / sub-processor in that chain, under its own terms and privacy policy.

This policy does not govern that information — our client's own privacy policy does. If you are a customer, employee or contact of one of our clients and you want to exercise your rights over data held in a solution we built for them, please approach that client directly. If you approach us instead, we will pass your request on and help our client answer it, but we are not permitted to act on it ourselves.

Section 8Who we share it with

We share personal information only with the following categories of recipient, and only as far as the work requires.

RecipientWhat for
Alis Exchange — Alis SARL, 43 Boulevard Prince Henri, Luxembourg 1724, and its affiliates Alis SA Branch and Alisx UK LtdThe platform on which we build and deliver client solutions. Its policy is at alisx.com/privacy-policy and its privacy contact is privacy@alisx.com.
Our email, document and productivity provider, Google WorkspaceHosting our correspondence and working files.
Our website host, Google Cloud PlatformRunning the Website.
Our accountants, auditors and legal advisersProfessional services, under a duty of confidence.
Law enforcement, regulators or courtsOnly where we are legally compelled, or where we need to establish or defend a legal claim.

We put a written agreement in place with every provider that processes personal information on our behalf, and we do not authorise any of them to use it for their own purposes.

Section 9Where your information is processed

We are based in South Africa and process personal information here and in the facilities of the providers listed in section 8.

If you are in the EU or EEA. South Africa is not currently covered by an EU adequacy decision. Where personal data reaches us from inside the EEA, we rely on an appropriate transfer mechanism under GDPR Chapter V — normally the European Commission's Standard Contractual Clauses, supplemented where necessary — or on a derogation in Art. 49 where one genuinely applies. Where you give us your details directly, for example by completing our enquiry form, you are disclosing them to us in South Africa rather than transferring them out of the EEA; we apply the same standard of protection either way.

Under POPIA. Section 72 lets us send personal information outside South Africa only where the recipient is subject to a law, binding corporate rules or a binding agreement giving an adequate level of protection, or where the transfer is necessary for a contract with you, or where you have consented.

Section 10How we protect your information

We take the technical and organisational measures required by POPIA s19 and GDPR Art. 32, proportionate to the size of our business and the sensitivity of what we hold. In practice:

  • access to personal information is limited to the people who need it for their work, and is removed when someone leaves or a project ends;
  • multi-factor authentication is enforced on our email, platform and administrative accounts;
  • traffic is encrypted in transit using TLS, and encrypted at rest wherever our providers support it;
  • we work with established providers that run their own security programmes — Alis Exchange, for example, states that it works to the ISO/IEC 27001:2022 standard.

We do not hold a security certification of our own, and we make no claim to one.

No system is perfectly secure. If a security compromise affects your personal information, we will notify the Information Regulator and you as soon as reasonably possible under POPIA s22. Where the GDPR applies, we will notify the competent supervisory authority within 72 hours and tell you directly where the breach is likely to result in a high risk to you.

Section 11Your rights

Subject to the limits each law sets, you may ask us to do any of the following.

RightPOPIAGDPR
Be told what we hold about you, and get a copys23Art. 15
Have inaccurate or incomplete information correcteds24Art. 16
Have information deleted where we no longer have grounds to keep its24Art. 17
Object to processing based on legitimate interestss11(3)(a)Art. 21
Stop direct marketing — absolute, and no reasons neededs69, s11(3)(b)Art. 21(2)
Restrict processing while a dispute is resolveds14(6)Art. 18
Receive your data in a portable formatArt. 20
Withdraw a consent you gave, without undoing what was lawful befores11(2)(b)Art. 7(3)
Not be subject to a decision made solely by automated processings71Art. 22
Complain to a regulators74Art. 77

How to exercise them. Email privacy@adventalis.com and tell us what you want. We may ask for enough information to satisfy ourselves that it is really you, and we will not use what you send for anything else. Formal access requests under POPIA are made through our PAIA manual and may attract the prescribed fee; we will tell you if that applies before we do the work.

We respond within 30 days of receiving a valid request, and within one month where the GDPR applies. If a request is complex we may need longer, and we will tell you why within that original period.

Section 12Contact us, and how to complain

Please raise anything with us first. We would far rather fix it directly.

Co. Reg. K2022/753000/07, trading as AdventAlis

Attention: the Information Officer

210 Main Road, Somerset West, 7130, South Africa

privacy@adventalis.com

If you are not satisfied with our answer, you may complain to a regulator.

Information Regulator (South Africa)

General enquiries: enquiries@inforegulator.org.za

POPIA complaints: POPIAComplaints@inforegulator.org.za

Toll free 0800 017 160  ·  Landline 010 023 5200

inforegulator.org.za

If you are in the EU or EEA, you may also complain to the supervisory authority of the country where you live or work, or where you believe the problem occurred. The European Data Protection Board keeps a list at edpb.europa.eu.

Section 13Changes to this policy

We update this policy when what we do changes. The version number and both dates at the top of this page always reflect the current text. Where a change materially affects you and we hold your contact details, we will tell you by email before it takes effect.