Section 1Who we are
We are a company registered in South Africa, Co. Reg. K2022/753000/07. We trade as AdventAlis, and that is the name you will see on our website, our proposals and our email. AdventAlis is a trading name only — the legal entity behind it, and the one responsible for the personal information described here, is the company registered as Co. Reg. K2022/753000/07.
In this policy, “we”, “us” and “AdventAlis” all mean that company. Our registered address is 210 Main Road, Somerset West, 7130, Western Cape, South Africa.
This policy covers the personal information we collect through adventalis.com (the Website) and in the ordinary course of working with our clients. Section 7 explains the one situation where it does not apply.
We have kept this short and written it in plain language on purpose. If anything here is unclear, ask us — our details are in section 12.
Section 2The laws this policy follows
The Protection of Personal Information Act 4 of 2013 (POPIA) applies to everything we do, because we are established in South Africa. The EU General Data Protection Regulation (GDPR) applies where we offer services to, or otherwise deal with, people in the European Union and the European Economic Area. Where the two differ, we apply whichever gives you more protection.
The vocabulary differs slightly between them. In this policy, “personal information” and “personal data” mean the same thing. What POPIA calls a responsible party, the GDPR calls a controller; what POPIA calls an operator, the GDPR calls a processor. We use both pairs of terms below so that the position is clear under either law.
Section 3What we do not do
This is the quickest way to tell you where you stand.
- We do not use advertising, marketing or cross-site tracking cookies.
- We do not use third-party analytics products, and we do not build profiles of visitors.
- We do not sell, rent or trade personal information, and we do not share it with data brokers.
- We do not make decisions about you by automated means that have legal effects for you.
- We do not seek special personal information, and the Website is not directed at children.
“Special personal information” means data about health, race or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, biometrics, sex life or sexual orientation, and criminal behaviour. We have no business reason to collect any of it.
If any of this changes, we will update this policy before it does, and ask for your consent where the law requires it.
Section 4What we collect and why
4.1 Website enquiries
If you complete an enquiry form on the Website or email us from a link on it, we collect what you choose to give us — your name and email address, and optionally your company, phone number and the content of your message — together with the date and the page you sent it from.
- Why: solely to answer you and take the steps you asked for before entering into a contract. An enquiry does not put you on a mailing list.
- Legal basis: POPIA s11(1)(b) and s11(1)(f); GDPR Art. 6(1)(b) and Art. 6(1)(f).
- How long: up to 24 months after our last contact about the enquiry, unless it becomes a client relationship — in which case 4.2 applies. You can ask us to delete it sooner.
4.2 Clients and prospective clients
When we work with a client we hold the names, work email addresses, phone numbers and roles of the people we deal with, our correspondence with them, and the project records, invoices and payment references that go with the engagement.
- Why: to deliver the services, run the project, invoice you, and keep the business records we are required by law to keep.
- Legal basis: POPIA s11(1)(b) and s11(1)(c); GDPR Art. 6(1)(b) and Art. 6(1)(c).
- How long: for the life of the relationship, then a further five years to meet South African company and tax record-keeping obligations. Correspondence with no record-keeping value goes sooner.
4.3 Email and correspondence
We correspond with you using a standard business email and productivity platform (Google Workspace). Messages sit on that platform under our account and follow the retention periods above.
4.4 Website hosting logs
Our hosting provider (Google Cloud Platform) keeps ordinary server logs — IP address, timestamp, the page requested and the browser identification string — for security and troubleshooting. We do not use these logs to identify visitors or to measure audiences. They are retained for 30 days and then overwritten.
- Legal basis: POPIA s11(1)(f); GDPR Art. 6(1)(f) — our legitimate interest in keeping the Website available and secure.
Section 6Emails we send you
Service and project email. If you are a client, we email you about your work with us. This is not marketing, and it continues for as long as the engagement runs.
Occasional updates to existing clients. We may email existing clients about services similar to those we already provide. Every such message carries a clear way to stop it, and you were given the chance to decline when we took your address. This follows POPIA s69(3) and the equivalent EU soft opt-in.
Everyone else. If you are not a client, we will only send you marketing email if you have asked us to.
You can opt out at any time, by using the unsubscribe link or simply replying to ask us to stop. We act on it promptly and keep a minimal suppression record so that we do not contact you again by mistake.
Section 7When we act for a client rather than for ourselves
AdventAlis is a Build Partner of Alis Exchange (alisx.com). We build and deliver solutions for our own clients on that platform. Where we do, the roles are as follows.
- Our client is the responsible party / controller for the personal information inside that solution. They decide what is collected and for what purpose.
- We act as an operator / processor on that client's documented instructions, under a written agreement as required by POPIA s20–21 and GDPR Art. 28.
- Alis Exchange acts as a further operator / sub-processor in that chain, under its own terms and privacy policy.
This policy does not govern that information — our client's own privacy policy does. If you are a customer, employee or contact of one of our clients and you want to exercise your rights over data held in a solution we built for them, please approach that client directly. If you approach us instead, we will pass your request on and help our client answer it, but we are not permitted to act on it ourselves.
Section 9Where your information is processed
We are based in South Africa and process personal information here and in the facilities of the providers listed in section 8.
If you are in the EU or EEA. South Africa is not currently covered by an EU adequacy decision. Where personal data reaches us from inside the EEA, we rely on an appropriate transfer mechanism under GDPR Chapter V — normally the European Commission's Standard Contractual Clauses, supplemented where necessary — or on a derogation in Art. 49 where one genuinely applies. Where you give us your details directly, for example by completing our enquiry form, you are disclosing them to us in South Africa rather than transferring them out of the EEA; we apply the same standard of protection either way.
Under POPIA. Section 72 lets us send personal information outside South Africa only where the recipient is subject to a law, binding corporate rules or a binding agreement giving an adequate level of protection, or where the transfer is necessary for a contract with you, or where you have consented.
Section 10How we protect your information
We take the technical and organisational measures required by POPIA s19 and GDPR Art. 32, proportionate to the size of our business and the sensitivity of what we hold. In practice:
- access to personal information is limited to the people who need it for their work, and is removed when someone leaves or a project ends;
- multi-factor authentication is enforced on our email, platform and administrative accounts;
- traffic is encrypted in transit using TLS, and encrypted at rest wherever our providers support it;
- we work with established providers that run their own security programmes — Alis Exchange, for example, states that it works to the ISO/IEC 27001:2022 standard.
We do not hold a security certification of our own, and we make no claim to one.
No system is perfectly secure. If a security compromise affects your personal information, we will notify the Information Regulator and you as soon as reasonably possible under POPIA s22. Where the GDPR applies, we will notify the competent supervisory authority within 72 hours and tell you directly where the breach is likely to result in a high risk to you.
Section 11Your rights
Subject to the limits each law sets, you may ask us to do any of the following.
| Right | POPIA | GDPR |
|---|---|---|
| Be told what we hold about you, and get a copy | s23 | Art. 15 |
| Have inaccurate or incomplete information corrected | s24 | Art. 16 |
| Have information deleted where we no longer have grounds to keep it | s24 | Art. 17 |
| Object to processing based on legitimate interests | s11(3)(a) | Art. 21 |
| Stop direct marketing — absolute, and no reasons needed | s69, s11(3)(b) | Art. 21(2) |
| Restrict processing while a dispute is resolved | s14(6) | Art. 18 |
| Receive your data in a portable format | — | Art. 20 |
| Withdraw a consent you gave, without undoing what was lawful before | s11(2)(b) | Art. 7(3) |
| Not be subject to a decision made solely by automated processing | s71 | Art. 22 |
| Complain to a regulator | s74 | Art. 77 |
How to exercise them. Email privacy@adventalis.com and tell us what you want. We may ask for enough information to satisfy ourselves that it is really you, and we will not use what you send for anything else. Formal access requests under POPIA are made through our PAIA manual and may attract the prescribed fee; we will tell you if that applies before we do the work.
We respond within 30 days of receiving a valid request, and within one month where the GDPR applies. If a request is complex we may need longer, and we will tell you why within that original period.
Section 12Contact us, and how to complain
Please raise anything with us first. We would far rather fix it directly.
Co. Reg. K2022/753000/07, trading as AdventAlis
Attention: the Information Officer
210 Main Road, Somerset West, 7130, South Africa
If you are not satisfied with our answer, you may complain to a regulator.
Information Regulator (South Africa)
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Toll free 0800 017 160 · Landline 010 023 5200
If you are in the EU or EEA, you may also complain to the supervisory authority of the country where you live or work, or where you believe the problem occurred. The European Data Protection Board keeps a list at edpb.europa.eu.
Section 13Changes to this policy
We update this policy when what we do changes. The version number and both dates at the top of this page always reflect the current text. Where a change materially affects you and we hold your contact details, we will tell you by email before it takes effect.