Privacy Policy.
This Privacy Policy explains how Elamilanga Consulting collects, uses, and protects your personal information – and how we handle client engagement data – in full compliance with South African law.
About This Policy & Who We Are
This Privacy Policy ("Policy") is published by Elamilanga Consulting (Registration Number: 2022/647668/07), based in Midrand, Gauteng, South Africa ("Elamilanga", "we", "us", "our"). For personal information collected through our website and general business enquiries, we act as the Responsible Party as defined in the Protection of Personal Information Act, 4 of 2013 ("POPIA"). Where we process personal information on behalf of a Client during an ISO consulting or audit Engagement, a different role applies – see Section 09 below.
This Policy applies to personal information collected when you visit our website, submit an enquiry through our contact form, message us on WhatsApp, or otherwise communicate with us directly.
We are committed to processing personal information lawfully, with minimal interference with your privacy, and only to the extent necessary for the legitimate purposes described in this Policy.
By using our website or contacting us, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please refrain from using our website or contacting us.
Information We Collect
Information you provide directly:
- Your name, email address, and phone number (optional) when you complete our website contact form.
- Your message content, business details, or compliance questions shared through the contact form or in written correspondence.
- Any information you voluntarily share with us over WhatsApp or email.
Information collected during a consulting Engagement:
- Business records, policies, procedures, and operational information you supply to enable a Gap Analysis, audit, or related service.
- Where an Engagement requires it (for example, during an internal audit or employee policy training), personal information relating to the Client's own employees, contractors, or other personnel – collected strictly on the Client's instruction and for the purposes of that Engagement (see Section 09).
Information collected automatically:
- Basic technical data (such as IP address, browser type, and device type) may be logged by our hosting provider for security and performance purposes. At present, our website does not use third-party analytics or advertising cookies; if this changes, we will update this Policy accordingly.
How We Use Your Information
We use personal information for the following purposes:
- Responding to enquiries submitted through our contact form, WhatsApp, or email.
- Providing quotes, scoping consultations, and the ISO consulting, audit, and compliance services you have engaged us for.
- Preparing gap analysis reports, policy documents, audit findings, and other deliverables as part of an Engagement.
- Maintaining business records for accounting, legal, and regulatory purposes.
- Improving our website and services.
We do not sell, rent, or trade personal information to third parties for marketing purposes.
Legal Basis for Processing
Under POPIA, we process personal information on one or more of the following lawful grounds:
- Consent: Where you have given consent, such as by submitting our contact form.
- Performance of a Contract: Where processing is necessary to perform an Engagement you have instructed us to carry out, or a contract to which you (or your employer) is a party.
- Legitimate Interest: Where processing is necessary for our legitimate business interests, such as responding to enquiries or maintaining accurate business records, and does not unreasonably override your privacy rights.
- Legal Obligation: Where processing is required to comply with a legal or regulatory obligation, including tax and accounting record-keeping requirements.
Cookies & Tracking
Our website currently uses only the minimum technical functionality required for our contact form to operate, and does not use third-party analytics, advertising, or tracking cookies. If we introduce analytics or marketing tools in future (for example, to understand website traffic), we will update this section and, where required by law, request your consent before doing so.
You can control or disable cookies at any time through your browser settings; note that some website functionality (such as our contact form) may not work correctly if cookies are disabled.
Third-Party Services
We use the following third-party service providers to help operate our website and business, each of which may process personal information on our behalf:
- WPForms – powers our website contact form and temporarily processes the information you submit before it is delivered to us.
- WhatsApp (Meta) – used as a direct messaging channel; messages sent to us via WhatsApp are subject to WhatsApp's own privacy policy and are stored on Meta's infrastructure.
- Our website hosting provider – stores website files and any data submitted through the website.
We require our service providers to protect personal information in accordance with applicable law, and we do not authorise them to use personal information for their own purposes.
Data Retention
We retain personal information for as long as necessary to fulfil the purposes described in this Policy, including:
- Contact form enquiries and general correspondence: retained for as long as reasonably necessary to respond to and follow up on your enquiry, and thereafter as required for our business records.
- Engagement records and deliverables (including audit reports, gap analyses, and policy documents prepared for a Client): retained for the period required by applicable accounting, tax, and – where relevant – certification body record-keeping requirements, typically several years after an Engagement ends.
When personal information is no longer required, we securely delete or anonymise it, except where longer retention is required by law.
Your Rights Under POPIA
As a data subject under the Protection of Personal Information Act, 4 of 2013, you have the following rights in respect of your personal information held by Elamilanga Consulting:
- Right of Access – request a copy of the personal information we hold about you.
- Right to Correction – request that we correct or update inaccurate or incomplete information.
- Right to Deletion – request deletion of your personal information, subject to our legal retention obligations.
- Right to Object – object to the processing of your information on grounds of legitimate interest.
- Right to Withdraw Consent – withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Right to Complain – lodge a complaint with the Information Regulator of South Africa if your rights have not been respected.
To exercise any of these rights, please submit your request in writing to info@elamilanga.co.za. We will respond within a reasonable time and, where required by POPIA, within 30 days of receiving your request. There is no charge for submitting a rights request, unless a request is manifestly unfounded or excessive.
Our Dual Role: Responsible Party vs. Operator
Depending on the context, Elamilanga acts in one of two distinct roles under POPIA:
- As Responsible Party: For personal information collected through our own website, contact form, and general business communications, Elamilanga determines the purpose and means of processing, and is therefore the Responsible Party.
- As Operator: When we carry out an ISO consulting Engagement – for example, an internal audit, gap analysis, or employee policy training – we may process personal information belonging to the Client's own employees, contractors, or other personnel strictly on the Client's instruction and for the Client's purposes. In this context, the Client organisation is the Responsible Party for that data, and Elamilanga acts only as an Operator under POPIA Sections 20 and 21.
As an Operator, we commit to:
- Process the personal information only for the purposes instructed by the Client, and not for our own independent purposes.
- Maintain the confidentiality of the personal information we process on the Client's behalf, in line with the Confidentiality & Non-Disclosure clause of our Terms & Conditions.
- Implement appropriate technical and organisational security measures to protect that personal information.
- Notify the Client promptly if we become aware of any security compromise affecting personal information processed on their behalf, so the Client can meet its own POPIA notification obligations.
- Assist the Client, where reasonably required, in responding to data subject requests relating to that personal information.
- Delete or securely return personal information processed on the Client's behalf at the end of the Engagement, unless required by law or a certification body's record-keeping rules to retain it for a defined period.
If you are an employee or representative of one of our Clients and have questions about how your personal information is processed during an Engagement, please direct your request to your employer in the first instance, as they remain the Responsible Party for that information.
Information Officer & Data Security
Information Officer: In terms of POPIA Section 55, Elamilanga Consulting has designated an Information Officer responsible for ensuring that we process personal information in compliance with POPIA, for handling requests from data subjects, and for liaising with the Information Regulator. To contact our Information Officer, please write to info@elamilanga.co.za.
Security Measures: We implement reasonable and appropriate technical and organisational measures to protect personal information against accidental loss, unauthorised access, disclosure, alteration, or destruction, including:
- SSL/TLS encryption on our website (HTTPS) to protect data in transit
- Secure, access-controlled storage of Client Engagement documents and audit records
- Access controls limiting personal information to authorised personnel only
- Regular security updates and maintenance on the systems we operate
Security Breaches: In the event of a security compromise involving personal information, we will notify affected data subjects (or, where we act as an Operator, the relevant Client) and, where required, the Information Regulator of South Africa, as soon as reasonably possible, in accordance with POPIA Section 22.
No system or method of electronic transmission is completely secure. While we take all reasonable precautions, we cannot guarantee absolute security of data transmitted over the internet. You transmit information to us at your own risk.
Cross-Border Data Transfers
Some of the third-party service providers we use – such as WhatsApp (Meta) and our website hosting infrastructure – may process or store data on servers located outside of the Republic of South Africa.
In terms of POPIA Section 72, we may only transfer personal information to a foreign country if:
- The recipient country has laws that provide an adequate level of protection substantially similar to POPIA's requirements, or
- The recipient is contractually bound to provide a comparable level of protection, or
- You have consented to the transfer after being informed of the risks.
We take reasonable steps to ensure that any cross-border transfer of your personal information is subject to appropriate protections.
Children's Privacy & Third-Party Links
Children's Privacy: Our website and services are directed at business owners, compliance officers, and other adults aged 18 years and older. We do not knowingly collect personal information from children under the age of 18. If you believe we have inadvertently collected personal information from a child, please contact us immediately at info@elamilanga.co.za and we will take prompt steps to delete it.
Links to Third-Party Websites: Our website may contain hyperlinks to external websites. This Privacy Policy applies only to our website and does not extend to those external sites. We encourage you to review the privacy policies of any external sites you visit before providing your personal information.
Changes to This Policy, Contact & Complaints
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable legislation, or operational requirements. The "Last updated" date at the top of this Policy indicates when it was most recently revised. Continued use of our website after a revised Policy has been published constitutes acceptance of the updated terms.
Contact Us: For any privacy-related queries, to exercise your POPIA rights, or to report a concern, please contact us at:
If you believe your rights under POPIA have not been respected and your complaint has not been satisfactorily resolved by us, you have the right to lodge a formal complaint with the South African Information Regulator:
South African Supervisory Authority
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Website: www.inforegulator.org.za
Questions about your privacy?
Contact our Information Officer for anything related to how we handle your information.