We respect the privacy of persons who visit our website, contact us, work with us, attend our programmes or otherwise interact with our business.
This policy explains what personal information and personal data we collect, why we use it, who we share it with, how we protect it and how you can exercise your rights.
In this policy
1. What this policy covers
This policy applies when you:
- visit techilalaw.com;
- use our contact form or email us;
- subscribe to our newsletter or other requested communications;
- request a proposal or engage TECHila Law for consulting, advisory, governance, training or implementation work;
- attend an event, workshop, training session or research activity;
- apply for employment or a consultant opportunity; or
- act on behalf of a client, supplier, partner or other organisation.
2. Who is responsible for your information?
TECHila Law is the responsible organisation for its own website, business administration, recruitment, marketing and direct client relationship processing.
For South African processing, we apply the Protection of Personal Information Act 4 of 2013 (POPIA) where applicable. For processing within the scope of the European Union General Data Protection Regulation (GDPR), we apply the GDPR where applicable.
When we process information on a client’s documented instructions, we may act as a POPIA operator or GDPR processor. The client contract and applicable data-processing schedule will govern that processing.
Privacy contact: Information Officer, TECHila Law, info@techilalaw.com.
TECHila Law has not designated a Data Protection Officer for its general processing as at the effective date. If a DPO or EU representative is legally required for a specific processing activity, we will designate one before that activity begins and update this policy.
3. Information we may collect
We collect only information that is adequate, relevant and reasonably necessary for the purpose for which it is processed. Depending on the relationship, this may include:
- Identity and contact information: name, title, organisation, email address, telephone number and correspondence details.
- Professional information: role, sector, qualifications, interests, event attendance and engagement history.
- Enquiry and proposal information: messages, subject lines, project requirements, business priorities, service preferences and meeting records.
- Client and project information: statements of work, deliverables, risk and decision records, workshop outputs, documents and information supplied for analysis.
- Billing and administration information: invoices, payment details, tax details, purchase-order information and supplier records.
- Technical information: IP address, device, browser, access logs, security events and website interactions.
- Recruitment information: applications, CVs, references, qualifications, work eligibility and onboarding information.
- Event and training information: attendance, participation, feedback and certificate details.
We do not seek special or sensitive information through ordinary website enquiries. If such information is necessary for a specific engagement, we will address it through the relevant contract, notice and safeguards.
4. How we collect information
- Directly from you through our contact form, newsletter sign-up, emails, calls, meetings, events, workshops, proposals, contracts and applications.
- From your organisation, authorised representatives, colleagues, clients, suppliers or professional advisers.
- From public professional sources, including business websites and professional networking profiles, where lawful and relevant.
- From service providers supporting hosting, communications, security, analytics, payments, recruitment or business administration.
- Automatically through website logs, essential cookies and analytics technologies, subject to the cookie controls described below.
5. Why we use information and the legal basis
The POPIA and GDPR frameworks do not use identical terminology. For each processing activity, we identify the applicable POPIA lawful-processing condition or justification and, where the GDPR applies, the relevant GDPR legal basis.
| Purpose | Information used | POPIA basis or justification | GDPR basis | Default retention |
|---|---|---|---|---|
| Respond to enquiries and requests for proposals | Identity, contact, message and business context | Consent where requested, pre-contract steps, lawful business purpose | Pre-contract steps or legitimate interests | 24 months after last contact |
| Deliver consulting, Ai advisory, governance, training and implementation services | Client contacts, project information, documents, meeting records and deliverables | Contract, client instructions, accountability and lawful business purpose | Contract, legitimate interests or legal obligation | 7 years after engagement close, unless law or contract requires longer |
| Manage contracts, billing, tax and payments | Identity, contact, contract, invoice and payment information | Contract, legal obligation and accountability | Contract or legal obligation | 7 years after the relevant financial or contractual record |
| Protect systems, people and information | Technical logs, access records, security events and identity information | Security safeguards, accountability and lawful purpose | Legitimate interests or legal obligation | 12 months for routine logs, longer for an incident or legal matter |
| Marketing, events and thought leadership | Contact details, preferences, attendance and submitted content | Consent or lawful direct-marketing justification, with objection and opt-out | Consent or legitimate interests, with opt-out | Until withdrawal or 24 months of inactivity |
| Recruitment and personnel administration | Application, professional, reference and onboarding information | Consent where required, contract, legal obligation and accountability | Pre-contract steps, contract or legal obligation | 12 months for unsuccessful applicants; longer where employment records require it |
| Website operation, analytics and cookies | IP address, device, browser and usage information | Consent where required, security safeguards and lawful purpose | Consent for non-essential analytics; legitimate interests for essential security | Essential logs 12 months; analytics according to the active cookie setting |
6. Contact forms
Our contact form may collect your first name, last name, email address, subject and message. We use this information to respond to your enquiry, understand your requirements, provide requested information and, where appropriate, prepare a proposal or arrange a consultation.
Do not submit passwords, API keys, access tokens, confidential credentials or highly sensitive information through the contact form. Use an agreed secure channel for information that requires enhanced protection.
7. Newsletter and marketing communications
If you subscribe to our newsletter, we use your email address and any optional name or preference information to send the communications you requested. You can unsubscribe at any time using the link in the communication or by emailing info@techilalaw.com.
We do not sell mailing lists. We may use a service provider to distribute communications on our behalf, subject to appropriate confidentiality, security and processing terms.
8. Cookies and website technologies
Our website uses essential cookies and similar technologies required for security, basic functionality and site operation. We also use analytics technology to understand website use and improve content.
| Category | Purpose | Default position | Your control |
|---|---|---|---|
| Essential | Security, page operation and necessary site preferences | Enabled where necessary | Browser settings and site controls |
| Analytics | Aggregate traffic, performance and content-use information | Activated only after consent where required | Cookie preference control |
| Marketing | Advertising or cross-site profiling | Not used by default | Would require a separate update and consent where required |
We do not currently use social-media feeds, video embeds, chat or WhatsApp tools, payments or client portals on the website as part of this policy configuration. If those features are introduced, this policy and the cookie controls will be updated before or when they are activated.
9. Sharing information
We may share information only where necessary for the stated purpose, authorised by contract, required or permitted by law, or otherwise supported by a lawful basis. Recipients may include:
- TECHila Law employees, consultants, contractors and professional advisers who need the information for the relevant purpose;
- hosting, cloud, communications, collaboration, accounting, payment, security, recruitment, analytics and other service providers;
- clients, suppliers, partners and counterparties where necessary for an engagement and authorised by the relevant relationship;
- regulators, courts, law-enforcement or public authorities where legally required or permitted; and
- a purchaser, successor, auditor or professional adviser involved in a restructuring or transaction.
10. International transfers and remote access
TECHila Law is based in South Africa and works with international clients, professionals and service providers. Personal information or personal data may therefore be accessed from or transferred to South Africa, the European Economic Area, the United Kingdom, the United States or another country in which an approved provider or professional participant operates.
Before making a restricted international transfer, we assess the applicable POPIA and GDPR requirements and use an appropriate safeguard, such as an adequacy decision, contractual protection, standard contractual clauses, binding corporate rules, documented client instructions or another lawful mechanism. The safeguard for a particular client engagement will be recorded in the relevant contract or data-processing schedule.
To request information about a specific transfer, email info@techilalaw.com with “International transfer request” in the subject line.
11. Retention and deletion
Our default retention schedule is set out in section 5. We review records periodically and securely delete, destroy or anonymise them when the purpose ends and no legal, contractual, security, audit or dispute reason requires retention. Backups may retain information for a limited period while they cycle out under the applicable backup process.
12. Security safeguards
We use reasonable and appropriate technical and organisational measures proportionate to the risk and the nature of the information. These may include role-based access, least privilege, authentication, confidentiality obligations, training, encryption where appropriate, secure configuration, patching, backups, logging, monitoring, vendor due diligence, written processing terms, change management, incident response, business continuity, recovery and secure deletion.
13. Breaches and security incidents
If TECHila Law becomes aware of a confirmed or reasonably suspected compromise involving personal information or personal data, we will assess and contain the event, preserve evidence, document the response and notify the relevant client, regulator or affected individuals where required by applicable law.
Report suspected incidents promptly to info@techilalaw.com with “Privacy incident” in the subject line.
14. Your rights
Subject to applicable law, exemptions and identity verification, you may have the right to:
- request access to personal information or personal data we hold about you;
- request correction or updating of inaccurate, incomplete, outdated or misleading information;
- request deletion or destruction where the information is no longer lawfully required or is unlawfully processed;
- object to certain processing, including direct marketing;
- request restriction of processing where the GDPR applies and the right is available;
- withdraw consent where consent is the basis;
- request data portability where the GDPR applies and the right is available;
- obtain information about relevant automated decision-making and request human intervention or review where applicable; and
- lodge a complaint with the South African Information Regulator or an EU supervisory authority with jurisdiction.
To exercise a right, email info@techilalaw.com with “Data subject request” in the subject line. We may request reasonable information to verify identity and protect against unauthorised disclosure. We will respond within the period required by applicable law and explain any lawful extension, refusal or limitation.
When acting as a processor or operator for a client, we may direct the request to that client or assist the client under the applicable contract.
18. Changes to this policy
We may update this policy when our services, processing, technology, legal obligations or governance changes. The version and effective date appear at the beginning of this policy. Material changes will be communicated through the website or another appropriate channel where required.
19. Applicable legal frameworks
This policy is intended to operate alongside the Protection of Personal Information Act 4 of 2013 and Regulation (EU) 2016/679, together with applicable regulations, codes of conduct, regulator guidance, contractual obligations and sector requirements.
Official reference texts: POPIA and GDPR consolidated text.
Questions about your information?
For privacy questions, data subject requests or security incident reports, contact the Information Officer at TECHila Law.
info@techilalaw.com →