Privacy Policy

How we handle personal information.

This policy explains what personal information Numata collects through this website and our commercial relationships, why we hold it, how long we keep it and the rights you can exercise over it.

Regimes
POPIA · GDPR · UK GDPR · PDPO · US state law
Owner
Information Officer
Requests
Answered within 30 days
Selling data
Never
Last reviewed
July 2026
On this page
  1. Who we are
  2. Information we collect
  3. Why we hold it
  4. Who we share it with
  5. Where it is held
  6. How long we keep it
  7. Your rights
  8. Security
  9. Categories of personal information we hold
  10. Is supplying information voluntary or mandatory?
  11. Your rights as a data subject
  12. Exercising your right of access
  13. Complaint process and contact particulars
  14. Processing client data under GDPR
  15. When we may disclose your information
  16. Which law applies to you

Applies to All Numata entities and visitors to this website.

Who we are

Numata is a business technology practice operating through local entities in South Africa, the United Kingdom, Ireland, the United States and Hong Kong. The entity that contracts with you is the controller of the personal information held for that relationship. Where we operate technology on your behalf, we act as a processor under the terms of the applicable Data Processing Agreement.

Information we collect

We collect only what a business relationship reasonably requires.

  • Contact details you submit through forms, downloads or newsletter sign-up: name, work email, company, role and country.
  • Correspondence and meeting records created while we scope, deliver or support an engagement.
  • Technical data captured when you browse: IP address, device and browser type, referring page and pages viewed.
  • Service telemetry from systems we manage under contract, held as a processor on the client's instruction.

Why we hold it

We process personal information to respond to enquiries, deliver and support contracted services, meet legal and accounting obligations, secure our own systems, and send relevant material where you have asked to receive it or where we have a legitimate interest in contacting a business audience. You can withdraw marketing consent at any time using the unsubscribe link in every email.

Who we share it with

We share personal information with sub-processors who support delivery, such as cloud hosting, email delivery, service management and CRM platforms, each under a written data processing agreement. Our current sub-processor list is available in the Trust Centre. We disclose information to regulators or law enforcement only where legally compelled, and we never sell personal information.

Where it is held

Client data is stored in the region closest to the client's operations, with residency commitments recorded in the applicable Data Processing Agreement. Where a transfer crosses a border, we rely on a recognised transfer mechanism such as Standard Contractual Clauses or the UK International Data Transfer Addendum.

How long we keep it

Enquiry and marketing records are retained for up to 24 months from last contact unless you ask us to erase them sooner. Contractual and financial records are retained for the period required by tax and company law in the relevant jurisdiction. Client service data is retained for the contract term and securely destroyed on termination in line with our data disposal policy.

Your rights

You may request access to the personal information we hold about you, ask for it to be corrected or erased, object to or restrict processing, request a portable copy, and withdraw consent. Requests are acknowledged and answered within 30 days. Contact our Information Officer through the contact page. If you are not satisfied with our response, you may complain to the Information Regulator (South Africa), the Information Commissioner's Office (United Kingdom) or the Data Protection Commission (Ireland).

Security

Personal information is protected by access control, encryption in transit and at rest, logging and monitoring through our security operations capability, and staff training. Full detail on our controls sits in the Trust Centre.

Categories of personal information we hold

Personal information is normally collected directly from job applicants, employees, clients and potential clients. Subject to applicable law, we may also use other sources to obtain relevant personal information about you.

  • Identification data: name, surname, gender, photograph, date of birth, identification number and language.
  • Contact details: home address, telephone, email addresses and emergency contact details.
  • Employment details: employment history, performance and disciplinary records, grievance procedures, and sickness or holiday records.
  • Educational and professional background: academic and professional qualifications, education, CV, reference letters and interview notes.
  • Family information: spouse, beneficiary and dependant information, and marital status.
  • Financial information: banking details, tax information, payroll information, salary, benefits, expenses and company allowances.
  • IT information: information required to provide access to our systems and networks, such as IP addresses, log files, login information and software or hardware inventories.
  • Automatically collected data when you visit our website, and information from trusted third parties such as recruitment references and employment records.

Is supplying information voluntary or mandatory?

Supplying certain types of information is mandatory in terms of legislation and regulation. Where personal information is collected under a particular law authorising or requiring the collection, we take steps to make you aware of that at the point of collection.

Your rights as a data subject

Under POPIA, GDPR and UK GDPR you hold the following rights, which you may exercise at any time through our Information Officer:

  • Right to be notified that personal information about you is being collected, and that your personal information has been accessed or acquired by an unauthorised person.
  • Right of access: to establish whether we hold personal information about you and to request access to it, using the prescribed request for access to record form.
  • Right to correction, destruction or deletion of your personal information where necessary.
  • Right to object, on reasonable grounds relating to your particular situation, to the processing of your personal information, and to object at any time to direct marketing, including direct marketing by unsolicited electronic communication.
  • Right not to be subject, in certain circumstances, to a decision based solely on automated processing intended to provide a profile of you.
  • Right to complain to the Regulator regarding alleged interference with the protection of personal information, to complain in respect of an adjudicator's determination, and to institute civil proceedings.

Exercising your right of access

Submit an access request using our online request form. It captures everything the prescribed PAIA request form requires, and it routes straight to our Information Officer. We acknowledge the request, confirm the outcome and set out any fees payable in writing before releasing records.

Complaint process and contact particulars

If you believe we have not replied to your access request or have not handled your personal information reasonably, raise your concerns first with our Information Officer. You may also complain to the Information Regulator.

Telephone: South Africa +27 87 231 0311 | United Kingdom +44 20 3890 5455 | Ireland +353 6 154 8017. Email: compliance@numata.co.

Objections and correction or deletion requests are submitted through the forms below. Our conduct standards, including our position on facilitation payments, are set out in the Business Conduct and Ethics policy.

Processing client data under GDPR

Where Numata processes personal data on a client's behalf when performing its obligations under an agreement, the client is the data controller and Numata is the data processor, as those terms are defined in the applicable Data Protection Legislation.

Personal data may be transferred or stored outside the EEA, or outside the country where the client is located, in order for Numata to carry out the services. The client ensures it has the necessary consents and notices in place to enable the lawful transfer of personal data to Numata for the duration and purposes of the agreement.

  • We process personal data only on the client's written instructions, unless required to process by applicable law, in which case we notify the client first where the law permits.
  • We do not transfer personal data outside the EEA unless appropriate safeguards are in place, the data subject has enforceable rights and effective legal remedies, and an adequate level of protection is provided.
  • We follow reasonable instructions notified to us in advance by the client with respect to the processing of the personal data.
  • We notify the client without undue delay on becoming aware of a personal data breach.
  • At the written direction of the client we delete or return personal data and copies of it on termination of the agreement, unless applicable law requires us to retain it.
  • We maintain complete and accurate records and information to demonstrate compliance with the legislation.
  • Where the client agrees to us appointing a third party, we contract with that third-party processor on terms substantially the same as those set out here.
  • Where personal information is transferred outside the Republic of South Africa to third-party service providers, we take steps to ensure it receives the same level of protection as if it had remained within the Republic.
  • Personal information is treated in accordance with the eight conditions for the lawful processing of personal information under POPIA.

When we may disclose your information

  • Service providers: third-party vendors, technology and service providers, contractors or agents who perform functions on our behalf, permitted to use the information only as needed for those functions and subject to contractual restrictions and security measures.
  • In response to legal process: to comply with the law, a legal proceeding, a court order, a subpoena or other legal process.
  • To protect us and others: where necessary to investigate, prevent or act on illegal activity, suspected fraud, potential threats to any person's safety, or breaches of this notice, or as evidence in litigation.
  • Legal obligation: to carry out obligations arising from current legislation and legal process.
  • We may also process your information where we need to protect your interests or someone else's interests, or where processing is in the public interest or for official purposes.

Which law applies to you

Numata operates in five jurisdictions and the rules that apply depend on where you and the contracting entity are located. The regional notices page sets out the specific regime, regulator and additional rights for each market.

  • South Africa: POPIA, regulated by the Information Regulator.
  • United Kingdom: UK GDPR and the Data Protection Act 2018, regulated by the ICO.
  • Ireland and the EU: GDPR, regulated by the Data Protection Commission.
  • United States: state privacy law, currently the CCPA and CPRA in California and equivalent statutes in other states.
  • Hong Kong: the Personal Data (Privacy) Ordinance, overseen by the PCPD.

Questions about our policies or a procurement pack?

Contact us