Data protection in each market we serve.
Numata contracts through local entities in South Africa, the United Kingdom, Ireland, the United States and Hong Kong. This notice sets out the regime, the regulator and the additional rights that apply in each market.
- Five
- SCCs and UK IDTA
- Never
- Annual
- July 2026
On this page
Applies to South Africa, United Kingdom, Ireland, United States and Hong Kong.
How to read this notice
Our privacy policy explains what we collect and why. This notice adds the jurisdiction specific detail: which law governs the relationship, who regulates us, and what extra rights you can exercise. The entity named in your contract is the controller for that relationship. Where we operate technology for you, the Data Processing Agreement governs and takes precedence over these pages.
The contracting entities
South Africa: Numata Business (Pty) Ltd, company registration number 2010/017558/07.
United Kingdom and Ireland: Numata Business IT Limited.
United States and Hong Kong: Numata Business IT LLC.
The entity named on your agreement is the controller or operator for that relationship. Registration numbers and registered office addresses for entities outside South Africa are confirmed in the signed agreement and in the procurement pack available on request.
South Africa
Processing by Numata Business (Pty) Ltd, company registration number 2010/017558/07, is governed by the Protection of Personal Information Act 4 of 2013. We operate as a responsible party for our own records and as an operator where we process client data on instruction. A registered Information Officer handles data subject requests, PAIA requests and engagement with the Information Regulator. Details of the PAIA process are on the PAIA and POPIA page. Complaints can be made to the Information Regulator of South Africa.
United Kingdom
Processing by Numata Business IT Limited is governed by the UK GDPR and the Data Protection Act 2018. You have the right of access, rectification, erasure, restriction, objection and portability, and the right not to be subject to solely automated decisions with legal effect. We do not make such decisions about individuals. Marketing to individuals follows PECR, which is why analytics and marketing cookies are set only after consent. Complaints go to the Information Commissioner's Office. Personal data leaving the UK moves under the UK International Data Transfer Addendum to the Standard Contractual Clauses.
Ireland and the European Union
Processing for Irish and wider EU clients, contracted through Numata Business IT Limited, is governed by the EU GDPR and the Data Protection Act 2018 (Ireland). The same data subject rights apply as in the UK. Our lead supervisory authority for EU processing is the Data Protection Commission. Transfers out of the EEA rely on the European Commission's Standard Contractual Clauses with a transfer risk assessment where required. Where we deploy or manage AI systems for EU clients, the roles and obligations under the EU AI Act are recorded in the engagement documentation and reflected in the AI pledge in the Trust Centre.
United States
Processing for United States clients is contracted through Numata Business IT LLC. There is no single federal privacy statute, so obligations follow state law. Where the California Consumer Privacy Act as amended by the CPRA applies, you may request the categories and specific pieces of personal information we hold, request deletion or correction, and opt out of sale or sharing. Numata does not sell personal information and does not share it for cross context behavioural advertising, so no opt out mechanism is required. We do not discriminate against anyone who exercises a privacy right. Comparable rights under other state statutes, including Virginia, Colorado, Connecticut, Utah and Texas, are honoured on the same basis. Sector specific obligations, such as HIPAA business associate terms, are handled contractually where an engagement requires them.
Hong Kong
Processing by Numata Business IT LLC is governed by the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles. You may request access to and correction of your personal data and we will respond within 40 days as the Ordinance requires. We use personal data only for the purpose for which it was collected or a directly related purpose, and we do not use it for direct marketing without your consent. The Office of the Privacy Commissioner for Personal Data oversees compliance and receives complaints.
Cross border transfers
We keep client data in the region closest to the client's operations and record residency commitments in the Data Processing Agreement. Where our global service desk or security operations capability needs access from another region, that access is controlled, logged and covered by intra-group agreements incorporating the Standard Contractual Clauses or the UK Addendum, with equivalent safeguards for South African and Hong Kong transfers.
Exercising your rights
Send any request through the contact page and name the country you are writing from so we route it to the right entity and regulator timeline. We acknowledge on receipt, verify identity proportionately, and respond within the statutory period for that jurisdiction. There is no charge unless a request is manifestly unfounded or excessive, or unless a prescribed PAIA fee applies.
Status of this page
This page is maintained by Numata to describe our own practices. It is not legal advice, an independent audit or a certification. Entity registration details, the appointed representatives for each market and any sector specific terms are confirmed in the signed agreement and the procurement pack available on request.
