Data Privacy and Handling

How we protect your data.

Numata is committed to compliance with POPIA, GDPR and UK GDPR. Our policies, procedures and employee training are designed to safeguard the confidentiality, integrity and availability of personal data.

Compliant
GDPR and UK GDPR
Compliant
POPIA
DSR response
Within 30 days
Model training
Never on client data
Policies and practice

How personal data is handled.

  • Lawful basis for processing

    We process personal data only where we have a lawful basis: contract performance, legitimate interest, legal obligation or explicit consent. We never sell personal data to third parties.

  • Data residency

    Client data is stored in the region closest to the client's operations, with data residency commitments documented in the applicable Data Processing Agreement. Specific hosting regions (for example Azure South Africa, EU and UK) are confirmed per engagement.

  • Encryption standards

    Personal data is protected through secure storage, access controls and encryption practices governed by Numata's Encryption Policy. Specific algorithms, key management and TLS versions are confirmed under the applicable Data Processing Agreement and internal Encryption Policy.

  • Data retention

    We retain client data only for as long as required to deliver services or meet legal obligations. Retention periods are defined per data category and documented in our retention schedule. Data is securely deleted upon contract termination.

  • Breach notification

    Numata's Incident Management and Response plan covers detection, containment, assessment, notification and remediation. Notification to affected clients follows GDPR, UK GDPR and POPIA requirements, with the CISO leading the coordinated response.

  • Data subject rights

    We support all data subject rights including access, rectification, erasure, portability and objection. Requests are processed within 30 days. Contact our Information Officer to exercise your rights.

Regulatory alignment

What compliance means in practice.

GDPR

  • Lawful basis documented for all processing
  • Data Processing Agreements with sub-processors
  • Breach notification aligned to regulatory timelines
  • Privacy impact assessments conducted where required
  • Cross-border transfer mechanisms confirmed per engagement

POPIA

  • Information Officer responsibilities assigned
  • Conditions for lawful processing satisfied
  • Data subject participation rights supported
  • Security safeguards aligned to CIS Controls
  • Retention and destruction governed by Electronic Data Disposal Policy