How we protect your data.
Numata is committed to compliance with POPIA, GDPR and UK GDPR. Our policies, procedures and employee training are designed to safeguard the confidentiality, integrity and availability of personal data.
- GDPR and UK GDPR
- POPIA
- Within 30 days
- Never on client data
How personal data is handled.
Lawful basis for processing
We process personal data only where we have a lawful basis: contract performance, legitimate interest, legal obligation or explicit consent. We never sell personal data to third parties.
Data residency
Client data is stored in the region closest to the client's operations, with data residency commitments documented in the applicable Data Processing Agreement. Specific hosting regions (for example Azure South Africa, EU and UK) are confirmed per engagement.
Encryption standards
Personal data is protected through secure storage, access controls and encryption practices governed by Numata's Encryption Policy. Specific algorithms, key management and TLS versions are confirmed under the applicable Data Processing Agreement and internal Encryption Policy.
Data retention
We retain client data only for as long as required to deliver services or meet legal obligations. Retention periods are defined per data category and documented in our retention schedule. Data is securely deleted upon contract termination.
Breach notification
Numata's Incident Management and Response plan covers detection, containment, assessment, notification and remediation. Notification to affected clients follows GDPR, UK GDPR and POPIA requirements, with the CISO leading the coordinated response.
Data subject rights
We support all data subject rights including access, rectification, erasure, portability and objection. Requests are processed within 30 days. Contact our Information Officer to exercise your rights.
What compliance means in practice.
GDPR
- Lawful basis documented for all processing
- Data Processing Agreements with sub-processors
- Breach notification aligned to regulatory timelines
- Privacy impact assessments conducted where required
- Cross-border transfer mechanisms confirmed per engagement
POPIA
- Information Officer responsibilities assigned
- Conditions for lawful processing satisfied
- Data subject participation rights supported
- Security safeguards aligned to CIS Controls
- Retention and destruction governed by Electronic Data Disposal Policy
