At a glance
We collect only what we reasonably need.
Website enquiries are validated and sent to our business mailbox rather than written to an enquiry database. The private client portal stores only the account and project information needed to provide protected draft access. We do not sell personal information, and the current website does not use advertising or analytics trackers.
1. Who we are and when this notice applies
HS Digital is a division of Humelela Swinene Group. Humelela Swinene Group remains the responsible party for personal information processed through this website and in connection with enquiries, quotations, website services, business email services and ongoing digital support.
This notice applies to website visitors, prospective customers, customers, customer representatives, suppliers and other people who communicate with us. It should be read together with any service agreement or specific notice provided for a particular project.
2. Personal information we may collect
Information you provide
- Your name, company name and role or relationship to a business.
- Your email address, telephone number and other contact details.
- The service you are interested in and the content of your enquiry.
- Correspondence sent by email, telephone or WhatsApp.
- Project, domain, mailbox, technical-support and account information reasonably required to deliver services you request.
- Client-portal account details, including your login email, securely hashed password and projects assigned to your account.
- Website drafts, project descriptions and related files made available through the private client portal.
- Quotation, contract, billing and transaction records where you become a customer.
Information recorded automatically
Our hosting infrastructure may create technical and security logs containing information such as an internet protocol (IP) address, browser or device type, requested page, date and time, referring page and error or security events. We use this information to operate, secure and troubleshoot the website.
Information from other sources
We may receive business contact information from your employer, an authorised representative, a referral source or a service provider involved in a project. We will use it only for a relevant business or service purpose.
3. Why and on what basis we use personal information
Depending on the circumstances, POPIA allows us to process information with your consent, to take steps at your request before entering into a contract, to perform a contract, to comply with a legal duty, or to pursue a legitimate interest that does not unjustifiably interfere with your privacy.
We may use personal information to:
- Receive, assess and respond to an enquiry.
- Recommend services and prepare a quotation or proposal.
- Set up, deliver, administer and support contracted services.
- Manage customer relationships, service requests and account changes.
- Create and administer private client-portal accounts, authenticate users and provide access to assigned website drafts.
- Allow customers to review draft websites securely before approval and public launch.
- Protect the website, email systems, customers and business against misuse, fraud or security threats.
- Keep appropriate business, financial, contractual and support records.
- Comply with tax, accounting, regulatory or other legal obligations.
- Establish, exercise or defend legal claims.
- Improve our services and the usability and reliability of the website.
Fields marked as required on a form are needed for us to review and respond to the request. If required information is not provided, we may be unable to respond or supply the requested service.
We will send direct marketing only where permitted by law. You may object or unsubscribe at any time. We do not use personal information for automated decision-making that produces legal or similarly significant effects.
4. When personal information may be shared
We do not sell or rent personal information. We may disclose limited information where reasonably necessary to:
- Website-hosting, email, domain, cloud, security and technical-support providers, including our current hosting provider, Xneelo.
- Service providers or subcontractors assisting with a customer-approved project.
- Accountants, auditors, insurers, legal advisers and other professional advisers.
- Regulators, law-enforcement bodies, courts or public authorities where disclosure is required or permitted by law.
- A successor or prospective purchaser in connection with a lawful business reorganisation, subject to appropriate confidentiality safeguards.
Service providers acting for us are expected to process information only for the agreed purpose and to apply appropriate security and confidentiality measures.
Processing outside South Africa
Some technology or cloud providers may process or store information outside South Africa. Where a cross-border transfer occurs, we will take reasonable steps to ensure that POPIA’s requirements for international transfers are met, including appropriate contractual or legal safeguards where required.
5. Cookies, logs and external services
The current website does not intentionally use advertising cookies, behavioural profiling or analytics trackers. The client portal uses an essential, temporary session cookie to keep an authorised user signed in and protect account actions. This cookie is not used for advertising and expires when the browser session ends. Basic technical information may still be recorded in hosting and security logs as described above.
If non-essential analytics or marketing technology is introduced in future, this notice and any required consent mechanism will be updated before that technology is used.
The website contains links to third-party services, including WhatsApp. When you follow an external link, that provider processes information under its own privacy terms. We are not responsible for a third party’s website or privacy practices.
6. How long we keep information
We retain personal information only for as long as it is reasonably needed for the purpose for which it was collected, for an ongoing customer relationship, to meet legal or contractual duties, to resolve disputes, or to establish or defend claims.
- General enquiries that do not become an active customer relationship are periodically reviewed and ordinarily retained for no longer than reasonably necessary to follow up the enquiry.
- Customer, project, support, contract and transaction records may be kept for the duration of the relationship and for the applicable legal or recordkeeping period afterwards.
- Client-portal accounts and protected website drafts are retained while they are needed for the project or customer relationship and are removed or deactivated when access is no longer reasonably required.
- Hosting and security logs are generally retained for shorter operational and security periods determined by the relevant system or hosting provider.
When information is no longer required, it is deleted, destroyed, de-identified or archived where continued retention is required by law.
7. How we protect information
We use reasonable organisational and technical safeguards appropriate to the information and the risks involved. These may include access controls, securely hashed portal passwords, private draft storage outside the public website directory, session protection, upload validation, secure hosting, malware and spam controls, software updates, backups, confidentiality duties and limiting access to people who need the information.
No internet or email transmission can be guaranteed to be completely secure. If we become aware of a security compromise affecting personal information, we will investigate, contain and address it and make notifications required by POPIA.
8. Your rights under POPIA
Subject to POPIA and any lawful limitations, you may:
- Ask whether we hold personal information about you.
- Request access to personal information we hold about you.
- Ask us to correct information that is inaccurate, incomplete, misleading or out of date.
- Ask us to delete or destroy information that we are no longer authorised to retain.
- Object to processing in appropriate circumstances.
- Withdraw consent where processing depends on consent, without affecting earlier lawful processing.
- Object to direct marketing and ask not to receive future marketing messages.
- Complain to the Information Regulator if you believe your information has been handled unlawfully.
We may need to verify your identity before acting on a request. We will respond within the period required by applicable law and will explain if a request cannot be fulfilled in full.
The Information Regulator provides official POPIA forms and guidance, including forms to object to processing or request correction or deletion.
9. Children’s information
This website and our services are directed to businesses and adults. We do not knowingly request personal information from children through the website. A parent or guardian who believes a child has provided information should contact us so that we can investigate and take appropriate action.
10. Changes to this notice
We may update this notice when our services, technology, providers or legal obligations change. The latest version will be published on this page with an updated date. Material changes may also be communicated through an appropriate additional notice.
11. Contact us or lodge a complaint
For privacy questions or to exercise a POPIA right, contact our privacy or Information Officer contact point:
If your concern is not resolved, you may lodge a complaint with the Information Regulator (South Africa) through its official complaints page, by email at POPIAComplaints@inforegulator.org.za, or by calling 010 023 5200.
You can read the full Protection of Personal Information Act 4 of 2013 on the South African Government website.