Legal

POPIA Compliance Statement

Protection of Personal Information Act 4 of 2013  |  Last updated: 4 June 2026

1. Introduction

Vectra Networks (Pty) Ltd (registration number 2026/349762/07) is committed to protecting the personal information of all individuals whose information we collect, process, and store. This statement outlines our compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), which regulates the processing of personal information in South Africa.

As a responsible party under POPIA, we take our obligations seriously and have implemented comprehensive measures to ensure lawful, fair, and responsible handling of personal information.

2. Our Commitment to POPIA

Vectra Networks is committed to complying with the eight conditions for lawful processing of personal information as set out in Chapter 3 of POPIA:

  • Accountability: We accept responsibility for all personal information under our control
  • Processing Limitation: We collect and process personal information lawfully and minimally
  • Purpose Specification: We collect information for specific, explicitly defined purposes
  • Information Quality: We ensure personal information is accurate, complete, and up to date
  • Openness: We notify individuals about our information practices
  • Security Safeguards: We implement appropriate technical and organisational security measures
  • Data Subject Participation: We respect individuals' rights to access and correct their information

3. Information Officer

In terms of Section 55 of POPIA, Vectra Networks has designated an Information Officer responsible for ensuring compliance with POPIA and handling data subject requests and queries.

Information Officer: Vectra Networks Information Officer

Email: info@vectranetworks.com

Address: The Atrium, Cnr Maude & 5th Street, Sandton City, 2196, South Africa

The Information Officer is responsible for:

  • Encouraging compliance with POPIA within the organisation
  • Handling requests from data subjects regarding their personal information
  • Working with the Information Regulator in relation to investigations
  • Ensuring awareness and training on POPIA compliance

4. What Personal Information We Process

In the course of our business operations, we may process the following categories of personal information:

  • Contact Information: Names, addresses, phone numbers, email addresses
  • Identity Information: Identity numbers, passport numbers, date of birth
  • Employment Information: Employment history, qualifications, CVs, references
  • Financial Information: Banking details and payment information where applicable
  • Service Usage Information: Data related to your use of our products and services
  • Technical Information: IP addresses, browser information, device identifiers

5. Lawful Basis for Processing

We process personal information only when we have a lawful basis under POPIA, which may include:

  • Consent of the data subject
  • Processing necessary to carry out actions for the conclusion or performance of a contract
  • Processing necessary for compliance with a legal obligation
  • Processing necessary to protect a legitimate interest of the data subject
  • Processing necessary for pursuing legitimate interests of the responsible party or a third party

6. How We Protect Personal Information

We have implemented appropriate technical and organisational measures to protect personal information against:

  • Loss, damage, or unauthorised destruction
  • Unlawful access or processing

Our security measures include, but are not limited to:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and vulnerability testing
  • Employee training on data protection practices
  • Incident response and breach notification procedures
  • Secure data storage and backup systems

7. Data Subject Rights Under POPIA

POPIA grants data subjects the following rights in relation to their personal information:

  • Right to Access: Request confirmation of whether we hold personal information about you and request access to that information
  • Right to Correction: Request correction of inaccurate, misleading, or incomplete personal information
  • Right to Deletion: Request destruction or deletion of personal information in certain circumstances
  • Right to Object: Object to the processing of personal information in certain circumstances
  • Right to Complain: Lodge a complaint with the Information Regulator regarding alleged interference with the protection of your personal information

To exercise any of these rights, please contact our Information Officer at info@vectranetworks.com.

8. Processing of Special Personal Information

Special personal information includes information relating to race, ethnic origin, trade union membership, political opinions, religious or philosophical beliefs, health, sex life, biometric information, and criminal behaviour. We do not generally process special personal information unless:

  • Processing is necessary for the establishment, exercise, or defence of a right or obligation in law
  • Processing is for historical, statistical, or research purposes
  • Processing is with the consent of the data subject
  • Another exception under Section 27 of POPIA applies

9. Cross-Border Data Transfers

We only transfer personal information to third parties in foreign jurisdictions where:

  • The recipient is subject to a law, binding corporate rules, or binding agreement providing adequate protection
  • The data subject has consented to the transfer
  • The transfer is necessary for the performance of a contract between the data subject and our organisation
  • The transfer is in the interest of the data subject and consent cannot be obtained in a reasonable time

10. Data Breach Notification

In the event of a data breach that poses a risk to the rights and freedoms of data subjects, we will:

  • Notify the Information Regulator as soon as reasonably possible after discovery
  • Notify affected data subjects where required by law
  • Take immediate steps to contain and mitigate the breach
  • Document the breach and our response for compliance purposes

11. Direct Marketing

We will only send you direct marketing communications where we have obtained your consent or where we have an existing relationship and the marketing relates to similar products or services. You may opt out of receiving marketing communications at any time by:

12. Record Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. When personal information is no longer needed, we securely destroy or de-identify it in accordance with our data retention policies.

13. Complaints to the Information Regulator

If you believe we have not adequately protected your personal information or complied with POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa:

Website: inforegulator.org.za

Email: inforeg@justice.gov.za

Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

14. Changes to This Statement

We may update this POPIA Compliance Statement from time to time to reflect changes in our practices or legal requirements. Updates will be posted on this page with a revised effective date.

15. Contact Us

For any questions regarding this POPIA Compliance Statement or our data protection practices, please contact us:

Email: info@vectranetworks.com

Address: The Atrium, Cnr Maude & 5th Street, Sandton City, 2196, South Africa

Company Registration: 2026/349762/07