Skip to content

Legal

Privacy policy.

What personal information we hold, why we hold it, who else gets to see it and what you can make us do about it — under the Protection of Personal Information Act. Including the one place we cannot keep your details private, and why.

Last updated

1.Who is responsible for your information

WiseGuy Design is the responsible party for the personal information described in this policy, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains what we collect, why, who else sees it, how long we keep it, and what you can require us to do about it.

Responsible party
WiseGuy Design
Registration number
2021/671559/07
Information Officer
Guilio Del Fava
Address
1a Pagoda Street, Salisbury Park, Gqeberha, 6070
Place of business
Gqeberha, South Africa
Email
hello@wiseguydesign.co.za
Telephone
+27 71 613 7767

Write to the Information Officer at hello@wiseguydesign.co.za about anything in this policy, including a request to see, correct or delete what we hold.

2.What this policy covers

This policy covers personal information we collect through this website, through our customer portal, and in the course of providing hosting, domain registration and design and development services.

It does not cover information you host on our servers about your own customers. There, you are the responsible party and we act as your operator — we process it only on your instruction, we do not use it for our own purposes, and the duties to secure it and to report a breach of it are yours. See Privacy and personal information in our terms.

3.What we collect

Information you give us

Account
Your name, email address, telephone number and, where you are buying on behalf of a business, its name and registration number.
Billing
Your billing address and the details that appear on your invoices. Not your card number — see Payments below.
Domain registrant
The registrant name, address, email and telephone number required by the registry for each domain you register. See Domains below, which is the part of this policy most worth reading.
Correspondence
What you send us by email, through the contact form or in a support request, including anything you choose to put in it.
Project material
For design and development work, the content, images, credentials and material you send us to build with.

Information collected automatically

Server logs
Your IP address, the pages requested, timestamps, the referring page and your browser's user agent. Standard web server logs, kept for security and troubleshooting.
Cookies
A session cookie when you sign in, a small preference cookie for your light or dark theme, and analytics cookies where you allow them. See Cookies below.
Service telemetry
Resource usage on your hosting account — storage, bandwidth, mail volume — which is how we bill accurately and spot a compromised account.

We do not collect special personal information as defined in section 26 of POPIA — health, religion, race, political or trade union affiliation, biometrics or criminal history. Please do not send it to us; if you do, we will delete it.

4.Why we process it, and on what basis

Section 11 of POPIA requires a lawful basis for every processing activity. Ours are set out below, so you can see which is which rather than being asked to take consent as the answer for everything.

To provide what you bought
Creating your account, provisioning hosting, registering and renewing domains, delivering project work, and supporting all of it. Basis: necessary to perform our agreement with you — section 11(1)(b).
To bill you
Raising invoices, taking payment, chasing an unpaid account. Basis: performance of the agreement, and our legitimate interest in being paid — sections 11(1)(b) and 11(1)(f).
To send service messages
Renewal notices, expiry warnings, maintenance windows, security advisories and changes to our terms. These are not marketing and you cannot unsubscribe from them while you hold a service — a domain expiry notice you did not receive is precisely the harm the notice exists to prevent. Basis: performance of the agreement.
To keep the service secure
Detecting abuse, investigating compromised accounts, rate limiting, blocking attacks. Basis: our legitimate interest, and our obligation under section 19 of POPIA to secure the information we hold.
To meet legal obligations
Keeping accounting records, responding to a lawful request from an authority, complying with registry and ICANN requirements. Basis: compliance with a legal obligation — section 11(1)(c).
To send marketing
Occasional email about our services. Basis: your consent, or the existing-customer exception in section 69(3) of POPIA. Always with an unsubscribe link. See Marketing.

5.Domain registration and public records

This section deserves its own heading because it is the one place where information you give us is deliberately made public, and where we cannot promise otherwise.

Registering a domain requires us to send the registrant's contact details — name, address, email, telephone number — to a registrar and then to the registry that operates the extension. This is a condition of registration set by the registry, not a choice we make. We cannot register a domain without it and we cannot register one under false details on your behalf.

Registries operate a public lookup service (WHOIS, or RDDS for newer extensions). How much of your information appears there depends on the extension:

  • .co.za and other .za extensions publish registrant and contact details in the ZACR WHOIS. Some fields are redacted; the registrant name and email are generally visible.
  • .com, .net and most gTLDs redact most personal fields for natural persons following ICANN's Temporary Specification and subsequent policy, and publish an anonymised forwarding address instead. Organisation names are often still published.

Registries and registrars are independent responsible parties for the information they hold. Their retention periods, their disclosure obligations and their dispute processes are theirs. Once a registration is made, we cannot retract the details from the registry, and deleting your account with us does not delete the registrant record for a domain you still own.

Some registries and registrars offer a paid privacy or proxy service that substitutes their details for yours in the public record. Where one is available for an extension you are registering, ask us and we will tell you what it covers and what it costs.

Registries and registrars are also required to disclose registrant details in response to a valid dispute, court order or law enforcement request. We will comply with those requests where they are lawful, and we will tell you that we have unless we are prohibited from doing so.

6.Payments

Card and instant-EFT payments are processed by PayFast, a South African payment gateway certified to PCI DSS Level 1.

We never see your card details. They are entered on PayFast's own pages, on PayFast's systems. Nothing on this website receives, transmits or stores a card number, expiry date or CVV, and there is no field anywhere in our systems that could hold one.

What we receive back from PayFast is a notification that a payment of a stated amount succeeded or failed, its payment reference, and the payment method used. We keep those, linked to your order, because they are our record that an invoice was paid.

PayFast is an independent responsible party for the information you give it. Its own privacy policy governs that, and it is worth reading if you would like to know how long it keeps a card on file for a recurring payment.

7.Who else sees your information

We do not sell personal information, and we do not share it for anyone else's marketing. We share it only with the parties we need to in order to run the service:

Registrars and registries
Registrant details, as described in Domains above. Required for registration.
PayFast
The information needed to take a payment, as described in Payments above.
Hosting and infrastructure providers
Our servers, database and file storage are operated by third-party providers under contract. They hold the data at rest and are contractually bound to process it only on our instruction.
Email delivery providers
The services that send our transactional email — invoices, renewal notices, password resets — see the recipient address and the content of the message.
Analytics
Aggregate usage statistics, where you have allowed analytics cookies. See Cookies.
Gravatar
If you have not uploaded a profile picture, we ask Gravatar — a service run by Automattic — whether one exists for your email address. We send a one-way hash of the address and nothing else, and we make that request from our own server: your browser never contacts Gravatar, so your IP address and the page you were reading are not disclosed to them. Upload a picture and no request is made at all.
Google reCAPTCHA
Our booking form, sign-in, registration, password and checkout forms are protected against automated abuse by reCAPTCHA v3, a service run by Google. When you open one of those forms your browser loads Google's script, which observes how the page is used — mouse movement, typing rhythm, timing — and sets a cookie. On submit it returns a score for how likely the request came from a person, and we send that score, your IP address and the name of the form to Google to be checked. We are told a number between 0 and 1. We are not told how it was arrived at, and we receive nothing else about you. Google's privacy policy and terms govern what they do with it. Only the forms listed above are affected — reading the site runs none of this.
Google AdSense
Our public pages carry advertising supplied by Google AdSense. Where you have allowed advertising cookies, your browser loads Google's script and Google may set cookies to choose which ads you are shown and to count how often an ad is seen or clicked — including, in Google's case, ads chosen using what it knows about you from elsewhere. Where you have not, the ads still appear but are chosen without that: we signal your refusal to Google before its script loads, using Consent Mode, and it serves non-personalised ads instead. Nothing about you travels from us to Google for this — we send no email address, no account, no order and no page of your own. You can review and change what Google uses across every site at My Ad Center, and Google's privacy policy and advertising terms govern the rest. The signed-in parts of this site — your account, your invoices, the checkout and any quote sent to you by link — carry no advertising and load none of this.
Meta and TikTok advertising pixels
Our public pages carry two advertising pixels: the Meta Pixel, which reports to Facebook and Instagram which of our pages your browser opened, and the TikTok Pixel, which does the same for TikTok. We use them for two things: to tell whether an advert we paid for led to a visit, and to build an audience so that our adverts can be shown again to people who have read a particular page. Where you have allowed advertising cookies, your browser loads their scripts and each sets a cookie of its own. Where you have not, neither script is fetched at all — the code that would load them sits on the page and waits for your answer, so until you give one your browser makes no request to Meta or TikTok, they are never told your IP address or which page you are reading, and neither sets a cookie. Change your mind later from Cookie settings in the footer and whichever has loaded is told to stop. Unlike the advertising above, these display nothing — there is nothing to see on the page either way, which is exactly why they are worth naming here. We send neither network an email address, an account, an order or anything you typed into a form: only that a browser opened a page, and which page. Meta's privacy policy and TikTok's privacy policy govern what each does with that, and the ad preferences inside your Facebook, Instagram or TikTok account are where you can see and limit it. The signed-in parts of this site — your account, your invoices, the checkout and any quote sent to you by link — load none of this.
Professional advisers
Our accountant and, if ever needed, our attorneys — under professional duties of confidentiality.
Authorities
Where we are required by law, by a court order, or by a valid law enforcement request. We satisfy ourselves that a request is lawful before acting on it, and we will tell you unless we are prohibited from doing so.
A purchaser of the business
If the business is ever sold or reorganised, customer records would transfer with it. You would be told, and this policy would continue to apply until you were given notice of a new one.

Every provider above that processes personal information on our behalf is an operator under section 21 of POPIA, bound by a written contract to process it only on our instruction and to secure it. Four are not, and we would rather say so than leave you to work it out. Gravatar we have no agreement with, which is precisely why we send them a hash rather than your address and make the request ourselves rather than from your browser. Google is the second, and it is an independent responsible party under its own terms — not our operator — in both of the roles it plays here. For reCAPTCHA the mitigation is narrowness: it runs on eight forms and nowhere else, it is never loaded by a page you are only reading, and the only thing it tells us is a score. For AdSense it cannot be narrowness, because advertising is on the public pages generally, so it is two other things instead — your refusal reaches Google before its script runs rather than after, and the flow is one-way: Google learns which page of ours a browser opened, and we learn nothing about you in return. What we are paid is a monthly total, not a record of who saw what. Meta and TikTok are the third and fourth, independent responsible parties on the same footing. Their mitigation is AdSense's shape taken one step further: your refusal reaches each pixel before it is started rather than after, so on an Essential only visit nothing is sent at all rather than being sent without personalisation. The flow is one-way here too — each learns that a browser opened a page of ours, and tells us nothing about you in return. What comes back to us is a count.

8.Information that leaves South Africa

Some of the providers we depend on operate outside South Africa, and your information may be stored or processed abroad — commonly in the European Union or the United States.

Section 72 of POPIA permits this where one of a defined set of conditions is met. We rely on these: the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA; or the transfer is necessary to perform our agreement with you; or you have consented.

In practice this means our providers are contractually bound to standards at least equivalent to those POPIA requires of us, and we check that before we choose one.

9.Cookies

This site uses five kinds of cookie.

Strictly necessary
A session cookie that keeps you signed in to your account, and the token that protects forms against cross-site request forgery. The site cannot work without these and they are not used for anything else.
Preference
A small cookie remembering whether you chose the light or dark theme, so the page does not flash the wrong one on load.
Security
A cookie set by Google reCAPTCHA on the booking, sign-in, registration, password and checkout forms, used to tell a person from a script. It is set by Google rather than by us, only on those forms, and never on a page you are only reading. See Google reCAPTCHA above.
Analytics
Where enabled and where you have allowed them, cookies set through Google Tag Manager that tell us which pages are read and where visitors arrive from, in aggregate. We use this to decide what to write next, not to identify individuals.
Advertising
Where you have allowed them, cookies set by Google to choose which advertisements you are shown on our public pages and to measure them, and cookies set by Meta and by TikTok recording that your browser opened a page of ours, so that our adverts on Facebook, Instagram and TikTok can be measured and shown to you again. These are set by Google, Meta and TikTok, not by us, and we cannot read any of them. Refusing means two different things, so we will not collapse them into one: the advertising on our pages stays where it is and loses only its personalisation, while the two pixels send nothing at all. All are told before their scripts run rather than after. See Google AdSense and Meta and TikTok advertising pixels above. No page you reach by signing in carries any of this.

Analytics and advertising cookies are off until you allow them. On your first visit a banner asks, and the answer is applied before Google's scripts run rather than after. Choosing Essential only leaves everything except those two categories untouched: the site works exactly as it did, the advertising is still there but is chosen without anything Google knows about you, and nothing at all is reported to Meta or TikTok. You can change your mind at any time from Cookie settings in the footer at the bottom of any page — and the choice is stored in your own browser, so clearing your browsing data asks you again.

Every browser lets you block or delete cookies, usually under Privacy or Site settings. Blocking strictly necessary cookies will stop you being able to sign in. Blocking the security cookie, or blocking Google's script with an extension, does not lock you out — we would rather let a real person through than turn a privacy setting into a closed door. Blocking the rest costs you nothing but a remembered preference.

We do not act on a browser's Do Not Track header, and we would rather tell you that than leave it implied. No standard ever settled what a site must do when it receives one, most browsers have dropped the setting, and the advertising and analytics scripts described above do not read it — so honouring it here would amount to us saying we had, while nothing changed. The control that does work on this site is the banner: Essential only is read by Google's tags before they load, and it is reachable from Cookie settings in the footer of every page, for as long as you like.

10.Marketing email

Section 69 of POPIA is strict about electronic direct marketing, and rightly. We send marketing email only where you have asked for it, or where you are already a customer, the message is about something similar to what you bought, and you were given the chance to opt out when we first collected your address.

Every marketing email carries an unsubscribe link. Using it takes effect immediately and permanently, and you never need to give a reason. Unsubscribing does not stop the service messages described in Why we process it — those continue for as long as you hold a service with us.

Section 45 of the Electronic Communications and Transactions Act separately entitles you to ask for the identifying particulars of the source from which we obtained your details. Ask at hello@wiseguydesign.co.za and we will tell you.

11.How long we keep it

Section 14 of POPIA says information may not be kept longer than is necessary for the purpose it was collected for, unless a law requires otherwise. Ours:

Account and contact details
For as long as you hold an account, and 12 months after it closes, in case you come back.
Invoices and payment records
Seven years from the end of the tax year they fall in, as required by section 29 of the Tax Administration Act 28 of 2011 and the Companies Act 71 of 2008. This is a legal obligation and a deletion request cannot override it.
Domain registration records
For the life of the registration, plus the retention period the registry itself requires of us. Registries typically require records to be retained for two years after a registration ends.
Support correspondence
Three years, because a question asked about a setup often needs the answer given three years ago.
Server and security logs
90 days, then deleted. Longer only where a log is part of an active security investigation.
Hosting account contents
Deleted on the timeline in Suspension and termination in our terms. Backups roll off within 30 days after that.
Marketing list
Until you unsubscribe. Your email is then kept on a suppression list — the only way to be sure we do not mail you again is to remember that you asked us not to.

12.How we protect it

Section 19 of POPIA requires appropriate technical and organisational measures. What we actually do:

  • Everything on this site and in the customer portal is served over TLS. Data is encrypted in transit, always.
  • Passwords are stored hashed, never in a form anyone here can read.
  • Card details are never in our systems at all — see Payments.
  • Access to customer data is limited to the people who need it to do their work, and is authenticated individually.
  • Every read of a customer's own records is constrained to that customer at the database layer, not only in the application — the check that stops one customer seeing another's invoice does not depend on the page asking nicely.
  • Databases and backups are encrypted at rest by our infrastructure providers.
  • Software and dependencies are patched on a routine schedule, and out of schedule where a vulnerability warrants it.
  • The forms a stranger can reach — booking, sign-in, registration, password resets, checkout — are rate limited and screened for automated abuse. That screening uses Google reCAPTCHA, which is the one part of this list that involves a third party seeing anything about your visit.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a compromise affects your personal information, section 22 of POPIA requires us to notify the Information Regulator and you as soon as reasonably possible after establishing what happened. We will tell you what was affected, what we have done, and what we suggest you do — in plain language, without waiting until we have a complete picture, if waiting would leave you exposed.

13.Your rights

Section 5 of POPIA gives you the following rights over the personal information we hold about you. Exercising any of them is free, except that we may charge the prescribed fee for a copy of a large volume of records.

To be told what we hold
You may ask us to confirm, free of charge, whether we hold information about you, and to describe it. Section 23.
To get a copy
You may request the record itself. We will respond within 30 days. Where a request is complex we may extend that once, and we will tell you why. Section 23, read with the Promotion of Access to Information Act 2 of 2000.
To correct or delete
You may ask us to correct information that is inaccurate, irrelevant, out of date or incomplete, or to delete information we are no longer entitled to keep. Section 24.
To object
You may object at any time, on reasonable grounds, to processing we base on legitimate interest. We stop unless we can show compelling legitimate grounds that override your objection. Section 11(3).
To withdraw consent
Where processing rests on your consent, you may withdraw it at any time. That does not undo processing already done lawfully. Section 11(2).
To stop marketing
Immediately and without reason. Section 69.
To complain
To us, and to the Information Regulator. See below.

Write to hello@wiseguydesign.co.za to exercise any of these. We will ask you to verify your identity first — an access request is exactly the shape of a request an impersonator would make, and confirming who is asking is part of protecting you.

Two honest limits. A deletion request cannot remove a record we are legally required to keep, such as an invoice inside its seven-year retention. And it cannot remove a registrant record already held by a registry — see Domains above.

14.Complaining to the Information Regulator

If you are not satisfied with how we have handled your information or your request, you may complain to the Information Regulator (South Africa). You do not have to come to us first, although we would rather you did.

Website
inforegulator.org.za
General enquiries
enquiries@inforegulator.org.za
POPIA complaints
POPIAComplaints@inforegulator.org.za

Complaints are made on the Regulator's prescribed form, which is available on its website along with its current postal and street address.

15.Children

Our services are sold to businesses and to adults, and are not directed at children. We do not knowingly collect personal information about anyone under 18. Section 34 of POPIA prohibits processing a child's personal information without a competent person's consent, and if we learn that we hold any, we will delete it. Tell us at hello@wiseguydesign.co.za if you believe we do.

16.Automated decisions

We do not make decisions that significantly affect you by automated means alone, as section 71 of POPIA describes. Automated systems do flag things — an unusual login, a spike in mail volume, a payment a fraud filter dislikes — but the decision to suspend an account or refuse an order is made by a person who has looked at it.

There is one automated refusal, and we would rather name it than let it sit inside the sentence above. The reCAPTCHA check on our forms can decline a submission outright, without a person seeing it, if Google's score says the request looks automated. It is a decision about one submission, not about you: it creates no record against your account, is never held against you afterwards, and nothing about your account changes because of it.

It can be wrong, and a privacy-conscious browser makes that more likely rather than less. So it is never the only way to reach us: every form that carries the check tells you, when it declines, to try again or to call or email us — and we will do it for you by hand. That is the human review section 71 asks for, and it is the reason the check is allowed to be strict.

17.Changes to this policy

We will update this policy when what we do changes. The date at the top always reflects the current version. Where a change materially affects how we use information we already hold about you, we will email you before it takes effect rather than rely on you noticing a new date.

18.Contact us

Any question about this policy, or any request under it, goes to our Information Officer:

Information Officer
Guilio Del Fava
Email
hello@wiseguydesign.co.za
Telephone
+27 71 613 7767
Address
1a Pagoda Street, Salisbury Park, Gqeberha, 6070
Or
use the form on our contact page