Skip to main content
VOIMAR Group policy

POPIA Compliance Policy

VOIMAR-POL-002 · Version 1.0 · Effective 9 October 2026 · Approved by VOIMAR (Pty) Ltd

Purpose

This policy sets out how VOIMAR complies with the Protection of Personal Information Act 4 of 2013 (POPIA) in everything it does. VOIMAR's Privacy Notice, at www.voimar.co.za/privacy, tells customers and users what VOIMAR collects and why. This policy sets the rules VOIMAR's people, systems and partners follow.

Scope

Personal information of customers, end users, employees, job applicants, suppliers and partners, in every VOIMAR system, and in client systems that VOIMAR builds or operates.

Information Officer

VOIMAR's Information Officer is Zuko Leonard Rabotapi (infoofficer@voimar.co.za), authorised in writing by the head of the company, the Chief Executive Officer. VOIMAR registers its Information Officer, and any Deputy Information Officers, with the Information Regulator.

Privacy requests and complaints: privacy@voimar.co.za.

The eight conditions for lawful processing

  • Accountability: VOIMAR takes responsibility for meeting every condition.
  • Processing limitation: only the information a task needs, collected lawfully, with consent or another lawful basis.
  • Purpose specification: collected for a defined purpose, and kept only as long as that purpose or the law requires.
  • Further processing limitation: used later only for purposes compatible with the original one.
  • Information quality: kept accurate and up to date.
  • Openness: people are told what is collected and why, through the Privacy Notice and at the point of collection.
  • Security safeguards: protected by the controls in the VOIMAR Information Security Policy.
  • Data subject participation: people may ask to see, correct or delete their information.

Where information is kept

VOIMAR keeps personal information on its own infrastructure in South Africa, and uses no foreign cloud for customer or company data. Information is transferred outside South Africa only where section 72 of POPIA allows it, for example when a customer uses a service, such as WhatsApp, that is delivered through an international provider.

Operators and partners

Anyone who processes personal information for VOIMAR, including subcontractors and local deployment partners, does so under a written operator agreement (sections 20 and 21 of POPIA), with security measures at least equal to VOIMAR's.

Client systems

When VOIMAR builds or operates a system for a client, the client remains the responsible party. VOIMAR acts as the client's operator, follows the client's instructions and security rules, and keeps the client's information inside the client's environment.

Employees and AI tools

Employees and contractors access personal information only as their work requires, and are trained in this policy. AI tools used by VOIMAR read personal information only as far as a task needs, run under VOIMAR's control, and are never used to train outside AI models.

Security compromises

If personal information is accessed or acquired by an unauthorised person, VOIMAR notifies the Information Regulator and the people affected as soon as reasonably possible (section 22 of POPIA), and records the incident and the corrective action.

Direct marketing

Electronic direct marketing is sent only with consent, or to existing customers about similar services, and every message offers an easy way to opt out (section 69 of POPIA).

Access to records

Requests for access to records are handled by the Information Officer under the Promotion of Access to Information Act 2 of 2000 (PAIA).

Retention and deletion

Records are kept for the periods the law requires (for example tax and RICA records) and are then deleted or de-identified. Customers can follow VOIMAR's data deletion instructions at www.voimar.co.za/data-deletion.

Review

This policy is reviewed every year, and after any security compromise or change in the law.

All company policies