Your privacy

Privacy Policy

This policy explains what personal information Webfast Technologies (Pty) Ltd collects, why we use it, how we protect it, and the choices you have.

Effective 5 August 2026 POPIA aligned

Webfast Technologies (Pty) Ltd respects your privacy and is committed to processing personal information lawfully, reasonably, transparently, and securely. Both Webfast and its clients must comply with the Protection of Personal Information Act 4 of 2013 (“POPIA”) when performing the service agreement.

In plain language: we use personal information to respond to you, deliver and support digital services, run our business, protect our systems, and improve our website. We do not sell personal information.

01

Who we are

Webfast Technologies (Pty) Ltd provides website design, e-commerce, custom development, hosting, domain registration, digital marketing, branding, search optimisation, and related support services.

For personal information that we decide how and why to process, Webfast Technologies (Pty) Ltd is the responsible party under POPIA.

Responsible party Webfast Technologies (Pty) Ltd
Address 18 C.J. Langenhoven Road, George Central, George, South Africa
Telephone 074 874 7886

When we host, maintain, or support a client’s website and process personal information on that client’s behalf, we act as the client’s operator and process it only on the client’s lawful instructions. The client remains the responsible party and warrants that it has obtained all necessary consents, or otherwise has a lawful basis under applicable law, for personal information supplied to us for processing. These confidentiality and POPIA obligations survive termination of the service agreement, and the client’s own privacy policy also applies.

02

Scope of this policy

This policy applies when you:

  • visit webfast.co.za or a Webfast webpage that links to this policy;
  • ask for a quote, website audit, consultation, domain search, or other information;
  • become, represent, or work for a client, supplier, partner, or prospective client;
  • communicate with us by email, telephone, WhatsApp, a web form, social media, or in person; or
  • use a website, hosting, domain, support, advertising, or related service that we provide directly to you.

It does not replace the privacy policy of a client whose website we build, host, or support, and it does not govern third-party websites or services that have their own privacy notices.

03

Information we collect

The information we collect depends on how you interact with us. It may include:

Contact and identity

Your name, email address, telephone number, company, job title, physical or postal address, and preferred contact method.

Enquiries and communications

The service you are interested in, messages, website audit details, call notes, emails, support requests, feedback, and correspondence history.

Client and project information

Contracts, proposals, instructions, project files, website content, authorised contacts, domain and hosting details, service configurations, and access credentials provided for project delivery.

Billing and transactions

Billing details, tax and invoice information, bank details where needed for payment or refunds, payment status, and transaction references. Payment providers may process payment credentials under their own policies.

Technical and security data

IP address, date and time, requested pages, browser and device details, referring address, diagnostic data, server logs, and security events.

Marketing and public information

Communication preferences, campaign interactions, social media details, and information you make public through business directories, websites, reviews, or professional profiles.

Special personal information

We do not intentionally request sensitive or special personal information through our public forms. Please do not send health, biometric, religious, political, criminal, or other sensitive information unless it is genuinely necessary and we have agreed on a secure way to receive it. If we must process special personal information, we will do so only where POPIA permits it and with appropriate safeguards.

04

How we collect information

We collect personal information:

  • directly from you, including through forms, calls, meetings, email, WhatsApp, orders, agreements, and support requests;
  • automatically from your device, through essential website technology, server logs, and optional first-party analytics;
  • from your organisation or an authorised person, such as an employer, colleague, project lead, or agency partner;
  • from service providers, including payment, hosting, domain, advertising, booking, and technology providers where needed to provide a service; and
  • from lawful public sources, such as company websites, public social profiles, business directories, domain records, and public reviews.

Where POPIA requires us to collect information directly from you, we will do so unless an exception applies.

05

How and why we use information

We process personal information only where there is a lawful reason. Depending on the circumstances, that reason may be your consent, taking steps at your request before entering a contract, performing a contract, complying with law, protecting your or another person’s legitimate interests, or pursuing our legitimate business interests in a way that does not unfairly override your rights.

What we do Why we do it
Respond to enquiries and prepare proposals

To take requested steps, communicate with you, understand your needs, and provide relevant pricing or recommendations.

Deliver and manage services

To perform agreements, manage projects, register domains, configure hosting, publish websites, run campaigns, invoice, and provide support.

Operate and improve our website

To provide requested pages and tools, understand performance, diagnose problems, and improve content and user journeys.

Protect our business and users

To prevent abuse, fraud, attacks, unauthorised access, data loss, and other security incidents; and to establish or defend legal claims.

Meet legal and financial duties

To maintain required records, respond to lawful requests, manage tax and accounting obligations, and comply with regulatory duties.

Communicate relevant services

To send requested updates and, where permitted, relevant marketing with a clear way to opt out.

If information is required to enter into or perform a contract and you do not provide it, we may not be able to quote for, deliver, or support the requested service. Where providing information is optional, we will make that clear where practical.

06

Analytics, cookies, and similar technology

Essential website technology

Our website and hosting platform may use cookies, local browser storage, and similar technology that is necessary to deliver pages, remember privacy choices, protect forms, balance traffic, and keep the site secure. Blocking essential technology may affect how the website works.

Optional first-party analytics

Webfast Insights is our first-party analytics tool. It does not collect analytics until you choose Allow analytics. If you opt in, it records:

  • page paths and titles, referring domains, and campaign tags;
  • device category and viewport size;
  • general click positions and labels, scroll depth, and active viewing time; and
  • coarse city, region, or country when our hosting platform supplies it.

A random identifier is stored in your browser and converted to a one-way salted hash before it is stored in WordPress. The tool does not request precise GPS, record keystrokes or form contents, or store full IP addresses or advertising identifiers. Live-presence records expire within 10 minutes of inactivity and analytics records are currently deleted automatically after 90 days.

You can accept or decline analytics when asked, change your decision using the Privacy choices control on the website, or reset the analytics identifier. We also respect supported Global Privacy Control and Do Not Track browser signals.

Third-party features

We may display information obtained from Google, such as public business reviews, through server-side connections. If you choose to open Google Maps, book a Google Meet, play an embedded YouTube video, or follow a link to Google, Meta, LinkedIn, Instagram, Facebook, or another platform, that provider may receive technical data and use cookies or similar technology under its own policy.

You can control cookies through your browser settings. For more information about third-party practices, see Google’s Privacy Policy and Meta’s Privacy Policy.

07

When we share information

We do not sell personal information. We may share only what is reasonably necessary with:

  • our team and authorised contractors who need the information to perform their work and are subject to confidentiality and security duties;
  • technology and operations providers, such as website, cloud, hosting, email, backup, security, support, analytics, communication, and file-storage providers;
  • domain and platform providers, including registries, registrars, DNS providers, content management systems, software vendors, app stores, and advertising or social platforms selected for a project;
  • payment and finance providers, banks, payment processors, bookkeepers, auditors, and tax advisers;
  • professional advisers and authorities, including lawyers, insurers, regulators, courts, law-enforcement bodies, or government authorities where permitted or required; and
  • a successor or transaction party if our business or relevant assets are restructured, sold, or transferred, subject to appropriate confidentiality and lawful processing.

Our service providers must process information only for agreed purposes, apply appropriate safeguards, and return, delete, or secure information as required by their contracts and applicable law.

08

Cross-border transfers

Some cloud, hosting, email, software, analytics, advertising, domain, or support providers may process information outside South Africa. When personal information is transferred to another country, we take reasonable steps to ensure the transfer complies with section 72 of POPIA. This may include using a recipient subject to an adequate privacy law, binding corporate rules, or a binding agreement that provides an appropriate level of protection, or relying on another lawful ground permitted by POPIA.

You can contact us if you would like more information about safeguards relevant to a particular service.

09

How we protect information

We use reasonable, appropriate technical and organisational safeguards based on the nature of the information and foreseeable risks. These may include access controls, strong authentication, encryption in transit, secure hosting configurations, backups, software updates, monitoring, staff and contractor confidentiality, limited access, and incident response procedures.

No internet transmission or storage system can be guaranteed completely secure. If we become aware of a security compromise involving your personal information, we will investigate, contain, and address it and notify affected people and the Information Regulator where POPIA requires.

Where required by POPIA, security compromises will be dealt with and notifications made in accordance with applicable legal requirements.

Please protect project access too. Do not send passwords or secret keys through an insecure channel. Ask us for a suitable transfer method if credentials are needed for a project.

10

How long we keep information

We retain personal information only for as long as it is needed for the purpose collected, required by law or contract, reasonably needed for evidence or dispute resolution, or authorised by you. We then delete, de-identify, or securely archive it as appropriate.

Enquiries and proposals

Usually up to 3 years after the last meaningful contact, unless you become a client or a longer period is justified.

Client, project, billing, and contract records

For the relationship and generally at least 5 years afterwards, or longer where tax, accounting, contractual, or legal requirements apply.

Support and security records

For the period needed to resolve the issue, maintain service history, protect systems, and establish or defend claims.

Optional website analytics

Analytics events are currently deleted after 90 days; live-presence records expire within 10 minutes of inactivity.

Marketing preferences

Until you opt out or the information is no longer useful, with a suppression record retained where needed to honour your choice.

Backups

Deleted information may remain in protected backups until those backups rotate, after which it is overwritten or securely removed.

11

Direct marketing

We may send information about Webfast services where you asked for it, consented, or where POPIA otherwise permits us to contact an existing customer about similar services. Electronic marketing will identify us and provide a reasonable way to opt out.

You can stop direct marketing at any time by using the unsubscribe option in the message or contacting info@webfast.co.za. Opting out of marketing will not stop essential service, billing, security, or project communications.

12

Your privacy rights

Subject to POPIA and any lawful limitations, you may:

  • Ask whether we hold personal information about you and request access to it.

  • Ask us to correct or update information that is inaccurate, incomplete, excessive, misleading, or out of date.

  • Ask us to delete or destroy information that we are no longer authorised to retain, subject to legal exceptions.

  • Object to processing on reasonable grounds where POPIA gives you that right.

  • Withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.

  • Object to direct marketing at any time and ask not to receive further marketing.

  • Complain to the Information Regulator if you believe your information has been processed unlawfully.

To exercise a right, contact us using the details below and describe your request. We may need to verify your identity and authority before releasing or changing information. We will respond within the period required by applicable law. Access may be subject to a lawful fee or refusal ground, in which case we will explain the basis where required.

13

Children’s information

Our website and services are intended for businesses and adults and are not directed at children under 18. We do not knowingly collect a child’s personal information through the website without the consent of a competent person or another lawful basis. If you believe a child has provided information to us improperly, please contact us so we can investigate and take appropriate action.

14

Automated decisions

We do not currently use personal information to make solely automated decisions that have legal consequences or similarly significant effects for website visitors or clients. If this changes, we will provide the notices and safeguards required by law.

16

Changes to this policy

We may update this policy when our services, technology, providers, or legal duties change. The effective date at the top shows when it was last materially revised. Important changes may also be highlighted on the website or communicated directly where appropriate.

17

Contact us or make a complaint

Questions and privacy requests can be sent to our Information Officer using the details below. We would appreciate the opportunity to address a concern directly.

Webfast privacy enquiries

Let’s sort it out.

Email our Information Officer
Webfast Technologies 18 C.J. Langenhoven Road
George Central, George
South Africa
info@webfast.co.za 074 874 7886

Information Regulator (South Africa)

If you believe we have not resolved your concern, you may lodge a POPIA complaint with the Information Regulator through its eServices portal or designated complaint channel.

Websiteinforegulator.org.za/complaints

EmailPOPIAComplaints@inforegulator.org.za

Telephone010 023 5200

AddressWoodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191