Legal
Privacy policy.
What personal information we hold, why we hold it, who else gets to see it and what you can make us do about it — under the Protection of Personal Information Act. Including the one place we cannot keep your details private, and why.
Last updated
1.Who is responsible for your information
WiseGuy Design is the responsible party for the personal information described in this policy, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains what we collect, why, who else sees it, how long we keep it, and what you can require us to do about it.
- Responsible party
- WiseGuy Design
- Information Officer
- Guilio Del Fava
- Place of business
- Gqeberha, South Africa
- hello@wiseguydesign.co.za
- Telephone
- +27 71 613 7767
Write to the Information Officer at hello@wiseguydesign.co.za about anything in this policy, including a request to see, correct or delete what we hold.
2.What this policy covers
This policy covers personal information we collect through this website, through our customer portal, and in the course of providing hosting, domain registration and design and development services.
It does not cover information you host on our servers about your own customers. There, you are the responsible party and we act as your operator — we process it only on your instruction, we do not use it for our own purposes, and the duties to secure it and to report a breach of it are yours. See Privacy and personal information in our terms.
3.What we collect
Information you give us
- Account
- Your name, email address, telephone number and, where you are buying on behalf of a business, its name and registration number.
- Billing
- Your billing address and the details that appear on your invoices. Not your card number — see Payments below.
- Domain registrant
- The registrant name, address, email and telephone number required by the registry for each domain you register. See Domains below, which is the part of this policy most worth reading.
- Correspondence
- What you send us by email, through the contact form or in a support request, including anything you choose to put in it.
- Project material
- For design and development work, the content, images, credentials and material you send us to build with.
Information collected automatically
- Server logs
- Your IP address, the pages requested, timestamps, the referring page and your browser's user agent. Standard web server logs, kept for security and troubleshooting.
- Cookies
- A session cookie when you sign in, a small preference cookie for your light or dark theme, and analytics cookies where you allow them. See Cookies below.
- Service telemetry
- Resource usage on your hosting account — storage, bandwidth, mail volume — which is how we bill accurately and spot a compromised account.
We do not collect special personal information as defined in section 26 of POPIA — health, religion, race, political or trade union affiliation, biometrics or criminal history. Please do not send it to us; if you do, we will delete it.
4.Why we process it, and on what basis
Section 11 of POPIA requires a lawful basis for every processing activity. Ours are set out below, so you can see which is which rather than being asked to take consent as the answer for everything.
- To provide what you bought
- Creating your account, provisioning hosting, registering and renewing domains, delivering project work, and supporting all of it. Basis: necessary to perform our agreement with you — section 11(1)(b).
- To bill you
- Raising invoices, taking payment, chasing an unpaid account. Basis: performance of the agreement, and our legitimate interest in being paid — sections 11(1)(b) and 11(1)(f).
- To send service messages
- Renewal notices, expiry warnings, maintenance windows, security advisories and changes to our terms. These are not marketing and you cannot unsubscribe from them while you hold a service — a domain expiry notice you did not receive is precisely the harm the notice exists to prevent. Basis: performance of the agreement.
- To keep the service secure
- Detecting abuse, investigating compromised accounts, rate limiting, blocking attacks. Basis: our legitimate interest, and our obligation under section 19 of POPIA to secure the information we hold.
- To meet legal obligations
- Keeping accounting records, responding to a lawful request from an authority, complying with registry and ICANN requirements. Basis: compliance with a legal obligation — section 11(1)(c).
- To send marketing
- Occasional email about our services. Basis: your consent, or the existing-customer exception in section 69(3) of POPIA. Always with an unsubscribe link. See Marketing.
5.Domain registration and public records
This section deserves its own heading because it is the one place where information you give us is deliberately made public, and where we cannot promise otherwise.
Registering a domain requires us to send the registrant's contact details — name, address, email, telephone number — to a registrar and then to the registry that operates the extension. This is a condition of registration set by the registry, not a choice we make. We cannot register a domain without it and we cannot register one under false details on your behalf.
Registries operate a public lookup service (WHOIS, or RDDS for newer extensions). How much of your information appears there depends on the extension:
- .co.za and other .za extensions publish registrant and contact details in the ZACR WHOIS. Some fields are redacted; the registrant name and email are generally visible.
- .com, .net and most gTLDs redact most personal fields for natural persons following ICANN's Temporary Specification and subsequent policy, and publish an anonymised forwarding address instead. Organisation names are often still published.
Registries and registrars are independent responsible parties for the information they hold. Their retention periods, their disclosure obligations and their dispute processes are theirs. Once a registration is made, we cannot retract the details from the registry, and deleting your account with us does not delete the registrant record for a domain you still own.
Some registries and registrars offer a paid privacy or proxy service that substitutes their details for yours in the public record. Where one is available for an extension you are registering, ask us and we will tell you what it covers and what it costs.
Registries and registrars are also required to disclose registrant details in response to a valid dispute, court order or law enforcement request. We will comply with those requests where they are lawful, and we will tell you that we have unless we are prohibited from doing so.
6.Payments
Card and instant-EFT payments are processed by PayFast, a South African payment gateway certified to PCI DSS Level 1.
We never see your card details. They are entered on PayFast's own pages, on PayFast's systems. Nothing on this website receives, transmits or stores a card number, expiry date or CVV, and there is no field anywhere in our systems that could hold one.
What we receive back from PayFast is a notification that a payment of a stated amount succeeded or failed, its payment reference, and the payment method used. We keep those, linked to your order, because they are our record that an invoice was paid.
PayFast is an independent responsible party for the information you give it. Its own privacy policy governs that, and it is worth reading if you would like to know how long it keeps a card on file for a recurring payment.
8.Information that leaves South Africa
Some of the providers we depend on operate outside South Africa, and your information may be stored or processed abroad — commonly in the European Union or the United States.
Section 72 of POPIA permits this where one of a defined set of conditions is met. We rely on these: the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA; or the transfer is necessary to perform our agreement with you; or you have consented.
In practice this means our providers are contractually bound to standards at least equivalent to those POPIA requires of us, and we check that before we choose one.
10.Marketing email
Section 69 of POPIA is strict about electronic direct marketing, and rightly. We send marketing email only where you have asked for it, or where you are already a customer, the message is about something similar to what you bought, and you were given the chance to opt out when we first collected your address.
Every marketing email carries an unsubscribe link. Using it takes effect immediately and permanently, and you never need to give a reason. Unsubscribing does not stop the service messages described in Why we process it — those continue for as long as you hold a service with us.
Section 45 of the Electronic Communications and Transactions Act separately entitles you to ask for the identifying particulars of the source from which we obtained your details. Ask at hello@wiseguydesign.co.za and we will tell you.
11.How long we keep it
Section 14 of POPIA says information may not be kept longer than is necessary for the purpose it was collected for, unless a law requires otherwise. Ours:
- Account and contact details
- For as long as you hold an account, and 12 months after it closes, in case you come back.
- Invoices and payment records
- Seven years from the end of the tax year they fall in, as required by section 29 of the Tax Administration Act 28 of 2011 and the Companies Act 71 of 2008. This is a legal obligation and a deletion request cannot override it.
- Domain registration records
- For the life of the registration, plus the retention period the registry itself requires of us. Registries typically require records to be retained for two years after a registration ends.
- Support correspondence
- Three years, because a question asked about a setup often needs the answer given three years ago.
- Server and security logs
- 90 days, then deleted. Longer only where a log is part of an active security investigation.
- Hosting account contents
- Deleted on the timeline in Suspension and termination in our terms. Backups roll off within 30 days after that.
- Marketing list
- Until you unsubscribe. Your email is then kept on a suppression list — the only way to be sure we do not mail you again is to remember that you asked us not to.
12.How we protect it
Section 19 of POPIA requires appropriate technical and organisational measures. What we actually do:
- Everything on this site and in the customer portal is served over TLS. Data is encrypted in transit, always.
- Passwords are stored hashed, never in a form anyone here can read.
- Card details are never in our systems at all — see Payments.
- Access to customer data is limited to the people who need it to do their work, and is authenticated individually.
- Every read of a customer's own records is constrained to that customer at the database layer, not only in the application — the check that stops one customer seeing another's invoice does not depend on the page asking nicely.
- Databases and backups are encrypted at rest by our infrastructure providers.
- Software and dependencies are patched on a routine schedule, and out of schedule where a vulnerability warrants it.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If a compromise affects your personal information, section 22 of POPIA requires us to notify the Information Regulator and you as soon as reasonably possible after establishing what happened. We will tell you what was affected, what we have done, and what we suggest you do — in plain language, without waiting until we have a complete picture, if waiting would leave you exposed.
13.Your rights
Section 5 of POPIA gives you the following rights over the personal information we hold about you. Exercising any of them is free, except that we may charge the prescribed fee for a copy of a large volume of records.
- To be told what we hold
- You may ask us to confirm, free of charge, whether we hold information about you, and to describe it. Section 23.
- To get a copy
- You may request the record itself. We will respond within 30 days. Where a request is complex we may extend that once, and we will tell you why. Section 23, read with the Promotion of Access to Information Act 2 of 2000.
- To correct or delete
- You may ask us to correct information that is inaccurate, irrelevant, out of date or incomplete, or to delete information we are no longer entitled to keep. Section 24.
- To object
- You may object at any time, on reasonable grounds, to processing we base on legitimate interest. We stop unless we can show compelling legitimate grounds that override your objection. Section 11(3).
- To withdraw consent
- Where processing rests on your consent, you may withdraw it at any time. That does not undo processing already done lawfully. Section 11(2).
- To stop marketing
- Immediately and without reason. Section 69.
- To complain
- To us, and to the Information Regulator. See below.
Write to hello@wiseguydesign.co.za to exercise any of these. We will ask you to verify your identity first — an access request is exactly the shape of a request an impersonator would make, and confirming who is asking is part of protecting you.
Two honest limits. A deletion request cannot remove a record we are legally required to keep, such as an invoice inside its seven-year retention. And it cannot remove a registrant record already held by a registry — see Domains above.
14.Complaining to the Information Regulator
If you are not satisfied with how we have handled your information or your request, you may complain to the Information Regulator (South Africa). You do not have to come to us first, although we would rather you did.
- Website
- inforegulator.org.za
- General enquiries
- enquiries@inforegulator.org.za
- POPIA complaints
- POPIAComplaints@inforegulator.org.za
Complaints are made on the Regulator's prescribed form, which is available on its website along with its current postal and street address.
15.Children
Our services are sold to businesses and to adults, and are not directed at children. We do not knowingly collect personal information about anyone under 18. Section 34 of POPIA prohibits processing a child's personal information without a competent person's consent, and if we learn that we hold any, we will delete it. Tell us at hello@wiseguydesign.co.za if you believe we do.
16.Automated decisions
We do not make decisions that significantly affect you by automated means alone, as section 71 of POPIA describes. Automated systems do flag things — an unusual login, a spike in mail volume, a payment a fraud filter dislikes — but the decision to suspend an account or refuse an order is made by a person who has looked at it.
17.Changes to this policy
We will update this policy when what we do changes. The date at the top always reflects the current version. Where a change materially affects how we use information we already hold about you, we will email you before it takes effect rather than rely on you noticing a new date.
18.Contact us
Any question about this policy, or any request under it, goes to our Information Officer:
- Information Officer
- Guilio Del Fava
- hello@wiseguydesign.co.za
- Telephone
- +27 71 613 7767
- Or
- use the form on our contact page

