Privacy notice.
What this website collects, why, who else sees it, how long we keep it and what you can require us to do about it. Written to be read rather than to cover us, and specific about the company profile, which asks for a great deal more than a contact form does.
Who is responsible for your information
Manelisi Technologies (Pty) Ltd is the responsible party for the personal information described in this notice, in the sense the Protection of Personal Information Act 4 of 2013 (POPIA) uses that term. In plainer language, we decide what is collected on this website and what happens to it, and we are accountable for it.
- Full legal name
- Manelisi Technologies (Pty) Ltd
- Registration number
- 2011/044016/23
- Place of registration
- Republic of South Africa
- Registered office
- 4 Daventry Street, 5th Floor, Bloukrans Building, Lynnwood Bridge, Lynnwood Manor, Pretoria, Gauteng, 0081
- Telephone
- +27 12 007 2568
- support@manelisi.com
- Website
- www.manelisi.com
Information Officer
We have an Information Officer who is accountable for how personal information is handled here. They are reachable at privacy@manelisi.com.
If you have a question about your information, or you want to exercise any of the rights in section 7 below, that is the address to write to.
What we collect, and why
We collect three kinds of information, and the third is much more detailed than the other two, so it is worth reading if you are thinking of completing the company profile.
1. Everyone who visits the site
- Server logs
- Your IP address, browser and operating system, the pages you request and when. Created automatically by the web server. We use them to keep the site running and to investigate abuse.
- Google Analytics
- Pages viewed, approximate location, device type and how you arrived. Your IP address is anonymised before it is stored. We use it to understand which parts of the site are useful.
- Google reCAPTCHA
- Runs on the two form pages to tell people from bots. Google collects hardware and software information and behavioural signals from your browser, and this is subject to Google’s own privacy terms.
2. If you send us an enquiry
The contact form asks for your name, organisation, work email, phone number, what you need and your timeline, plus whatever you write in your own words. We also record the page you sent it from, your IP address and your browser, because that is what makes spam filtering possible.
3. If you complete the company profile
This is the detailed one. The profiling questionnaire asks 61 questions about your organisation: its size, industry, turnover band, operations and processes, the systems it runs, its security and continuity arrangements, its compliance obligations, the average age and digital confidence of its workforce, its history with previous projects, its challenges and its priorities. It also asks for your name, role, email and phone number so we can send you the assessment.
Much of that is commercially sensitive information about your employer rather than personal information about you. Please only complete it if you are authorised to share it. Section 4 of our terms and conditions covers this.
We use it for one purpose: to prepare a written digital maturity assessment and to discuss that assessment with you. We do not sell it, we do not share it with other clients, and we do not use it as an example in marketing material unless you have given us separate written permission.
What we deliberately do not ask for
None of our forms asks for special personal information as POPIA section 26 defines it: no religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour. We also never ask for an identity number, a bank account number or a password. If a page on this website ever appears to ask you for any of those, it is not ours. Please tell us.
The grounds we rely on
POPIA requires a lawful justification for processing, over and above having a good reason. Ours are:
- Your consent. You choose to submit a form. Nothing on this site requires you to give us personal information in order to read it.
- Performance of a contract, or steps towards one. Preparing your assessment and responding to your enquiry is the thing you asked us to do.
- Our legitimate interests. Keeping the site secure, filtering spam and understanding which pages are read. We have weighed these against your interests, which is why the analytics are IP-anonymised and why the spam checks look only at free text rather than at your whole submission.
- Legal obligation, where a law requires us to keep or produce a record.
You can withdraw consent at any time by writing to our Information Officer. That does not undo processing that has already lawfully happened, and it may mean we can no longer complete an assessment you asked for.
Who else sees it
We do not sell personal information, and we do not share it for anyone else’s marketing. It reaches the following third parties because the website could not work otherwise:
- Our hosting provider
- Stores the website, the database and the mail queue under a contract that obliges them to keep it confidential and to process it only on our instructions. We do not name them here, for security reasons, but we will confirm who they are on request.
- Google LLC (United States)
- reCAPTCHA on the form pages, and Google Analytics 4 across the site. See Google’s privacy policy.
- Automattic Inc. (United States)
- Akismet checks form submissions for spam. It receives the free-text parts of a submission, your name, email address and IP address.
- Professional advisers
- Our auditors or attorneys, where they need it and are bound by confidentiality.
Information leaving South Africa
Google and Automattic process information outside South Africa, which POPIA section 72 treats as a transborder flow. We rely on the fact that both are bound by their own binding contractual terms giving effect to protection substantially similar to POPIA, and that the transfer is necessary for the performance of what you asked us to do. Copies of the relevant terms are available from our Information Officer on request.
How long we keep it
- Server logs
- 30 days
- Analytics
- 14 months
- Enquiries
- 30 days
- Company profiles and assessments
- 60 days
- Records we must keep by law
- For as long as the relevant law requires, then deleted.
Submissions our spam filter rejects are kept as a short record and are never read as enquiries. You can ask us to delete anything you have sent us sooner than the periods above, and we will unless a law requires us to keep it.
How it is protected
POPIA section 19 requires reasonable technical and organisational measures. Ours, specifically:
- The site is served over HTTPS, so what you type is encrypted in transit.
- Form submissions are validated against a fixed list of expected answers before anything is stored, and database queries use prepared statements.
- Database credentials live in a single server-side file that is not readable over the web and is never included in the website’s source.
- The assessment is emailed to one named person rather than a shared inbox.
- Access to the database is limited to administrators.
No system is perfectly secure. If we have reasonable grounds to believe your personal information has been accessed by someone unauthorised, POPIA section 22 requires us to notify both the regulator and you, and we will.
Cookies and browser storage
This site sets no cookies of its own. What it does set, through the two Google services and one browser feature, is:
- _ga, _ga_…
- Google Analytics. Tells repeat visits apart from new ones. Expires after two years.
- _GRECAPTCHA
- Google reCAPTCHA, on the contact and company profile pages only. Needed to tell people from bots.
- A saved draft
- The company profile keeps your answers in your own browser as you type, so that closing the tab does not cost you ten minutes of work. This is local storage rather than a cookie: it stays on your device, it is never transmitted until you press send, and it is deleted the moment you submit. There is a Clear this draft button on the form.
You can block or delete cookies in your browser settings. Blocking the reCAPTCHA cookie does not stop you using the forms: our endpoints are built to accept a submission that arrives without a reCAPTCHA result and flag it for a human to look at, because a blocked script is far more often a corporate firewall than a bot.
We do not use advertising or cross-site tracking cookies, and we do not respond to the Do Not Track browser signal, because there is no agreed standard for what responding to it should mean.
Your rights, and how to use them
Under POPIA you may:
- Ask what we hold about you and be given a copy, under section 23. We may charge the prescribed fee for this.
- Ask us to correct or delete it where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, under section 24.
- Object to processing we base on legitimate interests, under section 11(3).
- Withdraw consent you previously gave.
- Object to direct marketing at any time, and we must stop.
- Take the matter further if you are not satisfied with how we have handled it, using whatever avenue POPIA gives you.
- Not be subject to a decision based solely on automated processing that affects you, under section 71. Worth being specific here: the company profile is scored by a computer, but nothing is decided by one. A person reads every assessment before anyone contacts you, and the score determines only how we prepare for that conversation.
Write to our Information Officer at privacy@manelisi.com. We will confirm your identity first, because handing your information to someone claiming to be you would be the very thing this notice exists to prevent, and we will respond as soon as we reasonably can.
If you would rather make the request on a form, ask us and we will send you the appropriate one.
Marketing
If you send us an enquiry or a company profile, we will reply about that. That is not marketing, it is the thing you asked for.
POPIA section 69 does not allow us to send you unsolicited electronic marketing unless you are already our customer or you have given us permission. So we will not add you to a mailing list because you completed the profile. If we ever want to send you something more general, we will ask first, and every message we do send will carry a working way to stop them.
Children
This is a business-to-business website and nothing on it is directed at children. We do not knowingly collect personal information about anyone under 18. POPIA requires a competent person’s consent for a child’s information, and we have no basis on which to obtain it here. If you believe a child has sent us something, tell our Information Officer and we will delete it.
Changes to this notice
We will update this page when what we do changes. The date at the top always reflects the current version. If a change materially affects how we handle information you have already given us, we will contact you directly rather than rely on you noticing a new date.
If you are unhappy with something
Write to our Information Officer at privacy@manelisi.com and tell us what has gone wrong. We would far rather hear it from you directly, and most things are fixable quickly once someone knows about them.
We will look into it, tell you what we find, and say what we are doing about it. If you are still not satisfied after that, POPIA preserves whatever further steps the law allows you to take.