Legal
Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can make us do about it.
Effective 29 July 2026
Who is responsible for your information
This policy explains how CloudIA handles personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). In POPIA terms, CloudIA is the responsible party for the information described here.
CloudIA is a trading name of [REGISTERED ENTITY NAME] (Pty) Ltd, registration number [COMPANY REGISTRATION NUMBER].
[REGISTERED PHYSICAL ADDRESS], Johannesburg, South Africa
hello@cloudia.co.za · +27 11 219 5033 ext. 6209
Our Information Officer is [INFORMATION OFFICER NAME], reachable at hello@cloudia.co.za. Put POPIA in the subject line and it will be routed correctly.
What we collect
We collect three things, and only three.
1. What you send us through the audit form
The systems audit form on our contact page asks for your name, work email address and company. It optionally asks for your website or store URL, an annual revenue band, the problem closest to yours, and anything else you want to tell us. The optional fields are genuinely optional — leaving them blank does not stop the form submitting.
The form also carries a hidden field that real people never see or fill in. It exists to catch automated spam. If it is completed, the submission is discarded.
2. What you send us directly
Email, phone calls and messages you send us, along with whatever you choose to put in them. If you become a client, this extends to the information exchanged during an engagement — access credentials, account data, business metrics and anything else needed to do the work.
3. Server logs
Our web server records requests it receives: IP address, the page requested, the time, the referring page, and your browser's user-agent string. This is ordinary web-server behaviour, kept for security and diagnostics. We do not use it to build a profile of you and we do not combine it with anything else.
What we do not collect
This website sets no cookies, runs no analytics, and loads no advertising or social-media tracking pixels. Fonts and media are served from our own domain rather than a third-party CDN, so simply reading this page reports nothing about you to anyone else. See our Cookie Policy for the detail.
Why we process it, and on what basis
POPIA requires a lawful justification for every use of personal information. Ours are as follows.
- To respond to an audit request — to prepare and deliver the findings document you asked for, and to contact you about it. Basis: your consent, given by submitting the form, and the steps necessary to enter into a contract at your request.
- To deliver work you have engaged us for — building, running and reporting on the systems in scope. Basis: performance of our contract with you.
- To keep our own site and systems secure — spam filtering, abuse prevention, diagnostics. Basis: our legitimate interest in a working, uncompromised service.
- To meet legal and tax obligations — invoicing records, financial records, and anything a regulator or court legitimately requires. Basis: compliance with an obligation imposed by law.
We do not sell personal information. We do not share it with advertisers, data brokers or list vendors. We do not use it to train third-party AI models. If we ever want to use your information for a purpose not listed above, we will ask you first.
Direct marketing
We do not run a marketing list, and submitting the audit form does not subscribe you to one. If that changes, section 69 of POPIA applies: you will be asked to opt in, and every message will carry a working way to opt out. Replying "stop" to any message from us is always sufficient.
Who else can see it
Access inside CloudIA is limited to the people who need it to do the work. Outside CloudIA, your information reaches only:
- Our hosting and infrastructure providers, who operate the servers our site and database run on. They process data on our instructions and may not use it for their own purposes.
- Our email provider, for the obvious reason.
- Professional advisers — accountants, auditors, attorneys — where they need it and are bound by confidentiality.
- Anyone we are legally compelled to give it to, such as a court order or a lawful regulatory demand. Where we are permitted to tell you this has happened, we will.
Audit requests are stored in our own content system on infrastructure we operate, rather than in a third-party CRM.
Information leaving South Africa
Section 72 of POPIA restricts sending personal information outside the Republic. Where a provider we use stores or processes data abroad, we rely on that provider being subject to a law, binding corporate rules or a binding agreement that upholds principles substantially similar to POPIA — or on your consent, or on the transfer being necessary to perform our contract with you.
If you want to know specifically where the information you have given us is stored, ask and we will tell you.
How long we keep it
- Audit requests that do not become engagements — 24 months from your last contact with us, then deleted.
- Client records — for the engagement, plus the retention period South African tax and company law requires of us (generally five years from the end of the relevant financial year).
- Server logs — rotated and discarded within 90 days.
- Correspondence — kept while it remains relevant to a live or potential relationship, then deleted.
You can ask us to delete your information sooner. We will, unless a law requires us to keep it — in which case we will tell you which one and for how long.
Your rights
Under POPIA you may, free of charge except where the Act allows a prescribed fee:
- Ask what we hold about you, and be told where we got it and who we gave it to.
- Have it corrected or completed if it is wrong, misleading or out of date.
- Have it deleted or destroyed where we no longer have grounds to keep it.
- Object to processing we base on legitimate interest, on grounds relating to your particular situation.
- Withdraw consent you have given, at any time. This does not undo processing that was lawful before you withdrew it.
- Not be subject to a decision with legal consequences for you based solely on automated processing. We do not make such decisions.
- Complain — to us, and to the Information Regulator.
Email hello@cloudia.co.za to exercise any of these. We will respond within a reasonable period and in any event no later than 30 days. We may need to verify who you are first, which is a protection for you rather than an obstacle.
Complaining to the Regulator
If you are not satisfied with how we have handled a request or a complaint, you can take it to the Information Regulator (South Africa), which oversees POPIA. Its current contact details and complaint forms are published at inforegulator.org.za. You do not need our permission, and you do not need to come to us first — though we would rather you did, because it is usually faster.
How we protect it
Traffic to this site is encrypted in transit. Access to systems holding personal information is restricted, authenticated and limited to the people who need it. Credentials clients give us during an engagement are held in a password manager, scoped to the least access that does the job, and revoked at handover or on request.
No one can honestly promise a breach will never happen. If one does, and it creates a real risk of harm to you, POPIA section 22 requires us to notify both the Information Regulator and you — and we will, in writing, with what happened, what was affected and what to do about it.
Children
This site and our services are aimed at businesses, not children. We do not knowingly collect the personal information of anyone under 18. If you believe a child has sent us information, tell us and we will delete it.
Changes to this policy
We update this policy when what we actually do changes. The effective date at the top always reflects the current version. Material changes — a new category of information, a new purpose, a new recipient — will be announced on this page before they take effect, and we will contact clients directly where the change affects a live engagement.
Also: Terms of Service · Cookie Policy
Free audit