Loading
How we meet our obligations under the Protection of Personal Information Act, 4 of 2013 (POPIA), as a responsible party for our own clients, and as an operator processing personal information on their behalf.
Last updated · 2025
Both Fire-IT (PTY) Ltd and its clients acknowledge their obligations under POPIA. We process personal information only as necessary to provide our services, in accordance with applicable privacy laws and the Master Service Agreement, and in line with the eight conditions for lawful processing under POPIA.
Our information officer is responsible for POPIA compliance and can be reached at support@fire-it.co.za or 012 004 0615.
We process personal information under the following lawful bases:
When we process personal information on behalf of clients (for example through hosting, backups or managed services), we act as an operator. We process such information only on documented instruction, apply appropriate security safeguards, and assist clients in meeting their own POPIA obligations. These arrangements are formalised in a data processing agreement (DPA) available on request.
We maintain appropriate, reasonable technical and organisational measures, including encryption (AES-256 at rest, TLS in transit), access controls, least-privilege administration, multi-factor authentication, logging and audit trails, regular security assessments, staff training on data protection obligations, and tested backup and recovery.
Data is hosted in South African data centres, supporting in-country data residency.
Under POPIA, data subjects have the right to:
Contact our information officer to exercise these rights, or lodge a complaint with the Information Regulator. We respond within the timeframes required by POPIA.
We will notify affected clients of any confirmed data breach affecting their personal information within 72 hours of discovery, where feasible and as required by law, including the nature of the breach, the categories of data affected, potential consequences and the mitigation steps taken. We handle required regulatory notifications to the Information Regulator as per POPIA.
Where personal information is transferred outside South Africa to service providers or vendors, transfers are made to countries with adequate data protection levels or under appropriate safeguards, with standard contractual clauses or equivalent protections in place. Material cross-border transfers are disclosed to clients.
We maintain records of data processing activities as required by POPIA, including the purposes of processing and categories of personal information, recipients of personal information, cross-border transfer details and safeguards, and data retention periods and deletion procedures.
Clients agree to provide accurate and current personal information, notify us promptly of changes, ensure proper authorization for sharing the personal information of their employees or users, comply with POPIA in their own data processing activities, and cooperate with us in responding to data subject requests.
Our data protection obligations are limited to personal information directly provided by clients or collected in the course of service delivery, processing activities under our direct control, and security measures within our systems and infrastructure. We are not responsible for clients' own data protection compliance or internal data handling, the security of personal information once transmitted to client systems, or third-party data breaches beyond our control.
Questions about this document? Contact us at support@fire-it.co.za or 012 004 0615. Fire-IT (PTY) Ltd, Unit 4, 36 Regency Drive, Route 21 Business Park, Centurion, Gauteng 0178, South Africa.