Condorgreen processes only the personal information reasonably required to operate its business, deliver services, manage relationships, meet legal obligations and protect its systems. We do not sell personal information.
Scope and responsible party
This Privacy Notice applies to personal information processed by Condorgreen (Pty) Ltd (“Condorgreen”, “we”, “us” or “our”) through our website, business operations, service delivery, communications and relationships with clients, prospective clients, suppliers, partners, job applicants and other persons.
For purposes of the Protection of Personal Information Act 4 of 2013 (“POPIA”), Condorgreen is the responsible party where it determines why and how personal information is processed. Where we process information strictly on a client’s documented instructions, we may act as an operator and the client remains the responsible party.
This notice should be read together with any contract, service-specific notice, consent form, website terms, PAIA manual or other notice supplied when information is collected.
Our processing principles
We process personal information lawfully and reasonably, in a manner that does not unjustifiably infringe privacy. Our practices are guided by POPIA’s conditions for lawful processing, including accountability, processing limitation, purpose specification, further-processing limitation, information quality, openness, security safeguards and data-subject participation.
We seek to collect information directly from the data subject where reasonably practicable, limit collection to what is adequate, relevant and not excessive, keep information accurate where required, and use it only for a specific, explicitly defined and lawful purpose or a compatible further purpose.
Personal information we may collect
Depending on the relationship and service, we may process:
- Identity and contact information: name, surname, title, business contact details, postal or physical address, signature and preferred communication method.
- Business and professional information: employer, role, department, industry, professional profile, procurement information and relationship history.
- Client and service information: enquiries, proposals, contracts, instructions, support records, project information, meeting notes, correspondence and service-delivery records.
- Financial and transaction information: billing details, tax-related information, payment status and transaction records. We do not intentionally store complete payment-card credentials unless expressly required and appropriately secured.
- Technical and usage information: IP address, device and browser information, website interactions, timestamps, log data, security events, identifiers and cookie information.
- Security and access information: authentication records, authorised-user details, access logs and information required to protect systems and investigate incidents.
- Recruitment information: CVs, qualifications, work history, references, interview notes and other information voluntarily supplied by applicants.
- Images or recordings: photographs, video or audio where used for meetings, events, security, training or communications and where lawful notice or consent has been provided where required.
- Other information: any information voluntarily provided to us or generated through a lawful business interaction.
We do not intentionally request more information than is reasonably necessary for the relevant purpose.
Where we obtain personal information
We may obtain information directly from you, your employer or authorised representatives; through our website, email, telephone, meetings, events, forms and contracts; from clients where necessary to provide contracted services; from service providers and business partners; from public records, professional directories and publicly available sources; or from security and operational systems used in our business.
Where information is not collected directly from you, we will process it only where permitted by POPIA, such as where the information is contained in or derived from a public record, collection from another source would not prejudice your legitimate interests, direct collection is impracticable, or another lawful exception applies.
Why we process information and the lawful grounds we rely on
We may process personal information to:
- respond to enquiries, prepare proposals and manage client, supplier and partner relationships;
- enter into, administer and perform contracts and deliver technology, consulting, managed, data, development or related services;
- provide support, maintain service quality, manage projects, monitor performance and improve offerings;
- manage accounts, invoicing, procurement, payments, audits and business records;
- operate, secure, troubleshoot and improve our website, networks, platforms and systems;
- prevent, detect and investigate fraud, misuse, cyber threats, unauthorised access and other unlawful activity;
- meet legal, regulatory, tax, employment, audit, governance and reporting obligations;
- establish, exercise or defend legal rights and claims;
- recruit personnel and assess applications;
- send business communications and, where lawful, relevant marketing; and
- carry out corporate transactions, due diligence, restructuring or business-continuity activities.
Our lawful grounds may include your consent; the conclusion or performance of a contract; compliance with an obligation imposed by law; protection of your legitimate interests; performance of a public-law duty where applicable; or pursuit of the legitimate interests of Condorgreen or a third party, balanced against your rights and reasonable expectations.
Where processing depends on consent, consent may generally be withdrawn at any time. Withdrawal does not invalidate processing that was lawful before withdrawal and may affect our ability to provide a requested service.
Direct marketing and communications
We may send service-related and administrative communications where necessary for an existing relationship. Electronic direct marketing will be sent only where permitted by POPIA, including where valid consent has been obtained or, in appropriate cases, where you are an existing customer and the communication concerns our own similar products or services.
Marketing messages will identify the sender and provide a reasonable, free method to opt out. You may object to direct marketing or unsubscribe at any time by using the unsubscribe facility in the message or contacting us. We will retain only the minimum suppression information needed to honour an opt-out request.
Cross-border transfers
Some service providers, systems or recipients may be located outside South Africa. We transfer personal information across borders only where permitted under section 72 of POPIA, for example where the recipient is subject to a law, binding corporate rules or agreement providing an adequate level of protection; where the transfer is necessary for a contract; where you have consented after being informed; or where another statutory ground applies.
We assess the nature of the information, the purpose of the transfer, the recipient and the safeguards available, and use appropriate contractual and security measures where required.
Information security and security compromises
We implement reasonable and appropriate technical and organisational measures designed to preserve confidentiality, integrity and availability and to prevent loss, damage, unauthorised destruction, unlawful access or unlawful processing. Measures may include access control, least-privilege practices, authentication safeguards, encryption where appropriate, secure configuration, monitoring, logging, backups, vulnerability management, incident response, staff awareness and supplier controls.
No system can be guaranteed to be completely secure. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate, contain and remediate the incident and notify the Information Regulator and affected data subjects as soon as reasonably possible, subject to any lawful delay or exception. Notifications will contain the information required by POPIA where known.
Retention and deletion
We retain records only for as long as necessary to achieve the purpose for which the information was collected or subsequently processed, to meet legal or contractual retention requirements, to protect legitimate business and security interests, or with consent where appropriate.
Retention periods differ according to record type, legal requirements, contractual commitments, dispute and limitation periods, operational needs and the sensitivity of the information. When retention is no longer justified, information is securely deleted, destroyed or de-identified. De-identified information may be retained where it cannot reasonably be re-identified.
Your rights under POPIA
Subject to POPIA and any applicable limitations, you may:
- ask whether we hold personal information about you and request access to it;
- request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- request destruction or deletion of information we are no longer authorised to retain;
- object, on reasonable grounds relating to your particular situation, to processing based on specified statutory grounds;
- object at any time to processing for direct marketing;
- withdraw consent where consent is the basis for processing;
- request information about the identity of third parties who have had access to your information where POPIA provides for this;
- not be subject, in the circumstances described by POPIA, to a decision based solely on automated processing that produces legal consequences or substantially affects you; and
- lodge a complaint with the Information Regulator or institute civil proceedings where legally available.
To protect you and others, we may ask for sufficient proof of identity or authority before acting on a request. Requests will be handled within the periods and subject to the grounds for refusal, fees and procedures provided by POPIA and PAIA. We will explain a lawful refusal where required.
Children and special personal information
Our website and business services are primarily intended for organisations and adults. We do not knowingly collect personal information about children without the consent of a competent person or another lawful authorisation.
We process special personal information—such as information concerning health, race or ethnic origin, religious or philosophical beliefs, trade-union membership, political persuasion, sex life, biometric information or alleged or proven criminal behaviour—only where a lawful authorisation under POPIA applies and appropriate safeguards are in place.
Automated decision-making
Condorgreen does not intend to make decisions that produce legal consequences for a person or substantially affect a person solely through automated processing, unless the decision is permitted by POPIA and suitable measures are implemented to protect the person’s legitimate interests. Where applicable, those measures may include an opportunity to make representations and obtain meaningful human review.
Privacy queries, requests and complaints
Requests concerning personal information should be directed to Condorgreen’s Information Officer or authorised privacy contact:
Unit A1/A2, Spearhead Park, Montague Drive, Montague Gardens, Cape Town, 7441
Please use the subject line “POPIA Privacy Request” and describe the request clearly. Where another organisation is the responsible party and Condorgreen acts only as its operator, we may refer the request to that organisation.
You may also lodge a complaint with the Information Regulator (South Africa):
- Email for POPIA complaints: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Telephone: 010 023 5200 or toll-free 0800 017 160
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Changes to this notice
We may revise this notice to reflect changes in law, regulatory guidance, technology or our processing activities. The current version will be published on this page with a revised effective date. Material changes may also be communicated through an appropriate additional channel.
