This notice explains how Resilitech (Pty) Ltd (“Resilitech”, “we”, “us”) collects, uses, shares and protects personal information, and how you can exercise your rights under the Protection of Personal Information Act, 2013 (“POPIA”). It applies to our website, enquiries, and the delivery of our services.
1Who we are
Resilitech is the responsible party for the personal information described in this notice. We are an independent IT assurance and cyber security firm registered in South Africa. Where we process personal information on behalf of a client in the course of an engagement, we act as an operator and process it only on the client’s documented instructions.
2Information we collect
We collect only what we need for the purposes set out below:
- Enquiry details: your name, work email, phone number, organisation and the content of your message when you contact us or request an assessment.
- Engagement information: information necessary to scope and deliver a service, which may include technical and, where relevant, personal information within an agreed testing scope.
- Website data: limited technical information (such as IP address and device/browser type) and cookie data, as described in our cookie policy.
3How we use your information
We use personal information to respond to enquiries, prepare and deliver proposals and services, meet legal and regulatory obligations, and, where you have consented, to send you relevant insights. We do not sell personal information.
4Lawful basis for processing
Depending on the context, we rely on one or more of the following bases recognised under POPIA:
- Consent: for example, when you opt in to receive insights. You may withdraw consent at any time.
- Performance of a contract: to deliver a service you or your organisation have engaged us for.
- Legitimate interests: to operate and secure our business, balanced against your rights.
- Legal obligation: where processing is required by law.
5Sharing & sub-processors
We share personal information only where necessary: with vetted sub-processors who help us operate (listed in our Trust Centre), with professional advisers, or where required by law. Every sub-processor is bound by a written agreement and appropriate safeguards. Cross-border transfers occur only where a lawful transfer mechanism is in place.
6Retention
We keep personal information only for as long as necessary for the purpose it was collected, or as required by law and professional standards. Engagement records and evidence are retained according to the schedule agreed in each engagement, then securely destroyed.
7How we secure your information
We apply appropriate, reasonable technical and organisational measures, including encryption in transit and at rest, least-privilege access with multi-factor authentication, continuous monitoring, and staff vetting. A fuller description is available in our Trust Centre.
8Your rights
Subject to POPIA, you have the right to:
- Request access to the personal information we hold about you.
- Request correction or deletion of your personal information.
- Object to processing, or withdraw consent where processing is based on consent.
- Lodge a complaint with the Information Regulator.
9PAIA requests
Our Promotion of Access to Information Act (“PAIA”) manual explains how to request access to records held by Resilitech, the applicable fees, and the grounds on which access may be refused. Requests must be made on the prescribed form and directed to our Information Officer.
10Contact & Information Officer
For any privacy request, or to exercise your rights, contact our registered Information Officer:
This document is a template for demonstration and must be reviewed by qualified legal counsel before publication. It does not constitute legal advice.

