POPIA and your rights
The rights the Protection of Personal Information Act gives you over what we hold, how to exercise them, and how to complain to the Information Regulator.
- Last updated
- 1 August 2026
- Applies to
- bonangtech.com and our services
- Questions
- info@bonangtech.com
The privacy policy says what we collect and why. This document is the other half of it: what the Protection of Personal Information Act, 2013 (POPIA) entitles you to do about it.
Our information officer
The information officer of Bonang M Investments (Pty) Ltd, trading as Bonang Technologies, is the managing director, registered with the Information Regulator as POPIA requires. Every request, objection and complaint in this document goes to the same place: info@bonangtech.com, +27 72 823 2999, or in writing at Sunninghill, Sandton, Johannesburg, 2196, South Africa.
The conditions we process under
POPIA sets eight conditions for lawful processing. They are not a formality here; they are the reason several things on this site work the way they do.
- Accountability. One named person is responsible, and that person is reachable on the details above.
- Processing limitation. We collect the minimum that lets us answer you or do the work, and only with your consent, under a contract, or because the law requires it.
- Purpose specification. We say what a field is for at the point we ask for it, and we do not find a second use for it later.
- Further processing limitation. Information given for a quote is used for that quote. It does not become a marketing list.
- Information quality. We keep what we hold accurate, and we correct it when you tell us it is wrong.
- Openness. This document and the privacy policy are the notice POPIA requires, published rather than sent on request.
- Security safeguards. Set out in full in the security policy: multi-factor authentication, least privilege, encryption in transit, and backups that get restored on a schedule.
- Data subject participation. Everything in the next section.
What you can ask us to do
- Be told what we hold. A description of the personal information we have about you, and who it has been given to. That request runs through PAIA, and the PAIA manual explains how.
- Correct it. Anything inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully.
- Have it deleted. Where we no longer have a lawful reason to keep it and no law requires us to.
- Object to processing. Where our reason for holding it is legitimate interest rather than your consent or a contract.
- Withdraw consent. For anything you agreed to rather than anything a contract or a statute requires.
- Not be marketed at. Section 69 of POPIA, covered in its own section below.
- Not be subject to a decision made purely by a machine. We do not make decisions about people automatically, so this one has nothing to bite on here, and we will say so if that ever changes.
- Complain. To us first if you are willing, and to the Information Regulator whether or not you are.
How to exercise them
Write to info@bonangtech.com with what you want and enough detail for us to find you in our records. We will ask for proof of identity, because handing your information to somebody who says they are you would be the worse failure. We answer inside thirty days, and where we cannot, we say why before the thirty days are up rather than after.
A request to know what we hold, or to correct or delete it, costs you nothing. A request for copies of records follows the PAIA process and the prescribed fees, which we will put in writing before anything is charged.
Direct marketing
We send one newsletter and it goes only to addresses that asked for it. Every message carries an unsubscribe link that works immediately and without a reply from us. Under section 69 you may also object in writing at any time, and we record the objection against your details so a future list cannot pick you up again. We do not buy contact lists and we do not cold-call.
Where your information goes
Some of the providers we use process information outside South Africa. Section 72 permits that where the receiving country or the contract with the provider gives protection substantially similar to POPIA, and the providers we use are bound by written data processing terms that do exactly that. The security policy lists who they are and what each one touches.
If something goes wrong
Section 22 requires us to notify the Information Regulator and every affected person where there are reasonable grounds to believe personal information has been accessed by somebody who should not have it. We do that as soon as reasonably possible after establishing the facts, in writing, saying what happened, what it means for you and what to do about it. We would rather tell you early and be wrong about the extent than be certain and late.
The Information Regulator
You may complain to the Information Regulator at any time, and you do not have to come to us first.
- Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
- Postal: P.O. Box 31533, Braamfontein, Johannesburg, 2017.
- Telephone: 010 023 5200.
- General enquiries: enquiries@inforegulator.org.za.
- POPIA complaints: POPIAComplaints@inforegulator.org.za.
- PAIA complaints: PAIAComplaints@inforegulator.org.za.
You also keep every right you have in a civil court. Nothing in this document limits that.