Version 1.0 · published 24 September 2026
NTECH Privacy Policy
This policy explains how NTECH collects, uses, shares and protects personal information, and what your rights are under the Protection of Personal Information Act 4 of 2013 (POPIA). It applies to:
- visitors to the NTECH website
- NTECH clients and their staff who use the client portal and app
- businesses we contact about our services
1. Who is responsible
Responsible party: NTECH Digital Solutions (Pty) Ltd, trading as NTECH, registration number 2026/764182/07, KwaZulu-Natal, South Africa. NTECH works remotely and has no walk-in premises. Contact for anything privacy-related: info@ntech.website
Information Officer: under POPIA, the head of a company is its Information Officer. At NTECH that is the director, who handles every privacy question and request personally. Write to info@ntech.website and mark it "Privacy".
Websites NTECH hosts for clients: for personal information collected through those websites (e.g. their contact forms), the client business is the responsible party and NTECH acts only as its operator (see section 9).
2. What we collect
| Who | Information | How we get it |
|---|---|---|
| Website visitors | Name, email, phone and message (if you contact us); basic technical data (IP address, browser, pages visited) | Contact forms, WhatsApp, and our web server's standard logs |
| Clients and portal users | Name, business name and details, role, email, phone, billing details (invoices and payment references; we do not store card numbers), portal login data (hashed password, two-factor and passkey settings), support tickets and attachments, agreement acceptance records (date, time, IP address, browser, document version), notification preferences | You, when you sign up or use the portal and app |
| Prospective clients | Business name, publicly listed business contact details, public website information; if we meet, our notes of the meeting and, only with your permission, an audio recording of it | Public sources (e.g. your website, Google Business listing, directories), or you |
| App users | Device push-notification token (only if you allow notifications) | Your device |
We don't intentionally collect special personal information (e.g. health, religion, biometric data) or information about children.
3. Why we use it (purpose and lawful basis)
| Purpose | Lawful basis (POPIA s11) |
|---|---|
| Providing our services: building, hosting and maintaining websites, support, the portal and app | Performing our contract with you |
| Invoicing, collecting payment, keeping financial records | Contract; legal obligation (tax records) |
| Recording acceptance of agreements (SLA, Terms and others) | Contract; our legitimate interest in proving what was agreed |
| Security: protecting accounts, preventing fraud and abuse, monitoring our systems | Legitimate interest; legal obligation |
| Answering enquiries | Your request, taking steps before a contract |
| Sending service messages (downtime alerts, ticket replies, renewal reminders) | Contract |
| Telling you about new NTECH services | Your consent, or you are an existing client (you can opt out any time) |
| Contacting a business once to ask whether it would like to see a website concept | Legitimate interest. POPIA s69 allows one approach to ask for consent to direct marketing; if you say no or don't reply, we stop |
| Understanding what a business needs from its website: meeting notes, and a recording if you agreed to one | Your consent (for the recording); taking steps before a contract |
| Keeping our website working and secure (server logs) | Legitimate interest |
4. Who we share it with
We share personal information only when needed for the purposes above, with service providers bound by confidentiality and security obligations:
| Type of service provider | Why | Location |
|---|---|---|
| Our hosting and domain registration provider | Hosting the portal, client websites and email; registering and renewing domains | South Africa |
| Our backup provider | Encrypted off-site backups | South Africa or abroad |
| Our payment provider | Processing card payments (they receive your payment details directly — we never see or store card numbers) | South Africa |
| Website performance and security services | Checking your website's speed and keeping connections secure (only your website address is sent) | Global |
| Mapping and business-listing services | Finding local businesses that may need a website, from their public listings | Global |
| An AI assistant service | Transcribing meeting recordings and summarising meeting notes, so nothing you asked for is missed | Global |
| Our professional advisers (accountant, attorney) | Legal and tax compliance | South Africa |
We describe these by role rather than by name because the specific providers change from time to time, and publishing the exact make-up of our infrastructure would make it easier to attack. If you want to know exactly who processes your information today, ask us and we will tell you — you are entitled to that under POPIA, and we will answer in writing within 30 days. Operators are appointed under written contracts requiring confidentiality and POPIA-compliant security, and we remain accountable for what they do with your information.
We may also disclose information when the law requires it. We do not sell personal information.
5. Information sent outside South Africa
Some of these providers may process information outside South Africa. We only use providers that are subject to laws or binding agreements giving adequate protection, as required by POPIA s72.
6. How long we keep it
| Information | Kept for |
|---|---|
| Client and billing records | 5 years after the relationship ends (tax and accounting requirements) |
| Agreement acceptance records | 5 years after the agreement ends |
| Support tickets and attachments | 3 years after the ticket is closed, then deleted or anonymised |
| Portal accounts | Deactivated when the relationship ends; deleted after 12 months |
| Website enquiries (no contract) | 12 months |
| Prospect details | Deleted within 30 days if you decline or don't reply to our one approach |
| Meeting recordings | Deleted about a week after the meeting notes are written. The notes follow the enquiry or client periods above |
| Client website data we host as operator | 30 days after service ends (see the Care Plan Agreement), then deleted |
| Monitoring and security logs | 90 days |
These periods are enforced, not just written down. The NTECH system tracks the retention date of every record above and flags it for deletion or anonymisation when its period ends, so nothing is kept simply because nobody remembered to remove it. Where the law requires us to keep something longer (tax records, for example), that requirement wins and we keep only what the law asks for.
7. How we protect it
- Encrypted connections (HTTPS) everywhere; passwords stored only as secure hashes.
- Two-factor authentication and passkeys available for portal users, and required for NTECH administrators.
- Strict separation between clients: you can only see your own business's information in the portal.
- Private storage for attachments and documents (never publicly accessible).
- Least-privilege access, activity logs, security updates, and regular tested backups.
- Credentials for client systems are kept in an encrypted password manager, never in email or plain text.
If there's a breach: if we reasonably believe your personal information has been accessed or acquired by an unauthorised person, we will notify you and the Information Regulator as soon as reasonably possible, as POPIA s22 requires.
8. Your rights
You have the right to:
- ask whether we hold your personal information, and get a copy (access)
- correct or delete inaccurate, outdated or unlawfully held information
- object to processing based on legitimate interest, and to opt out of direct marketing at any time
- withdraw consent (this won't affect processing that happened before)
- complain to the Information Regulator
To exercise a right, email our Information Officer at info@ntech.website. We may need to confirm your identity. We'll respond within 30 days. Most requests are free; where the law allows a fee (e.g. for large access requests), we'll tell you first.
Information Regulator (South Africa): https://inforegulator.org.za · complaints: POPIAComplaints@inforegulator.org.za · general enquiries: enquiries@inforegulator.org.za · Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. (Checked 23 September 2026.)
9. Websites we host for clients (NTECH as operator)
When we host or maintain a client's website, we:
- process visitors' information only on the client's instructions, to host, secure, back up and maintain the website
- keep it confidential and secure
- notify the client without undue delay about any security compromise
- delete it when our service ends
Questions about how a client's website uses your information should go to that business. Its own privacy notice applies.
10. Cookies
- NTECH website, client portal and app: only strictly necessary cookies and storage — to keep you logged in, protect forms from forgery and remember your preferences (for example, that you have seen the cookie notice). They are needed for the site to work. We do not use advertising or analytics cookies. If that ever changes, we will ask for your consent first and update this policy.
11. Changes to this policy
We may update this policy. The version and effective date are shown at the top. Significant changes are announced by email and in the portal.