Skip to content
NTECH

Version 1.0 · published 24 September 2026

NTECH Privacy Policy

This policy explains how NTECH collects, uses, shares and protects personal information, and what your rights are under the Protection of Personal Information Act 4 of 2013 (POPIA). It applies to:

  • visitors to the NTECH website
  • NTECH clients and their staff who use the client portal and app
  • businesses we contact about our services

1. Who is responsible

Responsible party: NTECH Digital Solutions (Pty) Ltd, trading as NTECH, registration number 2026/764182/07, KwaZulu-Natal, South Africa. NTECH works remotely and has no walk-in premises. Contact for anything privacy-related: info@ntech.website

Information Officer: under POPIA, the head of a company is its Information Officer. At NTECH that is the director, who handles every privacy question and request personally. Write to info@ntech.website and mark it "Privacy".

Websites NTECH hosts for clients: for personal information collected through those websites (e.g. their contact forms), the client business is the responsible party and NTECH acts only as its operator (see section 9).

2. What we collect

Who Information How we get it
Website visitors Name, email, phone and message (if you contact us); basic technical data (IP address, browser, pages visited) Contact forms, WhatsApp, and our web server's standard logs
Clients and portal users Name, business name and details, role, email, phone, billing details (invoices and payment references; we do not store card numbers), portal login data (hashed password, two-factor and passkey settings), support tickets and attachments, agreement acceptance records (date, time, IP address, browser, document version), notification preferences You, when you sign up or use the portal and app
Prospective clients Business name, publicly listed business contact details, public website information; if we meet, our notes of the meeting and, only with your permission, an audio recording of it Public sources (e.g. your website, Google Business listing, directories), or you
App users Device push-notification token (only if you allow notifications) Your device

We don't intentionally collect special personal information (e.g. health, religion, biometric data) or information about children.

3. Why we use it (purpose and lawful basis)

Purpose Lawful basis (POPIA s11)
Providing our services: building, hosting and maintaining websites, support, the portal and app Performing our contract with you
Invoicing, collecting payment, keeping financial records Contract; legal obligation (tax records)
Recording acceptance of agreements (SLA, Terms and others) Contract; our legitimate interest in proving what was agreed
Security: protecting accounts, preventing fraud and abuse, monitoring our systems Legitimate interest; legal obligation
Answering enquiries Your request, taking steps before a contract
Sending service messages (downtime alerts, ticket replies, renewal reminders) Contract
Telling you about new NTECH services Your consent, or you are an existing client (you can opt out any time)
Contacting a business once to ask whether it would like to see a website concept Legitimate interest. POPIA s69 allows one approach to ask for consent to direct marketing; if you say no or don't reply, we stop
Understanding what a business needs from its website: meeting notes, and a recording if you agreed to one Your consent (for the recording); taking steps before a contract
Keeping our website working and secure (server logs) Legitimate interest

4. Who we share it with

We share personal information only when needed for the purposes above, with service providers bound by confidentiality and security obligations:

Type of service provider Why Location
Our hosting and domain registration provider Hosting the portal, client websites and email; registering and renewing domains South Africa
Our backup provider Encrypted off-site backups South Africa or abroad
Our payment provider Processing card payments (they receive your payment details directly — we never see or store card numbers) South Africa
Website performance and security services Checking your website's speed and keeping connections secure (only your website address is sent) Global
Mapping and business-listing services Finding local businesses that may need a website, from their public listings Global
An AI assistant service Transcribing meeting recordings and summarising meeting notes, so nothing you asked for is missed Global
Our professional advisers (accountant, attorney) Legal and tax compliance South Africa

We describe these by role rather than by name because the specific providers change from time to time, and publishing the exact make-up of our infrastructure would make it easier to attack. If you want to know exactly who processes your information today, ask us and we will tell you — you are entitled to that under POPIA, and we will answer in writing within 30 days. Operators are appointed under written contracts requiring confidentiality and POPIA-compliant security, and we remain accountable for what they do with your information.

We may also disclose information when the law requires it. We do not sell personal information.

5. Information sent outside South Africa

Some of these providers may process information outside South Africa. We only use providers that are subject to laws or binding agreements giving adequate protection, as required by POPIA s72.

6. How long we keep it

Information Kept for
Client and billing records 5 years after the relationship ends (tax and accounting requirements)
Agreement acceptance records 5 years after the agreement ends
Support tickets and attachments 3 years after the ticket is closed, then deleted or anonymised
Portal accounts Deactivated when the relationship ends; deleted after 12 months
Website enquiries (no contract) 12 months
Prospect details Deleted within 30 days if you decline or don't reply to our one approach
Meeting recordings Deleted about a week after the meeting notes are written. The notes follow the enquiry or client periods above
Client website data we host as operator 30 days after service ends (see the Care Plan Agreement), then deleted
Monitoring and security logs 90 days

These periods are enforced, not just written down. The NTECH system tracks the retention date of every record above and flags it for deletion or anonymisation when its period ends, so nothing is kept simply because nobody remembered to remove it. Where the law requires us to keep something longer (tax records, for example), that requirement wins and we keep only what the law asks for.

7. How we protect it

  • Encrypted connections (HTTPS) everywhere; passwords stored only as secure hashes.
  • Two-factor authentication and passkeys available for portal users, and required for NTECH administrators.
  • Strict separation between clients: you can only see your own business's information in the portal.
  • Private storage for attachments and documents (never publicly accessible).
  • Least-privilege access, activity logs, security updates, and regular tested backups.
  • Credentials for client systems are kept in an encrypted password manager, never in email or plain text.

If there's a breach: if we reasonably believe your personal information has been accessed or acquired by an unauthorised person, we will notify you and the Information Regulator as soon as reasonably possible, as POPIA s22 requires.

8. Your rights

You have the right to:

  • ask whether we hold your personal information, and get a copy (access)
  • correct or delete inaccurate, outdated or unlawfully held information
  • object to processing based on legitimate interest, and to opt out of direct marketing at any time
  • withdraw consent (this won't affect processing that happened before)
  • complain to the Information Regulator

To exercise a right, email our Information Officer at info@ntech.website. We may need to confirm your identity. We'll respond within 30 days. Most requests are free; where the law allows a fee (e.g. for large access requests), we'll tell you first.

Information Regulator (South Africa): https://inforegulator.org.za · complaints: POPIAComplaints@inforegulator.org.za · general enquiries: enquiries@inforegulator.org.za · Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. (Checked 23 September 2026.)

9. Websites we host for clients (NTECH as operator)

When we host or maintain a client's website, we:

  • process visitors' information only on the client's instructions, to host, secure, back up and maintain the website
  • keep it confidential and secure
  • notify the client without undue delay about any security compromise
  • delete it when our service ends

Questions about how a client's website uses your information should go to that business. Its own privacy notice applies.

10. Cookies

  • NTECH website, client portal and app: only strictly necessary cookies and storage — to keep you logged in, protect forms from forgery and remember your preferences (for example, that you have seen the cookie notice). They are needed for the site to work. We do not use advertising or analytics cookies. If that ever changes, we will ask for your consent first and update this policy.

11. Changes to this policy

We may update this policy. The version and effective date are shown at the top. Significant changes are announced by email and in the portal.

WhatsApp us