Privacy Policy
Effective Date: January 2024
Last Updated: January 2024
Herbst Group (Pty) Ltd ("Herbst Group", "we", "us", or "our") is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website herbstgroup.io and engage with our services.
This policy is designed to comply with the Protection of Personal Information Act 4 of 2013 ("POPIA") of South Africa.
1. Information We Collect
1.1 Personal Information You Provide
We may collect personal information that you voluntarily provide to us, including:
- Name and surname
- Email address
- Phone number
- Company name and job title
- Correspondence and communications with us
- Any other information you choose to provide
1.2 Information Collected Automatically
When you visit our website, we may automatically collect certain information, including:
- Browser type and version
- Operating system
- Pages visited and time spent on pages
- Referring website
- General geographic location (country/region level)
We use Plausible Analytics, a privacy-friendly analytics service that does not use cookies or collect personal data. This data is aggregated and cannot be used to identify you personally.
2. How We Use Your Information
We process your personal information for the following purposes:
- To respond to your inquiries and provide requested information
- To deliver our consulting services
- To send you relevant communications (with your consent)
- To improve our website and services
- To comply with legal obligations
- To protect our legitimate business interests
3. Legal Basis for Processing (POPIA)
Under POPIA, we process your personal information based on the following lawful grounds:
- Consent: Where you have given us explicit consent to process your information
- Contract: Where processing is necessary for the performance of a contract with you
- Legal obligation: Where we need to comply with a legal obligation
- Legitimate interest: Where processing is necessary for our legitimate business interests
4. Information Sharing and Disclosure
We may share your personal information in the following circumstances:
- Service providers: Third-party vendors who assist us in operating our website and delivering services (under strict confidentiality agreements)
- Legal requirements: When required by law, court order, or governmental authority
- Business transfers: In connection with any merger, acquisition, or sale of assets
- With your consent: For any other purpose with your explicit consent
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
5. Cross-Border Transfers
Your personal information may be transferred to and processed in countries outside South Africa. When we transfer personal information internationally, we ensure appropriate safeguards are in place to protect your information in accordance with POPIA requirements.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL)
- Secure hosting infrastructure
- Access controls and authentication
- Regular security assessments
We are working toward ISO 27001 certification to demonstrate our commitment to information security best practices.
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Retention periods vary depending on the type of information:
- Contact form submissions: 3 years
- Client records: 7 years after end of engagement
- Marketing communications: Until you unsubscribe
- Website analytics: 2 years (aggregated, non-personal)
8. Your Rights Under POPIA
As a data subject under POPIA, you have the following rights:
- Right to access: Request confirmation of whether we hold your personal information and obtain a copy
- Right to correction: Request correction of inaccurate or incomplete personal information
- Right to deletion: Request deletion of your personal information where it is no longer necessary
- Right to object: Object to processing of your personal information based on legitimate interests
- Right to restrict processing: Request restriction of processing in certain circumstances
- Right to data portability: Request a copy of your data in a structured, machine-readable format
- Right to withdraw consent: Withdraw previously given consent at any time
To exercise any of these rights, please contact our Information Officer using the details provided below.
9. Cookies
Our website uses only essential cookies required for the website to function. We do not use tracking cookies or third-party advertising cookies.
We use Plausible Analytics, which is a privacy-focused analytics service that does not use cookies and does not collect personal data.
Any non-essential cookies require your explicit opt-in consent before being set, in compliance with POPIA requirements.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read the privacy policies of any third-party websites you visit.
11. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy periodically.
13. Contact Information
Information Officer
For questions about this Privacy Policy or to exercise your data protection rights, please contact our Information Officer:
Information OfficerHerbst Group (Pty) Ltd
Suite E106, Midlands Office Park East
1 Mount Quray Street, Midlands Estate
Olifantsfontein, 1682
South Africa
Email: privacy@herbstgroup.io
Phone: +27 10 158 4336
Information Regulator (South Africa)
If you are not satisfied with how we have handled your personal information, you have the right to lodge a complaint with the Information Regulator:
Information Regulator (South Africa)JD House, 27 Stiemens Street
Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Email: enquiries@inforegulator.org.za
Website: www.justice.gov.za/inforeg/