Privacy Policy

POPIA Compliant - Protection of Personal Information

Last Updated: November 15, 2025

1. Introduction

Ngongoni (Pty) Ltd ("Ngongoni," "we," "us," or "our") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African laws.

Responsible Party:
Ngongoni (Pty) Ltd
Registered in South Africa
Email: [email protected]

2. POPIA Compliance

As the Responsible Party under POPIA, Ngongoni processes personal information in accordance with the eight conditions for lawful processing:

  • Accountability: We take responsibility for compliance with POPIA conditions
  • Processing Limitation: We process information lawfully, reasonably, and only for specified purposes
  • Purpose Specification: We collect information for specific, explicitly defined, and lawful purposes
  • Further Processing Limitation: We don't process information for secondary purposes incompatible with the original purpose
  • Information Quality: We take reasonable steps to ensure information is complete, accurate, and not misleading
  • Openness: We maintain documentation and notify you of information processing
  • Security Safeguards: We implement appropriate technical and organizational measures
  • Data Subject Participation: We respect your rights to access and correct your personal information

3. Information We Collect

3.1 Personal Information

We may collect the following types of personal information:

  • Identity Information: Name, surname, identity number, date of birth
  • Contact Information: Email address, phone number, physical address, WhatsApp number
  • Business Information: Company name, registration number, VAT number, tax information
  • Financial Information: Bank account details, payment information, credit history
  • Transaction Information: Purchase history, orders, invoices, payment records
  • Communication Information: Emails, messages, inquiry history, support tickets

3.2 Automatically Collected Information

When you visit our website, we automatically collect:

  • IP address and device information
  • Browser type and version
  • Pages viewed and time spent on pages
  • Referring website addresses
  • Cookies and similar tracking technologies

4. How We Use Your Information

We process your personal information for the following purposes:

4.1 Order Processing and Fulfillment

  • Processing and fulfilling your orders
  • Managing deliveries and logistics
  • Processing payments and invoicing
  • Managing returns and refunds

4.2 Customer Service

  • Responding to inquiries and support requests
  • Providing product information and assistance
  • Resolving disputes and complaints
  • Maintaining customer relationships

4.3 Marketing and Communications

  • Sending promotional materials and newsletters (with your consent)
  • Informing you about new products, services, and offers
  • Conducting market research and surveys
  • Personalizing your experience on our website

4.4 Legal and Compliance

  • Complying with legal obligations (tax, customs, regulatory reporting)
  • Preventing fraud and ensuring security
  • Enforcing our Terms of Service
  • Protecting our rights and property

4.5 Business Operations

  • Analyzing website usage and improving our services
  • Managing credit accounts and assessing creditworthiness
  • Maintaining business records and accounts
  • Internal auditing and quality assurance

5. Legal Basis for Processing

We process your personal information based on the following legal grounds under POPIA:

  • Consent: You have given explicit consent for specific purposes (e.g., marketing communications)
  • Contract: Processing is necessary to fulfill our contractual obligations to you
  • Legal Obligation: Processing is required to comply with South African law
  • Legitimate Interest: Processing is necessary for our legitimate business interests (where not overridden by your rights)

6. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share your information with:

6.1 Service Providers

Third-party service providers who assist with:

  • Logistics and delivery services
  • Payment processing and banking
  • IT services and website hosting
  • Marketing and communication platforms
  • Customer support systems

6.2 Business Partners

Authorized suppliers, manufacturers, and distributors to fulfill orders and provide warranty services.

6.3 Legal Requirements

Government agencies, law enforcement, or courts when:

  • Required by law or legal process
  • Necessary to protect our rights or property
  • To investigate fraud or security issues
  • To comply with tax, customs, or regulatory requirements

6.4 Regional Operations

Our regional offices and affiliates in Zimbabwe, Mozambique, Zambia, and Malawi to facilitate local operations and customer service.

7. Cross-Border Data Transfers

Your information may be transferred to and processed in countries outside South Africa, including Zimbabwe, Mozambique, Zambia, and Malawi. When transferring information internationally, we ensure:

  • Adequate levels of protection as required by POPIA
  • Appropriate contractual safeguards are in place
  • Compliance with applicable data protection laws in each jurisdiction
  • Your rights remain protected regardless of location

8. Data Retention

We retain your personal information for as long as necessary to:

  • Fulfill the purposes outlined in this Privacy Policy
  • Comply with legal, accounting, or regulatory requirements
  • Resolve disputes and enforce our agreements
  • Maintain business records as required by South African law

Typically, we retain transaction records for 7 years in accordance with South African tax and accounting laws. Marketing consent records are retained until you withdraw consent.

9. Your Rights Under POPIA

As a data subject under POPIA, you have the following rights:

Right to Access

Request confirmation of whether we hold your personal information and access to such information.

Right to Correction

Request correction, deletion, or updating of inaccurate or incomplete personal information.

Right to Object

Object to the processing of your personal information on reasonable grounds relating to your particular situation.

Right to Erasure

Request deletion of your personal information (subject to legal retention requirements).

Right to Restriction

Request restriction of processing of your personal information in certain circumstances.

Right to Data Portability

Request your personal information in a structured, commonly used format for transfer to another party.

Right to Withdraw Consent

Withdraw consent for processing at any time (where processing is based on consent).

Right to Lodge a Complaint

Lodge a complaint with the Information Regulator of South Africa if you believe your privacy rights have been violated.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days as required by POPIA.

10. Security Measures

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, loss, destruction, or alteration. Our security measures include:

  • Encryption of sensitive data during transmission (SSL/TLS)
  • Secure storage systems with access controls
  • Regular security assessments and updates
  • Employee training on data protection and confidentiality
  • Restricted access to personal information on a need-to-know basis
  • Backup and disaster recovery procedures
  • Monitoring and logging of system access

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to addressing any security breaches promptly in accordance with POPIA requirements.

11. Cookies and Tracking Technologies

11.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website. We use cookies and similar technologies to enhance your browsing experience, analyze website usage, and deliver personalized content.

11.2 Types of Cookies We Use

Essential Cookies

Required for website functionality, including shopping cart, security, and session management.

Performance Cookies

Collect information about how visitors use our website to improve performance.

Functionality Cookies

Remember your preferences and provide enhanced features.

Marketing Cookies

Track your online activity to deliver relevant advertisements (with your consent).

11.3 Managing Cookies

You can control cookies through your browser settings. Please note that disabling certain cookies may affect website functionality and your user experience.

12. Direct Marketing

In compliance with POPIA Section 69, we only send direct marketing communications with your consent. You have the right to:

  • Opt-in to receive marketing communications about our products, services, and promotions
  • Opt-out or unsubscribe from marketing communications at any time
  • Update your communication preferences
  • Choose your preferred communication channels (email, SMS, WhatsApp)

To unsubscribe, click the unsubscribe link in our marketing emails or contact us at [email protected].

13. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. In compliance with POPIA Section 35, we require verifiable parental or guardian consent before processing personal information of children.

If you believe we have inadvertently collected information from a child without proper consent, please contact us immediately, and we will take steps to delete such information.

14. Third-Party Links

Our website may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

When you click on third-party links, you leave our website and this Privacy Policy no longer applies.

15. Data Breach Notification

In the event of a data breach that compromises the integrity or confidentiality of your personal information, we will:

  • Notify the Information Regulator of South Africa as soon as reasonably possible
  • Inform affected data subjects where the breach is likely to cause harm
  • Provide details of the breach, potential consequences, and remedial measures
  • Take immediate steps to secure systems and prevent further breaches
  • Investigate the cause and implement corrective actions

All breach notifications will comply with POPIA Section 22 requirements.

16. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated through:

  • Prominent notice on our website
  • Email notification to registered customers
  • Updated "Last Updated" date at the top of this policy

Your continued use of our services after changes become effective constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.

17. Information Regulator Contact Details

If you have concerns about how we handle your personal information or wish to lodge a complaint, you may contact the Information Regulator of South Africa:

Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Email: [email protected]

Phone: 010 023 5200

Website: www.justice.gov.za/inforeg

18. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:

Ngongoni (Pty) Ltd - Privacy Office

Data Protection Officer: Available upon request

Email: [email protected]

Website: www.ngongoni.com

Phone: Available on our Contact Page

Request Your Data

Exercise your right to access your personal information we hold.

Update Information

Correct or update your personal information on file.

Marketing Preferences

Manage your communication and marketing preferences.

Delete Account

Request deletion of your personal information.

Your Privacy Matters

We are committed to protecting your personal information in full compliance with POPIA and South African law.

Last Updated: November 15, 2025