Contents
- Introduction
- Who We Are
- Scope of This Policy
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing
- Disclosure to Third Parties
- Cross-Border Transfers
- Online Booking & Payment
- Data Security
- Cookies
- Data Retention
- Your Rights
- Complaints
- Children’s Information
- Changes to This Policy
- Contact Us
1. Introduction
Ubuntu Compliance (Pty) Ltd (“Ubuntu Compliance”, “we”, “us” or “our”) provides accounting, tax, secretarial and business registration services to clients across the Southern African Development Community (“SADC”) region, including through our website where certain services, in particular business registration services, may be booked or purchased online.
We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what personal information we collect, why we collect it, how we use, store, share and protect it, and what rights you have in relation to it. It applies to personal information we collect through our website, our client onboarding processes, email, telephone and any other channel through which we provide our services.
This Policy is drafted with reference to the Protection of Personal Information Act 4 of 2013 (“POPIA”) of South Africa, and, where applicable to clients located elsewhere in the SADC region, the equivalent data protection legislation of those jurisdictions (for example Zimbabwe’s Data Protection Act, Botswana’s Data Protection Act, Mauritius’ Data Protection Act, and similar laws). Where local law imposes a stricter or different standard than this Policy, the local law will prevail for the personal information of individuals in that jurisdiction.
2. Who We Are
Ubuntu Compliance (Pty) Ltd,
Registration number: 2024/171848/07
Registered address: 1 Elias Rd, Vorna valley, Midrand, South Africa
Website: www.ubuntucompliance.com
Information Officer: info@ubuntucompliance.com
We are the “responsible party” (or “data controller”, depending on the jurisdiction) in respect of the personal information described in this Policy, unless we expressly state that we are acting as an “operator” (processor) on behalf of a client, for example when preparing tax returns or statutory filings using information the client has provided to us.
3. Scope of This Policy
This Policy applies to personal information of:
- Visitors to our website, including individuals who make enquiries or request quotes;
- Clients and prospective clients who engage us for accounting, tax, secretarial or business registration services, and their representatives, directors, shareholders, members, trustees or beneficial owners;
- Individuals whose information is submitted to us in connection with a business registration, company secretarial filing, tax matter or accounting engagement (for example directors and shareholders named in a company registration);
- Job applicants and our own personnel, to the extent addressed separately in our internal HR privacy notice.
This Policy does not apply to the practices of third-party websites, government portals or payment processors linked to or used through our website, which are governed by their own privacy policies.
4. Information We Collect
4.1 Information you provide to us
- Identification information: full name, date of birth, identity or passport number, tax reference number, nationality and residential/postal address;
- Contact information: email address, telephone number, and physical or registered business address;
- Business and entity information: company name, registration details, memorandum/articles of incorporation, director and shareholder details, beneficial ownership information, and proof of business address;
- Financial information: bank account details, income and expense records, financial statements, tax records, VAT and payroll information, and other data needed to prepare accounts or tax filings;
- Verification (FICA/KYC) documents: certified copies of identity documents, proof of residence, and other documents required for client due diligence and anti-money laundering compliance;
- Booking and payment information: details submitted when booking or purchasing business registration or other services through our website, including billing address and payment references (card numbers are processed by our payment provider and are not stored by us — see section 9);
- Correspondence: records of emails, calls, meeting notes and other communications with you.
4.2 Information we collect automatically
- Technical information such as your IP address, browser type, device type, operating system and general location, collected when you use our website;
- Usage information such as pages visited, time spent on the site, links clicked, and referring website, collected via cookies and similar technologies (see section 11).
4.3 Information from third parties
- Information from company registries, revenue and tax authorities, credit bureaux, identity verification providers, and other public or regulatory sources, where necessary to perform our services or comply with the law;
- Information from other professionals acting on your behalf, such as attorneys, auditors or other advisors, where you have authorised this.
5. How We Use Your Information
- Provide accounting, tax, secretarial and business registration services, including preparing and lodging statutory filings and returns;
- Process bookings and payments made through our website for business registration and related services;
- Verify your identity and conduct client due diligence and anti-money laundering / “know your client” checks as required by law;
- Communicate with you about your engagement, invoices, deadlines and regulatory obligations;
- Comply with legal, regulatory, tax and professional body obligations, including record-keeping requirements;
- Manage our client relationship, including billing, credit control and internal record-keeping;
- Improve and secure our website and services, and, where you have consented, send you marketing or informational communications;
- Prevent, detect and investigate fraud, error or unlawful activity.
6. Legal Basis for Processing
We rely on one or more of the following grounds to process your personal information, consistent with POPIA and comparable SADC data protection laws:
- Performance of a contract with you, or steps taken at your request before entering into a contract (for example, quoting for and processing a business registration order);
- Compliance with a legal obligation, including tax, company law, exchange control and anti-money laundering requirements;
- Our legitimate business interests, such as running and improving our practice, provided these do not override your rights and interests;
- Your consent, where required, for example for direct marketing or the use of certain cookies; you may withdraw consent at any time.
7. Disclosure of Information to Third Parties
We do not sell personal information. We may share personal information, on a need-to-know basis and subject to appropriate safeguards, with:
- Government departments, revenue authorities, companies and intellectual property registries, and other regulators, as required to register a business, file returns or comply with law;
- Banks and payment service providers, to process payments for services booked or purchased on our website;
- Our professional advisors, auditors, insurers and legal counsel, where necessary;
- IT service providers, cloud hosting and software providers who support our practice management, accounting and website systems, under confidentiality and data processing agreements;
- Other professionals you have authorised us to liaise with on your behalf;
- A purchaser or successor in the event of a merger, sale or restructuring of our business, subject to equivalent privacy protections;
- Any party where disclosure is required by law, court order, or to protect our rights or the safety of others.
All third parties who process personal information on our behalf are required to keep it confidential, use it only for the purposes we specify, and apply appropriate security measures.
8. Cross-Border Transfers Within and Beyond SADC
Because we provide services across the SADC region, personal information may be transferred between our offices, agents or service providers in different SADC countries, and in some cases to service providers located outside the region (for example, cloud hosting providers).
Where we transfer personal information across a country’s borders, we take reasonable steps to ensure the recipient is subject to a law, contract, or binding corporate rules that provide an adequate level of protection substantially similar to POPIA or the equivalent local law, or we obtain your consent to the transfer, or the transfer is otherwise necessary for the performance of a contract with you or in your interest.
9. Online Booking and Payment for Business Registration Services
When you book or purchase business registration or other services through our website, we collect the information necessary to process your order, prepare the relevant registration documents, and issue an invoice or receipt. Payment card details are entered directly into our payment gateway provider’s secure system and are not stored on our own servers; the payment provider processes this information subject to its own privacy and security policies, which we encourage you to review.
Please ensure that any personal information you submit about directors, shareholders, or other individuals in connection with a booking is accurate and that you are authorised to share that information with us for the purpose of the registration.
10. Data Security
We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, alteration, disclosure or destruction, including access controls, encryption where appropriate, secure storage of physical and electronic records, staff confidentiality obligations, and regular review of our security practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we will notify you and, where required, the relevant regulator without undue delay if we become aware of a security compromise that affects your personal information.
11. Cookies and Similar Technologies
Our website uses cookies and similar technologies to operate the site, remember your preferences, process bookings, and understand how visitors use the site. Cookies may be strictly necessary, functional, analytics-based, or used for marketing purposes. You can manage or disable cookies through your browser settings; please note that disabling certain cookies may affect the functionality of our booking system.
12. Data Retention
We retain personal information for as long as necessary to provide our services, to comply with tax, company law, anti-money laundering and other statutory record-keeping requirements (which in many SADC jurisdictions range from five to seven years or longer after the end of an engagement), to establish, exercise or defend legal claims, and for legitimate business and archival purposes. When personal information is no longer needed, we securely delete, destroy or anonymise it.
13. Your Rights as a Data Subject
Subject to applicable law and any exemptions, you have the right to:
- Be informed about how your personal information is processed;
- Request access to the personal information we hold about you;
- Request correction of inaccurate or incomplete personal information;
- Request deletion or destruction of personal information that we are no longer authorised or required to retain;
- Object to the processing of your personal information for direct marketing purposes, or on reasonable grounds relating to your particular situation;
- Withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- Request that we not subject you to a decision based solely on automated processing that significantly affects you;
- Lodge a complaint with the relevant supervisory authority (see section 14).
To exercise any of these rights, please contact our Information Officer using the details in section 2. We may need to verify your identity before actioning a request, and we will respond within the timeframes required by applicable law.
14. Complaints
If you have a concern about how we handle your personal information, we encourage you to contact us first so that we can try to resolve it. You also have the right to lodge a complaint with the relevant data protection authority, which for South Africa is the Information Regulator (details below), or with the equivalent authority in your own SADC jurisdiction. Information Regulator (SA) Email: complaints.IR@justice.gov.za | Website: www.justice.gov.za/inforeg/
15. Children’s Information
Our services are directed at businesses and adults, and we do not knowingly collect personal information directly from children. Where information relating to a minor is required in connection with a company registration or similar service (for example, a minor shareholder), it will only be processed with the consent of, and as submitted by, the minor’s parent or legal guardian, or the client instructing us.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Last updated” date at the top of this Policy indicates when it was last revised. Material changes will be communicated to clients or notified on our website. We encourage you to review this Policy periodically.
17. Contact Us
If you have questions about this Privacy Policy or how we handle your personal information,
Please contact: Info@ubuntucompliance.com
Telephone +27 71 735 8025 .