Overview & scope#
In shortWe are Digitel Africa, a South African digital infrastructure provider, and this policy covers the personal information we handle when you use our website and services.
Digitel Africa Pty Ltd ("Digitel Africa", "we", "us") provides digital infrastructure to African businesses, including business email, DNS, web hosting, our cloud and app platform, managed PostgreSQL databases, domain registration, SSL certificates, VPN, and related professional services such as DevOps, support, monitoring, security, software development, consulting, and training.
This policy applies to personal information we process as a responsible party (the term POPIA uses; GDPR calls this a "controller") — for example, information about the people who visit our website, sign up, buy from us, or contact our support team. It explains what we collect, why, who we share it with, and the rights you can exercise.
Two roles to keep in mind
When we handle account, billing, and support data, we act as the responsible party. When you store your own data on our services — email, hosted sites, databases, DNS records — we act as an operator (a "processor") handling that data on your behalf under your instructions and your contract with us. This policy focuses on the first role; how we treat customer-stored content is summarised in the section on information we collect.
We are governed primarily by South Africa's Protection of Personal Information Act, 2013 (POPIA). Where we offer services to, or collect information from, people in the EU or EEA, the General Data Protection Regulation (GDPR) also applies, and we honour its requirements for those individuals.
Information we collect#
In shortWe collect the account, billing, technical, and support information needed to run our services, plus we host the content and data you choose to store with us.
We collect information you give us directly, information generated as you use our services, and a limited amount from third parties such as payment and fraud-prevention providers. The table below summarises the categories.
| Category | Examples | Why we collect it |
|---|---|---|
| Account & contact data | Name, work email, phone number, company name, role, username, authentication credentials | To create and secure your account, provide the service, and communicate with you |
| Billing & transaction data | Billing name and address, VAT/tax details, invoices, plan and usage records, partial card details and payment references handled by our payment processor | To process payments, prevent fraud, and meet tax and accounting obligations |
| Customer content & stored data | Emails, hosted website files, database records, DNS records, domain and certificate details, and any personal information about third parties that you choose to store on our services | To deliver the services you have purchased; we handle this as your operator under your instructions |
| Technical & usage data | IP address, device and browser type, log files, timestamps, pages and features used, diagnostic and performance metrics | To operate, secure, troubleshoot, and improve the services — see our security practices |
| Support & communications data | Support tickets, chat and email correspondence, call notes, feedback and survey responses | To respond to requests, resolve issues, and improve our support |
| Cookies & similar identifiers | Cookie IDs and similar signals set when you use our website | See Cookies & similar technologies for detail |
We do not deliberately seek out special personal information (such as health, religion, or biometric data) to run our services. If such information reaches us because you store it on the platform, we handle it as your operator under your contract, not for our own purposes.
How we use your information#
In shortWe use your information to deliver and secure the services, bill you, support you, comply with the law, and — on clear bases — improve and market our services.
Under POPIA every use must have a lawful justification; under GDPR every use must have a legal basis. We rely on the following:
- To provide the services you have signed up for — provisioning, authentication, delivery, and account management. *Basis: performance of our contract with you; POPIA processing necessary to carry out a contract.*
- To bill you and prevent fraud — invoicing, payment processing, and detecting abuse. *Basis: contract, and compliance with legal obligations such as tax and accounting law.*
- To secure and maintain our platform — monitoring, logging, backups, and incident response. *Basis: our legitimate interests / POPIA legitimate interests in keeping the service safe and reliable.*
- To support you — responding to tickets and communicating about outages, changes, and security. *Basis: contract and legitimate interests; service messages are not marketing.*
- To comply with law — responding to lawful requests and meeting regulatory duties. *Basis: legal obligation.*
- To improve our services — analysing aggregated usage and diagnostics. *Basis: legitimate interests, with safeguards to limit impact on you.*
- To send marketing about relevant products — where permitted, and always with an easy opt-out. *Basis: consent where required, otherwise legitimate interests.*
Where we rely on consent (for example, certain cookies or marketing), you can withdraw it at any time without affecting processing already carried out.
International data transfers#
In shortWhen data moves outside South Africa, we make sure it stays protected to POPIA and GDPR standards.
Some of our sub-processors are located outside South Africa, so your information may be transferred and processed in other countries. We only make such transfers where the law allows and appropriate safeguards are in place.
- Under POPIA section 72, we transfer personal information across borders only when the recipient is subject to comparable protection, the transfer is necessary to perform our contract with you, or you have consented.
- Under GDPR, transfers out of the EEA rely on an adequacy decision or on appropriate safeguards such as Standard Contractual Clauses, together with any additional measures needed to protect the data.
- Where you can select a hosting region for your services, we honour that choice for the customer content stored there.
How long we keep data#
In shortWe keep personal information only as long as needed for the purpose it was collected, then delete or anonymise it.
Retention periods depend on the type of data and our legal obligations. The following are our general guidelines; specific periods may vary where the law requires.
| Data | Retention period |
|---|---|
| Account & contact data | For the life of your account, then up to 12 months after closure unless a longer period is legally required |
| Customer content & stored data | For as long as your service is active; deleted or returned after termination according to your contract, subject to a short backup rotation window |
| Billing & tax records | Up to 5 years (or longer) as required by South African tax and company law |
| Support communications | Up to 24 months after a ticket is resolved |
| Technical & security logs | Typically 12 months, with security-relevant logs kept longer where needed for investigations |
| Marketing preferences | Until you unsubscribe, plus a suppression record so we honour your opt-out |
When a retention period ends, we securely delete or irreversibly anonymise the information.
Your privacy rights#
In shortYou can access, correct, delete, object to, and export your personal information, and complain to a regulator if you are unhappy.
Subject to POPIA and, where it applies, GDPR, you have the following rights over your personal information:
- Access
- Ask whether we hold personal information about you and get a copy of it.
- Correction
- Ask us to fix information that is inaccurate, misleading, or out of date.
- Deletion
- Ask us to delete or destroy information we no longer have a lawful reason to keep.
- Objection
- Object, on reasonable grounds, to processing based on legitimate interests, and object at any time to direct marketing.
- Portability
- Where GDPR applies, receive certain data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider where technically feasible.
- Withdraw consent
- Withdraw any consent you previously gave, without affecting processing already done.
- Complain
- Lodge a complaint with a supervisory authority — see the final section for how to reach the Information Regulator (South Africa).
To exercise any of these rights, email our privacy team. We will verify your identity and respond within the timeframes set by applicable law. These rights are free to use, though we may decline or charge a reasonable fee for requests that are clearly excessive or repetitive, and some rights have legal limits.
If you are an end user of our customer
If your data sits on our platform because you deal with one of our business customers (for example, you email an address they host with us), that customer is the responsible party. Please direct your request to them; we will support them in responding.
How we protect your data#
In shortWe use layered technical and organisational safeguards to keep your information secure.
We apply encryption in transit, access controls, network security, monitoring, and regular backups, and we limit access to personal information to staff who need it. No system is perfectly secure, but we work continuously to reduce risk and to respond quickly to incidents.
For a fuller description of our controls and how to report a vulnerability, see our security practices. If a security compromise affects your personal information, we will notify you and the Information Regulator as required by POPIA.
Children's privacy#
In shortOur services are built for businesses and are not directed at children.
Our services are intended for businesses and the professionals who work in them. We do not knowingly collect personal information from children under 18, and we do not target our services at children.
If you believe a child has provided us with personal information without appropriate consent, please contact our privacy team and we will take steps to delete it.
Changes to this policy & how to contact us#
In shortWe will tell you about material changes, and you can reach our privacy team or the Information Regulator with any concerns.
We may update this policy as our services, the law, or our practices change. When we make material changes, we will update the version and dates at the top of this page and, where appropriate, notify you by email or an in-product notice. The current version is 2.1, effective 2026-08-01.
Contact us
For any privacy question or to exercise your rights, contact our Privacy team at [email protected]. We will do our best to resolve your concern directly.
Complaints to the regulator
If you are not satisfied with how we have handled your information, you may lodge a complaint with the Information Regulator (South Africa), our supervisory authority under POPIA. You can reach them via inforegulator.org.za. If GDPR applies to you, you may also complain to the data protection authority in your country of residence.
Questions about this privacy policy?
Our privacy team is here to help. Email us and a real person will get back to you.