Legal

Privacy Policy

This policy explains what personal information Digitel Africa collects, why we collect it, and the choices and rights you have. We aim to say it plainly, without legal fog.

Version

2.1

Effective

1 August 2026

Last updated

24 August 2026

Reading time

9 min

Jurisdiction

South Africa

01

Overview & scope#

In shortWe are Digitel Africa, a South African digital infrastructure provider, and this policy covers the personal information we handle when you use our website and services.

Digitel Africa Pty Ltd ("Digitel Africa", "we", "us") provides digital infrastructure to African businesses, including business email, DNS, web hosting, our cloud and app platform, managed PostgreSQL databases, domain registration, SSL certificates, VPN, and related professional services such as DevOps, support, monitoring, security, software development, consulting, and training.

This policy applies to personal information we process as a responsible party (the term POPIA uses; GDPR calls this a "controller") — for example, information about the people who visit our website, sign up, buy from us, or contact our support team. It explains what we collect, why, who we share it with, and the rights you can exercise.

Two roles to keep in mind

When we handle account, billing, and support data, we act as the responsible party. When you store your own data on our services — email, hosted sites, databases, DNS records — we act as an operator (a "processor") handling that data on your behalf under your instructions and your contract with us. This policy focuses on the first role; how we treat customer-stored content is summarised in the section on information we collect.

We are governed primarily by South Africa's Protection of Personal Information Act, 2013 (POPIA). Where we offer services to, or collect information from, people in the EU or EEA, the General Data Protection Regulation (GDPR) also applies, and we honour its requirements for those individuals.

02

Information we collect#

In shortWe collect the account, billing, technical, and support information needed to run our services, plus we host the content and data you choose to store with us.

We collect information you give us directly, information generated as you use our services, and a limited amount from third parties such as payment and fraud-prevention providers. The table below summarises the categories.

Categories of personal information we collect
CategoryExamplesWhy we collect it
Account & contact dataName, work email, phone number, company name, role, username, authentication credentialsTo create and secure your account, provide the service, and communicate with you
Billing & transaction dataBilling name and address, VAT/tax details, invoices, plan and usage records, partial card details and payment references handled by our payment processorTo process payments, prevent fraud, and meet tax and accounting obligations
Customer content & stored dataEmails, hosted website files, database records, DNS records, domain and certificate details, and any personal information about third parties that you choose to store on our servicesTo deliver the services you have purchased; we handle this as your operator under your instructions
Technical & usage dataIP address, device and browser type, log files, timestamps, pages and features used, diagnostic and performance metricsTo operate, secure, troubleshoot, and improve the services — see our security practices
Support & communications dataSupport tickets, chat and email correspondence, call notes, feedback and survey responsesTo respond to requests, resolve issues, and improve our support
Cookies & similar identifiersCookie IDs and similar signals set when you use our websiteSee Cookies & similar technologies for detail

We do not deliberately seek out special personal information (such as health, religion, or biometric data) to run our services. If such information reaches us because you store it on the platform, we handle it as your operator under your contract, not for our own purposes.

03

How we use your information#

In shortWe use your information to deliver and secure the services, bill you, support you, comply with the law, and — on clear bases — improve and market our services.

Under POPIA every use must have a lawful justification; under GDPR every use must have a legal basis. We rely on the following:

  • To provide the services you have signed up for — provisioning, authentication, delivery, and account management. *Basis: performance of our contract with you; POPIA processing necessary to carry out a contract.*
  • To bill you and prevent fraud — invoicing, payment processing, and detecting abuse. *Basis: contract, and compliance with legal obligations such as tax and accounting law.*
  • To secure and maintain our platform — monitoring, logging, backups, and incident response. *Basis: our legitimate interests / POPIA legitimate interests in keeping the service safe and reliable.*
  • To support you — responding to tickets and communicating about outages, changes, and security. *Basis: contract and legitimate interests; service messages are not marketing.*
  • To comply with law — responding to lawful requests and meeting regulatory duties. *Basis: legal obligation.*
  • To improve our services — analysing aggregated usage and diagnostics. *Basis: legitimate interests, with safeguards to limit impact on you.*
  • To send marketing about relevant products — where permitted, and always with an easy opt-out. *Basis: consent where required, otherwise legitimate interests.*

Where we rely on consent (for example, certain cookies or marketing), you can withdraw it at any time without affecting processing already carried out.

04

Cookies & similar technologies#

In shortWe use a small set of cookies to keep the site working, remember preferences, and understand usage — you control the optional ones.

Our website uses strictly necessary cookies to function, plus optional cookies for preferences and product analytics. We do not use advertising cookies that track you across other websites.

You can accept or reject optional cookies and change your choice at any time. For the full list, purposes, and durations, see our Cookie Policy.

05

How we share information — sub-processors & third parties#

In shortWe share data only with vetted sub-processors that help us run the service, and with authorities where the law requires — we never sell your personal information.

We do not sell your personal information

We have never sold personal information and we do not trade it for value. We share it only as described here, and our sub-processors may use it solely to perform services for us under written contracts.

To operate our services we rely on a limited set of sub-processors. We describe them by category rather than by brand so this stays accurate over time; a current list is available on request from our privacy team.

Categories of sub-processors
PurposeData involvedLocation
Cloud hosting & computeCustomer content, technical and account dataSouth Africa and other regions, depending on the service and your chosen region
Content delivery & DNS/securityIP addresses, request metadataGlobal edge network
Email deliverabilityEmail addresses, message metadata for transactional and notification emailsEU and other regions
Payment processingBilling details and payment referencesEU / South Africa
Fraud prevention & identity checksAccount and transaction signalsEU / South Africa
Product analyticsPseudonymised usage and diagnostic dataEU / South Africa
Customer support toolingSupport tickets and contact detailsEU / South Africa

We may also disclose information to comply with a valid legal request, to enforce our terms, to protect the rights and safety of our users or the public, or as part of a business transfer (such as a merger or acquisition), in which case we will require the recipient to honour this policy.

06

International data transfers#

In shortWhen data moves outside South Africa, we make sure it stays protected to POPIA and GDPR standards.

Some of our sub-processors are located outside South Africa, so your information may be transferred and processed in other countries. We only make such transfers where the law allows and appropriate safeguards are in place.

  • Under POPIA section 72, we transfer personal information across borders only when the recipient is subject to comparable protection, the transfer is necessary to perform our contract with you, or you have consented.
  • Under GDPR, transfers out of the EEA rely on an adequacy decision or on appropriate safeguards such as Standard Contractual Clauses, together with any additional measures needed to protect the data.
  • Where you can select a hosting region for your services, we honour that choice for the customer content stored there.
07

How long we keep data#

In shortWe keep personal information only as long as needed for the purpose it was collected, then delete or anonymise it.

Retention periods depend on the type of data and our legal obligations. The following are our general guidelines; specific periods may vary where the law requires.

Typical retention periods
DataRetention period
Account & contact dataFor the life of your account, then up to 12 months after closure unless a longer period is legally required
Customer content & stored dataFor as long as your service is active; deleted or returned after termination according to your contract, subject to a short backup rotation window
Billing & tax recordsUp to 5 years (or longer) as required by South African tax and company law
Support communicationsUp to 24 months after a ticket is resolved
Technical & security logsTypically 12 months, with security-relevant logs kept longer where needed for investigations
Marketing preferencesUntil you unsubscribe, plus a suppression record so we honour your opt-out

When a retention period ends, we securely delete or irreversibly anonymise the information.

08

Your privacy rights#

In shortYou can access, correct, delete, object to, and export your personal information, and complain to a regulator if you are unhappy.

Subject to POPIA and, where it applies, GDPR, you have the following rights over your personal information:

Access
Ask whether we hold personal information about you and get a copy of it.
Correction
Ask us to fix information that is inaccurate, misleading, or out of date.
Deletion
Ask us to delete or destroy information we no longer have a lawful reason to keep.
Objection
Object, on reasonable grounds, to processing based on legitimate interests, and object at any time to direct marketing.
Portability
Where GDPR applies, receive certain data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider where technically feasible.
Withdraw consent
Withdraw any consent you previously gave, without affecting processing already done.
Complain
Lodge a complaint with a supervisory authority — see the final section for how to reach the Information Regulator (South Africa).

To exercise any of these rights, email our privacy team. We will verify your identity and respond within the timeframes set by applicable law. These rights are free to use, though we may decline or charge a reasonable fee for requests that are clearly excessive or repetitive, and some rights have legal limits.

If you are an end user of our customer

If your data sits on our platform because you deal with one of our business customers (for example, you email an address they host with us), that customer is the responsible party. Please direct your request to them; we will support them in responding.

09

How we protect your data#

In shortWe use layered technical and organisational safeguards to keep your information secure.

We apply encryption in transit, access controls, network security, monitoring, and regular backups, and we limit access to personal information to staff who need it. No system is perfectly secure, but we work continuously to reduce risk and to respond quickly to incidents.

For a fuller description of our controls and how to report a vulnerability, see our security practices. If a security compromise affects your personal information, we will notify you and the Information Regulator as required by POPIA.

10

Children's privacy#

In shortOur services are built for businesses and are not directed at children.

Our services are intended for businesses and the professionals who work in them. We do not knowingly collect personal information from children under 18, and we do not target our services at children.

If you believe a child has provided us with personal information without appropriate consent, please contact our privacy team and we will take steps to delete it.

11

Changes to this policy & how to contact us#

In shortWe will tell you about material changes, and you can reach our privacy team or the Information Regulator with any concerns.

We may update this policy as our services, the law, or our practices change. When we make material changes, we will update the version and dates at the top of this page and, where appropriate, notify you by email or an in-product notice. The current version is 2.1, effective 2026-08-01.

Contact us

For any privacy question or to exercise your rights, contact our Privacy team at [email protected]. We will do our best to resolve your concern directly.

Complaints to the regulator

If you are not satisfied with how we have handled your information, you may lodge a complaint with the Information Regulator (South Africa), our supervisory authority under POPIA. You can reach them via inforegulator.org.za. If GDPR applies to you, you may also complain to the data protection authority in your country of residence.

Questions about this privacy policy?

Our privacy team is here to help. Email us and a real person will get back to you.

Digitel Africa Pty Ltd · Version 2.1 · Effective 1 August 2026Back to top ↑