PRIVACY POLICY
I and D Technology Solutions cc
Effective Date: 1 September 2026
Last Updated: 1 September 2026
Website: www.idts.co.za
1. Introduction
I and D Technology Solutions cc (“IDTS”, “we”, “us” or “our”) respects the privacy of our clients, prospective clients, business partners, suppliers, website visitors and other individuals whose personal information we process.
IDTS provides technology services including cybersecurity and Security Operations Centre (“SOC”) services, managed IT and technical support, technology consulting, software and web development, system integration, cloud and infrastructure services, security monitoring, vulnerability and risk management, incident response and related digital services.
This Privacy Policy explains how we collect, use, store, protect, disclose and otherwise process personal information.
We process personal information in accordance with applicable privacy and data protection legislation, including where applicable:
- the Protection of Personal Information Act 4 of 2013 (“POPIA”) in South Africa;
- the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”);
- the General Data Protection Regulation (“GDPR”) where it applies to our processing activities;
- the UK GDPR and other applicable United Kingdom data protection legislation where applicable; and
- other privacy and cybersecurity legislation applicable to the services we provide or the jurisdictions in which our clients operate.
This Privacy Policy should be read together with our Website Terms & Conditions and Cookie Policy.
2. Who is responsible for your personal information?
For personal information collected and used by IDTS for our own business purposes, I and D Technology Solutions cc is the responsible party for purposes of POPIA and, where applicable, the controller for purposes of the GDPR or UK GDPR.
Our contact details are:
I and D Technology Solutions cc
59 Lospalmos, Bryntirrold Road
Lonehill
2191
South Africa
Email: hello@idts.co.za
Telephone: +27 87 550 0546
Website: www.idts.co.za
Privacy and POPIA-related enquiries may be addressed to our Information Officer through the above contact details.
Please use “Privacy / POPIA Request” in the subject line where possible.
3. When IDTS acts on behalf of a client
Because IDTS provides cybersecurity, SOC, managed IT, cloud, remote support and other technology services, we may sometimes process personal information on behalf of our clients.
In these circumstances, the client will normally determine why the personal information is processed and IDTS will act as an operator under POPIA or a processor under applicable GDPR legislation.
When acting in this capacity, we:
- process personal information in accordance with the client’s lawful instructions and our applicable service agreement;
- use the information only to provide, maintain, secure or support the agreed services;
- apply appropriate technical and organisational safeguards;
- restrict access to authorised personnel and approved service providers;
- maintain confidentiality obligations;
- assist clients with data protection obligations where required by law or contract; and
- notify the relevant client where we become aware of a personal information security incident affecting information processed on that client’s behalf.
Where you wish to exercise privacy rights regarding information that IDTS processes solely on behalf of one of our clients, you may need to direct your request to that client. Where appropriate, we will assist the client in responding to the request.
4. Personal information we may collect
The personal information we collect depends on your relationship with IDTS and the services being provided.
4.1 Contact and identification information
We may process information such as:
- name and surname;
- business or organisation name;
- job title or role;
- email address;
- telephone or mobile number;
- business address;
- billing address; and
- other information you provide when contacting us.
4.2 Client and contractual information
When providing services, we may process:
- client account information;
- authorised user and contact information;
- service agreements and project information;
- quotations and purchase orders;
- correspondence;
- technical requirements;
- support requests;
- project documentation;
- records of instructions and approvals; and
- information necessary to administer the client relationship.
4.3 Billing, payment and credit information
We may process:
- billing information;
- invoice and transaction records;
- payment information;
- account balances;
- payment history;
- company or business information;
- authorised representative details;
- information relating to credit applications or credit facilities;
- information necessary to assess or manage commercial risk; and
- information required for debt collection or enforcement of contractual obligations.
Where permitted by law, information relevant to credit risk, fraud prevention or debt recovery may also be obtained from lawful public records, professional advisers, credit-related service providers or other legitimate sources.
We do not generally require clients to provide payment card details directly to IDTS unless this is specifically required for an approved payment service.
4.4 Website and technical information
When you use our website or online services, certain technical information may be collected automatically, including:
- IP address;
- browser type and version;
- device type;
- operating system;
- referring website;
- pages viewed;
- dates and times of visits;
- approximate location derived from an IP address;
- cookie identifiers;
- website performance information; and
- security and diagnostic information.
Further information regarding cookies is available in our Cookie Policy.
4.5 Support and remote-access information
Where IDTS provides IT support or remote technical assistance, we may process information such as:
- user names and account identifiers;
- device names;
- device and operating-system information;
- network information;
- IP addresses;
- system configuration;
- support tickets;
- diagnostic information;
- screenshots or information visible during a support session;
- communications between users and support personnel; and
- information necessary to diagnose or resolve a technical issue.
Remote access is used only for legitimate support, maintenance, administration or security purposes and subject to the applicable client arrangements.
4.6 Cybersecurity and SOC information
Where IDTS provides cybersecurity, monitoring or SOC services, we may process technical and security information generated by client systems.
Depending on the service and configuration, this may include:
- IP addresses;
- hostnames;
- usernames and account identifiers;
- authentication and login events;
- endpoint information;
- network and firewall events;
- application and system logs;
- security alerts;
- malware or threat indicators;
- vulnerability information;
- configuration information;
- process and service information;
- file names, file paths, hashes and metadata;
- email addresses contained in security events;
- device identifiers;
- access records;
- audit logs;
- incident information; and
- other telemetry necessary to detect, investigate, respond to or prevent cybersecurity threats.
Where incident response, digital investigation or forensic services are required, additional information may be encountered or collected where reasonably necessary to investigate the incident.
IDTS does not use client security information for unrelated commercial purposes.
4.7 Communications
We may retain communications including:
- email;
- telephone records where lawfully maintained;
- support communications;
- instant or electronic messages;
- meeting records;
- correspondence; and
- instructions relating to services or transactions.
5. How we collect personal information
We may collect information:
- directly from you;
- through our website;
- when you contact us by email, telephone or electronic messaging;
- when you submit an enquiry or request a quotation, audit, assessment or consultation;
- through our support systems and support portal;
- when you become a client, supplier or business partner;
- through contracts, purchase orders and other business documentation;
- when providing cybersecurity, SOC, monitoring, managed IT or remote support services;
- automatically from systems, devices and infrastructure that we have been authorised to monitor;
- from a client who provides or makes information available to us for service delivery;
- from our authorised service providers and business partners;
- from publicly available or lawful commercial sources where appropriate; and
- through cookies and similar technologies.
Where personal information is provided to IDTS by a client about the client’s employees, customers, contractors or other users, the client is responsible for ensuring that it has an appropriate legal basis for providing that information to IDTS.
6. Why we process personal information
We may process personal information for purposes including:
Providing our services
To:
- respond to enquiries;
- prepare quotations and proposals;
- enter into and administer contracts;
- deliver technology and consulting services;
- develop and maintain software and websites;
- provide managed IT services;
- provide technical support;
- remotely diagnose and resolve technical problems;
- provide cybersecurity and SOC services;
- monitor systems for security threats;
- identify vulnerabilities;
- investigate cybersecurity incidents;
- provide incident response services;
- manage cloud and infrastructure services;
- provide backups and recovery services; and
- produce technical, security or compliance reports.
Client administration
To:
- manage client relationships;
- maintain client accounts;
- communicate regarding projects and services;
- manage service requests;
- provide service notifications;
- maintain records of instructions and approvals;
- administer service agreements; and
- manage renewals and changes to services.
Billing and financial administration
To:
- issue quotations and invoices;
- process payments;
- manage credit facilities;
- reconcile accounts;
- manage overdue amounts;
- prevent fraud;
- assess commercial risk;
- recover debts;
- maintain accounting records; and
- comply with financial and tax obligations.
Security and fraud prevention
To:
- protect IDTS infrastructure;
- protect client systems where we have been authorised to do so;
- detect unauthorised activity;
- investigate security events;
- prevent fraud, abuse and cyberattacks;
- maintain access and audit records;
- manage vulnerabilities; and
- enforce our security policies and contractual rights.
Legal and regulatory compliance
To:
- comply with applicable laws;
- respond to lawful regulatory requests;
- comply with court orders;
- maintain legally required business records;
- investigate legal claims;
- establish, exercise or defend legal rights; and
- meet applicable privacy, information-security and cybersecurity obligations.
Service improvement
We may use appropriate operational and technical information to:
- improve our services;
- diagnose service problems;
- monitor performance;
- improve security;
- develop internal procedures; and
- improve our technical platforms.
Where practical, aggregated or de-identified information will be used for these purposes.
7. Lawful grounds for processing
Depending on the circumstances and applicable legislation, IDTS processes personal information where:
- you have given consent;
- processing is necessary to enter into or perform a contract;
- processing is necessary to comply with a legal obligation;
- processing protects a legitimate interest of the data subject;
- processing is necessary for our legitimate business interests or those of a third party, provided those interests do not unjustifiably override the rights of the individual;
- processing is necessary for the proper performance of our services; or
- another lawful basis recognised by applicable data protection legislation applies.
Where processing is based on consent, you may withdraw that consent, subject to applicable legal and contractual limitations.
Withdrawal of consent does not affect processing that was lawful before consent was withdrawn.
8. Is providing personal information mandatory?
In many cases, providing personal information is voluntary.
However, certain information may be required in order for IDTS to:
- respond to an enquiry;
- prepare a quotation;
- verify an authorised client contact;
- enter into a contract;
- provide technical or cybersecurity services;
- provide account or support access;
- process a transaction;
- extend credit;
- issue an invoice; or
- comply with a legal obligation.
If required information is not provided, we may be unable to provide the relevant service or complete the requested transaction.
9. Cookies and website analytics
Our website may use cookies and similar technologies for purposes including:
- essential website functionality;
- security;
- remembering user preferences;
- website performance;
- analytics; and
- understanding how visitors interact with the website.
Where consent is legally required for non-essential cookies, those cookies should only be activated in accordance with the user’s cookie preferences.
Users may review or change their cookie preferences through the cookie consent facility available on our website.
Further details are available in our Cookie Policy:
https://idts.co.za/cookies-policy/
10. Direct marketing
IDTS may occasionally communicate with existing or prospective clients regarding relevant services, cybersecurity information, business updates or related offerings where permitted by law.
Electronic direct marketing will only be conducted where permitted under applicable law.
Where consent is required, we will seek the required consent before sending unsolicited electronic marketing.
Existing clients may receive communications regarding similar IDTS products or services where legally permitted.
You may opt out of direct marketing at any time by:
- using an unsubscribe facility included in the communication, where available; or
- contacting us at hello@idts.co.za.
Requests to stop direct marketing will not prevent us from sending operational, security, billing, contractual or service-related communications that are necessary for an existing business relationship.
11. When we share personal information
IDTS does not sell personal information.
We may disclose personal information where reasonably necessary to:
- employees and authorised personnel;
- contractors and consultants;
- approved cybersecurity and technology partners;
- hosting and cloud infrastructure providers;
- email and productivity service providers;
- security-monitoring providers;
- backup and storage providers;
- IT support and remote-access platforms;
- CRM, service desk and ticketing providers;
- domain, DNS and website infrastructure providers;
- accounting and financial administration providers;
- banks and payment providers;
- professional advisers;
- insurers;
- auditors;
- legal representatives;
- debt-collection or recovery service providers;
- authorised subcontractors or white-label service providers;
- regulators, courts or government authorities where required by law; and
- a purchaser, successor or other relevant party in connection with a legitimate business restructuring, sale or transfer, subject to appropriate confidentiality and privacy safeguards.
Service providers that process personal information on our behalf are required, where applicable, to process the information for authorised purposes and to maintain appropriate confidentiality and security safeguards.
Some IDTS services may involve third-party technology products selected or approved by the client. Those providers may have their own privacy terms and data-processing obligations.
12. International transfers of information
IDTS operates from South Africa but provides technology services to clients in multiple jurisdictions and may use cloud, security, communications or infrastructure providers located outside South Africa.
Accordingly, personal information may in certain circumstances be stored, accessed or processed in another country.
Where we transfer personal information internationally, we take reasonable steps to ensure that the transfer is lawful and that appropriate protection is in place.
Depending on the circumstances, these protections may include:
- transferring information to a country with appropriate data-protection legislation;
- contractual data-protection obligations;
- appropriate data-transfer agreements;
- recognised adequacy mechanisms;
- binding obligations on the recipient;
- consent where appropriate; or
- another transfer mechanism permitted under POPIA, GDPR, UK GDPR or other applicable legislation.
Where IDTS processes personal information internationally on behalf of a client, transfers will also be subject to the applicable client agreement and lawful instructions.
13. Information security
As a technology and cybersecurity service provider, IDTS recognises the importance of protecting personal information against unauthorised access, alteration, disclosure, destruction, loss or misuse.
We implement reasonable and appropriate technical and organisational safeguards based on the nature of the information and the risks associated with processing.
These measures may include, where appropriate:
- access controls;
- role-based permissions;
- authentication controls;
- multi-factor authentication;
- encryption in transit;
- encryption of stored information where appropriate;
- network security;
- endpoint security;
- security monitoring;
- vulnerability management;
- file-integrity and system monitoring;
- logging and auditing;
- malware protection;
- secure backups;
- patching and system maintenance;
- incident-detection and response procedures;
- restricted administrative access;
- confidentiality obligations;
- staff security awareness; and
- supplier and service-provider controls.
No internet-connected environment can be guaranteed to be completely secure. IDTS therefore continually reviews security risks and adapts safeguards where reasonably necessary.
14. Personal information security incidents
If we have reasonable grounds to believe that personal information under our responsibility has been accessed, acquired, disclosed, altered or destroyed by an unauthorised person, we will investigate the incident and take appropriate steps to contain and remediate it.
Where required by applicable law, we will notify the relevant regulator and affected individuals.
Where IDTS is processing personal information on behalf of a client, we will notify the client in accordance with applicable law and contractual requirements so that the client can fulfil its responsibilities as responsible party or controller.
15. Retention of personal information
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or subsequently lawfully processed.
Retention periods may depend on:
- the duration of the client relationship;
- the type of service provided;
- contractual obligations;
- security and incident-response requirements;
- legitimate operational requirements;
- applicable limitation periods;
- tax, accounting and corporate record requirements;
- regulatory obligations; and
- actual or potential legal proceedings.
Security logs, system telemetry and monitoring information may be retained for periods appropriate to the cybersecurity service being provided and the client’s requirements.
Client information processed on behalf of a client may be retained or deleted in accordance with the applicable service agreement and the client’s lawful instructions.
When information is no longer required, we will take reasonable steps to securely delete, destroy or de-identify it, subject to applicable legal requirements.
16. Accuracy of information
We take reasonable steps to ensure that personal information used by IDTS is accurate, complete and not misleading where this is necessary for the purpose for which it is processed.
You should notify us if information that we hold about you changes or is incorrect.
17. Your privacy rights
Subject to applicable legislation, you may have the right to:
- ask whether IDTS holds personal information about you;
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion or destruction where legally permitted;
- object to certain processing;
- object to direct marketing;
- withdraw consent where processing is based on consent;
- request restriction of processing where applicable;
- request portability of certain information where applicable under GDPR legislation;
- receive information regarding how your personal information is processed; and
- lodge a complaint with the appropriate data-protection authority.
Some rights are subject to legal limitations.
For example, we may be required to retain information for tax, contractual, security, regulatory or legal reasons even where deletion has been requested.
We may request reasonable information to verify your identity before acting on a privacy request.
18. Rights relating to client-controlled information
Where IDTS holds information solely because we are providing services to another organisation, that organisation may be the responsible party or controller for the information.
If you submit a privacy request relating to such information, we may:
- inform you that the relevant client is responsible for the request;
- refer the request to the client; or
- assist the client with the request in accordance with our contractual and legal obligations.
We will not independently alter or delete client-controlled information where doing so would conflict with lawful client instructions or our obligations as an operator or processor.
19. Special personal information
IDTS does not ordinarily seek to collect special or sensitive categories of personal information through its public website.
However, cybersecurity, technical support, incident response or forensic activities may sometimes result in IDTS encountering information that contains sensitive or special personal information.
Where this occurs, we will process such information only where necessary, authorised and legally permitted, and subject to appropriate safeguards.
You should not submit sensitive personal information to IDTS unless it is reasonably required for a legitimate service or we have requested it.
20. Automated systems and cybersecurity monitoring
IDTS uses technology and automated security systems to identify suspicious events, vulnerabilities, abnormal activity and potential cyber threats.
These systems may automatically analyse technical data and generate alerts or risk indicators.
Automated cybersecurity detection does not ordinarily constitute a decision that produces legal or similarly significant effects concerning an individual.
Security alerts may be reviewed, investigated or escalated by authorised personnel where appropriate.
IDTS does not use the public website to make solely automated decisions about individuals that produce legal or similarly significant effects unless this is specifically disclosed and permitted by applicable law.
21. Children’s personal information
IDTS’s website and services are primarily intended for businesses and adult users.
We do not knowingly collect personal information directly from children through the website for marketing purposes.
Where children’s personal information is processed as part of a client system or service, IDTS will process that information only where appropriately authorised and in accordance with applicable law and the client’s instructions.
22. Third-party websites and services
Our website may contain links to websites, platforms or services operated by third parties.
IDTS does not control the privacy practices of independent third parties.
You should review the privacy policies of those organisations before providing them with personal information.
Where a third-party service is directly integrated into an IDTS service, the privacy responsibilities of the respective parties will depend on the nature of the integration and applicable agreements.
23. Business changes
If IDTS undergoes a merger, restructuring, acquisition, sale of assets or transfer of part of its business, personal information may be transferred to the relevant successor or acquiring entity where lawful and reasonably necessary.
Any recipient will be required to handle the information in accordance with applicable privacy legislation and appropriate confidentiality obligations.
24. Complaints
If you have a concern regarding the way IDTS processes your personal information, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.
Contact:
I and D Technology Solutions cc
Email: hello@idts.co.za
Telephone: +27 87 550 0546
You also have the right to lodge a complaint with the relevant data-protection authority.
South Africa
Information Regulator (South Africa)
Woodmead North Office Park
54 Maxwell Drive
Woodmead
Johannesburg
2191
Telephone: 010 023 5200
Toll Free: 0800 017 160
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Where GDPR or UK data-protection legislation applies, you may also have the right to complain to the competent supervisory authority in the relevant jurisdiction.
25. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time to reflect:
- changes in our services;
- changes in technology;
- changes in our processing activities;
- changes to service providers;
- legal or regulatory changes; or
- improvements to our privacy and security practices.
The updated version will be published on our website and the “Last Updated” date will be amended.
Material changes may also be communicated through other reasonable means where appropriate.
26. Contact us
For questions regarding this Privacy Policy, requests concerning your personal information, or other privacy-related matters, please contact:
I and D Technology Solutions cc
Email: hello@idts.co.za
Telephone: +27 87 550 0546
Website: www.idts.co.za
Please use “Privacy / POPIA Request” in the subject line where possible.