POPIA Compliance Notice
Last updated: 10 March 2026
- About POPIA
- Our Information Officer
- Personal Information We Process
- Purpose of Processing
- Lawful Basis for Processing
- Data Subject Rights
- Transborder Information Flows
- Data Retention
- Security Safeguards
- Complaints and Enforcement
- PAIA Manual
- Contact the Information Regulator
1. About POPIA
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's primary data protection legislation. It regulates how responsible parties (organisations that collect and process personal information) must handle the personal information of data subjects (natural and juristic persons).
POPIA came into full effect on 1 July 2021. Non-compliance may result in administrative fines of up to R10 million and/or imprisonment for up to 10 years.
LinkDaddy LLC ("we", "us", "our") is the responsible party in terms of POPIA for all personal information collected through linkdaddybuild.com and its associated services.
2. Our Information Officer
In terms of section 55 of POPIA, we have appointed an Information Officer who is responsible for ensuring compliance with POPIA and handling data subject requests.
Our Information Officer has been registered with the Information Regulator as required by section 55(1) of POPIA. Data subjects may direct all POPIA-related requests and complaints to the Information Officer at the contact details above.
3. Personal Information We Process
We process the following categories of personal information in the ordinary course of our business:
| Category | Examples | Source |
|---|---|---|
| Contact information | Name, email address, phone number | Provided by data subject |
| Business information | Company name, website URL, business type | Provided by data subject |
| Technical data | IP address, browser type, device identifiers | Automatically collected |
| Usage data | Pages visited, time on site, referral source | Automatically collected |
| Communication records | Enquiry content, support messages | Provided by data subject |
| Payment identifiers | Stripe customer ID (no card data stored) | Stripe payment processor |
We do not process special categories of personal information (as defined in section 26 of POPIA) such as race, health, religious beliefs, or biometric data.
4. Purpose of Processing
We process personal information only for the following specific, explicitly defined, and lawful purposes:
- To respond to website audit requests and service enquiries.
- To deliver website development, repair, and digital infrastructure services.
- To process payments and manage billing through our payment processor (Stripe).
- To send service-related communications, including project updates and invoices.
- To improve our website and services through anonymised analytics.
- To comply with applicable legal obligations.
- To protect the security and integrity of our systems.
We do not use personal information for automated decision-making or profiling that produces legal or similarly significant effects on data subjects.
5. Lawful Basis for Processing
In terms of section 11 of POPIA, we process personal information on the following lawful grounds:
- Consent of the data subject (e.g., newsletter sign-up, cookie consent).
- Necessity for the performance of a contract to which the data subject is a party (e.g., service delivery).
- Compliance with a legal obligation (e.g., tax records, anti-money laundering requirements).
- Legitimate interests of the responsible party or a third party (e.g., fraud prevention, website security), where such interests are not overridden by the interests of the data subject.
6. Data Subject Rights
In terms of POPIA, data subjects have the following rights, which may be exercised by contacting our Information Officer:
To exercise any of the above rights, please submit a written request to our Information Officer at [email protected]. We will respond within 30 days of receiving your request.
7. Transborder Information Flows
LinkDaddy LLC is incorporated in the United States of America. As a result, personal information collected from South African data subjects may be transferred to and processed in the United States, which may not have equivalent data protection laws to South Africa.
In terms of section 72 of POPIA, we transfer personal information outside South Africa only where:
- The recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA.
- The data subject consents to the transfer.
- The transfer is necessary for the performance of a contract between the data subject and the responsible party.
Our primary third-party processors (including Stripe, AWS, and analytics providers) maintain their own GDPR/POPIA-equivalent compliance programmes and data processing agreements.
8. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
- Client project records: 5 years after project completion (for tax and legal compliance).
- Enquiry and contact records: 2 years from last interaction.
- Analytics data: 26 months (anonymised after 12 months).
- Payment records: 7 years (as required by financial regulations).
- Cookie consent records: 1 year from consent date.
Upon expiry of the applicable retention period, personal information is securely deleted or anonymised in accordance with section 14 of POPIA.
9. Security Safeguards
In terms of section 19 of POPIA, we have implemented appropriate technical and organisational measures to secure the integrity and confidentiality of personal information in our possession or under our control. These measures include:
- Encrypted data transmission using HTTPS/TLS 1.3.
- Role-based access controls limiting data access to authorised personnel only.
- Regular security assessments and vulnerability testing.
- Secure cloud infrastructure with SOC 2-compliant providers.
- No storage of payment card data (all payments processed by Stripe).
- Incident response procedures for data breach notification.
In the event of a security compromise that may affect your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.
10. Complaints and Enforcement
If you believe we have infringed your rights under POPIA, you may:
- Contact our Information Officer first at [email protected] to allow us to address your concern.
- If unresolved, submit a complaint to the Information Regulator (South Africa) using Form 5 (Complaint Form) available at www.inforegulator.org.za.
11. PAIA Manual
In terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), private bodies are required to compile a PAIA Manual describing the categories of records held and the procedure for requesting access to those records.
Our PAIA Manual is available on request from our Information Officer at [email protected]. Requests for access to records must be submitted using Form C as prescribed under PAIA.
The South African Human Rights Commission (SAHRC) provides a guide on how to use PAIA, available at www.sahrc.org.za.
12. Contact the Information Regulator
The Information Regulator is the independent supervisory authority established under POPIA to enforce data protection rights in South Africa.
Opsomming in Afrikaans (Summary in Afrikaans)
Wet op Beskerming van Persoonlike Inligting (POPIA) — Hierdie kennisgewing verduidelik hoe LinkDaddy LLC u persoonlike inligting insamel, gebruik en beskerm ooreenkomstig die Wet op Beskerming van Persoonlike Inligting 4 van 2013 (Suid-Afrika).
Inligtingsbeampte: Anthony James Peacock — [email protected]
U regte ingevolge POPIA sluit in: Die reg op toegang tot u persoonlike inligting, die reg op regstelling of verwydering van onjuiste inligting, die reg om beswaar te maak teen die verwerking van u inligting, en die reg om 'n klagte by die Inligtingsreguleerder in te dien.
Inligtingsreguleerder (Suid-Afrika): www.inforegulator.org.za — [email protected]
Ons versamel slegs die persoonlike inligting wat nodig is om ons dienste te lewer. Ons verkoop nie u inligting aan derde partye nie. U kan te eniger tyd versoek dat u inligting verwyder word deur ons Inligtingsbeampte te kontak.
Isifinyezo ngesiZulu (Summary in isiZulu)
Umthetho Wokuqinisekiswa Kwemininingwane Yomuntu Siqu (POPIA) — Lesi saziso sichaza indlela i-LinkDaddy LLC eqoqa, isebenzisa futhi ivikela ngayo imininingwane yakho yomuntu siqu ngokuvumelana noMthetho Wokuqinisekiswa Kwemininingwane Yomuntu Siqu Wezi-2013 (iNingizimu Afrika).
Izikhalazo: Unelungelo lokuthola imininingwane yakho, ukulungisa imininingwane engalungile, ukuphikisa ukusetshenziswa kwemininingwane yakho, nokukhipha isikhalazo ku-Information Regulator.
Isikhulu Sezinhlelo Zemininingwane: Anthony James Peacock — [email protected]
I-Information Regulator: www.inforegulator.org.za — [email protected]
Isishwankathelo ngesiXhosa (Summary in isiXhosa)
Umthetho Wokhuseleko Lwezinto Zobuqu (POPIA) — Esi saziso sichaza indlela i-LinkDaddy LLC eqokelela, isebenzisa kwaye ikhuselela ngayo iinkcukacha zakho zobuqu ngokuvumelana noMthetho Wokhuseleko Lwezinto Zobuqu Wama-2013 (uMzantsi Afrika).
Amalungelo akho phantsi kwePOPIA: Unelungelo lokufumana iinkcukacha zakho, ukulungisa iinkcukacha ezingachanekanga, ukuchasa ukusetyenziswa kwezinkcukacha zakho, kunye nokufaka isikhalazo ku-Information Regulator.
Igosa Lolwazi: Anthony James Peacock — [email protected]
I-Information Regulator: www.inforegulator.org.za — [email protected]
