POPIA customer notice
How Sekretari handles personal information.
This notice explains what information Sekretari (Pty) Ltd collects, why it is needed, who may receive it, how it is protected and the rights available to data subjects.
1. Who is responsible for the information?
Sekretari (Pty) Ltd is the responsible party for personal information processed through this website and portal where Sekretari determines the purpose and means of processing.
Privacy and information requests may be sent to compliance@sekretari.co.za. Sekretari’s registered physical address is not displayed in this portal notice. It may be requested from the compliance contact where required for a formal notice or request.
2. Information collected
Depending on the service, Sekretari may process:
- names, identity or passport details, dates of birth and contact details;
- company, close corporation, trust and other entity information;
- director, member, shareholder, trustee, beneficiary and beneficial-owner information;
- addresses, shareholding, voting rights, control information and appointment details;
- financial statements, turnover figures and supporting accounting records;
- FIC/KYC verification information and risk-related supporting records;
- service requests, correspondence, uploaded documents, payment status and audit records;
- technical information needed to protect the portal, such as login, security and error records.
3. Where information comes from
Information may be collected:
- directly from the client or data subject;
- from a referring accounting, legal or professional firm acting for a client;
- from authorised representatives, directors, members, trustees or employees;
- from public registers and regulatory systems, including CIPC and the Master of the High Court;
- from documents and information already held for an existing client relationship;
- from lawful verification or compliance sources where the service requires it.
4. Why the information is processed
Sekretari processes personal information to:
- identify clients, entities and authorised representatives;
- prepare, review, submit and manage company-secretarial, CIPC, trust, statutory, FIC/KYC and related compliance work;
- issue quotations, confirm payment status, communicate progress and deliver final records;
- meet legal, regulatory, record-keeping, fraud-prevention and professional obligations;
- maintain entity records, compliance calendars, audit trails and service history;
- secure, support, troubleshoot and improve the portal and operational workflow;
- establish, exercise or defend legal rights.
5. Legal grounds
Processing may be based on consent, performance of a contract or mandate, compliance with a legal obligation, protection of a legitimate interest, or Sekretari’s legitimate operational and compliance interests, depending on the information and service involved.
Where special personal information is required, it is processed only where an applicable legal ground or authorisation exists and where it is relevant to the service.
6. Who may receive information?
Information is disclosed only where relevant and reasonably necessary. Recipients may include:
- authorised Sekretari staff and approved service providers acting under appropriate duties;
- the referring firm or authorised representative connected to the request;
- CIPC, the Master of the High Court, the Financial Intelligence Centre, SARS or another competent authority where applicable to the selected service;
- banks, verification providers, auditors, accountants, lawyers or other professional advisers where authorised or legally required;
- Cloudflare, Supabase, email and other infrastructure providers used to host, secure, store or transmit portal information;
- law-enforcement, courts, regulators or public bodies where disclosure is required or permitted by law.
Sekretari does not sell personal information to advertisers.
7. Cloud services and cross-border processing
The portal uses cloud infrastructure and service providers that may process or store information outside South Africa. Sekretari takes reasonable steps to use providers and arrangements that support appropriate confidentiality, security and lawful cross-border processing. A data subject may contact Sekretari for more information about the safeguards relevant to a particular service.
8. Retention
Records are kept only for as long as reasonably required for the service, legal and regulatory obligations, statutory record-keeping, dispute management, audit requirements and legitimate business needs. Retention periods differ according to the record and authority involved. Information is deleted, de-identified or securely restricted when continued retention is no longer justified, subject to lawful retention duties.
9. Security and incidents
Sekretari uses reasonable technical and organisational safeguards, including controlled access, authentication, private document storage, account-level permissions, audit records and operational review. No electronic system can be guaranteed to be risk-free.
Where Sekretari has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the incident will be handled and notifications made as required by applicable law.
10. Data-subject rights
Subject to POPIA and other applicable law, a data subject may:
- ask whether Sekretari holds personal information about them;
- request access to that information;
- request correction, deletion or destruction of inaccurate, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- object to processing in circumstances permitted by law;
- withdraw consent where processing is based on consent, without affecting prior lawful processing;
- complain to Sekretari or the Information Regulator.
Requests should include enough information to verify identity and locate the relevant records. Some requests may be refused or limited where another law requires retention or protects the rights of another person.
11. Complaints
Privacy concerns should first be sent to compliance@sekretari.co.za so that Sekretari can investigate and respond.
A complaint may also be submitted to the Information Regulator of South Africa through its official complaints process: Information Regulator complaints portal.
12. Changes to this notice
This notice may be updated when services, systems, providers or legal requirements change. The effective date above identifies the version currently presented through the portal.