Privacy Policy
1. Introduction
- Tecleo Cyber Solutions CC t/a Tecleo Data Recovery and Digital Forensics Lab (“TECLEO”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal information entrusted to us.
- Because our business involves data recovery, digital forensics, eDiscovery and related technical services, confidentiality and the responsible handling of information form an important part of our operations.
- This Privacy Policy explains how we collect, use, store, process, disclose and protect personal information when you use our website, contact us, request a quotation, become a customer, use our services, subscribe to communications or otherwise interact with us.
- We process personal information in accordance with applicable South African law, including the Protection of Personal Information Act 4 of 2013 (“POPIA”), where applicable.
- This Privacy Policy should be read together with our Terms and Conditions and any service-specific agreement, quotation, work order, confidentiality agreement or other terms applicable to the services you request.
2. Responsible Party
For personal information processed for our own business purposes, the responsible party is:
Tecleo Cyber Solutions CC
trading as Tecleo Data Recovery and Digital Forensics Lab
trading as Tecleo Data Recovery and Digital Forensics Lab
Registration No.: CK97/25667/23
Physical address:
20 Uitzicht Park
2 Bellingham Street
Centurion
South Africa
0157
20 Uitzicht Park
2 Bellingham Street
Centurion
South Africa
0157
Telephone: +27 (0)12 665 2945
Email:This email address is being protected from spambots. You need JavaScript enabled to view it.
Website: www.datarecovery.co.za
Email:
Website: www.datarecovery.co.za
Privacy, POPIA and Information Officer enquiries may be directed to us using the contact details above.
3. What is Personal Information?
- “Personal information” has the meaning given to it in POPIA and generally includes information relating to an identifiable natural or juristic person.
- Depending on the circumstances, this may include names, identity and contact details, addresses, email addresses, telephone numbers, employment or company information, financial information, correspondence, online identifiers and other information that can identify or relate to a person or organisation.
- Certain categories of information receive additional protection under POPIA, including special personal information and personal information relating to children.
4. Personal Information We Collect
- The type of personal information we collect depends on how you interact with us and the services you request.
- When you contact us, request a quotation, submit a device, open a service request, place an order or otherwise do business with us, we may collect information such as your name and surname, company name, job title, physical or postal address, telephone number, email address, billing information, VAT details, shipping details, service instructions, correspondence and other information reasonably necessary to provide the requested service.
- Where relevant to a data recovery or forensic matter, we may also collect information relating to the device or data source, including its manufacturer, model, serial number, storage capacity, operating system, encryption status, passwords or credentials supplied by you, details of the incident, information about previous recovery attempts and instructions regarding the data required.
- When you use our website, certain technical information may be collected automatically, including your IP address, browser and device information, operating system, referring pages, pages visited, approximate location information derived from an IP address, website usage information, cookies and similar technical identifiers.
- We may also receive personal information from third parties where they are authorised to provide it to us, such as employers, legal representatives, insurers, attorneys, investigators, courier companies, corporate clients or persons acting on behalf of a customer.
- Where you voluntarily provide demographic or other optional information to us, we may process that information for the purpose for which it was supplied.
5. Data Contained on Devices, Media, Systems and Accounts Entrusted to TECLEO
- In providing data recovery, digital forensic, forensic data recovery, eDiscovery, backup, repair, remote recovery and related services, TECLEO may necessarily access or process information contained on devices, storage media, computer systems, mobile devices, servers, RAID systems, backup media, email accounts, cloud accounts, databases or other data sources supplied or made accessible to us.
- This information may contain personal information relating to the customer and may also contain personal information relating to employees, family members, customers, suppliers, correspondents or other third parties. It may, depending on the contents of the device or data source, include special personal information, confidential information, privileged information, financial information or information relating to children.
- TECLEO does not use information contained in client devices, storage media, forensic images, or recovered datasets for unrelated marketing, profiling, or advertising purposes.
- Access to such information is limited to authorised personnel to the extent reasonably necessary to evaluate, recover, image, repair, examine, search, verify, report on or otherwise perform the services authorised by the client.
- Where TECLEO processes personal information on behalf of a client who determines the purpose and means of the processing, TECLEO may act as an operator as contemplated in POPIA. In other circumstances, TECLEO may itself act as the responsible party. The applicable role will depend on the circumstances and nature of the processing.
- Clients submitting devices, accounts, information, or data to TECLEO are responsible for ensuring they have the legal right, authority, or other lawful basis necessary to instruct TECLEO to access and process such information.
6. Digital Forensic and Evidential Information
- Digital forensic investigations may involve the acquisition, preservation, examination, recovery, analysis and reporting of information for legal, regulatory, disciplinary, investigative or evidential purposes.
- Where we are instructed to perform forensic services, information may be preserved in forensic images or other evidential formats to maintain data integrity, chain of custody, and evidential reliability.
- Such information will be processed in accordance with the lawful instructions under which TECLEO has been appointed, any applicable court order or legal process, contractual obligations and applicable law.
- Forensic and evidential information may need to be retained for longer periods than ordinary data recovery working data where required by the client, litigation, an investigation, a court order, a legal hold, professional obligations or applicable law.
7. How We Use Personal Information
- We process personal information only where reasonably necessary and where a lawful basis for processing exists under POPIA.
- We may use personal information to respond to enquiries and quotation requests; identify and communicate with customers; evaluate devices and data-loss situations; provide data recovery, digital forensic and related services; manage work orders and service requests; arrange courier collections and deliveries; provide technical support and customer service; issue quotations, invoices and statements; process and reconcile payments; maintain customer and service records; communicate progress and results; verify authority to access devices or data; protect our systems, customers, employees and business; investigate suspected unlawful activity or fraud; establish, exercise or defend legal rights; comply with court orders and other lawful requirements; improve our services and website; conduct appropriate surveys or request customer feedback; and fulfil our contractual and legal obligations.
- Where applicable, processing may be based on your consent, the conclusion or performance of a contract, compliance with a legal obligation, the protection of a legitimate interest of the data subject, our legitimate interests or those of a third party, or another ground permitted under POPIA.
- We will not process personal information in a manner that is incompatible with the purpose for which it was collected unless permitted by law.
8. Service Communications
- If you request a quotation or become a customer, we may contact you directly regarding your enquiry, quotation, evaluation, work order, device, investigation, recovery, payment, shipping, collection, or other matters related to the service you have requested.
- These are service-related communications and are separate from marketing communications.
- Opting out of marketing communications will therefore not prevent us from contacting you where reasonably necessary to provide a service, administer your account, respond to an enquiry or comply with our contractual or legal obligations.
9. Direct Marketing, Newsletters and Promotional Communications
- TECLEO may send newsletters, product or service information, industry news, promotions and other direct marketing communications where we are lawfully permitted to do so.
- Where required by POPIA, we will obtain your consent before sending unsolicited electronic direct marketing communications.
- If you are an existing customer, we may communicate with you about our similar products or services, where permitted by law, provided that the relevant requirements of POPIA are satisfied.
- Electronic direct marketing may include communications by email, SMS, WhatsApp, telephone or other electronic communication methods.
- We do not provide your personal information to unrelated third parties for their own direct marketing purposes without your consent or another lawful basis permitting us to do so.
- Every electronic marketing communication we send will provide a reasonable means to opt out of further marketing communications.
- You may unsubscribe at any time by following the unsubscribe instructions contained in the relevant communication or by contacting us at
This email address is being protected from spambots. You need JavaScript enabled to view it. . - We will process an opt-out request as soon as reasonably practicable and will not charge you for exercising your right to object to direct marketing.
10. Referrals and Information About Other People
- Where our website or services allow you to send, forward, or refer information to another person, we may process that person's contact information to provide the requested communication or service.
- You should only provide another person's personal information where you are authorised or otherwise legally entitled to do so.
- We will not use information supplied solely for a one-time referral for unrelated direct marketing unless we subsequently obtain an appropriate lawful basis to do so.
11. Cookies and Similar Technologies
- Our website may use cookies and similar technologies to operate correctly, remember preferences, understand how visitors use the website, maintain security, measure website performance and, where applicable, support marketing or advertising activities.
- Some cookies may be essential for the operation of the website, while others may relate to functionality, analytics or marketing.
- We may also use third-party services that place or access cookies or similar technologies, including services used for website analytics, maps, embedded content, security or advertising.
- Where cookies or similar technologies involve the processing of personal information, we will process that information in accordance with POPIA and obtain consent where consent is required by applicable law.
- You can control cookies through the options made available on our website, where applicable, and through your browser settings. Blocking certain cookies may affect the operation or functionality of parts of the website.
12. Website Analytics and Technical Information
- We may use website logs, analytics services and related technologies to understand website traffic, identify technical problems, improve website performance, assess the effectiveness of content or advertising and protect our website against malicious activity.
- Where possible and appropriate, reporting information may be aggregated or de-identified.
- Information that has been irreversibly de-identified so that it cannot reasonably identify a person is not treated as personal information to the extent provided by applicable law.
13. Personalisation
- Where appropriate and lawful, we may use information you have provided, together with information about your interaction with our website or communications, to personalise website content and communications or to provide information about services likely to be relevant to you.
- We will not use information contained within devices, forensic images or datasets entrusted to us for data recovery or forensic purposes to personalise marketing or advertising.
14. Sharing Personal Information
- We do not sell personal information.
- We may disclose personal information to third parties where reasonably necessary to provide our services or operate our business. These may include courier and logistics providers, information technology and hosting providers, cloud service providers, email and communication providers, payment or banking service providers, accountants, auditors, legal advisers, technical specialists, insurers and other authorised contractors or service providers.
- We seek to limit information supplied to service providers to what is reasonably necessary for the relevant service.
- We may also disclose personal information where required or permitted by law, including in response to a valid court order, subpoena, warrant, regulatory requirement or other lawful process; to establish, exercise or defend legal rights; to investigate or prevent fraud or unlawful activity; to protect the safety or rights of another person; or where disclosure is otherwise required by applicable law.
- Where TECLEO encounters information that we are legally required to preserve, report or disclose to a competent authority, we may do so in accordance with applicable law.
15. Operators and Service Providers
- Where a third-party operator processes personal information on our behalf, we take reasonable steps to ensure that the operator processes the information only with our knowledge or authorisation and maintains appropriate confidentiality and security safeguards.
- Where required by POPIA, appropriate contractual arrangements will be put in place with operators processing personal information on our behalf.
- Operators are required to notify us where they have reasonable grounds to believe that personal information processed on our behalf has been accessed or acquired by an unauthorised person.
16. International and Cross-Border Transfers
- Some of our service providers, software platforms, cloud services, hosting providers or other technology suppliers may process or store information outside South Africa.
- Where personal information is transferred to a recipient in another country, TECLEO will take reasonable steps to ensure that the transfer is permitted under section 72 of POPIA.
- Depending on the circumstances, this may include ensuring that the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection; obtaining consent where appropriate; transferring information where necessary for the performance or conclusion of a contract; or relying on another basis permitted under POPIA.
17. Security of Personal Information
- TECLEO takes reasonable and appropriate technical and organisational measures designed to protect personal information in our possession or under our control against loss, damage, unauthorised destruction, unlawful access, unauthorised processing, misuse or disclosure.
- Our safeguards may include physical security, restricted access to client data, access controls, authentication measures, network and system security, encryption where appropriate, secure working procedures, confidentiality obligations, secure storage, logging, monitoring, backup and recovery measures and the secure sanitisation or destruction of information where appropriate.
- Personnel with access to client information are required to maintain confidentiality, and access is limited according to operational requirements.
- No method of electronic communication, storage or information security can provide an absolute guarantee against every possible threat. We therefore continuously review appropriate safeguards having regard to the nature of the information, foreseeable risks and generally accepted information-security practices.
18. Security Compromises
- Where there are reasonable grounds to believe that personal information for which TECLEO is the responsible party has been accessed or acquired by an unauthorised person, we will investigate the incident, take reasonable steps to contain and mitigate it and comply with the notification requirements of POPIA.
- Where required, this includes notifying the Information Regulator and affected data subjects as soon as reasonably possible, subject to any lawful restriction or authorised delay.
- Where TECLEO is acting as an operator and becomes aware of a security compromise involving information processed on behalf of a client, we will notify the responsible party in accordance with POPIA and the applicable contractual arrangements.
19. Data Retention
- We retain personal information only for as long as reasonably necessary for the purpose for which it was collected or subsequently processed, unless retention is required or permitted by law, a contract, a court order, an evidential requirement or another legitimate purpose recognised under POPIA.
- Customer, quotation, accounting, transaction, service, and business records may be retained for periods required by applicable tax, accounting, legal, or regulatory obligations, or where reasonably necessary to establish, exercise, or defend legal rights.
- For standard data recovery matters, unless otherwise agreed in writing or required by the circumstances of the matter, working image drives containing recovered client data are sanitised fourteen (14) days after the client has collected the recovered data, in accordance with our applicable service Terms and Conditions.
- This retention period does not necessarily apply to original storage media belonging to the client, nor to forensic evidence, forensic images or investigation material that must be retained under a separate instruction, agreement, legal hold, court order, evidential requirement or legal obligation.
- When personal information is no longer required, and there is no lawful reason to retain it, we will delete, destroy, or de-identify it using methods appropriate to the nature of the information and the storage medium.
- Residual copies may remain for a limited period within properly managed backup systems until those backups are overwritten or securely retired.
20. Accuracy and Updating of Personal Information
- We take reasonable steps to ensure that personal information we use is complete, accurate, not misleading and updated where necessary for the purpose for which it is processed.
- You are encouraged to inform us if your contact, billing, shipping or other relevant information changes.
- We are not responsible for delays, failed communications or other problems caused by inaccurate or outdated information supplied to us.
21. Your Rights Under POPIA
- Subject to applicable law and any lawful limitations, you may have the right to:
- ask us to confirm whether we hold personal information about you;
- request access to personal information we hold about you;
- request correction or updating of inaccurate, incomplete, excessive, outdated or misleading personal information;
- request deletion or destruction of personal information where we are no longer authorised to retain it;
- object to certain processing of your personal information on reasonable grounds where POPIA permits such an objection;
object at any time to the processing of your personal information for direct marketing; - withdraw consent where processing is based on consent, without affecting the lawfulness of processing that occurred before withdrawal;
- request information about the identity or categories of third parties that have had access to your personal information where applicable; and
- odge a complaint with the Information Regulator if you believe that your personal information has been processed unlawfully.
- We may require reasonable proof of identity before acting on an access, correction, deletion or similar request.
- Some rights are subject to limitations and exceptions under POPIA, the Promotion of Access to Information Act 2 of 2000 (“PAIA”) and other applicable law. For example, we may be required to retain certain information despite a deletion request, or we may be unable to disclose information where doing so would infringe another person's rights, compromise legal privilege, interfere with an investigation or evidence, or otherwise be prohibited by law.
- Where TECLEO processes information solely as an operator on behalf of another responsible party, requests relating to that information may need to be referred to or dealt with in conjunction with the relevant responsible party.
- Requests for access to records under the Promotion of Access to Information Act 2 of 2000 (“PAIA”) must be submitted in accordance with our PAIA Manual, available upon request.
22. Personal Information of Children
- For purposes of this Privacy Policy, references to children are interpreted in accordance with POPIA and applicable South African law.
- We do not knowingly solicit personal information directly from children through our website for marketing purposes without appropriate authorisation or another lawful basis.
- Personal information relating to children may nevertheless be present on devices, storage media, accounts, systems or datasets supplied to TECLEO for data recovery, digital forensic or related professional services.
- Where this occurs, such information will only be processed to the extent reasonably necessary for the authorised service and in accordance with applicable law.
- The person instructing TECLEO is responsible for ensuring that they have the necessary authority or lawful basis to provide the relevant device, account, data or instructions to us.
23. Special Personal Information
- Devices and information sources supplied for data recovery or forensic examination may contain special personal information as contemplated in POPIA.
- TECLEO does not intentionally seek such information unless it is relevant or necessary to the service requested.
- Where special personal information is encountered or must be processed, we will do so only where a lawful basis or authorisation exists and will apply appropriate safeguards, having regard to the sensitivity of the information.
24. Payment Information
- Where payment information is required, we process only the information reasonably necessary to administer, record and reconcile the transaction.
- Where payment card or other payment information is processed directly by an external payment, banking, or financial service provider, that provider may process the information in accordance with its own privacy and security terms.
- TECLEO does not intentionally retain complete payment card information unless necessary, lawful, and appropriately secured.
25. Public Forums, Reviews and Comments
- Where our website or another TECLEO platform allows you to submit a public review, comment, forum post or similar contribution, information you choose to publish may become publicly accessible.
- You should therefore avoid publishing personal, confidential or sensitive information that you do not want others to see.
- Information voluntarily made public by you may be copied, indexed or redistributed by third parties outside TECLEO’s control.
26. Third-Party Websites and Services
- Our website may contain links to third-party websites, embedded media, maps, social media services, or other content controlled by third parties.
- TECLEO does not control the privacy practices of those third parties, and this Privacy Policy does not apply to personal information processed independently by them.
- We encourage you to review the privacy notices of third-party websites and services before providing personal information to them.
27. Automated Decision-Making
- TECLEO does not ordinarily make decisions about customers solely through automated processing where those decisions would have legal consequences or substantially affect the customer.
- If this changes, any automated processing will be implemented in accordance with the requirements of POPIA.
28. Legal and Regulatory Requests
- We may preserve or disclose personal information where we reasonably believe this is necessary to comply with applicable law, a lawful demand from a competent authority, a court order, legal proceedings or another legal obligation.
- We may also process information where reasonably necessary to establish, exercise, or defend legal rights, or to investigate suspected fraud, security incidents, unlawful conduct, or violations of our Terms and Conditions.
- Any such disclosure will be limited to what is reasonably required or authorised in the circumstances.
29. Changes to This Privacy Policy
- We may update this Privacy Policy from time to time to reflect changes in our services, technology, business practices or legal and regulatory requirements.
- The current version will be published on our website, along with the date of its last update.
- Where a change materially affects how we process personal information, we will, where appropriate, take reasonable steps to bring the change to the attention of affected persons.
30. Contacting TECLEO About Your Personal Information
Questions, requests, objections or complaints concerning this Privacy Policy or the processing of personal information may be directed to:
Information Officer / Privacy Enquiries
Tecleo Cyber Solutions CC t/a Tecleo Data Recovery and Digital Forensics Lab
Tecleo Cyber Solutions CC t/a Tecleo Data Recovery and Digital Forensics Lab
20 Uitzicht Park
2 Bellingham Street
Centurion
South Africa
0157
2 Bellingham Street
Centurion
South Africa
0157
Telephone: +27 (0)12 665 2945
Email:This email address is being protected from spambots. You need JavaScript enabled to view it.
Email:
Please include sufficient information so we can identify you and understand your request. We may request proof of identity where appropriate before disclosing or changing personal information.
31. Complaints to the Information Regulator
You have the right to lodge a complaint with the Information Regulator (South Africa) if you believe that your personal information has been processed in contravention of POPIA.
Information Regulator (South Africa)
Woodmead North Office Park
54 Maxwell Drive
Woodmead
Johannesburg
2191
South Africa
54 Maxwell Drive
Woodmead
Johannesburg
2191
South Africa
Telephone: 010 023 5200
Toll Free: 0800 017 160
General enquiries:This email address is being protected from spambots. You need JavaScript enabled to view it.
POPIA complaints:This email address is being protected from spambots. You need JavaScript enabled to view it.
Toll Free: 0800 017 160
General enquiries:
POPIA complaints:
Complaints and other regulatory services may also be accessed through the Information Regulator’s eServices portal.
32. Applicable Law
- This Privacy Policy is governed by the laws of the Republic of South Africa.
- Nothing in this Privacy Policy is intended to limit any rights available to a data subject under POPIA, PAIA or other applicable South African law.