Privacy Policy

About Prosirius

Prosirius (Pty) LTD

About Prosirius

Proudly South African. Built on experience. A lekker team that gets the job done properly.

Document Classification: Public

Document Owner: Information Officer

Approved By: Board of Directors

Review Cycle: Annually

  1. Introduction

1.1 Purpose

At Prosirius (Pty) Ltd (“Prosirius”, “we”, “our” or “us”), protecting the privacy and security of Personal Information is an integral part of the way we conduct business. As a provider of workplace technology, audiovisual, unified communications, digital signage and systems integration solutions, we understand the importance of safeguarding the information entrusted to us by our customers, suppliers, employees, applicants, business partners and visitors to our website.

This Privacy Policy explains how Prosirius collects, uses, stores, protects, shares and otherwise processes Personal Information in accordance with the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and other applicable South African legislation.

The purpose of this Privacy Policy is to ensure transparency regarding our information handling practices and to explain:

  • what Personal Information we collect;
  • how we collect it;
  • why we process it;
  • when it may be shared with authorised third parties;
  • how it is protected;
  • how long it is retained; and
  • the rights available to Data Subjects under POPIA.

This Privacy Policy serves as Prosirius’ notification to Data Subjects in terms of Section 18 of POPIA.

1.2 Our Commitment to Privacy

Privacy and information governance are fundamental to maintaining the trust of those who do business with us.

Prosirius is committed to processing Personal Information lawfully, fairly and transparently, and only for legitimate business purposes. We collect only the information reasonably necessary to deliver our products and services, fulfil contractual and legal obligations, support our business operations and maintain our customer relationships.

We recognise that, in addition to Personal Information, our customers frequently entrust us with commercially sensitive information relating to their organisations, technology environments and projects. Appropriate administrative, technical and organisational safeguards are implemented to protect both Personal Information and confidential business information against unauthorised access, disclosure, alteration, loss or misuse.

Our privacy and information governance practices are reviewed periodically to ensure they remain aligned with applicable legislation, evolving cybersecurity risks and recognised industry best practices.

1.3 Application of this Privacy Policy

This Privacy Policy applies to all Personal Information processed by Prosirius through its website, products, services and business operations, regardless of whether such information is collected electronically, in writing, verbally or through any other lawful means.

By engaging with Prosirius, requesting information, submitting an enquiry, purchasing products or services, applying for employment or otherwise providing Personal Information to us, you acknowledge that you have read and understood this Privacy Policy.

Where consent is required by applicable legislation, Prosirius will obtain such consent before processing Personal Information.

  1. About Prosirius

2.1 Company Overview

Prosirius (Pty) Ltd is a South African workplace technology and systems integration company specialising in the design, supply, implementation, integration and support of technology solutions that enable modern, secure and connected workspaces.

Our expertise spans workplace collaboration, audiovisual systems, unified communications, digital signage, professional audio, control systems, networking and managed support services. We work with organisations across both the public and private sectors to design and deliver technology solutions that are reliable, scalable and aligned with our customers’ operational requirements.

In delivering these services, Prosirius may process Personal Information as part of customer engagements, supplier relationships, recruitment activities and the day-to-day operation of our business. We also routinely handle commercially sensitive project information, technical documentation and confidential business information, all of which are protected through appropriate governance, confidentiality and information security practices.

Protecting information is an integral part of our service delivery and corporate governance framework. We continually review our policies, procedures and security controls to ensure they remain aligned with applicable legislation, evolving technology and recognised industry best practices.

  1. Scope

3.1 Application

This Privacy Policy applies to all Personal Information processed by Prosirius in the course of conducting its business, whether such information is collected directly from Data Subjects or obtained through lawful third-party sources.

This Policy applies to the processing of Personal Information relating to, among others:

  • Customers and prospective customers;
  • Suppliers, manufacturers and business partners;
  • Employees, contractors and directors;
  • Employment applicants;
  • Website visitors; and
  • Individuals who otherwise engage with Prosirius in the ordinary course of business.

Personal Information may be processed through a variety of business activities, including customer enquiries, quotations, contracts, procurement, project delivery, technical support, recruitment, supplier management, financial administration and the operation of the Prosirius website.

3.2 Processing Activities

This Privacy Policy applies irrespective of whether Personal Information is processed:

  • Electronically or in hard copy;
  • Through our website, email, telephone or other communication channels;
  • During customer engagements, projects or support services;
  • On systems owned or operated by Prosirius; or
  • By authorised third-party service providers acting on behalf of Prosirius.

Where Prosirius engages third-party service providers to process Personal Information, reasonable steps are taken to ensure that such processing is carried out in accordance with applicable legislation, contractual obligations and appropriate information security standards.

3.3 Related Policies

This Privacy Policy should be read together with any applicable contractual agreements, terms and conditions, confidentiality agreements, acceptable use policies, service agreements or other governance documents issued by Prosirius.

Where another agreement contains additional privacy, confidentiality or information security obligations, those obligations shall apply alongside this Privacy Policy.

Nothing contained in this Privacy Policy limits any rights or obligations arising under applicable legislation or any contractual agreement between Prosirius and its customers, suppliers, employees or business partners.

  1. Definitions

For the purposes of this Privacy Policy, the following definitions apply:

Data Subject

An identifiable, living natural person and, where applicable, an identifiable existing juristic person to whom Personal Information relates, as contemplated in the Protection of Personal Information Act, 4 of 2013 (“POPIA”).

Information Officer

The individual appointed by Prosirius in terms of POPIA who is responsible for overseeing the Company’s compliance with applicable privacy and data protection legislation.

Operator

A third party that processes Personal Information on behalf of Prosirius under a contractual arrangement and in accordance with Prosirius’ instructions, as contemplated in POPIA.

PAIA

The Promotion of Access to Information Act, 2 of 2000.

Personal Information

Information relating to an identifiable, living natural person and, where applicable, an identifiable existing juristic person, as defined in POPIA.

Personal Information may include information such as a person’s name, contact details, identification number, employment information, financial information, online identifiers or any other information capable of identifying that individual or juristic person.

POPIA

The Protection of Personal Information Act, 4 of 2013, together with any regulations issued thereunder.

Processing

Any operation or activity involving Personal Information, whether by automated means or otherwise, including the collection, recording, storage, updating, use, disclosure, transmission, restriction, deletion or destruction of Personal Information.

Prosirius

Prosirius (Pty) Ltd, Registration Number 2018/292421/07, together with its directors, employees, authorised representatives and service providers acting on its behalf where applicable

  1. Information Governance

5.1 Governance Framework

Prosirius recognises that the responsible management of Personal Information forms part of its broader corporate governance framework.

Privacy, information security and confidentiality are integrated into our business operations and decision-making processes to ensure that Personal Information is processed lawfully, responsibly and in accordance with applicable legislation.

Appropriate policies, procedures and technical controls are maintained to support the secure handling of Personal Information throughout its lifecycle, from collection and use to retention and secure disposal.

5.2 Legislative Compliance

Prosirius processes Personal Information in accordance with the requirements of applicable South African legislation, including but not limited to:

  • Protection of Personal Information Act, 4 of 2013 (“POPIA”);
  • Promotion of Access to Information Act, 2 of 2000 (“PAIA”);
  • Electronic Communications and Transactions Act, 25 of 2002 (“ECTA”);
  • Companies Act, 71 of 2008; and
  • Any other legislation or regulatory requirements applicable to the services provided by Prosirius.

Where this Privacy Policy imposes obligations that exceed the minimum requirements of applicable legislation, Prosirius will endeavour to apply those higher standards wherever reasonably practicable.

5.3 Information Officer

Prosirius has appointed an Information Officer in accordance with the requirements of POPIA.

The Information Officer is responsible for overseeing the Company’s privacy and information governance programme, monitoring compliance with applicable legislation, responding to privacy-related enquiries and requests, and promoting responsible information management throughout the organisation.

Information Officer

Richard Henn
Chief Executive Officer & Information Officer

Email: richard.henn@prosirius.co.za

Telephone: 0861 10 22 42

5.4 Our Privacy Principles

The processing of Personal Information at Prosirius is guided by the following principles:

  • Accountability – We accept responsibility for the lawful processing and protection of Personal Information.
  • Lawfulness and Transparency – Personal Information is processed fairly, lawfully and only for legitimate business purposes.
  • Purpose Limitation – Personal Information is collected only for specified, explicit and legitimate purposes.
  • Data Minimisation – We collect only the Personal Information reasonably necessary to fulfil those purposes.
  • Information Quality – Reasonable steps are taken to ensure that Personal Information remains accurate, complete and current where appropriate.
  • Security – Appropriate administrative, technical and physical safeguards are implemented to protect Personal Information throughout its lifecycle.
  • Respect for Data Subject Rights – We recognise and support the rights afforded to Data Subjects under POPIA.

These principles underpin the way Prosirius manages Personal Information across all areas of its business.

  1. Personal Information We Collect

The Personal Information processed by Prosirius depends on the nature of your relationship with us and the products or services we provide. We collect only the Personal Information reasonably necessary to fulfil legitimate business purposes, comply with legal obligations and deliver our services effectively.

The categories of Personal Information we may process include the following.

Customers and Prospective Customers

Where you enquire about or make use of our products or services, we may process information such as:

  • Name and surname;
  • Company or organisation name;
  • Job title or position;
  • Business contact details;
  • Physical, billing and delivery addresses;
  • Purchase orders and contractual information;
  • Billing and payment information;
  • Customer correspondence; and
  • Records relating to the products and services we provide.

Suppliers, Contractors and Business Partners

In managing our supplier and business relationships, we may process information including:

  • Business and contact information;
  • Banking and payment details;
  • Tax and regulatory information;
  • Contractual documentation;
  • Supplier compliance records; and
  • Commercial correspondence.

Employment Applicants

Where individuals apply for employment opportunities with Prosirius, we may process information including:

  • Curriculum Vitae (CV);
  • Employment history;
  • Qualifications and certifications;
  • References;
  • Recruitment correspondence; and
  • Information reasonably necessary to assess suitability for employment.

Website Visitors

When you visit the Prosirius website, certain technical information may be collected automatically to support website functionality, maintain security and improve user experience. This may include:

  • IP address;
  • Browser and device information;
  • Operating system;
  • Pages visited;
  • Date and time of access;
  • Cookie information; and
  • Diagnostic and usage information.

Further information regarding cookies and website technologies is provided in Section 13 of this Privacy Policy.

Business Communications

Where you communicate with Prosirius, we may retain records of business communications, including emails, meeting notes, service requests, support enquiries and other correspondence necessary to provide our products, services and customer support.

Project and Technical Information

As part of designing, implementing and supporting workplace technology solutions, Prosirius may receive or create project-related information, including technical documentation, system designs, equipment schedules, project records and other implementation documentation.

While much of this information does not constitute Personal Information under POPIA, it may be commercially sensitive or confidential. The protection of such information is addressed in Section 9 – Confidential Customer & Project Information.

Accuracy of Information

Prosirius relies on the accuracy of the information provided to us. Where reasonably practicable, individuals should ensure that the Personal Information they provide remains accurate, complete and up to date and notify us of any material changes.

  1. Collection and Processing of Personal Information

Prosirius collects and processes Personal Information only where it is reasonably necessary to conduct its business, deliver products and services, fulfil contractual obligations, comply with legal requirements or protect its legitimate interests.

Personal Information is obtained through lawful and transparent means and, wherever reasonably practicable, is collected directly from the Data Subject.

Depending on the nature of your engagement with Prosirius, Personal Information may be collected when you:

  • Contact us through our website, email, telephone or other communication channels;
  • Request a quotation, proposal or product information;
  • Purchase products or services;
  • Enter into a contract with Prosirius;
  • Participate in meetings, workshops or project engagements;
  • Submit support or service requests;
  • Apply for employment opportunities; or
  • Otherwise engage with Prosirius in the ordinary course of business.

Where appropriate and permitted by law, Personal Information may also be obtained from authorised representatives, publicly available sources, recruitment agencies, business partners or other third parties.

Lawful Processing

Prosirius processes Personal Information only where there is a lawful basis to do so. Depending on the circumstances, processing may be necessary:

  • To perform or enter into a contract;
  • To comply with a legal or regulatory obligation;
  • To protect the legitimate interests of Prosirius or the Data Subject;
  • To establish, exercise or defend legal rights; or
  • Where the Data Subject has provided consent, where such consent is required by law.

Where consent forms the basis for processing, it may be withdrawn at any time, subject to any legal or contractual obligations that require continued processing.

Purposes of Processing

Prosirius processes Personal Information for purposes including:

  • Responding to enquiries and requests for information;
  • Preparing quotations, proposals and tender submissions;
  • Delivering products and professional services;
  • Managing customer, supplier and business partner relationships;
  • Providing installation, commissioning, maintenance and technical support services;
  • Administering contracts, warranties and service agreements;
  • Managing procurement, finance and business administration;
  • Recruiting and employing personnel;
  • Maintaining the security and integrity of our systems and business operations; and
  • Complying with applicable legislation and regulatory obligations.

Prosirius will not process Personal Information for purposes that are incompatible with the purpose for which it was originally collected unless required or permitted by law or with the consent of the Data Subject where applicable.

Where the provision of Personal Information is mandatory for the performance of a contract or compliance with a legal obligation, failure to provide such information may limit Prosirius’ ability to provide the requested products or services or enter into a contractual relationship.

  1. Special Personal Information

Prosirius does not ordinarily collect or process Special Personal Information, as defined in the Protection of Personal Information Act, 4 of 2013 (“POPIA”), in the normal course of its business.

Where the processing of Special Personal Information is necessary, Prosirius will do so only where such processing is lawful and permitted under POPIA, including where:

  • the Data Subject has provided explicit consent;
  • the processing is required or authorised by law;
  • the processing is necessary to comply with employment or labour legislation;
  • the processing is necessary to establish, exercise or defend a legal right; or
  • the processing is otherwise permitted under applicable legislation.

Where Special Personal Information is processed, Prosirius implements safeguards appropriate to the sensitivity of the information, including restricting access to authorised personnel who require such information to perform their duties.

Prosirius will not process Special Personal Information for purposes that are incompatible with the reason for which it was collected and will retain such information only for as long as necessary to fulfil the relevant legal, contractual or operational requirements.

  1. Confidential Customer & Project Information

Protecting confidential customer information is fundamental to the way Prosirius delivers its services.

In the course of designing, implementing and supporting workplace technology solutions, Prosirius is routinely entrusted with confidential and commercially sensitive information relating to our customers’ organisations, facilities, technology environments and business operations.

While much of this information does not constitute Personal Information as defined by POPIA, Prosirius recognises that its unauthorised disclosure could expose customers to commercial, operational or security risks. Accordingly, we apply appropriate administrative, technical and organisational safeguards to protect all confidential information entrusted to us.

Confidential information may include, but is not limited to:

  • Architectural drawings and floor plans;
  • Workplace and meeting room designs;
  • Audiovisual system designs and schematics;
  • Network architecture and infrastructure documentation;
  • Equipment schedules and asset registers;
  • Bills of Materials (BOMs);
  • Rack layouts and cabinet elevations;
  • System configurations and programming files;
  • Commissioning documentation;
  • Project plans and implementation documentation;
  • Commercial proposals and pricing information;
  • Procurement and tender documentation;
  • Intellectual property belonging to our customers or business partners; and
  • Any other information identified as confidential by a customer or generated during the delivery of our services.

Prosirius uses confidential customer information solely for the purposes of delivering contracted products and services, fulfilling contractual and legal obligations, and providing ongoing support and maintenance where applicable.

Access to confidential information is limited to authorised personnel and approved service providers who require such access to perform their responsibilities. Where confidential information is shared with manufacturers, suppliers, subcontractors or other service providers, Prosirius takes reasonable steps to ensure that appropriate contractual and confidentiality obligations are in place.

Confidential customer information is not disclosed to third parties except where:

  • disclosure is authorised by the customer;
  • disclosure is necessary to fulfil a contractual obligation;
  • disclosure is required by law or a competent regulatory authority; or
  • disclosure is necessary to establish, exercise or defend a legal right.

Prosirius recognises that maintaining the confidentiality of customer information is essential to preserving the trust placed in us and forms an integral part of our broader information governance and security framework.

  1. Disclosure of Personal Information

Prosirius treats Personal Information as confidential and does not sell, rent or otherwise disclose Personal Information to third parties for marketing or commercial gain.

Personal Information will be disclosed only where such disclosure is necessary to provide our products or services, fulfil contractual obligations, comply with legal or regulatory requirements, protect legitimate business interests or where the Data Subject has otherwise authorised such disclosure.

Depending on the nature of our business relationship, Personal Information may be shared with:

  • Manufacturers, distributors and technology partners involved in the delivery or support of our products and services;
  • Logistics and courier providers responsible for the delivery of equipment;
  • Professional advisers, including legal advisers, auditors, accountants and insurers;
  • Financial institutions responsible for processing payments;
  • Cloud service providers and technology platforms that support our business operations;
  • Contractors and subcontractors engaged to deliver services on behalf of Prosirius; and
  • Government authorities, regulators or law enforcement agencies where disclosure is required by law.

Where Prosirius appoints third-party service providers to process Personal Information on its behalf, reasonable steps are taken to ensure that such parties:

  • process Personal Information only for authorised purposes;
  • implement appropriate security measures;
  • maintain appropriate confidentiality obligations; and
  • comply with applicable privacy and data protection legislation.

Some of the technology platforms and cloud services used by Prosirius may process or store information outside the Republic of South Africa. Where cross-border transfers occur, Prosirius takes reasonable steps to ensure that appropriate contractual, organisational and technical safeguards are in place and that such transfers comply with the requirements of POPIA.

Prosirius remains responsible for ensuring that any disclosure of Personal Information is limited to what is reasonably necessary and is carried out in a secure and responsible manner.

  1. Information Security and Data Retention

Protecting the confidentiality, integrity and availability of Personal Information is a key component of Prosirius’ information governance framework.

Prosirius maintains appropriate administrative, technical and physical safeguards designed to protect Personal Information against unauthorised access, disclosure, alteration, loss, misuse or destruction. These safeguards are reviewed periodically and are adapted where necessary to address changes in technology, business operations and cybersecurity risks.

Depending on the nature of the information processed, security measures may include:

  • Role-based access controls and user authentication;
  • Secure cloud services and business platforms;
  • Multi-factor authentication where appropriate;
  • Encryption of data during transmission and, where appropriate, at rest;
  • Endpoint protection and malware prevention technologies;
  • Firewall and network security controls;
  • Secure backup and disaster recovery processes;
  • Physical security measures to protect business premises and equipment; and
  • Ongoing employee awareness of information security and confidentiality responsibilities.

While Prosirius implements reasonable measures to protect Personal Information, no method of electronic transmission or storage can be guaranteed to be completely secure. Accordingly, while every reasonable effort is made to safeguard information, Prosirius cannot guarantee absolute security.

Personal Information is retained only for as long as reasonably necessary to fulfil the purpose for which it was collected, comply with legal or regulatory obligations, enforce contractual rights or meet legitimate business and operational requirements.

Once Personal Information is no longer required, and where there is no legal or contractual obligation to retain it, Prosirius will take reasonable steps to securely delete, destroy or anonymise the information using methods appropriate to the nature and sensitivity of the information.

  1. Your Rights Under POPIA

Prosirius respects the rights afforded to Data Subjects under the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and is committed to responding to privacy-related requests in a fair, transparent and timely manner.

Subject to applicable legislation and any lawful limitations, you have the right to:

  • Request confirmation of whether Prosirius processes your Personal Information;
  • Request access to the Personal Information we hold about you;
  • Request the correction or updating of inaccurate, incomplete or outdated Personal Information;
  • Request the deletion or destruction of Personal Information where permitted by law;
  • Object to the processing of your Personal Information in circumstances permitted by POPIA;
  • Withdraw your consent where processing is based on consent, subject to any legal or contractual obligations that require continued processing; and
  • Lodge a complaint regarding the processing of your Personal Information.

Requests relating to Personal Information should be submitted to the Information Officer using the contact details provided in this Privacy Policy.

To protect the privacy and security of individuals, reasonable steps may be taken to verify the identity of the person submitting a request before any Personal Information is disclosed, amended or deleted.

While Prosirius will make every reasonable effort to accommodate requests relating to Personal Information, certain information may be retained where required by law or where retention is necessary to establish, exercise or defend legal rights, fulfil contractual obligations or comply with regulatory requirements.

Prosirius will respond to requests within a reasonable period and in accordance with the requirements of POPIA and, where applicable, the Promotion of Access to Information Act, 2 of 2000 (“PAIA”).

  1. Website Privacy

The Prosirius website is intended to provide information about our business, products and services and to enable visitors to contact us or submit enquiries.

When you visit our website, certain technical information may be collected automatically to support website functionality, maintain security and improve the overall user experience. This information may include your IP address, browser type, device information, pages visited, date and time of access and other technical information generated during your interaction with the website.

Where you voluntarily submit Personal Information through a contact form, quotation request or other online enquiry, that information will be processed only for the purpose for which it was provided and in accordance with this Privacy Policy.

Cookies

The Prosirius website may use cookies and similar technologies to support website functionality, improve performance and better understand how visitors interact with the website.

Cookies are small text files stored on your device that enable certain website features and help us improve the overall user experience.

Most internet browsers allow cookies to be managed, restricted or disabled through browser settings. Please note that disabling certain cookies may affect the functionality of certain areas of the website.

Third-Party Websites

The Prosirius website may contain links to third-party websites for your convenience or reference.

Prosirius does not control or accept responsibility for the content, privacy practices or security of third-party websites. Visitors are encouraged to review the privacy policies of those websites before providing any Personal Information.

The inclusion of a link to a third-party website does not imply endorsement of that website, its products or its services.

Electronic Communications

Where you contact Prosirius electronically, including through our website or by email, we may retain records of those communications where reasonably necessary to respond to your enquiry, provide our services, maintain business records or comply with legal obligations.

Prosirius does not distribute unsolicited bulk marketing communications. Any electronic communications sent by Prosirius will generally relate to customer enquiries, quotations, projects, contractual matters, support services or other legitimate business communications.

  1. Changes to this Privacy Policy

Prosirius may update this Privacy Policy from time to time to reflect changes in applicable legislation, regulatory requirements, business operations, technology or information governance practices.

The most current version of this Privacy Policy will always be published on the Prosirius website and will indicate the effective date of the latest revision.

Where changes materially affect the manner in which Personal Information is processed, Prosirius will take reasonable steps, where appropriate, to notify affected individuals.

We encourage visitors to review this Privacy Policy periodically to remain informed about how Personal Information is collected, used and protected.

  1. Contact Information, Privacy Requests & Complaints

Prosirius is committed to maintaining transparent and responsible information management practices. If you have any questions regarding this Privacy Policy, wish to exercise your privacy rights, or have concerns regarding the processing of your Personal Information, we encourage you to contact our Information Officer.

Information Officer

Richard Henn
Chief Executive Officer & Information Officer

Email: richard.henn@prosirius.co.za

Telephone: 0861 10 22 42

General Enquiries: info@prosirius.co.za

Website: www.prosirius.co.za

Physical Address:
Block G, Central Park
400 16th Road
Randjespark
Midrand
1685
South Africa

Privacy Requests

Requests relating to Personal Information, including requests for access, correction, deletion, objection to processing or the withdrawal of consent, should be submitted in writing to the Information Officer.

To protect the privacy and security of individuals, Prosirius may request reasonable proof of identity before processing any privacy-related request.

Every reasonable effort will be made to respond to requests within the timeframes prescribed by applicable legislation.

Complaints

If you believe that Prosirius has not processed your Personal Information in accordance with applicable legislation or this Privacy Policy, we encourage you to contact the Information Officer in the first instance so that we may investigate the matter and, where appropriate, resolve it promptly and fairly.

If you remain dissatisfied after engaging with Prosirius, you have the right to lodge a complaint with the Information Regulator (South Africa).

Information Regulator (Republic of South Africa)

Physical Address
JD House
27 Stiemens Street
Braamfontein
Johannesburg
2001

Postal Address
P.O. Box 31533
Braamfontein
Johannesburg
2017

Telephone: +27 (0)10 023 5200

Email: enquiries@inforegulator.org.za

Website: www.inforegulator.org.za

Let’s build something that works

Let’s build something that works