1. Introduction
RE-TEC Solutions (Pty) Ltd (“RE-TEC”, “we”, “our” or “us”) is the controller of the personal information processed through our marketing website (re-tecsolutions.com) and the operator of the RE-TEC platform (the “Services”).
This Privacy Policy explains what personal information we collect, how and why we use it, who we share it with, the safeguards we apply, and the rights you have over your data under the Protection of Personal Information Act 4 of 2013 (POPIA), the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Where RE-TEC processes personal information on behalf of a customer (an enterprise client of the RE-TEC platform), RE-TEC acts as an operator (POPIA) / processor (GDPR) and the customer is the responsible party / controller. The processing of that data is governed by the Data Processing Addendum (DPA) executed with that customer, not by this Privacy Policy.
2. Who we are
RE-TEC Solutions (Pty) Ltd
28 Fricker Road, Illovo
Sandton, Johannesburg, South Africa
Our nominated Information Officer (POPIA) and Data Protection contact (GDPR) can be reached at aileen@re-tecsolutions.com.
3. What information we collect
We collect personal information in the following categories:
- Contact details - name, work email, employer name, role, telephone number, portfolio size, when you complete an enquiry, demo or newsletter form.
- Account credentials - for users of the RE-TEC platform: username, hashed password, multi-factor authentication tokens.
- Usage and device data - IP address, browser type, device identifiers, referring URL, pages visited, timestamps, collected automatically through server logs and cookies.
- Marketing preferences - consent flags, communication preferences, unsubscribe records.
- Customer data (processed as operator/processor) - tenant, leasing, financial, operational and behavioural data submitted to the RE-TEC platform by our customers. This category is governed by the relevant DPA.
We do not knowingly collect special personal information (POPIA) or special categories of personal data (GDPR Article 9). If you believe such data has been submitted to us in error, please contact us so we can delete it.
4. Lawful basis for processing
We rely on the following lawful bases:
- Legitimate interest (GDPR Art. 6(1)(f) / POPIA s11(1)(f)) - for marketing communications to existing business contacts, security monitoring, and product analytics aggregated in line with applicable law.
- Performance of a contract (GDPR Art. 6(1)(b) / POPIA s11(1)(b)) - to provide the Services to customers and authorised users.
- Consent (GDPR Art. 6(1)(a) / POPIA s11(1)(a)) - for non-essential cookies, newsletter sign-ups and direct marketing to new contacts. Consent can be withdrawn at any time.
- Legal obligation (GDPR Art. 6(1)(c) / POPIA s11(1)(c)) - to comply with tax, audit, anti-money-laundering and sanctions screening obligations.
5. How we use your information
- Respond to enquiries, schedule demonstrations, and follow up on proposals.
- Provision, operate, monitor, secure and improve the Services.
- Send service notifications, billing, security alerts and product updates.
- Send marketing communications you have agreed to receive. You can opt out of marketing at any time.
- Detect, prevent and investigate fraud, abuse, security incidents and policy violations.
- Comply with legal, regulatory and tax obligations.
7. International transfers
Our infrastructure is hosted in South Africa and the European Union. Limited support and engineering tooling may transfer data outside these regions. Where personal data leaves the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable). Where personal information leaves South Africa, transfers comply with POPIA s72.
8. Data retention
We retain personal information only as long as needed for the purpose for which it was collected, plus any period required by law:
- Marketing contacts - until you unsubscribe or after 24 months of inactivity, whichever comes first.
- Customer account data - for the term of the customer contract plus 90 days, after which data is deleted or returned per the DPA.
- Server logs - 90 days, unless retained for security investigation.
- Financial records - 5 years (or longer if required by the SARS, HMRC, or comparable tax authority).
9. Your rights
Subject to the conditions of POPIA, GDPR and the UK GDPR, you have the right to:
- Access a copy of the personal information we hold about you.
- Rectify inaccurate or incomplete personal information.
- Delete your personal information (“right to be forgotten”) where the legal basis no longer applies.
- Restrict or object to processing based on legitimate interest, including direct marketing.
- Receive a portable copy of personal information you provided to us.
- Withdraw consent at any time, where consent is the lawful basis. Withdrawal does not affect prior lawful processing.
- Lodge a complaint with the South African Information Regulator (inforegulator.org.za), the UK Information Commissioner’s Office (ico.org.uk) or your local EU supervisory authority.
To exercise any of these rights email aileen@re-tecsolutions.com. We will respond within 30 days (one calendar month for GDPR) and may verify your identity before acting on a request.
11. Security
RE-TEC operates a security programme aligned to the SOC 2 Type II Trust Services Criteria (Security, Availability and Confidentiality) and is actively progressing toward independent attestation. Controls include:
- Data encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Role-based access control and least-privilege provisioning.
- Multi-tenant logical isolation between customer environments.
- Continuous logging, monitoring and alerting on production systems.
- Regular vulnerability scanning, third-party penetration testing and patch management.
- Documented incident-response and business-continuity procedures.
- Mandatory security awareness training and background screening for personnel with access to production.
No security programme is perfect. If you suspect a vulnerability or incident, contact aileen@re-tecsolutions.com.
12. Personal information breach notification
Where a breach of personal information is reasonably likely to result in a risk to the rights of data subjects, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and the South African Information Regulator and affected data subjects as soon as reasonably possible (POPIA s22).
13. Children
The Services are intended for business use by adults. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, contact us and we will delete it.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Services or by email to registered users at least 30 days before they take effect. The current version, with the date of last revision, is always available at this URL.
15. Contact us
Questions, requests or complaints relating to this Privacy Policy can be sent to aileen@re-tecsolutions.com or by post to RE-TEC Solutions (Pty) Ltd, 28 Fricker Road, Illovo, Sandton, Johannesburg, South Africa.