PRIVACY POLICY+

PRIVACY POLICY

Effective date: 7 September 2026

Last updated: 7 September 2026

 

Your information deserves the same protection as everything else.

 

Tanosec Cybersecurity (“Tanosec”, “we”, “us” or “our”) respects your privacy and takes the protection of personal information seriously.

This Privacy Policy explains how we collect, use, store, share and protect personal information when you visit our website, contact us, enquire about our services, become a client, use our services, or otherwise interact with Tanosec.

 

We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the Promotion of Access to Information Act 2 of 2000 (“PAIA”), where applicable, and other applicable South African law.

This policy should be read together with any additional privacy notices, contractual terms, Rules of Engagement or engagement-specific documentation that may apply to a particular service.

1. WHO WE ARE +

Tanosec Cybersecurity is a South African cybersecurity business providing security assessment, testing, advisory, awareness and managed cybersecurity services.

For purposes of POPIA, Tanosec may act as a Responsible Party where we determine the purpose and means of processing personal information.

Where we process personal information on behalf of a client as part of an authorised engagement, Tanosec may instead act as an Operator and will process that information subject to applicable law and our contractual obligations to the client.

Responsible Party: Tanosec Cybersecurity
Location: Bloemfontein, Free State, South Africa
Website: tanosec.co.za

Privacy enquiries: privacy@tanosec.co.za
Information Officer contact: privacy@tanosec.co.za

Under POPIA, the head of a private body is ordinarily the Information Officer by virtue of that position. The Information Regulator requires Information Officers to be registered before assuming their statutory duties.

2. WHO THIS POLICY APPLIES TO +

This Privacy Policy may apply to personal information relating to:
– visitors to our website;
– prospective, current and former clients;
– client representatives and employees;
– people who contact or correspond with us;
– suppliers, contractors and service providers;
– business partners and professional advisers; and
– other persons whose information we lawfully process while providing our services.

3. PERSONAL INFORMATION WE MAY COLLECT +

The information we collect depends on how you interact with Tanosec and the services involved.

Identity and contact information
This may include your:
– name;
– business or organisation name;
– job title;
– email address;
– telephone number; and
– other contact details you provide to us.

Enquiry and communication information
When you contact us, we may process information contained in:
– website forms;
– emails;
– telephone conversations;
– meeting notes;
– support requests;
– quotations and proposals; and
– other correspondence.

Client and engagement information
Where necessary to establish or deliver a client engagement, we may process:
– client contact details;
– authorised user information;
– scope and authorisation records;
– engagement documentation;
– reports and findings;
– support records; and
– other information reasonably necessary to provide the requested service.

Technical and cybersecurity information
The nature of cybersecurity work means that, during an authorised engagement, we may process technical information including:
– IP addresses;
– domain names;
– hostnames;
– network information;
– system configurations;
– security logs;
– usernames or account identifiers;
– vulnerability information;
– security events;
– exposed or publicly accessible information; and
– other technical information relevant to the authorised scope.
Technical information may constitute personal information where it identifies or can reasonably be associated with an identifiable person.

Website and device information
When you use our website, our systems and service providers may process technical information such as:
– IP address;
– browser and device information;
– pages visited;
– referring pages;
– date and time information;
– website interaction information; and
– security-related request information.

Billing and administrative information
Where applicable, we may process information required for:
– quotations;
– invoicing;
– payment administration;
– accounting;
– tax and financial records; and
– general client administration.
We aim to collect only information that is adequate, relevant and reasonably necessary for the purpose for which it is processed.

4. HOW WE COLLECT PERSONAL INFORMATION +

We may obtain personal information:
– directly from you;
– from your organisation;
– from an authorised representative;
– when you submit a form through our website;
– through email, telephone, meetings or other communications;
– while providing an authorised cybersecurity service;
– from service providers acting on our behalf;
– from clients where information is necessary to perform an authorised engagement;
– from publicly accessible sources where appropriate and lawful; or
– from another lawful source relevant to a particular engagement.

Certain Tanosec services, particularly Digital Footprint Hunt and authorised reconnaissance activities, may involve information obtained from publicly accessible sources.
The fact that information is publicly available does not automatically remove applicable privacy obligations. We process such information only where appropriate to the purpose and lawful scope of the engagement.

5. WHY WE PROCESS PERSONAL INFORMATION +

We may process personal information where reasonably necessary to:
– respond to enquiries;
– communicate with you;
– understand your requirements;
– prepare quotations and proposals;
– establish and manage client relationships;
– enter into and perform contracts;
– verify authority for cybersecurity testing or assessment;
– scope and deliver authorised cybersecurity services;
– conduct security assessments and testing;
– prepare findings and reports;
– provide cybersecurity consulting;
– provide managed cybersecurity services;
– provide support;
– maintain engagement and authorisation records;
– operate and maintain our website;
– protect our website, infrastructure and users;
– detect, investigate and prevent security incidents, fraud or abuse;
– administer invoices and payments;
– maintain financial and business records;
– comply with legal, regulatory and contractual obligations;
– establish, exercise or defend legal rights;
– understand and improve our website and services; and
– send business communications where permitted by law.

We do not intentionally use personal information for purposes that are incompatible with the purpose for which it was collected unless further processing is permitted by law.

6. LAWFUL PROCESSING +

Depending on the circumstances, we may process personal information where:
– you have consented to the processing;
– processing is necessary to perform a contract to which you are a party;
– processing is necessary to take steps requested by you before entering into a contract;
– processing complies with an obligation imposed by law;
– processing protects a legitimate interest of the data subject;
– processing is necessary for the proper performance of a public-law duty, where applicable; or
– processing is necessary to pursue the legitimate interests of Tanosec or a third party, subject to applicable protections.

Where we rely on consent, you may withdraw that consent, subject to applicable law and any other lawful basis that permits or requires continued processing.

7. PROVIDING INFORMATION TO US +

Unless we tell you otherwise, or the information is required by law or contract, providing personal information to Tanosec is generally voluntary.
However, certain information may be necessary for us to:
– respond meaningfully to an enquiry;
– verify your identity or authority;
– prepare a quotation;
– establish a client relationship;
– comply with legal obligations;
– safely perform cybersecurity work; or
– provide a requested service.
If necessary information is not provided, we may be unable to proceed with the relevant request or service.

8. CYBERSECURITY ENGAGEMENTS +

Cybersecurity services can involve information that would not ordinarily be processed during a typical commercial relationship.
Depending on the agreed and authorised scope of an engagement, Tanosec may encounter or process:
– employee or user identifiers;
– email addresses;
– usernames;
– IP addresses;
– logs;
– publicly accessible information;
– exposed credentials or indications of credential exposure;
– security events;
– vulnerability information; and
– other information relevant to identifying or demonstrating a security risk.

We treat engagement information as confidential and limit our processing to what is reasonably necessary for the authorised purpose.
Cybersecurity testing and assessment activities are performed subject to an agreed scope, client authorisation and, where applicable, contractual terms or Rules of Engagement.
An engagement does not provide Tanosec with unrestricted authority to access systems, information or infrastructure outside the authorised scope.

Where Tanosec processes personal information on behalf of a client, the client remains responsible for ensuring that it has an appropriate lawful basis and authority for the processing it instructs us to perform.

9. SPECIAL PERSONAL INFORMATION AND CHILDREN’S INFORMATION +

Tanosec does not intentionally request special personal information or personal information relating to children through its general website.
Such information may occasionally be encountered during an authorised cybersecurity engagement or supplied to us for a legitimate and lawful purpose.
Where this occurs, we will process the information only where permitted by applicable law and will apply appropriate safeguards.

10. WEBSITE FORMS +

Our website uses Contact Form 7 and Ninja Forms to provide contact, enquiry and other website forms.
When you submit a form, we may collect the information you enter into that form together with limited technical information necessary to process, secure and deliver the submission.
The information will be used for the purpose indicated by the form, such as responding to an enquiry or request.
Please do not submit passwords, authentication credentials, highly sensitive personal information or confidential client data through a general website contact form unless we specifically ask you to use an approved secure method.

11. WEBSITE ANALYTICS AND MEASUREMENT +

Tanosec uses website analytics and measurement tools to understand how our website performs and how visitors use it.
We currently use Independent Analytics Pro as part of our website analytics environment. We also use Google Site Kit, through which Google Analytics and PageSpeed Insights are connected to our website.
Depending on their configuration and your interaction with the website, these services may process technical and usage information. Where consent is required before a non-essential cookie or similar technology may be used, we aim to respect the visitor’s applicable cookie choices. We do not intentionally use website analytics to identify individual visitors where that identification is unnecessary. Further information about the technologies and cookies used on this website will be provided in our Cookie Policy.

12. WEBSITE SECURITY +

As a cybersecurity company, we recognise that privacy promises mean little without appropriate security behind them.
Our website uses Wordfence Security as part of its security controls.
Security technologies may process information such as:
– IP addresses;
– request information;
– login attempts;
– timestamps;
– browser or technical information; and
– activity associated with suspected malicious behaviour.

This information may be used to detect, block, investigate and respond to malicious activity, attempted unauthorised access, abuse and other threats to our website and infrastructure.

13. OTHER WEBSITE TECHNOLOGIES +

Our website also uses technologies including:
Elementor
Used to build and deliver website pages and functionality.
Rank Math SEO
Used to manage search-engine optimisation and related website functionality.
OMGF
Used to host fonts locally, helping reduce unnecessary requests to external font services when visitors load our website.
The presence of a WordPress plugin does not necessarily mean that the plugin independently receives personal information. The information processed depends on the functionality being used and its configuration.

14. BACKUPS +

We maintain backups as part of our business continuity, security and recovery arrangements.
Our website uses UpdraftPlus for backup and restoration, and off-site website backups are stored using Google Drive.
Because backups may contain copies of website databases and files, information submitted to or stored by our website may also exist within encrypted or access-controlled backup environments for a period of time.
Information contained in backups may not always be immediately removed when information is deleted from an active system. Such information will ordinarily disappear as backups are rotated or deleted according to our applicable retention practices.
We restrict access to backup systems and use them for legitimate security, continuity and recovery purposes.

15. SERVICE PROVIDERS AND DISCLOSURE +

Tanosec does not sell, rent or trade personal information.

We use selected service providers and technology platforms to operate, secure and support our website and business.
Depending on the service involved, these providers may process limited personal information on our behalf or provide infrastructure through which information is processed.
These may include providers of:
– website hosting;
– cloud infrastructure;
– email and communications;
– website analytics;
– security;
– backup and recovery;
– business administration;
– accounting;
– professional services; and
– other infrastructure reasonably necessary to operate Tanosec.

We may also disclose information to:
– professional advisers;
– authorised contractors or specialist partners involved in an engagement;
– regulators;
– courts;
– law-enforcement authorities; or
– another party where disclosure is required or permitted by law or authorised by you.

Where an Operator processes personal information on our behalf, we take reasonable steps appropriate to the circumstances to ensure confidentiality, security and lawful processing requirements are addressed.

16. INTERNATIONAL PROCESSING AND TRANSFERS +

Some of the technology and cloud services used by Tanosec are operated by international providers, including Google services used for analytics, website performance measurement and off-site backups. As a result, personal information may in some circumstances be processed, transferred or stored outside South Africa. Where personal information is transferred outside South Africa, we will handle the transfer in accordance with section 72 of POPIA and other applicable requirements. This may include ensuring that the recipient is subject to an appropriate law, binding corporate rules or binding agreement providing an adequate level of protection, obtaining consent where appropriate, or relying on another basis permitted by POPIA. Section 72 specifically regulates transfers of personal information from South Africa to recipients in foreign countries.

17. HOW WE PROTECT PERSONAL INFORMATION +

Tanosec uses appropriate and reasonable technical and organisational measures designed to protect personal information against:
– loss;
– damage;
– unauthorised destruction;
– unlawful access;
– unauthorised processing;
– alteration; and
– disclosure.

Depending on the information, system and risks involved, our safeguards may include:
– access controls;
– authentication;
– encryption where appropriate;
– secure communications;
– system hardening;
– security monitoring;
– backups;
– logging;
– vulnerability management;
– endpoint and infrastructure security; and
– restrictions on access to client and personal information.

Access to information is limited according to legitimate operational requirements.
No internet-connected system can be guaranteed to be completely secure. We therefore assess risks and adapt safeguards where appropriate rather than representing any system as immune to compromise.

18. SECURITY COMPROMISES +

If we have reasonable grounds to believe that personal information under our control has been accessed or acquired by an unauthorised person, we will investigate and respond in accordance with applicable law.
Where required by POPIA, we will notify the Information Regulator and affected data subjects in the manner required by law.
Where Tanosec is acting as an Operator for a client, we will notify and cooperate with the relevant Responsible Party in accordance with applicable legal and contractual obligations.
The Information Regulator provides a dedicated mechanism for reporting personal-information security compromises.

19. HOW LONG WE RETAIN INFORMATION +

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, or where longer retention is required or permitted by:
– law;
– contractual obligations;
– accounting or tax requirements;
– legitimate business requirements;
– security requirements; or
– the establishment, exercise or defence of legal claims.

Different categories of information may therefore have different retention periods.
When personal information is no longer reasonably required and we are not legally entitled or required to retain it, we will delete, destroy or de-identify it in an appropriate manner.
Information contained in backups may remain until the relevant backup is securely rotated or deleted.

20. COOKIES AND SIMILAR TECHNOLOGIES +

Our website may use cookies and similar technologies for purposes including:
– essential website functionality;
– security;
– preferences;
– analytics; and
– website performance measurement.

Some technologies are necessary for the website to operate securely and correctly. Others may be non-essential.
Where consent or another choice is required for a particular technology, we will provide an appropriate mechanism for visitors to make that choice.
You can also control certain cookies through your browser settings.
Our separate Cookie Policy provides more information about the cookies and similar technologies used by Tanosec.

21. DIRECT MARKETING +

Tanosec may send marketing or business communications only where permitted by applicable law.
Where consent is required for unsolicited electronic direct marketing, we will seek that consent in accordance with POPIA.
You may object to direct marketing or unsubscribe from marketing communications using the method provided in the relevant communication or by contacting us at:
privacy@tanosec.co.za

Opting out of marketing communications will not prevent us from sending communications necessary to:
– provide a requested service;
– administer an existing client relationship;
– respond to an enquiry;
– address a security matter; or
– meet legal or contractual obligations.

22. YOUR PRIVACY RIGHTS +

Subject to POPIA and other applicable law, you may have the right to:
– ask whether Tanosec holds personal information about you;
– request access to your personal information;
– request correction of inaccurate or incomplete personal information;
– request deletion or destruction of personal information where legally permitted;
– object to certain processing on reasonable grounds;
– object to direct marketing;
– withdraw consent where processing relies on consent;
– request information concerning third parties or categories of third parties that have had access to your personal information where applicable; and
– lodge a complaint with the Information Regulator.

Certain rights are subject to lawful limitations.
For example, we may be unable to delete information that we are required to retain by law or that is reasonably necessary for the establishment, exercise or defence of a legal claim.

23. EXRECISING YOUR RIGHTS +

Privacy-related requests may be sent to:
Information Officer
Tanosec Cybersecurity
Email: privacy@tanosec.co.za

Please provide sufficient information for us to understand your request and identify the relevant information.
We may request reasonable proof of identity before disclosing, correcting or deleting personal information to protect against unauthorised requests.
Requests will be handled in accordance with POPIA, PAIA where applicable, and any prescribed procedures.

24. ACCESS TO INFORMATION AND PAIA +

Requests for access to certain records held by Tanosec may be governed by the Promotion of Access to Information Act 2 of 2000 (PAIA).
Where PAIA applies, requests must be submitted in accordance with the applicable prescribed procedure.
The Information Regulator currently provides PAIA guidance, a private-body PAIA Manual template and the prescribed access-request forms. Info Regulator
Information about Tanosec’s PAIA processes and applicable manual will be made available where required.

25. COMPLAINTS +

If you believe that Tanosec has processed your personal information improperly, we encourage you to contact us so that we can investigate the matter.
Privacy enquiries:
privacy@tanosec.co.za

You also have the right to lodge a complaint with the Information Regulator (South Africa).
At the date of this policy, the Regulator lists the following general contact information:
Information Regulator (South Africa)
Woodmead North Office Park
54 Maxwell Drive
Woodmead, Johannesburg
South Africa
Telephone: 010 023 5200
Email: enquiries@inforegulator.org.za
Information Regulator South Africa

The Regulator also provides online POPIA complaint services through its eServices platform.

26. THIRD-PARTY WEBSITES +

Our website may contain links to websites or services operated by other organisations.
Tanosec does not control those third-party websites and is not responsible for their privacy practices, security or content.
We recommend reviewing the privacy information of a third-party service before providing personal information to it.

27. CHANGES TO THIS PRIVACY POLICY +

Technology, our services, the systems we use and privacy requirements change over time.
We may update this Privacy Policy where our processing activities, technology, service providers, legal obligations or business practices change.
The latest version will be published on this page and identified by the Last updated date above.
Where a change materially affects how we process personal information, we may provide additional notice where appropriate.

28. CONTACT US +

If you have questions about this Privacy Policy, want to exercise a privacy right, or have concerns about how Tanosec handles personal information, please contact:

Tanosec Cybersecurity
Bloemfontein, Free State
South Africa
Information Officer

Privacy: privacy@tanosec.co.za
Website: tanosec.co.za