This statement explains how SeptiBytes Solutions ("SeptiBytes", "we", "us") complies with the Protection of Personal Information Act, 4 of 2013 ("POPIA"). It sits alongside our privacy policy, which tells you what we do with your information, and our cookie policy.
01Our two roles
POPIA treats the organisation that decides why and how personal information is processed as the responsible party, and an organisation that processes it on someone else's behalf as an operator. We act in both roles.
| Role | When it applies |
|---|---|
| Responsible party | Enquiries sent to us through this website or by email, the business contact details of people we deal with at client and supplier organisations, recruitment, and our own security and access logs. |
| Operator | Custom systems we build, host or support for clients, and the MedicalBytes and CultiBytes platforms. The client decides what is collected and why, and we process it only on its documented instructions. |
Where we are an operator, the client remains accountable for its own POPIA obligations. Sections 20 and 21 of POPIA require that relationship to be set out in a written agreement, and we put one in place before any live personal information is processed.
02Information Officer
Our Information Officer is responsible for encouraging and monitoring compliance with POPIA inside SeptiBytes, handling requests from data subjects and working with the Information Regulator. You can reach the Information Officer at info@septibytes.com. Please put Information Officer in the subject line so your message is routed correctly.
03The eight conditions for lawful processing
POPIA sets out eight conditions. This is how we apply each of them.
| Condition | How we apply it |
|---|---|
| Accountability | Responsibility for compliance sits with the partners and the Information Officer. We keep records of what we process and why. |
| Processing limitation | We collect only what we need for a stated purpose, on a lawful basis such as consent, a contract or a legitimate interest. |
| Purpose specification | Every purpose is stated in advance, and personal information is not kept longer than that purpose requires unless the law says otherwise. |
| Further processing limitation | Information collected for one purpose is not reused for an unrelated one. Client data is never used for another client or for our own products. |
| Information quality | We take reasonable steps to keep information complete, accurate and up to date, and we correct it when told it is wrong. |
| Openness | We publish this statement and our privacy policy, and we tell people what we collect when we collect it. |
| Security safeguards | We apply appropriate technical and organisational measures, described in section 5 below. |
| Data subject participation | You can ask what we hold about you, and ask for it to be corrected or deleted. See section 9. |
04Special personal information
Health and biometric information are special personal information under section 26 of POPIA. MedicalBytes is designed to process them for clients that are entitled to do so under section 27, for example a medical scheme administering benefits for its members. In that setting we are an operator, and we process special personal information only on the client's instruction and only for that purpose.
This website does not ask for, and we do not want to receive, special personal information. Please do not include health, biometric or similar details in an enquiry.
05Security safeguards and breaches
Security is part of how we build, not a layer added at the end. Our safeguards include:
- Role based access control, least privilege and multi factor authentication on the systems we operate
- Encryption of personal information in transit and at rest where the system supports it
- Segregation of duties and audit trails that record who did what, and when
- Secure development practice, code review and security testing before release
- Backups, disaster recovery design and tested restores
- Confidentiality obligations on everyone who works for us
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as section 22 of POPIA requires where we are the responsible party. Where we are an operator, we notify the client immediately, as section 21 requires, and support its response.
06Operators and suppliers we use
We use a small number of suppliers to run our business and this website, such as email, hosting, cloud infrastructure, website analytics and spam protection providers. We choose suppliers that commit to appropriate security, and where they process personal information for us we require them to keep it confidential and secure and to use it only on our instructions.
07Transfers outside South Africa
Some of our suppliers, including cloud and email providers, Google (Analytics and reCAPTCHA) and Automattic (Akismet), may store or process information outside South Africa. We transfer personal information across borders only where section 72 of POPIA allows it, for example where the recipient is bound by law, binding corporate rules or an agreement that gives an adequate level of protection, or where you have consented.
08Direct marketing
We do not send unsolicited electronic direct marketing. If you are a client, we may tell you about similar services, and every such message includes a simple way to opt out, as section 69 of POPIA requires. We never sell personal information.
09Your rights and how to use them
As a data subject you have the right to:
- Be told that your personal information is being collected, and why
- Ask whether we hold personal information about you, and ask for a record of it
- Ask us to correct, update or delete information that is inaccurate, out of date, excessive or unlawfully obtained
- Object to processing on reasonable grounds, and to direct marketing at any time
- Withdraw consent where processing is based on your consent
- Complain to the Information Regulator
Send your request to info@septibytes.com with Information Officer in the subject line. We may need to confirm your identity before we act. Formal requests for access to records can also be made under the Promotion of Access to Information Act, 2 of 2000. Where we hold the information only as an operator, we will pass your request to the client concerned and tell you that we have done so.
10Complaints
Please raise any concern with us first so we can try to put it right. If you are not satisfied with our response, you may lodge a complaint with the Information Regulator (South Africa) through its website, inforegulator.org.za.


