Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how PRIME ICT collects, uses, stores, and protects your personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and the Promotion of Access to Information Act, 2000 (PAIA).
1. Responsible Party
Prime ICT (Pty) Ltd is the responsible party for the personal information we process. Our Information Officer, David D, may be contacted at info@prime-ict.co.za. Full contact details are set out in our PAIA/POPIA Manual. General privacy enquiries may be sent to info@prime-ict.co.za.
2. Personal Information We Collect
- Contact details: name, email, phone, and business address.
- Identity and business details for account and contract setup, including company registration numbers.
- Service and technical data: IP addresses, circuit IDs, service usage, and network performance metrics.
- Billing and payment data processed via PayFast (we do not store full card or banking details).
- Support and ticket history, including communications and attachments.
- Coverage-check and quote-request lead data captured for sales follow-up.
- Website and portal usage data such as cookies and session logs (see our Cookie Policy).
3. Why We Collect It (Purposes)
- To provision, support, and bill for connectivity, VoIP, managed IT, cloud, hosting, and security services.
- To monitor and manage network and device health and respond to faults.
- To process online store orders and deliveries.
- To communicate with you about your account, incidents, and changes to services.
- To comply with legal, regulatory, and ICASA-related obligations.
- To provide direct marketing where you have opted in, and to send service-critical notices.
4. Lawful Basis under POPIA
We process personal information because it is necessary to conclude and perform a contract with you, to comply with a legal obligation, to protect our legitimate interests, or with your consent. Marketing is sent only with consent or where permitted by POPIA and the Electronic Communications and Transactions Act (ECTA).
5. Retention Periods
We retain personal information only as long as necessary for the purposes collected or as required by law. Customer account and billing records are generally retained for the duration of the relationship plus the period required by the South African Revenue Service and other applicable law. Support and monitoring data is retained according to operational and contractual requirements.
6. Sharing With Third Parties
- Fibre and wireless network operators (FNOs) and carriers required to deliver your service.
- Payment processor PayFast for checkout transactions.
- Hardware and software suppliers for fulfilment and licensing.
- Cloud and hosting providers where we host your services.
- Regulators and law enforcement where legally required.
- We do not sell your personal information.
7. Cross-Border Transfers
Some processing or storage may occur with providers located outside South Africa (for example, cloud platforms). Where this happens, we rely on the POPIA exceptions for trans-border information flows and take reasonable steps to ensure equivalent protection through contracts and provider safeguards.
8. Security Safeguards
We apply technical and organisational measures including encryption in transit, access controls, multi-factor authentication for administrative access, secure payment processing, and monitoring. Details are in our Data Processing & Security Policy. No system can be guaranteed 100% secure.
9. Your Rights
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of information where retention is no longer justified.
- Object to or restrict certain processing, including direct marketing.
- Withdraw consent for processing based on consent.
- Lodge a complaint with the Information Regulator.
10. Direct Marketing & Opt-Out
We may send direct marketing by electronic means where you have consented or where POPIA and ECTA permit. You can opt out at any time using the unsubscribe link or by emailing info@prime-ict.co.za. We will process opt-out requests promptly.
11. Security Incident Handling
If we become aware of a compromise of personal information as defined by POPIA, we will assess the situation, take reasonable steps to contain it, and notify affected parties and the Information Regulator where required, in line with POPIA section 22.
12. Children's Data
Our services are intended for businesses and adults. We do not knowingly collect personal information from children without verifiable parental consent. Contact us if you believe a child has provided information to us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on our website. Continued use of our services after changes constitutes acceptance.