Back to Home

Data Processing & Security Policy

Last updated: 27 July 2026

This policy describes the technical and organisational security measures PRIME ICT applies to protect customer data and the systems that process it. It supports our obligations under POPIA and our role as a managed IT and security provider.

1. Security Commitment

We treat the security of customer data and systems as a core responsibility. This policy outlines our safeguards; however, no system can be guaranteed 100% secure, and customers retain responsibility for their own data and backups unless a managed backup service is contracted.

2. Encryption

  • Data in transit is encrypted using TLS/HTTPS for website, portal, and API traffic.
  • Sensitive data at rest is encrypted where supported by the relevant platform.
  • We do not store full card or banking details; payments are handled by PayFast.

3. Password Security & MFA

We encourage strong, unique passwords and support multi-factor authentication for administrative and customer portal access where available. Customers should enable MFA to protect their accounts.

4. Secure Payment Processing

Online payments are processed by PayFast, a PCI-DSS compliant payment provider. Card details are entered directly with the provider and never pass through or are stored on our systems.

5. Access Control

Access to customer data and systems is role-based and granted on a least-privilege basis. Administrative access is logged and reviewed. Remote access for support is authorised by the customer and performed through controlled channels.

6. Data Backups & Disaster Recovery

  • Where we provide managed backup services, backups are taken per the agreed schedule and retention.
  • Customers remain responsible for their own data backups unless a managed backup service is contracted.
  • We maintain disaster-recovery procedures for our own internal systems and platforms.

7. Incident Response

We maintain an incident-response process for security events affecting our systems or customer services. Where a personal-information compromise occurs as defined by POPIA, we follow our notification obligations, including informing affected parties and the Information Regulator where required.

8. Security Monitoring

Our NOC monitors managed devices and services for availability and anomalies. We may use remote monitoring and management (RMM) tooling to detect faults and threats on managed systems with customer authorisation.

9. Customer Security Responsibilities

  • Keep credentials secure and enable MFA.
  • Apply vendor security updates to devices under your control.
  • Use approved configurations and do not bypass security controls.
  • Promptly report suspected security incidents.

10. No 100% Security Guarantee

Despite our safeguards, no environment can be made fully secure. We provide best-efforts protection and respond promptly to incidents, but cannot guarantee against all threats. Customers should maintain their own resilience, including backups and incident plans.

11. Reporting Vulnerabilities

To report a suspected vulnerability or security issue, contact support@prime-ict.co.za. We appreciate responsible disclosure and will investigate credible reports promptly.

Questions about this policy? Contact us.

Cookies & Privacy POPIA

We use essential cookies to run our site and optional cookies to improve it. You can accept all, reject non-essential, or manage your preferences. See our Cookie Policy and Privacy Policy.