Compliance Factory
Privacy & POPIA

Your data is our responsibility.

Compliance Factory respects your privacy and is committed to protecting your personal information. This statement explains how we collect, use, share, and safeguard your information in line with the Protection of Personal Information Act (POPIA).

Last updated: 01 June 2026

01

Introduction

Compliance Factory (“we”, “us”, “our”) respects your privacy and is committed to protecting your personal information. This Privacy Statement explains how we collect, use, disclose, and safeguard your information when you interact with our website, platform, and services.

02

Information we collect

We collect and process the following types of personal and business information:

Identity

  • Names
  • ID or passport numbers
  • Date of birth

Contact

  • Email addresses
  • Phone numbers
  • Physical addresses

Business

  • Company registration details
  • Director information
  • Tax and registration numbers

Compliance documents

  • CIPC, SARS, UIF and COIDA records
  • Supporting documentation
  • Status letters

Technical

  • Device information
  • IP addresses
  • Browser type & version

Usage

  • How you use our website
  • Service interaction history
03

How we collect information

We collect information through:

  • Direct interactions when you contact us or request a service
  • Forms, enquiries, and the Compliance Health Check
  • Documents you provide for compliance work
  • Automated technologies when you use our website
  • Public registers and authorised third-party sources
04

How we use your information

We use your personal information for the following purposes:

Service delivery

Performing and coordinating the compliance services you request.

Referrals

Introducing you to, and coordinating with, vetted panel professionals.

Legal compliance

Meeting our legal, regulatory, and record-keeping obligations.

Risk & verification

Verifying identity and preventing fraud or misuse.

Communication

Responding to enquiries and keeping you updated — marketing only with consent.

Improvement

Improving our website, services, and client experience.

05

Legal basis for processing

We process your personal information on one or more of the following bases:

Your consent
Performance of a contract
Legal obligations
Legitimate business interests
06

Information sharing

We do not sell your personal information. We may share it, only as needed, with:

  • Panel professionals

    Vetted accountants, tax practitioners, attorneys and compliance professionals engaged to assist your matter, under confidentiality.

  • Government and regulatory bodies

    CIPC, SARS, the UIF, the Compensation Fund, and other authorities, where a submission is made on your behalf or required by law.

  • Service providers

    Trusted hosting, communication, and technology providers that help us operate the platform, under data-processing terms.

  • Corporate transactions

    Only in the context of a merger, acquisition, or restructuring of Compliance Factory, and only with appropriate safeguards.

07

Your rights under POPIA

POPIA · Your rights

Under the Protection of Personal Information Act, you have the following rights in relation to your personal information:

Access your personal information

Correct your personal information

Request deletion of your personal information

Object to certain processing

Lodge a complaint with the Information Regulator

Withdraw consent at any time

08

Information security

We apply appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, or damage:

Encryption in transit and at rest
Access controls & authentication
Regular security reviews
Staff training on data protection
Secure storage & transmission
09

Retention

We keep your personal information only for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, tax, and record-keeping requirements. Where a longer retention period is required by law, we will retain the relevant records for that period.

10

International transfers

Some of our service providers may process or store data outside South Africa. Where personal information is transferred across borders, we ensure adequate safeguards are in place in compliance with POPIA.

11

Changes to this statement

We may update this Privacy Statement from time to time. Any changes will be posted on this page with a revised date. Your continued use of our services after an update constitutes your acknowledgement of the revised statement.

12

Contact our Information Officer

Information Officer

For access, correction, deletion, or any privacy query, contact us using the details below.

13

Complaints

If you believe your privacy rights have been infringed, you may raise it with us directly, or lodge a complaint with the Information Regulator:

This Privacy Statement was last updated on 01 June 2026 and should be read together with our Terms of Service.