POPIA Compliance Executive Summary
  • Responsible Party: Legacy Risk (A South African Private company, operating digital forensic, cybersecurity, A1 Audit, and EasyTrac platforms).
  • Data Protection Standard: 100% compliant with South Africa's POPIA (Act 4 of 2013) 8 Conditions for Lawful Processing.
  • Consent & Minimisation: Personal information (Name, Email, Phone, Company, PSIRA info) is processed solely with explicit consent for security audits, software demonstrations, and client service delivery.
  • Data Security: Enterprise TLS 1.3 in-transit encryption, role-based database access, and tamper-resistant audit logs.
  • Your Rights: You have the right to request access, correction, or complete deletion of your data at any time by contacting our Information Officer.

1. Introduction & Scope

Legacy Risk ("Legacy Risk", "we", "us", or "our") is a South African digital forensics, compliance, and cybersecurity organization. We are committed to protecting the privacy, confidentiality, and security of all personal information entrusted to us by clients, website visitors, and software users.

This Privacy Policy applies to all services, websites, and products operated by Legacy Risk, including legacyrisk.co.za, a1audit.legacyrisk.co.za, and the EasyTrac security workforce management platform.

2. Responsible Party & Information Officer

For the purposes of POPIA, Legacy Risk acts as the Responsible Party. In compliance with Section 55 of POPIA, our designated Information Officer oversees data protection and compliance:

Information Officer Contact Details

Company: Legacy Risk

Information Officer: Bryan Botha

Direct Email: bryan@legacyrisk.co.za

Physical Location: Republic of South Africa

Telephone / Direct Helpline: 081 806 8993 / WhatsApp: 062 206 2264

3. Categories of Personal Information We Collect

We only collect personal information that is adequate, relevant, and strictly necessary for our declared business purposes:

  • Contact Information: Full name, business email address, direct telephone / WhatsApp number, and job title.
  • Business Details: Company name, operating province, website URL (for automated security & SSL audit requests), and security fleet size (for EasyTrac demonstrations).
  • Technical & Log Data: IP address, browser type, referral URLs, and session timestamps captured strictly for cybersecurity defense, spam prevention, and server performance monitoring.
  • Public Intelligence Data: Open-source intelligence (OSINT) strictly gathered from publicly accessible records and registries.

4. Lawful Basis & Purpose for Processing

In accordance with Section 11 of POPIA, processing of personal information is conducted under the following lawful grounds:

  1. Explicit Consent: Provided by you when submitting intake forms, requesting an A1 Website Security Audit, or booking an EasyTrac demo.
  2. Contractual Performance: Necessary to provide cybersecurity assessments, digital forensic consulting, or software subscriptions.
  3. Legal Obligations: Compliance with South African statutory requirements, including NBCPSS Sectoral Determination 6 and PSIRA regulatory standards where applicable.
  4. Legitimate Interests: Protecting our infrastructure, preventing cyber attacks, and maintaining chain-of-custody audit logs.

5. Information Security & Technical Safeguards

In accordance with Condition 7 of POPIA, Legacy Risk implements robust administrative, technical, and physical security measures:

  • Transport Layer Security: All data transmitted between your browser and our servers is protected using 256-bit TLS / HTTPS encryption.
  • Input Sanitisation & Validation: Protection against cross-site scripting (XSS), SQL injection, and unauthorized remote access.
  • Zero-Knowledge Public Audits: Our A1 Website Audit only examines publicly visible web signals (SSL certificates, DNS, headers, robots.txt) and does not access any internal database or private files.
  • Strict Access Control: Access to consultation records is restricted solely to authorized compliance and investigative personnel.

6. Cookies, Analytics & Web Tracking Technologies

We use strictly necessary cookies to ensure technical website functionality, as well as performance cookies (via Google Analytics 4, Tag ID: G-7HHFPRH1S7) to analyze aggregate site traffic, measure diagnostic scan requests, and improve page responsiveness.

  • IP Anonymisation: Analytical tracking operates with IP anonymisation enabled by default.
  • No Retargeting or Advertising Trackers: We do not deploy third-party behavioural ad networks, remarketing pixels, or data broker beacons.
  • Managing Consent: Visitors can adjust their cookie preferences at any time using our on-site consent banner or by configuring their browser settings to reject non-essential cookies.

7. Third-Party Disclosures & Cross-Border Transfers

Legacy Risk will never sell, rent, or trade your personal information to third parties. Data is only shared with trusted service providers (e.g. secure cloud infrastructure, encrypted transactional email relays) under strict Data Processing Agreements requiring equivalent POPIA-grade protection. Cross-border transfers adhere strictly to Section 72 of POPIA.

8. Your Rights as a Data Subject Under POPIA

Under Sections 23 and 24 of POPIA, you possess enforceable rights regarding your personal information:

  • Right of Access: Request confirmation of whether we hold personal information about you and receive a copy of that record.
  • Right to Rectification: Request correction or update of inaccurate, incomplete, or outdated information.
  • Right to Erasure / Deletion: Request the destruction or deletion of your personal data when it is no longer required for the purpose for which it was collected.
  • Right to Object: Object at any time to the processing of your personal information on reasonable grounds.
  • Right to Withdraw Consent: Revoke consent previously given for marketing or demonstration communications.

To exercise any of these rights, please email our Information Officer at bryan@legacyrisk.co.za. Requests will be addressed within 14 business days.

9. Statutory PAIA Manual & Terms of Service

For formal access requests under the Promotion of Access to Information Act (PAIA, Act 2 of 2000), please consult our published PAIA Section 51 Statutory Compliance Manual. Usage of all Legacy Risk websites and diagnostic tools is governed by our Terms of Service.

10. Complaints to the Information Regulator

If you believe that your personal information has been processed in contravention of POPIA, you have the right to lodge a complaint directly with the South African Information Regulator:

Information Regulator (South Africa)

Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Complaints Email (POPIA): POPIAComplaints@inforegulator.org.za

Website: https://inforegulator.org.za/

Have Questions About Your Data or Security?

Contact our forensic and compliance specialists for a direct consultation regarding our systems and POPIA safeguards.

Contact Compliance Team