Version 1.0, effective 17 August 2026
This policy explains what personal information we collect, why we collect it, what we do with it, and what rights you have. It is issued in compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), and constitutes the notification required by section 18 of that Act.
1. Who is responsible
| Responsible Party | STACKBOU (PTY) LTD trading as StackBou |
| Registration number | 2026/674140/07 |
| Physical address | Available on request from contact@stackbou.co.za |
| Information Officer | privacy@stackbou.co.za |
| Contact for privacy matters | privacy@stackbou.co.za |
Our Information Officer is registered with the Information Regulator (South Africa), which you can contact at:
Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 complaints.IR@inforegulator.org.za https://inforegulator.org.za
2. Two different roles
2.1 Where we are the Responsible Party. For information about you as a visitor, enquirer or client of StackBou, we decide why and how it is processed. This policy governs that.
2.2 Where we are an Operator. When we host your website, we process personal information belonging to your customers and visitors, on your instruction. In that case you are the Responsible Party and we are the Operator. Our obligations are set out in clause 11 of the Web Hosting Agreement, and your own privacy policy, not this one, governs how that information may be used.
3. What we collect and why
3.1 Website visitors
| Information | Why | Lawful basis |
|---|---|---|
| IP address, browser, device, pages viewed | Security, abuse prevention, basic analytics | Legitimate interest, s 11(1)(f) |
| Cookies as described in clause 8 | Site function and preferences | Consent, s 11(1)(a), and legitimate interest |
3.2 Triage and enquiry forms
When you submit our repair or project form we collect:
- your name or organisation name;
- your email address;
- your website URL;
- your role and information about your business and site;
- a description of the problem or project, when it started, and what changed;
- your current hosting provider and installed plugins;
- your budget range and timeline; and
- whether you have a backup.
We use this to assess your request, respond to you, prepare a quote, and perform the work if you engage us.
Lawful basis: performance of a contract or steps taken at your request, POPIA section 11(1)(b).
3.3 System credentials
Credentials are not collected through this website. Where an engagement requires access to your systems, credentials are transferred by single-use secret link arranged after we accept the engagement.
How we handle credentials we receive:
- they are used only for the work you engaged us for;
- they are never stored in our website database;
- they are held in an encrypted credential store with access restricted to the Information Officer;
- they are not shared with any third party; and
- they are destroyed within 30 days of the engagement ending, unless we host you.
Credentials issued to us should be rotated once the work is complete.
3.4 Clients
For clients we also process: billing and contact details, invoices and payment records, correspondence and support history, and technical records of work performed.
Lawful basis: performance of a contract, POPIA section 11(1)(b), and compliance with a legal obligation, section 11(1)(c), since tax law requires us to retain records.
3.5 Website chat
If you use the chat widget on our site, we process the messages you send in order to respond. The chat is not a channel for credentials, financial details or third-party personal information.
3.6 What we do not collect
Payment card details are not collected or stored. Payments are made by EFT directly to our bank. We do not request card numbers or banking PINs.
4. Who we share information with
We share personal information only with:
| Recipient | Purpose |
|---|---|
| Our hosting and infrastructure provider | Hosting our website and servers |
| Our email service provider | Sending and receiving email |
| Our messaging notification service | Alerting us to new enquiries |
| Our accountant and bank | Invoicing, payment and statutory records |
| SARS and other regulators | Where the law requires it |
| Law enforcement | Where compelled by valid legal process |
We do not sell your personal information. We do not share it with advertisers or data brokers.
We name the categories rather than the individual suppliers. If you are a client and need the specific providers we use, for your own POPIA record keeping, ask us and we will give you the current list in writing.
5. Cross-border transfer
Our primary infrastructure is in South Africa. Some of the services in clause 4, notably email and messaging notification, may process data outside the Republic. Where that happens, we transfer only as permitted by section 72 of POPIA, meaning the recipient is subject to a law or binding agreement giving substantially similar protection, or the transfer is necessary to perform our contract with you.
6. How long we keep it
| Category | Retention |
|---|---|
| Enquiries that do not become engagements | 12 months, then deleted |
| System credentials | Destroyed within 30 days of engagement ending |
| Client records and correspondence | 5 years after the relationship ends |
| Invoices and financial records | 5 years, as required by the Tax Administration Act 28 of 2011 |
| Signed access authorisations | 5 years |
| Hosted Client Data on termination | 30 days, then permanently deleted |
| Server and security logs | 90 days |
We delete or de-identify personal information once the retention period ends and there is no longer a lawful purpose for keeping it, in accordance with section 14 of POPIA.
7. How we protect it
We apply the security safeguards required by section 19 of POPIA, including:
- TLS encryption on all connections to our website and infrastructure;
- encrypted storage for credentials, separate from our website;
- key-based SSH authentication with password login disabled;
- least-privilege access control and a firewalled server perimeter;
- regular patching of operating system and application software;
- monitoring for unauthorised access; and
- no storage of credentials in any web-accessible database.
If a compromise occurs we will notify the Information Regulator and every affected person as soon as reasonably possible after discovering it, as required by section 22 of POPIA.
8. Cookies
8.1 We use:
- Strictly necessary cookies, for session handling and form security tokens. These cannot be disabled without breaking the site.
- Preference cookies, remembering choices such as theme.
- We do not currently use analytics cookies.
8.2 You can block or delete cookies through your browser settings. Strictly necessary cookies are required for our forms to work.
8.3 We do not use advertising or cross-site tracking cookies.
9. Direct marketing
9.1 We may send you information about our services only where you are an existing client, or where you have consented.
9.2 Every marketing message includes an unsubscribe mechanism, as required by section 45 of ECTA and section 69 of POPIA. Unsubscribing takes effect promptly and we will not contact you again for marketing purposes.
9.3 We do not sell or rent our contact list.
10. Your rights
Under POPIA you have the right to:
10.1 be told what personal information we hold about you;
10.2 access that information, on request, subject to the procedures in the Promotion of Access to Information Act 2 of 2000;
10.3 correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, under section 24;
10.4 object to processing based on legitimate interest, under section 11(3);
10.5 withdraw consent at any time, where processing was based on consent, which does not affect processing already carried out;
10.6 not be subject to a decision based solely on automated processing that significantly affects you, under section 71; and
10.7 complain to us, and to the Information Regulator.
To exercise any of these rights, email contact@stackbou.co.za. We will respond within 30 days. We may ask you to verify your identity first, so that we do not disclose your information to someone else.
Some requests use prescribed forms available from the Information Regulator’s website. We will tell you if that applies and help you with the process.
11. Complaints
11.1 Come to us first. Email contact@stackbou.co.za. We acknowledge within 5 business days and respond substantively within 15 business days.
11.2 If you are not satisfied, you may complain to the Information Regulator using the contact details in clause 1. You do not need our permission to do so.
12. Access to information
Our PAIA manual, compiled under the Promotion of Access to Information Act 2 of 2000, is published at stackbou.co.za/paia and is available free on request.
13. Children
Our services are directed at businesses. We do not knowingly collect personal information of children under 18. Section 34 of POPIA prohibits processing children’s personal information without competent consent. If you believe we hold information about a child, contact us and we will delete it.
14. Changes
We may update this policy. The current version is always at stackbou.co.za/privacy. Where a change materially affects how we use your information, we will notify you directly.
StackBou Privacy Policy, version 1.0, 17 August 2026.