Legal

Privacy Policy

How Renovoir (Pty) Ltd collects, uses, stores, discloses and protects personal information under POPIA and, where applicable, international privacy law.

Effective date: 13 September 2026 · Last updated: 14 September 2026

01Who this policy applies to

This Privacy Policy applies to personal information processed in connection with:

  • visitors to our website;
  • prospective, current and former clients;
  • representatives, employees and contractors of clients;
  • individuals who contact or correspond with us;
  • suppliers, contractors, service providers and business partners;
  • individuals whose information may be provided to us by a client while delivering a service; and
  • other individuals who interact with Renovoir.

02Our role when processing personal information

When Renovoir determines why and how personal information is processed for our own business purposes, we generally act as the Responsible Party under POPIA or, where applicable, the Controller under the GDPR or comparable international privacy legislation.

Where Renovoir processes personal information solely on the documented instructions of a client — for example through a client’s website, CRM, forms, analytics, advertising systems, e-commerce platform or portal — Renovoir may act as an Operator under POPIA or a Processor under the GDPR or other applicable privacy legislation.

Technical access to information in a client system does not, by itself, make Renovoir the Responsible Party or Controller for that information.

03Personal information we may collect

Depending on the nature of our relationship with you, we may collect:

  • name and contact information, business or company information, professional role and industry;
  • telephone number, email address and correspondence or enquiry information;
  • project requirements and briefs, brand assets, website content and project materials;
  • account or access information supplied for project purposes;
  • billing and invoicing information, payment status and transaction records;
  • supplier or contractor information;
  • technical website information, IP address, browser and device information, operating system, referring pages and website interactions;
  • approximate location derived from technical information where applicable, and cookie or analytics information.

04How we collect information

We may collect information when you use our website, complete a contact or enquiry form, contact us by email, telephone or social media, request a quotation, enter into a service agreement, attend a consultation, work with us on a project, or otherwise voluntarily provide information.

Providing information through our general enquiry form is voluntary. However, certain information may be necessary for Renovoir to respond to an enquiry, prepare a quotation, enter into a contract, process payments or provide requested services.

Information may also be received from clients, authorised representatives, service providers, public business sources, professional networks, social-media platforms, analytics services and other lawful sources.

05Why we process personal information

Renovoir may process information to respond to enquiries, communicate with prospective and existing clients, prepare quotations, establish client relationships, deliver website, branding, marketing and digital services, manage projects, administer contracts, process invoices and payments, provide ongoing support, manage suppliers, maintain and improve our website, measure performance, maintain security, prevent fraud and abuse, keep accounting records, exercise or defend legal rights and comply with tax, regulatory and legal obligations.

We will not intentionally process personal information for a materially incompatible purpose unless legally permitted to do so.

06Lawful grounds for processing

Where applicable legislation requires a lawful basis, Renovoir may process personal information because it is necessary to take steps requested before entering into a contract, to perform a contract, to comply with a legal obligation, for legitimate interests where permitted, because another legally recognised ground applies, or because consent has been provided where consent is appropriate or required.

Consent is not the default legal basis for ordinary contractual processing. Where processing relies on consent, consent may be withdrawn where permitted by law. Withdrawal does not affect processing that was lawful before consent was withdrawn.

07Client data

Renovoir may process personal information controlled by clients while delivering digital services, including information held in websites, enquiry forms, CRM systems, email platforms, analytics systems, advertising platforms and other digital infrastructure.

Clients are responsible for ensuring that they have an appropriate lawful basis for providing personal information to Renovoir and instructing us to process it. Where applicable law requires a processing agreement, the relationship will be governed by written data-processing provisions or an appropriate Data Processing Agreement.

08Artificial intelligence and automated tools

Renovoir may use artificial-intelligence-enabled software, automation technologies and other digital tools to assist with certain aspects of our operations and services. Where personal information is processed through these technologies, we aim to minimise unnecessary personal information, apply appropriate safeguards, assess relevant service providers, respect contractual obligations and limit access to what is appropriate for the task.

This does not mean that Renovoir routinely uploads client personal information to AI systems. Renovoir does not intend to make decisions about individuals solely through automated processing where those decisions would have legal or similarly significant consequences unless such processing is lawful and appropriate safeguards apply.

09Sharing personal information

Renovoir does not sell personal information. Personal information may be disclosed, where reasonably necessary and legally permitted, to categories of recipients such as:

  • hosting and cloud infrastructure providers;
  • website, communication and collaboration platforms;
  • analytics and CRM providers, and project-management systems;
  • payment processors and accounting providers;
  • contractors and specialist collaborators;
  • marketing and advertising platforms where relevant;
  • security and IT providers, and professional advisers;
  • regulators, government authorities and law-enforcement bodies where disclosure is lawfully required; and
  • parties involved in a legitimate restructuring or transfer of the business.

10International transfers

Renovoir and its service providers may process personal information in South Africa and other countries in which our technology providers, hosting providers, contractors or other authorised service providers operate.

Where POPIA applies, transfers outside South Africa will be made in accordance with section 72 of POPIA. Where the GDPR applies and personal data is transferred outside the European Economic Area to a jurisdiction not covered by an adequacy decision, Renovoir will implement an appropriate transfer mechanism where required, which may include Standard Contractual Clauses and supplementary safeguards.

11Cookies and analytics

The website may use cookies and similar technologies for essential functionality, security, remembering preferences, analytics, performance measurement and, where applicable, marketing. Strictly necessary cookies may operate where required for the website to function. Where consent is legally required for non-essential technologies, those technologies remain disabled until appropriate consent has been obtained. Further information is available in our Cookie Policy.

12Direct marketing and social media

Renovoir does not currently offer a website newsletter or marketing-subscription facility. If Renovoir sends electronic direct marketing in future, it will do so only where legally permitted, and marketing communications will provide an appropriate method for unsubscribing or objecting. Opting out of marketing will not prevent necessary transactional, security or project-related communications.

Interactions with Renovoir through third-party social-media platforms may also be processed independently by those platforms under their own privacy terms.

13Security and security incidents

Renovoir takes reasonable technical and organisational measures designed to protect personal information from unauthorised access, loss, destruction, misuse, unlawful disclosure and alteration. Measures may include access controls, authentication, secure infrastructure, encryption, restricted permissions, backups, software maintenance and secure development practices. No digital system can be guaranteed completely secure.

Where Renovoir becomes aware of a security compromise involving personal information, we will investigate and take appropriate steps to contain, mitigate and address it, and will notify the relevant regulator, client and/or affected individuals where notification is required by applicable law.

14Retention

Personal information is retained only for as long as reasonably necessary for the purposes for which it was collected, subject to applicable legal, contractual, accounting, regulatory and dispute-resolution requirements. Information that is no longer required and is not legally required to be retained will be securely deleted, destroyed or de-identified where appropriate and reasonably practicable.

15Your privacy rights

Depending on applicable law and your jurisdiction, you may have rights to:

  • request confirmation of whether personal information about you is processed;
  • access personal information and correct inaccurate or incomplete information;
  • request deletion or destruction where legally permitted;
  • object to certain processing, including processing based on legitimate interests where the law provides that right;
  • withdraw consent where processing relies on consent, and object to direct marketing where applicable;
  • request restriction of certain processing, or portability where the legal requirements are satisfied; and
  • exercise rights relating to certain automated decisions where applicable.

16Children and third-party services

Renovoir’s website and commercial services are primarily directed toward businesses and adults. We do not knowingly solicit children’s personal information where doing so would be prohibited without appropriate authorisation.

The website may link to websites or platforms operated independently by third parties. Renovoir does not control independent third-party privacy practices, and users should review the privacy terms applicable to those services.

17Changes to this policy

This Privacy Policy may be updated to reflect changes in law, technology, our services, our business or our data-processing practices. The most recent revision date appears at the beginning of the Policy.

18Contacting Renovoir about privacy

Information Officer: Kyla Magliolo, Chief Executive Officer. Organisation: Renovoir (Pty) Ltd. Privacy contact: kyla@renovoir.co. General business enquiries: hello@renovoir.co. Business location: Johannesburg, South Africa. Website: renovoir.co. CIPC enterprise number: K2026292897.

Renovoir is a fully online business and does not operate from a public-facing office. For safety and privacy, no founder, director or team member residential street address is published as a public contact address. Johannesburg, South Africa is stated as Renovoir’s public business location and is not represented as a street-level registered, physical or service address.

19South African Information Regulator

If you are in South Africa and believe that your personal information has been processed in contravention of POPIA, you may have the right to lodge a complaint with the Information Regulator (South Africa). POPIA complaints: POPIAComplaints@inforegulator.org.za. General enquiries: enquiries@inforegulator.org.za. Telephone: 010 023 5200. Website: inforegulator.org.za.

If the GDPR or another applicable privacy law applies, you may also have the right to complain to the competent supervisory authority in the relevant jurisdiction.