Protection of Personal Information Act (POPIA) Policy
NetWize (Pty) Ltd (Reg 2024/000000/07) · Effective 2026-08-31
1. Responsible Party
NetWize (Pty) Ltd, Registration No. 2024/000000/07, ICASA Licence ICASA/ECS/xxxx.
Information Officer (PAIO): paio@netwize.co.za · Response time ≤ 21 days (POPIA s.50).
2. Information Collected
- Onboarding: full names, ID / registration, physical address, email, phone (WhatsApp)
- Service: PPPoE username, hotspot MAC, assigned IP, session logs (radacct / radpostauth)
- Financial: invoices, proof-of-payment attachments, references
- Support: ticket contents, WhatsApp message bodies retained for 24 months after closure
3. Lawful Bases
- Contract (service delivery & billing)
- Legal obligation (SARS 5-yr retention, ICASA ECS licence conditions)
- Legitimate interest (network abuse prevention, capacity planning)
- Consent (WhatsApp marketing — reply STOP any time)
4. Your Rights
- Access:
POST /api/customer/paia/access-request or request in writing to PAIO
- Correction: customer portal or email support
- Delete / Restrict: subject to lawful retention periods (Tax Admin Act s.20, ECT Act s.79)
- Data Portability: JSON export of your record on request
- Opt-out: reply STOP to any WhatsApp, or use
/api/customers/:id/opt-out
5. Cross-border Transfers
All personal information is processed within the Republic. Backup archives remain in RSA unless an international provider is used with adequate protections per POPIA s.72.
6. Data Breach Procedure
Within 48 hours of detection of a breach creating a real risk of harm: (a) IRASA to the Information Regulator (form 2); (b) notification to affected data subjects; (c) incident record kept in nw_audit.
Contact: support@netwize.co.za · Tel 010 000 0000 · 22 Internet Ave, Tech Park, South Africa