Legal

Privacy Policy

Plain-language detail on what we collect, why we collect it, who sees it, how long we keep it, and the rights you hold under POPIA.

Last updated: 14 August 2026

01Who we are and what this policy covers

ThatEngineer (Pty) Ltd ("ThatEngineer", "we", "us") is a South African software engineering studio based in Port Elizabeth / Gqeberha, Eastern Cape. This policy explains how we process personal information when you visit thatengineer.co.za, contact us, request a walkthrough or architecture specs, or engage us for services.

We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and, where it applies to a project, the client's own data protection obligations. Terms such as "personal information", "processing", "responsible party" and "operator" carry the meanings given to them in POPIA.

Where we decide why and how personal information is processed (for example, our website and sales enquiries), we act as the responsible party. Where we process personal information inside a client's systems on that client's instructions, the client remains the responsible party and we act as their operator under a written engagement.

02Information we collect

We collect only what we need for the purpose at hand:

  • Contact and enquiry data: name, work email address, telephone number, company name, role, location, the product or service you are interested in, and the description of the challenge or system you share with us.
  • Engagement data: correspondence, meeting notes, proposals, scoping documents, invoicing and payment records, and records required for tax and company law purposes.
  • Technical data: IP address, browser and device type, pages viewed, referring page and approximate region, collected when you use the website so that we can keep it available, secure and functional.
  • Client system data: where a project requires it, information contained in the systems we integrate with or automate. This is processed strictly on the client's documented instructions.

We do not knowingly collect special personal information (as defined in POPIA) or information about children through this website. Please do not send us such information through the contact form. If a project genuinely requires it, we agree the lawful basis and safeguards with the client in writing first.

03Why we process it and on what lawful basis

  • To respond to enquiries, prepare demonstrations, architecture specs and quotes — on your request and in the steps leading up to a contract.
  • To deliver, support and invoice engaged work — performance of our contract with you or your organisation.
  • To keep our website and systems secure, prevent abuse and diagnose faults — our legitimate interests, balanced against your rights.
  • To meet legal duties, including tax, company, accounting and B-BBEE record-keeping obligations — compliance with law.
  • To send occasional service or product updates to existing clients and people who asked to hear from us — consent or the direct-marketing provisions of POPIA and the Electronic Communications and Transactions Act 25 of 2002. Every message includes an opt-out.

We do not sell personal information, and we do not use it to build advertising profiles.

04Cookies and website analytics

The website uses only the cookies and local storage necessary to serve pages, remember your preferences and keep the site secure. If we later add analytics or embedded third-party content that sets non-essential cookies, we will ask for your consent before those cookies are placed and update this policy accordingly.

Most browsers let you block or delete cookies. Blocking essential cookies may affect how parts of the site work.

05Who we share information with

We share personal information only where there is a clear reason to do so:

  • Service providers who host our site, deliver email, host our infrastructure, or process payments — each under a written agreement limiting them to our instructions.
  • Professional advisers such as accountants, auditors and attorneys, where confidentiality applies.
  • Regulators, courts or law enforcement where we are legally compelled, and only to the extent required.
  • An acquirer or successor entity if our business is restructured or transferred, subject to this policy continuing to apply.

Some of our providers process information outside South Africa. Where that happens we rely on section 72 of POPIA: the recipient must be subject to a law, binding agreement or corporate rules that provide protection substantially similar to POPIA, or the transfer must be necessary to perform our contract with you.

06How we protect information

We apply technical and organisational safeguards appropriate to the sensitivity of the information: encryption in transit, access on a least-privilege and need-to-know basis, multi-factor authentication on administrative accounts, hardened deployment pipelines, logging, and vetted senior engineers bound by confidentiality obligations.

No system is absolutely secure. If a security compromise affects personal information under our control, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after establishing the scope of the compromise, as section 22 of POPIA requires.

07How long we keep it

We keep enquiry data for up to 24 months after our last meaningful contact, unless you ask us to delete it sooner. Contract, invoicing and tax records are kept for at least five years as required by South African tax and company law. Information processed inside a client's systems is retained and deleted according to that client's instructions and the engagement agreement.

When a retention period ends, we delete the information or de-identify it so that it can no longer be linked to a person.

08Your rights

Subject to POPIA, you may:

  • Ask what personal information we hold about you and request a copy.
  • Ask us to correct, complete or delete information that is inaccurate, irrelevant, excessive, out of date, misleading or unlawfully obtained.
  • Object to processing based on legitimate interests, on reasonable grounds relating to your situation.
  • Withdraw consent at any time, without affecting processing already carried out lawfully.
  • Opt out of direct marketing at any time.
  • Lodge a complaint with the Information Regulator (South Africa).

To exercise any of these rights, email contact@thatengineer.co.za. We may need to verify your identity before acting, and we will respond within the timeframes POPIA prescribes. Requests for access may be made using the Form 2 procedure under the Promotion of Access to Information Act 2 of 2000, and a prescribed fee may apply for copies.

Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg — enquiries@inforegulator.org.za.

09Third-party links and changes to this policy

Our site may link to third-party websites or documentation. We are not responsible for their content or privacy practices; review their policies before sharing information with them.

We may update this policy as our services, providers or legal obligations change. The revised version takes effect when published on this page, and the date above will reflect the change. Material changes affecting how we use your information will be communicated to active clients directly.

Information Officer

ThatEngineer (Pty) Ltd, Port Elizabeth / Gqeberha, Eastern Cape, South Africa. contact@thatengineer.co.za · 087 265 4432

This policy is a general statement of our practices and is not legal advice to you. Client engagements are governed by the signed agreement between us, which prevails over this page where the two differ.