Privacy Policy
How We Handle Your Information
Collect Responsibly
Use Transparently
Protect Your Data
Respect Your Rights
On This Page
Introduction
RC IT Services respects your privacy and is committed to protecting personal information processed through our website, products, services and business operations.
This Privacy Policy explains what personal information we may collect, how and why we use it, when it may be shared, how we seek to protect it, and the rights available to individuals under applicable data protection legislation, including the Protection of Personal Information Act 4 of 2013 (“POPIA”).
This policy applies when you visit our website, contact us, submit an enquiry, purchase products or services, request technical support, subscribe to communications, or otherwise interact with RC IT Services.
Information We Collect
RC IT Services may collect personal information directly from you, automatically when you use our website, or through our business and service relationships.
Depending on how you interact with us, this may include:
- Identity and contact information — such as your name, business name, email address, telephone number, physical or installation address and other contact details.
- Account and customer information — such as information associated with your customer account, service subscriptions, orders and support relationship with RC IT Services.
- Order and transaction information — including products or services purchased, billing information, delivery details, transaction history and related records. Payment card details may be processed by the applicable payment service provider rather than stored directly by RC IT Services.
- Service and technical information — including information you provide when requesting IT support, managed services, cybersecurity services, hosting, fibre, Microsoft 365 assistance or other technical services.
- Website and device information — such as IP address, browser type, device information, pages visited, referral information and other technical data generated when interacting with our website.
- Communications — including emails, contact-form submissions, support requests, enquiries, feedback and other correspondence with us.
- Marketing preferences — including your preferences relating to promotional or service-related communications where applicable.
We aim to collect only information that is reasonably relevant to the purpose for which it is required.
How We Use Your Information
RC IT Services may use personal information for purposes reasonably connected with operating our business, providing our products and services, maintaining security and meeting our legal and contractual responsibilities.
Depending on your relationship with us, we may use personal information to:
- Provide products and services — process orders, activate services, manage subscriptions and deliver the IT, cybersecurity, hosting, connectivity and other solutions you request.
- Provide technical support — respond to support requests, investigate technical issues, communicate with users and assist with the management, maintenance or security of relevant systems.
- Manage customer relationships — maintain customer records, administer accounts, provide service-related communications and manage our ongoing relationship with you or your organisation.
- Process orders and billing — manage quotations, purchases, invoices, payments, deliveries, renewals and related financial or administrative records.
- Respond to enquiries — process contact-form submissions, sales enquiries, requests for information and other communications.
- Protect systems and services — detect, investigate and respond to suspected fraud, misuse, cybersecurity threats, unauthorised activity and other security risks.
- Operate and improve our website — understand how our website is used, diagnose technical problems and improve website functionality, performance and user experience.
- Communicate about relevant products and services — send marketing or promotional communications where permitted and subject to applicable preferences or consent requirements.
- Meet legal and regulatory obligations — maintain records, respond to lawful requests and comply with applicable laws, regulations and legal processes.
- Establish or protect legal rights — where reasonably necessary to exercise, defend or protect our rights, customers, systems, property or legitimate business interests.
We will not use personal information for purposes that are materially incompatible with the reason it was collected unless there is an appropriate legal basis or we otherwise inform you where required.
Lawful Processing of Personal Information
RC IT Services processes personal information only where there is an appropriate basis for doing so under applicable law. The basis used will depend on the information involved, our relationship with you and the purpose of the processing.
Where applicable, we may process personal information on the basis of:
- Consent — where you have voluntarily provided consent for a specific processing activity and consent is an appropriate basis under applicable law.
- Contractual necessity — where processing is necessary to enter into, administer or perform a contract with you, including providing products, services, subscriptions or support.
- Legal obligations — where we are required to process or retain information to comply with applicable legislation, regulatory requirements, lawful requests or other legal obligations.
- Legitimate interests — where processing is reasonably necessary to pursue our legitimate business interests or those of a third party, provided those interests are appropriately balanced against your rights and interests.
- Protection of legitimate interests — where processing is necessary to protect your legitimate interests or those of another person, where permitted by applicable law.
- Other lawful grounds — where another basis for processing is permitted or required under POPIA or other applicable legislation.
Where consent is relied upon, you may generally withdraw that consent subject to applicable legal or contractual limitations. Withdrawal does not necessarily affect processing that was lawful before consent was withdrawn.
RC IT Services aims to process personal information in a manner that is reasonable, adequate, relevant and not excessive in relation to the purpose for which it is processed.
Orders, Billing & Payments
When you purchase a product or service, request a quotation, subscribe to a service or otherwise enter into a commercial relationship with RC IT Services, we may collect and process information necessary to manage the transaction.
This may include:
- Order information — products or services ordered, quantities, subscription details, order status and transaction history.
- Customer details — your name, business name, email address, telephone number and other information required to manage your order or account.
- Billing information — billing address, invoice details and information reasonably required for accounting and financial administration.
- Delivery or installation information — physical addresses and contact information required to deliver products, arrange installations or provide onsite services.
- Payment information — information necessary to process or confirm payments. Payments may be processed through third-party payment providers, banks or financial institutions, depending on the payment method selected.
- Service records — information relating to service activation, renewals, cancellations, upgrades and other changes to products or services supplied by RC IT Services.
Where a third-party payment provider is used, that provider may process payment information in accordance with its own privacy and security practices. RC IT Services does not control the independent processing activities of third-party financial institutions or payment providers.
We may retain transaction, invoice and related financial records where reasonably necessary for accounting, contractual, dispute-resolution or legal and regulatory purposes.
International Processing & Data Transfers
RC IT Services is based in South Africa, but some of the technology platforms, cloud infrastructure, service providers and other third parties used in providing our products and services may process or store personal information in other countries.
As a result, personal information may in certain circumstances be transferred to, stored in or accessed from jurisdictions outside South Africa.
Where cross-border processing or transfers occur, RC IT Services aims to take reasonable steps to ensure that personal information is handled in accordance with applicable data protection requirements, including the requirements of POPIA relating to the transfer of personal information outside South Africa.
Depending on the circumstances, appropriate safeguards may include:
- Adequate protection — transferring information to a recipient that is subject to a law, binding corporate rules or binding agreement that provides an adequate level of protection as contemplated by applicable law.
- Contractual safeguards — using appropriate contractual arrangements or data-protection obligations where relevant.
- Consent — obtaining consent for a cross-border transfer where consent is an appropriate and lawful basis.
- Contractual necessity — transferring information where this is necessary for the performance or conclusion of a contract in circumstances permitted by applicable law.
- Other lawful grounds — relying on another basis for an international transfer where permitted under POPIA or other applicable legislation.
The location in which information is processed may vary depending on the particular product, service, infrastructure or third-party provider involved.
Information Security
RC IT Services takes the protection of personal information seriously and uses reasonable technical and organisational measures designed to protect information against loss, misuse, unauthorised access, disclosure, alteration or destruction.
The safeguards used may vary depending on the nature of the information, systems and services involved and may include measures such as:
- Access controls — limiting access to systems and information to authorised persons where reasonably appropriate.
- Authentication and account security — using appropriate authentication and security controls to help protect accounts, platforms and administrative systems.
- Cybersecurity controls — using security technologies and practices designed to detect, prevent and respond to malicious or unauthorised activity.
- System monitoring and maintenance — maintaining, monitoring and updating relevant systems and infrastructure where appropriate.
- Backup and recovery measures — using appropriate backup and recovery practices for relevant business systems and information.
- Service-provider safeguards — considering appropriate security and privacy practices when selecting third-party providers that may process information on our behalf.
- Incident response — taking reasonable steps to investigate and respond to suspected security incidents involving systems or personal information.
While we take reasonable measures to protect personal information, no website, network, electronic communication or information system can be guaranteed to be completely secure.
If RC IT Services becomes aware of a security compromise involving personal information, we will assess the incident and take appropriate steps in accordance with applicable legal and regulatory requirements, including notification requirements where applicable.
Data Retention
RC IT Services retains personal information only for as long as reasonably necessary for the purposes for which it was collected or subsequently processed, subject to applicable legal, regulatory, contractual and operational requirements.
The period for which information is retained may vary depending on the type of information and the reason it is held. Factors we may consider include:
- Service requirements — whether the information is required to provide, maintain or support an active product, service, subscription or customer relationship.
- Financial and transaction records — whether records relating to orders, invoices, payments or other transactions must be retained for accounting, tax or other legal purposes.
- Support and technical records — whether information remains reasonably necessary to provide support, maintain service history, investigate technical issues or protect relevant systems.
- Security information — whether logs, records or other information are reasonably required for cybersecurity, fraud prevention, incident investigation or system integrity.
- Legal and regulatory obligations — whether applicable legislation, regulatory requirements or lawful processes require information to be retained.
- Disputes and legal claims — whether information may reasonably be required to establish, exercise or defend legal rights or resolve a dispute.
- Consent and preferences — whether certain information needs to be retained to record communication preferences, consent choices or objections.
When personal information is no longer reasonably required and there is no lawful reason to retain it, RC IT Services will take appropriate steps to delete, destroy, de-identify or otherwise dispose of the information in accordance with applicable requirements.
Backup systems and technical archives may retain copies for a limited period as part of normal backup, recovery and system-management processes before those copies are overwritten or otherwise removed.
Marketing & Communications
RC IT Services may communicate with customers, prospective customers and other contacts about our products, services, account matters, security information and relevant business updates.
These communications may include:
- Service communications — information relating to products or services you use, including activations, renewals, maintenance, support matters, service changes and other operational notices.
- Account and transaction communications — quotations, orders, invoices, payment information, delivery updates and other communications relating to your account or transactions.
- Security communications — important information concerning cybersecurity, account security, incidents, vulnerabilities or other matters that may affect services or systems.
- Marketing communications — information about products, services, promotions or other offerings that may be relevant to you, where such communications are permitted under applicable law.
- Requested communications — information sent in response to an enquiry, quotation request, contact-form submission or other request you have made.
Where required, RC IT Services will seek appropriate consent before sending direct marketing communications and will aim to provide a reasonable method for recipients to opt out of further marketing.
You may request that we stop sending you direct marketing communications at any time by using an available unsubscribe mechanism or by contacting us.
Opting out of marketing does not necessarily prevent us from sending communications that are reasonably necessary for an existing customer relationship, transaction, service, security matter or legal obligation.
Your Rights Under POPIA
Under the Protection of Personal Information Act (POPIA), you may have certain rights in relation to personal information processed by RC IT Services. These rights are subject to applicable legal requirements, limitations and exceptions.
Depending on the circumstances, your rights may include:
- Right to be informed — to be informed when personal information is collected and about the purposes for which it is processed.
- Right of access — to request confirmation of whether RC IT Services holds personal information about you and, subject to applicable requirements, request access to that information.
- Right to correction — to request the correction or updating of personal information that is inaccurate, incomplete, misleading or out of date.
- Right to deletion or destruction — to request the deletion or destruction of personal information in circumstances where RC IT Services is no longer authorised or required to retain it.
- Right to object — to object, on reasonable grounds and where permitted by law, to certain processing of your personal information.
- Right relating to direct marketing — to object to or withdraw from direct marketing communications in accordance with applicable requirements.
- Right to withdraw consent — where processing is based on consent, to withdraw that consent, subject to applicable legal and contractual limitations.
- Right to complain — to raise a privacy concern with RC IT Services and, where applicable, submit a complaint to the Information Regulator of South Africa.
- Rights relating to automated decisions — to receive applicable protections where a decision that significantly affects you is based solely on automated processing in circumstances covered by POPIA.
To exercise an applicable privacy right, you may contact RC IT Services using the contact information provided at the end of this Privacy Policy.
We may need to take reasonable steps to verify your identity before providing access to personal information or acting on certain requests. This helps us prevent unauthorised disclosure, alteration or deletion of information.
Certain requests may be subject to limitations or requirements imposed by applicable law, including circumstances where information must be retained for legal, contractual, security, financial or dispute-resolution purposes.
Children’s Information
RC IT Services’ website, products and services are primarily intended for adults, businesses and organisations and are not specifically directed at children.
Where personal information relating to a child is processed, RC IT Services will aim to do so only where permitted by applicable law and where an appropriate legal basis exists. Depending on the circumstances, this may include obtaining consent or authorisation from a competent person as contemplated by POPIA.
We do not knowingly seek to collect personal information from children through our website for marketing purposes.
If you believe that a child has provided personal information to RC IT Services in circumstances where it should not have been collected, please contact us so that we can review the matter and take appropriate action where necessary.
Changes to This Privacy Policy
RC IT Services may update this Privacy Policy from time to time to reflect changes to our business, website, products, services, technology, data-processing practices or applicable legal and regulatory requirements.
When this Privacy Policy is updated, the revised version will be published on this page and the “Last updated” date at the top of the policy will be changed accordingly.
Where changes are material and additional notification is appropriate or required by applicable law, we may take reasonable steps to bring those changes to the attention of affected individuals.
We encourage you to review this Privacy Policy periodically so that you remain informed about how RC IT Services handles personal information.
Privacy Enquiries & Complaints
If you have questions about this Privacy Policy, wish to exercise an applicable privacy right, or have concerns about how RC IT Services handles your personal information, you may contact us using the details below.
RC IT Services
17 Ingwe Road, Sandrift, Milnerton
Cape Town, Western Cape, 7441
South Africa
Email: sales@rcitservices.co.za
Telephone: +27 87 550 2103
Website: www.rcitservices.co.za
When submitting a privacy-related request, please provide sufficient information for us to understand your request and, where necessary, verify your identity. Please do not send passwords, authentication credentials or other unnecessary sensitive information when contacting us.
We will aim to consider and respond to privacy-related requests in accordance with applicable legal requirements.
If you are not satisfied with how a privacy matter has been handled, you may also have the right to lodge a complaint with the Information Regulator of South Africa in accordance with POPIA.
