Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how SG EduTech Solutions (Pty) Ltd (“SG Corp”, “we”, “us”) collects, uses, stores and protects personal information in compliance with the Protection of Personal Information Act, 2013 (POPIA).
1. Information We Collect
- Account information: name, email address, telephone number, organisation, country and customer role. Passwords are stored only as one-way password hashes.
- Order information: products, quantities, delivery and billing details, order notes, payment method, payment status and transaction references.
- Payment information: online card and bank payment details are entered on PayFast's secure service. We do not store card numbers, CVV values or online-banking credentials.
- Enquiries and documents: contact, quotation, training and purchase-order form content and attachments submitted to us.
- Technical and usage information: page address, page title, referrer, browser user agent and pseudonymous session and IP hashes used to measure website use and protect the service.
2. How We Use Personal Information
- To create and administer customer accounts, respond to enquiries and reset passwords.
- To calculate, process, deliver and support orders, refunds, EFTs and purchase orders.
- To send transactional emails and, only where permitted, marketing communications.
- To prevent abuse, maintain audit records, secure the website and investigate payment or account problems.
- To understand website performance and improve products and services.
- To comply with accounting, tax, contractual and legal obligations.
3. Service Providers and Cross-Border Processing
We use contracted service providers where needed to operate the website, including Afrihost for hosting and PayFast for online payment processing. These providers process information under their own security and privacy controls. Some technical processing may occur outside South Africa where lawful safeguards apply.
4. Retention
Order and payment records are retained for the periods required by tax, accounting and consumer law. Customer accounts are retained while active or until a valid deletion request can be fulfilled. Enquiries and attachments are retained only as long as reasonably needed for the related business purpose. Pseudonymous website analytics are automatically removed after approximately 180 days.
5. Security
We use HTTPS, access controls, password hashing, protected server storage, prepared database queries, rate limiting, audit logging and encryption of payment-gateway credentials. No internet service can be guaranteed completely secure, and suspected incidents should be reported promptly.
6. Your Rights
You may request access to, correction of or deletion of personal information, object to certain processing, or raise a complaint. Some records cannot be deleted immediately where retention is legally required. Email popia@sgcorpsolutions.africa.
7. Information Officer
Contact the Information Officer at popia@sgcorpsolutions.africa. See also our full POPIA notice.