Privacy Policy
What we collect, why we collect it, who else sees it, and how long we keep it. In plain language.
The Short Version
This policy explains how Wholistic Business Solutions (Pty) Ltd (registration 2025/872862/07) handles your personal information. We are the responsible party for that information under the Protection of Personal Information Act, 2013 (POPIA).
What We Collect
When you contact us, ask about a domain name, or request early access to Wholly Backup – your name, business name, email address, phone number, the size of your business, and whatever you write in the message.
When you complete our needs questionnaire – the above, plus information about how your business currently works: what email and software you use, how many people and computers you have, how you back up your data, what security you have in place, and who looks after your IT. Some of this describes weaknesses in your setup, which is exactly why we treat it carefully. See How we protect it below.
Automatically – standard technical information your browser sends, and security information collected by Cloudflare to protect our site from attacks and automated abuse.
You choose what to tell us. Every technical question on our questionnaire has a "not sure" option and none of them is compulsory.
Why We Collect It
- To reply to you, and to prepare a written proposal or quote you asked for
- To work out what you actually need, so we don't propose something unsuitable
- To obtain pricing from suppliers where a quote depends on it
- To provide and support the services you buy from us
- To meet our own legal, tax and record-keeping obligations
We do not use your information for automated decision-making, and we do not build advertising profiles.
Who Else Sees It
Two different things happen here and we think it's clearer to separate them.
Service providers who process information for us
These are our operators under POPIA. They handle information on our instructions and are contractually bound to protect it. They do not get to use it for their own purposes.
- Cloudflare – hosts our website, protects it from attacks, and filters automated abuse
- Mailgun – delivers email from our website and forms. Mailgun's European infrastructure is used, which means this information is processed in the European Union. The EU has data-protection laws that meet the standard POPIA requires for transfers outside South Africa
- Microsoft – our own email, files and business systems
Suppliers we ask for pricing
To quote you accurately we sometimes have to ask a distributor or vendor what something costs. That is a genuine disclosure to a third party and we would rather describe it honestly than claim we never share anything.
When we do it, we send only what is needed to get that price – for example the number and type of software licences. We do not send your security answers, and we do not send anything describing weaknesses in your setup. Where a supplier needs to know who the client is, we tell you first.
We also disclose information where the law requires it, or to protect our rights or someone's safety.
We never sell your personal information.
How We Protect It, and How Long We Keep It
Our systems are protected by encryption in transit and at rest, restricted access, and encrypted backups. Access is limited to the people who need it to do the work.
If a security compromise ever affects your personal information, POPIA obliges us to notify the Information Regulator and to notify you as soon as reasonably possible. We will tell you what happened, what information was involved, and what you can do about it.
How long we keep it
- If you don't become a client – we delete your enquiry and questionnaire answers six months after you last contacted us
- If you become a client – we keep what we need for as long as we work together, and afterwards only for as long as the law requires us to (generally five years for tax and company records)
- You can ask us to delete your information sooner. See below.
Your Rights
Under POPIA you may:
- Ask what personal information we hold about you, and get a copy
- Ask us to correct anything that is wrong or incomplete
- Ask us to delete information we no longer have a reason to keep
- Object to how we are using your information
- Withdraw consent where our use depends on it
- Complain to the Information Regulator
Email info@wholistic.group and we will respond. There is no charge for asking, and asking will not affect how we deal with you.
Cookies
Our website uses only what it needs to work and to stay secure, including Cloudflare's protection against automated abuse. We do not use advertising or tracking cookies. If that changes, this page will change with it and we will ask your permission first.
Who to Contact
Our Information Officer
Our Information Officer is Rudolf Eksteen, Founder and CEO, registered with the Information Regulator of South Africa.
Email info@wholistic.group
Phone +27 21 300 1184
The Colosseum, Foyer 3, 1st Floor, Century Way, Century City, Cape Town, 7441
The Information Regulator
If you are not satisfied with how we have handled your information, you may complain to the Information Regulator of South Africa.
inforegulator.org.za
complaints.IR@justice.gov.za
Changes to this policy
If we change how we handle your information we will update this page and change the date at the top. Where a change is significant and affects information you have already given us, we will tell you directly.
Questions About Any of This?
Ask us. We would rather explain it than have you wonder.