Skip to content
TheoSec

//Legal

Privacy Policy

Last updated: 9 August 2026

Theosec (Pty) Ltd ("Theosec", "we", "us") is committed to protecting the privacy of our clients, prospective clients and website visitors. This policy explains what personal information we collect, why we collect it, and what rights you have over it.

We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") of South Africa. Where we provide services to clients established in the European Economic Area or the United Kingdom, we also process personal data in accordance with the General Data Protection Regulation ("GDPR").

1. Who we are

Theosec (Pty) Ltd is a private company registered in South Africa and is the responsible party (POPIA) and data controller (GDPR) for the personal information described in this policy.

  • Registered entity: Theosec (Pty) Ltd
  • Registration number: [COMPANY REGISTRATION NUMBER]
  • Registered address: [REGISTERED ADDRESS]
  • Information Officer: Daniel Scragg
  • Contact: daniel@theosec.com

2. Information we collect

2.1 Information you give us

When you contact us, request a briefing, or engage our services, we collect the contact and business information you choose to provide — typically your name, email address, telephone number, employer and job title, and the content of your enquiry.

2.2 Information collected during an engagement

Security testing may involve encountering personal information held within your systems, or information about your personnel gathered from publicly available sources during reconnaissance and social engineering activities. This information is:

  • collected only within the scope agreed in writing with you;
  • processed solely for the purpose of delivering the engagement and reporting our findings to you;
  • held in encrypted storage, segregated per client, and never combined with information from other engagements;
  • never used to train models, enrich marketing databases, or for any purpose beyond the engagement.

Where we conduct social engineering or phishing simulation testing, we record only whether an interaction occurred. Passwords and credentials submitted to a simulation are never stored.

2.3 Website information

This website does not use advertising cookies, analytics cookies or third-party tracking. Our hosting provider processes standard server logs, which may include IP addresses, for security and operational purposes. Web fonts are served by Google Fonts, which may receive your IP address when the page loads.

3. Why we process it, and on what basis

  • To respond to enquiries — on the basis of your consent, or steps taken at your request prior to entering a contract.
  • To deliver contracted services — on the basis of performance of a contract with you.
  • To meet legal and regulatory obligations — including tax, accounting and company law requirements.
  • For legitimate business interests — including securing our own systems and maintaining engagement records for professional liability purposes, where these interests are not overridden by your rights.

We do not sell personal information, and we do not use it for automated decision-making or profiling.

4. Sharing

We do not share client information with third parties for marketing. Personal information may be shared only with:

  • service providers who process information on our behalf under written agreement (for example, encrypted cloud storage and email providers);
  • professional advisers, such as legal or accounting advisers, where necessary;
  • law enforcement or regulators where we are legally required to do so.

We do not name clients publicly, publish client logos, or reference engagement findings — including in anonymised form — without your express written permission.

5. Cross-border transfers

We deliver services internationally, and some of our service providers are located outside South Africa. Where personal information is transferred across borders, we ensure an appropriate level of protection through contractual safeguards, in line with section 72 of POPIA and, where the GDPR applies, Chapter V of that regulation.

6. Retention

  • Enquiries that do not lead to engagement — deleted within 12 months.
  • Engagement data and reports — retained for the period agreed in the engagement contract, then securely destroyed. Raw testing artefacts are destroyed following delivery unless you ask us to retain them.
  • Contractual and financial records — retained for the period required by South African tax and company law.

7. Security

Given the nature of our work, client information is treated as highly sensitive by default. We apply full-disk and at-rest encryption, multi-factor authentication on all accounts, per-client data segregation, least-privilege access, and secure destruction of engagement artefacts. All engagements are conducted under a mutual non-disclosure agreement.

8. Your rights

Subject to applicable law, you have the right to:

  • request access to the personal information we hold about you;
  • request correction or deletion of that information;
  • object to processing, or request that we restrict it;
  • request a portable copy of information you provided to us;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority.

To exercise any of these rights, contact daniel@theosec.com. We will respond within the timeframes required by applicable law.

If you are not satisfied with our response, you may complain to the Information Regulator of South Africa (inforegulator.org.za). If the GDPR applies to your personal data, you may also complain to the supervisory authority in your country of residence.

9. Changes

We may update this policy from time to time. The date at the top of this page reflects the most recent revision. Material changes affecting active clients will be communicated directly.

10. Contact

Questions about this policy, or about how we handle information, can be sent to daniel@theosec.com or+27 63 484 1051.