1. Who we are
CostusWorx (Pty) Ltd (“CostusWorx”, “we”, “us”), registration number 2026/431828/07, is a technology advisory and software development business registered in South Africa, operating from Centurion, Gauteng. We are the responsible party for the personal information described in this notice, as that term is used in the Protection of Personal Information Act 4 of 2013 (“POPIA”).
This notice covers costusworx.co.za and the enquiries we receive through it. It does not cover the separate applications we build and operate for clients — those systems are governed by their own agreements with the organisations that own the data in them.
2. What we collect
We collect only what you choose to send us. There is no tracking on this website.
| Information | When we get it | Why we need it |
|---|---|---|
| Name | You submit the audit request form | To address you correctly |
| Company name | Audit request form | To understand the context before we reply |
| Email address | Audit request form | To respond to your enquiry |
| Phone number (optional) | Audit request form | To call you if you prefer that |
| What you tell us | The free-text field | To prepare a useful first conversation |
| Email or call content | You contact us directly | To answer you and keep a record of the discussion |
| Server log entries | Automatically, by the web server | Security and fault diagnosis — see section 4 |
We do not collect special personal information as defined in POPIA section 26, and we do not knowingly collect information about children.
3. What we do not do
This is worth stating plainly, because most privacy notices bury it:
- No analytics. This site runs no Google Analytics, no Meta pixel, no heatmap or session-recording tool.
- No advertising or profiling. We do not build profiles, we do not re-target you, and we make no automated decisions about you.
- No third-party scripts. Every asset on this site is served from our own domain. Your browser makes no request to any other company when you load this page.
- No selling or renting. We do not sell, rent or trade personal information to anyone, for any purpose.
- No cookie tracking. We set no advertising or analytics cookies.
4. Server logs
Our hosting provider’s web server records standard technical entries for every request: IP address, date and time, the page requested, the referring page, and your browser’s user-agent string. This happens at the infrastructure level and is normal for any website.
We use these logs only to keep the site available and secure — diagnosing errors, and investigating abuse or attack. We do not use them to identify individual visitors or to build any profile. They are retained on a short rolling window by the host and are not exported, combined with form submissions, or shared.
5. Our legal basis for processing
Under POPIA section 11, we rely on the following justifications:
| Processing | Justification (POPIA s11) |
|---|---|
| Responding to your enquiry or audit request | Your consent, given when you submit the form, and steps taken at your request before entering a contract |
| Keeping a record of the engagement | Our legitimate interests in running and evidencing our business |
| Server logs | Our legitimate interests in the security and availability of the service |
| Retaining records after a project | Compliance with an obligation imposed by law, where applicable |
Where we rely on consent, you may withdraw it at any time — see section 9. Withdrawing consent does not affect processing already carried out.
6. Who else sees it
We keep the list of third parties deliberately short, and we maintain a formal sub-processor register as part of our POPIA governance.
| Party | Role | Location | Cross-border? |
|---|---|---|---|
| Afrihost (Pty) Ltd | Web and email hosting | South Africa | No |
Information submitted through this website is hosted in South Africa and is not transferred outside the Republic. If that ever changes, we will update this notice and comply with POPIA section 72 before any transfer takes place.
We may also disclose personal information where we are legally compelled to do so, or where it is necessary to establish, exercise or defend a legal claim.
7. How long we keep it
In accordance with POPIA section 14, we do not keep personal information for longer than is necessary for the purpose it was collected for.
| Record | Retention |
|---|---|
| Enquiry that does not become an engagement | 24 months from last contact, then deleted |
| Enquiry that becomes a client engagement | Duration of the engagement, then per the applicable contract and statutory record-keeping obligations |
| Email correspondence | Reviewed annually; deleted when no longer needed |
| Server logs | Short rolling window set by the host |
You can ask us to delete your information sooner — see section 9.
8. How we protect it
We apply the same standards to our own data that we contractually require of any developer who works on our clients’ systems:
- Encryption in transit using TLS 1.2 or higher across the whole site, enforced by HSTS.
- Encryption at rest to AES-256 where information is stored in a database.
- Access on a least-privilege basis, to named individuals only, with multi-factor authentication where the platform supports it.
- Secure development practice aligned to the OWASP Top 10, with security headers set at the web server.
- A documented breach response procedure — see section 10.
No system is perfectly secure, and we will not pretend otherwise. What we commit to is proportionate control and honest disclosure if something goes wrong.
9. Your rights, and how to use them
POPIA gives you the following rights over your personal information. You may exercise any of them by emailing bruce@costusworx.co.za with “POPIA request” in the subject line.
- Access — ask what personal information we hold about you.
- Correction — ask us to fix anything inaccurate or incomplete.
- Deletion — ask us to delete information we no longer have grounds to keep.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, for anything we do on the basis of consent.
- Complain — to us, and to the Information Regulator if we do not resolve it.
We will acknowledge your request within 5 business days and respond substantively as soon as reasonably possible. We may need to verify your identity first. There is no charge for a reasonable request.
10. If something goes wrong
If a security compromise affects your personal information, we will notify the Information Regulator and, where the law requires it, you directly — as soon as reasonably possible after establishing what happened, in terms of POPIA section 22. Our internal procedure requires a breach to be escalated within 24 hours of discovery, contained, and documented with a root cause analysis.
11. Contact us, and the Regulator
CostusWorx — Information Officer
Bruce Lowe, Information Officer
CostusWorx (Pty) Ltd
858 Carnoustie Crescent, Copperleaf Golf Estate, Centurion, Gauteng, 0157
bruce@costusworx.co.za · +27 82 650 9098
Information Regulator (South Africa)
If you are not satisfied with how we have handled your information or your request, you may
lodge a complaint directly with the Regulator.
inforegulator.org.za
Complaints: inforeg@justice.gov.za
12. Changes to this notice
We will update this notice when our practices change or when the law requires it. The version number and effective date at the top of this page always reflect the current version. Material changes will be summarised here rather than slipped in silently.
Applicable law. This notice is governed by the law of the Republic of South Africa, and specifically the Protection of Personal Information Act 4 of 2013 and its Regulations (GNR 1383 of 14 December 2018), read with the Electronic Communications and Transactions Act 25 of 2002 and the Cybercrimes Act 19 of 2020.
