PRIVACY POLICY • POPIA COMPLIANT • LAST UPDATED 10 JAN 2026 • NO TRACKING ADS

Privacy Policy - POPIA Compliant

What we collect (forms, calls to +27 76 948 9154, WhatsApp, RMM), why, how we protect SA SMEs 5-50 staff, retention, your rights. No tracking ads, SA-hosted backups, one invoice.

RESPONSIBLE PARTY
NextGrid Technologies (Pty) Ltd
Pretoria, Gauteng, SA — On-site Pretoria, Midrand, Centurion, Johannesburg | Anywhere else - Remote
INFORMATION OFFICER
Clem Chikanya
info@nextgridtechnologies.co.za+27 76 948 9154
WhatsApp wa.me/27769489154

1. What we collect

  • Forms: Name, company, phone, work email for R950 Check booking and PDF download email capture (1 email/month). Stored via formsubmit.co + encrypted local backup.
  • Calls: +27 76 948 9154 call logs (number, duration) for support + POPIA accountability – not call recordings unless you consent.
  • WhatsApp: Messages to wa.me/27769489154 – we keep for ticket context, delete after 2yrs or on request.
  • RMM / Monitoring: Device serials, BitLocker keys escrowed in Entra ID, Secure Score, audit logs – only for clients under MSA, Sec 20 Operator.
  • Website: IP, browser, pages, no tracking ads, no Facebook Pixel, no Google remarketing. Only gtag for GA4 + Clarity for UX.

2. Why we collect – lawful basis Sec 11

  • Contract – to deliver M365 R290 / R450 Secure, hardware, R950 Check, backup R45/user.
  • Legitimate Interest – 24/7 monitoring (inbox rule creation, impossible travel) to protect you from BEC, ransomware – avg 4.2 critical issues found.
  • Legal – SARS 5yr, audit logs 1yr+, security incidents 5yrs.
  • Consent – marketing opt-in checkbox not pre-ticked, or existing client opt-out for similar services.

3. How we protect – Sec 19 measures

Same controls from R950 Check and case studies: MFA number matching (61% audits missing), block legacy auth, Conditional Access SA only, Safe Links click-time, Safe Attachments sandbox, external banner [EXTERNAL] ON, DMARC p=reject + SPF + DKIM + impersonation protection (stopped R87k CEO fraud), inbox rule audit (18% have hidden Gmail rule), BitLocker enforced + keys escrowed, Intune compliance, Defender tamper + ASR, 3-2-1 immutable backup SA DC + real restore test monthly, FortiGate + Mikrotik hardening RDP 3389 blocked (34% audits), UPS load-shedding resilient.

14. Contact for privacy queries — real human

NextGrid
NextGrid Technologies (Pty) Ltd
Information Officer: Clem Chikanya
📍Pretoria, Gauteng, SA — On-site Pretoria, Midrand, Centurion, Johannesburg | Anywhere else - Remote, remote across SA
Escalation — Regulator
If unresolved after 30 days: Information Regulator SA — complaints.IR@justice.gov.za, 012 406 4818, JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2017, inforegulator.org.za, Form 5.