info@raft.co.za

021 559 9600

3 Monte Vista Blvd, Monte Vista, Cape Town

}

Mon-Fri: 8:00 to 16:30

Privacy Policy

Home 9 Privacy Policy

Privacy Policy

Introduction

At RAFT, we are committed to safeguarding the privacy and personal information of every individual who interacts with our business—whether as a client, supplier, staff member, or website visitor. This Privacy Policy outlines how we collect, use, store, and protect your personal data in compliance with the Protection of Personal Information Act (POPIA) and other applicable data protection laws.

By using our website or engaging with our services, you consent to the practices described in this policy. We encourage you to read this document carefully to understand how we handle your personal information and what rights you have in relation to it.

If you have any questions, please contact us using the details at the end of this policy.

Who We Are

RAFT is a proudly South African professional services firm specialising in auditing, accounting, tax, and advisory solutions. Established in 2005 by a team of ex-Big 4 professionals, we serve clients across South Africa and the African continent.

We operate as a black-owned and predominantly black-managed company, with a strong commitment to empowerment, transformation, and sustainable value creation. Our offices are located in Cape Town, Gauteng, and KwaZulu-Natal, with national and cross-border project reach.

For the purposes of this Privacy Policy, RAFT is the “Responsible Party” in terms of POPIA and determines the purpose and means for processing your personal information.

What Information We Collect

We collect both personal and non-personal information through our website, forms, communications, and client engagements. The type of information we collect may include:

Personal Information

  • Full name

  • Email address

  • Contact number

  • Company name and position

  • Physical and/or postal address

  • Identity or registration numbers (where required for contractual or regulatory purposes)

Usage and Technical Data

  • IP address

  • Browser type and version

  • Device type and operating system

  • Pages visited and time spent on the site

  • Referring websites or search terms

Client or Service Data

Where applicable, we may collect additional data necessary to deliver auditing, advisory, or training services. This may include financial records, organisational information, employee details, or project-specific materials.

We only collect what is necessary, and where required, we will request consent or notify you in line with legal requirements.

How We Collect Personal Information

We collect personal information through various lawful and transparent means, including:

1. Direct Interactions

  • When you complete contact forms on our website

  • When you send us emails or request information

  • When you engage us for services or consultations

  • When you attend our training sessions or events

2. Automated Technologies

  • As you interact with our website, we may automatically collect technical data using cookies, server logs, and similar technologies (see Cookies and Tracking below for more detail)

3. Third-Party Sources

  • Referrals or introductions from professional networks

  • Public databases or government registries

  • Social media platforms or business directories

  • Partners or clients who lawfully share your data as part of a service engagement

We ensure that all data collected is done so fairly, with your knowledge and in accordance with applicable privacy legislation.

How We Use Your Information

You agree to use the website for lawful purposes only. You are prohibited from using the site to:

  • Commit or encourage a criminal offence

  • Transmit or distribute a virus, trojan, worm, or any other malicious software

  • Post or transmit any material that is defamatory, offensive, or otherwise objectionable

  • Attempt to interfere with the operation or functionality of the website

  • Gain unauthorised access to any part of the website, its systems, or user data

We reserve the right to restrict or terminate your access if we believe you have violated these terms.

How we use your information

We use the personal information we collect for specific and legitimate purposes, including:

  • To respond to your enquiries and provide you with the information, services, or support you request

  • To manage client relationships and deliver professional services, including audit, advisory, training, or consulting

  • To comply with legal or regulatory obligations, such as audit and tax requirements or reporting duties

  • To improve our website, communications, and service offerings, through usage analysis and user feedback

  • To send you relevant updates, invitations, or newsletters (only where you have opted in)

  • To ensure data security and fraud prevention, and to protect the integrity of our systems and business operations

We will never sell or rent your information to third parties. All use of personal information is aligned with our core values and applicable privacy laws, including POPIA.

Lawful Basis for Processing

RAFT processes personal information in accordance with South African data protection laws, including the Protection of Personal Information Act (POPIA). Our lawful bases for processing include:

  • Consent – where you have given us clear permission to process your personal data for a specific purpose (e.g., newsletter sign-up or callback request).

  • Contractual necessity – when processing is required to fulfil a contract or take steps at your request before entering into a contract.

  • Legal obligation – when we are required to process your data to comply with a legal or regulatory requirement.

  • Legitimate interest – when processing is necessary for our legitimate business interests, provided this does not override your fundamental rights and freedoms. Examples include internal administration, improving services, or preventing fraud.

You are entitled to withdraw your consent at any time, and to object to certain types of processing under applicable data protection law.

Disclosure of Information

RAFT does not sell, rent, or trade your personal information to third parties. However, we may disclose your information under the following circumstances:

  • Service Providers: To trusted third-party service providers who assist us in operating our website, managing communications, or delivering services—provided they are bound by confidentiality and data protection obligations.

  • Legal Requirements: If required by law, regulation, subpoena, or court order, or if we believe disclosure is necessary to protect our rights, investigate fraud, or respond to a government request.

  • Business Transfers: In the unlikely event of a merger, acquisition, or sale of company assets, your personal information may be part of the transferred assets, subject to confidentiality agreements.

  • Client-Specific Engagements: Where disclosures are part of the scope of work or deliverables agreed upon in the client engagement process.

In all cases, we ensure that disclosure is limited to what is necessary and that appropriate safeguards are in place to protect your information.

Protection of Your Data

RAFT takes the security of your personal information seriously. We implement and maintain appropriate technical and organisational measures to safeguard your data against accidental loss, theft, misuse, unauthorised access, disclosure, alteration, or destruction.

These measures include:

  • Secure servers and encrypted storage environments

  • Firewalls and intrusion detection systems

  • Access controls and role-based permissions

  • Staff training on data protection principles and confidentiality

  • Regular reviews and updates of our security practices

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. As such, we cannot guarantee absolute security but are committed to maintaining best practices at all times.

Retention of Personal Information

RAFT retains personal information only for as long as it is necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, tax, accounting, or reporting requirements.

We determine appropriate retention periods based on:

  • The nature and sensitivity of the information

  • The potential risk of harm from unauthorised use or disclosure

  • Applicable legal requirements

  • The purposes for which we process the information

Once the retention period expires, we securely delete, anonymise, or destroy your personal information unless we are legally required or entitled to retain it for longer.

Your Rights Under POPIA

Under the Protection of Personal Information Act (POPIA), you have the following rights regarding your personal information:

  • Right to Access – You may request access to the personal information RAFT holds about you.

  • Right to Correction or Deletion – You may request that we correct or delete your personal information if it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.

  • Right to Object to Processing – You may object, on reasonable grounds, to the processing of your personal information.

  • Right to Withdraw Consent – Where processing is based on your consent, you may withdraw your consent at any time.

  • Right to Lodge a Complaint – If you believe your rights have been violated, you may lodge a complaint with the Information Regulator at https://www.justice.gov.za/inforeg/.

To exercise any of these rights, please contact us using the details provided at the end of this policy.

Use of Cookies

RAFT’s website uses cookies to enhance user experience, analyze site traffic, and improve our services. Cookies are small text files stored on your device that help us understand how visitors interact with our website.

Types of cookies we may use include:

  • Essential Cookies – Necessary for the functioning of our site (e.g., navigation or access to secure areas).

  • Analytical/Performance Cookies – Allow us to recognise and count the number of visitors and how they move through the site.

  • Functionality Cookies – Enable the website to remember choices you make and provide enhanced, more personal features.

By using our website, you consent to the use of cookies in accordance with this policy. You may modify your browser settings to decline cookies; however, some parts of the site may not function properly as a result.

Third-Party Links and Content

Our website may include links to external websites or services that are not operated by RAFT. Please note that once you leave our site, we do not have control over how your information is collected, stored, or used by third parties.

We are not responsible for the privacy practices, content, or terms and conditions of these third-party sites. We recommend that you review their respective privacy policies before providing any personal information.

RAFT may also use trusted third-party service providers to assist with website functionality, analytics, or marketing. These service providers are contractually obligated to protect your data and use it only for the specific purposes we define.

International Transfers

RAFT does not routinely transfer personal information across borders. However, in cases where international transfers of data do occur—such as when using cloud-based services hosted in other jurisdictions—we take all reasonable steps to ensure that your personal information is afforded an equivalent level of protection in line with South Africa’s Protection of Personal Information Act (POPIA).

Any such transfers will be conducted only where:

  • The recipient country or entity provides adequate data protection standards;

  • You have provided explicit consent;

  • It is necessary for the performance of a contract with you;

  • Or it is required by law.

We ensure that our service providers and partners implement appropriate safeguards, including standard contractual clauses or data processing agreements, to protect your privacy rights.

Children’s Privacy

RAFT’s services and website are not directed toward children or individuals under the age of 18. We do not knowingly collect, process, or store personal information from minors.

If it comes to our attention that we have inadvertently collected personal information from a child without verified parental consent, we will take immediate steps to delete such information from our systems.

If you believe that a child has provided us with personal data, please contact us using the details provided in the Contact Us section.

Updates to This Policy

RAFT may update or revise this Privacy Policy from time to time to reflect changes in legal obligations, business practices, or our services. When changes are made, the updated version will be posted on this website with the revised “Last Updated” date at the top of the page.

We encourage you to review this policy periodically to stay informed about how we are protecting your personal information. Continued use of our website or services after changes are published will indicate your acceptance of those changes.

Use from Outside South Africa & Compliance with International Privacy Laws

RAFT is a South African-based firm and operates primarily under the Protection of Personal Information Act (POPIA). However, we acknowledge that individuals outside of South Africa may access our website or engage with our services.

By using this website from outside South Africa, you acknowledge and agree that your information may be transferred to, processed, and stored in South Africa, where data protection laws may differ from those of your jurisdiction.

RAFT is committed to upholding the principles of lawful data processing and takes reasonable steps to ensure your personal information is handled securely and in accordance with applicable data protection regulations, including but not limited to the General Data Protection Regulation (GDPR) where relevant.

If you are a resident of a country with privacy legislation that offers additional rights or protections, we will make every reasonable effort to honour those rights, where applicable and within the framework of South African law.

Governing Law

This Privacy Policy, and any dispute or claim arising from or related to it, shall be governed by and construed in accordance with the laws of the Republic of South Africa.

By accessing this website or engaging with RAFT’s services, you consent to the jurisdiction of the South African courts in resolving any disputes that may arise in connection with your use of our website, services, or this Privacy Policy.

If any provision within this policy is found to be unenforceable or invalid under South African law, the remaining provisions will continue in full force and effect.

Contact Information

If you have any questions, concerns, or feedback regarding these Terms and Conditions, our services, or any aspect of this website, you are welcome to reach out to us:

RAFT Consulting (Pty) Ltd
Address: 3 Monte Vista Blvd, Monte Vista, Cape Town, 7460
Phone: 021 559 9600
Email: info@raft.co.za

For data protection queries, you may also contact our Information Officer at the same address or email.