Skip to content

LEGAL

POPIA statement, South Africa

How Lunava meets the Protection of Personal Information Act, No. 4 of 2013, as an operator and as a responsible party, including transfer safeguards, security measures and Information Regulator notification.

Effective 16 August 2026

Our commitment

Lunava Digital Solutions FZCO ("Lunava") acknowledges and respects the Protection of Personal Information Act, No. 4 of 2013 ("POPIA") and the Regulations relating to the Protection of Personal Information, 2018. Where we process personal information of data subjects in South Africa, or process personal information in or from South Africa, we apply POPIA in full alongside the other data protection regimes set out in our data protection notice.

For South African engagements Lunava will ordinarily act as an operator processing personal information on behalf of, and on the documented instruction of, the responsible party. Where we determine the purpose and means ourselves, for example an enquiry submitted to us through this website, we act as the responsible party for that limited processing.

We use POPIA terminology in South African contracting. Where our other policies refer to a controller, processor, personal data or a data protection officer, read those as responsible party, operator, personal information and Information Officer respectively.

The eight conditions for lawful processing

We design our delivery, hosting and support processes to satisfy each condition in Chapter 3 of POPIA:

  • Accountability, Section 8. Named accountability for compliance sits with our Information Officer, and operator obligations are recorded in writing in every South African engagement.
  • Processing limitation, Sections 9 to 12. Personal information is processed lawfully, minimally and for a defined purpose, with a valid justification such as consent, contract performance, legal obligation or legitimate interest, and we collect directly from the data subject unless an exception in Section 12 applies.
  • Purpose specification, Sections 13 and 14. Purposes are recorded before collection and records are not retained longer than necessary unless retention is required by law, contract or a legitimate research purpose.
  • Further processing limitation, Section 15. Personal information is not used for a purpose incompatible with the one for which it was collected.
  • Information quality, Section 16. We take reasonably practicable steps to keep personal information complete, accurate, not misleading and up to date.
  • Openness, Sections 17 and 18. Processing is documented, and data subjects are told who is processing their information, why, and where it will go, including any cross-border transfer.
  • Security safeguards, Sections 19 to 22. Appropriate, reasonable technical and organisational measures are maintained, operators are bound in writing, and security compromises are notified.
  • Data subject participation, Sections 23 to 25. Data subjects may confirm what is held, request access, and request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained.

Special personal information and children

We do not process special personal information as defined in Section 26, including religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information or criminal behaviour, unless an authorisation in Sections 27 to 33 applies or the Information Regulator has granted authorisation.

Where an engagement genuinely requires special personal information or the personal information of children under Section 34, the lawful ground, additional safeguards, access restrictions and retention period are agreed with the responsible party in writing before any such information is processed.

Our commitments as an operator

In line with Sections 20 and 21, when acting as an operator Lunava commits in contract to:

  • Process personal information only with the knowledge or authorisation of the responsible party and strictly on documented instruction
  • Treat all personal information that comes to our knowledge as confidential, and impose equivalent confidentiality obligations on personnel and subcontractors
  • Maintain the security measures required by Section 19 and notify the responsible party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person
  • Engage further operators only under written terms no less protective than these, with prior notice to the responsible party
  • Assist the responsible party with data subject requests, Information Regulator enquiries and any required assessments
  • Return or securely destroy personal information at the end of the engagement, subject to any retention required by law
  • Enter into a written operator agreement, or the responsible party's own POPIA annexure, as part of the services contract

Security safeguards, Section 19

We identify reasonably foreseeable internal and external risks to personal information in our care, establish and maintain safeguards against those risks, verify that the safeguards are effectively implemented, and update them as new risks or deficiencies emerge. Our controls are described in the information security policy and include least-privilege access, multi-factor authentication for administrative access, encryption in transit and at rest, environment separation, logging and monitoring, and vulnerability management.

We have regard to generally accepted information security practices and to any professional rules or industry codes applicable to the responsible party's sector.

Notification of security compromises, Section 22

Where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by an unauthorised person, we notify the responsible party immediately so that the responsible party can notify the Information Regulator and affected data subjects as soon as reasonably possible after discovery.

Where Lunava is itself the responsible party, we notify the Information Regulator and the affected data subjects directly, in writing and in one of the forms permitted by Section 22(4), describing the possible consequences, the measures we intend to take, and what the data subject can do to mitigate the effect.

Cross-border transfers, Section 72

Lunava is registered in the United Arab Emirates and delivers globally, so personal information originating in South Africa may be processed outside the Republic. Transfers of personal information about a data subject to a third party in a foreign country are made only where at least one Section 72 ground is met:

  • The recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection upholding principles substantially similar to POPIA, including provisions on onward transfer
  • The data subject consents to the transfer
  • The transfer is necessary for the performance of a contract between the data subject and the responsible party, or for pre-contractual steps taken at the data subject's request
  • The transfer is for the benefit of the data subject and consent is not reasonably practicable, and if it were, the data subject would be likely to give it

Data residency for South African engagements

Where a South African client, tender or sector regulator requires personal information to remain within the Republic, or within a named jurisdiction, we can scope hosting, support access and backup locations accordingly as part of contracting. Raise the requirement before design begins so that residency is built into the architecture rather than retrofitted.

Our current subprocessors and their processing locations are published on the subprocessors page, and South African clients receive notice before a new subprocessor is introduced into their engagement.

Direct marketing, Section 69

We do not send unsolicited electronic direct marketing to data subjects. Where we communicate with a data subject about our services, it is because they contacted us, are an existing customer in respect of similar services, or have given consent, and every such communication identifies the sender and offers a simple way to opt out at no cost.

Data subject requests and complaints

South African data subjects may exercise their Section 23 to 25 rights by writing to support@lunavadigital.com, marked for the attention of the Information Officer, with enough detail for us to identify the information concerned. We acknowledge within five working days and respond within 30 days, using the prescribed forms where the request requires them. Requests for access to records are handled in line with the Promotion of Access to Information Act, No. 2 of 2000 (PAIA), and our PAIA manual is available to clients and data subjects on request.

Where the personal information sits inside a platform we operate for a responsible party, we forward the request to that responsible party without delay and support them in responding within the statutory period.

If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa. Contact details for the Regulator are published on its official website.

Tender and due diligence support

For South African public sector and enterprise procurement we can provide, on request and under the engagement contract, a signed POPIA operator agreement or completion of the responsible party's own POPIA annexure, our information security policy and control summary, the subprocessor list with processing locations, a completed vendor due diligence or supplier data protection questionnaire, and confirmation of Information Officer contact details.

To request any of these for a bid submission, email support@lunavadigital.com with the tender reference and the deadline.

Relationship to our other policies

This statement supplements, and does not replace, our privacy policy, data protection and international transfers notice, subprocessors list and information security policy. Where a South African engagement contract and this statement differ, the executed contract prevails.

We review this statement at least annually and whenever our processing, service providers or the applicable legal framework change materially.

All Lunava policies are listed in our legal centre.