POPIA Compliant
Effective Date: September 2026
1. Introduction & Statutory Framework
Web Design Hosting (Pty) Ltd ("we", "us", or "our"), operating webdesignhosting.co.za, is committed to safeguarding the privacy and personal data of our clients, website visitors, and service subscribers.
This Privacy Policy sets out how we collect, process, retain, and protect personal information in compliance with the Protection of Personal Information Act No. 4 of 2013 (POPIA), the Electronic Communications and Transactions Act No. 25 of 2002 (ECTA), and applicable international data protection standards.
By using our website, registering domain names, or contracting our hosting, web design, or software licensing services, you acknowledge and agree to the practices outlined in this policy.
2. Personal Information We Collect
We only collect personal data that is adequate, relevant, and necessary to provision web services, establish accounts, process billings, and fulfill our contractual obligations:
- Identity Information: Full legal names, company names, business registration numbers, and VAT identification numbers.
- Contact Information: Physical and postal addresses, direct telephone numbers, mobile numbers, and primary contact email addresses.
- Account Credentials: WHMCS client portal usernames, hashed passwords, support PINs, and cPanel administrative links.
- Technical & Connectivity Logs: Internet Protocol (IP) addresses, browser type, operating systems, referring URLs, SSH/FTP connection logs, and firewall audit trails.
- Service Content: Files, databases, emails, and web assets uploaded directly by you to your hosted storage containers or email inboxes.
3. Lawful Basis & Purpose of Processing
Under Section 11 of POPIA, we process personal information strictly under legitimate legal grounds, including contractual necessity and legal compliance:
- Contractual Performance: Provisioning web hosting accounts, setting up MariaDB/MySQL databases, establishing OX Mail inboxes, and configuring DNS records.
- Billing & Account Administration: Issuing recurring invoices, processing gateway transactions, and sending automated renewal notices.
- Technical Support & Infrastructure Maintenance: Resolving service tickets, server health monitoring, investigating abuse complaints, and mitigating security threats.
- Legal & Regulatory Compliance: Retaining financial transaction registers for statutory tax reconciliation with the South African Revenue Service (SARS) and responding to lawful requests from law enforcement agencies.
4. Domain Registries & WHOIS Disclosures
Important Registry Disclosure: When you register or transfer a top-level domain (including .co.za, .com, or .org.za), central registry guidelines mandated by the ZACR (ZA Central Registry) and ICANN require specific registrant contact information to be submitted directly to registry operators.
This information—such as the registrant name, telephone number, physical address, and administrative email address—may be accessible on publicly searchable WHOIS databases or through authoritative registry lookup interfaces. Where supported by individual registries, we apply automated WHOIS privacy masking to redact sensitive residential details from public display.
5. Payment Gateways & Banking Security
We do not store full credit card numbers, debit card PINs, or CVV/CVC security codes on our local hosting servers.
All online payments are handled directly by PCI-DSS Level 1 compliant South African payment processors, including PayFast, Yoco, Ozow, and Paystack. These gateways utilize encrypted 256-bit SSL connections and tokenized payment architectures. We retain only non-sensitive transaction tokens, gateway references, and payment timestamps required for accounting and invoice reconciliation.
6. Server Infrastructure & Data Security
We employ layered physical, electronic, and administrative safeguards to protect your personal data from unauthorized access, accidental alteration, loss, or destruction:
- CloudLinux LVE Isolation: Every hosting tenant is isolated in its own virtual environment, preventing cross-account script access.
- Automated Threat Defense: Real-time heuristic scanning with Imunify360, CSF firewalls, and brute-force mitigation on all authentication endpoints.
- Transport Encryption: Compulsory HTTPS encryption across all client portal dashboards and automatic SSL certificates provided on hosted domains.
- Nightly Off-Site Snapshots: Encrypted automated backups maintained in geographically separated data center facilities to ensure rapid disaster recovery.
7. Cookies, Web Analytics & Security Scripts
Our site uses first-party cookies to manage active shopping cart sessions, authenticate client logins, and store cookie consent preferences. We also utilize:
- Google Analytics: We collect aggregated, anonymized analytical data (page visits, session lengths, browser models) to improve site navigation and performance.
- Google reCAPTCHA: Contact forms and checkout endpoints utilize Google reCAPTCHA v2 to defend against automated spam, bot brute-force attacks, and abusive submission scripts.
You may choose to disable cookies through your browser settings; however, disabling session cookies may prevent you from adding items to your cart or logging into your WHMCS client area.
8. Your Statutory Rights (POPIA Sections 23–25)
As a data subject under the Protection of Personal Information Act, you hold the following rights regarding the personal data we maintain:
- Right of Access: You may request confirmation of whether we hold personal information about you, along with a description of the data.
- Right to Rectification: You may request the correction, updating, or completion of inaccurate, incomplete, or outdated personal information via your client portal.
- Right to Erasure (De-registration): You may request the deletion or destruction of personal data that we are no longer authorized to retain, subject to statutory accounting requirements (such as SARS 5-year invoice retention rules).
- Right to Object: You hold the right to object to the processing of personal data for direct marketing purposes at any time.
9. Information Officer Contact Details
In accordance with Section 55 of POPIA, Web Design Hosting has appointed an Information Officer responsible for ensuring regulatory adherence. If you have questions regarding this policy or wish to submit a formal data access or deletion request:
Registered Physical Address
Web Design Hosting South Africa
334 Lake Drive, Rosetta
KwaZulu-Natal, 3301, South Africa
If you are dissatisfied with our resolution of your data inquiry, you have the right to lodge a formal complaint with the South African Information Regulator at inforegulator.org.za.