Legal

Privacy Policy

Last updated: 10 September 2026

1. Who we are and how to reach us

VDM Digital (Pty) Ltd (registration number 2026/179981/07) is the responsible party under the Protection of Personal Information Act 4 of 2013 ("POPIA"), and the controller under the EU and UK General Data Protection Regulation ("GDPR"), for the personal information described in this policy.

  • Address: 13 Jigger Avenue, Somerset West, Western Cape, 7130, South Africa
  • Information Officer: Erik van der Merwe, erik@vdmdigital.io
  • Deputy Information Officer: Nico van der Merwe
  • General privacy contact: erik@vdmdigital.io
  • Telephone: Our telephone number is published in the current version of this document on our website, and is available on request by email.

This policy covers vdmdigital.io and the services we provide from it, including the client and staff area behind the sign-in door. Where we build or run a system for a client, that client is usually the responsible party for the data in it and we act as their operator (POPIA) or processor (GDPR) — see clause 9.

2. The short version

  • We collect very little, and we do not sell any of it.
  • Our contact form does not send anything to a server of ours. It opens your email client with the message pre-filled. Nothing is stored on our side until you press send in your own mail app.
  • Our website analytics are first-party and cookie-free. No Google Analytics, no advertising pixels, no third-party tracking script of any kind.
  • Card details never reach us. Our payment processor handles them.
  • You can ask us what we hold, ask us to fix it, and ask us to delete it.

3. What we collect, why, and on what legal basis

3.1 When you contact us

Our contact form collects your name, email address, contact number, company name, budget range and your message, and hands them to your own email application through a mailto: link. We receive them only when you send that email, and then they sit in our vdmdigital.io mailbox like any other email.

  • Purpose: to answer you and to quote for the work.
  • Legal basis: POPIA section 11(1)(b) — steps at your request before entering a contract. GDPR Article 6(1)(b), same.
  • Retention: for the life of the enquiry and, if it becomes an engagement, for the retention period in clause 7.

3.2 When you become a client

To run an engagement and to invoice you, we hold: contact names, email addresses, telephone numbers, billing entity, company registration and VAT number where applicable, billing address, invoice and payment records, project correspondence, and any credentials you give us for systems we manage.

  • Purpose: performing the contract, invoicing, support, and record keeping.
  • Legal basis: POPIA sections 11(1)(a), (b) and (c); GDPR Article 6(1)(b) and (c).
  • Retention: clause 7.

3.3 When you pay us

Payments are processed by our payment processors. We never see, receive or store your full card number, CVV or PIN. Those are entered on the processor's own hosted, PCI-DSS-compliant page.

What we do receive and keep is: the amount, the currency, the date, whether it succeeded or failed, the reference, a transaction ID, the payment method type, and the last four digits and card brand where the processor supplies them.

  • Purpose: taking payment, reconciling accounts, refunds and chargebacks, fraud prevention, and the tax records we are legally obliged to keep.
  • Legal basis: POPIA sections 11(1)(b) and (c); GDPR Article 6(1)(b), (c) and (f).
  • Retention: financial records are kept for five years as required by the Companies Act 71 of 2008 and the Tax Administration Act 28 of 2011. We cannot delete them on request before then.

3.4 When you visit the site

Our analytics are our own, run on our own infrastructure. For each page view we record: the path you visited, the referring site (external referrers only — internal navigation is not recorded), a short browser and OS label such as "Chrome / Windows", a device class (one of mobile, tablet or desktop — not your screen size), any campaign tags in the link you arrived on (the utm_ parameters in the address, if a link carried them), whether your anonymous ID already existed (so we can count returning visits), how long the server took to answer, a random anonymous ID stored in your browser, a random session ID, and the timestamp.

When you leave a page, we record one more event for it: roughly how long the page was on screen, how far down it you scrolled (as a percentage), and how long the page took to load in your browser. Nothing in that event identifies you either.

We do not record your IP address in that table, we do not fingerprint your device, and we use no cookies for analytics. We deliberately do not record your screen size, pixel density, time zone or language — each is harmless on its own, and together they are the beginning of a fingerprint.

We do not collect analytics at all if:

  • Your browser sends Do Not Track or a Global Privacy Control signal;
  • You look like a bot or an automated browser; or
  • You are signed in to our admin area (staff activity is deliberately excluded).
  • Purpose: understanding which pages are useful, so we can improve the site.
  • Legal basis: POPIA section 11(1)(f) — our legitimate interest in running and improving our own website, balanced against a design that collects no identifiers we could tie back to you. GDPR Article 6(1)(f).
  • Retention: clause 7.

The identifiers live in your browser's localStorage and sessionStorage, not in cookies. See our Cookie and Local Storage Policy for the full list and how to clear them.

3.5 When you record a video testimonial

If a client sends you a private testimonial link, that page collects: your video recording, your name, your business name, your role, optionally your email address, an optional 1-to-5 star rating, and your explicit consent.

  • Consent is required and enforced in the database — a submission without it is rejected outright.
  • The video lands in a private store first. Nothing is published until a VDM Digital administrator reviews and approves it.
  • Only on approval is the video copied to a public location and shown on our site.
  • Your email address is never published and is deliberately excluded from the public feed.
  • Legal basis: consent — POPIA section 11(1)(a), GDPR Article 6(1)(a).
  • Withdrawing consent: email erik@vdmdigital.io and we will unpublish and delete the recording. Withdrawal does not affect the lawfulness of what we did before you withdrew.

3.6 When you sign in

For anyone with an account in our client and staff area we hold an email address, a hashed password, a role, session tokens and sign-in timestamps. Passwords are hashed by our authentication provider and are not visible to us.

  • Legal basis: performance of the contract and our legitimate interest in securing the system.

3.7 What we do not collect

We do not knowingly collect special personal information under POPIA section 26 (race, health, religion, biometrics, political or trade union affiliation, criminal behaviour) or GDPR Article 9 special categories, and we do not ask for it. We do not collect information from children under 18 knowingly. If you believe a child has given us personal information, tell us and we will delete it.

4. Who we share it with

We do not sell, rent or trade personal information. We share it only with:

4.1 Operators and sub-processors

  • Supabase — database, authentication and file storage for our application data. Processes client records, invoices, testimonial submissions and analytics events.
  • Hetzner Online GmbH — the server that hosts vdmdigital.io, located in Helsinki, Finland.
  • Google (Google Workspace) — our business email on the vdmdigital.io domain.
  • Paystack — our South African payment processor for card and instant-EFT payments in ZAR. See their privacy policy.
  • Stripe — pre-authorised for future international card payments. This is not live yet. Until we say otherwise on this page, every payment to us is processed in ZAR by Paystack or made by EFT. See their privacy policy.
  • First National Bank — our bank, for EFT payments and reconciliation.
  • Wise — used for some international receipts.

Each is bound by a written agreement, or by its own published terms, to process personal information only on our instructions and to secure it, as POPIA sections 20 and 21 and GDPR Article 28 require. This list is kept current; ask us for the version in force on a given date.

4.2 Other recipients

  • Professional advisers — our accountant, auditor or attorney, under a duty of confidentiality.
  • Authorities — where we are legally compelled, and only to the extent compelled.
  • A buyer — if the business is sold or merged, subject to this policy continuing to apply.

5. Sending information outside South Africa

Our server is in Finland and several of our processors are outside South Africa. That makes these cross-border transfers under POPIA section 72.

We rely on:

  • Section 72(1)(a) — the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection. Finland and the EU are covered by the GDPR, which is at least as protective as POPIA; our processor agreements carry the equivalent obligations.
  • Section 72(1)(b) — where you have consented to the transfer.
  • Section 72(1)(c) — where the transfer is necessary to perform a contract with you.

For personal information covered by the GDPR that we move out of the EEA or the UK, we rely on Standard Contractual Clauses or an adequacy decision, whichever applies to that processor.

6. How we protect it

  • Everything is served over TLS. HTTP Strict Transport Security is enforced.
  • A strict Content Security Policy blocks any script we did not ship, which is why there is no third-party tracker on this site and cannot casually become one.
  • Database access is controlled by row-level security: an account with no explicitly granted role gets nothing, and creating an account grants no access by itself.
  • Testimonial video uploads land in a private store, are rate limited, and are constrained to a fixed path so an anonymous caller cannot write arbitrary files.
  • Administrator accounts are created by us, not self-registered. There is no public sign-up.
  • Access is limited to the people who need it, and staff activity is excluded from analytics rather than merged into it.

No system is perfectly secure and we do not claim ours is.

7. How long we keep it

  • Enquiries that do not become work: up to 24 months, then deleted.
  • Client records and correspondence: for the engagement, plus 5 years after it ends.
  • Financial records — invoices, payments, refunds: 5 years, as the Companies Act and the Tax Administration Act require. This period overrides a deletion request.
  • Website analytics events: up to 24 months.
  • Testimonial recordings: until you withdraw consent, or until the client relationship ends and we no longer need them.
  • Account records: for the life of the account, plus 12 months.

After the applicable period we delete or de-identify the information.

8. Your rights

Under POPIA (sections 5, 23, 24 and 25) and, where it applies to you, the GDPR, you may:

  • Ask what we hold about you, and get a copy.
  • Correct or complete anything inaccurate, irrelevant, excessive, misleading or out of date.
  • Ask us to delete or destroy information we no longer have a lawful reason to keep.
  • Object to processing based on legitimate interest, on grounds relating to your particular situation.
  • Withdraw consent at any time where consent is the basis — for example a testimonial.
  • Object to direct marketing at any time, and we must stop.
  • Ask for portability and, where the GDPR applies, receive the data in a structured, commonly used, machine-readable format.
  • Not be subject to a decision based solely on automated processing that significantly affects you. We do not make such decisions.

How to exercise them: email erik@vdmdigital.io. Access and correction requests under POPIA are made on the prescribed forms described in our PAIA Manual, which also sets out the fees and the timelines. We respond within 30 days, and will tell you if we need longer and why.

We do not charge for exercising these rights, except for the copying fees prescribed under PAIA for a formal access request.

9. When we are the operator, not the responsible party

When we build, host or manage a system for a client, the personal information in that system belongs to the client's relationship with their own users. In that case:

  • The client is the responsible party or controller. They decide why and how it is processed.
  • We are the operator or processor. We act on their documented instructions, keep it confidential, secure it, and tell them without delay if we become aware of a compromise, as POPIA section 21 requires.
  • If you are a user of a client's system and want to exercise a right, ask that client. If you contact us instead, we will pass your request on and tell you we have.

10. If something goes wrong

If personal information under our control is accessed or acquired by an unauthorised person, we will notify the Information Regulator (South Africa) and every affected person as soon as reasonably possible after discovering it, as POPIA section 22 requires. Where the GDPR applies we will notify the relevant supervisory authority within 72 hours. The notification will say what happened, what the likely consequences are, and what you can do about it.

11. Complaints

Tell us first — erik@vdmdigital.io. We would rather fix it than have you escalate.

If you are not satisfied, you may complain to the Information Regulator (South Africa):

  • Complaints: complaints.IR@justice.gov.za
  • General: inforeg@justice.gov.za
  • Website: https://inforegulator.org.za

If the GDPR applies to you, you may also complain to the supervisory authority in your country of residence, work or the place of the alleged infringement.

12. Links to other sites

Our site links to third-party sites, including our clients and our processors. We are not responsible for their privacy practices. Read their policies.

13. Changes

We may update this policy. The current version, its publication date and its version number are shown on this page, and every previous published version is retained and available on request. Material changes will be brought to your attention by email or a notice on the site.

14. Contact

VDM Digital (Pty) Ltd (Reg. No. 2026/179981/07)

13 Jigger Avenue, Somerset West, Western Cape, 7130, South Africa

Information Officer: Erik van der Merwe — erik@vdmdigital.io

Telephone: Our telephone number is published in the current version of this document on our website, and is available on request by email.

Last updated: 10 September 2026.

Other policies

  • Terms of Service
  • Refund and Cancellation Policy
  • Acceptable Use Policy
  • Cookie and Local Storage Policy
  • PAIA Manual