Legal & Governance
Privacy Policy
Cyber Resilience is committed to protecting personal information and processing data responsibly, lawfully, and transparently.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (“POPIA”), and other applicable privacy and data protection obligations.
The policy applies to information collected through our website, services, communications, assessments, support engagements, events, and operational interactions with clients, suppliers, partners, and website users.
Information We collect
We may collect personal and organisational information, including names, contact details, company information, job titles, communications, support information, technical information, IP addresses, device information, usage data, and information required to provide cybersecurity, governance, forensic, advisory, and operational services.
Where required for service delivery, Cyber Resilience may also process operational security information, infrastructure information, audit information, vulnerability data, incident evidence, access records, or system-generated technical information.
Information is collected directly from users, through operational engagement, through authorised service delivery processes, or through lawful third-party interactions.
HOW WE USE PERSONAL INFORMATION
Personal information may be used for:
- delivering services and support;
- communicating with clients and stakeholders;
- responding to enquiries and requests;
- conducting assessments, investigations, or forensic engagements;
- supporting governance, operational resilience, and compliance programmes;
- improving website performance, security, and user experience;
- maintaining operational records;
- meeting legal, regulatory, contractual, or governance obligations;
- and protecting Cyber Resilience, its clients, and stakeholders from operational, cybersecurity, legal, or fraud-related risks.
We process information only where there is a lawful basis to do so.
INFORMATION SECURITY & PROTECTION
Cyber Resilience applies administrative, technical, and operational safeguards designed to protect personal information against unauthorised access, misuse, loss, disclosure, destruction, or alteration.
Security controls may include access management, encryption, monitoring, audit logging, identity controls, operational governance, backup processes, and structured information security practices, supported by an ISO/IEC 27001:2022-certified Information Security Management System (ISMS) and recognised cybersecurity frameworks.
While reasonable measures are implemented to protect information, no electronic system, communication method, or storage platform can be guaranteed to be completely secure.
SHARING OF INFORMATION
Cyber Resilience does not sell personal information.
Information may be shared with authorised employees, approved service providers, professional advisors, regulators, law enforcement authorities, certification bodies, or operational partners where required for lawful service delivery, governance, legal obligations, operational support, or incident response activities.
Third parties processing information on behalf of Cyber Resilience are expected to maintain appropriate confidentiality, privacy, and security controls.
CROSS-BORDER DATA TRANSFERS
Where operational, technical, or service requirements require cross-border processing or storage of information, Cyber Resilience will take reasonable steps to ensure that appropriate safeguards, contractual protections, and security measures are in place.
DATA RETENTION
Information is retained only for as long as reasonably necessary to fulfil operational, contractual, legal, regulatory, forensic, governance, or resilience-related obligations.
Retention periods may vary depending on the nature of the information, the engagement, legal requirements, audit obligations, or operational necessity.
YOUR RIGHTS
Subject to applicable law, individuals may request access to personal information, correction of inaccurate information, deletion where appropriate, objection to processing, or withdrawal of consent where processing is consent-based.
Requests may be directed to the appointed Information Officer.
WEBSITE ANALYTICS & TRACKING
The Cyber Resilience website uses cookies and similar technologies to support website functionality, security, performance, analytics, and user experience.
Necessary cookies may be used where required for the website to function securely and effectively. Where consent is required, we will use analytics, marketing, and other non-essential cookies only in accordance with the preferences selected by the user through our cookie consent mechanism.
Website visitors can accept all cookies, reject non-essential cookies, or manage their cookie preferences. Further information about the cookies and similar technologies used on our website is available in our Cookie Policy.
CONTACT DETAILS
Questions relating to this Privacy Policy or personal information processing may be directed to:
Information Officer Cyber Resilience Email: info@cyberres.co.za Website: www.cyberres.co.za