Suis Energy Consulting (Pty) Ltd ("Suis", "we", "our", or "us") is committed to protecting your personal information and your right to privacy in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or engage our consulting services.
1. Information We Collect
Personal Information
We may collect personal information that you voluntarily provide to us when you:
- Fill out contact forms or request a consultation
- Subscribe to our newsletter or blog updates
- Enter into a consulting engagement with us
- Apply for a position through our careers page
- Communicate with us via email, phone, or social media
This information may include your name, email address, phone number, company name, job title, physical address, energy consumption data, and any other details you choose to provide.
Usage Data
We automatically collect certain information when you visit our website, including:
- IP address and browser type
- Operating system and device information
- Pages visited, time spent on pages, and navigation paths
- Referring website addresses and search terms used
- Date and time of your visits
2. How We Use Your Information
Service Delivery
We use your personal information to:
- Respond to your enquiries and consultation requests
- Provide our energy consulting services and deliver project reports
- Process payments and manage client accounts
- Send project updates and deliverables
- Perform energy audits and system design calculations
Communication
With your consent, we may use your information to:
- Send newsletters with energy industry insights and updates
- Notify you about new services, events, or promotions
- Request feedback on our services to improve client experience
Improvement
We use aggregated and anonymised data to:
- Analyse website performance and user behaviour
- Improve our website design, content, and functionality
- Develop new services and enhance existing offerings
- Conduct internal research and statistical analysis
3. Data Sharing
We do not sell, trade, or rent your personal information. We may share your data with trusted third parties only in the following circumstances:
- Service providers: Companies that assist us with website hosting, email delivery, analytics, and payment processing, bound by strict confidentiality agreements
- Project partners: Engineering firms, equipment suppliers, or subcontractors involved in delivering your specific project, only with your prior consent
- Professional advisors: Our legal, accounting, and insurance advisors as necessary for business operations
- Legal requirements: Where required to do so by law, court order, or in response to valid requests by public authorities
4. Cookies and Tracking Technologies
Our website uses the following types of cookies:
- Strictly necessary cookies: Essential for the website to function properly, including session management and security features. These cannot be disabled
- Analytics cookies: Help us understand how visitors interact with our website by collecting anonymous statistical information. We use Google Analytics with IP anonymisation enabled
- Functional cookies: Remember your preferences and settings to provide a more personalised experience, such as language preference and calculator inputs
- Marketing cookies: Used to track visitors across websites to display relevant advertisements. These are only set with your explicit consent
You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.
5. Data Security
We implement robust technical and organisational measures to protect your personal information, including:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS/SSL technology. Sensitive data at rest is encrypted using AES-256 encryption
- Access controls: Strict role-based access controls ensure only authorised personnel can access personal data, with multi-factor authentication required for all staff accounts
- Regular audits: We conduct periodic security assessments and vulnerability testing of our systems
- Staff training: All employees receive regular training on data protection and information security best practices
- Incident response: We maintain a comprehensive data breach response plan and will notify affected data subjects and the Information Regulator within 72 hours as required by POPIA
6. Your Rights under POPIA
Under South Africa's Protection of Personal Information Act (POPIA), you have the following rights regarding your personal information:
- Right to access: You may request confirmation of whether we hold your personal information and request a copy of it
- Right to correction: You may request that we correct or update inaccurate, incomplete, or outdated personal information
- Right to deletion: You may request that we delete your personal information where it is no longer necessary for the purpose for which it was collected
- Right to object: You may object to the processing of your personal information for direct marketing purposes at any time
- Right to restriction: You may request that we restrict the processing of your personal information in certain circumstances
- Right to data portability: You may request a copy of your personal information in a structured, commonly used, and machine-readable format
- Right to lodge a complaint: You have the right to lodge a complaint with the Information Regulator of South Africa if you believe your personal information has been mishandled
To exercise any of these rights, please contact our Information Officer using the details provided below. We will respond to your request within 30 days as required by POPIA.
7. Children's Privacy
Our website and services are not directed at children under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers. If you believe we have inadvertently collected data from a child, please contact us immediately.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make significant changes, we will notify you by posting a prominent notice on our website and updating the "Last updated" date at the top of this policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
9. Contact Us