Legal
Privacy Policy
What we collect when you use this website, why we hold it, who else touches it, and how to get it back or have it deleted.
Last updated 18 August 2026
Who we are
Zorah Technologies (Pty) Ltd, registration number 2026/439248/07, a private company incorporated in the Republic of South Africa, with its registered address at 79 Dolweni Avenue, Boskruin Ext 5, Randburg, Gauteng, 2188.
This policy covers zorahtechnologies.co.za and the email we send from it. It does not cover the platforms we build and operate for clients: on those, the client is the responsible party and we act as an operator on their instructions. Section 08 explains that split.
For anything in this policy, write to sales@zorahtechnologies.co.za.
What we collect, and why
Only what a given interaction needs. There is no account to create on this site, and we do not buy, rent or scrape contact lists.
| When | What | Why | Lawful basis |
|---|---|---|---|
| You submit an enquiry or contact form | Name, email, phone, company, and whatever you write in the message | To reply to you and, if it goes further, to quote | Section 11(1)(b): steps toward a contract at your request |
| You subscribe to The Zorah Brief | Email address, the time you asked, the time you confirmed | To send the weekly newsletter, and to be able to prove you asked for it | Section 69(1): your consent, recorded by double opt-in |
| You comment on an article | The name you give and your comment | To publish the comment under the article | Section 11(1)(a): consent |
| You browse the site | Pages viewed, referrer, approximate location by country, device and browser type | To see which writing is worth doing more of, and to find slow pages | Section 11(1)(f): legitimate interests |
We do not collect special personal information, and we do not knowingly collect anything from children. Nothing on this site asks for an identity number, banking detail or payment card, and you should never send those to us by email.
Analytics and cookies
Two measurement tools run on this site, and they behave differently:
- Vercel Analytics and Speed Insights count page views and measure loading performance. They set no cookies and do not track you between sites.
- Google Analytics 4 sets cookies in your browser and reports aggregated behaviour: which pages are read, for how long, and where visitors arrived from. IP addresses are truncated by Google before storage.
If you would rather not be counted by Google Analytics, install the Google Analytics opt-out add-on, or block cookies for this site in your browser. Nothing on the site breaks if you do, because none of it is used to serve you content.
We run no advertising pixels, no retargeting tags and no third-party social trackers.
Email, and why we ask twice
The Zorah Brief uses double opt-in. You enter an address, we send one email asking you to confirm, and nothing else is ever sent unless you click it. Until you do, the address sits on our list marked unsubscribed and cannot be mailed.
We do this because section 69 of POPIA requires evidence that a person asked to be marketed to. A confirmed click with a timestamp is that evidence; an address someone typed is not. It also keeps typos and other people's addresses off the list.
Who else processes it
We use a small number of service providers, and each one only sees what it needs to do its job. None of them are permitted to use your information for their own purposes.
| Provider | What it handles | Where |
|---|---|---|
| Vercel | Website hosting, and the cookieless page-view analytics | United States and global edge network |
| Resend | Sending form notifications, confirmations and the newsletter, and storing the subscriber list | United States |
| Google Analytics 4, and our own Workspace email | United States and global |
These providers operate outside South Africa. Section 72 of POPIA permits a transfer of that kind where the recipient is subject to binding rules or a contract that gives effect to principles substantially similar to POPIA. Each of the above is engaged under terms that do so. We tell you this plainly because a policy that quietly omits it is not being straight with you.
How long we keep it
| What | How long |
|---|---|
| Enquiries and the correspondence that follows | 36 months from the last contact, then deleted |
| Prospect contact detail we researched ourselves | 24 months from the last contact, then deleted |
| Newsletter subscribers | Until you unsubscribe. The record that you consented is kept 12 months after that, as proof we were entitled to email you |
| Comments | Until you ask us to remove them |
| Analytics | 14 months in Google Analytics; Vercel keeps aggregates only |
Your rights
Under POPIA you may, at any time and without giving a reason:
- Ask what personal information we hold about you, and get a copy
- Have anything inaccurate corrected, or anything excessive deleted
- Object to processing we base on legitimate interests
- Withdraw consent, including by unsubscribing
- Ask where we got your details. If we contacted you and you did not give them to us, we will tell you exactly where they came from
Write to sales@zorahtechnologies.co.za. We will respond within 30 days, and there is no charge.
If you are not satisfied with how we handle it, you may complain to the Information Regulator of South Africa at inforegulator.org.za.
Client platforms are different
Where we build and operate a platform for a client, the personal information inside it belongs to that client's world, not ours. In POPIA terms the client is the responsible party and Zorah is an operator.
That means we process it only on the client's documented instructions and never for our own purposes, we hold it under section 19 security measures, we notify the client of any unauthorised access within 72 hours so they can meet their section 22 obligations, and any subcontractor is bound by obligations no less onerous than ours.
If your information sits on a platform we run for a business you deal with, that business is who to approach. Tell us and we will point you at the right party.
Security
Access to systems is limited to the people who need it, protected by single sign-on with two-factor authentication. Traffic to this site and to our providers is encrypted in transit. Client platform data is encrypted at rest, access is role-based, and actions are logged.
No system is perfect, and anyone who tells you otherwise is selling something. If we ever have reason to believe your personal information has been accessed unlawfully, we will tell you and the Information Regulator, as section 22 requires.
Changes
When this policy changes we update the date at the top. If a change materially affects how we use information you have already given us, we will say so directly rather than relying on you to notice.