Bitara

Privacy policy

How Bitara handles personal information, under the Protection of Personal Information Act 4 of 2013 (POPIA). Last updated 1 October 2026.

1. Who we are

Bitara, trading as Bitara (“we”), provides IT services, software and hosting in South Africa. Our address is South Africa. Our Information Officer can be reached at [email protected] or +27 82 050 4381.

2. Our two roles

As a responsible party, we decide how to use the personal information of people who contact us, our clients' contact people, and our suppliers.

As an operator, we process personal information on our clients' behalf when we work in their systems: their staff's accounts, mailboxes, devices and files, or their customers' data in the applications we build and host. Then our client is the responsible party, and we:

  • process it only on our client's instructions and only to deliver the service (section 21);
  • keep it confidential and disclose it to no one except as the law requires (section 20);
  • protect it with the security measures in section 8 below (section 19);
  • tell our client immediately if we believe it has been accessed or acquired by anyone not authorised (section 21(2));
  • use no sub-contractor to process it without our client's agreement;
  • return or delete it when the work ends, unless the law requires us to keep it.

A written operator agreement on these terms is available to every client on request.

3. What we collect

  • Enquiries: what you send through our contact form or by email: your name, email address, and if you give them, your company, phone number and message.
  • Clients: names, roles and contact details of the people we work with; billing and VAT details; agreements and correspondence.
  • Service delivery: as an operator, only the information in our clients' systems that the work requires, such as user names, device names and logs.
  • This website: our web server records each visit's IP address, time and page requested, for security. We use no analytics, advertising or tracking, and load nothing from other companies. The site sets one cookie, which protects the contact form against forgery and contains nothing about you.

We do not ask for special personal information (such as health or religious beliefs) or information about children. If a client's systems contain it, we treat it with the extra care POPIA requires.

4. Why we use it

  • To answer enquiries and prepare quotes (your consent, and steps towards a contract).
  • To deliver the services and products our clients engage us for (contract).
  • To invoice and keep financial records (contract, and tax law).
  • To keep our systems and our clients' systems secure (legitimate interest, and section 19).

We do not send marketing unless you ask for it, and we never sell personal information.

5. Who we share it with

  • Suppliers, only when needed to fulfil an order, for example the details a software vendor requires to issue your licence.
  • Our email provider, which carries the messages you send us and we send you.
  • Anyone the law requires us to disclose it to.

Our website and the applications we host run on our own hardened servers in South Africa.

6. Outside South Africa

Email can pass through providers whose systems are outside South Africa. Where personal information leaves the country, we make sure the recipient is bound by protection comparable to POPIA, or rely on another ground in section 72.

7. How long we keep it

  • Enquiries that do not lead to work: deleted within 12 months.
  • Client records: for the duration of our relationship and as long as tax law requires afterwards, currently five years for financial records.
  • Information we process as an operator: returned or deleted when the work ends, as our client instructs.
  • Web server logs: a few weeks, then deleted automatically.

8. How we protect it

  • Servers hardened to CIS benchmarks, with automatic security updates and file-integrity monitoring.
  • Encryption in transit (TLS 1.2 and 1.3, FIPS-approved ciphers) and, where we store sensitive data, at rest.
  • Two-step sign-in, least-privilege access and audit logging on our systems.
  • Nightly backups, and protection against password-guessing attacks.
  • Access to client systems only for the task at hand, recorded.

9. Security compromises

If we believe personal information we hold has been accessed or acquired by anyone not authorised, we tell the people affected and the Information Regulator, as section 22 requires, and, where we act as an operator, our client immediately.

10. Your rights

You may ask whether we hold personal information about you and for a copy of it, ask us to correct or delete it, object to its use, and withdraw consent you have given. Contact our Information Officer at the details in section 1. For records, see our PAIA manual. If we act as an operator for your employer or a business you deal with, contact them first; we will help them answer you.

If you are not satisfied with our answer, you may complain to the Information Regulator: inforegulator.org.za.

11. Changes

We update this policy when what we do changes, and show the date at the top.