Personal information and your choices

Privacy notice

This notice explains what Sourcegridbase collects, why we need it and how long it is kept.

Responsible party

Sourcegridbase is the responsible party for personal information processed through this website and our audit engagements. Privacy enquiries may be sent to info@sourcegridbase.digital or addressed to the Information Officer at our Durban office.

Information we process

Website enquiries may contain a name, email address, selected service, application stage and non-sensitive message. An accepted engagement can involve contact and identity details, authority to act, financial statements, income and asset records, household information, correspondence and audit findings. We ask clients not to submit medical detail through the public form.

We also receive limited technical information needed to serve and secure the website. Optional analytics, if introduced, will run only after consent and be reflected in the cookie notice.

Purpose and lawful basis

We process information to answer enquiries, assess fit, contract for and deliver audits, issue invoices, protect confidential files, meet legal duties and handle complaints. Depending on the activity, processing is necessary for a contract, consent, compliance with law or a legitimate interest balanced against the person’s rights.

Financial and disability-related context may be sensitive. Access is limited to people who need it for the agreed work. We do not sell personal information or use audit records for advertising.

Sharing and operators

Information may be handled by contracted hosting, secure storage, email, accounting and professional service providers acting under appropriate duties. We may share information with an authorised representative or public authority only when instructed, legally required or otherwise permitted by law.

International transfers

Some service providers may store or support information outside South Africa. Before such transfer we use a lawful basis under POPIA, such as adequate protection, a binding agreement requiring comparable safeguards or informed consent where appropriate. Provider locations can change; current details are available on request.

Retention

Unengaged web enquiries are generally retained for 12 months. Audit working files are generally retained for five years after closure to address professional and legal obligations, unless a longer period is required or a justified request permits earlier deletion. Invoices and statutory records are held for legally required periods. Records are then securely deleted or de-identified.

Security

We use access controls, secure transfer instructions, device protections and role-limited handling. No electronic method is risk-free. A suspected compromise is assessed and affected people and the Information Regulator are notified when required.

Your rights

Subject to POPIA and applicable limitations, you may ask whether we hold your information; request access, correction or deletion; object to certain processing; withdraw consent; or complain to the Information Regulator. We may need to verify identity before acting and will explain if a legal retention duty prevents deletion.

Changes and contact

Material updates will be dated on this page. Contact info@sourcegridbase.digital with “Privacy” in the subject line. You may also contact the Information Regulator of South Africa through its official channels.