GDPR Policy

This policy explains how Fosker Media handles personal data under the EU General Data Protection Regulation and the UK GDPR. It sits next to our privacy policy (what this website collects) and our POPI / POPIA policy (South African law, which is our home statute).

Fosker Media is a digital agency in Durban, South Africa. We work with clients in South Africa, the United Kingdom, the EU, Switzerland and Australia. If you are in the UK or the EEA and you use foskermedia.com, or you hire us, this page is for you.

We have not appointed an EU Article 27 representative. Contact us at the address below.

Controller

Fosker Media is the data controller for personal data we collect for our own purposes — including enquiries through this Site, our client and supplier records, and our own staff data.

Email: [email protected]
Phone: +27 (0)72 516 7115
Durban, South Africa

When we host or market a client’s website, that client is usually the controller of their visitors’ data and we are the processor. Their privacy notice applies to that site. We process on their documented instructions.

Personal data we collect

  • Identity and contact data: name, email, phone, company.
  • Enquiry data: project type, budget range, message.
  • Client and billing data needed to quote, contract, invoice and host.
  • Technical data: IP address, browser, URL, session cookie, rate-limit identifiers, Linkssi session id on the contact form, and UTM fields if you arrived from a campaign.

We do not collect special-category data (Article 9) through this Site. Do not send it in a form. We do not make solely automated decisions that produce legal or similarly significant effects.

Lawful bases

We process personal data only where a lawful basis applies:

  • Consent (Article 6(1)(a)) — submitting a form, or asking us to email you.
  • Contract (Article 6(1)(b)) — steps before a contract (a quote) and performing a contract (building, hosting, ads, care plans).
  • Legitimate interests (Article 6(1)(f)) — running and securing the Site, preventing spam, and keeping a record of enquiries, balanced against your rights.
  • Legal obligation (Article 6(1)(c)) — tax and accounting where an invoice exists.

You may withdraw consent at any time. That does not affect processing already carried out, or processing that rests on another basis (for example a contract).

We do not sell personal data. We do not add Site visitors to a marketing list unless you ask.

Who we share data with

  • Linkssi — CRM and the booking embed.
  • Our South African host — site files and, when configured, stored leads.
  • Cloudflare — CDN, TLS and security in front of the Site.
  • PayFast — payment processing. Full card numbers are not stored on this Site.
  • Email to [email protected] if the CRM is unavailable.

These parties act as processors for us, or as independent controllers for their own payment and infrastructure services. We do not share data with advertisers on this Site. This Site does not load Google Analytics, Meta Pixel or LinkedIn Insight on the pages we publish.

International transfers

We are established in South Africa. The Site is hosted there. Some processors (including Cloudflare and Linkssi) may store or access personal data in other countries, including the United States or the EU.

South Africa does not currently have an EU adequacy decision. Where UK or EEA data is transferred to us or through our processors, we rely on the processor’s published transfer tools (for example Cloudflare’s) and on the fact that you contacted a South African business, or contracted with one. Email us if you need a description of the safeguards for a specific processor.

Retention

We keep enquiry data for as long as needed to reply. If we work together, we keep what the contract, invoices and tax law require — typically up to seven years after the last invoice. Security logs and rate-limit data are short-lived. Backups expire on a delay.

Your rights

Subject to the limits in the UK and EU GDPR, you may:

  • access your personal data
  • rectify inaccurate data
  • request erasure
  • restrict or object to certain processing
  • receive a portable copy of data you provided, where processing is based on consent or contract and is carried out by automated means
  • withdraw consent
  • lodge a complaint with a supervisory authority

Email [email protected]. We may need to verify your identity. We will respond within one month, or tell you if we need more time (up to two further months for complex requests).

UK: Information Commissioner’s Office — ico.org.uk. EEA: your local data protection authority, listed by the European Data Protection Board.

Cookies

We use a session cookie so forms can be submitted safely (strictly necessary). Linkssi’s embed and Cloudflare may set their own cookies for bookings and security. You can block cookies in the browser; the Site and forms may then fail to submit. We do not use advertising cookies on this Site.

Children

The Site is for business customers. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete it.

Related pages

Privacy policy · POPI / POPIA policy · Terms & conditions

Changes

We will update this page when our processing or the law changes. The effective date at the top will change.