POPI / POPIA Policy

This is Fosker Media’s policy under the Protection of Personal Information Act 4 of 2013 (POPIA), often called POPI. It sits next to our privacy policy, which describes what the website actually collects. This page is the South African statement: who is responsible, why we process personal information, and how you exercise your rights.

Fosker Media is a digital agency in Durban, South Africa. We build websites and run marketing for businesses. We also run this website, foskermedia.com.

Information officer

Fosker Media is the responsible party for personal information we decide the purpose and means of processing — including enquiries sent through this Site, our own client and supplier records, and our staff records.

Requests to the information officer: [email protected]
Phone: +27 (0)72 516 7115
Durban, South Africa

When we are the operator

When we host, maintain or market a client’s website, we often process personal information on that client’s behalf (for example, form submissions or analytics they have asked us to run). In that case the client is the responsible party and we are the operator. We process only as instructed in the client agreement, keep the information secure, and do not use it for our own marketing.

If you are a visitor on a client site and you want your information corrected or deleted, start with that business. We will help the client where the agreement requires it.

Personal information we process as responsible party

  • Identity and contact details: name, email, phone, company name.
  • Enquiry content: project type, budget range, message, and any files you send us.
  • Client and billing details needed to quote, invoice and host a site, including VAT numbers where you give them.
  • Technical data needed to run and protect the Site: IP address, browser, requested URL, session cookies, rate-limit identifiers, and a Linkssi session id on the contact form.
  • Campaign context (UTM fields) when you arrive from an ad or a shared link.

We do not collect special personal information (health, religion, biometric data and similar) through this Site. Do not send it in a form. We do not run credit checks on website visitors.

Why we process it

POPIA requires a lawful justification. Ours are:

  • Consent — when you submit a form or ask us to email you.
  • Contract — to quote, to do the work you hired us for, and to host or care for a site.
  • Legitimate interests — to run, secure and improve the Site, and to keep a record of enquiries, balanced against your rights.
  • Legal obligation — tax, accounting and other duties. Where an invoice followed an enquiry we typically keep records up to seven years.

We do not sell personal information. We do not add Site visitors to a newsletter unless you ask.

Operators and other recipients

We use other organisations to process information for us:

  • Linkssi — CRM and the booking embed on this Site.
  • Our South African host — files and, when configured, a database of leads.
  • Cloudflare — CDN, TLS and abuse protection in front of the Site.
  • PayFast — payments for hosting and billed work. We do not store full card numbers on this Site.
  • Email — if the CRM is down, an enquiry may be mailed to [email protected].

They may only use the information to provide that service to us, unless they are a responsible party in their own right (for example PayFast for the payment itself).

Cross-border transfers

The Site is hosted in South Africa. Some operators (including Cloudflare and Linkssi) may process information on servers outside South Africa. We only use operators who have a reason to receive it and who we believe apply security appropriate to the work. If you need more detail about a specific transfer, email us.

Security and retention

We use HTTPS, HttpOnly SameSite session cookies, CSRF checks on forms, rate limits, and access control on the server. No method of storage or transmission is guaranteed.

Enquiries are kept for as long as we need them to reply and, if we work together, to do the work and meet legal retention rules. Rate-limit data is short-lived. Server logs follow host and CDN defaults. Backups take a while to age out.

Your rights under POPIA

You may:

  • ask whether we hold personal information about you, and request a copy
  • ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully
  • object to processing that is based on legitimate interests, or to direct marketing
  • withdraw consent where consent was the justification, without affecting processing already done
  • complain to the Information Regulator (South Africa)

Email [email protected]. We may need to confirm it is you. We will answer as soon as reasonably possible, and within the time POPIA allows.

Information Regulator: inforegulator.org.za. Complaints: [email protected].

Children

This Site is for business use. We do not knowingly collect personal information from children under 18. If you believe we have, tell us and we will delete it.

Related pages

Privacy policy · GDPR policy · Terms & conditions

Changes

We will update this page when our processing or the law changes. The effective date at the top will change.