YOUR INFORMATION. OUR RESPONSIBILITY.
Privacy Policy
This privacy policy explains how we collect, uses, protect and manage personal information, while ensuring transparency, accountability and respect for individual privacy.
Effective: 5 September 2026 Last Updated: 5 September 2026
1. Introduction
This Privacy Policy explains how PROGXES (“PROGXES”, “we”, “us” or “our”) collects, uses, discloses, protects and retains personal information in connection with our business activities. It applies to personal information relating to clients, prospective clients, participants, suppliers, service providers and other individuals who interact with us through our website, professional services, training and learning programmes, business engagements, marketing activities or other related activities. Our activities extend across South Africa and the global markets we serve, including Africa, Europe and North America. Where relevant, this Privacy Policy also applies to personal information processed through third-party technology platforms used to support our activities.
2. Legal Framework
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the Promotion of Access to Information Act 2 of 2000, as amended (“PAIA”), and other applicable laws relating to privacy and data protection.
As we serve clients and operate across South Africa and global markets, additional privacy or data-protection requirements may apply depending on the jurisdiction, the nature of the services provided, the location of the relevant data subject and the circumstances of the processing. Where applicable, we will take reasonable steps to comply with those requirements.
POPIA establishes conditions for the lawful processing of personal information and provides data subjects with rights in relation to their personal information. We seek to process personal information lawfully, fairly and transparently, for defined purposes and in a manner appropriate to the circumstances. For purposes of this Privacy Policy, “personal information” and “processing” have the meanings given to them in POPIA. Processing includes the collection, recording, storage, use, disclosure, distribution, alteration and destruction of personal information.
3. Purpose of Processing
We process personal information only for legitimate, defined and lawful business, operational, contractual and compliance purposes. Depending on the nature of our interaction with you, this may include responding to website enquiries, contact requests and requests for information; receiving, reviewing and assessing RFQs, RFPs, SOWs and related business requirements; preparing quotations, proposals, SOWs and related service documentation; and communicating with prospective and existing clients regarding enquiries, proposals and engagements.
We may also process personal information to deliver, administer and support agreed professional services, training programmes and related activities, and to manage lawful business, contractual, financial, administrative and regulatory requirements. We may process information to protect our websites, systems and information, prevent or investigate unauthorised access, misuse or security incidents, and analyse website usage to improve functionality, performance and user experience where permitted by law.
We may process personal information in connection with our social-media presence and digital marketing activities, including business communications, advertising and marketing through platforms such as LinkedIn, Facebook and Instagram, subject to applicable law and the relevant platforms’ privacy settings and terms. Where authorised by applicable law, we may conduct direct marketing through permitted channels, including email and SMS. Electronic direct marketing will comply with section 69 of POPIA, including applicable consent or customer-exception requirements, sender identification and a practical opt-out mechanism.
4. Information We Collect
The personal information we collect depends on the nature of our interaction with you and the services or activities involved. This may include your name and surname, company or organisation, email address, telephone or mobile number, and information contained in enquiries, RFQs, RFPs, SOWs, supporting documents and other business communications.
Where applicable, we may also collect technical and usage information generated through our website or supporting technologies, such as IP address, browser and device information, timestamps, referring information, cookies and similar technologies. We may receive information through interactions with our social-media profiles, marketing campaigns and communications, subject to the relevant platform’s functionality and privacy settings.
Where reasonably practicable, we collect personal information directly from the person to whom it relates and provide the notices required by POPIA. We do not intentionally collect personal information from children as defined in POPIA through our website or intentionally request special personal information through standard website forms. Users should not submit unnecessary sensitive or special personal information through public website forms.
5. Responsibility Party and Operators
We determine the purpose and means of processing personal information and therefore act as the responsible party under POPIA. We may appoint operators to process personal information on our behalf in support of our business and service delivery activities. These may include providers of technology, cloud and document-storage services; email and other business communication services; learning management systems (LMSs) and learning experience platforms (LXPs); customer relationship management and other business systems; and professional or other service providers acting on our behalf. Where we use operators, we will apply appropriate contractual, confidentiality and security measures as required by POPIA and other applicable law.
6. Third-Party Platforms
Our website and business activities may involve third-party websites, platforms and services, including social-media platforms such as LinkedIn, Facebook and Instagram. These services may process personal information in accordance with their own privacy policies, terms and data-processing practices.
Where you interact directly with a third-party platform, that platform may collect and process information independently of us. We are not responsible for the privacy practices or processing activities of third parties operating independently from us. Where a third-party processes personal information on our behalf as an operator, that processing remains subject to our requirements and applicable law.
7. Disclosure and Third-Party Requests
We may disclose or make personal information available where reasonably necessary and lawful. Depending on the circumstances, recipients may include service providers supporting our business activities; technology and business platforms; social-media, advertising and digital marketing platforms; legal, financial, accounting and other professional advisers; and public authorities, regulators or other bodies where disclosure is legally required or permitted.
We will seek to limit disclosures to information that is appropriate and reasonably necessary for the relevant purpose. Where we receive a third-party request for personal information, we will assess it against applicable legal requirements, the rights of the relevant data subject and applicable confidentiality obligations. Where disclosure is legally required or permitted, we will disclose only the information reasonably necessary and may verify the requester’s identity and authority.
8. Data Subject Rights
Subject to applicable law and statutory limitations, data subjects may have the right to request confirmation of whether we hold personal information about them, request access to that information, request correction, destruction or deletion where the statutory requirements are met, object to certain processing, object to direct marketing, withdraw consent where consent is the applicable basis, and lodge a complaint with the Information Regulator. Requests should be sent to the Information Officer at info@progxes.com. We may require adequate proof of identity before processing a request or providing access to personal information.
9. PAIA and Access to Records
PAIA provides a mechanism for requesting access to records held by private bodies where the applicable statutory requirements are met. Our PAIA Manual provides information about the records we hold, applicable access procedures and relevant contacts. Requests for access to records will be assessed in accordance with PAIA and any applicable grounds for refusal or limitation. A PAIA request does not override the privacy and confidentiality protections contained in PAIA or other applicable law.
10. Cross-Border Transfers
As we serve clients across global markets and may use service providers or technology platforms located outside South Africa, personal information may be processed or stored in other countries. Where personal information is transferred from South Africa to another country, we will comply with section 72 of POPIA and assess the applicable safeguards and circumstances.
A transfer may be permitted where the recipient is subject to an adequate level of protection, the data subject has consented to the transfer, the transfer is necessary for a qualifying contractual purpose, or another condition permitted under section 72 applies. We will take reasonable steps to ensure that applicable requirements are met before making or permitting relevant cross-border transfers.
11. Information Security
We apply reasonable technical and organisational measures appropriate to the risks associated with the personal information we process. Depending on the processing activity, these measures may include access controls, authentication and monitoring, secure transmission, encryption and backups where appropriate, security updates, malware protection, confidentiality obligations and ongoing risk assessment and review.
No electronic system can be guaranteed to be completely secure. If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will respond in accordance with section 22 of POPIA, including notifying the Information Regulator and affected data subjects as required by law.
12. Information Retention
We retain personal information only for as long as necessary for the purpose for which it was collected or subsequently processed, unless a longer period is required or authorised by law, reasonably required for lawful business functions, required by contract or otherwise permitted by POPIA. Retention periods may therefore vary according to the nature and purpose of the information and applicable statutory, contractual and operational requirements. When personal information is no longer authorised or required to be retained, we will take appropriate steps to securely delete, destroy or de-identify it.
13. Cookies and Similar Technologies
Our website may use cookies and other technologies for essential operation, security, functionality, analytics and, where enabled, marketing purposes. These technologies may involve the collection or processing of technical and usage information. Where required by applicable law, we will obtain consent before using non-essential cookies or similar technologies. Users may manage applicable cookie preferences through the controls provided on the website or through their browser settings.
14. Changes to Policy
We may update this Privacy Policy when our business activities, processing practices, technology, services or legal requirements change. The latest version will be published on our website with an updated effective or revision date. We encourage users to review the Privacy Policy periodically for changes.
15. Complaints
We encourage data subjects to contact our Information Officer first so that privacy concerns can be investigated and addressed where possible. If a concern cannot be resolved, or where otherwise appropriate, a data subject may lodge a complaint with the Information Regulator in accordance with applicable law.
16. Information Officer
Our Information Officer oversees our compliance with applicable privacy and information-access requirements and serves as our primary contact for privacy-related requests, data subject rights and information-access queries. Please contact us using our contact form.
Information Officer: Nicola Govender (Director)