Legal
Privacy policy
Last updated 3 September 2026.
Who we are
Velora Systems is a sole proprietorship registered in South Africa, trading from [YOUR BUSINESS ADDRESS]. For the purposes of the Protection of Personal Information Act 4 of 2013 ("POPIA") we are the responsible party for the personal information described here. For the purposes of the UK and EU General Data Protection Regulation we act as a controller in respect of that same information.
Our Information Officer is [YOUR FULL NAME], reachable at info@velorasystems.net.
What we collect
| Category | Where it comes from | Why we hold it |
|---|---|---|
| Name, email address, telephone number, employer | You, when you contact us or engage us | To reply to you and to perform our contract with you |
| Your website address and the publicly available content of those pages | You, or public sources | To carry out the accessibility audit you asked for |
| Business contact details of prospective clients | Publicly available business sources, such as a company's own website | To offer a service we reasonably believe is relevant |
| Billing details and invoice records | You, and our payment provider | To take payment and to meet tax and record-keeping obligations |
| Correspondence | You | To maintain a record of what was agreed |
What we do not collect
This website sets no cookies, runs no analytics, embeds no third-party trackers and contains no advertising. There is no login. We do not attempt to identify visitors to this site.
When we audit a website we read only pages that are publicly available. We do not log in, we do not attempt to access private areas, and we do not collect personal information belonging to your customers.
Our lawful basis
- Performance of a contract. To deliver the audit and remediation you engaged us for.
- Legitimate interests. To contact businesses about a service relevant to them, and to keep records of our work. We have weighed this against the rights of the people concerned, and every message we send identifies us and offers an immediate opt-out.
- Legal obligation. To retain invoices and tax records as South African law requires.
- Consent. Where we rely on it, you may withdraw it at any time.
Direct marketing
We do not send unsolicited electronic marketing to recipients in South Africa. Section 69 of POPIA does not permit it without prior consent, and we comply with that.
Where we contact businesses in other jurisdictions, every message identifies us, states why you received it, gives a postal address and offers a simple way to opt out. If you ask us not to contact you again, we record that and we do not.
Who we share it with
We do not sell personal information and we do not share it for anyone else's marketing. We use a small number of service providers who process information on our behalf, namely our email provider, our payment provider and our hosting provider. Each is bound to process it only on our instructions.
Some of these providers are outside South Africa. Where information is transferred across borders we satisfy ourselves that it is subject to protection substantially similar to POPIA, as section 72 requires.
How long we keep it
- Enquiries that do not become work: up to 12 months.
- Client records and audit reports: 5 years after the engagement ends.
- Invoices and tax records: 5 years, as required by South African tax law.
- Opt-out records: kept indefinitely, because that is the only way to honour the request.
Your rights
Under POPIA and, where it applies to you, the GDPR, you may:
- ask what personal information we hold about you and get a copy;
- ask us to correct or delete it;
- object to our processing it, including for direct marketing;
- ask us to restrict how we use it;
- ask for it in a portable format;
- withdraw consent where we relied on consent.
Email info@velorasystems.net and we will respond within 30 days. There is no charge.
Complaints
If you are unhappy with how we have handled your information, please tell us first. You also have the right to complain to the Information Regulator of South Africa, at complaints.IR@justice.gov.za, or to your own supervisory authority if you are in the UK or EU.
Security
We keep personal information on encrypted devices and in reputable hosted services protected by strong authentication. Access is limited to those who need it, which for a business of this size means the owner. No system is perfectly secure, and we will notify you and the Regulator without undue delay if a breach affects you.
Changes
If we change this policy we will update the date above. Material changes affecting existing clients will be notified by email.