Legal
PoPI Act Compliance
Last updated: 24 July 2026
This PoPI Act Compliance statement summarises how Modifly (Pty) Ltd approaches compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”). It should be read with our Privacy Policy, Cookie Policy, and Terms of Use.
POPIA regulates the processing of personal information by public and private bodies in South Africa. Modifly processes personal information primarily in a business-to-business context in connection with website enquiries, client engagements, supplier relationships, and related operations.
1. Our role under POPIA
Modifly (Pty) Ltd acts as a responsible party when it determines the purpose and means of processing personal information collected through this website and related business activities.
In some engagements we may process personal information as an operator on behalf of a client. In those cases, processing is governed by the applicable services agreement and written processing instructions, in addition to POPIA.
2. Information Officer
We have designated an Information Officer responsible for encouraging compliance with POPIA, dealing with requests from data subjects, and working with the Information Regulator where required.
Contact: admin@modifly.co.za | +27 (0)63 712 9334
3. Conditions for lawful processing
We align our practices to the eight conditions for lawful processing under POPIA:
- Accountability — we take responsibility for ensuring processing complies with POPIA
- Processing limitation — we process information lawfully, reasonably, and only for relevant purposes
- Purpose specification — we collect information for specific, explicitly defined, and lawful purposes
- Further processing limitation — further processing is compatible with the original purpose unless a lawful exception applies
- Information quality — we take reasonably practicable steps to ensure information is complete, accurate, and not misleading
- Openness — we take reasonably practicable steps to notify data subjects of collection where required
- Security safeguards — we implement appropriate technical and organisational measures
- Data subject participation — we facilitate access, correction, and related rights as required by POPIA
4. Categories of data subjects and information
Depending on the interaction, data subjects may include website visitors, prospective clients, client representatives, suppliers, partners, and other business contacts.
Categories of personal information may include identity and contact details, organisation and role information, communication content, and technical usage data. We do not intentionally collect special personal information via this website unless you voluntarily provide it and processing is lawful.
5. Security compromise procedure
If we become aware of a security compromise involving personal information, we will take steps consistent with POPIA section 22, including notifying the Information Regulator and affected data subjects where required, and documenting the incident and remedial actions.
6. Operators and service providers
We use operators and service providers (for example hosting, email, and analytics providers) under arrangements that require appropriate security and confidentiality. Where operators are located outside South Africa, we apply POPIA’s cross-border transfer requirements as described in our Privacy Policy.
7. Direct marketing
We do not use this website as a mass direct-marketing platform. Where we send electronic marketing communications to data subjects, we do so in accordance with POPIA section 69 and other applicable laws, including obtaining consent where required and providing an accessible opt-out.
Transactional or service-related communications about an existing enquiry or engagement are not treated as unsolicited direct marketing.
8. Retention and destruction
Personal information is retained only as long as needed for the purpose collected, or as required by law, contract, or legitimate business need. When no longer required, information is deleted, destroyed, or de-identified in a manner that prevents reconstruction where reasonably practicable.
9. Data subject requests
To exercise POPIA rights (access, correction, objection, deletion where applicable, or withdrawal of consent), contact our Information Officer at admin@modifly.co.za.
We may request reasonable proof of identity and, where someone submits a request on behalf of another person, proof of authority. We will respond within the periods required by POPIA, subject to lawful grounds for refusal or limitation.
10. Complaints
If you believe we have not handled your personal information in accordance with POPIA, please contact us first so we can attempt to resolve the matter.
You also have the right to lodge a complaint with the Information Regulator of South Africa:
- Website: https://inforegulator.org.za
- Complaints: complaints.IR@justice.gov.za
- Enquiries: enquiries@inforegulator.org.za
11. Updates
We may update this compliance statement as our practices, systems, or legal obligations evolve. The “Last updated” date reflects the latest revision.
12. Related documents
- Privacy Policy — detailed processing notice
- Cookie Policy — cookies and similar technologies
- Terms of Use — website terms under South African law
This document is provided for transparency and compliance purposes. It does not constitute legal advice. For matter-specific advice, consult a qualified South African attorney.
