POPIA and Privacy Policy
Effective date: 17 July 2026
Last updated: 17 July 2026
This POPIA and Privacy Policy explains how Son Security Systems (Pty) Ltd collects, uses, stores, protects and shares personal information when people use this website, submit enquiries, request quotations, book services or deal with SonSec for electronic security installation, repair, maintenance and support work.
Purpose and scope
This policy applies to personal information processed by SonSec in connection with the sonsec.co.za website, telephone enquiries, email enquiries, WhatsApp communication, quotation requests, service bookings, site assessments, installations, repairs, maintenance, upgrades, billing, after-sales support and related business administration.
POPIA means the Protection of Personal Information Act 4 of 2013. This policy is intended to explain SonSec’s practical privacy handling in plain language and does not replace POPIA or any other applicable South African law.
Responsible party
For the purposes of POPIA, Son Security Systems (Pty) Ltd is the responsible party for personal information processed for its own business purposes. Privacy requests may be sent to info@sonsec.co.za or made by calling 011 436 0533.
Privacy requests sent through the contact details above will be routed to the appropriate responsible person at SonSec for review and response.
Information SonSec may process
Depending on the enquiry, quotation, site, service, account or support request, SonSec may process the following categories of information where relevant:
- Names, company names and job titles.
- Identity, company or authorisation information where legitimately required for a service, account, site-access or legal purpose.
- Telephone numbers, WhatsApp numbers, email addresses and correspondence records.
- Physical addresses, site locations, access instructions and site contact details.
- Quotations, invoices, billing records, payment records and debt-collection records.
- Service histories, technician notes, job cards, support records and maintenance records.
- Equipment, product, installation and system information for alarm, CCTV, access-control, intercom, gate-automation, garage-door, electric-fencing and related electronic security systems.
- Website technical information, browser information, IP address information, cookies and analytics information.
- Photographs or video supplied by customers or captured for quotation, diagnosis, installation, repair, maintenance, handover or service-evidence purposes.
- Records reasonably needed for legal, insurance, warranty, accounting, safety, dispute, compliance or debt-collection purposes.
Sources of information
SonSec may collect information directly from customers, site representatives, company employees, tenants, body corporate or estate representatives, suppliers, manufacturers, subcontractors, insurers, accountants, payment providers, legal or debt-collection providers, hosting providers, website forms, email, telephone, WhatsApp and information generated during service work.
Purposes and lawful grounds
SonSec may process personal information to respond to enquiries, prepare and manage quotations, arrange site visits, diagnose faults, install systems, repair systems, service systems, maintain records, manage accounts, send invoices, recover overdue amounts, handle warranties, deal with suppliers and manufacturers, protect lawful interests, comply with legal obligations and administer the website.
Depending on the context, processing may be based on contract performance, steps requested before entering a contract, legitimate business interests, consent where appropriate, legal obligations, protection of lawful rights, safety considerations or another ground allowed by POPIA.
Children and special personal information
The SonSec website and enquiry process are intended for adults and business representatives. SonSec does not intentionally request information about children or special personal information through public website forms. If such information is supplied because it is relevant to a lawful service or safety matter, SonSec will process it only where permitted by law and reasonably necessary for the purpose.
CCTV, alarm, access-control and security-system information
Security-system work may involve sensitive site and system information, including equipment models, device locations, access methods, maintenance histories, fault symptoms, system status and service evidence. Customers should not submit passwords, alarm codes, remote-access credentials or other sensitive security credentials through public website forms.
Any CCTV footage, photographs or site evidence supplied for quotations, diagnosis or service support should be limited to what is reasonably necessary. Customers remain responsible for the lawful operation of their own CCTV, alarm, access-control and related systems.
Website enquiries, quote requests, service bookings and communications
Information submitted through website forms, email, telephone and WhatsApp is used to respond to the enquiry, discuss requirements, arrange quotation or service steps, maintain customer communication and keep necessary business records.
WhatsApp, email and telephone providers process communication metadata and message content according to their own systems and policies. SonSec uses these channels for normal business communication and support, but customers should avoid sending unnecessary sensitive credentials through them.
Cookies, analytics and embedded third-party services
The website may use cookies, analytics tools, embedded maps, embedded media, spam-prevention services, hosting logs or similar technical services. These tools may process technical information such as device, browser, IP address, page interaction and referral data. SonSec uses such information to operate, secure and improve the website and enquiry process.
Operators and third parties
SonSec may share or make information available to operators and third parties where reasonably necessary for the relevant purpose. These may include hosting providers, email providers, website service providers, payment providers, accountants, insurers, manufacturers, suppliers, subcontractors, legal advisers, debt-collection providers, auditors, regulators or public authorities.
Manufacturers and suppliers may receive product, warranty, technical or support information where necessary to quote, supply, repair, maintain, replace, upgrade or troubleshoot equipment. SonSec does not sell customer personal information.
Cross-border processing
Some website, email, cloud, messaging, manufacturer, support or hosting services may process information outside South Africa. SonSec will use such services only where this is relevant to the business purpose and permitted by applicable law, including through appropriate contractual, legal or service safeguards where required.
Information security and breaches
SonSec applies reasonable administrative, technical and operational safeguards appropriate to the nature of its business and the information processed. Safeguards may include access controls, role-limited records, secure communication practices, backups, security updates, supplier controls and internal handling procedures.
No website, email or communication system can be guaranteed to be completely secure. If SonSec becomes aware of a security compromise affecting personal information, it will assess the incident and take steps required by POPIA, which may include containment, investigation, notification and remedial action where applicable.
Retention and deletion
SonSec keeps personal information only for as long as reasonably necessary for the purpose for which it was collected, for related support and warranty purposes, for accounting and legal record-keeping, for dispute handling, for safety and security records, or where required or permitted by law. Retention periods may differ for enquiries, quotations, invoices, service histories, photographs, technical records and legal records.
When information is no longer required, SonSec will delete, de-identify or archive it in a manner appropriate to the record and business system involved.
Direct marketing
SonSec may communicate with existing customers about related services, maintenance, repairs, upgrades or support where permitted by law. Electronic direct marketing based on consent will be handled according to applicable POPIA requirements. Recipients may ask SonSec to stop direct marketing communication.
Your rights
Data subjects may have rights under POPIA to request access to personal information, request correction or deletion of inaccurate or unnecessary information, object to certain processing, withdraw consent where processing is based on consent, and complain to SonSec or the Information Regulator.
Requests must include enough information for SonSec to identify the requester, the relevant record and the request being made. SonSec may need to verify identity or authority before disclosing or changing information.
Complaints
Privacy questions or complaints should first be sent to SonSec using the contact details below. Complaints may also be directed to the Information Regulator of South Africa. Public contact information for the Information Regulator includes general enquiries at enquiries@inforegulator.org.za, POPIA complaints at POPIAComplaints@inforegulator.org.za, telephone 010 023 5200 and toll-free 0800 017 160.
Privacy contact details
Privacy, access, correction, objection or deletion requests may be sent to Son Security Systems (Pty) Ltd at info@sonsec.co.za or made by calling 011 436 0533.
Changes to this policy
SonSec may update this policy when its website, services, business processes, legal requirements or privacy practices change. The latest version published on this website applies from the stated effective date.