Hozit Domain Hosting (Pty) Ltd respects privacy and processes personal information for legitimate business, contractual, security and legal purposes. This policy applies to our website, customer relationships, services, support channels and business operations.
1. About this Privacy Policy
This Privacy Policy explains how Hozit Domain Hosting (Pty) Ltd (“Hozit”, “we”, “us” or “our”) collects, receives, records, uses, shares, stores, protects and otherwise processes personal information.
This policy applies to personal information processed through our website, customer portals, quotations, orders, invoices, support systems, communications and technology services.
Separate customer agreements, service schedules, data-processing terms or written instructions may also apply to particular services.
2. Responsible party and company details
Hozit Domain Hosting (Pty) Ltd is the responsible party for personal information that it determines the purpose and means of processing.
Hozit Domain Hosting (Pty) LtdRegistration number: 2020/001667/07
VAT number: 4820276410
145 Second Street
Sandton, Johannesburg, 2196
South Africa
Email: info@hozit.co.za
Telephone: 010 226 9219
3. Scope of this policy
This policy may apply when you:
- visit or interact with the Hozit website;
- request a quotation, consultation or technical assessment;
- purchase or use a Hozit service;
- register or manage a domain, hosting account or mailbox;
- use a customer, CRM, support or service-management portal;
- contact Hozit by telephone, email, WhatsApp, web form or support ticket;
- apply for employment or submit professional information;
- act as a supplier, contractor, partner or business contact; or
- otherwise interact with Hozit in a business or service context.
4. Personal information we may collect
Depending on the relationship and service, we may process:
- names, surnames, identity and registration information;
- company names, job titles and business contact details;
- email addresses, telephone numbers and physical addresses;
- billing, invoicing, payment and transaction information;
- domain-registration and authorised-contact information;
- account usernames, customer numbers and authentication records;
- support requests, technical records and communication history;
- IP addresses, browser details, device information and access logs;
- website, email, server, network and service-usage information;
- call recordings where recording is enabled and legally permitted;
- CRM records, enquiry information and customer-service notes;
- supplier, contractor and partner information;
- employment applications, qualifications and work history; and
- other information reasonably required to deliver or support a service.
We aim to collect information that is adequate, relevant and not excessive for the purpose for which it is processed.
5. Sources of personal information
We may obtain personal information:
- directly from the person or organisation concerned;
- from an authorised representative, employee or account administrator;
- through our website, forms, support systems and customer portals;
- from communications by email, telephone, WhatsApp or other channels;
- from domain registries, technology suppliers and service providers;
- from public business registers and publicly available sources;
- from referral partners and legitimate business-introduction sources; or
- automatically through logs, cookies and security technologies.
6. How we use personal information
Personal information may be processed to:
- respond to enquiries and prepare quotations or proposals;
- verify customer, supplier or authorised-contact information;
- open, administer and secure customer accounts;
- register, transfer, renew and manage domains;
- provide hosting, email, cloud, software, support and related services;
- configure, monitor, maintain and secure supported systems;
- process orders, invoices, payments, renewals and account records;
- provide technical support and investigate service issues;
- communicate service, maintenance, billing and security notices;
- prevent fraud, abuse, cyber threats and unauthorised access;
- maintain operational, security and audit records;
- improve services, website performance and customer experience;
- manage suppliers, contractors, staff and business relationships;
- comply with legal, regulatory, tax and contractual obligations; and
- establish, exercise or defend legal rights.
7. Grounds for lawful processing
Depending on the circumstances, we may process personal information:
- with the consent of the data subject;
- to perform a contract or take steps requested before entering a contract;
- to comply with an obligation imposed by law;
- to protect a legitimate interest of the data subject;
- to pursue the legitimate interests of Hozit or a third party, where lawful; or
- where another lawful justification under applicable law permits processing.
Where processing is based on consent, consent may generally be withdrawn, subject to legal and contractual consequences and any continued lawful basis for processing.
8. Customer-controlled service data
Some Hozit services process information under the control and instructions of a customer. Examples may include hosted website data, mailboxes, CRM records, support databases, application data, call-centre information and cloud workloads.
In those circumstances, the customer may be the responsible party and Hozit may act as an operator that processes information according to the customer’s lawful instructions, the service agreement and applicable law.
Customers are responsible for ensuring that they have lawful authority to collect and submit personal information to Hozit-managed services.
9. Sharing and disclosure
We do not sell personal information as a commercial product.
Personal information may be shared where reasonably necessary with:
- authorised Hozit personnel and approved contractors;
- domain registries, registrars and internet-service providers;
- data-centre, hosting, cloud and backup providers;
- email, communication, VoIP and telecommunications providers;
- software vendors, licence providers and technology distributors;
- payment processors, banks, accountants and professional advisers;
- security, fraud-prevention and monitoring providers;
- couriers, delivery providers and equipment suppliers;
- regulators, courts, law-enforcement bodies or government authorities where lawfully required; or
- another party where the data subject has authorised disclosure.
Providers receiving personal information are expected to process it for authorised purposes and apply appropriate safeguards.
10. International processing and transfers
Some cloud, software, domain, email, security and infrastructure providers may process or store information outside South Africa.
Where personal information is transferred internationally, Hozit will take reasonable steps to ensure that the transfer is lawful and that appropriate contractual, organisational or legal safeguards apply.
11. Website cookies and analytics
The Hozit website may use cookies and similar technologies for:
- website functionality and session management;
- security, fraud prevention and traffic protection;
- remembering preferences;
- measuring website usage and performance;
- understanding how visitors navigate the website; and
- improving content, services and marketing effectiveness.
Browser settings may allow users to block or delete cookies. Disabling essential cookies may affect website functionality. Further information is available in the Cookie Policy.
12. Service and marketing communications
Hozit may send operational communications relating to quotations, accounts, billing, renewals, maintenance, support, security and active services.
Marketing communications will be sent in accordance with applicable law. A recipient may use the available unsubscribe facility or contact Hozit to request that optional marketing communication stops.
Unsubscribing from marketing does not prevent necessary service, security, account or transactional communications.
13. Information security
Hozit applies reasonable technical and organisational measures appropriate to the nature of the information and service. These may include:
- access restrictions and administrative controls;
- password and authentication controls;
- firewalls, filtering and network-security measures;
- encryption where supported and appropriate;
- logging, monitoring and security alerts;
- software updates, maintenance and vulnerability management;
- backup and recovery controls where included in the service;
- confidentiality obligations and staff awareness; and
- incident investigation and response procedures.
No system can be guaranteed completely secure. Customers must also protect credentials, devices, authorised users and systems under their control.
14. Security compromises
Where Hozit has reasonable grounds to believe that personal information under its control has been accessed or acquired by an unauthorised person, the incident will be investigated and handled in accordance with applicable legal, contractual and operational requirements.
Where Hozit acts as an operator for a customer, incident communication may be made to the customer so that the customer can fulfil its own obligations as responsible party.
15. Retention and deletion
Personal information is retained only for as long as reasonably required for the purpose for which it was collected, or as required by law, contract, tax, security, dispute or operational obligations.
Retention periods differ according to the information and service. Examples include:
- customer and contractual records retained for the relationship and applicable legal period;
- financial and tax records retained for statutory periods;
- support and technical records retained for operational and security purposes;
- logs retained according to platform capacity, security requirements and service configuration;
- backups retained according to the applicable backup schedule; and
- unsuccessful employment applications retained only for an appropriate period.
Information may be deleted, anonymised or securely disposed of when it is no longer required, subject to technical and legal limitations.
16. Information quality
We take reasonable steps to keep personal information accurate, complete and current where necessary for its purpose.
Customers and data subjects should notify Hozit when their contact, billing, authorised-user or account information changes.
17. Rights of data subjects
Subject to POPIA and other applicable law, a data subject may have the right to:
- request confirmation that Hozit holds personal information about them;
- request access to personal information;
- request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete or unlawfully obtained information;
- object to certain processing on reasonable grounds;
- withdraw consent where processing depends on consent;
- object to certain direct marketing;
- request information about the identity of authorised recipients where applicable; and
- lodge a complaint with the Information Regulator.
A request may be subject to identity verification, legal limitations, prescribed procedures and reasonable response periods.
Where information is controlled by a Hozit customer, the request may need to be directed to that customer as the responsible party.
18. Submitting a privacy request
Privacy and personal-information requests may be submitted to:
Information Officer / Privacy EnquiriesHozit Domain Hosting (Pty) Ltd
Email: info@hozit.co.za
Telephone: 010 226 9219
Address: 145 Second Street, Sandton, Johannesburg, 2196
The requester may be required to provide sufficient details and proof of identity to protect information against unauthorised disclosure.
19. Complaints to the Information Regulator
A person who believes that personal information has been processed in contravention of POPIA may lodge a complaint with the South African Information Regulator.
Current complaint procedures and official contact information are available from the Information Regulator: Information Regulator complaints portal.
20. Third-party websites and platforms
The Hozit website and services may link to or integrate with external websites, software and platforms. Those parties control their own privacy and security practices.
Users should review the applicable privacy terms before providing information directly to a third party.
21. Information relating to children
Hozit services are primarily directed at businesses and authorised adult users. We do not knowingly collect personal information from children without an appropriate lawful basis or the involvement of a competent person where required.
A person who believes that child-related information has been submitted improperly should contact Hozit for investigation.
22. Changes to this Privacy Policy
Hozit may update this policy to reflect changes in law, services, technology, suppliers or operational practices.
The updated policy will be published on this page with a revised effective or last-updated date. Material changes may also be communicated through appropriate customer channels.
23. Contact
Hozit Domain Hosting (Pty) Ltd145 Second Street
Sandton, Johannesburg, 2196
South Africa
Email: info@hozit.co.za
Telephone: 010 226 9219
This policy provides general information about Hozit privacy practices. Customer-specific contracts, operator agreements and lawful instructions may contain additional requirements.