Legal & Compliance

Privacy &Compliance

Astrium Software Solutions CC is committed to protecting your personal information and complying with South African data protection legislation.

Privacy Policy

Effective date: 27 March 2026 · Last updated: 27 March 2026

This Privacy Policy explains how Astrium Software Solutions CC ("Astrium", "we", "us", or "our") collects, uses, stores, and protects personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").

1. Information Officer

Our designated Information Officer responsible for POPIA compliance is:

Name: Corne Beukes

Email: cornebeukes@astrium.co.za

Phone: 083 632 4281

2. What Personal Information We Collect

Depending on how you interact with us, we may collect:

  • Website visitors: Name, email address, phone number, and message content submitted via our contact form.
  • Astrium Connect users: Account registration details (name, email, password), organisation name, team member details, contact databases you upload or create, conversation content between you and your customers, payment and billing information.

3. Purpose of Processing

We process personal information for the following purposes:

  • Providing and maintaining our software products and services
  • Processing payments and managing subscriptions
  • Responding to enquiries submitted through our website
  • Sending service-related communications (account notifications, security alerts)
  • Improving our products and user experience
  • Complying with legal and regulatory obligations

4. Legal Basis for Processing

We process personal information on the following grounds as permitted by POPIA:

  • Consent: Where you have given us explicit consent (e.g. submitting a contact form)
  • Contract: Where processing is necessary to perform our obligations under a service agreement
  • Legal obligation: Where we are required to process information by law
  • Legitimate interest: Where processing is necessary for our legitimate business interests, provided your rights are not overridden

5. Third-Party Processors

We may share personal information with the following categories of third-party service providers, all of whom are contractually bound to protect your data:

  • Formspree: Contact form submissions
  • Netcash: Payment processing (South Africa)
  • Meta (WhatsApp Cloud API): Message delivery for Astrium Connect
  • Telegram: Message delivery for Astrium Connect
  • OpenAI / Anthropic: AI bot processing for Astrium Connect (when enabled by the customer)
  • Cloud infrastructure providers: Hosting and data storage

6. Cross-Border Transfers

Some of our third-party processors may store or process data outside South Africa. Where this occurs, we ensure that adequate safeguards are in place as required by Section 72 of POPIA, including contractual protections and ensuring the recipient country has adequate data protection laws or the transfer falls within a POPIA exemption.

7. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:

  • Contact form submissions: Retained for up to 12 months after the enquiry is resolved
  • Active account data: Retained for the duration of your subscription plus 90 days
  • Conversation data: Retained for the duration of your subscription; deleted within 90 days of account closure
  • Payment records: Retained for 5 years as required by tax legislation

8. Your Rights Under POPIA

As a data subject, you have the right to:

  • Access: Request confirmation of what personal information we hold about you
  • Correction: Request that inaccurate or incomplete information be corrected
  • Deletion: Request that your personal information be deleted where it is no longer necessary
  • Object: Object to the processing of your personal information on reasonable grounds
  • Data portability: Request your personal information in a structured, machine-readable format
  • Withdraw consent: Withdraw previously given consent at any time
  • Complaint: Lodge a complaint with the Information Regulator if you believe your rights have been infringed

To exercise any of these rights, contact our Information Officer at cornebeukes@astrium.co.za. We will respond within 30 days.

9. Security Measures

We implement appropriate technical and organisational measures to protect personal information, including:

  • AES-256-GCM encryption for sensitive tokens and credentials
  • HMAC SHA-256 webhook signature verification
  • PostgreSQL Row-Level Security for tenant data isolation
  • Role-based access control across all systems
  • JWT-based authentication with secure token handling
  • Regular security reviews and updates

10. Data Breach Notification

In the event of a personal information breach that poses a risk to data subjects, we will:

  • Notify the Information Regulator as soon as reasonably possible
  • Notify affected data subjects as required by Section 22 of POPIA
  • Take immediate steps to contain and remediate the breach

11. Cookies and Analytics

Our website uses localStorage to remember your theme preference (light/dark mode). We do not use tracking cookies or third-party analytics on this website.

12. Children's Information

Our services are not directed at children under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via our website. The "Last updated" date at the top of this policy indicates when it was last revised.

Promotion of Access to Information Manual

As required by Section 51 of the Promotion of Access to Information Act 2 of 2000

1. Introduction

The Promotion of Access to Information Act 2 of 2000 ("PAIA"), previously known as PROATIA, gives effect to the constitutional right of access to information held by private bodies. This manual is compiled in compliance with Section 51 of PAIA and describes the records held by Astrium Software Solutions CC and the process for requesting access to them.

2. Company Details

Registered Name: Astrium Software Solutions CC

Registration Number: 2002/061588/23

Information Officer: Corne Beukes

Email: cornebeukes@astrium.co.za

Phone: 083 632 4281

Website: www.astrium.co.za

3. South African Human Rights Commission Guide

The South African Human Rights Commission ("SAHRC") has compiled a guide in terms of Section 10 of PAIA. This guide is available from:

Phone: 011 877 3600

Email: inforeg@justice.gov.za

Website: www.justice.gov.za/inforeg

4. Applicable Legislation

The company holds records in accordance with the following legislation, among others:

  • Basic Conditions of Employment Act 75 of 1997
  • Companies Act 71 of 2008
  • Compensation for Occupational Injuries and Diseases Act 130 of 1993
  • Consumer Protection Act 68 of 2008
  • Electronic Communications and Transactions Act 25 of 2002
  • Employment Equity Act 55 of 1998
  • Income Tax Act 58 of 1962
  • Insurance Act 18 of 2017
  • Labour Relations Act 66 of 1995
  • Occupational Health and Safety Act 85 of 1993
  • Protection of Personal Information Act 4 of 2013
  • Skills Development Act 97 of 1998
  • Skills Development Levies Act 9 of 1999
  • Unemployment Contributions Act 4 of 2002
  • Unemployment Insurance Act 63 of 2001
  • Value-Added Tax Act 89 of 1991

5. Records Held by the Company

CategoryRecordsAvailability
Company SecretarialIncorporation documents, member detailsAutomatically available
FinancialFinancial statements, tax records, banking detailsNot automatically available
EmploymentEmployee contracts, personnel records, leave records, payrollNot automatically available
Company PoliciesInternal policies, external policies (clients/third parties)External policies automatically available
AgreementsClient contracts, supplier contracts, service agreementsNot automatically available
Customer InformationCustomer details, contact information, communicationsNot automatically available
Product DataAstrium Connect conversation records, contact databases, broadcast logs, API usage logsNot automatically available
RegulatoryPermits, licences, POPIA compliance recordsNot automatically available
MarketingBrochures, website content, promotional materialAutomatically available

6. How to Request Access to a Record

To request access to a record held by Astrium Software Solutions CC:

  1. Complete the prescribed Form C (available from the Information Regulator website at www.justice.gov.za/inforeg)
  2. Submit the completed form to our Information Officer via email at cornebeukes@astrium.co.za
  3. Pay the applicable request fee (see Fee Schedule below)

Your request must clearly identify the record(s) sought and the right you are seeking to exercise or protect.

7. Decision and Notification

You will be notified in writing within 30 days of receipt of a completed request form whether access has been granted or refused. PAIA provides for refusal of access on the following grounds:

  • Protection of the privacy of a third party
  • Protection of commercial information of a third party
  • Protection of confidential information
  • Safety of individuals or protection of property
  • Records privileged from production in legal proceedings
  • Research information of a third party

If access is refused, you will be informed of the reasons and your right to lodge an application with a court against the refusal.

8. Fee Schedule

ItemFee
Request fee (non-personal requesters)R50.00
Search fee (per hour or part thereof)R30.00
Photocopy of A4 pageR1.80
Printed copy from computer (A4 page)R0.75
Copy on compact discR70.00
Transcription of visual images (per A4 page)R40.00
Copy of visual imagesR60.00
Transcription of audio record (per A4 page)R20.00
Copy of audio recordR30.00

A deposit of one third of the access fee is payable if the search requires more than six hours. Personal requesters (requesting their own personal information) are exempt from the request fee.

9. Information Regulator

If you are not satisfied with the outcome of your request, you may lodge a complaint with the Information Regulator:

Phone: 012 406 4818

Email: inforeg@justice.gov.za

Website: www.justice.gov.za/inforeg

Download PAIA Manual (PDF)

The full PAIA Section 51 manual is available for download.

Download PDF