Home  /  Privacy Policy

Privacy Policy

This policy explains how Intelligent Tyre Systems (Pty) Ltd, trading as ITS, collects, uses, shares and protects personal information, and sets out your rights under the Protection of Personal Information Act, 2013 (POPIA).

Effective date: 6 August 2026 Last updated: 6 August 2026 Version: 1.0

1. Who we are

Intelligent Tyre Systems (Pty) Ltd, trading as ITS ("ITS", "we", "us" or "our"), is a South African technology solutions provider supplying retail-focused business systems and IT infrastructure, including IQ Retail ERP implementation and support, hosted services, managed services, hardware supply, Microsoft software support and VOIP services.

For the purposes of POPIA, ITS is the responsible party in respect of the personal information described in this policy.

The company was incorporated in 1994 and was subsequently renamed Intelligent Tyre Systems (Pty) Ltd. These changes are reflected in our CIPC records. The business has traded as ITS since 2013.

Intelligent Tyre Systems (Pty) Ltd
Registration number: 1994/000301/07
VAT number: 4710141377
Cnr Holliday & Shippard Street, Meyerton, 1961, Gauteng, South Africa
Telephone: +27 16 362 4011
Email: support@itstyre.co.za

2. Information Officer

In terms of POPIA, the head of ITS is the Information Officer of the company. The Information Officer is responsible for encouraging and ensuring our compliance with POPIA, dealing with requests made to us under POPIA and the Promotion of Access to Information Act, 2000 (PAIA), and working with the Information Regulator in relation to any investigation.

You may contact the Information Officer at support@itstyre.co.za or on +27 16 362 4011, or by post at the address in section 1. Please mark correspondence for the attention of the Information Officer.

3. Personal information we collect

Depending on your relationship with us, we may process the following categories of personal information:

CategoryExamples
Contact and identity informationName and surname, job title, employer, business telephone and mobile number, email address, physical and postal address.
Customer and account informationCompany name, registration and VAT numbers, account numbers, purchase orders, quotations, invoices, statements and payment records.
Support and technical informationSupport tickets, correspondence, call logs, remote-support session records, device and server names, IP addresses, system logs, error reports, licence and asset details.
CommunicationsEmails, telephone call records, WhatsApp and other messages exchanged with us, and their attachments.
Hosted and backup dataWhere you use our hosted server, hosted backup or managed services, the data stored in those environments may contain personal information belonging to you, your employees or your own customers.
Website informationLimited technical information generated when you visit our website, as described in section 14.

We do not deliberately collect special personal information (as defined in POPIA) or the personal information of children, and we ask that you do not send such information to us unless we have specifically requested it and a lawful basis exists.

Data held on your behalf. Where we host, back up, monitor or support systems containing personal information that belongs to your business, you remain the responsible party for that information and ITS acts as an operator processing it on your instruction. We process such information only as needed to provide the agreed services, and we treat it as confidential.

4. How we collect personal information

We collect personal information:

  • directly from you, when you contact us, request a quotation, place an order, log a support call, message us on WhatsApp, or enter into an agreement with us;
  • automatically, through the systems, devices and services we implement, host, monitor or support for you;
  • from your colleagues or representatives, where they provide your details in the course of dealing with us;
  • from third parties such as our suppliers, software vendors and credit or verification providers, where relevant and lawful; and
  • from publicly available sources, such as company registries and business websites.

Where personal information is not collected directly from you, the source will generally be one of those listed above.

5. Why we process personal information

We process personal information for the following purposes:

  • to respond to enquiries and provide quotations;
  • to conclude and perform our agreements with you, including implementation, training, support and managed services;
  • to supply, license, install and support software, hardware, hosting, backup and VOIP services;
  • to monitor, maintain, troubleshoot and secure the systems we support;
  • to administer accounts, billing, invoicing, payments and credit control;
  • to communicate with you about service issues, maintenance, incidents and renewals;
  • to keep records required for accounting, tax and audit purposes;
  • to protect our systems and those of our clients against fraud, unauthorised access and other security threats;
  • to comply with applicable law and to establish, exercise or defend legal claims; and
  • where you have agreed, to send you information about our services.

We do not sell personal information, and we do not use it for automated decision-making that produces legal consequences for you.

6. Lawful basis for processing

We process personal information only where POPIA permits it. Depending on the circumstances, we rely on one or more of the following:

  • Contract — processing is necessary to conclude or perform an agreement with you.
  • Legal obligation — processing is necessary to comply with a law binding on us, such as tax and companies legislation.
  • Legitimate interests — processing is necessary to pursue our legitimate interests, or those of our clients or a third party, such as securing systems, preventing fraud and recovering amounts owed.
  • Consent — where we have asked for and you have given consent, for example to receive marketing communications. You may withdraw consent at any time.

7. Whether supply is voluntary or mandatory

Supplying personal information to us is generally voluntary. However, certain information is necessary for us to conclude an agreement with you, deliver services, invoice correctly, or comply with the law.

If you choose not to provide that information, we may be unable to respond to your enquiry, provide a quotation, supply or support the relevant products and services, or continue with an existing engagement. Where information is required by law, we will tell you at the time of collection.

8. WhatsApp and messaging channels

ITS may communicate with clients over WhatsApp using the WhatsApp Business Platform, alongside telephone, email and our support channels.

  • We use WhatsApp to respond to enquiries, provide support updates, confirm appointments and send service-related notifications.
  • When you message us on WhatsApp, we receive and store your mobile number, your WhatsApp profile name, the content of your messages and any attachments you send.
  • Messages sent through this channel are transmitted and processed by WhatsApp Ireland Limited and Meta Platforms, Inc., and are subject to WhatsApp's own privacy policy in addition to this one. Our messaging is also routed through our communications provider, Twilio Inc.
  • You may opt out of WhatsApp communications at any time by replying "STOP" or by telling us in writing, and we will use an alternative channel.
  • Please do not send us banking credentials, passwords, identity document copies or other sensitive information over WhatsApp. If we need such information, we will arrange a secure method.

9. Who we share personal information with

We do not sell or rent personal information. We may share it with the following categories of recipient, only as far as necessary:

  • Software vendors and licensors, including IQ Retail and Microsoft, for licensing, registration, escalation and support purposes.
  • Managed services and data protection providers, including N-able and Redstor, whose platforms we resell and use to deliver endpoint management, monitoring, backup and recovery.
  • Hosting, connectivity and communications providers, including our data centre, VOIP and messaging providers such as Twilio and WhatsApp/Meta.
  • Professional advisors, such as our accountants, auditors, insurers and attorneys.
  • Payment providers and financial institutions, for processing payments and collections.
  • Regulators, courts and law enforcement, where we are legally required or permitted to disclose.
  • Acquirers, in the event of a sale, merger or restructuring of our business, subject to appropriate confidentiality protections.

Where we appoint an operator to process personal information on our behalf, we require it in writing to maintain appropriate confidentiality and security safeguards, and to process the information only for the agreed purposes.

10. Cross-border transfers

Some of the service providers we use — including cloud, backup, messaging and software vendors — process or store information outside South Africa, for example in the European Union, the United Kingdom or the United States.

Where we transfer personal information across borders, we do so in accordance with section 72 of POPIA. This means the transfer will be subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection substantially similar to POPIA, or the transfer will be necessary to perform a contract with you or in your interest, or you will have consented.

11. How we protect personal information

We take appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information, and unlawful access to or processing of it. These measures include:

  • access controls, unique user accounts and role-based permissions;
  • endpoint protection, patching and monitoring, including through the managed-services platforms we resell;
  • encrypted and tested backup and recovery arrangements;
  • secured remote-support tools and confidentiality obligations for our staff; and
  • periodic review of our safeguards in light of accepted information security practice.

No system can be guaranteed completely secure. If a security compromise affecting your personal information occurs, we will notify you and the Information Regulator as required by section 22 of POPIA.

12. How long we keep personal information

We keep personal information only for as long as necessary for the purpose it was collected, unless a longer period is required or permitted by law, or you have consented to longer retention.

  • Accounting, tax and company records are generally retained for at least five years, as required by South African law.
  • Contracts and related correspondence are generally retained for the duration of the engagement and for a period afterwards to allow for legal claims.
  • Support records and system logs are retained for as long as they remain operationally useful.
  • Hosted and backup data is retained according to the retention period agreed with you for that service.

When personal information is no longer required, we delete, destroy or de-identify it in a manner that prevents its reconstruction.

13. Your rights

Subject to POPIA and the Promotion of Access to Information Act, 2000 (PAIA), you have the right to:

  • be notified that we are collecting personal information about you, and that it has been accessed or acquired by an unauthorised person;
  • request confirmation of whether we hold personal information about you, and to request access to it;
  • request that we correct, update, or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully;
  • request that we destroy or delete a record of personal information that we are no longer authorised to retain;
  • object, on reasonable grounds, to the processing of your personal information;
  • object at any time to processing for direct marketing purposes;
  • withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal; and
  • lodge a complaint with the Information Regulator, and to institute civil proceedings regarding an alleged breach of POPIA.

To exercise any of these rights, contact our Information Officer using the details in section 2. Requests for access or correction should be made on the prescribed forms under POPIA and PAIA. We may need to verify your identity before acting on a request, and a prescribed fee may apply to access requests. We will respond within a reasonable period.

14. Our website and cookies

Our website is a simple informational site. It does not require you to create an account, and it does not run advertising or third-party analytics tracking.

Our hosting provider processes limited technical information as part of delivering the site securely, such as your IP address, browser type and the pages requested. This is used for security, availability and aggregate traffic purposes.

Our contact page embeds a Google Maps frame so you can find our offices. When that map loads, Google may set cookies and receive information about your visit, in accordance with Google's privacy policy. If you follow links to third-party websites, this policy no longer applies and you should review the policy of that site.

15. Complaints

If you are unhappy with how we have handled your personal information, please raise it with our Information Officer first so that we can try to resolve it directly.

You also have the right to lodge a complaint with the Information Regulator of South Africa:

The Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Telephone: 010 023 5200  |  Toll free: 0800 017 160
Website: inforegulator.org.za

16. Changes to this policy

We may update this policy from time to time to reflect changes in our services, our systems or the law. The current version will always be available on this page, with the effective date shown at the top. Where changes are material, we will take reasonable steps to bring them to your attention.

17. Contact us

If you have any questions about this policy or about how we handle personal information, please contact us:

Intelligent Tyre Systems (Pty) Ltd t/a ITS
Attention: The Information Officer
Cnr Holliday & Shippard Street, Meyerton, 1961, Gauteng, South Africa
Telephone: +27 16 362 4011
Fax: +27 86 675 8341
Email: support@itstyre.co.za