Privacy Policy

Privacy Policy

How Braveheart Analytics & Consulting collects, uses, protects and manages personal information.

Effective date: 15 August 2026. This Privacy Policy governs the collection and processing of personal information by Braveheart Analytics & Consulting (“Braveheart”, “we”, “us” or “our”) when you use this website, contact us, enquire about our services or engage us to provide analytics, consulting or Dashboard as a Service (DaaS) offerings. We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African law.

1. Our role and commitment

Braveheart is the responsible party for personal information that we collect directly through this website and in the ordinary course of providing our services. We will process personal information lawfully, reasonably and transparently, and only for a specific, legitimate purpose.

2. Information we may collect

Depending on how you engage with us, this may include your name, business contact details, job title, company, communications with us, service requirements, website usage data, and information needed to prepare proposals, deliver services or manage our relationship with you.

3. Why we use your information

We use personal information to respond to enquiries; arrange meetings; provide, support and improve our services; manage contracts and invoices; communicate relevant service information; protect our website and systems; and comply with legal, regulatory or professional obligations.

4. Lawful basis for processing

We process information where it is necessary to take steps at your request, perform a contract, comply with a legal obligation, pursue a legitimate business interest that does not override your rights, or where you have provided consent. You may withdraw consent at any time, subject to lawful processing already undertaken.

5. DaaS and customer data

When Braveheart processes personal information on behalf of a DaaS or consulting customer, that customer remains responsible for determining the purpose and means of processing. Braveheart will act only on documented instructions, subject to the applicable agreement and required law. Project-specific data-processing, security and retention terms may supplement this policy.

6. Sharing and service providers

We do not sell personal information. We may disclose information to carefully selected providers who help us host systems, communicate, deliver services, secure our environment or meet professional obligations. Those parties may process information only for the authorised purpose and must apply appropriate confidentiality and security measures.

7. International transfers

Some technology providers may process information outside South Africa. Where this occurs, we will take reasonable steps to ensure that the recipient is subject to laws, binding corporate rules or agreements that provide an adequate level of protection, as required by POPIA.

8. Retention

We retain personal information only for as long as it is needed for the purpose for which it was collected, to meet contractual, legal, accounting or dispute-resolution requirements, or to establish, exercise or defend legal claims. Information is then securely deleted or anonymised where appropriate.

9. Security

We use reasonable technical and organisational safeguards designed to protect personal information against loss, unauthorised access, disclosure, alteration or destruction. No electronic transmission or storage method is completely secure; if we become aware of a material security compromise, we will respond in accordance with applicable law.

10. Cookies and website analytics

Our website may use essential cookies and limited analytics technologies to operate, protect and improve the site. You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.

11. Your rights

Subject to applicable law, you may request access to, correction of or deletion of your personal information; object to certain processing; request restriction; withdraw consent; or lodge a complaint. We may require reasonable proof of identity before responding.

To exercise a right, please use our Contact page.

12. Marketing communications

We will not send direct electronic marketing unless permitted by law. You may opt out of marketing communications at any time by following the unsubscribe instruction in the communication or contacting us through the Contact page.

13. Children’s information

Our services and website are intended for business users and are not directed at children. We do not knowingly collect personal information from children without the required authorisation.

14. Changes to this policy

We may update this policy when our practices, services or legal requirements change. The current version will be published on this page with its effective date. Continued use of the website after an update is subject to the revised policy.

Legal notice. This policy is intended to explain our privacy practices and forms part of the terms on which we operate this website and interact with you. It does not limit any rights you have under POPIA or other applicable law. Where a written agreement with Braveheart contains specific privacy or data-processing provisions, that agreement will apply to the extent of any inconsistency.

Privacy contact and complaints

For privacy requests or concerns, please contact Braveheart through our Contact page. You may also lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za.