1. Introduction
This Privacy Policy explains how Datenhafen NivaCity (Pty) Ltd, trading as NivaCity (“NivaCity”, “we”, “us” or “our”), collects, uses, stores, shares and protects Personal Information when you visit our websites, register an account, buy or use our hosting, domain and related services, or otherwise interact with us (collectively, the “Services”).
We are committed to handling Personal Information lawfully, transparently and securely. This Policy is designed to meet the requirements of the Protection of Personal Information Act 4 of 2013 (POPIA), the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR, the data protection laws of Zimbabwe and Botswana, the Electronic Communications and Transactions Act 25 of 2002 (ECTA), the CAN-SPAM Act of 2003 and other applicable privacy laws in the jurisdictions where our customers are located.
This Policy forms part of, and should be read together with, our Terms of Service, including the Acceptable Use Policy in section 6 of the Terms. By using the Services, you acknowledge that you have read and understood this Policy.
2. Who we are
For the purposes of POPIA, NivaCity is the Responsible Party. For the purposes of GDPR, NivaCity is the Data Controller for Personal Information we collect about our own customers and website visitors.
Where you use our Services to host, store or process Personal Information belonging to your own end users (for example, visitors to a website you host with us), you are the Responsible Party or Data Controller for that data, and NivaCity acts as an Operator or Data Processor on your instructions. Section 12 describes this relationship.
All privacy enquiries, data subject requests and correspondence for our Information Officer should be sent to:
Email: [email protected]
3. Definitions
“Personal Information” or “Personal Data” means any information relating to an identified or identifiable natural person and, where applicable under POPIA, an identifiable juristic person.
“Processing” means any operation performed on Personal Information, including collection, recording, storage, use, disclosure, transfer, restriction and deletion.
“Data Subject” means the natural or juristic person to whom Personal Information relates.
“Responsible Party” or “Data Controller” means the entity that determines the purpose and means of Processing.
“Operator” or “Data Processor” means an entity that Processes Personal Information on behalf of a Responsible Party.
“Services” has the meaning given in the Terms of Service.
4. Information we collect
4.1 Information you provide directly
When you register an account, place an order, submit a support ticket or contact us, we may collect:
- (a) Identity and contact details: full name, company name, email address, telephone number, and physical and postal address;
- (b) Account credentials: username, password (stored in hashed form), security questions and two-factor authentication settings;
- (c) Billing information: billing address, tax or VAT number where applicable, and payment method details. Card numbers are entered directly into our payment gateway and are not stored in full on NivaCity systems;
- (d) Domain registration details: registrant, administrative and technical contact information required by domain registries and ICANN;
- (e) Support communications: the content of tickets, emails and WhatsApp messages, together with any attachments you provide;
- (f) Identity verification documents, where we are required by law, a registry or a payment provider to verify your identity.
4.2 Information collected automatically
When you visit our websites or use the Services, our systems automatically record:
- (a) IP address, browser type and version, operating system, device identifiers and referring URLs;
- (b) date, time and duration of access, pages viewed and actions taken within the client portal;
- (c) server, access, error and mail logs generated by the hosting infrastructure, which may include your IP address and the IP addresses of visitors to services you host;
- (d) cookies and similar technologies, as described in section 8.
4.3 Information from third parties
We may receive limited information about you from payment processors (for example, payment confirmations and fraud screening results), domain registries (WHOIS and registration status) and fraud prevention services.
4.4 Special Personal Information
We do not intentionally collect special personal information as defined in POPIA, or special categories of data under GDPR (such as health, religious, biometric or political information). Please do not send us such information unless it is necessary for a specific request you have made.
5. How we use your information
We Process Personal Information for the following purposes:
- (a) Providing the Services: creating and administering your account, provisioning hosting and domains, delivering support and maintaining service continuity;
- (b) Billing and payments: issuing invoices, processing payments, managing renewals, recovering outstanding amounts and preventing fraud;
- (c) Legal and regulatory compliance: meeting domain registry and ICANN requirements, tax and accounting obligations, and responding to lawful requests from authorities;
- (d) Security: detecting, investigating and preventing abuse, spam, malware, unauthorised access and breaches of our Acceptable Use Policy;
- (e) Service communications: sending transactional and operational notices such as invoices, renewal reminders, maintenance alerts, security notifications and replies to your enquiries, by email and, where you have chosen it, by WhatsApp;
- (f) Marketing: sending promotional communications where you have opted in, and measuring their effectiveness;
- (g) Improvement: analysing usage patterns to improve our websites, Services and customer experience.
6. Lawful basis for processing
We rely on the following lawful bases under POPIA, GDPR and other applicable laws:
- (a) Contract: Processing necessary to perform the contract between you and NivaCity, including account administration, service provisioning and billing;
- (b) Legal obligation: Processing required to comply with tax, accounting, domain registry, anti-fraud and law enforcement obligations;
- (c) Legitimate interests: Processing necessary for our legitimate business interests, including securing our infrastructure, preventing abuse, improving the Services and administering our business, provided those interests are not overridden by your rights;
- (d) Consent: where we rely on consent, for example for marketing communications and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of earlier Processing.
7. Service and marketing communications
7.1 Service communications
By registering an account, you agree to receive service and transactional communications by email. These are necessary for the operation of your account and cannot be opted out of while your account remains active.
7.2 Marketing communications
Marketing communications are strictly opt-in. We only send promotional messages where you have actively chosen to receive them. Every marketing email will:
- (a) clearly identify NivaCity as the sender;
- (b) be identifiable as a commercial communication;
- (c) include a working unsubscribe link;
- (d) honour unsubscribe requests within 10 business days, and in practice immediately.
This applies in line with the CAN-SPAM Act, section 45 of ECTA, section 69 of POPIA and the GDPR ePrivacy rules.
To unsubscribe, use the link at the bottom of any marketing email or contact [email protected].
8. Cookies and tracking technologies
8.1 What we use
Our websites and client portal use cookies and similar technologies for:
- (a) Strictly necessary purposes: session management, authentication, shopping cart operation and security. These cannot be disabled without affecting how the site works;
- (b) Preferences: remembering language, currency and display settings;
- (c) Analytics: understanding how visitors use our websites so that we can improve them.
8.2 Google Analytics
We use Google Analytics to compile aggregate statistics about website traffic. Google Analytics uses cookies and may collect your IP address and usage data. IP anonymisation is enabled where the platform supports it. Where the law requires consent, including for visitors in the EEA and the United Kingdom, analytics cookies are only set after you agree to them. Google processes this data under its own privacy policy, available at https://policies.google.com/privacy. You can opt out using the Google Analytics browser add-on at https://tools.google.com/dlpage/gaoptout.
8.3 Managing cookies
You can control or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent you from logging in or completing orders.
9. Where your data is stored and international transfers
9.1 Infrastructure
Our core systems, including our billing platform, client portal, hosting servers and mail servers, are operated and administered in-house by NivaCity. The service providers described in section 10 support specific functions, such as website delivery, backup storage, email delivery and messaging, and receive only the information they need for that function.
Our infrastructure is located in data centre facilities in the following countries:
- Germany
- South Africa
- United States
- Finland
- Austria
- France
Data centre facility providers supply physical hosting, power and network connectivity only. They do not have logical access to the data stored on our servers.
9.2 Cross-border transfers
Because our infrastructure and service providers span multiple jurisdictions, your Personal Information may be stored in, or transferred between, the countries listed above and the countries where our service providers operate, depending on the service you buy and the location of the server assigned to you.
Where Personal Information originating in the European Economic Area or the United Kingdom is transferred to a country not recognised as providing adequate protection, we rely on the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, together with supplementary technical measures.
Where Personal Information originating in South Africa is transferred outside South Africa, we do so in compliance with section 72 of POPIA, on the basis that the recipient is bound by contractual or legal obligations providing substantially similar protection, or that the transfer is necessary to perform your contract with us. We apply equivalent safeguards to transfers governed by the data protection laws of Zimbabwe and Botswana.
10. Disclosure to third parties
We do not sell, rent or trade Personal Information. We disclose Personal Information only in the following circumstances:
- (a) Service providers acting on our behalf, who receive only the information needed for their function and are bound by confidentiality and data protection obligations:
- Cloudflare, for website delivery, security, access control and image storage, which involves processing visitors’ IP addresses and request data;
- an S3-compatible cloud storage provider, for storing offsite backups, including backups of VPS servers where you have purchased a backup service;
- an outbound email relay provider, for delivering email sent from our mail servers;
- Twilio and Meta, for sending and receiving WhatsApp messages;
- Google, for website analytics, as described in section 8;
- trusted contractors who carry out work on our behalf, such as development and technical work, under confidentiality obligations;
- (b) Payment processors: to process payments, refunds and fraud checks. Payment processors act as independent controllers of the payment data they receive;
- (c) Domain registries and registrars: registrant and contact details are sent to the relevant registry (and, for some domain extensions, published in WHOIS or RDAP) as required by ICANN and registry policy. Some registries are located outside your country;
- (d) Professional advisers: auditors, accountants and legal advisers under obligations of confidentiality;
- (e) Legal requirements: where required by law, court order, subpoena or lawful request from a competent authority in any jurisdiction where we operate infrastructure;
- (f) Protection of rights: where necessary to enforce our Terms of Service and Acceptable Use Policy, investigate abuse, or protect the rights, property or safety of NivaCity, our customers or the public;
- (g) Business transfers: in connection with a merger, acquisition or sale of assets, subject to the acquiring party taking on the obligations in this Policy.
Apart from the providers listed above, we do not use external CRM, ticketing or email marketing providers to process customer data.
11. Data retention
We keep Personal Information only for as long as necessary for the purposes described in this Policy, in line with the following periods:
- (a) Account and billing records: 5 years from the date of account closure, to meet tax, accounting and legal obligations;
- (b) Support tickets and correspondence: 5 years from closure of the ticket;
- (c) Server and access logs: kept for security and operational purposes for a limited rolling period, after which they are automatically overwritten or deleted;
- (d) Hosted data on terminated accounts: NivaCity does not keep backups of terminated accounts. On termination, and after the 7 day grace period set out in the Terms of Service, all hosted data, email and databases are permanently deleted and cannot be recovered. You are responsible for retrieving your data before termination;
- (e) Marketing consent records: for as long as you remain subscribed, plus a further period long enough to evidence the withdrawal of consent.
Where information is no longer required, we delete it or irreversibly anonymise it.
12. Data you host with us (processor relationship)
12.1 Your responsibilities
If you collect Personal Information from your own customers, visitors or users through websites, applications, databases or email hosted on NivaCity infrastructure, you are the Responsible Party or Data Controller for that data. You are responsible for:
- (a) having a lawful basis for collecting and processing it;
- (b) providing your own privacy notice to your users;
- (c) responding to data subject requests from your users;
- (d) implementing appropriate security within your website or application, including keeping software and plugins updated;
- (e) complying with any cross-border transfer requirements that apply to your users, taking into account the server location assigned to you.
12.2 NivaCity’s role
NivaCity acts as an Operator or Data Processor for such data and will:
- (a) process it only to provide the Services and as instructed by you through your use of the Services;
- (b) not access the content of your hosted data except where necessary for support, security, abuse investigation or as required by law;
- (c) use the service providers described in section 10 only where needed to provide the Services, such as offsite backups and email delivery;
- (d) implement the technical and organisational security measures described in section 13;
- (e) notify you without undue delay if we become aware of a security breach affecting your hosted data;
- (f) delete the data on termination of your account in line with section 11.
12.3 Data Processing Agreement
Customers subject to GDPR who need a Data Processing Agreement under Article 28 may request one by contacting [email protected].
13. How we protect your information
We apply appropriate technical and organisational measures to protect Personal Information against loss, unauthorised access, disclosure, alteration and destruction, including:
- (a) encryption of data in transit using TLS across all websites, the client portal, mail services and control panels;
- (b) hashed storage of account passwords;
- (c) card data handled exclusively by PCI DSS compliant payment gateways, with no full card numbers stored on NivaCity systems;
- (d) server hardening, firewalling, intrusion detection and malware scanning across the hosting fleet;
- (e) role-based access controls, with administrative access limited to authorised NivaCity personnel;
- (f) logging and monitoring of administrative and system activity;
- (g) regular security updates and patching of infrastructure.
No system is completely secure. You are responsible for choosing a strong password, enabling two-factor authentication where available, and keeping your credentials confidential.
14. Data breach notification
If we become aware of a security compromise that affects Personal Information, we will:
- (a) notify the Information Regulator of South Africa as soon as reasonably possible, as required by section 22 of POPIA;
- (b) notify the relevant EU or UK supervisory authority within 72 hours of becoming aware of the breach, where required by GDPR;
- (c) notify any other supervisory authority where required by applicable law, including in Zimbabwe and Botswana;
- (d) notify affected Data Subjects by email and by notice in the client portal within 7 working days of confirming the breach, or sooner where the breach presents a high risk to their rights;
- (e) provide enough information to allow you to take protective measures, including the nature of the breach, the data affected and the steps we have taken.
15. Your rights
Subject to applicable law, you have the right to:
- (a) Access: ask whether we hold Personal Information about you and obtain a copy of it;
- (b) Correction: ask for inaccurate or incomplete Personal Information to be corrected;
- (c) Deletion: ask for your Personal Information to be deleted where it is no longer necessary, where you withdraw consent, or where Processing is unlawful, subject to our legal retention obligations;
- (d) Restriction: ask us to restrict Processing in certain circumstances;
- (e) Objection: object to Processing based on legitimate interests, and object at any time to direct marketing;
- (f) Portability: receive Personal Information you gave us in a structured, commonly used, machine-readable format, where Processing is based on contract or consent;
- (g) Withdraw consent: at any time, where Processing is based on consent;
- (h) Complain: lodge a complaint with a supervisory authority, including:
- The Information Regulator of South Africa: https://inforegulator.org.za
- The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), as Zimbabwe’s data protection authority
- The Information and Data Protection Commission of Botswana
- Your local EU data protection authority, or the UK Information Commissioner’s Office: https://ico.org.uk
To exercise any of these rights, contact [email protected]. We may need to verify your identity before acting on a request. We will respond within 30 days, or within any shorter period required by applicable law. We do not charge a fee for handling requests unless they are clearly unfounded or excessive.
Please note that we cannot delete information we are legally required to keep, and deleting account records may mean the Services have to end.
16. Age limit
The Services are intended for people aged 16 and over. Users under 18 need the consent of a parent or legal guardian, as set out in the Terms of Service. We do not knowingly collect Personal Information from anyone under 16. If we become aware that we have collected Personal Information from a person under 16 without appropriate parental or guardian consent, we will delete it. If you believe a minor has given us Personal Information, contact [email protected].
17. Third-party links
Our websites may contain links to third-party websites, including payment providers, registries and partners. This Policy does not apply to those websites, and we are not responsible for their privacy practices. We encourage you to read their privacy policies before giving them any information.
18. Automated decision-making
We may use automated systems for fraud screening when you place an order and for detecting abuse or security threats on our infrastructure. Where an automated decision has a significant effect on you, such as an order being declined, you may contact us to ask for a human review.
19. Changes to this policy
We may update this Policy from time to time to reflect changes in law, our Services or our practices. Where changes are material, we will notify you by email or by notice in the client portal at least 14 days before they take effect. The “Last updated” date at the top of this Policy shows when it was last revised. Continuing to use the Services after the effective date means you accept the revised Policy.
20. Contact us
For any questions, requests or complaints about this Policy or how we handle Personal Information, including Information Officer and data subject request enquiries, contact:
Datenhafen NivaCity (Pty) Ltd, trading as NivaCity
Email: [email protected]