Privacy Policy & POPIA Notice
✎ "Zero retail consumer exposure. Strict corporate veil separation under Companies Act Section 20(9)."
Protection of Personal Information Act (Act No. 4 of 2013) • Promotion of Access to Information Act (Act No. 2 of 2000) • Companies Act (Act No. 71 of 2008)
Effective Date: 14 July 2025 • Last Revised & Published: 01 October 2026 • Version 2.0
Statutory Responsible Party Particulars (Section 18 POPIA)
Official CIPC registered corporate identity under Companies Act 71 of 2008 & POPIA
Statutory Table of Contents • POPIA Sections
01. Legislative Framework & Definitions
This Statutory Privacy Policy and POPIA Compliance Manual constitutes the statutory disclosure of HORIZON STRATEGIC GROUP (PTY) LTD ("HSG", "the Holding Company", "the Responsible Party", "we", "us", or "our") pursuant to the provisions of:
- Section 14 of the Constitution of the Republic of South Africa, 1996 (the fundamental constitutional right to privacy);
- The Protection of Personal Information Act No. 4 of 2013 ("POPIA");
- The Promotion of Access to Information Act No. 2 of 2000 ("PAIA");
- The Companies Act No. 71 of 2008 (governing company records, director registers, and Section 45 financial assistance);
- The Electronic Communications and Transactions Act No. 25 of 2002 ("ECTA"); and
- The Cybercrimes Act No. 19 of 2020.
"Data Subject" means the person or juristic entity to whom personal information relates, including institutional investors, lenders, transaction advisors, and subsidiary directors.
"Personal Information" means information relating to an identifiable, living natural person or existing juristic person as defined in Section 1 of POPIA.
"Processing" means any operation or activity concerning personal information, including collection, receipt, recording, organization, storage, updating, retrieval, alteration, dissemination, and destruction.
"Responsible Party" means a public or private body or any other person which determines the purpose of and means for processing personal information.
02. Lawful Grounds & Justification for Processing
In terms of Section 11(1) of POPIA, Horizon Strategic Group processes personal information strictly and solely where one or more of the following lawful grounds apply:
- Statutory & Legal Obligation (Section 11(1)(c)): Processing is mandatory to comply with duties imposed by South African corporate legislation, including the Companies Act 71 of 2008 (maintaining shareholder registers, director declarations, beneficial ownership filings with CIPC), and the Tax Administration Act No. 28 of 2011.
- Performance of a Contract (Section 11(1)(b)): Processing is necessary for concluding or executing institutional shareholder compacts, intercompany commercial agreements, term sheets, or corporate financing facilities.
- Legitimate Interests of the Responsible Party (Section 11(1)(f)): Processing is necessary for capital allocation governance, conducting due diligence, maintaining virtual data room audit trails, and ensuring statutory corporate veil protection.
- Voluntary Consent (Section 11(1)(a)): Where explicit consent is granted by an authorized corporate representative submitting an institutional inquiry through our secure web portal.
03. Categories of Personal Information Collected
In strict compliance with the Principle of Minimality (Section 10 of POPIA), HSG collects only the information strictly required for holding company governance and institutional transactions:
A. Institutional Contact & Representative Particulars
Full names, corporate designation, institutional organization name, business email address, corporate telephone number, and message briefs submitted via our communications channel.
B. Statutory Board & Director Information
Identity numbers, passport numbers, dates of birth, residential and postal addresses, declarations of financial interest, and appointment resolutions for subsidiary directors and executive officers.
C. Transactional & Due Diligence Records
FICA / KYB verification records, beneficial ownership disclosure documentation, corporate constitutional instruments (MOIs), shareholder resolutions, Section 45 solvency/liquidity certifications, and intercompany service contracts.
D. Technical Server Telemetry
Anonymized, aggregate server access logs (IP address, browser user-agent, timestamp) collected by Truehost cPanel server infrastructure solely for web security, DDoS prevention, and routing verification.
04. Statutory Operating Boundary & Corporate Veil (Sec 20(9))
Statutory Boundary Invariant: Horizon Strategic Group (Pty) Ltd is an investment holding company. HSG does not provide direct consumer services, retail sales, or operational field support.
In accordance with Section 20(9) of the Companies Act 71 of 2008 (statutory veil protection), operational customer databases, field responder PII, and retail telemetry are strictly isolated within the respective operating subsidiaries:
- VaultCore Solutions (Pty) Ltd: Governs applied cryptography and software licensing under its independent POPIA and intellectual property protocols (vaultcore.co.za).
- Mind Haven Innovations (Pty) Ltd: Governs emergency dispatch control rooms, responder verifications, and public safety data under its independent POPIA customer notice (mindhaven.co.za).
05. Compliance with the 8 Conditions for Lawful Processing
Our governance architecture embeds the eight statutory conditions of Chapter 3 of POPIA:
1. Accountability (Section 8): The Information Officer ensures all compliance measures giving effect to the conditions of POPIA are actively audited.
2. Processing Limitation (Sections 9–12): Information is processed lawfully, minimally, and directly from institutional representatives or official regulatory registries.
3. Purpose Specification (Sections 13–14): Personal information is gathered exclusively for defined corporate governance and institutional transaction purposes.
4. Further Processing Limitation (Section 15): Any subsequent processing must be strictly compatible with the original fiduciary purpose.
5. Information Quality (Section 16): We take all reasonably practicable steps to ensure that company and governance records are accurate, complete, and up to date.
6. Openness (Sections 17–18): Direct disclosure of all processing operations, CIPC registration details, and Information Officer contacts provided herein.
7. Security Safeguards (Sections 19–22): Robust digital, operational, and organizational controls shielding data against unauthorized disclosure, loss, or corruption.
8. Data Subject Participation (Sections 23–25): Guaranteed statutory rights for data subjects to confirm, access, correct, or request deletion of personal records.
06. Institutional Due Diligence, FICA & KYB Verification
For prospective co-investors, institutional lenders, and transaction partners engaging in M&A or credit facilities:
FICA & KYB Verification: Authorized representatives submit corporate constitutional instruments, beneficial ownership disclosures, and director identities to satisfy anti-money laundering and FICA requirements.
Virtual Data Room ("VDR") Security: Due diligence access is granted exclusively under signed non-disclosure covenants, watermarked document delivery, and complete audit logging of access times and document downloads.
07. Authorized Operators & Cross-Border Transfers (Sec 72)
We do not sell, rent, or trade personal information to any third parties under any circumstances. Personal data is shared strictly with authorized service providers (Operators) performing essential infrastructure functions:
- Hosting & Server Infrastructure (Truehost / cPanel): Static web delivery and secure corporate email routing hosted on enterprise infrastructure in compliant data centres.
- Statutory & Legal Advisors: External corporate secretarial, auditing, and legal counsel engaged under binding professional confidentiality mandates.
- Cross-Border Safeguards (Section 72 POPIA): To the extent that cloud infrastructure is backed up across international nodes, transfers comply with Section 72(1)(a) of POPIA, ensuring that recipient jurisdictions provide substantially similar protection or are bound by corporate agreements.
08. Security Safeguards & Breach Protocol (Sec 19–22)
We enforce comprehensive technical, cryptographic, and operational security measures:
The website compiles purely to static HTML, CSS, and client-side assets in dist/. There is zero server-side database, no PHP, and zero public attack surface for SQL injection or credential leakage.
All network transmissions are strictly enforced over modern TLS 1.3 encryption (HTTPS). Corporate records and legal files are protected under role-based access control and salted password hashing.
Section 22 Breach Notification: In the event of an actual or reasonably suspected security compromise, HSG will notify the Information Regulator and affected data subjects as soon as reasonably possible, specifying the nature of the breach and remediation measures taken.
09. Retention & Statutory Destruction of Records (Sec 14)
Personal information is retained only for as long as necessary to achieve the initial purpose or as required by South African law:
- Corporate Governance, MOIs & Board Minutes: Retained indefinitely in terms of Section 24(1) of the Companies Act 71 of 2008.
- Financial & Tax Records: Retained for a mandatory statutory period of seven (7) years in compliance with the Companies Act 71 of 2008 and Tax Administration Act No. 28 of 2011.
- Institutional Inquiries: Retained for twenty-four (24) months post-inquiry conclusion, after which records are archived or deleted unless ongoing commercial negotiations exist.
- Secure Destruction Protocol: Expired electronic records are purged using cryptographic de-identification; paper documents are cross-shredded or incinerated.
10. Data Subject Rights & Access Request Procedure
Under Sections 23, 24, and 25 of POPIA and the provisions of PAIA, you have the following statutory rights:
- Right of Access: Request confirmation whether we hold your personal information and obtain an official copy thereof.
- Right to Rectification: Request correction or updating of inaccurate, irrelevant, or incomplete records.
- Right to Erasure / Deletion: Request destruction or deletion of records where we are no longer authorized to retain them.
- Right to Object: Object on reasonable grounds to the processing of your personal information (Form 1 of the POPIA Regulations).
Designated Information Officer Contact Details
All statutory requests for access (PAIA Form 02), correction, or objection must be directed in writing to:
11. Direct Marketing & Zero Tracking Cookie Policy
No Unsolicited Marketing: Horizon Strategic Group does not engage in consumer marketing or mass unsolicited promotional communications. Communications are strictly bespoke and transactional.
Zero Invasive Tracking Cookies: This website does not deploy third-party advertising trackers, cross-site telemetry beacons, or profiling cookies.
12. Lodging a Complaint with the Information Regulator
If you believe your personal information has been processed in breach of POPIA, we encourage you to contact our Information Officer first. However, you have the statutory right under Section 74 of POPIA to lodge a formal complaint with the Information Regulator:
The Information Regulator (South Africa)
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
General Inquiries: [email protected]
POPIA Complaints Email: [email protected]
PAIA Complaints Email: [email protected]
Official Website: https://inforegulator.org.za/