How we collect, use, store and delete personal information — written to the Protection of Personal Information Act 4 of 2013 (POPIA). We sell POPIA audits. It would be a poor look to not have this page, and a worse one for it to be vague.
The responsible party — the person who decides what happens to your information and answers for it — is:
Information Officer: Rogan Kitching, contactable at the address above. Under POPIA the Information Officer is the person you deal with about your own information, and the person the Information Regulator deals with about ours.
Rokit Systems is in the process of registering as Rokit Systems (Pty) Ltd. Until that registration is complete, the responsible party is the sole proprietor named above. When it completes, this page will be updated and the effective date changed — the obligations to you do not change either way.
If you only read the website. Our analytics record that a page was viewed, roughly where in the world from, what kind of device, and which site sent you. It is counted in aggregate. It does not identify you, it is not linked across sites, and no cookie is set to do it.
If you fill in a form. Your name, the contact details you give us — email address or WhatsApp number — your business name if you provide it, and whatever you write in the message box. We collect it because you asked us to contact you, and we use it for that.
If you message us on WhatsApp. Your WhatsApp number, your display name and the conversation itself. WhatsApp is operated by Meta and its own terms apply to the message in transit; what we hold is the conversation on our side.
If we contact you first. We build prospect lists from information businesses publish about themselves for the purpose of being contacted — company websites, public directories, listing sites, industry association member lists. That is typically the business name, a switchboard or published mobile number, a suburb and a sector. We do not buy contact lists, we do not scrape personal email addresses, and we do not use information a business has not published for that purpose.
If you become a client. Contact details for the people we work with, billing details, the scope and history of the work, and our notes from meetings and calls.
What we deliberately do not collect. We do not ask for or store identity numbers, banking details, or card numbers on this website. There is no payment form here. If you pay us, it is by EFT or through a payment provider that handles those details directly — they never reach us.
POPIA requires a lawful basis for each purpose. Ours are:
Where we rely on your consent, you may withdraw it at any time. That does not undo processing that already happened lawfully, and it does not affect records we are legally required to keep.
Our analytics provider, Cloudflare Web Analytics, is cookieless by design. It does not use a device fingerprint, does not track you between websites, and does not build a profile of you. It exists so we can tell whether anybody reads this site.
One thing is stored on your device: if you dismiss the small notice at the bottom of the page, we remember that in your browser's local storage so it does not reappear on every page. It is a single yes/no, it never leaves your device, and clearing your browsing data removes it.
We run no advertising pixels — no Meta pixel, no Google Ads tag, no LinkedIn Insight tag. If that ever changes, this page changes first and you will be asked properly.
We use a small number of service providers — POPIA calls them operators. They process information on our instructions and may not use it for their own purposes:
| Who | What for | What they see |
|---|---|---|
| Netlify | Website hosting and form submissions | Anything you type into a form; standard server logs |
| Cloudflare | Website analytics | Aggregate page views. No cookies, no identifiers |
| Meta (WhatsApp) | The channel you message us on | The conversation, under their own terms |
| Our email provider | Receiving and sending email | Email you send us and our replies |
We do not sell your personal information, and we do not share it for anyone else's marketing. The only other circumstances in which we would hand it over are where the law requires it, or where it is necessary to establish or defend a legal claim.
Section 72 of POPIA restricts sending personal information outside the Republic. Being straight with you: our website host and our analytics provider are both international, so information handled by them is processed on servers outside South Africa.
We rely on those providers being subject to binding agreements and legal frameworks that give your information a level of protection substantially similar to POPIA, and on their contractual undertaking to process it only on our instructions. The categories involved are small — form submissions and aggregate page counts.
Client business data that we build systems around is a separate matter and is dealt with in section 10.
| What | How long | Why |
|---|---|---|
| Form submissions and enquiries that go nowhere | 12 months | Long enough to pick a conversation back up, short enough not to hoard |
| Prospect contact details | Until you ask us to remove them, or 24 months without contact | Whichever comes first |
| Client records and correspondence | For the engagement, then 5 years | Tax and company law record-keeping |
| Invoices and financial records | 5 years | Required by SARS and the Companies Act |
| Do-not-contact list | Indefinitely | Deleting it is how someone gets called again by mistake. This one exists to protect you |
| Website analytics | Aggregate only, no personal information to keep | — |
Under POPIA you may:
The one thing we will not do is delete you from the do-not-contact list, because that list exists to keep us away from you.
We contact South African businesses about automation work. When we do, we say who we are and why we are calling in the first sentence. We do not use a survey or research pretext to open a sales call.
Section 69 of POPIA restricts unsolicited electronic direct marketing to people who have not consented or are not existing customers. Our position is that we contact businesses on numbers they publish for the purpose of being contacted, for work of the kind we do, and that we honour a refusal on the spot and permanently. If you think we have got that wrong in your case, tell us and we will fix it rather than argue about it.
We do not add anyone to a mailing list for filling in a form. If you asked for an audit, you will hear from us about that audit.
This section matters if you are our client, or thinking about becoming one.
When we build a system that captures your customers' information — a WhatsApp front desk, a lead capture flow, a quoting engine — that information lives in your own accounts. Your Google Sheet, your CRM, your inbox, under your login and your ownership. We take delegated access to build and maintain it. We do not keep a pooled copy of our clients' customer databases, and we never mix one client's data with another's.
In that arrangement you are the responsible party for your customers' information and we act as your operator. That means it stays yours: if you leave, you keep everything, and there is nothing of yours for us to hold onto. We will sign a written operator agreement to that effect, because POPIA expects the arrangement to be in writing and because you should ask for one.
We take reasonable technical and organisational measures appropriate to a business of our size: encrypted connections across the site, access limited to the people who need it, multi-factor authentication on the accounts that support it, and no storage of payment or identity-document data at all.
Honest limitation: no system is perfectly secure, and we will not pretend otherwise. If a breach occurs that creates a real risk of harm to you, POPIA requires us to notify both the Information Regulator and you as soon as reasonably possible. We will, in plain language, and we will tell you what to do about it.
This is a business-to-business service. We do not knowingly collect the personal information of anyone under 18. If you believe we have, tell us and we will delete it.
If we change how we handle personal information, we change this page and move the effective date at the top. Material changes — a new category of information, a new purpose, or anything that starts setting cookies — will be flagged on the website rather than made quietly.
Come to us first — email hello@rokitsystems.co.za and we will take it seriously. But you do not have to, and you can go directly to the regulator at any time:
Regulator contact details verified against inforegulator.org.za on 20 August 2026. They have moved offices before — check the site if a letter comes back.
No cookies here. We count page views without identifying anyone, and run no advertising trackers. What we do collect →