Introduction
Kura Digital is a web design business operating from Edenvale in Gauteng, South Africa. We design and build websites, run online stores, and provide hosting, business email, SEO and ongoing support for businesses across Gauteng and the rest of the country.
This policy explains how we collect, use, share, store and protect personal information, and what your rights are under the Protection of Personal Information Act 4 of 2013 (POPIA). In POPIA’s language, Kura Digital is the responsible party for the personal information described here, and you are the data subject.
It applies to information we process through this website, through the enquiry and quote forms on it, and in the course of providing our services to clients.
Personal information we collect
When you use an enquiry or quote form on this website, you give us your full name, your email address and your message. You can also, if you choose to, give us your phone or WhatsApp number, your business name and the service you are interested in. We also record that you ticked the consent box, so we can show the basis on which we contacted you.
Recorded automatically when you submit a form, purely to keep the form working and free of spam:
- Your IP address and browser user agent, used to sign a short-lived anti-spam token that proves the form was loaded from this website, and to limit how many submissions can come from one address in an hour. Your IP address is never stored in readable form, only as a truncated one-way hash, in files that are deleted automatically two hours after they are written.
- A log entry for each enquiry: the date and time, which form was used, the address it was sent to, the reply-to address, and the mail server’s queue reference. This is what allows us to confirm an enquiry was actually sent, and to trace it with the hosting provider if it does not arrive.
When you contact us directly by phone, WhatsApp or email, we hold whatever you choose to tell us in that conversation.
If you become a client, we also hold the information needed to do the work and to invoice: your billing contact details, the registrant details required to register a domain in your name, hosting and mailbox account details, any logins you choose to share with us, and the text and images you supply for your website.
We do not ask for, and do not want, the categories POPIA calls special personal information, such as health, religious, political or biometric information, or the personal information of children. Please do not send these to us through the website.
How we use personal information
We use personal information to:
- Reply to your enquiry and prepare a written quote
- Deliver the services we have agreed: design, build, hosting, business email, SEO and maintenance
- Register and administer domains, hosting accounts and mailboxes in your name
- Invoice you and keep the accounting records the law requires us to keep
- Protect this website and our mailbox from spam and automated abuse
- Answer support requests and improve how we work
We do not sell, rent or trade personal information to anyone. We do not add people who send an enquiry to a marketing list. If we ever want to send you something that is not a reply to your enquiry or part of a project, we will ask you first.
Legal basis for processing
Section 11 of POPIA requires a lawful basis for processing personal information. We rely on:
- Consent: you tick the consent box before an enquiry can be submitted, and that consent is to us storing your details in order to reply.
- Performance of a contract: quoting for, and then delivering, the work you have asked us to do.
- Legal obligation: tax, accounting and company records we are required to keep.
- Legitimate interests: keeping the website secure, blocking automated spam, and retaining delivery logs so that we can prove and trace enquiries.
Where we rely on your consent, you can withdraw it at any time by emailing info@kuradigital.co.za. Withdrawing consent does not make the processing we carried out before that point unlawful, and it does not affect information we are required by law to keep.
Data security
The measures actually in place on this website and around our mailbox:
- The website is served over HTTPS with a valid TLS certificate, and plain HTTP is redirected to it.
- Enquiries are submitted over that encrypted connection and delivered to our mailbox over authenticated SMTP with TLS.
- Mailbox credentials live in a server-side configuration file that cannot be requested through a browser. They never appear in the website’s HTML, JavaScript or any response sent to a visitor.
- Forms are protected by a signed single-use token, a hidden honeypot field and per-address rate limiting, so automated submissions are rejected before they reach our mailbox.
- The recipient address is fixed on the server. Nothing submitted through a form can redirect an enquiry to a different address or add a hidden recipient.
- Hosting includes daily off-site backups, an SSL certificate and uptime monitoring.
- Access to the mailbox and the hosting account is limited to the people who need it.
No method of transmitting or storing information is completely secure, and we do not claim otherwise. If a security compromise occurs where there are reasonable grounds to believe your personal information has been accessed by an unauthorised person, section 22 of POPIA requires us to notify you and the Information Regulator, and we will do so.
Data retention
We keep personal information only as long as there is a reason to:
- Enquiries: for as long as we are dealing with your enquiry and for a reasonable period afterwards so that we can pick the conversation back up. Deleted sooner if you ask.
- Delivery logs: kept for troubleshooting; each log file is rotated once it reaches 2 MB.
- Anti-spam and rate-limit records: deleted automatically two hours after they are written.
- Client and project records: for the life of the working relationship, and afterwards for as long as tax, accounting and company law require.
- Website backups: overwritten on the hosting provider’s own backup cycle.
When information is no longer needed for any of these purposes, we delete it or remove the parts that identify you.
Your rights as a data subject
Sections 5, 23, 24 and 25 of POPIA give you the following rights. They are free to exercise, apart from where PAIA allows a prescribed fee for providing a copy of records.
- To be told whether we hold personal information about you, and to be given a description of it.
- To access that information, subject to the procedures and fees the Promotion of Access to Information Act allows.
- To have it corrected or deleted where it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully.
- To withdraw consent where consent is the basis we rely on.
- To object, on reasonable grounds, to processing we base on legitimate interests.
- Not to be subject to a decision based solely on automated processing that affects you. We do not make decisions that way.
- To complain to the Information Regulator, or to bring a civil claim.
To exercise any of these, email info@kuradigital.co.za or message us on WhatsApp. We may need to confirm your identity before acting, so that we are not handing your information to someone else. We aim to respond within 30 days, and will tell you if a request will take longer than that.
Contacting us about personal information
POPIA requires every responsible party to have an Information Officer. For Kura Digital that is the head of the business, who can be reached through any of the details below. Please put “POPIA” in the subject line so the request is not missed.
Kura Digital
- Emailinfo@kuradigital.co.za
- WhatsApp069 316 5141
- Phone069 316 5141
- Where we areEdenvale, Gauteng, South Africa
If you are not satisfied with how we have handled your request, you can complain to the Information Regulator:
The Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone 010 023 5200 ·
Toll free 0800 017 160
General enquiries: enquiries@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
POPIA complaints are lodged on the Regulator’s eServices portal using the prescribed POPIA Form 5. See inforegulator.org.za/complaints.
These details were taken from the Regulator’s own website on 16 August 2026. Check inforegulator.org.za for the current details before writing to them.
Policy updates
This policy was last updated on 16 August 2026.
We will update it when our practices change, when we add a service that handles personal information differently, or when the law changes. The date at the top of this page always reflects the current version.
If we make a change that materially affects how we handle information we already hold about you, we will say so on the website rather than change the page quietly. It is worth checking the date here from time to time.