1 Who is responsible for your information?
CW Connect is the responsible party for the personal information described in this policy. We process personal information in accordance with South Africa's Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable laws.
Providing information marked as required on an application or service request is necessary for us to assess the request, open and manage an account, install a service, or meet legal and billing requirements. If it is not provided, we may be unable to supply the requested service.
2 Personal information we collect
Depending on how you interact with us, we may collect:
- Identity and account information: names, identity or registration details, account numbers, login details, and authorised contacts.
- Contact and location information: phone numbers, email addresses, service, installation, postal, and billing addresses.
- Billing information: selected package, invoices, payment status, bank or payment references, and transaction records. Payment providers may process full card or bank details on our behalf.
- Service and technical information: installation details, equipment identifiers, IP addresses, network connection and usage records, fault diagnostics, and service performance information.
- Communications: applications, support requests, calls or messages, complaints, feedback, and consent or preference records.
- Website information: browser, device, approximate location derived from an IP address, pages viewed, referral information, and cookie or similar technology data.
- Other information: information reasonably required for credit assessment, fraud prevention, regulatory compliance, or to protect our network, customers, and staff.
We only process special personal information where it is necessary and permitted by law.
3 How we collect information
We usually collect information directly from you through our website, application forms, contracts, support channels, installations, payments, and your use of the service. Where lawful, we may also receive information from an authorised representative, payment or credit provider, installer, reseller, public record, fraud-prevention service, or another service provider involved in delivering your service.
4 Why we use your information
We process personal information only where there is a lawful basis, including to perform or prepare for a contract with you, comply with a legal duty, pursue a legitimate interest that does not unjustifiably affect your rights, or act with your consent where consent is required. We use it to:
- assess applications, confirm coverage, install, activate, and manage services;
- authenticate users, operate accounts, bill, collect payment, and keep financial records;
- deliver connectivity, monitor performance, manage network capacity, and resolve faults;
- provide support and communicate service, account, security, or outage information;
- prevent fraud, misuse, security incidents, and unlawful network activity;
- meet tax, accounting, telecommunications, law-enforcement, and other legal duties;
- improve our services, customer experience, website, and internal operations; and
- send marketing where permitted, subject to your right to opt out.
6 How long we keep information
We retain personal information only for as long as needed for the purpose for which it was collected, to provide the service, resolve disputes, enforce agreements, and meet legal, tax, accounting, fraud-prevention, and regulatory requirements. We then securely delete, destroy, or de-identify it, unless the law permits or requires continued retention.
7 How we protect information
We use reasonable technical and organisational safeguards appropriate to the nature of the information and the risks involved. These may include access controls, authentication, network and endpoint protections, backups, staff confidentiality obligations, service-provider controls, monitoring, and secure disposal practices.
No system can be guaranteed completely secure. If a security compromise creates a risk to your information, we will investigate and notify the Information Regulator and affected people where POPIA requires it.
8 Your privacy rights
Subject to POPIA and other applicable law, you may:
- ask whether we hold personal information about you and request access to it;
- ask us to correct, update, delete, or destroy inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading, unlawfully obtained, or no-longer-authorised information;
- object to certain processing on reasonable grounds, or object to direct marketing at any time;
- withdraw consent where processing depends on consent, without affecting earlier lawful processing;
- not be subjected, in the circumstances set out in POPIA, to a decision based solely on automated processing that has legal or substantial effects; and
- complain to us or the Information Regulator.
We may need to verify your identity before acting on a request. Some rights are limited where another law requires us to retain information or permits us to refuse access. We will explain any applicable limitation.
10 Direct marketing
We send electronic marketing only where permitted by law. You can opt out at any time by using the unsubscribe method in the message or contacting us. Opting out of marketing does not stop essential service, billing, security, or account communications.
11 Contact us or lodge a complaint
Contact our Information Officer or privacy contact to exercise a right, ask a question, or raise a concern:
If we cannot resolve your concern, you may lodge a complaint with the Information Regulator (South Africa).
12 Changes to this policy
We may update this policy when our practices, services, or legal obligations change. The current version will be posted on this page with its effective date. We will provide additional notice where a material change requires it.