Legal

Privacy & POPIA Policy

Effective date: 26 September 2026

1. Introduction

BIRTAS (Batshele Integration Readiness & Transformation Analytics Suite) is operated by Batshele Consulting (Pty) Ltd ("Batshele", "we", "us"). This Privacy and POPIA Policy explains how we collect, use, store, share and protect personal information in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA).

By registering for or using BIRTAS, you acknowledge that you have read and understood this policy and consent to the processing of your personal information as described below.

2. Responsible party

Responsible party: Batshele Consulting (Pty) Ltd

Information Officer: Information Officer

Email: privacy@batshele.co.za

3. What information we collect

  • Account information: full name, corporate email address, employing organisation, job title, and any role or access level assigned by a workspace administrator.
  • Authentication information: password hashes managed through our authentication provider; we do not store plain-text passwords.
  • Assessment responses: answers to diagnostic and pulse surveys, together with any demographic or organisational banding fields you choose to disclose.
  • Technical information: browser type, IP address, device type, and timestamps, collected automatically for security and operational purposes.

We do not require or collect special personal information under section 26 of POPIA (e.g., health, biometric, racial or ethnic origin, political opinion, trade-union membership, criminal record).

4. How we use your information

  • To provision and administer your workspace access.
  • To operate merger integration readiness diagnostics and pulse assessments.
  • To produce aggregated, de-identified analytics and reports for the client Integration Management Office.
  • To maintain platform security, audit activity, and prevent misuse.
  • To communicate with you about your account, assessments, or support requests.

We do not use your personal information for automated decision-making about you as an individual, and we do not sell personal information or use it for marketing unrelated to BIRTAS.

5. How we store and protect your information

Personal information is hosted with secure cloud sub-processors under written operator agreements. Data is encrypted in transit and at rest. Access is restricted by role-based permissions, and we maintain an audit trail of sensitive operations.

Retention: Workspace access is granted for the duration of the engagement and revoked on completion. Response data is retained for the engagement period plus 24 months for benefits realisation tracking, after which it is securely deleted or irreversibly de-identified.

Security measures: multi-factor authentication, row-level security controls, encrypted storage, regular access reviews, and least-privilege administrative access.

6. How we share your information

  • Within your client workspace: administrators and designated client executives may see aggregated reports. Individual responses are not shared directly with your employer.
  • Service providers: we use trusted sub-processors for hosting, authentication, email delivery, and security monitoring. These providers only process data on our instructions and are bound by confidentiality and security obligations.
  • Legal requirements: we may disclose information if required by law, regulation, or court order, or to protect our rights, users, or the public.

Aggregated, de-identified results are reported only where the group size meets the applicable minimum reporting threshold. No group smaller than that threshold is disclosed.

7. Your POPIA rights

Under POPIA you have the right to:

  • Request access to your personal information.
  • Request correction or updating of inaccurate information.
  • Request deletion of personal information where retention is no longer justified.
  • Object to processing, subject to lawful grounds.
  • Withdraw consent at any time by contacting the Information Officer.
  • Lodge a complaint with the Information Regulator of South Africa.

We will respond to requests within 30 days. Withdrawing consent may end your workspace access, but lawful processing completed before withdrawal is not affected.

8. Cookies and tracking

BIRTAS uses essential cookies and local storage to maintain authentication state and session security. We do not use third-party advertising or behavioural tracking cookies.

9. International transfers

Some sub-processors may store data in facilities outside South Africa. We ensure that appropriate safeguards are in place, such as operator agreements and recognised data-protection standards, to protect your personal information.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to workspace administrators, and the effective date will be updated at the top of this page. Continued use of BIRTAS after changes constitutes acceptance of the updated policy.

11. Contact us

For privacy-related queries, POPIA requests, or to exercise your rights, please contact the Information Officer at privacy@batshele.co.za.

© 2026 Batshele Consulting (Pty) Ltd. All rights reserved.

Return to BIRTAS