Privacy Notice.
How TForge collects, uses and protects personal information.
Introduction
This Privacy Notice explains how TForge (Pty) Ltd, registration number 2015/031282/07, trading as TForge (“TForge”, “we”, “us” or “our”), collects, uses, stores, shares and protects personal information.
TForge respects the privacy of its customers, prospective customers, suppliers, business partners, website visitors, job applicants, event attendees, users and other individuals whose personal information it processes.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the Promotion of Access to Information Act 2 of 2000 (“PAIA”) and other applicable South African laws.
This Privacy Notice applies to personal information processed through the TForge website at www.tforge.co.za; contact, demonstration and enquiry forms; email, telephone and other business communications; marketing campaigns and newsletters; webinars, events and product demonstrations; customer and supplier relationships; recruitment activities; TForge products and services where TForge determines the purpose and means of processing; customer support and professional services; social-media platforms; analytics, cookies and similar technologies; and other lawful business activities carried out by TForge.
This Privacy Notice does not replace the privacy obligations contained in a customer agreement, employment agreement, supplier agreement, Data Processing Addendum or other contract.
Responsible party
The responsible party for personal information covered by this Privacy Notice is:
In certain circumstances, another TForge group company or jointly identified organisation may also act as a responsible party. Where this applies, the relevant entity and responsibilities should be identified in the applicable agreement or service documentation.
TForge’s role when processing information
Depending on the circumstances, TForge may act as either a responsible party or an operator.
3.1 TForge as responsible party
TForge acts as a responsible party when it determines why and how personal information will be processed. Examples include processing information for sales and business-development activities, website enquiries, marketing, recruitment, supplier management, customer account management, events and webinars, website analytics, security, compliance, and internal business administration.
3.2 TForge as operator
TForge may act as an operator when it processes personal information on behalf of a customer and according to that customer’s documented instructions. This may occur when TForge supplies or supports contact-centre technology, artificial intelligence solutions, voice or conversational AI, omnichannel communication services, cloud communication services, managed infrastructure, customer engagement platforms, interaction intelligence, data-processing services, professional services, or related enterprise technology.
Where TForge acts solely as an operator, the customer will generally remain responsible for determining the lawful purpose of processing, providing required notices and dealing with data-subject requests. Requests relating to personal information controlled by a TForge customer may therefore need to be directed to that customer.
What is personal information?
Personal information is information relating to an identifiable living natural person and, where applicable under POPIA, an identifiable existing juristic person.
Personal information may include identification information, contact details, employment information, business information, financial information, communication records, online identifiers, location-related information, opinions and preferences, correspondence, technical information, and other information that can identify or be linked to a person or organisation.
Categories of personal information we collect
Depending on your relationship with TForge, we may collect the following categories of personal information.
5.1 Identity information
This may include name and surname, title, username, customer or supplier reference number, identity or passport information where lawfully required, signature, and information used to verify identity or authority. We do not ordinarily request identity-document or passport information through general website enquiry forms.
5.2 Contact information
This may include business or personal email address, telephone or mobile number, physical address, postal address, preferred contact method, and social-media or messaging contact details.
5.3 Professional and business information
This may include employer, company name, job title, department, industry, business location, business contact details, professional responsibilities, areas of interest, purchasing authority, and business relationship with TForge.
5.4 Customer and commercial information
This may include products or services requested, proposals and quotations, customer requirements, contract information, orders, account information, billing details, payment and transaction records, service history, licence information, support history, and relationship-management records. TForge does not intend to collect full payment-card information directly through ordinary website forms.
5.5 Communication information
This may include emails, enquiry details, contact-form submissions, meeting notes, telephone records, support requests, complaint records, survey responses, webinar participation, event registrations, product feedback, and other correspondence with TForge. Where calls or meetings are recorded, participants should be notified where required.
5.6 Website and technical information
This may include Internet Protocol address, browser type, device type, operating system, screen information, general geographic location, referring website, pages viewed, links selected, session duration, date and time of access, cookie identifiers, advertising identifiers, Website interactions, technical logs, consent preferences, and security information.
5.7 Marketing information
This may include marketing preferences, subscription status, consent records, campaign engagement, email-opening or link-selection information, events attended, content downloaded, products or services of interest, advertising interactions, and records of objections or unsubscribe requests.
5.8 Recruitment information
This may include curriculum vitae, qualifications, employment history, skills, professional memberships, references, salary expectations, availability, interview notes, assessment results, work-eligibility information, and other information supplied during recruitment. Background, reference or criminal-record checks will only be performed where lawful, relevant and proportionate to the role.
5.9 Supplier and partner information
This may include supplier contact details, company records, banking confirmation, tax and VAT information, contracts, due-diligence records, ownership or authorised-representative information, performance information, and compliance documentation.
5.10 Security information
This may include login records, access logs, authentication information, network and device information, security-alert information, incident reports, physical access records, CCTV footage where applicable, and information used to detect fraud, misuse or cyber threats.
5.11 Special personal information
TForge does not generally intend to collect special personal information through its public website. Special personal information may include information relating to health, race or ethnic origin, religious or philosophical beliefs, trade-union membership, political persuasion, sex life, biometric information, or alleged or proven criminal behaviour. Where special personal information is processed, TForge will do so only where legally permitted and subject to appropriate safeguards.
How we collect personal information
We may collect personal information:
6.1 Directly from you
This may occur when you complete a website form, contact us by email or telephone, request a demonstration, request a quotation or proposal, subscribe to communications, attend an event or webinar, download content, enter into a contract, create an account, request support, apply for employment, participate in a survey, visit our premises, or otherwise communicate with TForge.
6.2 From your employer or organisation
Your employer, customer, supplier or business partner may provide information where you are a contact person, an authorised representative, a user of TForge services, a technical contact, a billing contact, a procurement contact, or a person involved in a business relationship.
6.3 From TForge customers
Where TForge acts as an operator, a customer may provide personal information for processing through a TForge service. The customer is generally responsible for ensuring that it has authority to collect and provide that information.
6.4 From publicly available sources
We may collect relevant professional or business information from company websites, public business directories, professional networking platforms, public registers, media publications, event information, public social-media profiles, and other lawful public sources.
6.5 From service providers and partners
We may receive information from marketing platforms, event organisers, referral partners, resellers, technology partners, analytics providers, advertising platforms, recruitment providers, credit or compliance providers, and other authorised service providers.
6.6 Automatically through technology
Information may be collected automatically through cookies, pixels, tags, analytics tools, log files, website hosting services, security systems, CRM tracking, embedded content, and similar technologies. Please read the TForge Cookie Notice for more information.
Why we process personal information
TForge may process personal information for the following purposes.
7.1 Responding to enquiries
We process information to respond to questions, provide requested information, arrange consultations, schedule demonstrations, assess business requirements, prepare proposals or quotations, and follow up on legitimate business enquiries.
7.2 Delivering products and services
We may process information to enter into and perform contracts, set up customer accounts, implement solutions, provision services, provide licences, configure systems, manage projects, provide support, monitor service performance, resolve incidents, maintain customer relationships, and communicate service or operational information.
7.3 Artificial intelligence and technology services
Where applicable, information may be processed to configure and operate AI-enabled solutions, process customer interactions, support voice or conversational automation, produce analytics or interaction insights, route communications, support quality assurance, detect technical problems, improve customer-specific workflows, monitor performance, and provide agreed professional services.
The precise purpose and responsibility applicable to customer data should be governed by the relevant customer agreement and Data Processing Addendum.
TForge will not use customer-controlled personal information to train a general-purpose AI model unless this is expressly authorised, lawfully permitted and subject to appropriate contractual safeguards.
7.4 Sales and relationship management
We may process information to identify legitimate business opportunities, manage prospective-customer relationships, maintain CRM records, understand customer requirements, provide product updates, manage partner or reseller relationships, conduct account planning, and maintain accurate business contact information.
7.5 Marketing
Where legally permitted, we may process information to send newsletters, send product announcements, promote webinars or events, share industry insights, conduct business-to-business marketing, measure campaign effectiveness, manage subscriptions, create relevant advertising audiences, and personalise business communications. You may object to direct marketing or unsubscribe at any time.
7.6 Website operation and improvement
We may process information to operate the website, provide requested functionality, analyse website traffic, understand visitor behaviour, improve content and navigation, measure marketing performance, diagnose errors, maintain cookie choices, and improve the visitor experience.
7.7 Security and fraud prevention
We may process information to protect systems and information, authenticate users, control access, monitor security, detect unauthorised activity, investigate incidents, prevent fraud, enforce agreements, preserve evidence, and protect TForge, its customers and users.
7.8 Legal and regulatory compliance
We may process information to comply with POPIA and PAIA, comply with tax, employment, telecommunications or company laws, respond to lawful requests, maintain statutory records, exercise or defend legal rights, conduct due diligence, meet audit obligations, and cooperate with regulators or law-enforcement authorities.
7.9 Recruitment and employment
We may process applicant information to evaluate applications, communicate with candidates, conduct interviews, verify qualifications or references, assess suitability, make employment decisions, maintain recruitment records, and meet legal obligations.
7.10 Internal business administration
We may process information for finance, accounting, reporting, governance, supplier management, risk management, insurance, auditing, business continuity, corporate transactions, and internal record-keeping.
Lawful grounds for processing
Depending on the circumstances, TForge may process personal information where you have consented; processing is necessary to conclude or perform a contract; processing complies with a legal obligation; processing protects your legitimate interests; processing protects the legitimate interests of another person; processing is necessary for TForge’s legitimate interests or those of a third party, where compatible with your rights; or another lawful justification under POPIA applies.
TForge does not rely on consent for every processing activity. Where processing is based on consent, you may withdraw that consent. Withdrawal does not invalidate processing that was lawful before the withdrawal.
Is providing information voluntary or mandatory?
Providing personal information through a general website enquiry form is usually voluntary.
However, certain information may be required to respond meaningfully to an enquiry, provide requested services, verify identity or authority, enter into a contract, meet legal obligations, administer a customer account, process a job application, or protect the security of TForge systems.
Where required information is not provided, TForge may be unable to respond to the request, provide a quotation or demonstration, conclude or perform a contract, provide access to a service, process an application, or meet the requested purpose.
Fields marked as required on a website form must be completed before the form can be submitted. Marketing consent is voluntary and should not ordinarily be required to submit a general business enquiry.
Direct marketing
TForge may send direct-marketing communications where legally permitted. Communications may relate to TForge products and services, product updates, events and webinars, industry insights, relevant partner solutions, research and reports, and other business-related information.
Where consent is required, TForge will request it through an appropriate opt-in mechanism. Marketing consent will not be preselected on website forms.
Every electronic marketing communication should provide a reasonable way to unsubscribe or object. You may opt out by selecting the unsubscribe link in a marketing email, updating your communication preferences, contacting TForge at antony@tforge.co.za, or submitting a privacy request.
TForge may retain limited information on a suppression list to ensure that an unsubscribe or objection continues to be respected. Opting out of marketing will not prevent TForge from sending necessary contractual, service, security, billing or administrative communications.
Cookies and website analytics
TForge uses cookies and similar technologies to operate, secure, analyse and improve the website. Depending on the website configuration, these technologies may include Wix cookies, Wix Analytics, Google Analytics, Google Tag Manager, Microsoft Clarity, LinkedIn Insight Tag, Meta Pixel, HubSpot or CRM tracking, embedded video services, scheduling tools, chat or support tools, and other analytics or marketing technologies.
Where required, non-essential cookies should not be activated until the visitor has made the relevant cookie choice. Visitors may manage cookie preferences through the cookie banner or Cookie Settings tool.
Further information is available in the TForge Cookie Notice.
Automated processing and artificial intelligence
Some TForge products or business processes may use artificial intelligence, automation, analytics or algorithmic technologies. Depending on the context, these technologies may be used to route communications, assist contact-centre interactions, analyse customer interactions, categorise enquiries, produce summaries, identify trends, support quality assurance, support business decisions, detect security or operational risks, and improve workflow efficiency.
TForge aims to apply proportionate human oversight, privacy safeguards and governance to AI-enabled processing.
Where a TForge customer determines the purpose and means of AI processing, the customer is responsible for establishing the lawful basis, providing relevant notices and determining whether human review or additional safeguards are required.
TForge will not subject a person to a decision based solely on automated processing that produces legal consequences or substantially affects that person unless the processing is lawfully permitted and appropriate safeguards are implemented.
Where appropriate and legally applicable, a person may request information about automated processing or request suitable human consideration.
Who we share personal information with
TForge may share personal information with the following categories of recipients where reasonably necessary and legally permitted.
13.1 TForge personnel
Information may be accessed by authorised employees, directors, contractors, consultants, support personnel, sales representatives, finance personnel, legal or compliance personnel, and other authorised representatives. Access should be limited according to role and business need.
13.2 Technology and service providers
These may include providers of website hosting, cloud infrastructure, telecommunications, email, CRM systems, marketing automation, analytics, advertising, cybersecurity, customer support, data storage, backup, collaboration, video conferencing, scheduling, recruitment, accounting, payment services, and professional services. Depending on TForge’s active configuration, service providers may include Wix, Microsoft, Google, LinkedIn, Meta, HubSpot and other technology providers.
13.3 Business partners
Information may be shared with strategic technology partners, resellers, referral partners, implementation partners, telecommunications providers, software vendors, cloud providers, and other parties involved in providing a requested solution. Information should only be shared to the extent reasonably necessary for the relevant purpose.
13.4 Professional advisers
Information may be shared with attorneys, auditors, accountants, insurers, tax advisers, consultants, and other professional advisers.
13.5 Regulators and authorities
TForge may disclose information to the Information Regulator, courts, law-enforcement authorities, tax authorities, government departments, industry regulators, and other competent authorities. Disclosure will occur where required or authorised by law.
13.6 Corporate transactions
Information may be disclosed in connection with a merger, acquisition, investment, restructuring, financing, sale of assets, due-diligence process, or other lawful corporate transaction. Appropriate confidentiality and data-protection measures should apply.
Operators and service providers
Where another party processes personal information for TForge, TForge will take reasonable steps to select appropriate service providers and impose suitable confidentiality, security and data-protection obligations.
Operators should process personal information only with TForge’s knowledge or authorisation, for the agreed purpose, subject to confidentiality, with appropriate security safeguards, and in accordance with applicable law and contractual requirements.
International and cross-border transfers
TForge operates and provides services in South Africa and may conduct business or support customers in other countries. Some of TForge’s technology, cloud, communications, analytics, CRM, marketing and support providers may process or store information outside South Africa.
Personal information may therefore be transferred to or accessed from countries including the United Arab Emirates, the Kingdom of Saudi Arabia and other jurisdictions in which TForge operates or its service providers host infrastructure; countries in which TForge customers operate; countries in which approved cloud or service providers host systems; and other locations necessary for service delivery.
Where personal information is transferred outside South Africa, TForge will take reasonable steps to ensure that the transfer is permitted under POPIA. Safeguards may include laws providing an adequate level of protection, binding agreements, data-processing terms, contractual confidentiality requirements, customer instructions, security assessments, technical safeguards, and consent where appropriate.
Specific hosting or processing locations applicable to a customer service may be addressed in the relevant contract, service documentation or Data Processing Addendum.
Retention of personal information
TForge retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required or permitted by law.
Retention periods may depend on the nature of the information, the purpose of processing, contractual requirements, legal record-keeping periods, tax and accounting obligations, potential disputes, security needs, customer instructions, consent status, and legitimate business requirements.
16.1 Sales enquiries
Sales and business-development information may be retained while an opportunity remains active and for a reasonable period after the last meaningful interaction.
16.2 Customer records
Customer, contract and service records may be retained for the duration of the relationship and for an appropriate legal, contractual, audit or dispute period afterwards.
16.3 Marketing information
Marketing information may be retained until the person unsubscribes, objects or the information is no longer relevant. Suppression records may be retained for longer to ensure that an objection continues to be respected.
16.4 Recruitment information
Successful-candidate information may form part of the employment record. Unsuccessful-candidate information may be retained for a defined recruitment period, unless the candidate consents to longer retention or another lawful reason applies.
16.5 Website analytics
Website analytics and cookie information will be retained according to TForge’s configuration and the relevant service provider’s retention periods.
16.6 Security records
Security logs and incident records may be retained for a period appropriate to investigation, threat detection, legal compliance and system protection.
16.7 Customer-controlled data
Where TForge acts as an operator, customer data will be retained, returned or deleted according to the customer agreement, documented instructions and applicable law.
When information is no longer required, TForge will take reasonable steps to delete, destroy, anonymise or de-identify it, subject to lawful retention requirements.
Security safeguards
TForge applies reasonable technical and organisational measures designed to protect personal information against loss, damage, unauthorised destruction, unlawful access, unauthorised processing, accidental disclosure, alteration, misuse, and other security risks.
Depending on the environment and risk, safeguards may include access controls, role-based permissions, authentication, password controls, encryption, secure connections, network security, logging and monitoring, backups, vulnerability management, endpoint protection, secure configuration, incident-response procedures, employee confidentiality, security awareness, vendor assessment, contractual safeguards, business-continuity procedures, and data minimisation.
No website, cloud platform, telecommunications network or electronic storage system can be guaranteed to be completely secure. Users should not submit confidential, special or unnecessary personal information through general website forms.
Security compromises
Where TForge has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, TForge will investigate and take appropriate action.
Where required by law, TForge will notify the Information Regulator, affected data subjects, and relevant customers where TForge acts as an operator.
A notification may describe the nature of the compromise, possible consequences, measures taken by TForge, recommended protective steps, and relevant contact information.
Notification may be delayed where required by law-enforcement authorities or otherwise permitted by law.
Your rights
Subject to POPIA and other applicable laws, you may have the right to:
19.1 Request confirmation
You may ask whether TForge holds personal information about you.
19.2 Request access
You may request access to personal information held by TForge, subject to lawful grounds for refusal and applicable procedures or fees.
19.3 Request correction
You may ask TForge to correct or update inaccurate, incomplete, misleading or outdated information.
19.4 Request deletion or destruction
You may ask TForge to delete or destroy information that is no longer authorised to be retained, subject to legal, contractual and operational limitations.
19.5 Object to processing
You may object, on reasonable grounds, to certain processing activities.
19.6 Object to direct marketing
You may object to direct marketing at any time.
19.7 Withdraw consent
Where processing is based on consent, you may withdraw that consent.
19.8 Request information about recipients
Where legally applicable, you may request information concerning third parties that have received your personal information.
19.9 Complain
You may submit a complaint to TForge or lodge a complaint with the South African Information Regulator.
19.10 Request human consideration
Where applicable, you may raise a concern about a decision based solely on automated processing and request appropriate human consideration.
These rights are not absolute and may be subject to identity verification, legal exceptions, third-party rights and other applicable requirements.
Exercising your rights
To submit a privacy request, contact:
Your request should include your name, your contact details, your relationship with TForge, the type of request, a description of the information concerned, and any details reasonably necessary to locate the relevant records.
TForge may request reasonable proof of identity or authority before providing access or making changes. Identity verification information should be requested only where necessary and should be submitted through a reasonably secure channel.
TForge may refuse or limit a request where permitted by law. Where appropriate, reasons will be provided.
Information relating to other people
You must not provide another person’s personal information to TForge unless you are authorised to do so, the information is relevant and necessary, the disclosure is lawful, and the person has received any required privacy information.
Where you act for a company or another individual, TForge may request proof of your authority.
Children’s personal information
The public TForge website and TForge’s enterprise services are not primarily directed at children. TForge does not intentionally collect children’s personal information through general sales, marketing or analytics activities.
Where personal information relating to a child is processed, TForge will do so only where a competent person has authorised the processing, processing is required or permitted by law, or another lawful justification applies.
A child should not submit personal information through the website without appropriate adult involvement.
Recruitment privacy
When you apply for a position at TForge, your information may be processed to evaluate your application, communicate with you, arrange interviews, verify qualifications, contact references, conduct lawful and proportionate checks, make recruitment decisions, and maintain recruitment records.
TForge may share applicant information with authorised employees, recruitment providers, assessment providers, background-check providers and professional advisers.
Do not include unnecessary special personal information, banking details, account passwords or unrelated identity documents in an initial application.
TForge may retain unsuccessful applications for a reasonable period. Consent should be obtained where TForge wishes to retain an application for materially longer future recruitment purposes.
Social media
TForge may maintain pages on LinkedIn, Facebook, Instagram, YouTube and other platforms. When you interact with a TForge social-media page, both TForge and the platform provider may process information. The platform provider’s privacy notice and settings also apply.
TForge may process public profile information, comments, messages, reactions, campaign engagement, business enquiries, and advertising information made available through the platform.
Do not publish confidential or sensitive information in public comments.
Third-party websites
The TForge website may contain links to third-party websites, services or resources. TForge does not control the privacy practices of those third parties.
You should review the applicable privacy notice before providing information to another website or service. A link does not necessarily mean that TForge endorses all activities or privacy practices of the third party.
PAIA requests
Requests for access to records under PAIA must be submitted in accordance with TForge’s PAIA Manual.
PAIA enquiries may be directed to Information Officer Antony Makins at antony@tforge.co.za.
A PAIA request is different from a routine request to access your own personal information, although the applicable procedures may overlap.
Complaints to TForge
TForge encourages you to contact its Information Officer first so that the concern can be investigated.
A complaint should include your name and contact details, a description of the concern, the relevant dates, the information or processing involved, any previous correspondence, and the outcome you are seeking.
Complaints may be sent to antony@tforge.co.za. TForge will review the complaint and respond within a reasonable period, taking account of its nature and complexity.
Complaints to the Information Regulator
You have the right to lodge a complaint with the South African Information Regulator if you believe your personal information has been processed in a manner that violates POPIA.
TForge recommends confirming the Regulator’s current details through its official website before submitting a complaint.
Changes to this Privacy Notice
TForge may update this Privacy Notice to reflect changes to its business, new products or services, new processing activities, changes in technology, changes to service providers, legal or regulatory developments, security or governance improvements, or changes to international operations.
The latest version will be published on the TForge website with an updated revision date. Where changes materially affect how personal information is processed, TForge may take additional reasonable steps to notify affected persons.
Contact details
Questions, requests or complaints concerning this Privacy Notice or TForge’s processing of personal information may be directed to: