Home / Privacy Policy Legal

Privacy Policy

How we collect, use, and protect your personal information, including our POPIA compliance details and cookie policy.

Last updated: 21 July 2026

RedSide Cyber ("RedSide," "we," "us," or "our") provides offensive security testing services. This policy explains what personal information we collect through this website, why we collect it, how it's protected, and the rights you have over it under South Africa's Protection of Personal Information Act 4 of 2013 (POPIA).

This policy describes our actual practices and how this website is built to enforce them. It is provided for transparency and is not a substitute for independent legal advice; if you need a compliance opinion for your own organization, consult a qualified attorney.
On This Page
  1. Who Is Responsible For Your Information
  2. Information We Collect
  3. How We Use Your Information
  4. Our Legal Basis For Processing
  5. How We Protect Your Information
  6. Sharing & Third Parties
  7. How Long We Keep Information
  8. Cookies & Local Storage
  9. Your Rights
  10. POPIA: How We Comply
  11. Children's Privacy
  12. Changes To This Policy
  13. Contact Us

1. Who Is Responsible For Your Information

RedSide Cyber is the "responsible party" (as POPIA defines that term) for personal information collected through this website. You can reach us at info@redside.co.za for any privacy question, request, or complaint, see Contact Us below.

2. Information We Collect

Information you give us directly

When you submit our contact form, we collect:

  • Your name
  • Your email address
  • Your company name (optional)
  • Which service you're interested in (optional)
  • The message you write, including any details you choose to share about your environment or engagement

Information collected automatically

When you submit the contact form, our server also records:

  • Your IP address, included in the notification email so we can spot abuse or spoofed submissions
  • A one-way hashed version of your IP address, held briefly to enforce a rate limit that stops automated form abuse (see Security)
  • The time of submission

Standard web server logs (e.g. requested page, browser user-agent, timestamp) are generated by our hosting provider for security and operational purposes, as is standard for virtually all websites. We do not use these logs for tracking or profiling.

Information we do not collect

We do not use analytics, advertising, or marketing-tracking cookies or scripts on this site. We do not sell, rent, or trade personal information.

3. How We Use Your Information

We use the information above only to:

  • Respond to your enquiry and scope a potential engagement
  • Communicate with you about services you've requested
  • Detect, prevent, and investigate spam, abuse, or fraudulent submissions
  • Meet legal or regulatory obligations, if any apply

We do not use your information for automated decision-making or profiling, and we do not use it for marketing unless you separately opt in to that in the future.

4. Our Legal Basis For Processing

We process your personal information on the following bases:

  • Consent: by submitting the contact form, you consent to us processing the information you've provided in order to respond to you.
  • Legitimate interest: processing your IP address (hashed) for rate-limiting is necessary to protect the site and our inbox from automated abuse, and is limited to that purpose.

5. How We Protect Your Information

Our contact form is built with the following safeguards:

  • All traffic to this site is served over HTTPS (encrypted in transit)
  • Form submissions are validated and sanitized server-side before use, including stripping characters that could be used for email header injection
  • A hidden honeypot field and a minimum-fill-time check help filter out automated bot submissions
  • Submissions are rate-limited per IP address to prevent abuse
  • Your message is transmitted directly to our mailbox by email. It is not written to a public-facing database, so there is no website database of submissions that could be exposed in a breach of this site

No system is perfectly secure, but the form is deliberately built to minimize what is collected and stored in the first place.

6. Sharing & Third Parties

We do not sell or share your personal information with third parties for their own marketing purposes. Limited technical third parties are involved in running this site:

  • Hosting provider: the infrastructure this site and the contact form run on.
  • Google Fonts: this site loads the Bebas Neue, Inter, and JetBrains Mono fonts from Google's font CDN. Loading a font from Google's servers means your device's IP address is sent to Google as part of that request, in the same way it would be for any resource loaded from a third-party domain. We don't control what Google does with that request beyond serving the font file.
  • Email delivery: contact form messages are delivered via our hosting provider's outbound mail service to our own mailbox.

We may disclose personal information if required to do so by law, or to protect our rights, property, or safety, or that of our users or the public.

7. How Long We Keep Information

  • Contact form messages: delivered by email and retained only as long as they remain in our mailbox, subject to our own inbox management. They are not stored in a separate website database.
  • Rate-limit records: a hashed IP address with submission timestamps, kept only long enough to enforce the rate-limit window (a matter of minutes), after which new activity from that address is treated independently.
  • Cookie preference: your accept/decline choice is kept in your browser's local storage until you clear it or change it via "Cookie Settings" in the footer.

8. Cookies & Local Storage

This site does not currently set analytics, advertising, or marketing cookies of any kind. The only browser storage we use is a single local storage entry that remembers whether you accepted or declined our cookie banner, so we don't ask you again on every visit. That preference is stored only on your device and is not sent to us or any third party.

If we ever introduce analytics or other non-essential tracking in the future, we will update this section and the cookie banner first, and we will not activate anything non-essential until you've given consent through that banner.

You can change your cookie choice at any time using the Cookie Settings link in the site footer, or by clearing your browser's local storage for this site.

9. Your Rights

Under POPIA, you have the right to:

  • Access the personal information we hold about you
  • Correct personal information that is inaccurate, out of date, incomplete, or misleading
  • Request deletion of personal information we hold about you that we're not otherwise required to keep
  • Object to the processing of your personal information on reasonable grounds
  • Withdraw consent at any time, where our processing is based on consent (this won't affect processing already carried out)
  • Complain to the Information Regulator (see POPIA below) if you believe we've handled your information unlawfully

To exercise any of these rights, email info@redside.co.za. We'll respond within a reasonable time and, in any event, within the timeframes POPIA requires.

10. POPIA: How We Comply

The Protection of Personal Information Act 4 of 2013 (POPIA) sets out eight conditions for the lawful processing of personal information in South Africa. Here's how this site is built to meet each one.

1. Accountability

RedSide Cyber is the responsible party for personal information collected through this site and is accountable for complying with POPIA's conditions, as set out throughout this policy.

2. Processing Limitation

We only collect what the contact form actually asks for (name, email, optional company, optional service interest, and your message), process it lawfully and with your consent, and don't collect excessive information beyond what's needed to respond to you.

3. Purpose Specification

We collect personal information for the specific, explicitly stated purpose of responding to enquiries and scoping engagements (see How We Use Your Information), and we don't repurpose it beyond that without telling you.

4. Further Processing Limitation

We don't use your information for anything incompatible with the purpose you gave it to us for. We don't, for example, add contact form submitters to a marketing list.

5. Information Quality

We take reasonable steps to keep the information you give us accurate and up to date. Since it comes directly from you, you can correct it at any time by emailing us.

6. Openness

This policy is that openness commitment: what we collect, why, how long we keep it, and who else touches it is documented here, in plain language, and is not buried behind a login or a request process.

7. Security Safeguards

Covered in detail in How We Protect Your Information above: HTTPS, server-side validation, bot mitigation, rate limiting, and no persistent database of submissions.

8. Data Subject Participation

You can ask what we hold about you, ask us to correct or delete it, object to processing, or lodge a complaint. See Your Rights above.

The Information Regulator

If you believe we have not handled your personal information in line with POPIA, you have the right to lodge a complaint with South Africa's Information Regulator:

  • Website: inforegulator.org.za
  • General enquiries: enquiries@inforegulator.org.za
  • POPIA complaints: POPIAComplaints@inforegulator.org.za

We'd appreciate the chance to resolve any concern directly first (email info@redside.co.za), but you're under no obligation to contact us before approaching the Regulator.

11. Children's Privacy

This site and our services are directed at businesses and professionals, not children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we'll delete it.

12. Changes To This Policy

We may update this policy as our practices or the law change. Material changes will update the "Last updated" date at the top of this page. We encourage you to review this page periodically.

13. Contact Us

For any question about this policy, your personal information, or to exercise any of your rights above, contact:

  • Email: info@redside.co.za
  • Instagram: @redside_cyber_security
  • LinkedIn: RedSide Cyber