1. Introduction

Sihlelisile Consultants ("we", "us", "our") is committed to protecting the privacy and security of your personal information. This Privacy Notice is issued in compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) and sets out how we collect, use, disclose, and safeguard your personal information when you interact with our services, website, and communication channels.

By providing us with your personal information, you consent to the practices described in this notice. We encourage you to read this notice carefully to understand our views and practices regarding your personal data.

🔒 Our Commitment

We are registered as Professional Accountants (SA) and Tax Practitioners, bound by strict professional and ethical standards. Your data is handled with the same integrity and confidentiality we apply to our clients' financial records.

2. Definitions

For the purposes of this Privacy Notice, the following terms shall have the meanings assigned to them:

Data Subject
The person to whom personal information relates — this includes clients, prospective clients, employees, suppliers, and website visitors.
Personal Information
Information relating to an identifiable, living natural person or existing juristic person, including but not limited to name, contact details, identity number, financial information, and employment history.
Processing
Any operation or activity concerning personal information, including collection, recording, organisation, storage, updating, retrieval, consultation, use, dissemination, merging, linking, restriction, degradation, and destruction.
Responsible Party
Sihlelisile Consultants, as the entity that determines the purpose and means for processing personal information.
Information Officer
The individual appointed by Sihlelisile Consultants to oversee compliance with POPIA and handle data protection queries and requests.

3. Information We Collect

We may collect and process the following categories of personal information:

  • Identity Information: Full name, identity number, date of birth, nationality, and gender.
  • Contact Information: Physical address, email address, telephone numbers, and emergency contact details.
  • Financial Information: Banking details, tax reference numbers, income and expense records, VAT numbers, and financial statements.
  • Business Information: Company registration numbers, CIPC details, beneficial ownership information, and business structure details.
  • Employment Information: For payroll clients — employee names, ID numbers, salaries, benefits, UIF numbers, and employment contracts.
  • Technical Information: IP address, browser type, device information, and cookies when you use our website.
  • Communication Records: Emails, phone call logs, meeting notes, and correspondence related to our services.
Special Personal Information

We do not ordinarily collect special personal information (e.g., health data, religious beliefs, criminal records) unless strictly necessary for specific regulatory compliance purposes and with your explicit consent.

4. How We Collect Information

We collect personal information through the following means:

  • Directly from you: When you complete forms, engage our services, send emails, call our office, or meet with us.
  • From third parties: SARS, CIPC, banks, and other regulatory bodies where necessary for compliance services.
  • Automatically: Through cookies and analytics when you browse our website.
  • From public records: Company registrations, property records, and other publicly available information for verification purposes.

5. Purpose of Processing

We process your personal information for the following lawful purposes:

Purpose Legal Basis
Providing accounting, bookkeeping, tax, and payroll services Contractual necessity
SARS tax compliance and submissions (VAT201, EMP201, ITR12, etc.) Legal obligation
CIPC company secretarial services and annual returns Legal obligation / Consent
Business advisory and financial reporting Contractual necessity / Legitimate interest
Communication regarding your account and services Contractual necessity
Marketing communications (with your consent) Consent
Fraud prevention and security Legitimate interest / Legal obligation
Compliance with professional regulatory requirements (SAIPA, SARS) Legal obligation

6. Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • Regulatory Bodies: SARS, CIPC, UIF, Department of Labour, and other government agencies as required by law.
  • Professional Service Providers: Auditors, legal advisors, and IT service providers bound by confidentiality agreements.
  • Financial Institutions: Banks when processing payments or verifying account details.
  • With Your Consent: Any other third party where you have given explicit written permission.
💡 Third-Party Obligations

All third parties with whom we share personal information are contractually obligated to maintain confidentiality and process data only for the specified purposes, in compliance with POPIA.

7. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction:

  • Password-protected digital files and encrypted storage systems.
  • Secure cloud-based accounting software with role-based access controls.
  • Physical security measures for paper records (locked filing cabinets, restricted access).
  • Regular staff training on data protection and confidentiality.
  • Secure disposal of records no longer required (shredding for physical, secure deletion for digital).

Despite our security measures, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.

8. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including:

  • Active Client Records: For the duration of our engagement plus the applicable statutory retention period.
  • Tax Records: Minimum of 5 years from the date of submission, as required by SARS.
  • Company Secretarial Records: As long as the company exists plus 7 years after deregistration.
  • Payroll Records: Minimum of 3 years from the date of the last entry, per the Basic Conditions of Employment Act.

Once the retention period expires, we securely destroy or anonymise your personal information in a manner that ensures it cannot be reconstructed or read.

9. Your Rights as a Data Subject

Under POPIA, you have the following rights regarding your personal information:

  • Right to Access: Request confirmation of whether we hold your personal information and obtain a copy thereof.
  • Right to Correction: Request that we correct or update inaccurate, irrelevant, excessive, or outdated personal information.
  • Right to Deletion: Request deletion of your personal information where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent.
  • Right to Object: Object to the processing of your personal information for direct marketing purposes.
  • Right to Lodge a Complaint: Lodge a complaint with the Information Regulator if you believe your rights have been infringed.
📜 Limitations on Rights

Please note that certain rights may be limited where the processing is necessary for compliance with a legal obligation (e.g., SARS record-keeping requirements) or for the establishment, exercise, or defence of legal claims.

10. Cookies and Website Tracking

Our website may use cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and understand where our visitors are coming from. Cookies are small text files stored on your device.

You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or not function properly.

11. Cross-Border Transfers

We primarily process personal information within the Republic of South Africa. Where we use cloud-based software providers (e.g., accounting software, email services), your data may be stored on servers located outside South Africa. In such cases, we ensure that adequate protection measures are in place, including contractual safeguards that meet POPIA requirements.

12. Changes to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, legal requirements, or operational needs. Any material changes will be communicated to you via email or through a prominent notice on our website. The updated notice will indicate the effective date of the changes.

Last updated: July 2026

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Notice or our data protection practices, please contact our Information Officer:

Physical Address
13 Austin Road, Midrand,
Johannesburg, 1685
Phone / WhatsApp
👤 Information Regulator

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa:

Website: inforegulator.org.za
Email: inforeg@justice.gov.za
Tel: 010 023 5207