Legal

POPIA Privacy & Data Protection Policy

Effective Date: 1 July 2021  |  Last Updated: March 2026

1. Introduction

The Protection of Personal Information Act, 2013 ("POPIA") provides for eight data protection principles to ensure the protection of all data relating to companies, staff, and clients. The Promotion of Access to Information Act, 2 of 2000 ("PAIA") provides for access to such information and the instances in which it may be refused.

2. Purpose

Data privacy and data protection is important to Stonebridge Properties & Developments (Pty) Ltd, trading as Stonebridge Finance ("Stonebridge," "we," "us," or "our"). This Policy sets out the POPIA principles to ensure the safekeeping of all data by Stonebridge and all persons, employees, and parties associated with us. This Policy applies to all data obtained via our products, services, websites, and events, or by any other means.

3. Definitions

4. The Eight POPIA Principles

Principle 1: Accountability

Stonebridge has appointed an Information Officer who is responsible for ensuring that the eight POPIA information principles are implemented and enforced.

Principle 2: Processing Limitation

Only necessary information is collected, directly from the person to whom the personal information relates, and with their consent. Processing shall be for a lawful purpose only.

Principle 3: Purpose Specification

Personal information is collected for a specific purpose and the Data Subject must be made aware of the purpose for which it was collected.

Principle 4: Further Processing Limitation

Further processing of personal information must be compatible with the purpose for which the information was originally collected.

Principle 5: Information Quality

Reasonable steps are taken to ensure that all information collected is accurate, complete, not misleading, and up to date in accordance with the purpose for which it was collected.

Principle 6: Openness

The party collecting the information must be transparent and inform the applicable regulator where required. The Data Subject must be made aware that their information is being collected.

Principle 7: Security Safeguards

The integrity of the information under our control is secured through appropriate technical and organisational measures, including encryption, access controls, and secure storage.

Principle 8: Data Subject Participation

Data Subjects have the right (free of charge) to request confirmation from Stonebridge regarding the personal details we hold, and may request that such information be amended or deleted.

5. Information Officer

Stonebridge has appointed an Information Officer who is a senior person in the organisation and is responsible for ensuring compliance with POPIA, training, and implementation of the required processes.

Information Officer Contact:
Email: info@stonebridgefinance.co.za
Address: George, Western Cape, South Africa

6. Purpose of Information Collection

Stonebridge collects information from Data Subjects for various purposes, including:

7. Access to Information

Data Subjects have the right to request a copy of the information that Stonebridge holds on them. Such requests may be directed to the Information Officer at the contact details above. Access requests may be subject to the payment of an allowable administration fee.

Stonebridge will not disclose or share information relating to any Data Subject unless: it is specifically agreed with the Data Subject; it is already publicly available or in the interest of the public; it is required in terms of law; or Stonebridge believes in good faith that the law requires disclosure.

8. Collection of Information

Stonebridge collects information in various ways, including directly from individuals (for example, when submitting a funding application, completing our online enquiry form, or communicating with us), from publicly available sources, and through cookies and similar technologies on our website.

Where possible, we inform Data Subjects which information they are legally required to provide and which is optional.

9. Cookies and Website Usage

Our website may use cookies to enhance the user experience. Cookies are small data files stored on your device that help us understand how you interact with our site. You may configure your browser to reject cookies, although doing so may limit certain website functionality.

10. Marketing

Stonebridge may use certain information provided by Data Subjects to offer further services that we believe may be of interest. This is subject to prior consent. Data Subjects may unsubscribe from marketing communications at any time by contacting the Information Officer.

11. Data Retention

Personal information is retained only for as long as is necessary for the purpose for which it was collected, or as required by law. When personal information is no longer needed, it is securely destroyed or de-identified.

12. Data Breach Notification

In the event of a data breach that compromises the confidentiality or security of personal information, Stonebridge will notify the Information Regulator and affected Data Subjects as soon as reasonably possible, in accordance with POPIA requirements.

13. Complaints

If a Data Subject believes that their personal information has been improperly processed by Stonebridge, they may lodge a complaint with the Information Officer or directly with the Information Regulator of South Africa:

Information Regulator (South Africa)
Website: inforegulator.org.za
Email: complaints.IR@justice.gov.za

14. Changes to This Policy

Stonebridge reserves the right to amend this policy from time to time. Any material changes will be communicated via our website. Continued use of our services after such changes constitutes acceptance of the updated policy.