Privacy Policy

Last updated: 22 August 2025

Effective date: 22 August 2025

1) Who we are

Controller: Coastal Labs

Registered entity: Coastal Labs, (Pty) Ltd

Registration number: K2025/628031/07

Registered address: Wessel Swart Drive, Pinelands, Port Eliabeth, 6070

Information Officer (POPIA): Kieran Armstrong, Directorkieran.armstrong@coastal-labs.co.za

Contact: info@coastal-labs.co.za

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use coastal-labs.co.za (the Site) and when you contact us about our services.

2) What we collect

We collect information that you provide directly and data collected automatically.

2.1 Information you provide

  • Contact forms / enquiries: name, surname, email, phone, company, message content, and any files you upload.
  • Client onboarding (if you become a client): billing details, address, domain ownership details, and authorised user information.

2.2 Information collected automatically

  • Usage data: pages visited, actions taken, session duration, and referring URLs.
  • Device data: browser, device type, operating system, approximate location (city/region).
  • Log data: IP address and timestamps collected by our hosting and security tools for security and troubleshooting.
  • Cookies & similar tech: analytics cookies (e.g., GA4) and strictly necessary cookies (e.g., load balancing, security).

We do not intentionally collect special categories of data via the Site. Please avoid submitting sensitive information (e.g., health data, ID numbers) via general forms.

3) Why we process your information

  • To respond to enquiries and provide quotes.
  • To operate, secure, and improve the Site (debugging, analytics, preventing abuse).
  • To perform a contract and manage client relationships (if you engage us).
  • To comply with legal obligations (tax, accounting, lawful requests).
  • Marketing (lightweight): to send service updates or case studies if you opt in (you can opt out at any time).

Depending on context, we rely on:

  • Consent (e.g., non-essential analytics/marketing cookies where required).
  • Legitimate interests (website security, basic analytics, responding to your enquiry) balanced against your rights.
  • Contract (providing services you request).
  • Legal obligation (record keeping, lawful disclosures).

5) Cookies

We use cookies to run the Site and understand usage.

  • Strictly necessary: required for security and core functionality.
  • Analytics: helps us improve content and performance.

Where law requires consent for non-essential cookies, we will obtain it via a banner. You can change preferences in your browser or cookie banner settings at any time. Blocking some cookies may impact Site functionality.

6) Analytics

We use Google Analytics 4 to understand aggregate usage. Analytics may set cookies and process usage data. Where required, we request consent before loading analytics scripts. We configure analytics to minimize data where possible (e.g., IP anonymization if available). See the provider’s privacy policy for details.

7) Sharing and disclosure

We share personal information only with:

  • Service providers / processors: hosting (Hostinger), email (Zoho Mail), analytics (Google Analytics 4). These providers process data on our instructions and are subject to confidentiality and appropriate safeguards.
  • Professional advisors: legal, banking, accounting (where necessary).
  • Authorities: if legally required or to protect rights, safety, or property.
  • Business transfers: in connection with a merger, acquisition, or asset sale (we will notify you where legally required).

We do not sell personal information.

8) International transfers

Your information may be transferred to and processed in countries outside South Africa, the EU/EEA, and the UK. Where we transfer personal information internationally, we use appropriate safeguards (e.g., standard contractual clauses or equivalent) as required by law.

9) Data retention

  • Enquiry records: kept for 24 months after last contact unless you ask us to delete sooner (subject to legal holds).
  • Client records: retained for 5 after contract end to meet legal and tax obligations.
  • Server logs/security events: 90 days.
  • Backups: 30 days rolling.

We delete or anonymise data when no longer needed.

10) Your rights

Depending on your location, you may have rights to:

  • Access the personal information we hold about you.
  • Rectify inaccurate or incomplete information.
  • Delete your information (subject to legal exceptions).
  • Object to or restrict certain processing.
  • Data portability (where applicable).
  • Withdraw consent at any time for processing based on consent.

To exercise rights, contact info@coastal-labs.co.za. We will verify your identity before fulfilling requests.

Complaints

If you believe we have not handled your information lawfully, you can complain to the Information Regulator (South Africa) or your local supervisory authority. We encourage you to contact us first so we can resolve concerns.

11) Security

We use reasonable technical and organisational measures to protect personal information (e.g., TLS, access controls, least-privilege, updates/patching, backups). No system is perfectly secure; transmission of data over the internet carries risk.

12) Children

The Site is intended for business audiences and not for children under 18. We do not knowingly collect information from children. If you believe a child has provided us information, contact us to delete it.

The Site may contain links to third-party websites. We are not responsible for their privacy practices. Review their policies before providing personal information.

14) Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be indicated by a new “Last updated” date and will be effective when posted. Material changes will be highlighted on the Site or communicated to you.

15) Contact

Questions about this Privacy Policy or our data practices?

Email: info@coastal-labs.co.za