Effective Date: 8 November 2025 Last Reviewed: May 2026 Applies to: kxx.co.za and all KXX service engagements
KXX ("we", "us", "our") is committed to protecting your privacy and ensuring that your personal information is collected, processed, and stored lawfully and transparently. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit kxx.co.za (the "Website"), engage our services, or communicate with us.
This policy complies with the Protection of Personal Information Act 4 of 2013 (POPIA) and incorporates relevant principles of the General Data Protection Regulation (GDPR) where applicable.
1. Responsible Party
KXX is the responsible party for the processing of personal information as defined under POPIA.
Contact details:
- Email: info@kxx.co.za
- Telephone: +27 011 462 6269
- Website: kxx.co.za
- LinkedIn: linkedin.com/company/kxxinc
2. Personal Information We Collect
2.1 Information You Provide Directly
We may collect the following when you make an enquiry, apply for a position, or engage our services:
- Full name and contact details (email, phone number)
- Company name and job title
- Information submitted through contact or career application forms
- Professional and financial information required for audit, advisory, or assurance engagements
- Identity documentation required for compliance and onboarding
2.2 Information Collected Automatically
When you visit our Website, the following data may be collected automatically:
- IP address and approximate location
- Browser type and version
- Device and operating system information
- Pages visited and time spent on the Website
- Date and time of access
- Referring website or URL
- Cookies and usage analytics data
3. How We Use Personal Information
We process personal information for the following purposes:
- Responding to enquiries submitted through the Website or by other means
- Providing audit, assurance, advisory, and related professional services
- Conducting client onboarding and regulatory compliance checks
- Fulfilling statutory and professional reporting obligations
- Processing career applications and managing recruitment
- Improving Website performance, usability, and content
- Sending service-related communications, including newsletters where consent has been provided
- Maintaining internal records and business administration
- Protecting against fraud, security threats, and unlawful activity
We will only process personal information where there is a lawful basis to do so under POPIA and applicable law.
4. Legal Basis for Processing
We rely on one or more of the following lawful grounds:
- Performance of a contract - where processing is necessary to provide our services or fulfil an engagement
- Legal obligation - where processing is required to comply with applicable legislation (including the Companies Act, PFMA, MFMA, and tax statutes)
- Legitimate interests - where processing supports our business operations without overriding your rights
- Consent - where you have provided specific, informed consent, which you may withdraw at any time
5. Cookies and Website Analytics
Our Website uses cookies and similar tracking technologies to enable core functionality, analyse traffic, and improve performance. We may use tools such as Google Analytics to understand how visitors interact with our Website. Data collected through these tools is subject to the service provider's own privacy policies.
You may disable or delete cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of our Website.
Where required by law, we will seek your consent before placing non-essential cookies on your device.
6. Disclosure of Personal Information
We do not sell, rent, or trade personal information to third parties.
We may share personal information with:
- Regulatory bodies and oversight authorities, where required by law or professional standards
- Professional advisors including legal counsel, tax practitioners, and compliance specialists
- IT service providers and hosting partners who support our operations
- Third-party service providers assisting with Website functionality, subject to appropriate data processing agreements
- Law enforcement or government bodies where required by statute or court order
All third parties are required to implement appropriate technical and organisational security measures and are contractually bound to process personal information only as instructed.
7. International Transfers
Where personal information is transferred outside of South Africa - for example, to cloud-hosted service providers - we ensure that appropriate safeguards are in place in accordance with POPIA Section 72 and, where applicable, GDPR standards. We will only transfer personal information to jurisdictions that offer an adequate level of protection, or where suitable contractual protections have been established.
8. Data Security
We implement reasonable and appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.
Our security practices include:
- Access controls and authentication protocols
- Encrypted data transmission (HTTPS)
- Regular security reviews and software updates
- Staff training on data protection obligations
Despite these measures, no method of electronic transmission or storage is completely secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the Information Regulator and affected individuals in accordance with our obligations under POPIA.
9. Retention of Personal Information
We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law, professional standards, or regulatory obligations.
Audit and assurance records are retained in accordance with the requirements of the Independent Regulatory Board for Auditors (IRBA), the Companies Act, and other applicable legislation. Where personal information is no longer required, it will be securely deleted or anonymised.
10. Your Rights
Subject to applicable law, you have the right to:
- Access - request a copy of the personal information we hold about you
- Correction - request that inaccurate or incomplete information be corrected
- Deletion - request that your personal information be deleted where it is no longer required
- Objection - object to the processing of your personal information on grounds relating to your specific situation
- Restriction - request that we restrict how we process your personal information
- Withdrawal of consent - withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing
- Complaint - lodge a complaint with the Information Regulator of South Africa
To exercise any of the above rights, please contact us at info@kxx.co.za.
Information Regulator (South Africa): inforeg.org.za
11. Third-Party Links
Our Website may contain links to third-party websites, including platforms such as LinkedIn, Instagram, and Facebook. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party site you visit.
12. Newsletter and Marketing Communications
Where you have subscribed to our newsletter or opted in to marketing communications, we will use your contact information to send you updates, insights, and news from KXX. You may unsubscribe at any time by clicking the unsubscribe link in any communication, or by contacting us directly at info@kxx.co.za.
13. Children's Privacy
Our Website and services are not directed at or intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has submitted personal information to us, please contact us immediately and we will take steps to remove such information.
14. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. The revised policy will be published on our Website with an updated effective date. We encourage you to review this page periodically. Continued use of the Website following any changes constitutes acceptance of the updated policy.
15. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information, please contact:
- Email: info@kxx.co.za
- Telephone: +27 011 462 6269
- Website: kxx.co.za/contact-us