1. Who We Are
This Privacy Policy is published by AXIOUS SPACES DESIGN AND BUILD (Pty) Ltd (Registration No. 2025/647631/07, VAT/Tax Ref. 9615981207), trading as Axious Creative Studio ("Axious", "we", "us", "our"). We are a private company incorporated in the Republic of South Africa.
We build custom websites, client portals, and cloud POS systems for South African businesses. We are the responsible party for personal information collected through our website, portals, and services, as defined in the Protection of Personal Information Act 4 of 2013 ("POPIA").
Contact us at: design@axiouscreativestudio.co.za
2. Information We Collect
2.1 Information you give us directly
- Quote & contact forms: name, business name, email address, phone number, and project details.
- Client portal registration: name, email, password (stored hashed), company, profile picture (optional).
- Agent programme application: full name, email, phone, WhatsApp number, South African ID number or passport number and country, banking details (for payout), and why you want to join.
- Support & billing: payment confirmations, invoices, bank details for EFT payouts.
2.2 Information collected automatically
- Server logs: IP address, browser user-agent, date and time of access, pages visited. Retained for security and debugging purposes.
- Cookies: session cookies for portal login. Analytics cookies if you consent (see §5).
- Referral tracking: if you arrive via an agent referral link, a short-lived tracking cookie records the referral code for up to 30 days.
2.3 Information from third parties
We may receive limited information from payment providers (PayFast, Yoco) confirming that a transaction was completed. We do not receive or store your full card details — these are handled entirely by the payment provider.
3. How We Use Your Information
We process your personal information only for the purposes for which it was collected:
- Responding to quote requests and enquiries
- Delivering and supporting the services you have purchased
- Managing your client portal or agent account
- Processing commission payments to approved agents
- Sending transactional messages (invoices, receipts, delivery updates)
- Sending service-related updates (new features, important policy changes) — you can opt out at any time
- Complying with our legal obligations (SARS, POPIA, Consumer Protection Act)
- Detecting and preventing fraud or misuse of our platform
We do not sell, rent, or exchange your personal information with third parties for their own marketing purposes.
4. Who We Share It With
We share personal information only where necessary:
- Service providers: hosting (Vercel), email delivery (transactional mail providers), database (MongoDB Atlas). These operators process data on our behalf under confidentiality obligations.
- Payment processors: PayFast and/or Yoco, for processing online payments. Each has its own privacy policy.
- SARS / legal authorities: where required by South African law (e.g., IT3(a) certificates for agent commissions, SARS compliance).
- Other agents (limited): if you are an agent, your first name and last initial — and optionally a profile photo — may appear on your co-branded landing page. No sensitive details are shared publicly.
5. Cookies & Tracking
5.1 Strictly necessary cookies
We use session cookies to keep you logged in to our portals. These are essential for functionality and cannot be opted out of while using the portal.
5.2 Analytics cookies
Our main website may use Google Analytics 4 to understand how visitors interact with our pages (pages visited, time on site, device type). This data is anonymised and aggregated. You can opt out by installing the Google Analytics Opt-out Browser Add-on.
5.3 Referral tracking cookie
If you click an agent referral link, a cookie stores the referral code on your device for up to 30 days. This cookie is used only to credit the referring agent if you make a purchase. It contains no personal information about you.
5.4 Managing cookies
You can delete or block cookies in your browser settings. Blocking strictly necessary cookies may prevent you from logging in to our portals.
6. Retention
We retain personal information for as long as necessary to fulfil the purposes described above, or as required by law:
- Client accounts: for the duration of the client relationship plus 5 years (SARS and CPA compliance).
- Agent accounts: for the duration of the agent relationship plus 2 years (confidentiality obligations per §7 of the Agent Agreement).
- Server logs: 90 days, then automatically purged.
- Inactive enquiries / leads: deleted or anonymised after 24 months of inactivity.
When information is no longer needed, we securely delete or anonymise it.
7. Your Rights Under POPIA
As a data subject under POPIA, you have the following rights:
- Access: request a copy of the personal information we hold about you.
- Correction: ask us to correct inaccurate or incomplete information.
- Deletion: request that we delete your information, subject to any legal retention obligations.
- Objection: object to processing of your information for direct marketing purposes.
- Complaint: lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za if you believe your rights have been violated.
To exercise any of these rights, email design@axiouscreativestudio.co.za with your name, account email, and a description of your request. We will respond within 30 days.
8. Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Passwords stored using bcrypt hashing — never in plain text
- HTTPS (TLS) enforced on all pages and API endpoints
- API authentication via signed JWT tokens with expiry
- Access to production databases restricted to authorised personnel only
- Login audit logs to detect unauthorised access attempts
No system is completely secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and the Information Regulator as required by POPIA.
9. Third-Party Services
Our website and portals integrate with the following third-party services. Each has its own privacy policy:
- Vercel — hosting and edge delivery
- MongoDB Atlas — cloud database
- Google Analytics — website analytics (anonymised)
- Google Fonts — typography (font files served from Google's CDN)
- PayFast — payment processing
- Yoco — payment processing
We are not responsible for the privacy practices of these third-party services.
10. Children's Privacy
Our services are not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has submitted information to us, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The version date at the top of this page reflects when it was last revised. For material changes, we will notify registered users by email at least 14 days before the change takes effect. Continued use of our services after the effective date constitutes acceptance.
12. Contact & Complaints
For any privacy-related queries, access requests, or complaints:
- Email: design@axiouscreativestudio.co.za
- WhatsApp: +27 78 012 0013
- Website: axiouscreativestudio.co.za
If you are not satisfied with our response, you may contact the Information Regulator of South Africa:
- Website: inforegulator.org.za
- Email: inforeg@justice.gov.za