This policy explains how Tri2b (Pty) Ltd collects and handles personal information, in line with the Protection of Personal Information Act 4 of 2013 (POPIA). It covers this website and the services we provide to clients.
Tri2b (Pty) Ltd is the responsible party for the information described here. Our Information Officer is Jacques Barnard, who can be reached at hello@tri2b.cloud, on +27 72 153 5649, or by post at Tri2b (Pty) Ltd, Riverside Loft 1051, Tyger Falls Boulevard, Bellville, Western Cape, 7530, South Africa.
1. What we collect
Information you give us directly:
- Your name, email address, company, and whatever you choose to include when you email us or connect with us on LinkedIn.
- Client and billing details — contact person, billing address, VAT number where applicable, and the invoice and payment records that go with an engagement.
- Anything you share with us in the course of a project, which may include access credentials and business data belonging to you.
Information collected automatically when you visit this site, through PostHog, a product analytics service we run on its EU-hosted infrastructure:
- Pages viewed, the referring page, and time spent on each page.
- Device type, browser, operating system, and screen size.
- Approximate location (city or region level), derived from your IP address.
- Session replays — anonymised recordings of how pages are used. All form inputs are masked, so anything you type is not captured. Recordings are deleted after seven days.
We do not run advertising trackers, and we do not sell or rent personal information to anyone.
2. Payment information
Card payments are processed by Paystack, a licensed payment service provider. Card numbers, expiry dates, and CVV codes are entered directly on Paystack's secure checkout and are never received or stored by us. What we receive back is the transaction reference, the amount, whether the payment succeeded, and the masked last four digits of the card. Paystack processes that data as a separate responsible party under its own privacy policy.
For payments made by electronic funds transfer, we see the bank account name and reference that appear on our bank statement, which we keep as part of our accounting records.
3. Why we process it
- To answer enquiries and prepare proposals.
- To deliver the services we have been engaged to provide.
- To invoice, collect payment, and keep the accounting and tax records South African law requires of us.
- To understand how this website is used, so we can improve it.
- To keep our systems secure and to detect and prevent fraud.
- To meet legal, regulatory, and payment-provider compliance obligations.
4. Our legal grounds under POPIA
We process personal information where it is necessary to perform a contract with you, where we have a legal obligation (tax and company law, for example), where you have consented, or where we have a legitimate interest that does not override your rights — such as understanding site usage or securing our infrastructure. You can withdraw consent at any time where consent is the ground we rely on.
5. When we hold information on a client's behalf
Much of our work runs inside a client's own systems. Where we build, host, or maintain an application that holds personal information about their customers, staff, or users, it is the client who decides why and how that information is processed. They are the responsible party for it. We act as an operator on their behalf, we process it only on their instructions and only for the engagement, and we do not use it for our own purposes.
Sections 20 and 21 of POPIA require that arrangement to be set out in a written contract, so we put one in place before we are given access. Under it we hold the information in confidence, apply the safeguards described in section 10 below, and tell the client without undue delay if we have reason to believe someone has accessed or acquired it without authorisation. When the engagement ends we return the information or delete it, whichever the client asks for.
If you are a customer or user of a system we built for one of our clients, this policy is not the one that governs your information — theirs is. Write to us anyway if you are unsure who to ask, and we will point you to the right party.
6. Cookies and local storage
PostHog sets first-party cookies and browser local storage so that repeat visits within a session are counted as one visit rather than many. We do not set advertising cookies, and we do not track you across other websites. You can block or clear these through your browser settings; the site works normally without them.
7. Who we share it with
We share personal information only with the operators and advisors we need to run the business, and only as far as each of them needs it:
- PostHog — website analytics and session replay, hosted in the European Union.
- Paystack — card and instant EFT payment processing.
- Google Cloud — hosting for this site and its supporting services.
- Cloudflare — DNS, content delivery, TLS termination, and protection against attack. It sits in front of every request, so it sees the IP address of each visit.
- Our email and calendar provider, for correspondence with you.
- Our accountants, auditors, and professional advisors, under confidentiality obligations.
- Regulators, banks, or law enforcement, where a law or a lawful request requires it.
8. Cross-border transfers
Some of the operators above process information outside South Africa — PostHog in the European Union, and Google Cloud and Cloudflare across their global networks. Where that happens, we transfer information only to recipients that are subject to laws or binding agreements offering protection substantially similar to POPIA, as required by section 72 of the Act.
9. How long we keep it
- Enquiry correspondence: up to 24 months after the last exchange, unless it becomes part of a client file.
- Client, invoice, and payment records: seven years, the minimum section 24 of the Companies Act 71 of 2008 requires for company records.
- Website analytics: 12 months.
- Session replays: seven days.
- Project data belonging to a client: for the duration of the engagement, then deleted or handed back on request.
10. How we protect it
Traffic to this site is encrypted in transit with TLS. Access to client systems and to our own infrastructure is restricted to those who need it, protected by multi-factor authentication, and kept patched. Form inputs are masked in session replays. No system is perfectly secure, but if a breach affects your personal information we will notify you and the Information Regulator as POPIA requires.
11. Your rights
Under POPIA you have the right to:
- Ask what personal information we hold about you, and get a copy of it.
- Have inaccurate or incomplete information corrected.
- Ask us to delete information we no longer have grounds to keep.
- Object to processing based on legitimate interest, and to withdraw consent where consent applies.
- Complain to the Information Regulator.
To exercise any of these, email hello@tri2b.cloud. We may need to verify your identity first, and we will respond within 30 days. There is no charge unless a request is manifestly excessive.
If you are not satisfied with how we have handled a request, you can complain to the Information Regulator (South Africa) at inforeg@justice.gov.za or through inforegulator.org.za.
12. Children
This website and our services are aimed at businesses and are not directed at children under 18. We do not knowingly collect their personal information.
13. Changes to this policy
We will update this page when our practices change, and the date at the top shows when it was last revised. Material changes affecting existing clients will be communicated by email.
14. Contact
Privacy questions and requests go to hello@tri2b.cloud.