SOC OPERATIONAL24/7/365 MONITORINGMTTA < 15 MINTHREAT INTEL: UPDATED HOURLYPOPIA-ALIGNED INCIDENT HANDLINGB-BBEE LEVEL 1 · 135% PROCUREMENT RECOGNITION
Policy

Privacy & Data Protection Policy

Lightbeam Digital Group (Pty) Ltd · Website Policy · South Africa

Effective Date: 2 September 2026 · Version 1.0

1. Purpose and Scope

This Privacy & Data Protection Policy explains how Lightbeam Digital Group (Pty) Ltd (“Lightbeam Digital”, “we”, “us” or “our”) collects, uses, stores, protects and discloses personal information in connection with our website, managed IT services, cybersecurity services, Security Operations Centre (“SOC”) functions, technical support, connectivity, endpoint management, communications, portals and related services.

This policy applies to visitors to our websites, prospective and existing clients, client personnel, suppliers, partners, applicants and other individuals whose personal information we process. Where we process personal information on behalf of a client, the client may determine the purposes and means of processing and Lightbeam Digital may act as an operator/service provider subject to the applicable agreement and law.

2. Legal and Regulatory Framework

Lightbeam Digital seeks to process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), applicable regulations and other South African laws relevant to privacy, electronic communications, cybersecurity, records and information management. Where another jurisdiction’s mandatory privacy law applies to a particular processing activity, additional requirements may apply.

3. Information We May Collect

  • Identity and contact information, including names, business contact details, usernames and account identifiers.
  • Business and employment information supplied by clients or their personnel.
  • Service and account information, including contracts, service requests, tickets, quotations, billing and support history.
  • Technical information such as IP addresses, device identifiers, operating-system information, browser information, network information, authentication events and service logs.
  • Security telemetry generated by managed endpoints, firewalls, email-security systems, SIEM/SOC tooling, vulnerability-management platforms, endpoint-protection products and other security controls.
  • Communications and correspondence, including email, support tickets, telephone records where lawfully recorded, and information provided through forms.
  • Website usage information, including cookies, analytics data, pages visited and approximate technical location derived from network information.
  • Information necessary to investigate security incidents, fraud, abuse, unauthorised access or other threats.
  • Information voluntarily provided to us for recruitment, supplier onboarding, marketing or business development.

4. How We Collect Information

  • Directly from individuals or authorised client representatives.
  • Automatically through websites, applications, portals, security and infrastructure systems.
  • From clients where necessary to deliver contracted services.
  • From service providers and business partners where lawful and necessary.
  • From publicly available sources where appropriate and lawful.
  • Through security monitoring and logging performed under an applicable service agreement or authorised security function.

5. Purposes of Processing

We may process personal information to provide and support managed IT, network, cloud, endpoint, email, connectivity and cybersecurity services; monitor and protect systems; detect and respond to threats; authenticate users; troubleshoot incidents; maintain service quality; administer contracts and accounts; process billing; communicate with customers; comply with legal obligations; prevent fraud and abuse; improve our services; maintain records; and protect the rights, property and security of Lightbeam Digital, our clients and other parties.

6. Cybersecurity, SOC and Monitoring Data

Because Lightbeam Digital operates in the IT and cybersecurity environment, service delivery may require the collection or processing of security-relevant information. Depending on the contracted service, this can include authentication events, endpoint telemetry, network flows, firewall events, email-security metadata, malware detections, vulnerability findings, alerts, domain information, IP addresses, usernames, device names and incident evidence. Such processing is performed for authorised operational, security and support purposes and is subject to contractual, technical and access controls.

Clients remain responsible for ensuring that they have the necessary authority to instruct Lightbeam Digital to process information within their environments, including information relating to their employees, contractors, customers and other data subjects.

7. Responsible Party and Operator Roles

The applicable role depends on the processing activity. Lightbeam Digital may act as a responsible party where it determines the purpose and means of processing its own business information. In managed services and cybersecurity engagements, Lightbeam Digital may act as an operator processing information on behalf of a client. Where an agreement contains specific data-processing terms, those terms will govern to the extent of any inconsistency.

8. Sharing and Disclosure

We may disclose information to authorised employees and contractors, technology vendors, hosting and cloud providers, security vendors, telecommunications providers, professional advisers, payment providers, regulators, law-enforcement authorities and other third parties where necessary, lawful and proportionate. We do not sell personal information as a business model.

9. International Transfers

Certain technology, cloud, security or support providers may process information outside South Africa. Where applicable, Lightbeam Digital will implement appropriate contractual, organisational or other safeguards required by applicable law. Clients requiring specific data residency arrangements should address those requirements contractually before service commencement.

10. Information Security

We apply reasonable technical and organisational safeguards appropriate to the nature and risk of the information processed. Depending on the service, controls may include access management, least-privilege principles, authentication controls, endpoint protection, encryption, network security, logging, monitoring, backups, vulnerability management, incident response procedures, segregation of duties and staff awareness measures.

No internet-connected system can be guaranteed to be completely secure. Security controls reduce risk but do not eliminate the possibility of compromise, outage, data loss or unauthorised access.

11. Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, contractual and operational requirements, legal obligations, dispute resolution, security investigations and legitimate business requirements. Retention periods may differ by record type and service agreement. Secure deletion, destruction or anonymisation may be applied when information is no longer required.

12. Data Subject Rights

Subject to applicable law and lawful grounds for refusal or limitation, individuals may request access to personal information, correction or updating of inaccurate information, deletion where legally permissible, objection to certain processing, or other rights available under applicable privacy law. Requests may require identity verification and may be subject to applicable fees, exemptions and statutory timeframes.

13. Cookies and Analytics

Our website may use necessary cookies and, where enabled, analytics or functional technologies to operate the site, understand usage and improve user experience. Where consent is legally required, we will seek it through appropriate mechanisms. Users may control cookies through their browser, although disabling certain cookies may affect website functionality.

14. Direct Marketing

Where we conduct electronic direct marketing, we seek to comply with applicable legal requirements, including consent and opt-out requirements where applicable. Recipients may unsubscribe from marketing communications using the mechanism provided or by contacting us.

15. Security Incidents and Breaches

If we identify a security incident involving personal information, we will assess and manage it in accordance with our incident-response procedures, contractual obligations and applicable law. Where notification is legally required, affected parties and/or regulators will be notified in accordance with the applicable requirements.

16. Third-Party Websites

Our website may contain links to third-party websites or services. Their privacy practices are governed by their own policies. Lightbeam Digital is not responsible for the privacy, security or content practices of third parties.

17. Children

Our business services are intended primarily for organisations and professional users. We do not knowingly seek to collect personal information from children through the website except where lawfully authorised and necessary for a specific service.

18. Changes to this Policy

We may update this policy to reflect changes in law, technology, services or business practices. The latest version published on our website will apply from its stated effective date.

19. Contact

Privacy enquiries, data-subject requests and complaints should be directed to Lightbeam Digital through the official contact channels published on our website. Where an Information Officer or designated privacy contact is appointed, the relevant details will be published or supplied upon request.

End of Policy