Data Protection (GDPR/POPIA) Policy

    Last Updated: September 29, 2026

    1. Key terms used in this policy

    • Individual / data subject - a living person who is identified, or identifiable, from the information in question.
    • Personal data - any information relating to an individual who is or can be identified from it.
    • Processing - anything done with personal data: collecting, recording, storing, organising, changing, retrieving, restricting, deleting, or sharing it with others.
    • Consent - a freely given, specific, informed indication that the individual agrees to their personal data being used for a stated purpose.
    • Criminal offence data - personal data relating to criminal allegations, proceedings, convictions, or offences.
    • Applicable data protection law - the UK GDPR and the Data Protection Act 2018 (and, where relevant, the EU GDPR), and South Africa's Protection of Personal Information Act 2013 (POPIA) for personal information processed in or from South Africa.
    • Team member - any director, employee, intern, volunteer, contractor, or consultant working for or engaged by Solv Systems.
    • Special category data - data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health information, or data about a person's sex life or sexual orientation. Under POPIA this is called special personal information, and it also includes information about a person's criminal behaviour.

    2. Why this policy exists, and what happens if it isn't followed

    Solv Systems holds personal data belonging to many people - job applicants, current and former team members, clients, customers, suppliers, and other contacts. This policy sets out how we handle that information responsibly, and how we stay transparent about it.

    It applies to every team member whenever they handle personal data in the course of their work. Not following it is treated as a disciplinary matter. Where a breach is serious or deliberate - for example, accessing or sharing personal data without authorisation - it will be treated as gross misconduct, which can result in dismissal or termination of a contract.

    Team members should also be aware that some misuse of personal data is a criminal offence, not just a policy breach. It is unlawful to knowingly or recklessly:

    • obtain, take, or pass on personal data without Solv Systems' or the individual's permission - including taking a client's contact details for personal use, accessing a colleague's records without a valid reason, or otherwise misusing or removing personal data;
    • re-identify data that has been anonymised, without proper authorisation;
    • alter, hide, delete, or destroy personal data in order to stop it being disclosed in response to a data subject request (see Section 11).

    If unlawful activity of this kind is suspected, Solv Systems will refer the matter to the relevant supervisory authority - the Information Commissioner's Office (ICO) in the UK, the Information Regulator in South Africa, or the equivalent body in the jurisdiction concerned.

    3. The principles we work to

    Everyone handling personal data at Solv Systems must ensure it is:

    1. processed lawfully, fairly, and transparently;
    2. collected for specific, stated purposes and not used in ways incompatible with those purposes;
    3. adequate and relevant, and limited to what's actually needed;
    4. accurate, and kept up to date where necessary, with inaccuracies corrected or removed promptly;
    5. kept in identifiable form for no longer than necessary;
    6. protected by appropriate security against unauthorised use, loss, or damage;
    7. only transferred outside the UK/EEA, or outside South Africa, where suitable safeguards are in place; and
    8. handled in a way that respects individuals' rights over their own data, as described in Section 11.

    4. The Data Protection Officer

    Solv Systems' Data Protection Officer, Steve Smith (steve.smith@solv-systems.com), is responsible for overseeing data protection compliance across the business. Team members should get in touch with the Data Protection Officer whenever:

    • they're unsure whether, how, or when a piece of personal data can be used;
    • they're not certain which lawful basis applies to a particular use of personal data;
    • personal data is being collected and a privacy notice may be needed;
    • there's doubt about whether data held is still accurate or current;
    • it's unclear how long personal data should be retained;
    • there's a concern about how securely personal data is being kept;
    • a data subject has asked to exercise one of their rights and help is needed to respond; or
    • a data breach, or a possible breach of this policy, is suspected.

    5. Deciding when and how personal data may be used

    Every team member is individually responsible for using personal data appropriately - this covers everything from significant data-driven work down to something as small as emailing a client about a social or charity event. Before using anyone's personal data, a team member should be satisfied that:

    • it doesn't involve special category data or criminal offence data (see Section 1) unless the Data Protection Officer has approved this in advance;
    • it doesn't relate to Solv Systems' own finance or HR records, unless that specific use has been signed off in writing;
    • they've correctly identified the lawful basis for the use (Section 6), checking with the Data Protection Officer if they are unsure;
    • the individual concerned is unlikely to be annoyed or upset by what's being sent or asked, and hasn't already said they don't want to be contacted;
    • they actually know the individual well enough to be contacting them directly; and
    • the individual is given a clear, easy way to say they don't want further contact - and if someone does say this, it must be reported to HR immediately and recorded against their details in Solv Systems' central contact record.

    6. Establishing a lawful basis

    Personal data should only be used where it's genuinely needed for a team member's role, and only where one of the following applies:

    • it's necessary to perform a contract with the individual or their organisation - for example, delivering a service to a client;
    • the individual has approached Solv Systems to enter into a contract, such as a prospective employee or client;
    • the individual has given specific consent, provided we keep a clear record of what they were told, how, and when they agreed;
    • it's needed to meet a legal obligation Solv Systems is subject to;
    • it's necessary to protect someone's vital interests; or
    • it serves Solv Systems' legitimate business interests - provided those interests don't override the individual's own rights and freedoms, the purpose is disclosed in a privacy notice, and a written record explains why this basis applies.

    Any basis relied on should be revisited periodically to check it still holds, particularly for ongoing or repeated processing.

    Where consent is the basis, it must be an active, clear, affirmative choice - pre-checked boxes, inaction, or silence don't count. Anyone who gives consent must also be told, clearly, how to withdraw it later.

    Personal data must always be collected for a defined purpose, kept to what's genuinely relevant and necessary, and never repurposed for something new or incompatible without first telling the individual.

    Special category and criminal offence data

    These categories carry extra risk and need the Data Protection Officer's sign-off before use, because an additional condition must also be met - typically one of:

    • the individual has given explicit, specific consent;
    • the use is necessary to meet obligations or exercise rights under employment or social security law; or
    • the use is necessary for establishing, exercising, or defending legal claims.

    7. Privacy notices

    Whenever Solv Systems collects personal data, the individual concerned must be given a privacy notice - written in plain, accessible language and approved in form and content by the Data Protection Officer - covering:

    • who to contact about that specific use of their data (or the Data Protection Officer, if there's no specific contact);
    • why the data is being used;
    • the lawful basis relied on, and - where it's legitimate interests - what those interests are;
    • the right to withdraw consent, where consent is the basis;
    • where the data wasn't collected directly from them, what it consists of and where it came from;
    • who the data may be shared with, including any service providers;
    • details of any transfers outside the country of origin and the safeguards used;
    • how long the data will be kept, or how that period will be decided;
    • their rights to access, correct, delete, restrict, or object to the use of their data;
    • their right to complain to the ICO, the Information Regulator in South Africa, or the equivalent authority;
    • whether any automated decision-making or profiling is involved, and what that means for them; and
    • whether providing the data is required by law, by contract, or to enter into a contract, and what happens if they choose not to provide it.

    Timing matters: the notice must be given when data is first collected directly from someone; within one month if it was obtained from a third party; before or at the point of first contacting the individual, if the data will be used to communicate with them; and before or at the point of any disclosure to a third party, if one is planned.

    8. Keeping data accurate and current

    Personal data must be accurate and kept up to date where relevant, with reasonable steps taken to correct or remove anything that's wrong. Team members are expected to tell the HR Manager promptly if their own details change - Solv Systems can't be held responsible for outdated records where it was never told of a change. Team members must also keep accurate any records of other people's data that fall within their role, checking accuracy at the point of collection and at sensible intervals afterwards, and correcting or removing anything outdated.

    9. How long we keep personal data

    Personal data is kept only for as long as it's needed for the purpose it was collected for, including to meet legal, tax, health and safety, reporting, or accounting obligations. Before anything is deleted, it's reviewed to check whether there's a reason to hold onto it longer; otherwise, it's removed at the end of the periods below. In some cases, data may instead be anonymised so it no longer identifies anyone, allowing it to be kept for longer in that form.

    Unsuccessful job applicants: generally held for one year after the recruitment process ends, though this may extend up to six years where needed for legal, tax, or similar reasons. If an applicant has agreed to being considered for future roles, their data is kept for a further six months, or until they withdraw that consent.

    Current and former team members: generally held for the duration of employment or engagement. Disciplinary, grievance, and capability records are kept only until any warning expires, after which just a summary is retained. After someone leaves, their data is generally kept for six years, except where it forms part of service records or is subject to longer statutory, tax, or similar requirements.

    Clients, customers, and suppliers: generally held for the length of the business relationship, and then for six years afterwards, except where it forms part of service documentation or is subject to a longer legal, tax, or regulatory requirement.

    10. Keeping personal data secure

    Solv Systems maintains security measures proportionate to its size, the volume of data it holds, and the risks involved - including encrypting personal data where appropriate, and taking steps to keep processing systems confidential, resilient, and quickly recoverable if something goes wrong. These safeguards are reviewed and tested periodically.

    Every team member shares responsibility for keeping personal data secure, from the moment it's collected to the moment it's destroyed, and must follow all related procedures.

    Where a third-party service provider processes personal data on Solv Systems' behalf, they may only access it where they:

    • genuinely need it to deliver the contracted service;
    • were named or described in the relevant privacy notice;
    • have agreed to meet Solv Systems' data security requirements;
    • are bound by a written contract setting out approved terms and obligations;
    • will help Solv Systems respond to data subject requests, security obligations, breach notifications, and data protection impact assessments;
    • will return or delete all personal data once the contract ends; and
    • agree to be audited.

    The Data Protection Officer must approve any new or amended arrangement involving a third party processing personal data on Solv Systems' behalf.

    Personal data accessed through a team member's role should never be saved to a local hard drive or personal device and should only be shared internally with colleagues who genuinely need it for their own work. Physical files and portable media containing personal data must be kept in locked storage, accessible only to those with a legitimate need; electronic records must be password-protected and similarly restricted. Solv Systems maintains regular backups to guard against accidental loss or damage to electronic records.

    Breach notification: applicable law requires Solv Systems to notify the ICO (or equivalent authority) within 72 hours of becoming aware of a personal data breach, and to notify affected individuals directly where the breach poses a high risk to their rights and freedoms. Under POPIA, the Information Regulator and the affected individuals must be notified as soon as reasonably possible after a compromise is discovered. A breach means any security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorised access to or disclosure of personal data - including anything that compromises the confidentiality, integrity, or availability of that data or the safeguards protecting it. Anyone who knows of or suspects a breach must contact the Data Protection Officer immediately at steve.smith@solv-systems.com, and preserve any evidence relating to it.

    11. Rights individuals have over their data

    Anyone wanting to exercise their rights over personal data Solv Systems holds should email the Data Protection Officer at steve.smith@solv-systems.com. Any team member who receives such a request directly must forward it to the Data Protection Officer immediately.

    Subject to certain conditions, individuals have the right to:

    • be informed about how their data is used, typically through a privacy notice;
    • access their data, and receive confirmation of whether it's being processed, copies of it, the purposes and categories involved, who it's shared with, where it came from (if not from them directly), details of any international transfers and safeguards, how long it will be kept, information about any automated decision-making, and details of their other rights;
    • request correction of inaccurate or incomplete data, with the correction passed on to anyone it was shared with, unless that's impossible or disproportionately difficult;
    • request deletion of their data in certain circumstances, again passed on to recipients where reasonably possible;
    • request restriction of how their data is used - including marketing or other outreach - in which case Solv Systems may only continue to store it, or use it, with consent, for legal claims, to protect someone else's rights, or for an important public interest reason, and must tell the individual before lifting any restriction;
    • object to processing based on legitimate interests, where something about their particular situation gives them grounds to object - in which case Solv Systems must stop, unless it can show compelling legitimate grounds that override the individual's interests, or the processing relates to legal claims;
    • request data portability - receiving their data, or having it transferred elsewhere, where the basis for processing is consent or contract and it's carried out by automated means;
    • not be subject to solely automated decision-making, including profiling, that has legal or similarly significant effects, unless it's necessary for a contract, authorised by law with appropriate safeguards, or based on explicit consent - and even then, they must be able to express their view and contest the decision; and
    • be notified of a data breach likely to pose a high risk to their rights and freedoms.

    Where consent is the basis for a particular use, it can be withdrawn at any time by notifying the Data Protection Officer - this doesn't affect the lawfulness of anything done before withdrawal, but Solv Systems will stop that specific use unless another lawful basis applies.

    How access requests are handled

    When a request is received, Solv Systems will record the date, confirm the requester's identity (asking for further verification if there's reasonable doubt), and search relevant systems and records. Where a large volume of data is involved, the requester may be asked to narrow down what they're looking for, to help respond more quickly.

    Requests made electronically will normally be answered in a common electronic format, unless the individual asks otherwise. Further copies beyond the first may attract a reasonable administrative fee.

    Solv Systems will respond within one month of a request. Where a request is complex, or several requests have been received from the same person, this may be extended by up to two further months - in which case the individual will be told within the first month, with an explanation of why.

    Before releasing any data, Solv Systems will check whether it contains personal data about other people, redacting that information unless those individuals have consented to its disclosure, and will also check for any legal exemptions that might limit what can be disclosed.

    Responses are normally free of charge. However, Solv Systems may charge a reasonable administrative fee, or decline to act, where a request is manifestly unfounded, excessive, or repeats one already answered. Where a request is refused, the individual will be given written reasons within one month, along with information about their right to complain to the ICO or the Information Regulator, or to seek a remedy through the courts.

    12. Keeping this policy current

    Solv Systems reviews this policy regularly and may update it at any time. Any revised version will be circulated to team members, including by email where appropriate. This policy is intended to fully reflect applicable data protection law; if any conflict arises between the two, the law takes precedence.