Zizian
Privacy

How we handle your information.

What Zizian (Pty) Ltd collects, why, how long it stays, and what you can ask us to do about it. Written to be read rather than to be survived.

Last updated 17 August 2026

Who is responsible

Zizian (Pty) Ltd is the responsible party for the personal information described on this page, as that term is used in the Protection of Personal Information Act 4 of 2013 (POPIA).

The Information Officer is Mpho Malcom Miya, reachable at info@zizian.co.za. Every request described below goes to that address.

What we collect, and when

Nothing here is collected speculatively. Each item exists because something on the site needs it.

When you submit a project brief
Your name, email address, company, what you want built, your timeline and your budget band. This is the enquiry itself. Without it there is nothing to reply to.
When you request a consultation
Your name, email address, company, the slot you asked for and any notes you added. A booking reference is generated so a payment can be matched to it.
When you open a client account
Your company name, contact name, email address and phone number, plus a password. The password is stored only as a bcrypt hash. It is never stored, transmitted or displayed in a form we could read.
When you use the client portal
The projects, deliverables, invoices and documents belonging to your account, and any files you upload. Files are stored in encrypted object storage and are served through short-lived links rather than public URLs.
Every time a page loads
A random identifier stored in your browser, the page path, the referring site, your IP address, your browser's user-agent string and its language preference. The identifier is generated locally, contains nothing about you, and is used to count returning visitors as one person rather than several.
Every time someone tries to sign in
The email address that was tried, whether it worked, the reason it did not, and the IP address and browser it came from, including attempts that failed. This is how a run of password guesses against an account becomes visible at all.

About IP addresses in particular

An IP address is personal information under POPIA, so it is worth being plain about it rather than filing it under “technical data”.

We record the full address, not a truncated or anonymised one. We do so for three reasons: to tell genuine visitors apart from automated crawlers, so that traffic figures mean something; to investigate a fraudulent booking or enquiry; and to detect somebody working through passwords against an account. We do not use it to build a profile of you, we do not combine it with data bought from anyone else, and we do not sell it.

We do not run Google Analytics, advertising pixels, or any third-party tracking script. The counting described above is done by our own systems, on our own servers, and the data does not leave them.

How long we keep it

IP addresses and sign-in records are held in a searchable store for 90 days, after which that copy expires automatically. Nobody has to remember to delete it.

Being straight about the exception: underneath that sits an append-only event log, which is how the platform reconstructs its own state and serves as its audit record. Entries written to it are not edited or removed, so an IP address recorded there persists beyond the 90 days. It is not searchable by address, is not used for analysis, and is reachable only by us. If you ask us to erase your information, we will tell you exactly what can be removed from the live systems and what remains in that log.

Enquiries, bookings, accounts, project records and invoices are kept for as long as the relationship lasts, and afterwards for the period South African tax and company law requires records to be retained.

Who else sees it

Nobody buys it, and nobody is given it for their own purposes. The people and services that necessarily touch it are:

  • Zizian staff working on your engagement.
  • Our hosting provider, whose servers run the platform.
  • Our object storage provider, which holds uploaded documents in encrypted form. Files are stored under keys scoped to your organisation and are not shared between clients.
  • A professional adviser, or a regulator or court, where the law requires it, and we will tell you when that happens unless we are prohibited from doing so.

Your rights

Under POPIA you may:

  • Ask what personal information we hold about you, and get a copy of it.
  • Ask us to correct anything that is wrong or incomplete.
  • Ask us to delete information we no longer have grounds to keep, subject to the event log described above, and to records we are legally required to retain.
  • Object to a particular use of your information.
  • Complain to the Information Regulator (South Africa) if you think we have got it wrong. You can do that without going through us first, though we would rather you gave us the chance to fix it.

Email info@zizian.co.za and we will respond within 30 days.

Security

Traffic to this site and to the platform behind it is encrypted in transit. Passwords are stored as bcrypt hashes. Sessions are held server-side with an expiry, so signing out genuinely ends a session rather than only clearing your browser.

No system is beyond compromise. If personal information is exposed in a way that creates a real risk to you, we will notify you and the Information Regulator, as POPIA requires We will not decide on your behalf that it was not worth telling you about.

Changes to this notice

When the platform starts collecting something new, this page changes in the same release rather than in a later one. The date at the top is when it was last revised.

Questions about any of this go to info@zizian.co.za, or through the contact page.