1. Introduction
RapidProto (Pty) Ltd (“RapidProto”, “we”, “us”, or “our”) is a South African technology company registered and operating in the Republic of South Africa. This Privacy Policy governs the collection, use, storage, and disclosure of personal information collected through rapidproto.co.za and any related services we provide.
We are committed to protecting your personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA). By using our website or engaging our services, you acknowledge that you have read and understood this policy.
2. Information We Collect
We collect the following categories of personal information:
- Contact information — name, email address, business description, and responses submitted via our contact or Prototype Readiness Scorecard forms.
- Payment data — payments are processed by PayFast. RapidProto does not store, transmit, or have access to your card details or banking credentials.
- Usage data — page views, referrer URLs, browser type, and device type collected via standard web analytics. This data is anonymised where possible.
- Project information — business context, technical requirements, and other details submitted during client onboarding or project delivery.
3. Lawful Basis for Processing (POPIA)
We process personal information on the following lawful bases:
- Scorecard and contact forms: Consent — you voluntarily submit your information to request information or receive a report.
- Blueprint & Sprint Map purchase: Contractual necessity — processing is required to fulfil the service you have purchased.
- Retainer engagements: Contractual necessity and legitimate interest — to manage the ongoing service relationship.
- Analytics: Legitimate interest — to understand how our website is used and improve our services.
4. How We Use Your Information
Your personal information is used for the following purposes:
- To respond to enquiries and provide the services you have requested.
- To generate your personalised Prototype Readiness Report.
- To fulfil Blueprint & Sprint Map and Foundation Sprint deliverables.
- To manage retainer service delivery and ongoing client communication.
- To improve our website, content, and service offerings.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
5. Data Sharing
We share personal information only with the following service providers, and only to the extent necessary to deliver our services:
- PayFast — payment processing, subject to PayFast’s own Privacy Policy.
- Amazon Web Services (AWS) — infrastructure hosting. Data may be stored in
eu-west-1(Ireland) and/oraf-south-1(Cape Town) regions. - Email service provider — for the delivery of transactional emails (e.g., scorecard reports, onboarding communications).
No other third-party sharing takes place. We do not use advertising networks or social media tracking pixels.
6. Data Retention
We retain personal information for the following periods:
- Enquiry and scorecard data: 12 months from the date of last contact.
- Client project data: 36 months from the date of project completion.
- Financial records: 5 years, as required by South African statutory obligations.
You may request deletion of your personal information at any time, subject to applicable legal retention requirements. See “Your Rights” below.
7. Your Rights Under POPIA
As a data subject, you have the following rights under POPIA:
- Right to access — you may request a copy of the personal information we hold about you.
- Right to correct — you may request that inaccurate or incomplete information be corrected.
- Right to delete — you may request deletion of your personal information, subject to our legal retention obligations.
- Right to object — you may object to the processing of your personal information on grounds relating to your particular situation.
- Right to lodge a complaint — you have the right to lodge a complaint with the Information Regulator of South Africa: inforegulator.org.za.
To exercise any of the above rights, please contact us at privacy@rapidproto.co.za.
8. Cookies
We use cookies on this website for the following purposes only:
- Functional cookies — necessary for the website to operate correctly.
- Analytics cookies — to understand aggregate usage patterns and improve our content.
We do not use advertising cookies, tracking pixels, or any third-party behavioural targeting technologies. You can disable cookies at any time in your browser settings; however, some functionality may be affected.
9. Security
We implement appropriate technical and organisational measures to protect your personal information:
- All data is encrypted in transit using TLS 1.3.
- Data stored on our infrastructure is encrypted at rest using AES-256.
- Access to personal information is restricted to authorised personnel and governed by role-based access controls.
- Audit logging is in place for access to sensitive data.
- We conduct annual security reviews of our systems and processes.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or best practices. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of our website or services following any update constitutes your acceptance of the revised policy.
11. Contact
For any privacy-related queries, requests, or complaints, please contact our Information Officer:
- Email: privacy@rapidproto.co.za
- Entity: RapidProto (Pty) Ltd, South Africa
- Website: rapidproto.co.za