Nanopixel CC | Reg. No. 2010/038461/23 | Unit 12, Barn Lodge, Thrush Avenue, Boskruin, Johannesburg, Gauteng, 2195, South Africa | Privacy: privacy@nanopixel.co.za | General: info@nanopixel.co.za | Effective date: August 2026 | Last reviewed date: August 2026
1. Introduction
Nanopixel CC ("Nanopixel", "we", "us" or "our") respects your privacy and is committed to processing personal information lawfully, fairly, transparently, and securely.
This Privacy Policy applies to: visitors to and users of www.nanopixel.co.za (the "Website"); individuals who submit enquiries or otherwise communicate with us; individuals who interact with us in a business or professional capacity; and individuals whose personal information we otherwise process in connection with our business activities.
Nanopixel generally acts as a responsible party under POPIA and, where the GDPR applies, as a controller. In certain circumstances where Nanopixel processes personal information on behalf of a client who determines purposes and means, Nanopixel may act as an operator, processor, or service provider, as applicable. This Policy should be read together with any specific privacy notices or contractual terms applicable to particular services.
2. Applicable Law
Depending on the circumstances and location of the individual concerned, Nanopixel may be subject to: POPIA — Protection of Personal Information Act 4 of 2013 (South Africa); GDPR — Regulation (EU) 2016/679 (European Union); applicable data-protection legislation in the United Kingdom, where relevant; and CCPA/CPRA — California Consumer Privacy Act as amended by the California Privacy Rights Act, where applicable. Where more than one privacy law applies, we seek to process personal information in a manner that satisfies the applicable legal requirements.
3. Who We Are and How to Contact Us
The entity responsible for the Website and the personal information described in this Policy is Nanopixel CC. In accordance with POPIA Section 55, Nanopixel CC has designated an Information Officer responsible for ensuring compliance with South African privacy laws.
Information Officer: J. Siedentopf | Physical Address: Unit 12, Barn Lodge, Thrush Avenue, Boskruin, Johannesburg, Gauteng, 2195, South Africa | Privacy Email: privacy@nanopixel.co.za | General Email: info@nanopixel.co.za
Nanopixel has not appointed a formal Data Protection Officer under European law where such appointment is not required. If applicable law requires a designated EU or UK representative, relevant details will be provided in a supplementary notice.
4. Personal Information We Collect
We seek to collect only personal information that is reasonably necessary for identified and lawful purposes.
4.1 Information you provide directly: When you submit an enquiry or communicate with us, we may collect your full name, email address, telephone number, company or organisation name, professional or business information, current website URL, project timeline or requirements, services of interest, project descriptions, how you found us, and any other information you voluntarily provide. Optional information is not required, but failure to provide information necessary to respond to an enquiry may prevent us from doing so.
4.2 Information collected automatically: When you visit the Website, certain technical information may be collected automatically, including IP address, browser type and version, device type, operating system, pages visited, approximate time on pages, referring website or search information, approximate geographic location (country/city), technical information relating to website security and performance, and cookie-related information where permitted.
4.3 Information from other sources: Where relevant to our business activities, we may receive business contact information from your employer or organisation, existing clients or referrals, publicly available professional websites, or other lawful business sources.
5. Categories of Personal Information
- Identifiers — name, email address, telephone number: used to communicate with you and respond to enquiries.
- Professional / business information — company, organisation, website, role: used to understand project requirements and business relationships.
- Commercial information — services requested, project requirements and communications: used to prepare proposals and provide services.
- Internet / electronic activity — IP address, browser, device and website activity: used for security, website operation and analytics.
- Approximate location — country or city: used for website analytics, security and service optimisation.
- Communications — enquiries, correspondence and information supplied by you: used to respond to enquiries, manage relationships and maintain records.
We do not intentionally request or collect special categories of personal information or sensitive personal information through the Website unless necessary for a specific lawful purpose.
6. How We Use Personal Information
- Responding to enquiries: To process form submissions, assess fit, and communicate with you.
- Preparing proposals and providing services: To assess project scope, issue quotes, enter contracts, and execute deliverables.
- Managing business relationships: To communicate with clients, suppliers, and contacts, and maintain records.
- Website operation and security: To maintain systems, prevent abuse or fraud, and troubleshoot issues.
- Analytics: Subject to user consent, to analyse website traffic and usability via Google Analytics.
- Legal and regulatory compliance: To comply with statutory obligations, legal orders, or defend legal claims.
7. Lawful Bases for Processing
Where the GDPR applies, we rely on statutory bases under Article 6 — including Legitimate Interests, Pre-contractual steps, Performance of a Contract, Legal Obligation, or Consent — depending on the processing activity. Under POPIA, we process personal information in accordance with Section 11 and the eight statutory conditions for lawful processing.
8. Contact Forms and Email
Our Website contact form uses a self-hosted PHP-based mailer to transmit submitted information directly to our business email environment. We do not retain contact-form submissions in a separate website database after transmission. Once received, enquiry details are retained within our secure email systems and backups in accordance with our retention schedule.
9. Cookies and Similar Technologies
9.1 Strictly necessary technologies: These include core operational scripts, essential form mechanics, and spam-prevention tools (including Google reCAPTCHA v3). Strictly necessary technologies operate without requiring consent as permitted by applicable law.
9.2 Analytics technologies: We use Google Analytics 4 (GA4) to evaluate usage patterns. Analytics cookies are non-essential and will not execute or place cookies on your device unless explicit opt-in consent is provided via our cookie preference mechanism.
9.3 Preference management: Visitors can adjust or revoke cookie choices at any time via the Website's cookie banner or by clicking "Manage Preferences" in the footer.
9.4 Advertising: Nanopixel does not deploy advertising cookies, pixels, or cross-context tracking tools.
10. Google Analytics
Where consent is explicitly granted, GA4 processes aggregate usage metrics, device classifications, and general geographic location data. Analytics settings are configured to anonymise data where technically feasible. Google may store or process this information on servers outside South Africa under the EU-US Data Privacy Framework and applicable adequacy mechanisms.
11. Google reCAPTCHA
We use Google reCAPTCHA v3 to protect web forms against automated spam and abuse. reCAPTCHA evaluates hardware, browser, and interaction metrics and is deployed on the basis of our legitimate interest in maintaining website security. It is classified as a strictly necessary security measure and operates invisibly without user interaction.
12. Third-Party Service Providers and Disclosure
Nanopixel does not sell personal information. We may share data with vetted service providers strictly necessary for operating our business:
- Hosting & Systems: Domain, DNS, web hosting, and email infrastructure providers.
- Analytics & Security: Google Analytics, Google reCAPTCHA, and network security operators.
- Cloud Storage: IDrive (AES-256 encrypted cloud infrastructure for client records and project assets).
- Professional Advisers: Legal, accounting, audit, and insurance professionals under strict duties of confidentiality.
- Legal Disclosures: Authorities, statutory bodies, or courts where mandated by applicable law.
13. International Data Transfers
13.1 Transfers under POPIA Section 72: Where personal information subject to POPIA is transferred outside South Africa, transfers take place only where the recipient is bound by law, binding corporate rules, or binding agreements offering protection substantially similar to POPIA's conditions; the transfer is necessary for pre-contractual steps or performance of a contract; or you have provided explicit consent where required.
13.2 Transfers under GDPR / UK Law: For EU/UK residents whose personal data is transferred outside the EEA/UK, we rely on adequacy decisions, Standard Contractual Clauses (SCCs), or the UK International Data Transfer Agreement/Addendum.
14. Data Security
We implement robust technical and organisational measures including: AES-256 encryption on cloud storage environments (IDrive); endpoint defence and active anti-malware (ESET) across all operational devices; role-based access controls on a strict need-to-know basis; and secure authentication standards. No digital transmission or storage infrastructure can be guaranteed as completely immune to breach.
15. Security Compromises and Data Breaches
In the event of a confirmed or suspected data compromise involving personal information, we will launch an investigation, contain the issue, and fulfil statutory breach notification obligations. Under POPIA Section 22 and GDPR Articles 33/34, notifications will be issued to affected individuals and relevant supervisory authorities as required by law.
16. Use of Artificial Intelligence
Nanopixel uses generative AI platforms — including Anthropic Claude, OpenAI ChatGPT, xAI Grok, Google Gemini, Midjourney, and Topaz Labs Gigapixel AI — for internal creative ideation, research, and workflow efficiency.
- Data Safeguards: Client confidential information and personal information submitted via our website are never entered into public AI training models.
- Human Oversight: AI output serves solely as an initial operational reference. Qualified human practitioners independently review, refine, and validate all final client deliverables. No automated AI processing produces binding legal effects on individuals.
17. Automated Decision-Making and Profiling
Nanopixel does not subject individuals or website visitors to automated decision-making or profiling systems that yield legal or similarly significant consequences.
18. Data Retention
- Enquiries: Retained for the duration of the business engagement plus a reasonable record-keeping buffer (typically up to 5 years under South African commercial law).
- Client Records: Retained for contract execution, accounting, tax, and legal defence requirements.
- Analytics Data: Configured in GA4 to purge automatically in accordance with standard retention schedules (14 months).
19. Your Privacy Rights
19.1 South Africa (POPIA): Data subjects may confirm what personal data we hold; request correction, completion, or deletion of records; object to processing based on legitimate interests; and submit complaints to the Information Regulator. To exercise these rights, email privacy@nanopixel.co.za (Attention: J. Siedentopf).
19.2 European Union / UK (GDPR): Data subjects hold rights to Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Data Portability (Art. 20), and Objection (Art. 21). Contact privacy@nanopixel.co.za.
19.3 California (CCPA/CPRA): California residents hold the right to Know, Delete, Correct, and Non-Discrimination. Nanopixel does not sell or share personal information for cross-context behavioural advertising.
20. Verification of Privacy Rights Requests
To protect against unauthorised disclosure, we verify the identity of any individual lodging a privacy request before releasing records or amending details. Authorised agents acting on behalf of an individual must provide written authorisation.
21. Children's Privacy
Our Website is intended for adult business audiences. We do not knowingly collect personal information from individuals under 18 years of age. If a minor has submitted information, please contact privacy@nanopixel.co.za for prompt deletion.
22. Direct Marketing
Nanopixel does not issue unsolicited direct electronic marketing without appropriate lawful basis or prior opt-in consent. All direct marketing messages will contain a functional opt-out/unsubscribe facility.
23. Third-Party Websites and Links
This Policy applies strictly to Nanopixel's own operations and website. We accept no responsibility for the content, security, or privacy policies of external websites linked on our platform.
24. PAIA and Access to Records
Nanopixel CC is subject to the Promotion of Access to Information Act 2 of 2000 (PAIA). Information regarding the procedure for requesting access to corporate records is set out in our PAIA Manual, available at: www.nanopixel.co.za/paia-manual.pdf.
25. Complaints
If you have concerns about our handling of your personal data, please contact J. Siedentopf at privacy@nanopixel.co.za so we can resolve the issue. If you remain unsatisfied, you have the right to lodge a formal complaint:
- South Africa: Information Regulator of South Africa — inforegulator.org.za | enquiries@inforegulator.org.za | POPIAComplaints@inforegulator.org.za
- European Union / UK: Your local Data Protection Supervisory Authority.
- California: California Privacy Protection Agency (CPPA) or Attorney General.
26. Changes to This Privacy Policy
We reserve the right to amend this Policy to reflect operational, technological, or legal updates. Revisions take effect from the "Last reviewed" date published at the head of this document.
27. Contact
Nanopixel CC — Privacy Enquiries
Attention: J. Siedentopf (Information Officer)
Unit 12, Barn Lodge, Thrush Avenue, Boskruin, Johannesburg, Gauteng, 2195, South Africa
Privacy Email: privacy@nanopixel.co.za | General Email: info@nanopixel.co.za