Skip to Content

Privacy Policy

Introduction


Amplifi ERP is committed to protecting the privacy, confidentiality and security of the personal information entrusted to us.

This Privacy Policy explains how Amplifi ERP (“Amplifi ERP”, “we”, “us” or “our”), a division of Steltix Development South Africa (Pty) Ltd, collects, uses, stores, shares and otherwise processes personal information.


It also explains the rights available to individuals and organisations whose personal information we process and how those rights may be exercised.

Amplifi ERP provides enterprise resource planning advisory, implementation, configuration, integration, development, training, support and managed services. Our services may include solutions relating to Odoo.


This Privacy Policy applies to personal information processed through:

  • our website and related online services;
  • enquiries submitted to Amplifi ERP;
  • sales, marketing and business-development activities;
  • proposals, quotations and contractual engagements;
  • ERP discovery, implementation, migration and support projects;
  • training, demonstrations, workshops and events;
  • customer-support and managed-services activities;
  • supplier and business-partner relationships;
  • recruitment and employment applications;
  • social-media pages and communications;
  • any other interaction through which Amplifi ERP collects or processes personal information.


This Privacy Policy should be read together with any other privacy notice, contractual provision, website terms, consent notice or data-processing agreement that may apply to a particular service or engagement.


Our legal identity


Amplifi ERP is a trading name of:


Legal entity: Amplifi ERP, a division of Steltix Development South Africa (Pty) Ltd

Registration number: 2022/601465/07

VAT Registration Number: 4520307333

Registered address: Standard House, 18 Royal Street, Hermanus, 7200, South Africa

Postal address: PO Box 24033, Claremont, 7725, South Africa

Telephone: +27 28 316 1257

General email: sales@amplifierp.com

Website: www.amplifierp.com


For purposes of the Protection of Personal Information Act, 4 of 2013 (“POPIA”), Amplifi ERP may act as either:

  • a Responsible Party, where we determine the purpose and means of processing personal information; or
  • an Operator, where we process personal information on behalf of a customer or another Responsible Party under a contract or mandate.


Under the General Data Protection Regulation (“GDPR”), the corresponding terms are generally “controller” and “processor”.


The role we perform will depend on the nature of the relevant service, relationship or processing activity.


Applicable privacy legislation


Amplifi ERP processes personal information in accordance with applicable privacy and data-protection legislation, including POPIA.


Where applicable to a particular individual, processing activity or customer engagement, we may also comply with:

  • the Promotion of Access to Information Act, 2 of 2000 (“PAIA”);
  • the Electronic Communications and Transactions Act, 25 of 2002;
  • the Consumer Protection Act, 68 of 2008;
  • the GDPR;
  • applicable employment, tax, accounting and company legislation;
  • other laws governing the confidentiality, retention, security or disclosure of information.


Where different laws apply to the same processing activity, Amplifi ERP will seek to apply the requirements that provide the appropriate level of protection in the relevant circumstances.


Definitions


For purposes of this Privacy Policy:


Personal information


“Personal information” means information relating to an identifiable living natural person and, where applicable under POPIA, an identifiable existing juristic person. Personal information may include, among other things:

  • names and surnames;
  • company names and registration details;
  • identification and passport numbers;
  • contact details;
  • physical and postal addresses;
  • email addresses;
  • telephone numbers;
  • employment and professional information;
  • financial and payment information;
  • online identifiers and device information;
  • opinions, correspondence and communications;
  • information relating to education, employment history or professional experience;
  • information about an individual’s interactions with Amplifi ERP;
  • any identifying number, symbol, email address, physical address, telephone number, location information or online identifier.


Processing


“Processing” includes any operation or activity involving personal information, whether performed automatically or manually.


This may include:

  • collecting;
  • receiving;
  • recording;
  • organising;
  • storing;
  • updating;
  • modifying;
  • retrieving;
  • consulting;
  • using;
  • analysing;
  • sharing;
  • transmitting;
  • combining;
  • restricting;
  • erasing;
  • destroying.


Data subject


A “data subject” is the person or organisation to whom personal information relates.


Responsible Party


A “Responsible Party” is the person or organisation that determines the purpose and means of processing personal information.


Operator


An “Operator” is a person or organisation that processes personal information for a Responsible Party under a contract or mandate without acting under the direct authority of the Responsible Party.


Special personal information


“Special personal information” includes certain sensitive categories of information protected under applicable law, such as information concerning health, biometric information, religious or philosophical beliefs, race or ethnic origin, political persuasion, trade-union membership, sex life or criminal behaviour.


Our commitment to lawful processing


Amplifi ERP seeks to process personal information in accordance with the applicable principles and conditions for lawful processing.


We aim to ensure that personal information is:

  • processed lawfully and reasonably;
  • collected for specific, defined and legitimate purposes;
  • adequate, relevant and not excessive;
  • accurate and kept up to date where reasonably necessary;
  • retained only for as long as required;
  • protected through appropriate technical and organisational safeguards;
  • processed transparently;
  • handled in a way that enables data subjects to exercise their rights.


We will not process personal information in a manner that is incompatible with the purpose for which it was collected, unless further processing is permitted by law, required for a related purpose or authorised by the data subject.


Personal information we collect


The type of personal information we collect depends on the nature of your relationship and interaction with Amplifi ERP.


Website visitors


When you visit our website, we may collect:

  • your Internet Protocol address;
  • browser type and version;
  • device type;
  • operating system;
  • referring website or source;
  • pages visited;
  • date and time of access;
  • approximate geographic location derived from technical information;
  • cookie identifiers;
  • website-usage and analytics information;
  • security and diagnostic data.


Prospective customers and business contacts


When you enquire about our services or engage with our sales team, we may collect:

  • your name and surname;
  • job title and department;
  • employer or organisation;
  • business email address;
  • business telephone or mobile number;
  • location;
  • details of your enquiry;
  • information about your current systems and business requirements;
  • budgetary or procurement information;
  • meeting notes and correspondence;
  • proposed project scope;
  • records of demonstrations, workshops and discovery sessions;
  • information contained in requests for proposals, tenders or questionnaires.


Customers and authorised customer representatives


In connection with customer engagements, we may collect:

• contact and identification details;

• job titles, roles and responsibilities;

• account and contract information;

• billing and payment information;

• authorised-user details;

• support-request information;

• meeting records;

• project documentation;

• training attendance;

• system access information;

• communications and approvals;

• information required to deliver contracted services.


Information processed during ERP services


ERP implementations, migrations, integrations, support activities and managed services may involve access to personal information contained in a customer’s systems.


Depending on the customer’s environment, this may include:

  • employee information;
  • customer and supplier records;
  • user accounts;
  • contact information;
  • financial transaction records;
  • payroll-related information;
  • purchasing and sales records;
  • project and timesheet information;
  • system logs;
  • audit records;
  • user-access and security information;
  • attachments and business documents;
  • data used for testing, migration, troubleshooting or support.


Where Amplifi ERP processes such information on behalf of a customer, the customer will generally remain the Responsible Party and Amplifi ERP will act as an Operator.


Our access to customer information will be limited to what is reasonably required to perform the agreed services.


Suppliers, contractors and business partners


We may collect:

  • names and contact details;
  • company and registration details;
  • banking and payment information;
  • tax information;
  • contractual records;
  • professional qualifications;
  • correspondence;
  • due-diligence information;
  • performance and service information.


Job applicants


When an individual applies for employment or submits a curriculum vitae, we may collect:

  • name and contact details;
  • identification information;
  • employment history;
  • education and qualifications;
  • professional memberships;
  • references;
  • remuneration expectations;
  • work-eligibility information;
  • interview notes;
  • assessment results;
  • information voluntarily included in an application;
  • background-screening information where lawful and appropriate.


Events, webinars and training


When you register for or attend an event, webinar, training session or demonstration, we may collect:

  • registration details;
  • contact information;
  • employer and job title;
  • attendance information;
  • dietary or accessibility requirements, where provided;
  • session participation and feedback;
  • photographs or recordings, where appropriate notice or consent has been provided.


Communications


We may retain records of communications conducted through:

  • email;
  • telephone;
  • online meeting platforms;
  • website forms;
  • customer-support systems;
  • instant-messaging platforms;
  • social media;
  • face-to-face meetings.


Calls or meetings will not be recorded without appropriate notice and, where required, consent.


How we collect personal information


We may collect personal information:


Directly from you


This includes information provided when you:

  • complete a website form;
  • contact us by email or telephone;
  • request a demonstration;
  • ask for a quotation or proposal;
  • attend a meeting, workshop or event;
  • enter into a contract;
  • submit a support request;
  • subscribe to communications;
  • apply for employment;
  • engage with us on social media.


From your employer or organisation


Your employer, customer, supplier or other organisation may provide your details when:

  • nominating you as a project contact;
  • authorising system access;
  • registering you for training;
  • assigning you as a customer representative;
  • involving you in an ERP implementation or support engagement.


From customers whose systems we support


We may encounter or receive personal information when providing ERP consulting, implementation, integration, migration, hosting, support or managed services.


From publicly available sources


We may collect business-related information from:

  • company websites;
  • professional networking platforms;
  • industry directories;
  • public registers;
  • tender portals;
  • conference or event listings;
  • publicly available social-media profiles.


From service providers and business partners


We may receive information from:

  • technology vendors;
  • implementation partners;
  • referral partners;
  • event organisers;
  • marketing service providers;
  • recruitment agencies;
  • due-diligence providers;
  • professional advisers.



Through automated technologies


Our website and electronic services may automatically collect technical information using cookies, log files, analytics technologies and similar tools.


Purposes for which we process personal information


Amplifi ERP may process personal information for the following purposes:


Providing services


We use personal information to:

  • assess customer requirements;
  • prepare proposals, quotations and statements of work;
  • provide advisory and consulting services;
  • configure and implement ERP solutions;
  • migrate and validate data;
  • develop integrations and custom functionality;
  • provide training;
  • provide technical and functional support;
  • manage service-level agreements;
  • perform project management;
  • monitor service performance;
  • provide managed services;
  • administer software licensing and subscriptions;
  • manage customer relationships.


Communicating with customers and contacts


We use contact information to:

  • respond to enquiries;
  • arrange meetings;
  • provide project updates;
  • issue reports;
  • communicate support information;
  • obtain approvals;
  • provide notices relating to services;
  • manage complaints and feedback.


Managing contracts and commercial relationships


We may process personal information to:

  • negotiate and conclude agreements;
  • verify authorised representatives;
  • administer contracts;
  • process invoices and payments;
  • maintain financial records;
  • manage credit and collections;
  • address disputes;
  • enforce contractual rights;
  • comply with procurement requirements.


Operating and improving our business


We may process information to:

  • manage internal operations;
  • allocate resources;
  • monitor quality;
  • improve services;
  • develop new offerings;
  • conduct business analysis;
  • prepare forecasts;
  • manage risks;
  • maintain business-continuity arrangements;
  • conduct audits;
  • protect our systems and intellectual property.


Website administration and security


We may process technical information to:

  • operate the website;
  • ensure website functionality;
  • detect and prevent fraud or misuse;
  • maintain information security;
  • diagnose errors;
  • analyse website traffic;
  • improve usability and performance;
  • maintain logs;
  • manage cookie preferences.


Marketing and business development


Subject to applicable law, we may process personal information to:

  • communicate information about our services;
  • distribute newsletters;
  • invite contacts to events and webinars;
  • conduct market research;
  • manage prospective-customer relationships;
  • measure campaign effectiveness;
  • maintain business-development records.


Recruitment and employment administration


We may process applicant information to:

  • assess applications;
  • communicate with candidates;
  • conduct interviews;
  • verify qualifications and references;
  • conduct lawful background checks;
  • make employment decisions;
  • retain candidate information for future opportunities where permitted.


Legal and regulatory compliance


We may process personal information to:

  • comply with legal duties;
  • maintain statutory records;
  • respond to lawful requests;
  • support audits and investigations;
  • meet tax and accounting obligations;
  • prevent and detect unlawful activity;
  • establish, exercise or defend legal claims;
  • report security compromises where required.

Grounds for processing


Depending on the circumstances, Amplifi ERP may process personal information where:

  • you have consented to the processing;
  • processing is necessary to enter into or perform a contract;
  • processing is required to comply with a legal obligation;
  • processing protects a legitimate interest of the data subject;
  • processing is necessary for the pursuit of Amplifi ERP’s legitimate interests or those of a third party, provided those interests are not overridden by the rights of the data subject;
  • processing is otherwise authorised or required by law.


Examples of legitimate interests may include:

  • providing and improving our services;
  • maintaining customer and business relationships;
  • protecting information systems;
  • preventing fraud and misuse;
  • managing projects and service delivery;
  • recovering amounts owed;
  • maintaining appropriate business records;
  • communicating relevant business information to professional contacts.


Where consent is the basis for processing, consent may generally be withdrawn at any time. Withdrawal will not affect processing lawfully carried out before the consent was withdrawn.


Whether you are required to provide personal information


In some circumstances, providing personal information is voluntary. However, certain information may be necessary for us to:

  • respond to an enquiry;
  • prepare a quotation;
  • enter into a contract;
  • comply with legal obligations;
  • grant system access;
  • deliver services;
  • process a payment;
  • evaluate an employment application.


Where required information is not provided, we may be unable to provide the requested service, proceed with an application or conclude the relevant transaction.


Special personal information


Amplifi ERP does not intentionally collect special personal information unless:

  • it is required for a lawful and defined purpose;
  • processing is authorised by law;
  • processing is necessary for the establishment, exercise or defence of a legal right;
  • the data subject has provided appropriate consent;
  • processing is otherwise permitted under applicable legislation.


Customers are responsible for informing Amplifi ERP where systems, files or data provided to us contain special personal information. Where such information is processed during an ERP engagement, we will seek to apply heightened confidentiality and security controls appropriate to the circumstances.


Personal information relating to children


Our website and services are primarily intended for businesses and adult users. We do not knowingly collect personal information directly from children for marketing or general commercial purposes.


We may process information relating to children where:

  • it forms part of a customer’s authorised business data;
  • it is required for employee-benefit, payroll or dependent-related records within a customer system;
  • a competent person has consented;
  • processing is required or permitted by law.


Where Amplifi ERP acts as an Operator, the relevant customer is responsible for ensuring that it has lawful authority to provide personal information relating to children.


Direct marketing


Amplifi ERP may send business-related marketing communications about:

  • ERP products and services;
  • events and webinars;
  • training;
  • industry insights;
  • product updates;
  • customer success stories;
  • related technology offerings.


We will conduct direct marketing in accordance with applicable law. Where prior consent is required for unsolicited electronic marketing, we will seek that consent before sending the relevant communication. Where permitted, we may communicate with existing customers about our own similar products or services, subject to applicable opt-out requirements. Every electronic marketing communication will provide a reasonable method to unsubscribe or opt out.


You may object to direct marketing or withdraw your consent at any time by:

  • using the unsubscribe link in the communication;
  • replying to the communication;
  • contacting us using the details in this Privacy Policy.


We will process opt-out requests as soon as reasonably practicable. We may retain limited information on a suppression list to ensure that your preference continues to be respected.


Cookies and similar technologies


What cookies are


Cookies are small data files placed on a device when a website is visited. They help websites operate, remember preferences, improve user experience and provide information about website usage.


Types of cookies we may use

Our website may use:

  • Necessary cookies

​These cookies are required for the operation, security and basic functionality of the website.

  • Preference cookies

​These cookies remember choices such as language, location or display preferences.

  • Analytics cookies

​These cookies help us understand website traffic, visitor behaviour and website performance.

  • Functional cookies

​These support additional features, such as embedded videos, maps, forms or social-media content.

  • Marketing cookies

​These may be used to measure marketing campaigns, understand engagement or provide relevant advertising.

Cookie consent


Where required, non-essential cookies will only be used after you have made an appropriate selection through our cookie-consent tool. You can change your preferences through the cookie settings displayed on our website, where available. You may also configure your browser to block or delete cookies. Blocking certain cookies may affect website functionality or user experience.


Third-party technologies


Some website functions may be provided by third parties, including:

  • analytics providers;
  • video-hosting services;
  • social-media platforms;
  • marketing platforms;
  • website-security providers;
  • customer-relationship management tools.


These providers may set their own cookies or collect information in accordance with their privacy notices. A detailed list of active cookies should be maintained in the website’s cookie-management tool or separate Cookie Notice.


15. Sharing personal information


Amplifi ERP does not sell personal information.


We may share personal information where reasonably necessary with:


Employees and authorised personnel


Information may be accessed by employees, contractors and consultants who require it to perform their duties and who are subject to confidentiality and security obligations.


Technology and service providers


We may use providers that support:

  • website hosting;
  • cloud infrastructure;
  • email and collaboration;
  • customer-relationship management;
  • project management;
  • accounting;
  • document storage;
  • electronic signatures;
  • analytics;
  • cybersecurity;
  • backups and disaster recovery;
  • customer support;
  • marketing communications;
  • recruitment;
  • payment processing.


These providers are expected to process personal information only for authorised purposes and subject to appropriate contractual, confidentiality and security obligations.


ERP and software vendors


Personal information may be shared with or processed through relevant software vendors, platform providers and technology partners where required to:

  • administer software subscriptions;
  • resolve product-support issues;
  • operate cloud environments;
  • provide implementation services;
  • perform authorised integrations;
  • deliver customer services.


Professional advisers


We may share information with:

  • attorneys;
  • auditors;
  • accountants;
  • insurers;
  • tax advisers;
  • consultants;
  • other professional advisers.


Group companies and affiliated organisations


Where lawful and appropriate, personal information may be shared with affiliated entities or members of the broader Steltix group for:

  • service delivery;
  • specialist resource allocation;
  • internal administration;
  • customer support;
  • financial management;
  • compliance;
  • business continuity.


Any such sharing will remain subject to applicable privacy, confidentiality and contractual requirements.


Authorities and other legally authorised recipients


We may disclose personal information where:

  • required by legislation;
  • required by a court order, subpoena or lawful request;
  • necessary to cooperate with a regulator or law-enforcement authority;
  • necessary to protect rights, safety, property or systems;
  • necessary to investigate fraud, misconduct or security incidents;
  • required to establish, exercise or defend legal claims.

Business transactions


If Amplifi ERP or the relevant legal entity is involved in a merger, acquisition, restructuring, financing, sale of assets or similar transaction, personal information may be disclosed to prospective advisers, funders or counterparties subject to confidentiality safeguards.


Processing on behalf of customers


When Amplifi ERP accesses or processes personal information held in a customer’s ERP system, Amplifi ERP will generally act as an Operator.


In those circumstances:

  • the customer determines the purposes for which the information is processed;
  • the customer is responsible for ensuring that the information was collected lawfully;
  • Amplifi ERP processes the information only for the agreed services or documented instructions;
  • Amplifi ERP applies appropriate security and confidentiality measures;
  • access is limited to authorised personnel;
  • subcontractors or sub-operators are appointed in accordance with contractual requirements;
  • Amplifi ERP assists the customer with reasonable privacy and security obligations where contractually agreed;
  • information is returned, retained or deleted in accordance with the agreement and applicable law.


Requests relating to information held in a customer’s system should generally be directed to the relevant customer as the Responsible Party.


Amplifi ERP may refer a request to the customer or notify the customer before responding.


International transfers


Amplifi ERP is based in South Africa, but our services, systems, technology providers, customers, partners and group resources may operate in other countries. Personal information may therefore be transferred to, stored in or accessed from jurisdictions outside South Africa.


This may occur where:

  • cloud services are hosted internationally;
  • a customer’s chosen platform is hosted outside South Africa;
  • international group resources provide specialist support;
  • technology vendors operate global support centres;
  • international partners participate in a project;
  • business continuity or backup services use international infrastructure.


Where personal information is transferred outside South Africa, Amplifi ERP will take reasonable steps to ensure that the transfer complies with section 72 of POPIA and other applicable requirements.


Depending on the circumstances, this may include ensuring that:

  • the recipient is subject to a law, binding corporate rule or binding agreement that provides an adequate level of protection;
  • appropriate contractual safeguards are in place;
  • the transfer is necessary for the performance of a contract;
  • the data subject has consented to the transfer;
  • another lawful transfer condition applies.


Where GDPR applies, we will use an appropriate transfer mechanism where required, which may include adequacy decisions, standard contractual clauses or another legally recognised safeguard.


Customers remain responsible for assessing and approving the hosting arrangements and international transfers associated with the platforms and services they select.


Information security


Amplifi ERP takes reasonable and appropriate technical and organisational measures to protect personal information against:

  • loss;
  • damage;
  • unauthorised destruction;
  • unlawful access;
  • unauthorised disclosure;
  • alteration;
  • misuse;
  • unlawful processing.


Measures may include, where appropriate:

  • role-based access controls;
  • unique user accounts;
  • authentication controls;
  • password-management requirements;
  • multi-factor authentication;
  • encryption in transit and, where supported, at rest;
  • network and endpoint protection;
  • vulnerability and patch management;
  • logging and monitoring;
  • backup and recovery controls;
  • confidentiality undertakings;
  • employee security awareness;
  • supplier due diligence;
  • contractual security obligations;
  • access reviews;
  • secure data-transfer methods;
  • incident-response procedures;
  • business-continuity planning.


The measures applied will depend on factors such as:

  • the nature and volume of information;
  • the sensitivity of the information;
  • the purpose of processing;
  • available technology;
  • implementation costs;
  • the potential impact of a security compromise.


No electronic transmission, system or storage method can be guaranteed to be completely secure. We therefore cannot warrant absolute security, but we will continue to review and improve our controls in response to identified risks.


Security compromises


A security compromise may include the loss, unauthorised access, acquisition, alteration, destruction or unlawful disclosure of personal information.


Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, Amplifi ERP will take appropriate action, which may include:

  • investigating the incident;
  • containing and remediating the compromise;
  • preserving relevant evidence;
  • assessing the information and data subjects affected;
  • notifying the relevant customer where Amplifi ERP acts as an Operator;
  • notifying the Information Regulator where required;
  • notifying affected data subjects where required;
  • providing information about reasonable protective measures;
  • reviewing and improving applicable controls.


Where Amplifi ERP acts as an Operator, we will notify the relevant Responsible Party as soon as reasonably practicable after becoming aware of a suspected or confirmed compromise, in accordance with the applicable agreement and law.


Security concerns relating to Amplifi ERP may be reported to:


Security email: warwick.smith@steltix.com


Data accuracy


Amplifi ERP takes reasonable steps to ensure that personal information is complete, accurate, not misleading and updated where necessary.


We rely on customers, contacts, employees, applicants, suppliers and other data subjects to provide accurate information and to notify us when that information changes.


You may request that inaccurate or incomplete information be corrected by contacting our Information Officer.


Retention of personal information


Amplifi ERP retains personal information only for as long as reasonably necessary to:

  • fulfil the purpose for which it was collected;
  • deliver services;
  • comply with contracts;
  • maintain financial and statutory records;
  • comply with legal obligations;
  • respond to audits;
  • resolve disputes;
  • enforce agreements;
  • establish, exercise or defend legal rights;
  • maintain necessary security, suppression or evidentiary records.


Retention periods vary depending on:

  • the category of information;
  • the purpose of processing;
  • legal requirements;
  • contractual requirements;
  • operational needs;
  • limitation and prescription periods;
  • relevant industry practices.


Examples may include:

  • customer and supplier financial records retained for the applicable statutory period;
  • project documentation retained for the contract period and a reasonable period thereafter;
  • unsuccessful job applications retained for a limited period unless longer retention is authorised;
  • marketing information retained until consent is withdrawn, an objection is received or the information is no longer required;
  • system logs retained according to operational and security requirements;
  • backup data retained according to established backup cycles.


At the end of the applicable retention period, information will be securely deleted, destroyed, anonymised or archived where continued retention is authorised by law.


Information contained in backups may remain until the applicable backup is overwritten or securely destroyed, provided it is not restored or used except for legitimate recovery, security or legal purposes.


Automated decision-making and artificial intelligence


Amplifi ERP does not ordinarily make decisions that produce significant legal or similarly material effects based solely on automated processing of website visitor, prospect or customer personal information.


We may use software-assisted tools to support:

  • analytics;
  • security monitoring;
  • data classification;
  • service management;
  • marketing administration;
  • recruitment administration;
  • document drafting or summarisation;
  • technical troubleshooting.


Where artificial-intelligence or automated tools are used, Amplifi ERP will seek to apply appropriate confidentiality, security and human-oversight measures.


We will not intentionally submit confidential customer data or personal information to a public generative artificial-intelligence service unless:

  • it is authorised;
  • appropriate safeguards are in place;
  • use is consistent with the applicable customer agreement;
  • the processing complies with applicable law.


Customers should not submit sensitive or confidential information through demonstration environments, public tools or unapproved communication channels.


Links to third-party websites


Our website may contain links to third-party websites, platforms or services.


Amplifi ERP does not control the privacy practices, security or content of those third parties.


When you follow a third-party link, the relevant third party’s terms and privacy notice will apply. We encourage you to review those notices before providing personal information.


The inclusion of a link does not necessarily imply endorsement of the third party’s privacy or security practices.


Social media


Amplifi ERP may operate pages on social-media and professional-networking platforms.


When you interact with those pages:

  • the platform may collect personal information under its own privacy terms;
  • Amplifi ERP may receive profile, engagement or communication information;
  • public comments and reactions may be visible to others;
  • aggregated analytics may be provided to Amplifi ERP.


You should avoid posting confidential, sensitive or account-related information through public social-media channels.


Your rights under POPIA


Subject to applicable law and any lawful limitations, you may have the right to:


Be informed


You have the right to be informed when personal information is collected and about how that information is processed.


Request confirmation


You may ask whether Amplifi ERP holds personal information about you.


Request access


You may request access to your personal information and information about how it is processed.


Access requests may be subject to:

  • appropriate proof of identity;
  • the procedures prescribed by POPIA and PAIA;
  • protection of third-party rights;
  • lawful grounds for refusal;
  • prescribed fees, where applicable.


Request correction


You may request correction or updating of information that is inaccurate, incomplete, excessive, out of date, misleading or obtained unlawfully.


Request deletion or destruction


You may request deletion or destruction of personal information that Amplifi ERP is no longer authorised to retain, subject to legal, contractual and operational retention requirements.


Object to processing


You may object, on reasonable grounds relating to your particular situation, to certain processing activities.


You may object to the processing of your personal information for direct-marketing purposes at any time.


Withdraw consent


Where processing is based on consent, you may withdraw consent at any time.


Withdrawal does not affect the lawfulness of processing completed before withdrawal.


Complain


You may submit a complaint to Amplifi ERP’s Information Officer or lodge a complaint with the Information Regulator.


Challenge automated decisions


Where applicable, you may have rights relating to decisions based solely on automated processing that produce legal or substantial effects.


Additional rights where GDPR applies


Where the GDPR applies to the processing of your personal data, you may also have the right to:

  • request access;
  • request rectification;
  • request erasure;
  • restrict processing;
  • object to processing;
  • receive certain personal data in a structured, commonly used and machine-readable format;
  • request transmission of eligible personal data to another controller;
  • withdraw consent;
  • object to direct marketing;
  • lodge a complaint with an applicable supervisory authority;
  • obtain information about international-transfer safeguards;
  • exercise rights relating to automated decision-making.


These rights are subject to the conditions, exceptions and limitations in the GDPR and applicable national legislation.


Exercising your rights


Requests may be submitted to the Information Officer using the contact details below.


Your request should include:

  • your full name;
  • your contact details;
  • sufficient information to identify the relevant records or processing activity;
  • the right you wish to exercise;
  • proof of identity or authority where appropriate.


We may request additional information where reasonably necessary to:

  • verify your identity;
  • protect personal information;
  • locate the relevant records;
  • determine whether you are authorised to act for another person.


We will respond within the period required by applicable law.


Where we cannot comply with a request, we will provide an explanation where required or appropriate.


We will generally not charge for responding to a request, although a prescribed or reasonable fee may apply where permitted by law, particularly for copies, repeated requests or requests requiring substantial effort.


Where information is processed on behalf of a customer, we may refer your request to the relevant customer.


Information Officer


Questions, requests, objections and complaints relating to privacy may be directed to:

Information Officer: Warwick Smith

Legal entity: Amplifi ERP, a division of Steltix Development South Africa (Pty) Ltd

Registered address: Standard House, 18 Royal Street, Hermanus, 7200, South Africa

Postal address: PO Box 24033, Claremont, 7725, South Africa

Telephone: +27 28 316 1257

​Email: warwick.smith@steltix.com

​Website: www.amplifierp.com


Please use the subject line: Privacy Request – Amplifi ERP


The Information Officer is responsible for supporting compliance with POPIA and applicable internal privacy requirements.


Complaints to the Information Regulator


You have the right to lodge a complaint with the Information Regulator of South Africa if you believe that your personal information has been processed unlawfully or that your privacy rights have not been appropriately addressed.


At the date of this Privacy Policy, the Information Regulator’s general contact details include:


Information Regulator South Africa

JD House

27 Stiemens Street

Braamfontein

Johannesburg

2001

South Africa


Telephone: +27 10 023 5200

Email: enquiries@inforegulator.org.za

Complaints email: PAIAComplaints@inforegulator.org.za or POPIAComplaints@inforegulator.org.za

Website: https://inforegulator.org.za/


As the Regulator may update its submission procedures, you should consult its website for the current complaint forms and filing instructions.


PAIA Manual


Amplifi ERP or its underlying legal entity may maintain a PAIA Manual describing:

  • the records it holds;
  • how requests for access may be submitted;
  • the categories of personal information processed;
  • •he recipients of personal information;
  • planned international transfers;
  • applicable security measures.


The PAIA Manual may be requested from the Information Officer or accessed at:

PAIA Manual: [Insert link once available]


Changes to this Privacy Policy


Amplifi ERP may update this Privacy Policy periodically to reflect:

  • changes in legislation;
  • regulatory guidance;
  • changes to our services;
  • changes to technology;
  • changes to our processing activities;
  • improvements to privacy and security practices.


The latest version will be published on our website with the date of the most recent update.


Material changes may also be communicated through reasonable additional channels where appropriate.


We encourage you to review this Privacy Policy periodically.


Contacting us


For general enquiries about Amplifi ERP:

Amplifi ERP, a division of Steltix Development South Africa (Pty) Ltd

Standard House, 18 Royal Street, Hermanus, 7200, South Africa

Tel: +27 28 316 1257

​Email: sales@amplifierp.com

Website: www.amplifierp.com


For privacy-related matters:

Email: warwick.smith@steltix.com

Information Officer: Warwick Smith