LockLayerCyber
Legal

Privacy Policy

This Privacy Policy explains how LockLayer Cyber processes personal information when you visit our website, communicate with us or use LockLayer ONE.

Effective date: 17 September 2026

Last updated: 17 September 2026

LockLayer Cyber (Pty) Ltd, trading as LockLayer Cyber ("LockLayer", "we", "us" or "our"), respects privacy and is committed to processing personal information responsibly and in accordance with applicable South African data protection law, including the Protection of Personal Information Act 4 of 2013 ("POPIA").

This Privacy Policy applies to personal information processed in connection with the LockLayer Cyber website, LockLayer ONE, customer enquiries, account administration, subscriptions, support and related business activities.

1. Who we are

LockLayer Cyber is a South African technology company that develops LockLayer ONE, a business-to-business cloud software platform for governance, risk and compliance management.

Our website is www.locklayercyber.co.za.

2. Scope of this Privacy Policy

This Policy describes how we process personal information when you:

  • visit or interact with the LockLayer Cyber website;
  • contact us or request information about LockLayer ONE;
  • join an early-access, trial or other product programme;
  • register for or use LockLayer ONE;
  • purchase or administer a subscription;
  • request customer support;
  • communicate with us in a business capacity; or
  • otherwise provide personal information to us in connection with our services.

3. Our role when processing information

Our role under POPIA depends on the circumstances in which personal information is processed.

LockLayer may determine the purpose and means of processing certain information relating to our own website visitors, prospective customers, customer contacts, account administration, billing, security and business operations.

Customers may also submit information to LockLayer ONE for their own GRC purposes. Where a Customer determines why and how personal information contained in Customer Data is processed and LockLayer processes that information to provide the service, the respective responsibilities of LockLayer and the Customer will depend on POPIA, the circumstances and any applicable data-processing agreement.

Customers remain responsible for ensuring that personal information they submit to LockLayer ONE is collected and processed lawfully.

4. Personal information we may collect

Depending on how you interact with us, we may process categories of personal information such as:

  • name and surname;
  • business email address;
  • telephone or other business contact details;
  • job title, role and organisation;
  • account identifiers and authentication-related information;
  • organisation membership, roles and permissions;
  • subscription and billing-related information;
  • correspondence, enquiries, support requests and other communications;
  • technical information associated with access to our website or platform;
  • security and activity information reasonably required to protect, administer or troubleshoot the service; and
  • personal information contained in documents, records or other Customer Data submitted to LockLayer ONE.

5. Customer compliance information and uploaded documents

LockLayer ONE allows Customers to manage business and compliance information such as risks, controls, policies, evidence, audits, incidents, assets, vendors, privacy records, business continuity information and compliance obligations.

Some of this information may contain personal information about employees, contractors, customers, suppliers or other individuals. The nature of this information is determined largely by what the Customer chooses to submit to the platform.

Customers should avoid submitting personal information that is not reasonably necessary for their legitimate use of the service and should take particular care before submitting sensitive or special personal information.

6. How we collect information

We may obtain personal information:

  • directly from you;
  • from the organisation you represent;
  • when you register for or use LockLayer ONE;
  • when you submit information through our website;
  • when you communicate with our support or business teams;
  • through authorised users of a Customer organisation;
  • automatically through reasonable technical, security and operational mechanisms when you interact with our systems; and
  • from service providers where reasonably necessary to administer a payment, account, security event or service interaction.

7. Why we process personal information

We may process personal information for purposes including:

  • providing and operating LockLayer ONE;
  • creating and administering accounts and organisations;
  • authenticating users and managing access;
  • providing trials and subscriptions;
  • processing and reconciling payments;
  • responding to enquiries and providing customer support;
  • maintaining and improving service functionality;
  • protecting our systems, Customers and users;
  • detecting, investigating and responding to security incidents;
  • maintaining appropriate business and transaction records;
  • meeting legal, regulatory and contractual obligations;
  • communicating important administrative, security or service information;
  • managing our business relationships; and
  • exercising or defending legitimate legal rights where necessary.

8. Lawful processing

LockLayer processes personal information only where there is an appropriate basis for doing so under applicable law.

Depending on the circumstances, processing may be necessary to perform a contract, take steps requested before entering into a contract, comply with a legal obligation, pursue a legitimate interest of LockLayer or a third party, protect a legitimate interest of the data subject, or take place with consent where consent is the appropriate basis.

We seek to process personal information in a manner that is adequate, relevant and not excessive in relation to the purpose for which it is processed.

9. Authentication

LockLayer ONE currently uses Clerk to provide authentication and organisation-related identity functionality.

Authentication providers may process information necessary to create, authenticate and secure user accounts. Their processing may also be subject to their applicable privacy and security terms.

LockLayer does not require users to disclose their account password to LockLayer personnel.

10. Payments

Subscription payments may be processed by third-party payment providers, including PayFast and Paystack.

Payment providers may collect and process information necessary to authorise, process, verify or reconcile a transaction. Where payment card information is entered directly into a payment provider's payment environment, LockLayer does not need to receive the full card details in order to provide the subscription.

LockLayer may receive transaction-related information such as payment status, amount, transaction reference, customer reference or other information reasonably necessary to administer a subscription.

11. Service providers

We use third-party technology and service providers to operate LockLayer ONE and our business. Depending on the service or feature, these may include:

  • Clerk — authentication and identity-related functionality;
  • Vercel — application and website hosting or deployment infrastructure;
  • Neon — PostgreSQL database infrastructure;
  • Amazon Web Services (AWS) — cloud infrastructure, secure document storage or processing and related security services;
  • Google Cloud / Vertex AI — certain advisory artificial intelligence functionality;
  • PayFast — payment processing where enabled; and
  • Paystack — payment processing where enabled.

The providers used may change as our infrastructure and services develop. We seek to use service providers appropriate to the services they perform and to manage personal information in accordance with applicable legal requirements.

12. Artificial intelligence processing

Certain LockLayer ONE features may use artificial intelligence to assist Customers with activities such as evidence review, identifying potential gaps, summarising information or preparing policy drafts.

Information submitted to an AI-assisted feature may be processed by the relevant AI infrastructure provider to the extent necessary to provide that feature.

LockLayer ONE's AI functionality is advisory. AI-generated results require human review and do not constitute legal advice, regulatory certification, audit assurance or a guarantee of compliance.

Customers should consider the nature and sensitivity of information before submitting it to an AI-assisted workflow and should avoid providing unnecessary personal information.

13. Cookies and similar technologies

Our website and platform may use cookies or similar technologies that are reasonably necessary for functionality, authentication, security, session management, preferences or related technical purposes.

If we use non-essential analytics, advertising or similar technologies that require additional notice or consent under applicable law, we will provide appropriate information and controls.

Browser settings may allow you to block or delete certain cookies. Blocking cookies required for authentication or essential platform functionality may prevent parts of the service from working correctly.

14. Security

We use reasonable technical and organisational safeguards designed to protect information against loss, unauthorised access, interference, modification, destruction or unauthorised disclosure.

Depending on the relevant service, measures may include access controls, authentication, tenant separation, security monitoring, secure cloud infrastructure and security scanning of uploaded documents.

LockLayer uses AWS S3 and security services including GuardDuty in connection with secure document-processing workflows. The precise security architecture may evolve as we improve the service.

No method of electronic storage or transmission can be guaranteed to be completely secure. Customers also remain responsible for securing their own devices, user accounts, credentials and authorised-user access.

15. Cross-border processing

Some technology or service providers used by LockLayer may process, support or make information accessible from infrastructure or personnel located outside South Africa.

Where personal information is transferred outside the Republic of South Africa, LockLayer will seek to handle the transfer consistently with applicable requirements under POPIA, including section 72 where applicable.

We do not represent that every category of information or every supporting service is processed exclusively within South Africa unless this is expressly confirmed for the relevant service or contractual arrangement.

16. Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or subsequently processed, subject to legal, regulatory, contractual, security and legitimate business requirements.

Retention periods may differ depending on the type of information, Customer relationship, subscription status and applicable legal obligations.

Information may be retained for an appropriate period after an account or subscription ends where necessary to comply with law, resolve disputes, maintain required business records, protect legal rights or complete secure deletion processes.

17. Data subject rights

Subject to POPIA and other applicable law, a data subject may have rights concerning their personal information, including rights to:

  • request confirmation of whether LockLayer holds personal information about them;
  • request access to applicable personal information;
  • request correction or, where legally appropriate, deletion of personal information;
  • object to certain processing in circumstances permitted by law;
  • withdraw consent where processing is based on consent, subject to the consequences and lawfulness of processing before withdrawal; and
  • lodge a complaint with the Information Regulator where applicable.

Some requests may be subject to verification, legal limitations, record-retention obligations or procedures prescribed by POPIA, PAIA or other applicable legislation.

18. Requests concerning Customer Data

If your personal information was submitted to LockLayer ONE by one of our Customers, that Customer may be the appropriate organisation to contact first regarding access, correction, objection or deletion.

Where appropriate and legally required, LockLayer will assist with requests relating to information processed through our service in accordance with the respective responsibilities of LockLayer and the Customer.

19. Direct marketing

LockLayer may communicate with business contacts about our services in accordance with applicable law.

Where consent or another legal requirement applies to electronic direct marketing, we will seek to comply with the applicable requirements. Marketing communications that provide an unsubscribe mechanism may be opted out of using that mechanism.

Service, security, billing and other necessary administrative communications are not necessarily marketing communications and may continue where required to administer an active account or business relationship.

20. Information relating to children

LockLayer ONE is a business service and is not intended to be used by children as consumer users.

Customers should not intentionally submit children's personal information unless they have determined that doing so is lawful, necessary and appropriate for their legitimate use of the platform.

21. Security incidents

If LockLayer becomes aware of a security compromise involving personal information, we will assess the circumstances and take steps required under applicable law and relevant contractual obligations.

Where POPIA requires notification to the Information Regulator, an affected data subject or a Customer, the applicable notification process will be followed.

22. Changes to this Privacy Policy

We may update this Privacy Policy as our services, technology, processing activities or legal obligations change.

The current version will be published on this page and will display its effective date and last-updated date. Where appropriate, we may provide additional notice of material changes.

23. Contacting us about privacy

Privacy questions and data-subject requests may be sent to:

LockLayer Cyber (Pty) Ltd
Trading as LockLayer Cyber
Registration number: 2023/125743/07
Physical business address: 17 Elliot Street, Rynfield, Benoni, Gauteng, South Africa
Email: info@locklayercyber.co.za
Website: www.locklayercyber.co.za

24. Information Regulator

Data subjects may have the right to lodge a complaint with the South African Information Regulator regarding the processing of their personal information.

Current Information Regulator contact and complaint information can be obtained from the Information Regulator's official website.

Legal review: This Privacy Policy is intended to provide practical transparency regarding LockLayer Cyber's current services and technology. The final policy, together with LockLayer's internal POPIA documentation, operator arrangements and PAIA/Information Officer obligations, should be reviewed by a qualified South African legal or privacy professional before public launch.