Privacy Policy

Privacy Policy

Last updated: 20 August 2026

This Privacy Policy explains how Catalyse Digital (Pty) Ltd collects, uses, stores, shares and protects personal information.

1. Introduction

Catalyse Digital (Pty) Ltd respects your privacy and is committed to protecting personal information entrusted to us.

This Privacy Policy explains how we collect, use, store, share, protect and otherwise process personal information when you:

  • visit our website;
  • contact us;
  • submit an enquiry;
  • request or download a resource;
  • subscribe to Catalyse Insights;
  • complete a form, checklist or assessment;
  • book a consultation or Growth Strategy Call;
  • interact with our emails or digital content;
  • engage us for services; or
  • otherwise provide personal information to us.

Catalyse Digital (Pty) Ltd is incorporated in the Republic of South Africa. Our primary privacy framework is the Protection of Personal Information Act 4 of 2013 (“POPIA”).

Where our activities fall within the territorial scope of privacy or data-protection legislation in another jurisdiction, additional requirements may apply, including the European Union General Data Protection Regulation (“EU GDPR”), the United Kingdom GDPR (“UK GDPR”), the Australian Privacy Act 1988 and applicable United States privacy laws.

The inclusion of provisions relating to another jurisdiction does not mean that every such law necessarily applies to every interaction with Catalyse Digital.


2. Who We Are

Company: Catalyse Digital (Pty) Ltd
Registration Number: 2012/026496/07
Country of incorporation: Republic of South Africa
Website: catalysedigital.com
Email: info@catalysedigital.com

For purposes of POPIA, Catalyse Digital (Pty) Ltd is the Responsible Party where we determine the purpose and means of processing personal information.

Where applicable international privacy legislation applies to our processing, including the EU GDPR or UK GDPR, Catalyse Digital (Pty) Ltd generally acts as the Controller of personal data collected directly through this website.

Privacy and data-protection enquiries may be directed to:

info@catalysedigital.com


3. What We Mean by Personal Information

“Personal information” generally means information relating to an identifiable natural person and, where applicable under POPIA, an identifiable juristic person.

Depending on the law that applies, similar concepts may be referred to as “personal data” or another equivalent term.


4. Personal Information We May Collect

Depending on how you interact with Catalyse Digital, we may collect:

  • first and last name;
  • email address;
  • telephone number;
  • company or organisation name;
  • job title or professional role;
  • country or approximate location;
  • business website;
  • information provided in contact or enquiry forms;
  • consultation or appointment information;
  • answers submitted through forms, checklists, questionnaires or assessments;
  • information concerning business needs, challenges, priorities or goals;
  • marketing and communication preferences;
  • records of consent;
  • correspondence with Catalyse Digital;
  • engagement with emails and digital communications where permitted;
  • IP address;
  • browser and device information;
  • operating system;
  • referring website;
  • website usage and interaction information;
  • cookie and similar identifiers; and
  • any other information you voluntarily provide.

We seek to collect only information that is reasonably adequate, relevant and necessary for the purpose for which it is processed.


5. Growth Systems Checklist™

When you request the Catalyse Growth Systems Checklist™, we may collect:

  • your first name;
  • business email address;
  • form submission date and source;
  • communication preferences; and
  • information concerning engagement with related emails.

We process this information to:

  • deliver the requested Checklist;
  • manage the associated email sequence;
  • provide practical guidance concerning use of the Checklist;
  • respond to related enquiries; and
  • manage our business relationship with you.

The Checklist is a self-assessment resource and does not itself constitute a professional diagnosis of your business.


6. Catalyse Insights

When you subscribe to Catalyse Insights, we may collect:

  • your first name;
  • email address;
  • marketing consent;
  • subscription date;
  • source of subscription;
  • communication preferences; and
  • email engagement information where permitted.

Catalyse Insights may include practical perspectives and resources relating to:

  • growth strategy;
  • business systems;
  • lead generation;
  • conversion;
  • AI;
  • automation;
  • technology;
  • search visibility;
  • growth optimisation; and
  • business performance.

You may unsubscribe at any time using the unsubscribe mechanism included in our emails.


7. Contact Forms and Business Enquiries

If you contact Catalyse Digital through the website, email or another channel, we may process information you provide to:

  • respond to your enquiry;
  • understand your requirements;
  • provide requested information;
  • arrange a consultation;
  • prepare a proposal;
  • take steps towards entering into a business relationship; and
  • maintain appropriate records of the enquiry.

8. Strategy Calls, Discovery Calls and Appointments

If you book a call or consultation, we may collect:

  • your name;
  • email address;
  • company details;
  • company website;
  • appointment date and time;
  • information about your business goals or challenges;
  • information you provide in booking questions; and
  • related correspondence.

We may use third-party scheduling and video-conferencing services to facilitate these appointments.


9. Information Collected Automatically

When you use our website, certain technical information may be collected automatically, including:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • referring website;
  • pages visited;
  • date and time of visits;
  • approximate geographic location;
  • website interactions;
  • cookie identifiers; and
  • website performance and analytics information.

We may use this information to operate, secure, analyse and improve the website.

Please refer to our Cookie Policy for further information.


10. How We Use Personal Information

We may process personal information for purposes including:

  • operating and maintaining our website;
  • responding to enquiries;
  • delivering requested resources;
  • managing subscriptions;
  • sending communications you have requested or agreed to receive;
  • scheduling and managing consultations;
  • providing services;
  • preparing proposals and quotations;
  • managing prospective and existing client relationships;
  • administering our CRM and contact records;
  • improving our website, services and customer experience;
  • analysing website and campaign performance;
  • understanding how visitors use the website;
  • maintaining security;
  • preventing misuse or fraud;
  • complying with legal and regulatory obligations;
  • maintaining accounting, business and compliance records;
  • establishing, exercising or defending legal claims; and
  • pursuing other legitimate business purposes permitted by applicable law.

11. Lawful Grounds for Processing

Under POPIA, personal information must be processed lawfully and in a reasonable manner that does not unjustifiably infringe your privacy.

Depending on the circumstances, processing may be based on:

  • your consent;
  • performance of a contract;
  • steps required before entering into a contract;
  • compliance with a legal obligation;
  • protection of your legitimate interests;
  • pursuit of Catalyse Digital’s legitimate interests or those of a third party where permitted by law; or
  • another lawful basis recognised under applicable legislation.

Where the EU GDPR or UK GDPR applies, we rely on an appropriate lawful basis under the applicable regulation.


12. Consent

Where we rely on your consent, you may withdraw it at any time.

Withdrawal of consent does not affect the lawfulness of processing that occurred before consent was withdrawn.

Where consent relates to marketing communications, you can normally withdraw it by using the unsubscribe mechanism contained in the communication.


13. Direct Marketing

Catalyse Digital aims to send direct marketing communications only where permitted by applicable law.

Where consent is required, we seek appropriate consent before sending electronic marketing communications.

Marketing communications may include:

  • Catalyse Insights;
  • practical resources;
  • business-growth perspectives;
  • information about relevant Catalyse Digital services;
  • invitations to consultations or events; and
  • other related business communications.

You may unsubscribe at any time by:

We may retain a suppression record of an unsubscribe request so that we can honour that preference.


14. Our Technology and Service Providers

We use third-party technology and service providers to operate our website and business.

These may include providers supporting:

  • website hosting;
  • WordPress functionality;
  • forms;
  • customer relationship management;
  • email delivery and marketing;
  • appointment scheduling;
  • video conferencing;
  • website security;
  • analytics;
  • cloud services; and
  • professional business services.

Our current technology environment may include services such as:

  • WordPress;
  • Fluent Forms;
  • FluentCRM;
  • FluentSMTP;
  • Calendly;
  • Google services where applicable; and
  • our website hosting and infrastructure providers.

The providers used may change over time.

Where a service provider processes personal information on our behalf, we seek to use appropriate contractual, technical and organisational safeguards.


15. Sharing and Disclosure of Personal Information

Catalyse Digital does not sell personal information.

We may disclose personal information where reasonably necessary to:

  • technology and hosting providers;
  • CRM and email providers;
  • appointment and communication providers;
  • professional advisers;
  • contractors or service providers supporting our operations;
  • auditors, accountants or legal advisers;
  • regulators or governmental authorities;
  • courts or law-enforcement bodies where legally required;
  • parties involved in legal proceedings; or
  • parties involved in a legitimate merger, acquisition, restructuring or transfer of business assets.

We seek to limit disclosure to information reasonably necessary for the relevant purpose.


16. Operators and Processors

Where another organisation processes personal information on our behalf, it may act as an Operator under POPIA or a Processor under applicable international data-protection law.

We seek to ensure that appropriate contractual and security arrangements are in place where required.


17. International and Cross-Border Transfers

Catalyse Digital operates internationally and uses technology services that may process or store personal information outside South Africa.

Where personal information is transferred outside South Africa, we seek to comply with applicable requirements relating to cross-border processing and appropriate protection.

Where GDPR or UK GDPR applies, additional safeguards may be required for certain international transfers. UK GDPR, for example, contains specific rules governing restricted transfers of personal information outside the UK.

Where Australian privacy law applies to a particular processing activity, Australian Privacy Principle 8 contains requirements relating to certain disclosures of personal information to overseas recipients.

Safeguards may include contractual protections, assessments of recipient protections or another mechanism permitted by applicable law.


18. Data Security

We take reasonable technical and organisational measures designed to protect personal information against:

  • loss;
  • misuse;
  • unauthorised access;
  • unlawful processing;
  • alteration;
  • unauthorised disclosure; and
  • destruction.

Measures may include:

  • controlled access;
  • password protection;
  • secure hosting;
  • security monitoring;
  • software maintenance;
  • backups;
  • security tools; and
  • appropriate internal procedures.

No electronic transmission or storage system can be guaranteed to be completely secure.


19. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected or as required by applicable law.

Retention periods depend on factors including:

  • the nature of the information;
  • the reason for collection;
  • whether an active relationship exists;
  • contractual requirements;
  • accounting and tax obligations;
  • regulatory requirements;
  • possible disputes or legal claims; and
  • communication and consent preferences.

For example:

  • enquiry records may be retained while the enquiry remains relevant;
  • subscriber information may be retained while you remain subscribed;
  • records of consent and unsubscribe requests may be retained for compliance purposes;
  • client and transaction records may be retained for applicable contractual, accounting, legal or regulatory periods.

When information is no longer required, we may delete, destroy or anonymise it in accordance with applicable requirements.


20. Accuracy of Personal Information

We seek to take reasonable steps to ensure that personal information we use is accurate, complete, not misleading and updated where necessary.

You may request correction of inaccurate information by contacting us.


21. Your Rights Under POPIA

Subject to applicable legal requirements and exceptions, you may have rights to:

  • request confirmation of whether we hold personal information about you;
  • request access to personal information we hold;
  • request correction or updating of inaccurate information;
  • request deletion or destruction where permitted;
  • object to certain processing;
  • withdraw consent where processing depends on consent;
  • object to direct marketing;
  • complain about our processing; and
  • lodge a complaint with the Information Regulator of South Africa.

Requests may be sent to:

info@catalysedigital.com

We may need to verify your identity before responding to a request.


22. EU/EEA — GDPR Rights Where Applicable

The EU GDPR may apply to organisations outside the European Union in certain circumstances, including where an organisation offers goods or services to individuals in the EU or monitors their behaviour there.

Where EU GDPR applies to our processing, you may have rights including:

  • the right to be informed;
  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection;
  • withdrawal of consent; and
  • rights relating to certain automated decision-making.

You may also have the right to lodge a complaint with the competent data-protection supervisory authority.

These rights are subject to the conditions and exceptions contained in applicable law.


23. United Kingdom — UK GDPR Rights Where Applicable

Where UK GDPR applies to our processing, UK individuals may have rights corresponding broadly to those described above, subject to applicable UK law.

UK GDPR may apply to organisations outside the United Kingdom in specified circumstances, including where an organisation specifically offers goods or services to people in the UK or monitors their behaviour.

International transfers governed by UK GDPR may also require an appropriate transfer mechanism.


24. Australia — Privacy Rights Where Applicable

Where the Australian Privacy Act 1988 and Australian Privacy Principles apply to Catalyse Digital’s activities, we will seek to comply with the applicable requirements.

The Australian Privacy Principles address matters including:

  • collection;
  • notice;
  • use and disclosure;
  • direct marketing;
  • security;
  • access;
  • correction; and
  • cross-border disclosure.

Where APP 8 applies, an APP entity generally must take reasonable steps before disclosing personal information to an overseas recipient to ensure that the recipient does not breach applicable Australian Privacy Principles, subject to specified exceptions.

Nothing in this policy represents that Australian privacy legislation necessarily applies to every interaction with an Australian visitor.


25. United States — Privacy Rights Where Applicable

Privacy legislation in the United States consists of federal sector-specific rules and a growing number of state privacy laws.

Applicability depends on factors such as:

  • the state concerned;
  • the nature of the business;
  • revenue;
  • the type and volume of personal information processed;
  • whether personal information is sold or shared; and
  • other statutory thresholds.

Where a US privacy law applies to our processing, we will seek to comply with the requirements applicable to Catalyse Digital.

We do not represent that every United States federal or state privacy law applies merely because this website can be accessed from the United States.

If applicable law grants you additional privacy rights, you may contact us at:

info@catalysedigital.com


26. Automated Processing and Profiling

We may use automation to:

  • deliver requested resources;
  • create or update CRM records;
  • send scheduled communications;
  • manage subscriber journeys;
  • categorise contacts;
  • administer marketing workflows; and
  • support ordinary business operations.

We do not currently use personal information collected through this website to make solely automated decisions that produce legal effects or similarly significant effects on individuals.


27. Cookies and Similar Technologies

Our website may use cookies and similar technologies for purposes including:

  • essential website functionality;
  • security;
  • user preferences;
  • analytics;
  • performance measurement; and
  • understanding website usage.

Where applicable law requires consent for non-essential cookies, we will seek appropriate consent before those technologies are activated.

Please see our Cookie Policy for further information.


28. Third-Party Websites

Our website may contain links to third-party websites or services.

Third-party websites operate independently of Catalyse Digital and may have their own:

  • privacy policies;
  • cookie policies;
  • security practices; and
  • terms of use.

Catalyse Digital is not responsible for the privacy, security or content practices of independent third-party websites.


29. Children’s Privacy

Catalyse Digital provides business and professional services.

Our website is intended for business and professional audiences and is not directed at children.

We do not knowingly seek to collect personal information from children through our website.

If you believe a child has provided personal information to us, please contact us so that we can review the matter and take appropriate action.


30. Privacy Complaints

If you have a concern about how Catalyse Digital processes your personal information, please contact us at:

info@catalysedigital.com

We will seek to review and address legitimate privacy concerns appropriately.

Where POPIA applies, you may also have the right to lodge a complaint with the Information Regulator of South Africa.

Where another applicable privacy law grants you a right to complain to a regulator or supervisory authority, you may also exercise that right.


31. Access to Information

Requests for access to records may also be subject to the Promotion of Access to Information Act 2 of 2000 (“PAIA”) and Catalyse Digital’s applicable PAIA procedures.

Where required, information concerning formal PAIA requests will be made available through the appropriate Catalyse Digital PAIA documentation.


32. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes in our business;
  • changes in technology;
  • new services or systems;
  • legal or regulatory developments; or
  • improvements to our privacy practices.

The latest version will be published on this website.

The Last Updated date at the top of this policy identifies the most recent revision.


33. Contact Us

For privacy enquiries, requests relating to your personal information or questions about this Privacy Policy, contact:

Catalyse Digital (Pty) Ltd
Registration Number: 2012/026496/07
Republic of South Africa

Website: catalysedigital.com
Email: info@catalysedigital.com

Privacy and data-protection enquiries:
info@catalysedigital.com

Scroll to Top