Legacy Risk Consult (Pty) Ltd
Effective date: 23 September 2026
1. Who is responsible for your information?
Legacy Risk Consult (Pty) Ltd, registration number 1997/001746/07, is the responsible party for personal information used to manage this website and respond to enquiries where we determine why and how that information is processed.
This policy covers visitors to legacyconsult.co.za, people who contact us through the site and the resulting enquiry correspondence. Personal information can relate to identifiable living individuals and, where applicable under POPIA, existing legal entities.
Insurance applications, policy administration, claims, employee records and client platforms may require additional notices and agreements. Where we process information solely on another responsible party's instructions, our operator role and the relevant client's notice must also be considered. This website notice does not describe every processing activity in those separate services.
Privacy contact: compliance@legacyconsult.co.za
Information Officer: Dirk Coetzee
Information Officer contact: compliance@legacyconsult.co.za
Telephone: +27 12 658 0464
Address: 91 Lyttelton Road, Clubview, Centurion, Gauteng, 0157, South Africa
2. Information collected
| Category | Information and source | Why it is relevant |
|---|---|---|
| Required enquiry details | Full name and email address supplied by you | Identify the enquiry and respond |
| Optional enquiry details | Company, phone number, selected service and message supplied by you | Understand your needs and use a suitable contact channel |
| Correspondence | Follow-up messages and information you provide while discussing an enquiry | Resolve questions and maintain the enquiry record |
| Website measurements | Page and referral information, browser/device information, approximate location and performance measurements through configured analytics services | Understand usage and improve the website |
| Operational records | Hosting, email-delivery and error records, potentially including network information and timestamps | Operate delivery, investigate faults and protect the service |
Providing enquiry information is voluntary, not a statutory requirement simply to browse the website. The form requires your name and email; without these it cannot submit an enquiry. Other fields are optional, although limited context may affect how specifically we can respond.
Information is normally obtained directly from you or through your interaction with the website. If you submit information about someone else, ensure you may lawfully do so and make this notice available to them.
Please do not include identity documents, payment-card details, passwords, medical information, children's details or client/member lists in the general enquiry form. Contact us to arrange an appropriate process if these are needed for a separate service.
3. Purposes and lawful grounds
We use enquiry information to respond, discuss the services requested and, where appropriate, take steps towards an engagement. Depending on the circumstances, the lawful ground is taking steps at your request towards a contract or pursuing legitimate interests in responding to business enquiries. Security, troubleshooting and proportionate website improvement are assessed against our legitimate interests and the impact on individuals. We also process information where necessary to meet applicable legal obligations. Where a particular activity requires consent, we must request it specifically rather than infer it from your acceptance of this notice.
These grounds are subject to the other safeguards in POPIA; consent is not its only possible lawful ground. See the Protection of Personal Information Act, particularly section 11.
We do not treat an enquiry as a subscription to unrelated promotional messages. Any electronic direct marketing must meet section 69's consent requirements or its limited existing-customer exception, including an opportunity to object. An existing-customer exception is limited to our own similar offerings and does not arise merely because someone visited the website. You may object to direct marketing using the contact details above. See the Information Regulator's direct-marketing guidance.
The website enquiry workflow does not make automated decisions about insurance eligibility, premiums or claims.
4. Recipients and service providers
Our website is hosted on Vercel, and our business mailbox is managed through Microsoft 365. The website is configured to send enquiry details through Resend to info@legacyconsult.co.za, using your email address as the reply-to address. The enquiry therefore passes through the website's server-side workflow and Resend's email-delivery service into our Microsoft 365 mailbox, where authorised staff can respond. Enquiry emails are not necessarily erased when you close your browser.
Relevant recipients may include authorised staff handling your enquiry, website and email service providers, professional advisers when needed, and authorities where disclosure is required or lawfully justified. Our handling rule is to disclose only what the recipient needs for the stated purpose. A partner logo on the website does not itself mean that enquiries are sent to that partner.
Resend processes email information under its Data Processing Addendum.
Vercel Web Analytics and Vercel Speed Insights are included in the website implementation. Web Analytics reports traffic information; Speed Insights reports page-performance information. Neither integration is configured in the website application to receive contact-form field values as custom events. Their technical operation is explained further in the Cookie Policy. Refer to Web Analytics privacy information and Speed Insights privacy information.
5. Processing outside South Africa
Cloud, email and measurement providers may process information outside South Africa. Use of an international provider does not establish that all information remains in South Africa.
Transfers must have an applicable basis under section 72 of POPIA, such as adequate protection through relevant law or a binding agreement, or another permitted ground. Publication of this policy is not consent to unrestricted international transfers. The relevant transfer basis and safeguards must be assessed before the transfer. See the Regulator's transborder-information guidance.
6. Retention and disposal
Our standard retention period for enquiry and related business records is five years, measured from the relevant closure date below. This is our company retention policy, not a claim that POPIA prescribes five years for every record. We retain information only while its purpose or another lawful ground justifies it. A shorter period applies where information is no longer lawfully needed; a longer period may apply where required by law or justified by a documented legal hold or unresolved dispute. When the applicable retention period and any justified hold end, information must be securely deleted or de-identified. See the POPIA retention provisions.
| Record | Retention period or rule |
|---|---|
| Enquiries that do not become engagements | Five years from closure of the enquiry, subject to the exceptions above |
| Enquiries that become client/service records | Five years from the end of the relevant engagement, subject to record-specific legal requirements and the exceptions above |
| Privacy-request records | Five years from closure of the request, subject to the exceptions above |
| Marketing-objection suppression records | Keep only the minimum information needed for as long as necessary to honour the objection; do not erase a suppression instruction automatically if doing so would restart unwanted marketing |
Deleting an email from one inbox may not immediately remove copies from delivery logs, archives or backups. These copies must be included in the retention arrangements. A provider's short-lived visitor identifier is not the same as its overall analytics-data retention period.
7. Security
We are required to take reasonable technical and organisational measures appropriate to the risks. Our adopted safeguards must address access permissions, secure transmission, account protection, provider oversight and incident handling. No internet transmission or storage system can be guaranteed completely secure.
Where a security compromise triggers notification duties, we must notify the Information Regulator and affected people as required by POPIA. The POPIA Policy sets out the response requirements.
8. Your rights and requests
Subject to applicable legal conditions, you may ask whether we hold your personal information; request access, correction or deletion; object to qualifying processing; withdraw consent for future consent-based processing; and complain about misuse. Withdrawal does not retrospectively invalidate lawful processing already completed. Access and deletion may be limited by lawful retention obligations, other people's rights or applicable statutory refusal grounds.
Email the privacy contact with the request and enough context to locate the relevant records. We may request proportionate identity or authority verification before disclosing records. Do not send a full identity document unless we have explained why it is needed and arranged an appropriate channel. We will explain the applicable procedure, any lawful fee, the outcome and available recourse. Requests must be handled within applicable legal timeframes.
You may complain to the Information Regulator through its complaints page and eServices portal. Contacting us does not remove that right. The Regulator's published general telephone number is 010 023 5200.
9. Children and policy changes
This business website is not directed at children and its general enquiry form is not intended to collect their information. If you believe a child has supplied information, contact us so that we can assess and address it. Separate insurance services involving children require the relevant legal safeguards and notices.
We will publish changes to this policy with an updated effective date and give additional notice where required. A revised notice does not by itself authorise a new incompatible use of information or replace consent where required.