GoTo.

Legal

Privacy Policy

How this website collects, uses and protects personal information. Written to be read rather than to be defensible.
Applies to
gotocommunications.co.za
Responsible party
GoTo Communications (Pty) Ltd
Governing law
POPIA, Act 4 of 2013
Last reviewed
Reviewed annually in October
01

Who we are

GoTo Communications (Pty) Ltd is the responsible party for personal information collected through this website. We are registered in South Africa and operate from Bloemfontein, Free State. A named Information Officer is responsible for compliance and is registered with the Information Regulator.

02

What we collect

Information you give us. When you complete the enquiry form we collect your name, email address, country and the content of your message, and, where you choose to supply them, your organisation, telephone number, the services you are interested in, an indication of budget, a preferred meeting date and time, and any document you attach. Only your name, email address, country, the area you need help with and your message are required; everything else is optional.

Information collected automatically. Our hosting provider records standard server logs, including IP address, browser type and pages requested, for security and diagnostic purposes.

Measurement, only if you agree. We would like to understand how this site is used so we can improve it. Nothing that measures you loads until you choose to allow it. If you do, we use Google Analytics 4 (through Google Tag Manager) and Microsoft Clarity, which records how pages are used so we can see where the site is confusing. If you decline, or if your browser sends a Global Privacy Control or Do Not Track signal, none of it loads at all and we do not ask again.

You can change your mind at any time by clearing this site’s data in your browser, which removes the stored choice and lets you decide again on your next visit.

What we do not do. We do not use advertising trackers, we do not run remarketing, we do not build advertising profiles, and we do not sell personal information under any circumstances.

03

Why we process it, and on what basis

Enquiry information is processed to respond to your enquiry, on the basis of your consent, which you give explicitly when submitting the form, and on the basis of our legitimate interest in conducting business correspondence. Server logs are processed on the basis of legitimate interest in the security and availability of the site.

We do not add enquiry contacts to a marketing list. If we ever introduce a mailing list, joining it will be a separate, explicit action.

04

Who we share it with

Enquiry information may be processed by our email provider and, where the primary route is unavailable, by Web3Forms as a fallback delivery service, each acting as an operator under documented instruction. The enquiry form is protected by Cloudflare Turnstile, which checks that a submission comes from a person; it receives your IP address for that check and does not set a tracking cookie.

If you choose to allow measurement, Google and Microsoft process usage data as described above. If you book a meeting, Calendly processes the details you enter into its booking form under its own terms.

We do not share personal information with any other party unless we are legally required to do so.

Where a third party processes information on our instruction, the tool, the provider, the data location and any no-training commitment are recorded on our supplier register.

05

Artificial intelligence

We do not index client confidential material or enquiry contents into any AI system with wider access than the engagement it belongs to. Where we use hosted commercial AI models in our own work, they are accessed under a recorded no-training commitment.

06

How long we keep it

Enquiry correspondence is retained for as long as necessary to respond and to maintain a reasonable business record, and is then deleted. Project files are archived at closure with personal data removed where it is no longer required. Server logs are retained for a short operational period by our hosting provider.

07

How we protect it

HTTPS on every page, multi-factor authentication on every account, a password manager, documented backup arrangements and a written incident response procedure. In the event of a compromise involving personal information, the Information Officer and the Managing Director are notified immediately, and affected parties and the Information Regulator are notified as required.

08

Your rights

Under POPIA you may request access to the personal information we hold about you, request correction or deletion, object to processing, and lodge a complaint with the Information Regulator. To exercise any of these rights, email hello@gotocommunications.co.za and mark the message for the attention of the Information Officer. We will acknowledge within one business day.

09

Cookies

This website sets no cookie of its own. Your measurement choice is stored in your browser’s local storage rather than a cookie, so declining does not itself set anything.

If you allow measurement, Google Analytics and Microsoft Clarity set their own cookies. If you decline, they are never loaded and set nothing. Third-party embeds, such as the map on the contact page and the booking calendar, are provided by their own operators, load only on the pages that use them, and are governed by their own privacy terms.

10

Changes

This policy is versioned and reviewed annually in October, reissued in November, and reviewed immediately after any incident the documentation should have prevented. Material changes will be noted on this page.

Related
See the POPIA statement for how we establish responsible party and operator roles on client engagements, and governance and compliance for the standing document set.