Privacy Policy
Personal information, project data and how to contact our Information Officer.
1. Introduction
Ace Consulting Global ("we", "us", or "the Firm") is committed to protecting the privacy and security of your personal data. This policy outlines how we handle personal information in compliance with the Protection of Personal Information Act (POPIA) of South Africa and the General Data Protection Regulation (GDPR) of the European Union.
As a global engineering and project management consultancy, we process data related to clients, contractors, and stakeholders across multiple jurisdictions. We apply the highest standard of data protection across all our operations regardless of geographic location.
2. Data Collection
We collect and process personal information only to the extent necessary for our business functions. This includes:
- Identity Data: Full names, professional titles, and government-issued identification where required for site access.
- Contact Data: Professional email addresses, phone numbers, and physical business addresses.
- Technical Data: IP addresses, browser types, and usage patterns collected via our digital project management portals.
- Project Data: Information relevant to engineering procurement, environmental impact assessments, and site management.
3. Lawful Grounds for Processing
Under both POPIA and GDPR, we only process data when there is a lawful basis to do so:
- Contractual Necessity: To fulfill our obligations under consulting agreements.
- Legal Obligation: To comply with international engineering standards and local labor laws.
- Legitimate Interest: To maintain the security of our infrastructure and improve our service delivery.
- Consent: Where you have explicitly opted-in to receive our quarterly industry insights and sustainability reports.
Data Sovereignty
Ask our Information Officer about the storage location, access controls and handling arrangements that apply to your project before sharing confidential material.
4. International Data Transfers
International projects may involve recipients and service providers in different countries. Contact our Information Officer to confirm the recipients, transfer arrangements and applicable safeguards for your project.
For transfers within our South African operations, we adhere strictly to Section 72 of POPIA regarding the transfer of personal information outside of the Republic.
5. Your Data Rights
You have the following rights regarding your personal information:
- Access: The right to request a copy of the data we hold about you.
- Rectification: The right to correct inaccurate or incomplete information.
- Objection: The right to object to processing based on legitimate interests.
- Portability: The right to receive your data in a structured, machine-readable format (GDPR specific).
- Erasure: The right to be "forgotten" under certain legal conditions.
6. POPIA Compliance (South Africa)
For questions about personal information handled in our South African operations, including access, correction or deletion requests, contact the Information Officer below. Please identify the relevant project or interaction so we can address your request.
What POPIA gives you as a data subject
- Right to be notified that we are collecting your information, who is collecting it, and what we intend to use it for.
- Right of access to confirm what information we hold and to receive a copy of it.
- Right to correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, misleading, or unlawfully obtained.
- Right to object to processing on reasonable grounds, including direct marketing.
- Right to complain to the Information Regulator if you believe your rights have been infringed.
The eight POPIA processing conditions we follow
- Accountability — our Information Officer is named below and remains responsible for compliance.
- Processing limitation — minimum information, lawful basis, with consent or contractual / legitimate interest.
- Purpose specification — information is collected for a specific, explicitly defined and lawful purpose tied to a function or activity.
- Further-processing limitation — secondary uses must be compatible with the original purpose.
- Information quality — we take reasonable steps to keep records accurate, complete, current.
- Openness — this policy, our PAIA manual, and our Information Officer details are published openly.
- Security safeguards — encryption in transit and at rest, access controls, breach notification within 72 hours where required.
- Data-subject participation — the mechanisms above let you exercise your rights without friction.
Cross-border transfers under Section 72
We are headquartered in Cape Town and serve clients in Dubai, Tripoli and Istanbul. Where personal information of South African data subjects is transferred outside the Republic in the course of serving these markets, the transfer complies with Section 72 of POPIA: the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or you have consented to the transfer, or the transfer is necessary for the performance of a contract.
Complaints and escalation
If you believe Ace Consulting has not handled your personal information in accordance with POPIA, contact our Information Officer first (details below). If your complaint is not resolved to your satisfaction, you may approach the Information Regulator at inforegulator.org.za or by email at POPIAComplaints@inforegulator.org.za.
7. Information Officer
In accordance with POPIA, Ace Consulting has appointed an Information Officer to oversee data compliance. For any queries or to exercise your rights, please contact:
Head of Legal & Compliance
Ace Consulting Global HQ
info@aceconsulting.co.za
+27 21 825 0230
