Privacy notice

How information submitted here is handled.

Last updated 1 September 2026

Confidentiality and privacy are core operating values of the firm rather than a compliance formality. The nature of the work — independent review of designs, calculations, project plans and technology programmes — depends entirely on clients being able to share sensitive material in confidence. This notice sets out how information submitted through this website is handled.

Who is responsible

ImmersaEngineering is the independent engineering advisory division of Immersa Hub (Pty) Ltd, registration number 2026/463574/07, a company registered in South Africa and situated in Pretoria, Gauteng. That entity is the responsible party under the Protection of Personal Information Act, 2013 (POPIA) and the controller under the UK and EU General Data Protection Regulation where those apply.

The Information Officer of Immersa Hub (Pty) Ltd, in terms of section 56 of POPIA and registered with the Information Regulator of South Africa, is Dr Xandra van Wyk, who may be contacted through the address below.

The company is situated in Pretoria, Gauteng. Enquiries about this notice, correspondence for the Information Officer, and any request described below should be sent to info@immersaengineering.com and will be acknowledged in writing. A postal address will be published here once the company’s premises are established, and may be requested in the meantime.

What is collected

Only what is submitted through the enquiry form or sent by email:

The IP address is recorded for one purpose only: to limit how many enquiries a single connection can submit in an hour, which is what stops the form being used to send bulk mail. Where the site is configured to use its own mail handler, a one-way cryptographic hash of the address is written to a short-lived file on the server for that purpose, and the address itself appears in the enquiry email. Neither is used to identify, locate or profile anyone.

No account is created, no profile is built, and no special categories of personal information are sought. Technical or commercially sensitive detail should not be submitted through this form before a non-disclosure agreement is in place — a secure transfer route is provided at that point.

Cookies and tracking

This website sets no cookies, uses no analytics or advertising scripts, and loads no third-party resources before a form is submitted. Nothing on this site tracks visitors between sessions or across other websites.

Why it is collected, and on what basis

Information is used solely to respond to the enquiry, to assess whether the requirement can be accepted, and to scope and quote potential work. Under GDPR the lawful basis is legitimate interest — responding to an unsolicited business enquiry — and, once an engagement proceeds, performance of a contract. Under POPIA the ground for responding to an unsolicited enquiry is the legitimate interest of the responsible party under section 11(1)(f); once an engagement is agreed, the ground becomes the conclusion and performance of a contract under section 11(1)(b). No consent is requested or relied on for an initial enquiry, because none is required and the form offers no mechanism to give it.

Submissions are never sold, never rented, and never added to a marketing list. There is no newsletter and no automated follow-up sequence.

Who else sees it

Enquiries are received by the principals of the firm. Where an engagement requires a named specialist, that person is disclosed before any client information is shared, and is bound by the same confidentiality terms.

The enquiry form posts to a handler on this website’s own server, which sends the submission by email to the enquiries mailbox. The only other party involved is the website and email host, Domains.co.za, acting as an operator under POPIA and a processor under GDPR. No third-party form service, marketing platform or analytics provider receives enquiry information.

How long it is kept

Two different records are involved and they are kept for different periods. The abuse-prevention record — a hashed IP address and a timestamp on the server — is deleted within two hours. The enquiry itself is an email, and the IP address the enquiry was sent from appears in the body of that email, so it is retained for as long as the email is: enquiries that do not lead to an engagement are deleted within 24 months. If the IP address is not wanted in the mailbox, it can be removed from the handler; it is there to make repeated abusive submissions traceable, not to identify enquirers. Submissions are also screened automatically for the characteristics of bulk marketing spam, which includes recording the number of seconds between the page loading and the first key pressed in the form; the outcome of that check is written into the notification email and is not stored anywhere else. Where an engagement proceeds, records are retained for the period required by the engagement terms and by South African company and tax law, and no longer. Documents supplied for review are held only for the duration of the engagement and are returned or destroyed at close-out, confirmed in writing.

Where it is held

Information is held in South Africa, on servers operated by the website and email host. Enquiry content is not routed through, stored in, or processed in any other country. Should that ever change, this notice will be updated before the change takes effect, and any transfer would be made under a lawful transfer mechanism under section 72 of POPIA.

Rights

Under POPIA and, where applicable, the UK and EU GDPR, the following may be requested at any time:

Requests are actioned without charge. A complaint may also be lodged with the Information Regulator of South Africa (inforegulator.org.za) or, for those in the United Kingdom or the European Union, with the relevant supervisory authority.

Security

This website is served over HTTPS. Enquiry content — name, organisation, email address and the description of the requirement — is held in access-controlled mailboxes and storage, and is not retained on this website. The single exception is the abuse-prevention record described above: a hashed IP address and a timestamp, held on the server for at most two hours and then deleted, and readable by nobody over the web. Client review material is handled on separate systems dedicated to that purpose and is not mixed with any other business.

Changes to this notice

Any material change will be reflected here, with the date at the top of this page updated accordingly.