Privacy Policy
Last updated: 8 May 2026
1. Who we are
This registry is operated by The Archive and Heritage Group (Pty) Ltd. We are the responsible party for personal information you provide here, in terms of POPIA (South Africa) and the GDPR (EU/UK).
2. What we collect
- Account details: email, display name, password (hashed).
- Profile content you publish: institution / vendor / software listings, contacts, reviews, comments.
- Technical data: IP address, browser user-agent, timestamps. Used for security (rate-limiting, abuse detection) and aggregate stats.
- Newsletter subscription, if you opt in.
3. How we use it
- To run the registry: show listings, deliver notifications, manage your account.
- To prevent abuse: rate-limit auth endpoints, flag suspicious activity.
- To send service email and (only if you opt in) newsletters.
We do not sell your data. We do not share it with third parties for advertising.
4. Cookies
We use a session cookie to keep you signed in. We do not use third-party tracking or advertising cookies. The cookie banner you saw on first visit confirms you are aware of the session cookie.
5. Retention
- Account data: kept while your account is active. Deleted on request.
- Reset tokens: 1 hour live, deleted within 7 days of expiry.
- Error logs: 30 days after resolution, then deleted.
- Database backups: 30 days, then rotated out.
6. Your rights
You can request access to, correction of, or deletion of your personal data at any time. Email us at johan@theahg.co.za with the subject line "Privacy Request" and we will respond within 30 days.
7. Contact
Questions? Email johan@theahg.co.za.
This page is a starting point and does not constitute legal advice. Your operations may impose additional disclosure requirements; consult a privacy lawyer for production use.