1. Who is responsible for your information
The “responsible party” under the Protection of Personal Information Act 4 of 2013 (“POPIA”) — and the “controller” where the EU/UK General Data Protection Regulation (“GDPR”) applies — is Absolute Actuator and Valve Sales (Pty) Ltd (registration number 2020/807636/07), trading as AAVS and South African Controls (“AAVS”, “we”, “us”), of Silverleaf Business Park, Kempton Park, Gauteng, South Africa. Full company details are on the Company & Legal Information page.
This policy covers the website www.aavs.co.za and the personal information we process when you enquire, request a quotation, buy from us, or otherwise deal with us. It applies together with our Cookie Policy.
2. Information Officer
Our Information Officer is Neil (Neeraj) Arjoon, director. For anything in this policy — questions, access requests, corrections, objections or complaints — contact:
- Email: neil.arjoon@aavs.co.za (or admin@aavs.co.za)
- Telephone: +27 81 477 3099
- Post: Silverleaf Business Park, Kempton Park, Gauteng, South Africa
3. What we collect, and where it comes from
Almost everything we hold comes directly from you. We do not buy marketing lists.
- Enquiry and quotation details — when you submit the quote or contact form: your name, company name (optional), email address, phone number (optional), your message, and the products, quantities and specifications you asked about.
- Order and payment details — billing information for invoicing, delivery addresses, and payment confirmations. We never see or store card numbers: payments are made on PayFast’s secure page, and PayFast sends us only the payment status, amount and reference.
- Correspondence — emails, calls and WhatsApp messages exchanged with our team in the course of business.
- Anonymous usage data — which pages are viewed, the device class (phone/tablet/desktop) and the referring site, tied to random identifiers that are never linked to your identity. Details and an opt-out are in the Cookie Policy.
- Transient technical data — your IP address is used in the moment to protect our forms against abuse (rate limiting) and to pre-select your country dialling code; it is not stored with your enquiry, and it is not used to profile you. Standard server logs at our hosting providers may record IP addresses for security purposes for short periods.
The site is not directed at children, and we do not knowingly collect children’s personal information. We also process no “special personal information” (such as health or biometric data) as defined in POPIA.
4. Why we use it, and on what legal grounds
POPIA requires a lawful justification for processing (section 11); the GDPR calls this a lawful basis (Article 6). Ours are:
- Answering your enquiry and performing a contract — preparing quotations, processing orders and payments, arranging delivery, and administering warranties (POPIA s11(1)(b); GDPR Art 6(1)(b)).
- Legal obligations — keeping tax invoices and transaction records the law requires (POPIA s11(1)(c); GDPR Art 6(1)(c)).
- Legitimate interests — securing the website against abuse and fraud, keeping business records, and anonymous measurement of how the site is used (POPIA s11(1)(f); GDPR Art 6(1)(f)). You may object as described in section 10.
- Consent, where we ask for it — for example if we ever send you marketing you did not qualify to receive under the rules below (POPIA s11(1)(a); GDPR Art 6(1)(a)). Consent can be withdrawn at any time.
We do no automated decision-making with legal or similarly significant effect, and no profiling.
5. Direct marketing
Under section 69 of POPIA we send electronic marketing only to (a) existing customers, about our own similar goods and services, whose details we obtained in the course of a sale or enquiry — with a free opt-out offered at collection and in every message — or (b) people who have consented, which we may request only once. Every marketing email we send contains a working unsubscribe link, and opting out never affects your service. We never give your details to third parties for their marketing.
Replies to your own enquiry — quotations, order updates, receipts — are service messages, not marketing. We do not currently run unsolicited marketing campaigns; before we ever do, we will register with the National Consumer Commission and screen our lists against the National Opt-Out Registry established under the Consumer Protection Act’s 2026 amendment regulations, in addition to the POPIA rules above.
6. Who we share information with
We never sell personal information. We share it only with the “operators” (POPIA’s term for processors) who run our infrastructure under contracts that bind them to confidentiality and security, and with parties needed to fulfil your order:
| Service | What they do for us | Where they process |
|---|---|---|
| Supabase | Database hosting — enquiry and quotation records | EU (Ireland, eu-west-1) |
| Vercel | Website hosting and content delivery network | United States / global edge network |
| Resend | Transactional email delivery (acknowledgements, quotations, receipts) | EU (Ireland) infrastructure; US company |
| PayFast (Network International) | Payment processing — card and instant-EFT payments | South Africa |
| Twilio | WhatsApp notifications to our own sales team | United States |
In addition, and only as needed: couriers and manufacturers (name, delivery address and order details, to deliver goods and process warranty claims), our professional advisers and auditors, and public authorities where the law requires disclosure. If AAVS is ever sold or restructured, records may transfer to the successor under the same protections.
7. Where your information is stored (cross-border transfers)
Our enquiry and quotation database is hosted in the European Union (Ireland), and our website and email providers process data in the EU and the United States, as set out above. Section 72 of POPIA allows these transfers because the recipients are either in jurisdictions with laws providing an adequate level of protection (such as the GDPR in the EU), or bound by written contracts that impose POPIA-equivalent protections, and because the transfer is necessary to perform our contract with you. For visitors protected by the GDPR, transfers to providers outside the EEA are made under the European Commission’s Standard Contractual Clauses entered into by those providers.
8. How long we keep it
- Enquiries that do not become orders — kept while we correspond with you and for up to 3 years afterwards (the general prescription period for contractual claims), then deleted. You may ask us to delete an enquiry sooner at any time.
- Quotations, invoices and payment records — kept for at least 5 years as the Tax Administration Act requires, and up to 7 years where the Companies Act requires.
- Warranty and dispute records — kept for the life of the warranty or claim plus the applicable prescription period.
- Anonymous usage data — contains no personal information and is kept in aggregate for trend reporting.
9. How we protect it
We apply the security safeguards section 19 of POPIA requires, appropriate to the risk: encryption in transit (TLS) on every page and API; a database locked down so that public visitors can submit enquiries but can never read them back; role-restricted, individually authenticated staff access with multi-factor authentication and audit-logged administrative actions; least-privilege service keys; and vetted infrastructure providers with their own certified security programmes. No system is perfectly secure — if we ever have reasonable grounds to believe your personal information has been accessed by an unauthorised person, we will notify you and the Information Regulator as section 22 of POPIA requires.
10. Your rights under POPIA
You have the right to:
- Access — confirmation of whether we hold personal information about you, and a copy of it (also see the PAIA note in section 14);
- Correction and deletion — have inaccurate, out-of-date or excessive information corrected, and information we are no longer entitled to keep destroyed (POPIA s24);
- Objection — object, on reasonable grounds, to processing based on legitimate interests, and object absolutely to direct marketing (POPIA s11(3));
- Withdraw consent where processing is based on it;
- Complain to the Information Regulator (details below) — though we would appreciate the chance to fix the problem first.
To exercise any of these, contact the Information Officer (section 2). We respond as soon as reasonably possible, and in any event within the periods PAIA and POPIA prescribe. We will verify your identity before releasing information.
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, 2017 · Tel: 010 023 5200
Complaints: POPIAComplaints@inforegulator.org.za · Enquiries: enquiries@inforegulator.org.za · inforegulator.org.za
11. Visitors from the EU / EEA and United Kingdom
Our services are directed at the South African and broader African market, but where the GDPR or UK GDPR nonetheless applies to you, you additionally have the rights to data portability, to restriction of processing, to erasure (“right to be forgotten”), and to lodge a complaint with your local supervisory authority. The lawful bases in section 4 apply as described. Our primary database is hosted in the EU. We have not appointed an EU or UK representative because our processing of EU/UK data is occasional and low-risk; if that changes, this policy will be updated.
12. Visitors from other countries
Wherever you are, the commitments in this policy apply: we do not sell personal information, we do not use it for behavioural advertising, and we honour requests for access, correction and deletion as described in section 10 regardless of your location, without ever discriminating against you for making one. Where the law of your country gives you additional rights, contact the Information Officer and we will deal with your request under that law to the extent it applies to us.
13. Children
This website sells industrial equipment to businesses and adults; it is not directed at children under 18 and we do not knowingly process children’s personal information. If you believe a child has given us personal information, contact us and we will delete it.
14. Access to records (PAIA)
Requests for access to records held by AAVS may also be made under the Promotion of Access to Information Act 2 of 2000 (“PAIA”). Our PAIA manual, prepared under section 51 of PAIA, is published on this website and available at our premises during business hours; it explains the records we hold, the prescribed form (Form 02), the fees, and the request procedure.
15. Changes to this policy
We review this policy when our processing changes and at least annually. The current version, with its “last updated” date, is always at this address; material changes will be highlighted here for a reasonable period.