GDPR Policy

Last updated: July 2026

Introduction

SasAfrik ("we", "us", "our", or "Company") operates in compliance with the General Data Protection Regulation (GDPR) of the European Union. This policy outlines how we collect, process, store, and protect personal data of individuals within the EU and EEA.

Legal Basis for Processing

We process personal data on the following legal bases:

  • Consent from the individual
  • Performance of a contract
  • Compliance with legal obligations
  • Protection of vital interests
  • Performance of tasks in the public interest
  • Legitimate interests pursued by the Company

Data Subject Rights

Under GDPR, you have the following rights:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right not to be subject to automated decision-making

To exercise any of these rights, please contact us at hello@sasafrik.com

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. When data is no longer needed, it will be securely deleted or anonymized.

Data Transfers

Any transfer of personal data outside the EU/EEA will only occur with appropriate safeguards in place, such as Standard Contractual Clauses or adequacy decisions.

Contact Us

For any GDPR-related inquiries or to exercise your rights, please contact us at hello@sasafrik.com