Privacy Policy

Protecting personal information through responsible, lawful and secure processing

Integrated Risk Solutions (Pty) Ltd — Website and Business Operations

Effective date
1 January 2026
Last updated
1 January 2026

Integrated Risk Solutions (Pty) Ltd ("IRS", "we", "us" or "our") respects your privacy and is committed to protecting personal information collected through our website, enquiries, consulting engagements and business operations. This Privacy Policy explains how we collect, use, store, share and protect personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA") and other applicable South African law.

1. Who We Are

Integrated Risk Solutions (Pty) Ltd is a specialised risk consulting agency providing Security Consulting, Occupational Safety and Insurance Risk Consulting services across South Africa and the broader Southern African region.

For purposes of POPIA, IRS may act as the responsible party when determining the purpose and means of processing personal information, or as an operator when processing information on behalf of a client under an authorised mandate.

2. Personal Information We May Collect

Depending on how you interact with us, we may collect names, surnames, job titles, company details, telephone numbers, email addresses, physical addresses, identification details, enquiry information, contractual records, invoices, payment information and correspondence.

Where relevant to an authorised consulting engagement, we may also process information obtained during site surveys, inspections, interviews, investigations and assessments, including photographs, video footage, access-control records, CCTV information, incident details and information relating to employees, contractors, tenants, witnesses, service providers or client representatives.

Our website may automatically collect limited technical information such as an IP address, browser type, device information, pages visited and cookie data. We will only process special personal information where this is lawful, reasonably necessary and appropriately authorised.

3. How We Collect Information

We may collect personal information directly from you; from your employer, broker, insurer, underwriter or authorised representative; during surveys, inspections, interviews, consultations or investigations; through contracts, service-level agreements, forms and correspondence; from approved service providers; from lawful public sources; and through website technologies such as cookies and analytics.

4. Why We Process Personal Information

We process personal information to respond to enquiries, provide quotations, deliver our consulting services, conduct surveys and assessments, prepare reports and recommendations, manage projects and appointments, communicate with authorised parties, verify compliance or competency, issue invoices, process payments, protect our systems and personnel, comply with legal and contractual duties, improve our services and establish or defend legal rights.

Processing will only take place where there is a lawful and reasonable basis, including consent, contractual necessity, legal obligation, protection of a legitimate interest or the proper performance of our business functions.

5. Risk Surveys, Assessments and Investigations

Our work may require information about properties, operations, security systems, workplace conditions, employees, tenants, contractors and incidents. Information gathered during an engagement will be limited to what is reasonably necessary for the authorised purpose.

Reports, photographs and supporting records may be shared with the appointing client, insurer, underwriter, broker, legal adviser or another authorised recipient where required by the mandate.

IRS will not knowingly use information gathered during a survey, assessment or investigation for an unrelated purpose without lawful authority.

6. Sharing of Personal Information

We may share personal information with clients and authorised representatives; insurers, underwriters and brokers; approved surveyors, consultants, investigators and subcontractors; technology, hosting and cloud-service providers; accountants, auditors, attorneys and other professional advisers; and regulatory, law-enforcement or judicial authorities where disclosure is required or permitted by law.

Service providers processing information on our behalf are expected to maintain appropriate confidentiality, security and data-protection measures. IRS does not sell personal information.

7. Cross-Border Processing

Some technology, cloud-storage, communication or support providers may process or store information outside South Africa. Where personal information is transferred across borders, IRS will take reasonable steps to ensure that the recipient is subject to appropriate legal, contractual or corporate safeguards consistent with POPIA.

8. Information Security

IRS applies reasonable technical and organisational safeguards designed to protect personal information against loss, damage, unauthorised access, alteration, disclosure or destruction. These may include access controls, password protection, secure storage and backups, antivirus and firewall measures, confidentiality obligations, controlled handling of reports and photographs, secure disposal and incident-response procedures.

Although reasonable precautions are taken, no electronic transmission or storage system can be guaranteed to be completely secure.

9. Retention of Information

Personal information will be retained only for as long as reasonably necessary to complete the purpose for which it was collected, meet contractual, tax, insurance, regulatory and legal obligations, maintain professional records, resolve disputes or protect legitimate business interests. Once information is no longer required, it will be securely deleted, destroyed or de-identified, subject to applicable retention duties.

10. Cookies and Website Analytics

Our website may use cookies and similar technologies to support website functionality, remember preferences, understand website traffic, improve performance and strengthen security. You may restrict or disable cookies through your browser settings, although this may affect the operation of parts of the website.

Where non-essential analytics or marketing cookies are used, appropriate notice and consent controls should be presented through the website.

11. Electronic Communications and Direct Marketing

We may use contact information to respond to enquiries, communicate about current services or provide relevant business information. Direct marketing communications will be managed in accordance with POPIA and applicable electronic-communications law. You may opt out of marketing communications at any time by using the unsubscribe option provided or by contacting us through the website.

12. Your Rights

Subject to applicable law, you may request confirmation of whether IRS holds personal information about you; request access to that information; ask that inaccurate or incomplete information be corrected; request deletion or destruction where retention is no longer authorised; object to or restrict certain processing; request information about the source or use of your information; and withdraw from direct marketing.

Requests may be subject to identity verification, legal limitations and the procedures prescribed by POPIA or PAIA.

13. PAIA and Access to Records

PAIA gives effect to the right of access to information held by public bodies and to information held by private bodies where it is required for the exercise or protection of rights. IRS will maintain and make available a PAIA Manual where required by law. Requests for access to records must follow the applicable PAIA process and prescribed forms.

14. Children's Personal Information

Our website and general consulting services are not directed at children. Where children's personal information is processed as part of an authorised school, childcare, workplace, insurance or investigation engagement, it will only be handled where legally permitted and reasonably necessary for the authorised purpose.

15. Third-Party Websites

Our website may contain links to third-party websites or services. IRS is not responsible for the privacy practices, security or content of external websites, and users should review the privacy notices of those third parties before providing personal information.

16. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our services, legal duties, technology or information-processing practices. The latest version will be published on the IRS website with an updated effective date.

17. Contacting IRS

Questions, objections, correction requests, access requests or privacy complaints may be directed to the IRS Information Officer through the contact details or enquiry form published on the Integrated Risk Solutions website. Please include sufficient information for us to identify you and respond to the request.

18. Complaints to the Information Regulator

You may lodge a complaint with the Information Regulator South Africa if you believe your personal information has been processed unlawfully or your rights have not been properly addressed.

Information Regulator South Africa

Address
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone
010 023 5200
Toll-free
0800 017 160
General enquiries
enquiries@inforegulator.org.za
POPIA complaints
POPIAComplaints@inforegulator.org.za

Legal notice: This Privacy Policy is intended as a general website privacy notice and should be read together with the IRS PAIA Manual, contractual terms, engagement-specific notices and internal information-governance procedures where applicable.