Privacy Policy
At Brushstroke Investments (and including this website, https://brushstrokeinvestments.co.za) (“we,” “us,” or “our”), we are committed to protecting your privacy and ensuring the confidentiality and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and protect your personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA").
1. Definitions
Personal Information
Under POPIA, "personal information" means information that relates to an identifiable, living person or an existing juristic person, including but not limited to contact information, demographic information, personal history, and any other data that can identify a person or organization.
Data Subject
The individual or entity to whom the personal information relates.
2. Collection of Personal Information
We collect personal information directly from you when you interact with us, including when you:
- Contact us via email, phone, or other methods
- Register for services or subscribe to our content
- Provide feedback or participate in surveys
The types of information we may collect include:
- Contact details (e.g., name, email address, phone number)
- Demographic information (e.g., age, gender, location)
- Financial information (e.g., billing details for services, if applicable)
3. Purpose of Processing Personal Information
We collect and process your personal information to:
- Provide you with our services
- Improve, personalize, and analyse our services and website
- Respond to your inquiries and communicate with you
- Comply with legal, regulatory, and contractual obligations
- Protect our legitimate business interests and maintain website security
4. Legal Grounds for Processing
We will process your personal information only where:
- You have provided consent
- It is necessary to fulfill a contract with you
- We have a legitimate interest to do so, in a way that is not overridden by your privacy rights
- We are legally required to do so
5. Sharing of Personal Information
We are committed to maintaining your privacy and ensuring the confidentiality of your personal information. We do not sell, rent, trade, or share your personal information with any third parties for marketing or any other purposes without your explicit consent, except in the following circumstances:
- Legal Compliance: We may disclose your personal information if required to do so by law, such as in response to a court order, subpoena, or other legal processes, or if we believe in good faith that such action is necessary to comply with applicable laws.
- Protection of Rights: We may disclose your information when we believe it is necessary to investigate, prevent, or take action regarding potential violations of our terms, suspected fraud, situations involving potential threats to the safety of any person, or as evidence in litigation in which we are involved.
Rest assured, we take all reasonable steps to ensure that your personal information remains secure and confidential. Should our data-sharing practices change, we will update this policy and notify you as required by applicable law.
6. Security of Personal Information
We are committed to safeguarding your personal information and take reasonable security measures to prevent unauthorized access, loss, or misuse. These measures include:
- Secure data storage and encryption
- Access controls and authentication procedures
- Regular security audits and vulnerability assessments
7. Your Rights as a Data Subject
As a data subject under POPIA, you have the following rights regarding your personal information:
- Right of access – You may request access to your personal information held by us.
- Right to correction – You may request that we correct or update any personal information that is inaccurate or outdated.
- Right to deletion – You may request deletion of personal information in certain circumstances, where it is no longer needed for its intended purpose.
- Right to object – You may object to the processing of your personal information where such processing is not necessary for our legitimate interests.
To exercise any of these rights, please contact us at billytongsa@gmail.com.
8. Retention of Personal Information
We will retain your personal information only as long as it is necessary to fulfill the purposes for which it was collected, or as required by law. When your personal information is no longer needed, we will securely delete or anonymize it.
9. Use of Cookies
Our website uses cookies. For more details on our use of cookies, please refer to our Cookies Policy.
10. hCaptcha
We use the hCaptcha security service (hereinafter "hCaptcha") on our website. This service is provided by Intuition Machines, Inc., a Delaware US Corporation ("IMI"). hCaptcha is used to check whether user actions on our online service (such as submitting a login or contact form) meet our security requirements. To do this, hCaptcha analyzes the behavior of the website or mobile app visitor based on various characteristics. This analysis starts automatically as soon as the website or mobile app visitor enters a part of the website or app with hCaptcha enabled. For the analysis, hCaptcha evaluates various information (e.g. IP address, how long the visitor has been on the website or app, or mouse movements made by the user). The data collected during the analysis will be forwarded to IMI. hCaptcha analysis in the "invisible mode" may take place completely in the background. Website or app visitors are not advised that such an analysis is taking place if the user is not shown a challenge. Data processing is based on Art. 6(1)(b) of the GDPR: the processing of personal data is necessary for the performance of a contract to which the website visitor is party (for example, the website terms) or in order to take steps at the request of the website visitor prior to entering into a contract. Our online service (including our website, mobile apps, and any other apps or other forms of access offered by us) needs to ensure that it is interacting with a human, not a bot, and that activities performed by the user are not related to fraud or abuse. In addition, processing may also be based on Art. 6(1)(f) of the GDPR: our online service has a legitimate interest in protecting the service from abusive automated crawling, spam, and other forms of abuse that can harm our service or other users of our service. IMI acts as a "data processor" acting on behalf of its customers as defined under the GDPR, and a "service provider" for the purposes of the California Consumer Privacy Act (CCPA). For more information about hCaptcha’s privacy policy and terms of use, please visit the following links: https://www.hcaptcha.com/privacy and https://www.hcaptcha.com/terms
11. Google Analytics
We use Analytics services from Google LLC. Google Analytics uses "cookies", which are websited on your computer, in order to help the website analyze how users use the site during their visit. The nature of these cookies is mainly for performance, as also for marketing. The collected data (information about your web preferences, ads based on what you visit or even your language) are analyzed and categorized in order to create a useful report about how this website is used and emphasize on its performance. These data are transmitted and websited on a server controlled by Google, located in the United States.
Google will use all this information, determined by the way you are using our website, in order to generate reports based on website’s activity for website operators and to provide other services related to website activity and internet usage. Your IP address is anonymized before being sent to Google.
All user level and event data are being deleted from Google Analytics 14 months after the last visit in our website.
You can deactivate the installation and use of Cookies by simply setting up your web browser’s preferences. However, you might have access to a less functional or even malfunctional environment within the site. If you wish to prevent the storage of personal data (including your anonymized IP address) and their use only by Google, you can install the following plugin: https://tools.google.com/dlpage/gaoptout
For more information, please see the terms of use https://www.google.com/analytics/terms/us.html and the privacy policy https://support.google.com/analytics/answer/6004245 of Google Analytics.
12. Google Tag Manager (GTM)
Google Tag Manager (GTM) is a tag management system to manage JavaScript and HTML tags used for tracking and analytics on websites. Tags are small code elements that, among other things, are used to measure traffic and visitor behaviour, to understand the effect of online advertising and social channels. We occasionally set up remarketing and orientation towards target groups. We might also set them up when testing or optimising websites. We use GTM on our websites to include the following tracking tools: Google Analytics. For more information about GTM’s privacy practices can be found at https://policies.google.com/privacy and terms of use at https://www.google.com/analytics/tag-manager/use-policy/
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically to stay informed about our data practices.
14. Contact Us
If you have any questions or concerns about this Privacy Policy or the handling of your personal information, please Contact Us.