LAW (Pty) Ltd is committed to processing personal information lawfully, reasonably, and transparently in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA). This notice explains how we meet our obligations as a responsible party.
POPIA establishes eight conditions for the lawful processing of personal information. Below we explain how LAW meets each condition:
We have appointed a dedicated Information Officer responsible for overseeing POPIA compliance across all data processing activities.
We only collect personal information that is necessary for providing the LAW platform services. We do not process information beyond the stated purpose.
Personal information is collected for specific, explicit, and lawful purposes related to your practice management subscription and is not used for other purposes.
We do not process personal information in a manner incompatible with the original purpose of collection.
We take reasonable steps to ensure that personal information we process is complete, accurate, and up-to-date for its intended purpose.
We document all processing activities and inform data subjects of how their information is used through this notice and our Privacy Policy.
We implement appropriate technical and organisational measures including TLS 1.3 encryption in transit, AES-256 at rest, and role-based access controls.
Data subjects may request access, correction, or deletion of their personal information at any time by contacting our Information Officer.
The LAW platform may process special categories of personal information contained within legal documents (e.g., health records referenced in personal injury matters, financial records in insolvency matters). This information is processed solely on your instruction as part of our legal practice management service and is protected with enhanced security controls.
All personal information processed through the LAW platform is stored and processed within South Africa (AWS Cape Town region). We do not transfer personal information to operators or third parties outside of South Africa without ensuring adequate protection levels as required by POPIA.
We may use third-party operators to assist in providing our services. All operators are contractually bound to process personal information only on our documented instructions and in compliance with POPIA. Key operators include:
Under POPIA, you have the right to:
If you believe your rights have been violated, you may contact the Information Regulator of South Africa:
Website: inforegulator.org.za
Email: inforeg@justice.gov.za
For all POPIA-related requests and complaints:
Email: privacy@lawapp.co.za
Response time: We aim to respond to all data subject requests within 10 business days.