Privacy Notice
1. Scope
This notice explains how Veltrion Laboratories (Pty) Ltd ("Veltrion") collects, uses, shares and protects personal information. It is written to meet the Protection of Personal Information Act 4 of 2013 ("POPIA") in South Africa and, where it applies to our processing, the EU and UK General Data Protection Regulation ("GDPR").
It covers personal information of prospective and current client contacts, delivery partners, suppliers, site visitors, applicants, and any individual who corresponds with us.
2. Who is responsible
Veltrion Laboratories (Pty) Ltd, registration number 2026/155300/07, Cape Town, South Africa, is the responsible party under POPIA and, where GDPR applies, the controller.
Our Information Officer can be reached at info@veltrionlaboratories.com, marked for the attention of the Information Officer.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Business contact data | Name, job title, employer, business email, business telephone | You, your employer, professional networks, public sources |
| Engagement data | Correspondence, meeting notes, scoping information, mandate records | You and your organisation |
| Commercial data | Billing contact, purchase order and invoicing details | Your organisation |
| Technical data | Server request logs only. The site sets no cookies and runs no analytics script. See our Cookie Notice | Your device |
| Safety data | Information contained in an adverse event or product complaint report | Reporter. See Adverse Event Reporting |
We do not seek special personal information or children's information. Safety reports may unavoidably contain health information, which is handled under section 4 below.
4. Why we process it, and on what basis
| Purpose | POPIA justification | GDPR lawful basis |
|---|---|---|
| Responding to enquiries and scoping work | s.11(1)(b) performance of a contract, or steps prior to it | Art 6(1)(b) |
| Delivering a mandate | s.11(1)(b) | Art 6(1)(b) |
| Engaging delivery partners | s.11(1)(f) legitimate interests | Art 6(1)(f) |
| Business development to business contacts | s.11(1)(f) legitimate interests | Art 6(1)(f) |
| Meeting regulatory, safety and record-keeping obligations | s.11(1)(c) legal obligation | Art 6(1)(c), and Art 9(2)(i) for health data in safety reports |
| Site analytics | s.11(1)(f), aggregated and non-identifying | Art 6(1)(f) |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal.
5. Who we share it with
We share personal information only as necessary, with:
- Contracted delivery partners engaged for a specific market and product, under written confidentiality terms agreed before any client material is transferred.
- Regulatory authorities, where a submission, safety report or lawful request requires it.
- Professional advisers, including attorneys and accountants, under professional duties of confidence.
- Service providers, such as email, storage and scheduling platforms, under data processing terms.
We do not sell personal information, and we do not use client or portfolio information as a public reference without written consent.
6. Cross-border transfers
Our work is inherently cross-border. Personal information may be transferred to countries other than the one in which it was collected, including to regulatory authorities and delivery partners in African markets and to service providers outside South Africa.
Transfers are made in accordance with section 72 of POPIA and, where GDPR applies, Chapter V, relying on an adequacy decision, appropriate safeguards such as standard contractual clauses, or the necessity of the transfer for performance of a contract or for the establishment or defence of a legal claim.
7. How long we keep it
| Record type | Retention |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact |
| Mandate and engagement records | 7 years from conclusion, for statutory and professional record-keeping |
| Regulatory submission and safety records | As required by the applicable authority, which may exceed 10 years |
| Financial records | As required by South African tax and companies legislation |
8. Your rights
Subject to the conditions in the applicable law, you may:
- ask what personal information we hold about you, and request access to it;
- ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date or unlawfully obtained;
- object to processing based on legitimate interests;
- ask us to restrict processing, or request portability where GDPR applies;
- withdraw consent where processing relies on it;
- complain to a regulator.
To exercise a right, contact the Information Officer. We may need to verify your identity, and we will respond within the period required by law.
9. Complaints
If you are not satisfied with our response, you may complain to the Information Regulator (South Africa), or, where GDPR applies, to your local supervisory authority.
10. Security
We maintain reasonable technical and organisational safeguards appropriate to the sensitivity of the information. See Information Security and Data Handling. No system is perfectly secure, and we do not represent otherwise.
11. Changes
We may update this notice. The version in force is the one published here, with the effective date shown above.
Contact
Questions about this document should be directed to info@veltrionlaboratories.com, marked for the attention of the Information Officer.