Governance and policies

Privacy Notice

Effective 4 August 2026 Version 1.0 Applies to All personal information processed by Veltrion Owner Veltrion Laboratories (Pty) Ltd

1. Scope

This notice explains how Veltrion Laboratories (Pty) Ltd ("Veltrion") collects, uses, shares and protects personal information. It is written to meet the Protection of Personal Information Act 4 of 2013 ("POPIA") in South Africa and, where it applies to our processing, the EU and UK General Data Protection Regulation ("GDPR").

It covers personal information of prospective and current client contacts, delivery partners, suppliers, site visitors, applicants, and any individual who corresponds with us.

2. Who is responsible

Veltrion Laboratories (Pty) Ltd, registration number 2026/155300/07, Cape Town, South Africa, is the responsible party under POPIA and, where GDPR applies, the controller.

Our Information Officer can be reached at info@veltrionlaboratories.com, marked for the attention of the Information Officer.

3. What we collect

CategoryExamplesSource
Business contact dataName, job title, employer, business email, business telephoneYou, your employer, professional networks, public sources
Engagement dataCorrespondence, meeting notes, scoping information, mandate recordsYou and your organisation
Commercial dataBilling contact, purchase order and invoicing detailsYour organisation
Technical dataServer request logs only. The site sets no cookies and runs no analytics script. See our Cookie NoticeYour device
Safety dataInformation contained in an adverse event or product complaint reportReporter. See Adverse Event Reporting

We do not seek special personal information or children's information. Safety reports may unavoidably contain health information, which is handled under section 4 below.

4. Why we process it, and on what basis

PurposePOPIA justificationGDPR lawful basis
Responding to enquiries and scoping works.11(1)(b) performance of a contract, or steps prior to itArt 6(1)(b)
Delivering a mandates.11(1)(b)Art 6(1)(b)
Engaging delivery partnerss.11(1)(f) legitimate interestsArt 6(1)(f)
Business development to business contactss.11(1)(f) legitimate interestsArt 6(1)(f)
Meeting regulatory, safety and record-keeping obligationss.11(1)(c) legal obligationArt 6(1)(c), and Art 9(2)(i) for health data in safety reports
Site analyticss.11(1)(f), aggregated and non-identifyingArt 6(1)(f)

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal.

5. Who we share it with

We share personal information only as necessary, with:

  • Contracted delivery partners engaged for a specific market and product, under written confidentiality terms agreed before any client material is transferred.
  • Regulatory authorities, where a submission, safety report or lawful request requires it.
  • Professional advisers, including attorneys and accountants, under professional duties of confidence.
  • Service providers, such as email, storage and scheduling platforms, under data processing terms.

We do not sell personal information, and we do not use client or portfolio information as a public reference without written consent.

6. Cross-border transfers

Our work is inherently cross-border. Personal information may be transferred to countries other than the one in which it was collected, including to regulatory authorities and delivery partners in African markets and to service providers outside South Africa.

Transfers are made in accordance with section 72 of POPIA and, where GDPR applies, Chapter V, relying on an adequacy decision, appropriate safeguards such as standard contractual clauses, or the necessity of the transfer for performance of a contract or for the establishment or defence of a legal claim.

7. How long we keep it

Record typeRetention
Enquiries that do not become engagements24 months from last contact
Mandate and engagement records7 years from conclusion, for statutory and professional record-keeping
Regulatory submission and safety recordsAs required by the applicable authority, which may exceed 10 years
Financial recordsAs required by South African tax and companies legislation

8. Your rights

Subject to the conditions in the applicable law, you may:

  • ask what personal information we hold about you, and request access to it;
  • ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date or unlawfully obtained;
  • object to processing based on legitimate interests;
  • ask us to restrict processing, or request portability where GDPR applies;
  • withdraw consent where processing relies on it;
  • complain to a regulator.

To exercise a right, contact the Information Officer. We may need to verify your identity, and we will respond within the period required by law.

9. Complaints

If you are not satisfied with our response, you may complain to the Information Regulator (South Africa), or, where GDPR applies, to your local supervisory authority.

10. Security

We maintain reasonable technical and organisational safeguards appropriate to the sensitivity of the information. See Information Security and Data Handling. No system is perfectly secure, and we do not represent otherwise.

11. Changes

We may update this notice. The version in force is the one published here, with the effective date shown above.

Contact

Questions about this document should be directed to info@veltrionlaboratories.com, marked for the attention of the Information Officer.