Privacy Policy
1. Who is responsible for your information
[FULL LEGAL NAME AND LEGAL STATUS], trading as Fringe Studios, is the responsible party for the personal information it processes through this website and the resulting enquiry correspondence. Our business address is [BUSINESS ADDRESS].
This policy explains website visits and enquiries, including contact by email or telephone. If we begin a client engagement or collect information for another purpose, the relevant agreement and any additional privacy information will explain that processing.
For privacy questions, requests or suspected misuse of information, contact our Information Officer, [NAME], at [CONFIRMED PRIVACY EMAIL AND TELEPHONE]. General enquiries can be sent to hello@fringestudios.co.za.
2. Information we collect and why
| Information | Collection and purpose |
|---|---|
| Enquiry details | Information you provide: name, work email, company, optional phone number and any description of your problem or enquiry. We use it to understand your request, contact you and consider possible work together. |
| Correspondence | Email messages and information you share during follow-up conversations. We use these to continue the discussion and keep an appropriate record of it. |
| Connection and security information | IP address, browser/device and connection signals, the website being accessed, verification results and technical request information. Hosting and security services process this to deliver the site, distinguish legitimate visitors from bots and prevent abuse. |
| Temporary submission controls | A short-lived identifier derived from an IP address and a time window, an attempt count, a verification token and a submission identifier. These help limit repeated attempts and duplicate email delivery. The stored attempt counter does not contain your name, email or enquiry text. |
Our form currently requires your name, work email and company; phone number and enquiry text are optional. Without the required fields or successful security verification, the form cannot submit. You can use our direct email route instead. [CONFIRM WHETHER COMPANY SHOULD REMAIN REQUIRED; UPDATE THE FORM AND THIS SENTENCE TOGETHER]
Site security checks can process connection information when the page loads, even if you do not submit an enquiry. Automated checks may block or delay a form submission. The direct email route is available if you have difficulty using the form.
3. Grounds and limits for processing
We process enquiry information to respond to your request and, where applicable, take steps you request towards an engagement. We process technical information for our legitimate interests in operating and protecting the website, balanced against your privacy interests. A legal obligation or consent may apply to a particular activity where appropriate. [CONFIRM THE PURPOSES AND APPLICABLE LAWFUL GROUNDS AGAINST ACTUAL BUSINESS PRACTICE]
The website does not automatically add enquirers to a newsletter, advertising audience or customer relationship management system. Submitting an enquiry is not permission for unrelated promotional messages. [CONFIRM MANUAL FOLLOW-UP, MARKETING USE AND ANY SHARING OUTSIDE THE ENQUIRY TEAM]
4. Who receives information
Information is handled by the people and services needed for the relevant purpose:
- Authorised Fringe personnel: people responsible for receiving, considering and responding to enquiries. [CONFIRM STAFF ACCESS AND ANY FORWARDING]
- Website hosting and infrastructure services: services that deliver the site and process its contact form, including technical request and connection information.
- Site security and integrity services: services that check for bots, verify submissions and limit abuse. A security provider also processes technical signals for its own improvement of bot detection under its privacy notice.
- Email delivery and mailbox services: services that transmit the enquiry to our business inbox and store correspondence. The email delivery service receives the submitted contact details and enquiry text; your email address is used as the reply address.
- Professional advisers or authorities: where needed for a specific legal matter or lawful obligation. [CONFIRM ANY OTHER BUSINESS RECIPIENT CATEGORIES]
Service providers may use subprocessors to deliver their services. Provider arrangements and access must be appropriate to the information and purpose. [VERIFY APPLICABLE OPERATOR AGREEMENTS AND ACCESS CONTROLS] For the security provider's separate processing, see its site verification privacy notice.
5. Processing outside South Africa
Our hosting, security and email services operate internationally. Website connection information and enquiry information may therefore be processed outside South Africa.
The form's email delivery is configured to send from Ireland. The delivery service stores message content and delivery logs in the United States; selecting Ireland for sending does not make those records EU-resident. Hosting and security processing can also take place across a global network. [CONFIRM THE RECEIVING MAILBOX'S LOCATIONS AND ANY ADDITIONAL TRANSFERS]
[INSERT THE CONFIRMED POPIA SECTION 72 TRANSFER GROUND AND SAFEGUARDS, INCLUDING PROTECTION OF PERSONAL INFORMATION AND ONWARD TRANSFERS. DO NOT PUBLISH AN ADEQUACY GUARANTEE BEFORE REVIEWING THE ACTUAL ARRANGEMENTS.]
6. How long information is kept
Different records have different purposes and retention arrangements. The temporary form abuse counter is configured to expire 20 minutes after its last update. It is a limited security record; that expiry does not delete an enquiry email, provider logs or mailbox copies.
| Record category | Retention |
|---|---|
| Enquiries and follow-up correspondence | [APPROVED PERIOD OR CRITERIA, START POINT, REVIEW/DELETION PROCESS AND RESPONSIBLE PERSON] |
| Email delivery records and message copies | [CONFIRM ACCOUNT PLAN AND APPLICABLE PROVIDER RETENTION, INCLUDING BACKUPS AND ACCOUNT CLOSURE] |
| Business mailbox records and backups | [CONFIRM MAILBOX RETENTION, FORWARDING/COPIES AND BACKUP ARRANGEMENTS] |
| Hosting and security provider records | [CONFIRM APPLICABLE TECHNICAL LOG AND SECURITY RETENTION] |
Where an enquiry becomes an engagement, the applicable client-record arrangements also need to be explained. Records may need to be kept for a lawful obligation or an unresolved dispute. [CONFIRM THE BUSINESS RETENTION SCHEDULE AND HOW RECORDS ARE DELETED OR DE-IDENTIFIED]
7. Cookies, browser storage and tracking
No advertising, audience analytics, session replay or marketing tracking tools are installed on this website. The site's own code does not write cookies or use persistent browser storage. Our site security services still process technical signals to protect the website and its form; these checks are separate from audience tracking.
[COMPLETE A REAL-BROWSER COOKIE AND STORAGE INVENTORY ON THE FINAL DOMAIN, INCLUDING SECURITY SERVICES, THEN FINALISE ANY SECURITY-COOKIE/STORAGE DESCRIPTION AND APPLICABLE CHOICES. DO NOT CLAIM “NO COOKIES” FROM THE CODE CHECK ALONE.]
Open and click tracking are disabled for the form's enquiry emails. The website's fonts are served with the site rather than requested from an external font service.
8. Protecting information
The website uses HTTPS, server-side input validation, bot verification and limits on repeated submissions. Provider credentials are kept server-side. The application's logging does not record submitted form values, raw IP addresses or verification tokens. Hosting, security and email providers may separately keep technical or delivery records.
[CONFIRM INTERNAL MAILBOX ACCESS, STAFF PRACTICES, SUPPLIER CONTROLS AND SECURITY-INCIDENT RESPONSE ARRANGEMENTS] No online service can guarantee absolute security.
9. Your rights and complaints
You can ask about personal information we hold about you and request access or correction. You may request deletion, object to processing or withdraw consent where the relevant legal conditions apply. These rights do not require us to erase records we must lawfully retain.
Contact the Information Officer using the details above. We may need appropriate identity or authority evidence; we will explain a suitable way to provide it. Our PAIA manual sets out the access-to-records route.
You can also contact the Information Regulator: enquiries@inforegulator.org.za, telephone 010 023 5200. Its website provides the current complaint process and eServices portal.
10. Changes to this policy
We will update this policy if our collection, purposes or services change. The effective date identifies the published version. Any future introduction of analytics, marketing tools or new enquiry uses requires a review of the processing and visitor information before implementation.