Privacy Policy & POPIA Statement
Entity: Jay & Co Attorneys | Governing Law: Republic of South Africa | Effective Date: 2026
1. Statutory Commitment & Scope
Jay & Co Attorneys (trading as Jay & Co, "the Firm", "we", "our", or "us") operates as a multidisciplinary professional services and corporate legal advisory firm encompassing legal counsel, corporate governance consulting, executive leadership coaching, and professional legal education.
We are committed to safeguarding personal and corporate information in strict compliance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) ("POPIA"), the Promotion of Access to Information Act, 2000 (Act No. 2 of 2000) ("PAIA"), and international data protection standards. This policy governs all personal data collected through our website, online consultation forms, academy registration portals, and direct professional client mandates.
2. Information Officer & Designated Contact Particulars
In accordance with Section 55 and Section 56 of POPIA, the Firm has formally registered its Information Officer with the Information Regulator of South Africa. The Information Officer is responsible for ensuring compliance with conditions for lawful data processing, facilitating data subject requests, and liaising with statutory authorities.
3. Categories of Information Collected & Purpose of Processing
We collect and process personal and corporate information strictly to the extent necessary to fulfil our statutory obligations and provide specialised professional services across our divisions:
- Client Identification & Statutory Compliance: Full legal names, identity/passport numbers, company registration particulars, proof of residence, and related documentation required to perform statutory Know-Your-Customer (KYC) and Financial Intelligence Centre Act (FICA) verification.
- Legal & Advisory Mandates: Corporate commercial transaction documentation, governance records, board evaluations, contract drafting particulars, and dispute resolution briefs protected by attorney-client privilege.
- Executive Leadership & Coaching: Professional biographies, organizational development assessments, executive profiling, and workshop attendance records.
- Jay & Co Academy Enrolments: Candidate practitioner status, LPC examination session selections, academic history, firm affiliations, and assessment evaluation deliverables.
- Website & Digital Enquiries: Information voluntarily provided via our digital appointment and enquiry forms, including name, corporate email address, contact numbers, and subject-matter requirements.
4. Data Security, Retention & Storage Architecture
The Firm implements robust physical, technical, and organizational measures to prevent unauthorized access, loss, destruction, or damage to personal information. All electronic communications, form submissions, and database repositories are protected using enterprise-grade TLS 1.3 encryption in transit and AES-256 encryption at rest.
Personal data is retained only for the duration required to achieve the purpose for which it was originally collected, or as mandated by South African legislation (including the Legal Practice Act, Companies Act, and Tax Administration Act), after which it is securely shredded, anonymized, or permanently destroyed.
5. Rights of Data Subjects
Under Chapter 3 of POPIA, all individuals and juristic entities have fundamental rights regarding their personal information, including:
- The right to request confirmation of whether we hold personal information concerning you.
- The right to request access to the record or a description of the personal information held.
- The right to request the correction, amendment, or deletion of inaccurate, irrelevant, excessive, or outdated information.
- The right to object, on reasonable grounds, to the processing of personal data for direct marketing purposes.
- The right to submit a complaint to the Information Regulator (South Africa) at complaints.IR@justice.gov.za.
6. Cross-Border Data Transfers & Third Parties
Jay & Co does not sell, rent, or commercialise personal data to any external parties. Personal information is only disclosed to third-party service providers (such as accredited cloud infrastructure providers, statutory regulators, or financial institutions) who are bound by strict non-disclosure covenants and adhere to data protection standards equal to or exceeding Section 72 of POPIA.