Skip to content
Handee

Privacy policy

How we collect, use and protect personal information: on this website, in our work with clients and inside the connected products we build.

  • Effective 6 October 2026
  • POPIA notice

Handee IoT designs and builds connected products: devices, firmware, cloud platforms and the web and mobile apps on top. This policy explains how we handle personal information on this website, in our work with clients and suppliers, and inside the products we build and run. It is our notice under section 18 of the Protection of Personal Information Act 4 of 2013 (POPIA). We have kept it plain. If anything is unclear, email us at hello@handee.co.za.

1. Who we are

The responsible party is Handee (Pty) Ltd, registration number 2020/272422/07, trading as Handee IoT ("Handee", "we", "us"), a South African company. We are a remote team; our registered address is available on request.

Our Information Officer can be reached at hello@handee.co.za.

2. Who this policy covers

  • Visitors and enquirers. People who use this website or send us a brief.
  • Clients, partners and suppliers. The people we deal with at the businesses we work with, including co-creation partners.
  • Applicants. People who apply to work with us as employees or contractors.
  • People who use products we build. Users of the devices, platforms and apps we build or run for our clients. Section 6 explains how that works.

3. What we collect

We collect only what we need, and mostly what you choose to give us:

  • Enquiry details. When you fill in a form on this site: your name, email address and phone number, and optionally your company, what you need, your project stage and timeline, and your message. We also record which page you sent it from and how you found the site (see section 11).
  • Marketing preference. Whether you ticked the box to receive occasional Handee insights by email.
  • Business contact details. For clients, partners and suppliers: names, roles, work email addresses and phone numbers, and the contract, billing and payment details we need to work together.
  • Correspondence and meetings. What you send us by email, phone or WhatsApp, and notes from our calls. We do not record a call without telling everyone on it first.
  • Applications. Your CV, work history, portfolio and references, if you apply to work with us.
  • Technical data. Our hosting providers keep standard server logs, such as IP address, browser type and the pages requested, to run and secure the site.
  • Usage data. How visitors use this site, such as the pages viewed, how they arrived and the type of device, collected through Google Analytics, and whether a visit came from one of our Google Ads (see section 11).

Please do not send us special personal information, such as health information, or information about children through our forms.

4. Why we use it, and on what basis

  • To reply to your enquiry and discuss a possible project, because you asked us to and it is a step towards a contract (section 11(1)(b)), and in our legitimate interest in responding to business enquiries (section 11(1)(f)).
  • To prepare proposals, deliver projects, invoice and support the products we build, to perform our contract with you (section 11(1)(b)).
  • To keep business, tax and accounting records, because the law requires it (section 11(1)(c)).
  • To consider an application to work with us, at your request (section 11(1)(b)).
  • To send you occasional insights by email, only with your consent (sections 11(1)(a) and 69).
  • To keep this website and our systems secure and working, in our legitimate interest (section 11(1)(f)).

5. Is it voluntary?

Yes. Your name, email address and a short message are needed for us to reply to an enquiry, and contract and billing details are needed to work together. Without them we cannot respond to you or take on the work. You can always phone us instead of using a form.

6. Personal information inside the products we build

When we build or run a connected product for a client, the client decides what personal information the product handles and why. Under POPIA the client is the responsible party, and Handee is its operator. Our contracts require us to:

  • process that information only on the client's instructions and only to deliver and support the product;
  • keep it confidential, and give access only to the engineers who need it;
  • apply appropriate security safeguards, as sections 19 to 21 require;
  • tell the client without delay if we believe the information has been accessed or acquired without authorisation.

Much of what a connected device reports is not personal: a tank level, a meter reading, a camera's health. Where a reading can be linked to a person, such as the prepaid meter of a particular home or a number plate read at a parking boom, we treat it as personal information. We design for that from the start: we collect only what the product needs, encrypt data in transit, limit access by role and keep data only as long as the client's retention rules allow.

If you use a product we built for someone else and have a question about your information, contact the business that provides the product. We will help them respond.

7. Who we share it with

We do not sell or rent personal information. We share it only with:

  • Service providers who act as our operators: cloud hosting, website analytics and advertising (Google Analytics and Google Ads), email and productivity tools, our client records system and our accounting software, under written agreements that require them to keep it confidential and secure;
  • Professional advisers, such as our auditors and lawyers, who are bound to confidentiality;
  • Authorities, where the law requires it.

8. Transfers outside South Africa

Some of our service providers store data outside South Africa. When personal information is transferred, we make sure the recipient is bound by law, binding corporate rules or an agreement that gives it protection substantially similar to POPIA, as section 72 requires. For client products, where data is hosted is agreed with the client.

9. How we protect it

We take appropriate technical and organisational measures to prevent loss, damage or unauthorised access: encrypted connections, access limited to the people who need it, strong authentication on our systems, and the same secure engineering practices we build into client products. If we believe personal information has been compromised, we will notify the Information Regulator and the people affected, as section 22 requires.

10. How long we keep it

  • Enquiries that do not lead to a project are deleted after 24 months.
  • Client, supplier and contract records are kept for the life of the relationship and then for as long as tax and company law require, generally five years.
  • Applications are kept for 12 months unless you ask us to delete them sooner, or you join us.
  • If you opt out of marketing, we keep a record of that so we do not contact you again.

11. Cookies and analytics

This website uses Google Analytics to understand how it is used: which pages are visited, how people arrive (for example from a search or a link), roughly which country or city they are in, and what kind of device and browser they use. Google Analytics sets cookies in your browser to tell visits apart. It does not give us your name or contact details, and Google Analytics does not store IP addresses.

We also advertise on Google Ads, and our Google Analytics account is linked to it so we can see which ads lead to visits and enquiries. For that, Google may set advertising cookies when you arrive from one of our ads. We do not use your information for personalised advertising or remarketing, and we do not use analytics to track you across other sites.

Google processes this information for us, on servers that may be outside South Africa (see section 8).

This website also sets one cookie of its own that remembers how you first found us and how you most recently arrived (for example the link, search or ad you came from), for 90 days. It is only read if you send us an enquiry, when it is stored with your enquiry in our client records so we know which of our work and advertising reaches people.

You can stop it at any time by blocking cookies in your browser settings, or with Google's opt-out add-on at tools.google.com/dlpage/gaoptout.

12. Direct marketing

We only send marketing emails to people who have opted in, or to clients about services similar to those they have used with us. Every email includes a way to unsubscribe, and you can opt out at any time by emailing hello@handee.co.za.

13. Your rights

Under POPIA you have the right to:

  • ask whether we hold personal information about you, and to see it;
  • ask us to correct or delete information that is inaccurate, out of date, excessive or unlawfully held;
  • object to us processing your information, including for direct marketing;
  • withdraw your consent at any time, where we rely on it;
  • complain to the Information Regulator.

To use any of these rights, email hello@handee.co.za. We may need to confirm your identity first. There is no charge. Our manual under the Promotion of Access to Information Act (PAIA) is available on request.

14. Complaints

If you are unhappy with how we have handled your information, please tell us first so we can put it right. You may also complain to the Information Regulator (South Africa):

15. Changes to this policy

We may update this policy from time to time. The effective date at the top shows when it last changed.

Questions?

Talk to a person

Talk to a person

Questions about your data, or about a project? Send us a message and we'll reply.

  • A new connected product
  • Firmware & embedded
  • Web or mobile app
  • Device management
  • Monitoring & dashboards
  • A co-creation venture
  • Not sure yet
  • Just an idea
  • Have hardware
  • Prototype exists
  • Live and scaling
  • Rescuing a product
  • As soon as possible
  • In the next 3 months
  • In 3 to 6 months
  • Just exploring

We use these details only to reply to your enquiry. See our privacy policy.