Privacy Policy

Business name: Ndipheleke – Take Me Home (“Ndipheleke”, “we”, “us”)
Website: ndipheleke.co.za
Email: info@ndipheleke.co.za
Physical address: 9 Watt Street, Industrial Area, Daljosafat, Paarl, 7646, South Africa
Effective date: 22 December 2025

This Privacy Policy explains how we collect, use, share, store, and protect personal information when you visit our website, contact us, request a quote, or use our funeral transport, repatriation, and undertaker support services.

Note: This policy is a general privacy notice. It’s not a substitute for tailored legal advice for your exact tech stack (hosting, forms, analytics, payments, WhatsApp, etc.).


1) Who is responsible for your personal information?

For purposes of the Protection of Personal Information Act, 2013 (“POPIA”), we are the Responsible Party. For purposes of the EU/UK General Data Protection Regulation (“GDPR”), we are the Data Controller.

POPIA Information Officer: The head of Ndipheleke (or designated person)
Contact: info@ndipheleke.co.za


2) When does this policy apply?

It applies when you:

  • visit our website;
  • call, email, message, or submit a form to us;
  • request quotes or book funeral transport/repatriation services;
  • engage us as an undertaker support provider;
  • interact with our marketing (if any), social media pages, or adverts.

3) What personal information we collect

We may collect the following categories (depending on your interaction with us):

A. Information you provide

  • Identity & contact details: name, surname, phone number, email address, relationship to the deceased (e.g., next of kin), organisation/undertaker details.
  • Service and logistics details: collection and destination addresses, dates/times, travel and routing needs, next-of-kin instructions, authorisations.
  • Documentation and compliance details: copies/details from documents that may include personal information of living persons (e.g., next-of-kin IDs, permits, airline details, letters of authority).
  • Billing details: invoice details, payment confirmations, VAT/tax information (where applicable).

B. Information we collect automatically (website)

  • Technical data: IP address, device type, browser, pages visited, approximate location, referral source, and similar usage data (via server logs and/or analytics).
  • Cookies and similar technologies: see Section 10.

C. Special categories / “special personal information”

Our industry can involve sensitive contexts. Depending on the situation, information shared with us may include:

  • health/medical-related information contained in official documentation (where relevant);
  • religious/cultural preferences for service arrangements (if you share them);
  • biometric/ID numbers contained in copies of identity documents (if you provide them).

We only process such information when necessary for providing services, meeting legal requirements, or with your consent (see Section 5).

Important: POPIA primarily protects information of living persons. However, many funeral-related documents include personal information of living relatives/representatives, and we protect that information accordingly.


4) Why we process personal information

We process personal information for purposes including:

  • providing quotes and arranging bookings;
  • delivering funeral transport, repatriation, and undertaker support services;
  • communicating with families, undertakers, and relevant third parties about logistics;
  • meeting legal, regulatory, and safety requirements (e.g., permits, audit trails, tax/accounting);
  • preventing fraud, securing our systems, and managing operational risk;
  • customer service, dispute handling, and quality improvement;
  • sending service-related notices (and marketing only where lawful—see Section 9).

5) Lawful bases for processing (POPIA + GDPR)

We only process personal information when a lawful basis applies, including:

  • Contract / taking steps to contract: to provide services you request (quotes, bookings, transport coordination).
  • Legal obligation: to meet legal and regulatory duties (e.g., recordkeeping, tax/accounting, compliance with applicable transport or documentation rules).
  • Legitimate interests: to run our business, keep systems secure, prevent fraud, and improve services—balanced against your rights.
  • Consent: where required (e.g., certain marketing, or when you provide sensitive information not strictly needed).
  • Vital interests: in rare urgent situations where processing is necessary to protect someone’s life or safety.

GDPR transparency expectations for what controllers must tell you (including purposes, legal bases, retention, rights, etc.) are reflected throughout this notice.


6) Who we share personal information with

We may share personal information only as needed and with appropriate safeguards, including with:

  • Families / authorised representatives and undertakers involved in the service;
  • Transport and logistics providers (e.g., drivers, vehicle operators, shipping/air cargo/airlines, courier services);
  • Accommodation or coordination partners if required for repatriation logistics;
  • Regulators, government departments, or law enforcement where required by law or lawful request;
  • Professional advisers (accountants, auditors, legal advisers) under confidentiality duties;
  • IT and hosting providers (website hosting, email providers, cloud storage, security services);
  • Payment and banking providers (if and when payments are processed through third parties).

We do not sell personal information.


7) International transfers (including repatriation contexts)

Because repatriation can be cross-border, personal information may be transferred to or accessed from other countries, for example by:

  • airlines/cargo handlers and their agents,
  • foreign authorities or counterpart service providers (as needed for documentation/logistics),
  • cloud/IT providers whose servers may be outside South Africa.

Where information is transferred internationally, we take reasonable steps to ensure appropriate protection, including contractual safeguards and limiting transfers to what is necessary.


8) How long we keep personal information (retention)

We keep personal information only for as long as necessary for the purposes described above, unless a longer period is required or permitted by law.

Typical retention periods (guideline):

  • Quotes and enquiries not converted to bookings: up to 12 months
  • Service and logistics records (bookings, job cards, delivery confirmations): typically 3–5 years
  • Accounting and tax records (invoices, receipts): typically 5 years (or longer if legally required)
  • Security logs and access records: typically 6–12 months (unless needed for investigation)

We may keep information longer if needed to resolve disputes, enforce agreements, or comply with lawful requests.


9) Direct marketing

We may send marketing communications only where lawful and appropriate (for example, where you consented or where an existing customer relationship permits it under applicable rules).

You can opt out at any time by:

  • clicking an unsubscribe link (if provided), or
  • emailing info@ndipheleke.co.za with “Opt-out” in the subject.

10) Cookies and analytics

Our website may use:

  • Essential cookies needed for the website to function.
  • Preference cookies (e.g., language or session settings), if enabled.
  • Analytics cookies (e.g., traffic measurement) if configured on the site.

You can control cookies through your browser settings. If you disable certain cookies, some site features may not work properly.

(If you use Google Analytics, Meta Pixel, or similar tools, you should list them here explicitly and link to their opt-out mechanisms.)


11) Your rights (POPIA and GDPR)

Under POPIA (South Africa)

Subject to POPIA conditions and exceptions, you may request:

  • access to your personal information;
  • correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained;
  • objection to processing in certain circumstances (including direct marketing);
  • withdrawal of consent where processing is based on consent.

You may lodge a complaint with the Information Regulator (South Africa), including via their POPIA complaints channel.

Under GDPR (EEA/UK, where applicable)

If GDPR applies to the processing, you may have rights to:

  • access, rectification, erasure;
  • restriction and objection;
  • data portability (in certain cases);
  • withdraw consent (where consent is the basis);
  • lodge a complaint with your local supervisory authority.

12) Security safeguards

We use reasonable technical and organisational measures to protect personal information, which may include:

  • access controls and least-privilege permissions;
  • staff confidentiality and training where relevant;
  • secure storage, backups, and malware protection;
  • encryption in transit where supported (HTTPS/TLS);
  • incident monitoring and response processes.

No method of transmission or storage is 100% secure, but we work to maintain appropriate safeguards for the sensitivity of the information we handle.


13) Data breaches (security compromises)

If there is a security compromise involving personal information, we will take steps to investigate, mitigate harm, and notify affected people and/or regulators where required.

  • POPIA: notification must be made as soon as reasonably possible after discovering the compromise (subject to certain allowances).
  • GDPR (where applicable): controllers must generally notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless it is unlikely to result in risk to individuals.

14) Children’s information

Our services are intended for adults (families, authorised representatives, and undertakers). If we ever need to process a child’s personal information, we will do so only where lawful and with appropriate consent/authorisation.


15) Third-party links

Our website may contain links to third-party websites or platforms (e.g., social media). We are not responsible for their privacy practices. Please review their privacy notices before providing them with your personal information.


16) Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on our website with a revised “Effective date”. Material changes will be highlighted where reasonable.


17) How to contact us

For privacy questions, access requests, corrections, objections, or complaints, contact:

Ndipheleke – Take Me Home
Email: info@ndipheleke.co.za
Address: 9 Watt Street, Industrial Area, Daljosafat, Paarl, 7646, South Africa