Legal
Themis Legal Consulting - Privacy Policy
Website and business privacy policy
Status
This document is reproduced from the text supplied by Themis Legal Consulting and is for legal review before publication. It has not been amended, summarised or interpreted.
Effective 25 August 2026
1Who We Are
1.1This Privacy Policy explains how Themis Legal Consulting Proprietary Limited (“Themis”, “we”, “us” or “our”) collects, receives, records, organises, stores, updates, uses, disseminates, transfers, secures, retains and otherwise processes personal information in connection with our website, enquiries, prospective engagements, professional services and ordinary business operations.
1.2This Policy must be read together with our POPIA Information Notice, PAIA Manual, Website Terms of Service and Legal Disclaimer. Where a specific engagement letter, service agreement, confidentiality undertaking or other written agreement regulates the processing of information in a particular matter, that agreement applies in addition to this Policy and prevails to the extent of a direct inconsistency concerning that engagement.
1.3Themis Legal Consulting Proprietary Limited is a South African commercial and corporate legal consultancy, registration number 2022/730552/07, with its registered office and principal place of business at 585 Alendale Street, Elarduspark, Pretoria, Gauteng, 0181. Themis is not a firm of attorneys or an attorneys’ practice. We do not operate an attorneys’ trust account, hold client money in trust, conduct litigation or provide services reserved by law for practising legal practitioners where the applicable statutory requirements have not been met.
1.4Our primary contact address for privacy-related communications is info@themislegal.co.za. The contact particulars of the Information Officer are set out in our POPIA Information Notice and PAIA Manual.
2Scope
2.1This Policy applies to personal information processed by or on behalf of Themis relating to website visitors, persons submitting enquiries, prospective and existing clients, representatives and personnel of clients and counterparties, suppliers and service providers, professional advisers, job applicants (where applicable), business contacts, and any other person whose personal information is lawfully processed in the course of our operations.
2.2The Policy applies irrespective of whether information is obtained through the website, email, telephone, electronic messaging, documents supplied to us, meetings, third-party platforms, public records or another lawful source.
3Personal Information We May Process
3.1Depending on the nature of the interaction, we may process the following categories of information:
3.1.1identity and contact information, including names, surnames, identity or registration details where reasonably required, email addresses, telephone numbers, addresses and preferred contact methods;
3.1.2business and professional information, including company name, position, role, authority, business contact details and information concerning an organisation’s operations;
3.1.3enquiry and matter information, including the type of assistance required, a description of the matter, urgency or required timeframe, instructions, correspondence, supporting documents and files uploaded or otherwise supplied to us;
3.1.4contractual and commercial information, including agreements, transaction information, governance records, policies, risk information, financial or operational information relevant to an instruction, and information concerning counterparties;
3.1.5billing and administrative information, including invoicing details, payment confirmations and transaction references, but not client funds held in trust;
3.1.6technical and usage information generated when the website is used, such as IP address, browser type, device information, operating system, referring pages, date and time information, page interactions, diagnostic information and cookies or similar technologies where enabled;
3.1.7communications and records of interactions with us, including emails, telephone notes, meeting notes, live-chat content and other correspondence;
3.1.8information obtained from lawful public sources, regulators, company registries, counterparties, professional advisers or other persons where relevant to a legitimate instruction; and
3.1.9special personal information or information relating to children only where it is necessary, lawful and proportionate for a specific legitimate purpose and an appropriate legal basis exists.
4How Information Is Collected
4.1We may collect information directly from you when you browse the website, complete the enquiry form, upload a file, contact us, request a proposal, instruct us, conclude an agreement, attend a meeting or otherwise interact with Themis.
4.2The website enquiry form is intended to request only the information reasonably necessary to understand and respond to an initial enquiry. It may request first name, last name, company, email address, telephone number, type of assistance required, a brief description of the matter, preferred contact method, urgency or required timeframe, an optional or required file upload as configured, and acknowledgement of the applicable privacy/POPIA notice.
4.3We may also receive information indirectly from your employer or organisation, a colleague, a counterparty, an adviser, a referral source, a service provider, a public registry or another lawful source. Where reasonably practicable and required by law, we will take appropriate steps to ensure that the data subject is informed of the processing.
5Purposes of Processing
5.1Themis processes personal information only for identified, lawful and reasonably necessary purposes, which may include:
5.1.1operating, administering, securing, maintaining and improving the website and associated systems;
5.1.2receiving, assessing, acknowledging, allocating and responding to enquiries;
5.1.3conducting preliminary conflict, capacity, scope, risk or suitability assessments before accepting an engagement;
5.1.4preparing proposals, scopes of work, fee arrangements and engagement terms;
5.1.5providing commercial and corporate legal consulting services after an engagement has been properly established;
5.1.6drafting, reviewing, negotiating and administering agreements and related records;
5.1.7providing corporate advisory, governance, compliance, commercial risk and outsourced legal support;
5.1.8communicating with clients, prospective clients, counterparties, service providers and professional advisers;
5.1.9performing contractual obligations, exercising contractual rights and administering client or supplier relationships;
5.1.10maintaining internal matter, business, financial, governance, compliance and audit records;
5.1.11issuing invoices, processing payments made to Themis for its own account, collecting amounts lawfully due and complying with tax and accounting obligations;
5.1.12preventing, detecting, investigating and responding to fraud, misuse, security incidents, unlawful activity, complaints and legal claims;
5.1.13complying with applicable law, lawful regulatory requirements, court orders and other binding legal processes;
5.1.14establishing, exercising or defending legal rights or claims;
5.1.15conducting reasonable business analytics, service improvement and website performance analysis using information appropriate to that purpose; and
5.1.16sending business or service communications and, where lawfully permitted, direct marketing, subject to applicable consent and opt-out requirements.
6Lawful Basis and Processing Limitation
6.1We process personal information in accordance with applicable South African law, including the Protection of Personal Information Act 4 of 2013 (“POPIA”). Depending on the circumstances, processing may be justified because the data subject has consented; processing is necessary to carry out actions for the conclusion or performance of a contract; processing complies with an obligation imposed by law; processing protects a legitimate interest of the data subject; processing is necessary for the proper performance of a public-law duty by a public body; or processing is necessary for pursuing the legitimate interests of Themis or a third party to whom information is supplied, subject always to applicable legal limitations.
6.2Consent is not relied upon where another lawful basis properly applies. Where processing is based on consent, consent may generally be withdrawn prospectively, but withdrawal does not invalidate processing that was lawful before withdrawal and may affect our ability to provide a requested service.
7Voluntary and Mandatory Information
7.1Information requested through a general website enquiry is ordinarily supplied voluntarily. Certain information may, however, become necessary to respond meaningfully, assess whether we can accept an engagement, comply with law, conclude or perform an agreement, verify authority, invoice a client or protect legitimate interests. If information that is reasonably necessary is not provided, Themis may be unable to respond fully, accept an instruction or provide the requested service.
8Disclosure and Recipients
8.1Themis does not sell personal information. We may disclose personal information only where reasonably necessary and lawful, including to:
8.1.1our personnel, consultants or authorised representatives who require access for legitimate business purposes and are subject to appropriate confidentiality obligations;
8.1.2technology, website, hosting, cloud, email, cybersecurity, document management, accounting, payment, telecommunications and other service providers acting under appropriate contractual or legal safeguards;
8.1.3professional advisers, auditors, insurers, consultants and specialist service providers where their involvement is reasonably required;
8.1.4a client, prospective client, counterparty or its advisers where disclosure is necessary for a lawful instruction and is consistent with confidentiality obligations;
8.1.5regulators, public bodies, courts, law-enforcement agencies or other competent authorities where disclosure is required or permitted by law;
8.1.6persons involved in a proposed or actual restructuring, sale, transfer or other transaction affecting all or part of our business, subject to appropriate confidentiality and legal safeguards; and
8.1.7any other recipient where the data subject has validly consented or disclosure is otherwise permitted by law.
8.2A website enquiry, and particularly an uploaded document, should not contain information that is irrelevant, excessive or unnecessarily sensitive. Before a formal engagement is accepted, you should avoid sending original documents, passwords, privileged third-party material that you are not authorised to disclose, or highly sensitive information unless we have specifically requested it and an appropriate transmission method has been agreed.
9Operators and Service Providers
9.1Where another person processes personal information for Themis as an operator, we will take reasonably appropriate steps to ensure that the operator processes the information only with our knowledge or authorisation, treats it as confidential and implements appropriate security measures as required by law and contract. We remain entitled to use reputable third-party technology infrastructure where this is reasonably necessary for our operations.
10Cross-Border Transfers
10.1Some service providers, cloud platforms or technical infrastructure may process or store information outside South Africa. Where personal information is transferred to a foreign country, Themis will take reasonable steps to ensure that the transfer is permitted under POPIA, including where the recipient is subject to a law, binding corporate rules or binding agreement providing an adequate level of protection; the data subject consents where consent is an appropriate basis; the transfer is necessary for performance of a contract or implementation of pre-contractual measures; or another statutory basis applies.
11Security Safeguards
11.1Themis applies reasonable technical and organisational measures appropriate to the nature of the information and the reasonably foreseeable risks. These measures may include access controls, password and authentication controls, device and account security, secure cloud services, anti-malware measures, backups, restricted permissions, confidentiality obligations, secure disposal practices and incident-response procedures.
11.2No website, email system, cloud service or internet transmission can be guaranteed to be completely secure. Accordingly, while we take reasonable measures to protect information, we cannot warrant absolute security and users remain responsible for taking reasonable precautions when transmitting information electronically.
12Security Compromises
12.1Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, Themis will assess the incident and, where required by POPIA, notify the Information Regulator and affected data subjects as soon as reasonably possible, subject to any lawful delay or restriction. Notifications may describe the possible consequences, measures taken or intended, recommendations for mitigating potential adverse effects and, where known, the identity of the unauthorised person.
13Retention and Destruction
13.1We retain personal information only for as long as its retention is reasonably necessary or authorised for the purpose for which it was collected, required by law, reasonably required for lawful business, tax, accounting, evidentiary, contractual, insurance, risk-management or dispute purposes, or agreed with the data subject where appropriate.
13.2When information is no longer required and no lawful basis for continued retention exists, we will take reasonable steps to destroy, delete or de-identify it in a manner that prevents reconstruction in an intelligible form, subject to backup cycles and technical limitations reasonably inherent in secure systems.
14Information Quality
14.1We take reasonably practicable steps to ensure that personal information is complete, accurate, not misleading and updated where necessary, having regard to the purpose for which it is processed. Data subjects should inform us if material information changes or if they reasonably believe information held by us is inaccurate.
15Your Rights
15.1Subject to POPIA, PAIA and other applicable law, a data subject may have the right to request confirmation of whether Themis holds personal information about them; request access to a record or description of that information; request correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading or unlawfully obtained information; request destruction or deletion of information that Themis is no longer authorised to retain; object to certain processing on reasonable grounds; object to direct marketing; withdraw consent where consent is relied upon; and lodge a complaint with the Information Regulator.
15.2Rights are not absolute. Themis may refuse, limit, defer or condition a request where permitted or required by law, including to protect legal privilege, confidentiality, the rights of third parties, security, legally protected records, legitimate retention requirements or other statutory grounds.
16Direct Marketing
16.1Themis will conduct electronic direct marketing in accordance with POPIA and other applicable law. Where prior consent is legally required, we will seek it before sending unsolicited electronic marketing. Where marketing is lawfully sent to an existing client or another permitted recipient, each communication will provide a reasonably practicable opportunity to object or unsubscribe. Service, transactional, regulatory or engagement-related communications are not marketing merely because they are sent electronically.
17Cookies, Analytics and Similar Technologies
17.1The website may use strictly necessary, functional, performance, analytics or similar technologies to operate the site, maintain security, remember preferences, understand website usage and improve performance. Where non-essential cookies or tracking technologies require consent under applicable law or platform settings, they should be activated only in accordance with the applicable consent mechanism.
17.2Third-party services may set their own cookies or process technical information when integrated into the website. Their processing may also be governed by their own privacy terms. Themis will endeavour to configure integrations proportionately but does not control the independent processing activities of third-party platforms acting as responsible parties in their own right.
18Third-Party Links and Platforms
18.1The website may link to third-party websites or social-media platforms. Themis is not responsible for the privacy, security, availability or content practices of third parties. Users should review the applicable third-party privacy terms before providing information to them.
19Children and Special Personal Information
19.1The website and Themis’s commercial legal consulting services are not directed primarily at children. Users should not submit children’s personal information or special personal information through a general enquiry unless it is genuinely necessary and lawful. Where Themis must process such information for a legitimate instruction, it will do so only on an appropriate statutory basis and subject to proportionate safeguards.
20Changes to this Policy
20.1We may amend this Policy from time to time to reflect legal, regulatory, operational, technological or service changes. The current version will be published on the website with its effective or last-updated date. Material changes may be communicated by additional reasonable means where appropriate.
21Contact and Complaints
21.1Privacy requests and questions may be directed to the Information Officer at info@themislegal.co.za, marked for the attention of the Information Officer. A data subject may also lodge a complaint with the Information Regulator (South Africa) using the Regulator’s official channels. The current official contact and prescribed-form information should be obtained from the Information Regulator’s website.
22Interpretation
22.1In this Policy, headings are for convenience only and do not affect interpretation; the singular includes the plural and vice versa; a reference to a person includes a natural or juristic person; the words “include”, “includes” and “including” are not words of limitation; and a reference to any statute includes that statute as amended, re-enacted or replaced from time to time.
23Limitation of Liability
23.1To the maximum extent permitted by law, Themis’s liability arising from or in connection with the processing of personal information under this Policy is limited to loss directly caused by Themis’s own unlawful conduct, and excludes indirect, incidental, special, punitive or consequential loss of any kind, including loss of profit, revenue, business opportunity, goodwill or data. This Policy does not create, extend or replace any liability regime separately agreed in a written professional engagement, and nothing in this Policy constitutes an admission of liability or broadens any liability that would not otherwise arise under POPIA or other applicable law.
24Severability
24.1If any provision of this Policy is found by a competent authority or court to be invalid, unlawful or unenforceable, that provision will be severed to the minimum extent necessary and the remaining provisions will continue in full force and effect.
25Governing Law
25.1This Policy is governed by the laws of the Republic of South Africa. Any dispute concerning this Policy that is not resolved through the Information Regulator’s statutory processes is subject to the jurisdiction of the South African courts, without prejudice to any statutory remedy available to a data subject.
Related documents
Questions about these documents may be sent to info@themislegal.co.za.