1. Overview
Privacy compliance for a telematics business involves both website interactions and operational processing of location, vehicle, driver and account data. Cellstop’s primary legal framework is PoPIA, because we are established and primarily operate in the Republic of South Africa. Where GDPR applies (for example to certain EU/UK data subjects or processing activities), we apply GDPR principles alongside PoPIA.
This page is a compliance summary. Detailed processing notices are set out in our Privacy Policy, Cookie Policy and Terms of Use.
2. Who we are
Cellstop Fleet Tracking (Pty) Ltd is a private company registered with the Companies and Intellectual Property Commission (CIPC). We are licensed by Cellstop International (CIL) to provide Cellstop-branded tracking services in our licensed territory.
- Address: 33 Bell Crescent, Westlake, Cape Town, 7945
- Email: sales@cellstop.org
- Call centre: 08600 27867
- Sales: +27 21 001 3710
Our Information Officer may be contacted through these channels. Please mark privacy requests “For the attention of the Information Officer”.
3. PoPI Act (PoPIA) compliance posture
Under PoPIA we aim to process personal information lawfully and reasonably, in a manner that does not infringe the privacy of data subjects. Our operational approach includes:
- Accountability: defining responsibilities for personal information, including engagement of our Information Officer;
- Processing limitation: collecting information for specific, explicitly defined and lawful purposes related to enquiries, contracts and tracking services;
- Purpose specification and further processing: using information compatibly with the purpose for which it was collected;
- Information quality: taking reasonable steps to keep information complete, accurate and not misleading;
- Openness: publishing privacy information and responding to access requests;
- Security safeguards: implementing appropriate technical and organisational measures; and
- Data subject participation: enabling access, correction and related rights as provided by PoPIA.
Where we process personal information as an operator for a customer who is the responsible party (for example fleet telematics relating to that customer’s drivers), we process under that customer’s instructions and applicable agreements, consistent with PoPIA sections 20 and 21.
Cross-border transfers are handled in accordance with PoPIA section 72 where applicable.
4. GDPR (where applicable)
GDPR may apply when we process personal data of individuals in the EEA or United Kingdom, or in other circumstances where GDPR has extraterritorial effect. Where GDPR applies, we rely on appropriate Article 6 lawful bases (contract, legitimate interests, legal obligation or consent, as relevant) and, for special category data, an applicable Article 9 condition.
We support GDPR data subject rights where they apply (including access, rectification, erasure, restriction, portability and objection) and use appropriate transfer safeguards under Chapter V GDPR / UK GDPR for restricted international transfers.
PoPIA remains the primary framework for our South African operations; GDPR overlays apply where legally required.
5. Responsible party and operator roles
- Website and Cellstop marketing: Cellstop is typically the responsible party (controller) for enquiry and marketing data we collect through our public website.
- Customer telematics: the customer is generally the responsible party for driver, employee and operational fleet data; Cellstop acts as operator (processor) on documented instructions.
- White Label / Reseller: roles may be allocated in the partner agreement; partners must provide appropriate notices to their own customers and end users.
6. Telematics and location data
Vehicle and asset tracking necessarily involves location, trip, event and related operational data. Where that data relates to an identifiable person (for example a driver), it is personal information under PoPIA and may be personal data under GDPR.
Customers who deploy Cellstop services for workforce or fleet monitoring remain responsible for ensuring they have a lawful basis, workplace policies and notices for their data subjects. Cellstop provides tools and operator processing under contract; we do not replace the customer’s own compliance obligations as responsible party.
7. Security and incident response
We implement reasonable technical and organisational measures appropriate to the nature of telematics and account data. Measures may include access control, authentication, secure hosting postures, operational procedures and contractual controls with operators.
If a security compromise affecting personal information occurs, we will notify the Information Regulator and affected data subjects as required by PoPIA, and take other steps required by applicable law (including GDPR breach notification where it applies).
8. Exercising your rights and complaints
To exercise PoPIA or GDPR rights, contact us using the details above and address your request to the Information Officer. We may verify identity and authority before responding. Where Cellstop is only an operator, we may refer your request to the relevant customer responsible party.
You may lodge a complaint with the Information Regulator (South Africa):
- Website: https://inforegulator.org.za/
- Email: enquiries@inforegulator.org.za / POPIAComplaints@inforegulator.org.za
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Where GDPR applies, you may also complain to your local EEA supervisory authority or the UK Information Commissioner’s Office.
9. Related legal documents
- Privacy Policy — full processing notice
- Cookie Policy — cookies and similar technologies
- Terms of Use — website terms
10. Contact and updates
We may update this page when our practices or legal requirements change. The “Last updated” date shows when this version took effect.
For privacy or compliance questions: sales@cellstop.org.
This page summarises our compliance posture for transparency. It does not constitute legal advice and does not create warranties beyond those in applicable contracts and mandatory law. Recommend review by your attorney or Information Officer for organisation-specific obligations.