1. Who we are
The responsible party for this Privacy Policy is Cellstop Fleet Tracking (Pty) Ltd (“Cellstop”, “we”, “us” or “our”). We are a South African private company registered with the Companies and Intellectual Property Commission (CIPC). Cellstop is licensed by Cellstop International (CIL) to provide Cellstop-branded vehicle, fleet and asset tracking services in our licensed territory.
Contact details for privacy and general enquiries:
- Physical address: 33 Bell Crescent, Westlake, Cape Town, 7945, South Africa
- Postal address: P.O. Box 30120, Tokai, 7966
- Email: sales@cellstop.org
- Call centre: 08600 27867
- Sales: +27 21 001 3710
- Emergency: 08610 11 911
- Website: https://www.cellstop.co.za
Our Information Officer (and any Deputy Information Officer appointed from time to time) may be contacted through the channels above. Please mark correspondence “For the attention of the Information Officer” when you wish to exercise a data subject right or raise a privacy concern.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal information we process in connection with:
- our website at www.cellstop.co.za and related online content;
- enquiry, proposal, White Label and Reseller forms and related communications;
- customer and partner accounts, support and billing administration;
- telematics platforms and tools we make available, including iLocate, iFleet and iReports;
- the Cellstop mobile applications and related login access;
- vehicle, fleet and asset tracking, stolen vehicle recovery (SVR) and related operational or security services; and
- White Label and Reseller partner programmes.
This Privacy Policy is not a substitute for customer master services agreements, service level agreements, hardware or fitment contracts, or partner agreements. Those documents may contain additional confidentiality, data-processing and security terms. Where we process personal information as an operator on behalf of a customer, that customer’s own privacy notices to its employees, drivers or end users also apply.
By using our website, applications or services, or by providing personal information to us, you acknowledge that you have read this Privacy Policy. Where PoPIA or GDPR requires consent for a specific processing activity, we will request that consent separately where appropriate.
3. Personal information we process
The categories of personal information we process depend on how you interact with Cellstop. They may include:
- Identity and contact details: name, job title, company name, email address, telephone numbers, and physical or postal addresses.
- Enquiry and correspondence content: messages, service interests, partner type, region, business focus and other information you submit through our forms or communications.
- Account and authentication data: usernames, credentials, roles and access permissions for platforms and mobile apps (we do not ask you to share passwords in open enquiry forms).
- Vehicle, asset and fleet identifiers: registration numbers, VIN or asset IDs, unit identifiers, installation or fitment details, and related configuration data.
- Location and telematics data: GPS location, trip history, routes, speed, ignition status, movement, towing, tampering, signal interference and similar event or sensor data generated by tracking devices and services.
- Driver and operator-related data: where enabled under a customer configuration, driver identification, behaviour indicators and related accountability data.
- Video and imagery: where contracted (for example dashcam or MDVR services), video, still images and associated event metadata.
- Technical and usage data: IP address, browser or device type, approximate location derived from network data, log files, diagnostic data and similar information generated when you use our website, apps or platforms.
- Cookies and similar technologies: as described in the Cookies section below.
- Billing and contract administration data: customer account details, invoices, payment references and related records needed to administer the commercial relationship.
We generally do not seek special personal information as defined in PoPIA (for example biometric information used to uniquely identify a person, or information concerning health, religion or criminal behaviour) through our website. Certain tracking or security features may involve biometric or similar technologies only where expressly configured under a customer contract and permitted by law. We process such information only to the extent necessary and lawful for the relevant service.
Location data associated with a vehicle, asset or identifiable driver can constitute personal information. Customers remain responsible for ensuring they have a lawful basis and appropriate notices for monitoring employees, contractors or other data subjects using Cellstop services.
4. Purposes of processing
We process personal information for the following purposes:
- responding to sales, support, White Label and Reseller enquiries and routing them to the right team;
- providing, configuring, maintaining and improving vehicle, fleet and asset tracking and related telematics services;
- enabling authorised users to access platforms and mobile applications;
- supporting stolen vehicle recovery, security response and control-room workflows where those services apply;
- providing customer support, incident handling and service communications;
- administering accounts, contracts, billing and partner programmes;
- meeting legal, regulatory, accreditation and law-enforcement obligations;
- protecting our rights, property, users and the integrity of our systems (including fraud prevention and security monitoring);
- improving service quality, reliability and documentation, using aggregated or de-identified information where practicable; and
- direct marketing only where permitted by PoPIA and other applicable law, and subject to your right to object or opt out.
5. Lawful bases for processing
5.1 PoPIA (South Africa)
We process personal information in accordance with PoPIA. Depending on the context, processing may be justified because:
- it is necessary to conclude or perform a contract with you or your organisation;
- it is necessary to comply with an obligation imposed by law;
- it protects a legitimate interest of yours;
- it is necessary for pursuing our legitimate interests or those of a third party to whom the information is supplied, balanced against your rights; or
- you (or a competent person where required) have consented, where consent is the appropriate justification.
Where we process personal information as an operator on behalf of a customer who is the responsible party (for example fleet location data relating to that customer’s drivers or assets), we do so under that customer’s instructions and applicable operator agreements, consistent with PoPIA sections 20 and 21.
Special personal information and personal information of children are processed only where PoPIA permits (including applicable exceptions or authorisations) and only to the extent necessary for the relevant purpose.
5.2 GDPR (where applicable)
If you are located in the European Economic Area or the United Kingdom, or GDPR otherwise applies to a particular processing activity, we rely on one or more of the following lawful bases under Article 6 GDPR (and UK GDPR equivalents):
- Contract: processing necessary to perform a contract with you or to take steps at your request before entering into a contract;
- Legitimate interests: for example responding to business enquiries, securing our services, or improving reliability, where these interests are not overridden by your rights;
- Legal obligation: where processing is necessary to comply with applicable law; and
- Consent: where we ask for consent (for example certain optional cookies or marketing), which you may withdraw at any time without affecting the lawfulness of processing before withdrawal.
Where we process special categories of data under GDPR, we do so only under an applicable Article 9 condition, typically where necessary for reasons of substantial public interest, for the establishment or defence of legal claims, or with explicit consent, as relevant to the service configuration.
6. Our role as responsible party or operator
Website and Cellstop marketing communications. For personal information collected through our public website enquiry forms and related Cellstop marketing or partner outreach that we control, Cellstop is typically the responsible party (controller under GDPR terminology).
Customer telematics and fleet data. For vehicle, asset, driver and related operational data processed to deliver a customer’s tracking or fleet service, the customer is generally the responsible party. Cellstop acts as an operator (processor) on the customer’s documented instructions, except where we determine purposes and means independently (for example our own billing records, platform security logs, or Cellstop’s own direct marketing), in which case we are the responsible party for that processing.
White Label and Reseller arrangements may allocate privacy roles differently in the relevant partner agreement. Partners must ensure their own customers and end users receive appropriate privacy information.
8. Cross-border transfers
Our services are primarily oriented to South Africa. Personal information may, however, be stored or accessed from other countries where our licensor, cloud, support or technology partners operate.
Where PoPIA applies, we transfer personal information outside South Africa only in accordance with section 72 of PoPIA (for example where the recipient is subject to a law, binding corporate rules or binding agreement that provides an adequate level of protection, or another permitted ground applies).
Where GDPR applies to a transfer of personal data from the EEA/UK to a third country, we use an appropriate transfer mechanism under Chapter V GDPR / UK GDPR (such as adequacy decisions, standard contractual clauses or other lawful safeguards) together with any required supplementary measures.
9. Retention
We retain personal information only for as long as necessary for the purposes described in this Privacy Policy, or as required or permitted by law. Typical retention approaches include:
- Website enquiries: retained for as long as needed to respond, follow up and manage the sales or partner relationship, and thereafter for a limited period for record-keeping and dispute management;
- Customer and partner account records: retained for the duration of the contract and for a further period consistent with statutory, tax, accounting and legal-claim requirements;
- Location, trip and telematics records: retained according to the service configuration, customer instructions and operational needs, and any longer period required for security investigations, SVR matters or legal holds; and
- Security and system logs: retained for periods appropriate to detect, investigate and prevent abuse or incidents.
When personal information is no longer required, we destroy, delete or de-identify it in a manner that prevents reconstruction insofar as reasonably practicable, subject to backup and legal hold constraints.
10. Security safeguards
We implement appropriate, reasonable technical and organisational measures designed to protect personal information against loss, damage, unauthorised destruction and unlawful access or processing, taking into account the nature of the information and the risks involved. Measures may include access controls, authentication, network and hosting security, operational procedures, and contractual controls with operators.
No method of transmission or storage is completely secure. If we become aware of a security compromise involving personal information, we will notify the Information Regulator and affected data subjects as required by PoPIA, and take other steps required by applicable law (including GDPR breach-notification rules where they apply).
11. Your rights
11.1 Rights under PoPIA
Subject to the limitations in PoPIA, you may have the right to:
- be notified that personal information about you is being collected or that it has been accessed by an unauthorised person;
- request access to your personal information;
- request correction, destruction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- object to processing in certain circumstances, including for direct marketing; and
- lodge a complaint with the Information Regulator.
11.2 Additional rights where GDPR applies
Where GDPR applies, you may also have rights of access, rectification, erasure, restriction, data portability, objection, and the right not to be subject to certain automated decision-making, as well as the right to withdraw consent where processing is based on consent.
11.3 How to exercise your rights
To exercise these rights, contact us using the details in the “Who we are” section and address your request to the Information Officer. We may need to verify your identity and, where you act for an organisation or another person, confirm your authority. We will respond within the timeframes required by applicable law. Where Cellstop processes information only as an operator for a customer, we may need to refer your request to that customer as the responsible party.
12. Direct marketing
We may send electronic communications about Cellstop products, services or partner programmes where permitted by PoPIA and other applicable law. Where consent is required for unsolicited electronic marketing, we will obtain it before sending such communications. You may opt out of marketing at any time by using the unsubscribe mechanism in the message or by contacting us. Opting out of marketing does not affect transactional or service messages necessary to provide contracted services.
13. Children
Our website and services are directed at businesses and adult individuals. We do not knowingly collect personal information from children under 18 years of age through our public website. If you believe we have collected a child’s personal information without proper authority, please contact us so that we can take appropriate steps.
15. Complaints
If you have a privacy concern, please contact our Information Officer first using the details in this Privacy Policy so that we can try to resolve it.
You may also lodge a complaint with the Information Regulator (South Africa):
- Website: https://inforegulator.org.za/
- Email (general / complaints): enquiries@inforegulator.org.za / POPIAComplaints@inforegulator.org.za
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Where GDPR applies, you may also lodge a complaint with your local supervisory authority in the EEA or with the UK Information Commissioner’s Office, as applicable.
16. Updates and governing law
We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal requirements. The “Last updated” date at the top of this page indicates when this version took effect. Material changes will be published on this page and, where appropriate, communicated through other reasonable channels.
This Privacy Policy is governed by the laws of the Republic of South Africa. Nothing in this Privacy Policy limits any mandatory rights you may have under PoPIA, GDPR or other applicable law.
This notice is provided for transparency and operational compliance. It does not constitute legal advice. For advice on your specific circumstances, please consult your attorney or Information Officer.