HBGSchindlers Attorneys
PRIVACY POLICY
Effective Date: 24 June 2025
Next Review Date: 24 June 2028
Policy Owner: Managing Partner
Contact: info@hbgschindlers.com | +27 (11) 568 8500
Address: Third Floor, 3 Melrose Boulevard, Melrose Arch, 2076
Website: www.hbgschindlers.com
- INTRODUCTION
- HBGSchindlers Attorneys (“HBGSchindlers”, “the Firm”, “we”, “us”, or “our”) is a full-service South African law firm committed to protecting your privacy and processing personal information lawfully, fairly and transparently.
- This Privacy Policy explains how we collect, use, store, share, retain and protect your personal information, including data collected via our website, in accordance with the Protection of Personal Information Act, 4 of 2013 (“PoPIA”), the Promotion of Access to Information Act, 2 of 2000 (“PAIA”), and other applicable privacy and data protection laws.
- SCOPE
This policy applies to all clients, service providers, prospective clients, vendors, suppliers, job applicants, employees, and users of our website (https://www.hbgschindlers.com) who provide us with Personal Information, whether directly or through automated means. - DEFINITIONS
- Personal Information: Information relating to an identifiable, living individual or juristic person.
- Special Personal Information: Information relating to race, health, biometrics, religious or philosophical beliefs, political opinions, or criminal behaviour.
- Processing: Any operation or activity concerning personal information, including collection, use, storage, disclosure, or destruction.
- WHAT PERSONAL INFORMATION DO WE COLLECT?
We may collect the following categories of information:-
- Identity and Contact Details: Names, ID numbers, registration numbers, addresses, email addresses, phone numbers.
- Financial and Transactional Data: Bank details, payment records, tax and VAT numbers.
- Employment and HR Data: CVs, employment history, equity statistics, health and disability status (where relevant), criminal checks, references.
- Website and Technical Data: IP address, browser type, device details, cookies, clickstream data.
- Usage and Marketing Data: Preferences, feedback, subscription interests.
- CCTV and Access Logs: Visual images for security purposes when entering our premises.
-
- HOW DO WE COLLECT INFORMATION?
- Directly from you (e.g. via forms, correspondence, onboarding, employment process).
- Automatically through our website (cookies, analytics, log files).
- From third-party sources (e.g. recruitment agencies, background checks, regulators).
- Through CCTV and access control systems at our premises.
- PURPOSE OF COLLECTION
- We collect and process your Personal Information for the following purposes:
- deliver legal services;
- client onboarding (KYC, FICA, CDD requirements);
- HR, recruitment, and payroll administration;
- comply with legal, tax, and regulatory obligations;
- dispute resolution and to protect our legal rights;
- website administration and user experience optimisation;
- marketing and events communications (with opt-in consent).
- We will only process Special Personal Information where legally justified (e.g. consent, public interest, legal obligation).
- We collect and process your Personal Information for the following purposes:
- LEGAL BASIS FOR PROCESSING
We process Personal Information on the basis of:- your consent;
- a legal obligation;
- performance of a contract;
- our legitimate interests (e.g. improving services, protecting the firm); or
- protection of your or another person’s legitimate interest.
- MARKETING COMMUNICATIONS
We may contact you with legal updates or event invitations. You may opt out at any time by following the unsubscribe link or emailing us. We respect all requests to withdraw consent. - SHARING OF PERSONAL INFORMATION
- We may share your personal information with:
- third-party service providers (IT, storage, consultants, background checks) under written confidentiality agreements;
- legal and regulatory authorities where required;
- professional advisers and counsel involved in your matter;
- our insurers, auditors, alliance partners, and approved subcontractors;
- third parties with whom we are legally permitted or required to share such data.
- We do not sell your personal data.
- We may share your personal information with:
- CROSS-BORDER TRANSFERS
Where we transfer personal information across borders (e.g., for cloud hosting or international legal advice), we will:- ensure the recipient jurisdiction offers adequate protection; or
- enter into appropriate contractual safeguards.
- SECURITY SAFEGUARDS
We implement reasonable administrative, physical, and technical safeguards to protect personal information, including:- access controls;
- encrypted storage;
- firewalls and anti-malware;
- POPIA training;
- incident response protocols.We also maintain business continuity and backup protocols.
- DATA RETENTION
We retain Personal Information only for as long as necessary:- to fulfil the purpose for which it was collected;
- as required by law or regulation;
- for legitimate business or evidentiary purposes; or
- as agreed with you.
- YOUR RIGHTS
You have the right to:- request access the Personal Information we hold about you;
- request correction or deletion of your Personal Information;
- object to processing or request restrictions;
- withdraw consent (where applicable);
- lodge a complaint with the Information Regulator.We may charge a statutory fee to process certain requests where permitted by law.
- CHILDREN’S INFORMATION
We do not intentionally collect information of persons under 18, except where required in specific legal contexts, and then only with proper consent from a competent person. - COOKIES
We use cookies to enhance your experience on our website. You may disable cookies in your browser settings, but this may affect functionality. Our Cookie Policy is available upon request. - WEBSITE LINKS & SOCIAL MEDIA
Our website may link to external sites or social media platforms. We are not responsible for their privacy practices, and their use is governed by their own policies. - WEBSITE-SPECIFIC PROCESSING
- We process limited Personal Information via iour website (e.g. name, email, country of residence).
- Metadata such as IP address, device type, and browsing history may also be processed for analytics and performance improvement.
- We rely on consent for such processing, which can be withdrawn at any time.
- PRIVACY INCIDENT RESPONSE
We have a dedicated POPIA Incident Response Policy that sets out procedures for:- reporting and escalating actual or suspected data breaches;
- notifying the Information Regulator and affected parties;
- mitigating risks and documenting actions taken;
- continuous policy review and system improvement.Third-party operators must notify us of any breach without delay.
- RECORD KEEPING
We maintain a Security Compromise Register documenting:- breach date;
- affected systems/data;
- action taken;
- notifications made;
- lessons learned.
- POLICY UPDATES
We may update this policy from time to time. Updates will be posted on our website and take effect upon publication. We recommend checking this policy periodically. - CONTACT DETAILS
For any privacy-related queries or to exercise your rights, contact our Information Officer:Sarah Thackwell
info@hbgschindlers.com
+27 (11) 568 8500If unresolved, you may contact the Information Regulator via https://www.inforegulator.org.za -
COPYRIGHT AND USE DISCLAIMER
-
All content available on the HBGSchindlers website, including but not limited to legal articles, policies, documents, graphics, branding, layouts, and any downloadable resources (“Website Content”), is protected under South African and international copyright laws. The copyright and all intellectual property rights therein are owned by HBGSchindlers unless otherwise indicated.
-
No person, company, institution, automated system, or artificial intelligence agent may copy, reproduce, adapt, translate, publish, upload, post, publicly display, encode, transmit, distribute, or in any way exploit or use any portion of the Website Content, whether in whole or in part, for the purposes of training, feeding, or refining any artificial intelligence (AI) system, machine learning model, or large language model (LLM), without the express prior written consent of HBGSchindlers.
-
This restriction includes, but is not limited to, the use of Website Content for:
-
AI model training or dataset compilation;
-
automated scraping or indexing for commercial, academic, or development purposes;
-
derivative works or tools based on any portion of the Website Content.
-
-
Exceptions are permitted only:
-
under the limited doctrine of “fair use” or “fair dealing” as contemplated in section 12 of the Copyright Act, 98 of 1978;
-
where the author, firm name, source link, and date of publication are clearly cited in a recognised academic referencing format, for educational or research purposes only; and
-
with prior written permission granted by HBGSchindlers.
-
-
Any unauthorised use, reproduction, scraping, or re-publication of our content – especially for AI development or commercial gain — may result in civil or criminal liability and the immediate institution of legal proceedings.
-
To request permission for use of any material, please contact: Email: gladwin-wood@hbgschindlers.com
-