Privacy Policy

Effective date: 17 September 2026. Stalvnek (Pty) Ltd, 45 Smith Street, Durban Central, 4001 Durban, KwaZulu-Natal, handles personal information in line with the Protection of Personal Information Act.

1. Scope and responsible party

Data protection contact: Stalvnek Data Protection Contact, Stalvnek (Pty) Ltd, 45 Smith Street, Durban Central, 4001 Durban, KwaZulu-Natal, [email protected], +27 31 123 4603. This contact coordinates privacy questions and requests; Stalvnek will identify the appropriate responsible person for each matter.

This policy covers stalvnek.info, order forms, customer messages and delivery coordination. Stalvnek is responsible for deciding why and how information is used. Questions may be sent to [email protected].

2. Information collected

We may collect a name, phone number, delivery address, email address, order details, consent record and correspondence. Technical information such as browser type, approximate location, referring page and timestamps may be collected by hosting and security systems.

3. Purpose

Information is used to confirm orders, arrange cash-on-delivery dispatch, answer enquiries, maintain records, prevent misuse and improve site performance. We do not sell personal information.

4. Legal basis

Processing may be based on consent, steps requested before an order, fulfilment of an agreement, legal duties or a legitimate operational interest. Where consent is used, it can be withdrawn by contacting us, although withdrawal may affect an unfulfilled order.

5. Retention

Order records are retained for seven years where required for accounting and statutory purposes. Enquiry messages are normally retained for 24 months after the last interaction. Security logs are normally retained for 90 days, while consent records may be retained for five years after the relevant interaction.

6. Processors

We may use hosting, email, telephony, courier, payment-on-delivery and analytics suppliers. Suppliers receive only information needed for their task and must apply suitable confidentiality and security measures. Their processing may be governed by their own notices.

7. International transfers

Some infrastructure suppliers may process data outside South Africa. Where this occurs, Stalvnek seeks contractual protections, access controls and a lawful transfer basis under applicable privacy requirements.

8. Security

We use access restrictions, encrypted transport where available, account permissions and limited staff access. No online transmission can be promised completely secure. Suspected incidents are assessed and handled according to applicable requirements.

9. Your rights

You may request access, correction, deletion where lawful, information about processing, or withdrawal of consent. Send a written request with enough detail to locate the record to [email protected]. We may request reasonable identity information before responding.

10. Response process

We aim to acknowledge requests within five business days and respond within 30 days, subject to complexity and lawful extensions. If a request cannot be fulfilled, we will explain the reason and available complaint route.

11. Cookies

Our consent banner stores a cookieChoice value in browser storage after a visitor selects an option. Session and analytics technologies may be used only where configured and permitted. See cookies.html for names, purposes and lifespans.

12. Children

The website is intended for adults making their own purchasing decisions. We do not knowingly collect information from children. If a guardian believes information was submitted by a child, please contact us for review.

13. Complaints

First contact Stalvnek so we can investigate. You may also approach the Information Regulator of South Africa through its official channels if you remain dissatisfied.

14. Third-party links

External pages are not controlled by Stalvnek. Their collection practices, notices and retention periods are their responsibility. Review their terms before sharing information.

15. Revision log

17 September 2026: initial publication for stalvnek.info. Future changes will be dated here and highlighted where reasonably practical.

How information is received and used in practice

Information may be supplied directly through an order form, email, telephone call or other customer message. Some details are created when Stalvnek records an order reference, confirms a delivery address or responds to a question. Technical logs may also record an IP address, browser event, approximate region and time of access for security and reliability.

We use only the information reasonably needed for the stated purpose. A delivery partner may receive a recipient name, phone number, address and parcel reference, but does not need access to unrelated website enquiries. Staff and contractors are expected to use access controls and to keep information confidential.

Retention and deletion

Order and transaction records are generally retained for seven years after the relevant transaction or the end of the applicable accounting period, whichever is later. Customer-service correspondence is normally retained for up to three years after the last meaningful interaction, unless a longer period is needed for a complaint, dispute or legal duty. Security and access logs are generally retained for up to twelve months.

Consent records are retained while the consent is relevant and for a reasonable period afterwards so that Stalvnek can demonstrate how a request was received. When a retention period ends, information is deleted, anonymised or securely restricted unless another lawful reason requires continued retention.

Service providers and transfers

Stalvnek may use hosting, website security, email, telephone, courier, payment-record and analytics service providers. These providers receive only the information needed for their stated service and are expected to apply suitable confidentiality and security measures. Current providers may process information in South Africa or in another country where their infrastructure is located.

Where information leaves South Africa, Stalvnek will consider the safeguards required by POPIA, including contractual protections, the recipient’s legal framework and the nature of the information involved. We do not intentionally sell personal information or use it for unrelated advertising audiences.

Your requests and complaints

You may ask whether personal information is held, request access, seek correction, object to certain processing, withdraw consent where consent is the basis, or ask for deletion where no continuing legal reason applies. Send a request to [email protected] with enough detail to identify the record; Stalvnek may request reasonable identity confirmation before responding.

Stalvnek aims to acknowledge privacy requests within two business days and respond within thirty days, subject to lawful extensions for complex requests. A complaint should include the relevant date and communication, and will be reviewed with a written outcome where possible. You may also contact the Information Regulator of South Africa if you remain dissatisfied.

Security and changes

Reasonable safeguards include restricted access, secure connections, careful supplier selection and procedures for correcting or deleting information. No online transmission can be described as completely risk-free, so customers should avoid sending unnecessary sensitive details by ordinary email.

This policy was reviewed on 17 September 2026. Later versions will identify the new effective date and describe material changes, while records already collected will continue to be handled under the applicable version and law.

Operational examples and data minimisation

For an order, the practical record may include a name, phone number, delivery address, selected pack, quantity, order time and confirmation outcome. A general enquiry may need only an email address and the message itself. Technical records can help identify a failed page load or suspicious access, but they are not used to create a personal profile for unrelated purposes. Stalvnek asks for information that is relevant to the requested service. Optional details should not be sent unless they are needed to resolve the enquiry.

Access is limited according to role and operational need. A courier may receive delivery details, while a website support provider may receive technical information required to keep the site available. These recipients are not authorised to use order information for their own unrelated marketing. If information is corrected, Stalvnek will take reasonable steps to update relevant operational records. Where a record cannot be changed because it is part of an accounting trail, the reason will be explained.

Retention periods

Order, dispatch and accounting records are generally retained for seven years after the relevant transaction or the end of the applicable accounting period, whichever is later. Customer-service correspondence is normally retained for up to three years after the last meaningful interaction. Security and access logs are generally retained for up to twelve months. Consent records may be kept for up to three years after the last recorded choice so Stalvnek can demonstrate how preferences were managed.

Retention is reviewed periodically rather than extended automatically. At the end of the applicable period, information is deleted, anonymised or securely restricted unless a complaint, dispute, audit or legal duty requires longer preservation. Backups may expire on a separate rolling schedule, typically within ninety days after deletion from active systems. A deletion request cannot override a lawful retention obligation, but access and restriction options may still be considered.

Service providers and international processing

Stalvnek may use hosting and security providers, email and telephone service providers, courier partners, accounting support and consent or analytics tools. Examples of provider categories are given to explain the workflow; the active supplier list can change as services are reviewed. Each provider should receive only the information needed for its defined task. Contracts and access controls are used where appropriate.

Some infrastructure may process technical or contact information outside South Africa. Before using such a service, Stalvnek considers the recipient’s safeguards, contractual duties, confidentiality terms and the requirements of POPIA. International processing does not change the purpose for which information was collected. A person may ask for more information about a relevant transfer by contacting [email protected].

Rights, identity checks and complaints

You may ask whether personal information is held, request access, ask for correction, object to certain processing, withdraw consent where consent is the basis, or request deletion where no continuing legal reason applies. Send the request to [email protected] with the name and communication or order reference needed to locate it. Stalvnek may request reasonable identity confirmation before disclosing or changing information. This protects customers from requests made by someone else.

Stalvnek aims to acknowledge a privacy request within two business days and respond within thirty days, subject to lawful extensions for complex requests. A complaint should include the relevant date, communication and desired outcome. The complaint will be reviewed and a written response provided where possible. If the matter remains unresolved, a person may contact the Information Regulator of South Africa through its current official channels.

Security and revision history

Reasonable safeguards include restricted access, secure connections, supplier review, password controls and procedures for responding to suspected incidents. No online transmission can be described as completely risk-free, so customers should avoid sending unnecessary sensitive information by ordinary email. If Stalvnek becomes aware of an incident affecting personal information, it will assess notification and remedial duties under applicable law. Security measures may change as the website and suppliers change.

This policy was reviewed on 17 September 2026. Material future changes will carry a new effective date and a concise change description. Older versions may be retained for governance and audit purposes. Questions remain welcome at 45 Smith Street, Durban Central, 4001 Durban, KwaZulu-Natal, [email protected] or +27 31 123 4603.