Privacy Policy
Effective date: 1 June 2026. How Nexlor (Pty) Ltd collects, uses, discloses, retains and protects personal information under POPIA.
1.Introduction
1.1. Nexlor (Pty) Ltd respects your right to privacy and is committed to protecting your personal information.
1.2. This Privacy Policy explains how we collect, receive, use, store, disclose, retain and protect personal information when you:
1.2.1. visit or use our websites;
1.2.2. purchase our digital products;
1.2.3. use our software, platforms or digital services;
1.2.4. participate in our workshops or events;
1.2.5. engage us for consulting or related professional services;
1.2.6. communicate or interact with us; or
1.2.7. otherwise provide personal information to us.
1.3. This Privacy Policy applies to Nexlor (Pty) Ltd and the brands, websites, services and products operated by it, including:
1.3.1. NEXLOR;
1.3.2. ScaleUp Flow;
1.3.3. nexlor.co;
1.3.4. scaleupflow.com;
1.3.5. NEXLOR AI Academy;
1.3.6. NEXLOR Command Centre;
1.3.7. NEXLOR consulting engagements; and
1.3.8. NEXLOR workshops, events, software and digital products.
1.4. In this Privacy Policy, “NEXLOR”, “we”, “us” and “our” refer to Nexlor (Pty) Ltd.
1.5. This Privacy Policy should be read together with any specific privacy notice, contractual provision, consent form or terms and conditions that apply to a particular product, service or engagement.
2.Responsible party
2.1. The responsible party for the personal information described in this Privacy Policy is:
Registration number: 2023/699061/07
15 Heron Circle
Kommetjie
Cape Town
7976
South Africa
2.2. Our general privacy contact details are:
Email: privacy@nexlor.co
2.3. Requests to access, correct, delete or otherwise exercise rights in relation to personal information may be sent to:
Email: support@nexlor.co
3.Information Officer
3.1. NEXLOR’s Information Officer is the person occupying the position of Chief Executive Officer of Nexlor (Pty) Ltd.
3.2. At the effective date of this Privacy Policy, that person is:
Chief Executive Officer and Information Officer
Email: privacy@nexlor.co
Incident contact: schalk@nexlor.co
3.3. NEXLOR will register its Information Officer with the Information Regulator in accordance with applicable law.
3.4. The Information Officer is responsible for encouraging and monitoring NEXLOR’s compliance with applicable privacy and access-to-information legislation.
4.Applicable law
4.1. NEXLOR processes personal information in accordance with applicable South African law, including:
4.1.1. the Protection of Personal Information Act 4 of 2013, referred to as “POPIA”;
4.1.2. the Promotion of Access to Information Act 2 of 2000, referred to as “PAIA”;
4.1.3. the Electronic Communications and Transactions Act 25 of 2002; and
4.1.4. other applicable consumer protection, electronic communication, tax, accounting and commercial laws.
4.2. Where another jurisdiction’s privacy legislation applies to a specific activity, NEXLOR will take reasonable steps to comply with that legislation to the extent required.
5.Meaning of personal information
5.1. “Personal information” means information relating to an identifiable living person and, where applicable, an identifiable existing juristic person or organisation.
5.2. Personal information may include:
5.2.1. a person’s name and contact details;
5.2.2. company and employment information;
5.2.3. correspondence and communications;
5.2.4. account or transaction information;
5.2.5. online identifiers;
5.2.6. records of products or services purchased;
5.2.7. information submitted through forms; and
5.2.8. other information that identifies a person or can reasonably be connected to them.
5.3. “Processing” includes collecting, receiving, recording, organising, storing, updating, retrieving, using, sharing, transmitting, restricting, deleting or destroying personal information.
6.Personal information we collect
6.1. Depending on how you interact with NEXLOR, we may collect the following categories of personal information.
6.2. Website and lead information
6.2.1. Your first and last name.
6.2.2. Your email address.
6.2.3. Your company or organisation name.
6.2.4. Your organisation’s team size.
6.2.5. The information contained in an enquiry, message or form submission.
6.2.6. Records of your consent and communication preferences.
6.3. Client information
6.3.1. Names and business email addresses of client employees and representatives.
6.3.2. Job titles, roles and business responsibilities, where relevant.
6.3.3. Company and organisational details.
6.3.4. Records of consulting engagements, workshops, meetings and communications.
6.3.5. Information needed to manage the client relationship, provide services and administer contracts.
6.3.6. Invoicing, transaction and accounting information.
6.4. Where a client provides NEXLOR with personal information concerning its employees or representatives, the client is responsible for ensuring that it is permitted to provide that information to NEXLOR.
6.5. Workshop and event information
6.5.1. Names and business contact details.
6.5.2. Company names, team sizes and professional roles.
6.5.3. Registration and attendance information.
6.5.4. Workshop responses, feedback and participation records.
6.5.5. Dietary, accessibility or logistical information where voluntarily provided and reasonably required for an event.
6.6. Digital product and transaction information
6.6.1. Your name and contact details.
6.6.2. The digital product, programme or service purchased.
6.6.3. Payment status, transaction reference and related transaction information.
6.6.4. Invoices and accounting records.
6.6.5. Access and fulfilment records for purchased digital products.
6.7. Payments are processed through Payfast or another disclosed payment provider.
6.8. NEXLOR does not receive or store your complete payment-card details. Payment providers process these details under their own terms and privacy practices.
6.9. Communications
6.9.1. Emails and other correspondence sent to or received from you.
6.9.2. Records of enquiries, support requests and responses.
6.9.3. Notes and records relating to meetings, sales discussions or client engagements.
6.9.4. Your marketing preferences, including subscription and unsubscribe records.
6.10. Technical and operational information
6.10.1. NEXLOR does not currently use website analytics, behavioural advertising, heatmaps, session recording or similar tracking tools on the websites covered by this Privacy Policy.
6.10.2. Our websites, hosting providers and security systems may nevertheless process limited technical information that is necessary to operate, secure and deliver the websites. This may include IP addresses, request logs, browser information, timestamps and security-related information.
6.10.3. This limited processing is performed for website delivery, troubleshooting, fraud prevention, service reliability and cybersecurity rather than behavioural advertising or marketing profiling.
7.How we collect personal information
7.1. We may collect personal information:
7.1.1. directly from you when you complete a form;
7.1.2. when you contact or correspond with us;
7.1.3. when you purchase a product or service;
7.1.4. when you register for or attend an event or workshop;
7.1.5. when your employer or organisation engages us;
7.1.6. when a client provides us with the contact details of its employees or representatives;
7.1.7. when you subscribe to a communication or download a resource;
7.1.8. from our payment, email, accounting and other service providers;
7.1.9. through records generated when we provide our services; or
7.1.10. from publicly available business sources where lawful and reasonably necessary.
7.2. We primarily obtain marketing contact details through:
7.2.1. forms on our websites;
7.2.2. event and workshop registrations; and
7.2.3. existing business or client relationships.
7.3. Where we collect information from another source, we will process it only where permitted by law and where the processing is compatible with the context in which the information was obtained.
8.Why we process personal information
8.1. NEXLOR may process personal information for the following purposes:
8.1.1. responding to enquiries and requests;
8.1.2. communicating with prospective and existing clients;
8.1.3. providing proposals, consulting services and professional support;
8.1.4. delivering software, digital products and online services;
8.1.5. administering NEXLOR AI Academy and NEXLOR Command Centre;
8.1.6. administering ScaleUp Flow products and services;
8.1.7. registering and managing workshop or event participants;
8.1.8. processing payments and confirming transactions;
8.1.9. issuing quotations, invoices and accounting records;
8.1.10. fulfilling contractual obligations;
8.1.11. managing client and business relationships;
8.1.12. providing customer support;
8.1.13. sending requested resources, downloads or information;
8.1.14. sending marketing communications where permitted;
8.1.15. maintaining unsubscribe and objection records;
8.1.16. protecting our websites, systems, clients and business against fraud, misuse and security threats;
8.1.17. maintaining backups, logs and business records;
8.1.18. complying with legal, tax, accounting, regulatory and contractual obligations;
8.1.19. establishing, exercising or defending legal rights;
8.1.20. obtaining professional advice;
8.1.21. developing and improving our products and services using non-personal, aggregated or operational insights where appropriate; and
8.1.22. carrying out other purposes that are reasonably compatible with the purpose for which the information was collected.
9.Lawful grounds for processing
9.1. Depending on the circumstances, we process personal information on one or more of the following grounds:
9.1.1. you have consented to the processing;
9.1.2. the processing is necessary to enter into or perform a contract with you;
9.1.3. the processing is necessary to perform a contract with your organisation;
9.1.4. the processing is necessary to comply with a legal obligation;
9.1.5. the processing protects a legitimate interest of you or another person;
9.1.6. the processing is necessary to pursue the legitimate interests of NEXLOR or a third party, provided that those interests do not unjustifiably interfere with your privacy; or
9.1.7. the processing is otherwise permitted or required by law.
9.2. Examples of NEXLOR’s legitimate interests include:
9.2.1. operating and securing its business;
9.2.2. communicating with business prospects and clients;
9.2.3. delivering and improving services;
9.2.4. maintaining accurate records;
9.2.5. preventing fraud and unauthorised use;
9.2.6. protecting legal rights; and
9.2.7. understanding and serving the operational needs of clients.
9.3. Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that occurred lawfully before the withdrawal.
10.Information required from you
10.1. Some personal information is required for us to:
10.1.1. respond meaningfully to an enquiry;
10.1.2. register you for an event or programme;
10.1.3. complete a purchase;
10.1.4. provide a digital product;
10.1.5. enter into or perform a contract; or
10.1.6. comply with legal and accounting obligations.
10.2. Where information is mandatory, failure to provide it may prevent us from providing the requested product, service, access or response.
10.3. Where information is optional, we will indicate this where reasonably practical.
11.Direct marketing
11.1. We may send relevant business, product, event, educational or marketing communications by email where:
11.1.1. you have consented to receive them;
11.1.2. you are an existing client and the communication concerns similar NEXLOR products or services, where permitted by law; or
11.1.3. another lawful basis permits the communication.
11.2. NEXLOR uses Brevo to manage certain email communications and mailing lists.
11.3. Marketing emails will ordinarily include an unsubscribe facility.
11.4. You may opt out at any time by:
11.4.1. using the unsubscribe link in the communication; or
11.4.2. emailing support@nexlor.co.
11.5. After you unsubscribe, we may retain limited information in a suppression list to ensure that your preference is respected.
11.6. Opting out of marketing does not prevent NEXLOR from sending necessary administrative, transactional, contractual, security or service-related communications.
11.7. NEXLOR does not currently use automated lead scoring or marketing profiling.
13.Payments
13.1. Online payments are processed by Payfast or another payment provider identified during the transaction.
13.2. When making payment, you may be redirected to or interact directly with the payment provider.
13.3. The payment provider processes your payment information according to its own privacy policy, terms and security requirements.
13.4. NEXLOR may receive limited transaction information, such as:
13.4.1. your name;
13.4.2. your email address;
13.4.3. the payment amount;
13.4.4. the payment status;
13.4.5. a transaction reference; and
13.4.6. information needed to issue an invoice or provide the purchased product.
13.5. NEXLOR does not store full payment-card numbers or card security codes.
14.Artificial intelligence
14.1. NEXLOR may use artificial intelligence tools supplied by providers such as OpenAI and Anthropic for internal business and operational purposes.
14.2. NEXLOR does not intentionally submit client personal information to third-party artificial intelligence systems unless:
14.2.1. the processing is necessary for an agreed service;
14.2.2. the client has authorised or instructed the processing;
14.2.3. the information has been appropriately minimised, anonymised or protected; or
14.2.4. another lawful basis permits the processing.
14.3. NEXLOR does not use client personal information to train NEXLOR’s own general-purpose artificial intelligence models.
14.4. NEXLOR does not authorise third-party artificial intelligence providers to use client personal information to train their general-purpose models where provider controls allow this use to be disabled.
14.5. NEXLOR does not currently use artificial intelligence systems to make decisions that produce legal or similarly significant effects concerning individuals without meaningful human involvement.
14.6. Where an individual interacts directly with a NEXLOR artificial intelligence assistant, NEXLOR will take reasonable steps to make the artificial nature of the interaction clear.
14.7. Where appropriate, an individual may request:
14.7.1. human assistance;
14.7.2. correction of inaccurate information; or
14.7.3. human review of an artificial intelligence-generated result.
14.8. Artificial intelligence outputs may be incomplete or inaccurate and should not automatically be treated as verified professional advice or factual conclusions.
15.Client and employee information
15.1. When providing consulting, software, workshop or related services, NEXLOR may process business contact details belonging to a client’s employees, representatives, contractors or other authorised participants.
15.2. This may include names, business email addresses, roles, team information, communications and participation records.
15.3. NEXLOR processes this information to:
15.3.1. deliver the agreed services;
15.3.2. communicate with relevant participants;
15.3.3. organise meetings and workshops;
15.3.4. provide access to relevant products or materials;
15.3.5. maintain project and engagement records; and
15.3.6. fulfil contractual and legal obligations.
15.4. NEXLOR currently acts principally as the responsible party determining why and how the information described in this Privacy Policy is processed.
15.5. If NEXLOR processes personal information solely on behalf of a client in a future engagement, the relevant agreement may identify NEXLOR as an operator and impose additional data-processing obligations.
15.6. NEXLOR does not use client information to train artificial intelligence models, develop unrelated commercial datasets or create personal profiles.
16.Testimonials and case studies
16.1. NEXLOR may publish client testimonials, case studies, logos, results or other client-related marketing material only where:
16.1.1. the client has given permission;
16.1.2. the relevant content has otherwise been approved; or
16.1.3. publication is permitted under an applicable agreement or law.
16.2. Where a testimonial or case study identifies a specific individual, NEXLOR will obtain appropriate permission before publication.
16.3. Consent to a testimonial may be withdrawn, subject to reasonable limitations where material has already been lawfully published, distributed or incorporated into completed materials.
18.Service providers
18.1. NEXLOR uses third-party platforms to operate its business and provide its services.
18.2. These providers may include:
18.2.1. Supabase for database and backend services;
18.2.2. Vercel for website and application hosting;
18.2.3. Google Workspace, including Gmail, Google Calendar, Google Drive and Google Meet;
18.2.4. Brevo for email communications and mailing-list management;
18.2.5. Zoho Books and related Zoho services for accounting and business administration;
18.2.6. n8n for automation and system integration;
18.2.7. Slack for internal communication;
18.2.8. Fathom for meeting records, notes or related functionality where used;
18.2.9. Notion for documentation and internal information management;
18.2.10. Canva for design and content creation;
18.2.11. OpenAI and Anthropic for approved artificial intelligence use cases;
18.2.12. Payfast for payment processing; and
18.2.13. other professional, technology or infrastructure providers reasonably required to operate the business.
18.3. The availability, use and location of a provider may change over time.
18.4. NEXLOR takes reasonable steps to select reputable providers and to limit the information disclosed to what is reasonably necessary for the relevant service.
18.5. Third-party providers may process information under their own privacy policies and terms in addition to their obligations to NEXLOR.
19.International processing and transfers
19.1. Although NEXLOR is based in South Africa, some of our technology and service providers operate infrastructure or support services in Europe or other countries.
19.2. As a result, personal information may be:
19.2.1. stored outside South Africa;
19.2.2. accessed by authorised personnel outside South Africa;
19.2.3. routed through infrastructure outside South Africa; or
19.2.4. processed by an international service provider.
19.3. NEXLOR will transfer personal information outside South Africa only where the transfer is permitted by applicable law.
19.4. Depending on the circumstances, safeguards may include:
19.4.1. the recipient being subject to a law, binding corporate rules or agreement providing an adequate level of protection;
19.4.2. contractual commitments to protect the information in accordance with principles substantially similar to those contained in POPIA;
19.4.3. your consent, where consent is an appropriate basis;
19.4.4. the transfer being necessary for the performance of a contract;
19.4.5. the transfer being necessary for the implementation of pre-contractual measures requested by you;
19.4.6. the transfer being necessary for your benefit under a contract with another person; or
19.4.7. another ground permitted by applicable law.
19.5. NEXLOR will take reasonable steps to assess material service providers and the protections applicable to personal information processed internationally.
20.Security
20.1. NEXLOR applies reasonable technical and organisational safeguards designed to protect personal information against:
20.1.1. loss;
20.1.2. damage;
20.1.3. unauthorised destruction;
20.1.4. unlawful access;
20.1.5. unauthorised use;
20.1.6. disclosure; and
20.1.7. alteration.
20.2. Safeguards used by NEXLOR may include:
20.2.1. multi-factor authentication;
20.2.2. role-based access controls;
20.2.3. system and data backups;
20.2.4. access and activity logging;
20.2.5. restricted administrative access;
20.2.6. security controls provided by reputable cloud providers;
20.2.7. review and removal of access when it is no longer required;
20.2.8. confidentiality obligations where appropriate; and
20.2.9. documented security-incident procedures.
20.3. No electronic system or method of transmission is completely secure. NEXLOR therefore cannot guarantee absolute security.
20.4. You are responsible for protecting any password, access link or authentication credential issued to you and for notifying us promptly if you suspect unauthorised access.
21.Security incidents
21.1. NEXLOR maintains a procedure for responding to suspected or confirmed security incidents.
21.2. Suspected security incidents should be reported to:
Email: schalk@nexlor.co
21.3. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, NEXLOR will:
21.3.1. investigate the incident;
21.3.2. take reasonable steps to contain and remediate it;
21.3.3. preserve relevant evidence;
21.3.4. assess the information and individuals affected;
21.3.5. notify the Information Regulator as required by law; and
21.3.6. notify affected individuals as required by law, unless notification is delayed or restricted by an authorised body.
21.4. NEXLOR has not identified a previous material security compromise requiring disclosure in this Privacy Policy as at its effective date.
22.Retention
22.1. NEXLOR retains personal information only for as long as reasonably necessary for the purpose for which it was collected, or as otherwise required or permitted by law.
22.2. The applicable retention period depends on factors such as:
22.2.1. the nature of the information;
22.2.2. the purpose for which it was collected;
22.2.3. the duration of the client or contractual relationship;
22.2.4. legal, tax and accounting requirements;
22.2.5. contractual obligations;
22.2.6. applicable limitation periods;
22.2.7. operational and security requirements;
22.2.8. dispute or complaint handling; and
22.2.9. whether the information is needed to establish, exercise or defend legal rights.
22.3. Examples include:
22.3.1. enquiry and prospect information being retained while an enquiry or potential business relationship remains active and for a reasonable period afterwards;
22.3.2. client and contract records being retained for the engagement and any legally required period afterwards;
22.3.3. invoice, payment and accounting records being retained for the period required under applicable tax and accounting law;
22.3.4. marketing information being retained until you unsubscribe or object, subject to retention of a limited suppression record;
22.3.5. event and workshop records being retained for administration, follow-up and legitimate business records;
22.3.6. logs and security records being retained for a period proportionate to operational and cybersecurity needs; and
22.3.7. backups being retained until they are overwritten or expire through the applicable backup cycle.
22.4. When information is no longer required, NEXLOR may securely delete, destroy, de-identify or return it.
22.5. Where a client engagement ends, client information will be returned to the client where appropriate and agreed, subject to:
22.5.1. information that NEXLOR must retain by law;
22.5.2. records reasonably required to evidence the engagement;
22.5.3. information contained in routine backups; and
22.5.4. information that cannot reasonably be separated from legitimate business records.
22.6. Information remaining in backups will be protected and deleted or overwritten through the normal backup-retention cycle.
23.Accuracy and updating
23.1. NEXLOR takes reasonable steps to keep personal information accurate, complete and up to date where necessary for the purpose for which it is processed.
23.2. You should notify us if your personal information changes or if you believe that information held by us is inaccurate.
23.3. Requests to update or correct information may be sent to support@nexlor.co.
24.Your rights
24.1. Subject to applicable law, you may have the right to:
24.1.1. ask whether NEXLOR holds personal information about you;
24.1.2. request access to your personal information;
24.1.3. request correction or updating of inaccurate personal information;
24.1.4. request deletion or destruction of personal information where permitted;
24.1.5. object to processing on reasonable grounds;
24.1.6. object to direct marketing;
24.1.7. withdraw consent where processing is based on consent;
24.1.8. request information about the identity of third parties that have had access to your personal information, where applicable;
24.1.9. submit a complaint to the Information Regulator;
24.1.10. request human review of an applicable automated decision; and
24.1.11. exercise any other right granted under POPIA or another applicable law.
24.2. Rights are not absolute. NEXLOR may lawfully retain or continue processing information where, for example:
24.2.1. retention is required by law;
24.2.2. the information is required for a contract;
24.2.3. the information is needed to establish, exercise or defend legal rights;
24.2.4. another person’s rights must be protected; or
24.2.5. another lawful ground applies.
25.How to exercise your rights
25.1. Privacy requests may be submitted to:
Email: support@nexlor.co
25.2. Your request should, where possible, include:
25.2.1. your full name;
25.2.2. your contact details;
25.2.3. a description of the information or processing concerned;
25.2.4. the right you wish to exercise; and
25.2.5. information that will help us identify the relevant records.
25.3. NEXLOR may request reasonable proof of identity before providing access, correcting information or processing another privacy request.
25.4. Identity verification is intended to protect personal information from unauthorised disclosure or alteration.
25.5. NEXLOR will respond within the period required by applicable law.
25.6. Where permitted by law, NEXLOR may:
25.6.1. charge a prescribed fee;
25.6.2. request completion of a prescribed form;
25.6.3. refuse a request on lawful grounds; or
25.6.4. provide reasons for refusing or limiting a request.
26.Children and special personal information
26.1. NEXLOR’s websites, products and services are intended principally for business owners and adult business users.
26.2. NEXLOR does not intentionally collect personal information from children under the age of 18 through the activities covered by this Privacy Policy.
26.3. NEXLOR does not intentionally process special personal information such as:
26.3.1. health information;
26.3.2. biometric information;
26.3.3. race or ethnic origin;
26.3.4. religious or philosophical beliefs;
26.3.5. political persuasion;
26.3.6. trade-union membership;
26.3.7. criminal behaviour information; or
26.3.8. information concerning sex life or sexual orientation.
26.4. If NEXLOR learns that it has unintentionally collected children’s information or special personal information without an appropriate lawful basis, it will take reasonable steps to delete or otherwise lawfully address the information.
26.5. Please do not submit children’s information or special personal information to NEXLOR unless NEXLOR has specifically requested it and appropriate legal safeguards have been agreed.
27.Third-party websites and services
27.1. NEXLOR’s websites and communications may contain links to third-party websites, payment services, platforms or resources.
27.2. NEXLOR does not control the privacy practices of independent third parties.
27.3. You should review the applicable third party’s privacy policy before providing personal information to it.
27.4. The inclusion of a link does not necessarily constitute an endorsement of the third party’s privacy or security practices.
28.PAIA and access to records
28.1. PAIA gives persons a right to request access to certain records held by private bodies where the information is required for the exercise or protection of a right, subject to the requirements and grounds of refusal contained in PAIA.
28.2. A request under PAIA is separate from an ordinary customer-service enquiry and may need to be submitted using the prescribed form.
28.3. PAIA requests may be directed to NEXLOR’s Information Officer at:
Physical address: 15 Heron Circle, Kommetjie, Cape Town, 7976, South Africa
28.4. NEXLOR will maintain and make available a PAIA Manual in accordance with applicable law.
28.5. The PAIA Manual will describe:
28.5.1. NEXLOR’s contact details;
28.5.2. categories of records held by NEXLOR;
28.5.3. records that may be automatically available;
28.5.4. the procedure for requesting access;
28.5.5. applicable fees;
28.5.6. grounds on which access may be refused; and
28.5.7. remedies available to a requester.
28.6. Until a separate PAIA Manual is published, a person seeking access to a record may contact privacy@nexlor.co for assistance.
29.Complaints
29.1. We encourage you to contact NEXLOR first so that we can investigate and attempt to resolve your concern.
29.2. Complaints may be addressed to:
29.3. You also have the right to lodge a complaint with the Information Regulator of South Africa.
At the effective date of this Privacy Policy, the Information Regulator’s contact details include:
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Toll-free telephone: 0800 017 160
29.4. The Information Regulator may update its contact details or complaint procedure. Current details should be obtained from the Information Regulator’s official website.
30.Changes to this Privacy Policy
30.1. NEXLOR may amend this Privacy Policy from time to time to reflect:
30.1.1. changes to our services or operations;
30.1.2. changes to the information we process;
30.1.3. changes to our service providers;
30.1.4. changes to applicable law or regulatory guidance; or
30.1.5. improvements to our privacy and security practices.
30.2. The updated policy will be published on the relevant NEXLOR website.
30.3. Where a change is material and NEXLOR has appropriate contact details, NEXLOR may notify affected persons by email.
30.4. The effective date displayed at the beginning of the Privacy Policy indicates when the current version took effect.
30.5. Continued use of our websites or services after a change does not replace the need for consent where applicable law specifically requires new consent.
31.Governing law and jurisdiction
31.1. This Privacy Policy is governed by the laws of the Republic of South Africa.
31.2. Subject to any rights a person has to approach the Information Regulator, a court, tribunal or another competent authority, legal proceedings concerning this Privacy Policy will be subject to the jurisdiction of the competent courts serving Cape Town, South Africa.
32.Contact us
32.1. For general privacy questions:
Email: privacy@nexlor.co
32.2. To exercise a privacy right or request access, correction or deletion:
Email: support@nexlor.co
32.3. To report a suspected security incident:
Email: schalk@nexlor.co
32.4. Postal and physical address:
15 Heron Circle
Kommetjie
Cape Town
7976
South Africa