Last Updated: 17 September 2026
IMG Systems (Pty) Ltd, trading as "IMG" ("IMG", "we", "us", "our"), is a South African marketing and technology agency. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit img-systems.com (the "Website"), engage us for services, or otherwise interact with us.
This Policy is drafted to comply with the Protection of Personal Information Act 4 of 2013 ("POPIA"), South Africa’s data protection law, and the General Data Protection Regulation (EU) 2016/679 ("GDPR"), for visitors and clients in the European Union / European Economic Area, together with relevant principles from other applicable international privacy frameworks (including the UK GDPR and, where applicable, the California Consumer Privacy Act / CPRA). Where these frameworks impose differing obligations, we apply the stricter standard. For the purposes of POPIA, IMG is the "Responsible Party." For the purposes of GDPR, IMG is the "Data Controller" in respect of personal information collected via the Website and through our client relationships. You can contact us at hello@img-systems.com.
This Policy applies to personal information we process in connection with the Website and our Services. It does not apply to third-party websites linked from the Website, which are governed by their own privacy policies. By using the Website or engaging our Services, you acknowledge that you have read and understood this Policy.
We collect information you provide directly, including your name and surname, email address, phone number, company name and job title, the content of messages submitted via our contact form or email, and any information you voluntarily share when engaging our Services (for example, project briefs, brand assets, or business information relevant to a project).
We collect certain information automatically, including your IP address, browser type and device information, pages visited, time on page, referral source, and general approximate location derived from your IP address. We use Umami Analytics, a privacy-focused, cookieless analytics platform, to understand aggregate Website usage. Umami does not use tracking cookies and does not collect personally identifiable information for advertising purposes.
We do not knowingly collect special personal information (as defined by POPIA) or special category data (as defined by GDPR) — such as race, religion, health information, or biometric data — via the Website. If you voluntarily submit such information to us (for example, within a message), we will only process it for the purpose you provided it and will not retain it longer than necessary.
We process personal information to respond to enquiries submitted via our contact form (on the basis of consent or our legitimate interest); to provide quotes and onboard new clients (as a pre-contractual step, or to perform a contract); to deliver contracted services across our web, software, campaign, and content divisions (performance of a contract); to issue invoices and process payments (performance of a contract and compliance with legal obligations); to monitor and improve Website performance (legitimate interest); to send marketing communications only where you have opted in (consent); and to comply with our legal, tax, and regulatory obligations. We do not sell personal information to third parties, and we do not use personal information for automated decision-making or profiling that produces legal or similarly significant effects on you.
We share personal information only where necessary to operate our business or deliver Services, including with Hostinger (web hosting, file storage, and email forwarding), Google Workspace / Gmail (for receiving and managing enquiries), Umami Cloud (cookieless, aggregated usage analytics), our payment processor where applicable, and our professional advisors (accountants, auditors, and legal counsel) where necessary. We may also disclose information to legal or regulatory authorities where required by law, court order, or to protect our legal rights. All third-party service providers are contractually required, or otherwise bound by their own applicable data protection obligations, to protect your information and to process it only for the purposes we specify. We do not share personal information with third parties for their own independent marketing purposes.
Some of our service providers, including Hostinger, Google, and Umami Cloud, may process or store data outside South Africa, including in the European Union, the United States, or elsewhere. Under POPIA, we only transfer personal information outside South Africa where the recipient is subject to a law, binding corporate rules, or an agreement that provides an adequate level of protection substantially similar to POPIA, or where you have consented to the transfer. Under GDPR, where personal information of EU/EEA data subjects is transferred outside the EU/EEA, we rely on adequacy decisions, Standard Contractual Clauses, or another lawful transfer mechanism recognised by the GDPR.
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy. Contact form enquiries are generally retained for up to twelve months unless a client relationship is established. Client and project records are retained for the duration of the engagement plus a period required by South African tax and company law, generally five years. Financial and invoicing records are retained as required by the South African Revenue Service and the Companies Act 71 of 2008. Analytics data is aggregated and does not identify individuals. When personal information is no longer required, it is securely deleted or anonymised.
We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, alteration, or disclosure, including encrypted connections (HTTPS/TLS) across the Website, restricted access to systems containing personal information, secure hosting infrastructure with regular monitoring, and DKIM/SPF/DMARC email authentication to reduce phishing and spoofing risk. No method of transmission or storage is completely secure. Where a data breach poses a risk to your rights, we will notify affected individuals and the relevant regulator as required by POPIA and/or GDPR.
Under POPIA, you have the right to be notified that your personal information is being collected, to access the personal information we hold about you, to request correction, destruction, or deletion of personal information, to object to the processing of your personal information, and to lodge a complaint with the Information Regulator (South Africa). If you are located in the EU/EEA/UK, GDPR additionally gives you the right to data portability, the right to restrict processing in certain circumstances, the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal, and the right to lodge a complaint with your local supervisory authority. To exercise any of these rights, contact us at hello@img-systems.com. We will respond within the timeframes required by applicable law, generally within 30 days under POPIA and one month under GDPR.
The Website uses minimal, essential technologies to function correctly. Our analytics provider, Umami, is cookieless by design and does not track individual users across sites. We do not currently use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies. If this changes, this Policy will be updated and, where required by law, a cookie consent mechanism will be implemented.
Our Services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will delete it promptly.
The Website may contain links to third-party websites, including social media platforms. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies independently.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last Updated" date at the top of this Policy reflects the most recent revision. Material changes will be communicated via the Website or directly to clients where appropriate.
If you believe your rights under POPIA have been infringed, you may lodge a complaint with the Information Regulator (South Africa) at complaints.IR@justice.gov.za or via https://inforegulator.org.za. If you are located in the EU/EEA, you may lodge a complaint with your local Data Protection Authority if you believe your GDPR rights have been infringed.
For any questions about this Privacy Policy or our data practices, contact IMG Systems (Pty) Ltd at hello@img-systems.com or via img-systems.com.
This Privacy Policy takes effect on the date stated as "Last Updated" above and remains in force until amended or replaced by IMG Systems.