top of page

Privacy Policy

Effective date: 15 July 2026
Last updated: 15 July 2026

Introduction

Dabisa Consulting (Pty) Ltd (“Dabisa”, “we”, “us” or “our”) respects your privacy and is committed to processing personal information lawfully, responsibly and transparently.

​

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:

  • visit or interact with the Dabisa website;

  • complete a contact, assessment, checklist, download or enquiry form;

  • request information about our services;

  • subscribe to communications;

  • communicate with us by email, telephone, social media or another channel;

  • submit project information, BIM models, drawings, documents or supporting files; or

  • engage with us as a prospective client, client, supplier, consultant, contractor or business partner.

​

This policy should be read together with our Terms and Conditions, Cookie Notice and, where applicable, any client agreement, non-disclosure agreement, data-processing agreement, proposal or statement of work.

Who We Are

The responsible party for personal information processed under this policy is:

​

Legal name: Dabisa Consulting (Pty) Ltd
Company registration number: 2016/390907/07
Registered address: 35 Moffat Dr, Ballito Business Park, Ballito, 4399
Principal place of business: 35 Moffat Dr, Ballito Business park, Ballito, 4399
Email: info@dabisa.co.za
Information Officer:Loyiso Toyi
Information Officer contact: info@dabisa.co.za

​

For privacy enquiries, emails sent to info@dabisa.co.za should be marked “Privacy Request”.

​

Under the Protection of Personal Information Act 4 of 2013 (“POPIA”), Dabisa will ordinarily act as the responsible party for personal information collected through the website.

​

Where Dabisa processes personal information contained in client-supplied project files solely on a client’s documented instructions, Dabisa may act as an operator on behalf of that client. Those processing activities should be governed by the applicable client agreement or data-processing agreement.

Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of information.

​

3.1 Contact and identity information

​

This may include your:

  • first and last name;

  • email address;

  • telephone number;

  • job title or position;

  • employer or organisation;

  • business address; and

  • professional or industry details.

​

3.2 Enquiry and assessment information

​

When you complete a contact form, BIM readiness assessment, checklist, resource request or similar form, we may collect:

  • your project type and sector;

  • a project description;

  • BIM maturity or compliance information;

  • software used, including Revit, Civil 3D, IFC or other platforms;

  • your organisation’s information-management practices;

  • your assessment responses and resulting score;

  • information about how you heard about Dabisa; and

  • the contents of messages or requests submitted to us.

​

3.3 Project and technical information

​

Where you engage us or are invited to submit files through an approved channel, we may process:

  • BIM models;

  • IFC, Revit, Civil 3D, CAD or PDF files;

  • asset registers;

  • equipment schedules;

  • model metadata and object properties;

  • project documentation;

  • Employer’s Information Requirements;

  • BIM Execution Plans;

  • Information Delivery Specifications;

  • facility-management information;

  • information concerning consultants, contractors, suppliers or project stakeholders; and

  • other technical or operational information associated with a built asset.

​

Project files may contain personal information relating to individuals other than the person submitting the file. The submitting party is responsible for ensuring that it is authorised to provide that information to Dabisa.

​

3.4 Website and device information

​

When you use the website, we or our technology providers may collect:

  • IP address;

  • approximate location derived from an IP address;

  • browser and device type;

  • operating system;

  • date and time of access;

  • referring website;

  • pages viewed;

  • links or buttons selected;

  • session information;

  • form interaction information;

  • cookie identifiers; and

  • diagnostic, performance and security logs.

​

3.5 Communications and marketing information

​

We may keep records of:

  • emails and other correspondence;

  • meeting notes;

  • requests for proposals or quotations;

  • marketing preferences;

  • subscriptions and unsubscribe requests; and

  • participation in webinars, demonstrations, events or surveys.

​

3.6 Client, supplier and commercial information

​

Where relevant, we may process:

  • contract and proposal information;

  • billing and invoicing details;

  • VAT or company registration information;

  • bank-account details;

  • procurement and supplier information;

  • authorised representatives and signatories; and

  • records needed to manage our commercial relationship.

​

We do not currently intend to collect payment-card information directly through the public website. Where online payment functionality is introduced, payment information should be processed by an authorised payment provider and this policy must be updated.

​

3.7 Special personal information

​

The public website is not intended to collect special personal information such as health information, biometric information, political opinions, religious beliefs or criminal information.

You should not submit special personal information through a general website form unless Dabisa has specifically requested it and appropriate safeguards have been agreed.

How We Collect Information

We collect personal information:

  • directly from you;

  • from your employer, client, consultant, contractor or authorised representative;

  • through website forms and downloadable-resource requests;

  • through cookies and similar technologies;

  • through meetings, correspondence and project engagements;

  • from project files supplied to us;

  • from public professional sources such as company websites, tender documents, professional directories or LinkedIn;

  • from referrals and business partners; and

  • from service providers supporting our website, communications and business operations.

Why We Process Personal Information

We may process personal information for the following purposes:

  • responding to enquiries and requests;

  • arranging meetings, demonstrations and assessments;

  • preparing proposals, quotations and statements of work;

  • delivering BIM compliance audits, data-population services, reporting dashboards, workflow standards and related services;

  • analysing BIM readiness or assessment responses;

  • validating submitted models and project data;

  • generating compliance reports and FM-ready asset datasets;

  • managing client and supplier relationships;

  • delivering requested resources or communications;

  • administering the website and improving its usability;

  • measuring website performance and engagement;

  • securing our systems and detecting fraud, abuse or unauthorised access;

  • meeting legal, regulatory, tax, accounting and contractual requirements;

  • establishing, exercising or defending legal rights;

  • conducting reasonable business development and direct marketing;

  • maintaining records of consent, objections and unsubscribe requests; and

  • carrying out corporate transactions, audits or due-diligence exercises.

Legal Grounds for Processing

Under POPIA, we process personal information where one or more of the following grounds applies:

  • you have consented to the processing;

  • processing is necessary to perform a contract with you or take steps requested by you before entering into a contract;

  • processing is required by law;

  • processing protects your legitimate interests;

  • processing is necessary to pursue the legitimate interests of Dabisa or a third party, provided those interests do not unjustifiably prejudice your rights; or

  • the information has deliberately been made public by you.

​

Where the EU General Data Protection Regulation or UK GDPR applies, our corresponding legal grounds may include consent, contractual necessity, compliance with a legal obligation and legitimate interests.

​

Our legitimate interests may include responding to business enquiries, delivering professional services, protecting project and company information, improving our services, maintaining business relationships and communicating with relevant professional contacts.

BIM Models and Confidential Project Information

BIM models, drawings and infrastructure information may contain commercially sensitive, security-sensitive or confidential information.

​

Do not upload BIM models, detailed drawings, infrastructure layouts, access-control information or confidential client documents through a general public contact form.

​

Where Dabisa requires such information, we should provide an approved transfer channel and, where appropriate, enter into a non-disclosure agreement, operator agreement or data-processing agreement.

​

Project information will only be used for the agreed assessment, validation, reporting, proposal or service-delivery purpose, together with related administration, security and legal requirements.

​

Dabisa will not use identifiable client models to train public artificial-intelligence systems or create unrelated products unless this has been expressly authorised in writing.

​

Where aggregated or de-identified information is used for internal analytics, service improvement or benchmarking, Dabisa will take reasonable steps to prevent the information from identifying a client, project or individual.

Assessment Scores and Automated Processing

Dabisa may use rules-based processes to calculate BIM readiness, compliance or information-quality scores.

​

These scores are indicative tools intended to support professional review and project discussions. They do not constitute statutory approval, engineering certification, regulatory approval or a decision producing legal effects for an individual.

​

We do not intend to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.

Cookies and Analytics

The website may use cookies, pixels, local storage and similar technologies.

​

These technologies may be used to:

  • operate and secure the website;

  • remember settings and consent preferences;

  • process form submissions;

  • measure traffic and website performance;

  • understand how visitors interact with pages and content; and

  • support marketing activities where enabled.

​

Our website is currently hosted using Wix, which may provide essential website, security, form and analytics functionality. Other services may be added or removed over time.

Where required by applicable law, non-essential analytics or marketing cookies will only be activated after the visitor has provided consent.

​

Visitors must be able to reject non-essential cookies and change their preferences later. More detailed and current information should be provided through the website’s cookie-preference tool or a separate Cookie Notice.

Direct Marketing

We may send information about Dabisa’s services, reports, events, resources or industry updates where:

  • you have consented;

  • you are an existing client and the communication concerns similar services, where permitted by law; or

  • another lawful basis allows the communication.

​

Every electronic marketing communication will provide a reasonable method of unsubscribing.

You may withdraw marketing consent or object to direct marketing at any time by using the unsubscribe function or contacting us.

​

We may retain limited information on a suppression list to ensure that we respect an unsubscribe request.

When We Share Personal Information

We may disclose personal information to:

  • website hosting and form-service providers;

  • cloud-storage and file-transfer providers;

  • analytics, CRM, email and communication providers;

  • IT, cybersecurity and technical-support providers;

  • consultants, subcontractors and professional advisers;

  • accountants, auditors, insurers and legal advisers;

  • a client or project team where disclosure is necessary for the agreed engagement;

  • public authorities, regulators or law-enforcement bodies where required by law;

  • a purchaser, investor or adviser involved in a merger, sale, restructuring or due-diligence process; and

  • other parties where you have authorised the disclosure.

​

Service providers may only process information for authorised purposes and must be subject to appropriate confidentiality, security and data-protection obligations.

​

We do not sell personal information for monetary compensation.

Cross-Border Processing

ome of our hosting, software, communication, analytics or cloud-service providers may process information outside South Africa.

​

Where personal information is transferred outside South Africa, we will take reasonable steps to ensure that the transfer complies with POPIA, including by using:

  • a recipient subject to a law, binding corporate rules or agreement providing an adequate level of protection;

  • contractual safeguards;

  • consent, where legally appropriate; or

  • another lawful transfer mechanism.

​

Where EU or UK data-protection law applies, additional approved transfer safeguards may be required.

Security

We use reasonable and appropriate technical and organisational safeguards designed to protect personal information against loss, unauthorised access, interference, alteration, disclosure or destruction.

​

Depending on the nature of the information, safeguards may include:

  • access controls;

  • multi-factor authentication;

  • encryption in transit;

  • secure file-transfer methods;

  • backup and recovery controls;

  • confidentiality obligations;

  • service-provider due diligence;

  • malware and vulnerability controls;

  • activity logging; and

  • incident-response procedures.

​

No internet transmission or information system is completely secure. We therefore cannot guarantee absolute security.

​

Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and make notifications required by applicable law.

Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required by law, a contract or a legitimate business need.

​

Subject to specific legal or contractual requirements, our intended retention approach is:

  • general website enquiries: up to 24 months after the last meaningful interaction;

  • readiness assessments and resource requests: up to 24 months;

  • marketing records: until consent is withdrawn or an objection is received, with limited suppression information retained thereafter;

  • website security and technical logs: generally up to 12 months;

  • unsuccessful proposals: generally up to 3 years;

  • client, contractual, accounting and project-administration records: for the contractual period and any applicable legal, tax, audit or claims period, commonly between 5 and 7 years;

  • BIM models and client project files: for the period stated in the client agreement, after which they should be returned, securely deleted, archived or de-identified as agreed; and

  • legal-dispute records: until the dispute and any relevant prescription or appeal period have ended.

​

These periods must be aligned with Dabisa’s actual retention schedule before publication.

Your Rights

Subject to POPIA and any applicable limitations, you may have the right to:

  • ask whether we hold personal information about you;

  • request access to that information;

  • request correction or updating of inaccurate information;

  • request deletion or destruction where we are no longer authorised to retain the information;

  • object to processing based on certain lawful grounds;

  • object to direct marketing;

  • withdraw consent where processing is based on consent;

  • request information about the identity of third parties that have had access to your information, where legally required; and

  • lodge a complaint with the Information Regulator.

​

Where the GDPR or UK GDPR applies, you may also have rights relating to restriction, portability and certain forms of automated decision-making.

​

We may ask for information needed to confirm your identity before processing a request. Some requests may be refused or limited where the law permits or requires us to retain or continue processing the information.

​

Requests may be submitted to info@dabisa.co.za with the subject line “Privacy Request”.

Complaints

We encourage you to contact Dabisa first so that we can attempt to address your concern.

​

You may also lodge a complaint with the Information Regulator of South Africa through its official complaints or eServices portal.

​

Information Regulator contact details

Telephone: 010 023 5200
Toll-free: 0800 017 160
General enquiries: enquiries@inforegulator.org.za

​

Regulator contact details may change and should be confirmed periodically.

Third-Party Websites

The website may contain links to LinkedIn, YouTube, software providers, standards bodies or other external websites.

Those organisations process information under their own terms and privacy policies. Dabisa is not responsible for the privacy practices or content of third-party websites.

Children

The website and Dabisa’s professional services are directed at organisations and adult professionals. We do not knowingly collect personal information from children through the website.

​

If we become aware that a child’s personal information has been submitted without proper authority, we will take reasonable steps to delete or appropriately restrict that information.

Changes to This Policy

We may update this Privacy Policy to reflect changes to our services, technology, service providers or legal obligations.

 

The updated version will be published with a revised effective date. Material changes may also be communicated through the website or another appropriate channel.

Contact Us

Questions, requests or complaints about this policy may be sent to:

​

Dabisa Consulting (Pty) Ltd
Attention: Information Officer
Email: info@dabisa.co.za

bottom of page