PRIVACY POLICY
Tim respects your privacy. Review our policy to understand how we protect and manage your data.
TIM Africa Privacy Policy
Updated on 30th September 2026.
This policy explains how TIM Africa collects, uses, shares and protects personal information, and how you can exercise your privacy rights. It covers our website, enquiries, business relationships, marketing, content production and services. Separate notices may provide more detail for a particular project, recruitment process, event or competition.
1 Who we are
TIM Africa (Pty) Ltd, registration number 2024/110206/07, is referred to in this policy as “TIM Africa”, “we”, “us” or “our”. We operate www.tim.africa.
Address: Level 1, 8 Bishop Court, Delamore Road, Hillcrest, South Africa.
Information Officer: Lynn Moustache | Managing Director
Privacy email: lynn.moustache@tim.africa, marked “For the Information Officer”
Telephone: 073 219 7054
When we decide why and how personal information is used, we are the “Responsible Party” under the Protection of Personal Information Act 4 of 2013 (POPIA). Personal information includes information about an identifiable living person and, where applicable, an identifiable existing company or other legal entity.
2 Information we collect
Depending on your interaction with us, we may collect:
- Contact and business details, such as your name, email address, telephone number, organisation and role.
- Enquiries, correspondence, meeting notes, project briefs, contracts and information you provide when working with us.
- Billing, payment and transaction information needed to administer our business relationship.
- Photographs, video, voice recordings, biographies and social media information relevant to agreed content or campaigns.
- Website and campaign information, such as IP addresses, device and browser details, pages visited and interactions with content, where the relevant tools are used.
- Marketing preferences, consent records and records of requests or objections.
We collect only information that is relevant and reasonably necessary for a specific purpose. Please avoid sending sensitive information unless it is needed for the matter you are discussing with us.
3 Where information comes from
We normally collect information directly from you through forms, emails, calls, meetings, bookings or our services. We may also receive it from a client, your employer, an authorised representative, a referral source, a public business directory or a public professional profile, where POPIA permits this.
If we collect information indirectly, we will explain the source and purpose before collection or as soon as reasonably practicable afterwards, unless a lawful exception applies. Publicly available information is still subject to privacy and direct-marketing requirements.
4 Why we use your information
We use personal information to respond to enquiries, prepare proposals, provide and manage services, produce agreed content, administer contracts and payments, maintain business records, improve our services, protect our systems, resolve disputes and meet legal obligations. Marketing is subject to section 5 below.
Our legal basis depends on the purpose. It may be your consent; steps needed to conclude or perform a contract with you; a legal obligation; protection of your legitimate interests; or a legitimate interest of TIM Africa or a third party, where the processing is necessary and lawful. A general business interest does not override the specific rules for electronic direct marketing.
Providing information is generally voluntary. We may need particular details to respond, provide a service or fulfil a legal obligation. We will identify mandatory fields and explain the consequences of not providing them. Where a law requires collection, the relevant notice will identify that law. Without necessary information, we may be unable to assist or provide the requested service.
We will use information for a new purpose only if that use is compatible with the original purpose or otherwise permitted by law. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect lawful processing already carried out.
5 Marketing and your choices
We send electronic direct marketing, including email, SMS, WhatsApp and marketing calls, only with your consent or where POPIA’s existing-customer exception applies. That exception requires contact details obtained in the context of a sale, marketing of our own similar products or services, and a free, simple opportunity to object when details are collected and in every marketing communication.
Where consent is required and you have not previously withheld it, POPIA allows us to approach you once to request it in the prescribed manner.
Marketing communications identify the sender and provide a way to stop further marketing. You can unsubscribe, use the opt-out method in the message or email info@tim.africa. We honour objections and applicable pre-emptive blocks under the Consumer Protection Act and its direct-marketing regulations. Absence from an opt-out registry does not give us permission to market to you.
We may keep a limited suppression record to ensure that you are not contacted again for marketing. Necessary service and account communications may continue where there is a lawful basis.
6 Cookies and online tools
Cookies are small files placed on your device. Similar tools, such as tracking pixels, may collect information about website or campaign activity. Necessary tools support functions such as security and remembering your privacy choices.
Where we use optional analytics, advertising or similar tracking tools, we will explain their purposes and obtain consent before activating them. You can refuse optional tools or withdraw consent through the website’s privacy settings. Browser controls also allow you to manage cookies, although disabling necessary cookies may affect website functions.
External websites, social platforms and embedded services may process information under their own privacy notices. We will explain relevant third-party processing when we introduce those services.
7 Who receives your information
We may share relevant information with authorised team members and service providers that help us deliver our work. Depending on the service, these may include hosting, cloud storage, email, customer-management, accounting, payment, analytics, advertising, production and technology providers, as well as professional advisers.
We may also share information with the client or production partner connected to your project, a regulator or authority where legally required, or another person where a lawful basis permits the disclosure. We do not sell personal information.
Providers processing information on our behalf must act under our authorisation. We require written arrangements addressing confidentiality and appropriate security. Platforms that determine their own processing purposes may act as separate responsible parties; their privacy notices also apply.
8 Information processed outside South Africa
Some service providers or publishing platforms may store or process information outside South Africa. We will transfer personal information only where section 72 of POPIA permits it. This may involve a law or binding agreement providing adequate protection, your consent, or another applicable statutory ground.
Where we rely on adequate protection, the safeguards must uphold principles substantially similar to POPIA and address onward transfers. Where prior authorisation is required, including certain transfers of children’s or special personal information to inadequately protected destinations, we will obtain it before the processing proceeds.
9 Artificial intelligence and automation
Where we use AI tools to assist with agreed work, we limit the personal information supplied, check the purpose and provider safeguards, and apply the same privacy requirements as for other service providers. We will not use personal information to train a general-purpose AI model without a separate lawful basis and appropriate notice.
Decisions based solely on automated profiling that have legal consequences or substantially affect you are subject to POPIA’s restrictions. If a permitted exception applies, we will provide the safeguards required by law, including an opportunity to make representations where required.
10 Client campaigns and production work
When we process information solely on a client’s instructions, for example by managing its campaign contacts or website enquiries, we act as an “operator”. The client remains responsible for deciding the purpose and lawful basis. We process that information under the agreed instructions and applicable law, and assist the client with privacy requests and security incidents.
The client’s privacy notice should explain that processing. If you contact us about information we hold for a client, we will help direct the request to the relevant responsible party and assist as appropriate. Where we also decide purposes of our own, this policy applies to those purposes.
For podcasts, filming, photography and other production activities, the project notice or release will explain the intended recordings, editing, publication, promotional uses and channels. This general policy is not a substitute for a project-specific notice or permission where required.
Published content may be accessible worldwide and copied or shared by others. Contact us if you have a privacy concern or wish to request removal. We will assess the request against your rights, the lawful basis and any applicable retention obligations; we cannot guarantee removal of copies held independently by others.
11 Children and sensitive information
We process children’s personal information only where POPIA permits it, including with prior consent from a legally competent person where applicable. For productions involving children, we will provide suitable information and obtain the necessary permissions before recording or publication.
Special personal information includes information about health, race, religious beliefs, political views, trade union membership, sex life, biometrics and certain criminal matters. We process this information only where a specific POPIA authorisation applies, with safeguards appropriate to its sensitivity.
12 How long we keep information
We keep information only for as long as we are authorised to retain it. The period depends on the purpose, legal requirements, contractual needs and any lawful need to retain evidence or resolve a dispute. Different periods may apply to enquiries, financial records, contracts, consent records, raw recordings and published content.
Once retention is no longer authorised, we securely delete, destroy or de-identify the information so that it cannot be reconstructed in an identifiable form. Backup copies are managed through the relevant deletion cycle and remain protected while retained. You may ask our Information Officer about the retention period or criteria for a particular record.
13 Security and incidents
We apply reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised destruction, access and unlawful processing. Measures must be appropriate to the risks and reviewed as those risks change.
If there are reasonable grounds to believe an unauthorised person has accessed or acquired personal information for which we are responsible, we will notify the Information Regulator and affected people as soon as reasonably possible, subject to POPIA’s exceptions and permitted delays. Notifications will explain the possible consequences, steps taken and protective measures you can take. Where we act as an operator, we notify the relevant responsible party immediately.
14 Your privacy rights
Subject to POPIA and applicable access-to-information rules, you may:
- Ask us to confirm, free of charge, whether we hold personal information about you.
- Request access to that information and details of the third parties, or categories of third parties, that have had access to it.
- Request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained.
- Request deletion or destruction of a record we are no longer authorised to retain.
- Object on reasonable grounds relating to your particular situation where processing relies on the legitimate interests specified in section 11(1)(d) or (f), unless legislation provides for that processing.
- Object to direct marketing, withdraw consent where we rely on it, and request restriction of processing where section 14(6) applies.
- Complain to the Information Regulator and pursue available legal remedies.
Send requests to info@tim.africa, marked “For the Information Officer”. We may need reasonable proof of identity or authority before disclosing information or acting on a request. We will help you use the applicable forms: Form 1 or a substantially similar form for objections, and Form 2 or a substantially similar form for correction or deletion requests. Contact us if you need assistance submitting a request in another accessible manner.
Objections and correction or deletion requests are free. Access to copies may attract a prescribed fee where permitted; we will explain any fee before proceeding. We handle requests within the periods required by applicable law and explain any lawful refusal or limitation. A deletion request does not override a lawful obligation to retain a record.
Requests for access to records may also fall under the Promotion of Access to Information Act 2 of 2000 (PAIA). Our PAIA Manual explains the applicable process.
15 Complaints
You may raise a concern with our Information Officer. You also have the right to complain directly to the Information Regulator without first contacting us.
Information Regulator South Africa
Website: https://inforegulator.org.za
Complaints portal: https://eservices.inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Use the Regulator’s current complaint process and Form 5 where applicable. Its website provides forms and assistance.
16 Updates to this policy
We may update this policy when our practices or legal requirements change. We will publish the revised policy with its effective date and take appropriate steps to notify you of material changes. Where a change requires new consent, we will request it separately.
Effective date: 01 October 2026
