Privacy Policy

Brightside Marketing

Effective date: 20 July 2026

1. Introduction

Brightside Marketing (“Brightside”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable South African laws.

This Privacy Policy explains how we collect, use, store, share and protect personal information when you:

  • Visit brightsidemarketing.co.za;
  • Contact or communicate with us;
  • Subscribe to our newsletter or marketing communications;
  • Request information, an audit, proposal or quotation;
  • Become a client, supplier, contractor or business partner;
  • Attend one of our events, workshops or webinars; or
  • Otherwise interact with Brightside Marketing.

For purposes of POPIA, Brightside Marketing is the “responsible party” where we determine why and how personal information is processed.

Where we process personal information on behalf of a client, Brightside may act as an “operator” under POPIA. In those circumstances, the client remains the responsible party and its privacy policy may also apply.

2. What is personal information?

Personal information is information relating to an identifiable natural or juristic person. This may include an individual, company, close corporation, trust or other identifiable organisation.

3. Personal information we collect

Depending on how you interact with us, we may collect:

3.1 Contact information

This may include your:

  • Name and surname;
  • Job title;
  • Company or organisation;
  • Email address;
  • Telephone or mobile number;
  • Business or postal address; and
  • Preferred method of communication.

3.2 Enquiry and communication information

We may collect information you provide when you:

  • Complete a website form;
  • Request a consultation, proposal, quotation or marketing audit;
  • Send us an email or message;
  • Communicate with us through social media;
  • Provide feedback or participate in a survey; or
  • Attend a meeting, event, webinar or workshop.

This may include the contents of messages, marketing requirements, business challenges, project briefs and other information you choose to provide.

3.3 Client and supplier information

When working with clients, suppliers, contractors or partners, we may process:

  • Contact and account information;
  • Agreements, proposals and project records;
  • Billing, invoicing and payment information;
  • Marketing strategies, campaign information and brand assets;
  • Website, social media and advertising account information;
  • Customer or prospect information supplied for campaign purposes; and
  • Performance, analytics and reporting data.

3.4 Newsletter and marketing information

When you subscribe to a newsletter, download content or request marketing information, we may collect your name, email address, telephone number, company details, communication preferences and information about how you interact with our communications.

3.5 Website and technical information

When you use our website, certain information may be collected automatically, including:

  • Internet Protocol address;
  • Browser type and version;
  • Device type and operating system;
  • General location derived from your IP address;
  • Pages visited and links selected;
  • Date, time and duration of visits;
  • Referring website or campaign;
  • Form interactions and conversion information; and
  • Cookie identifiers and similar technical data.

3.6 Information obtained from other sources

Where permitted by law, we may receive information from:

  • Clients, suppliers and business partners;
  • Publicly available business directories and websites;
  • Social and professional networking platforms;
  • Marketing, analytics and lead-generation platforms;
  • Event organisers; and
  • Referral partners.

We will only use information obtained from third parties where we have a lawful reason to do so.

4. How we collect personal information

We may collect personal information:

  • Directly from you;
  • Through our website and online forms;
  • Through email, telephone, video calls or in-person meetings;
  • Through newsletter subscriptions;
  • Through social media and advertising platforms;
  • Through cookies and similar technologies;
  • From clients where we provide marketing services on their behalf;
  • From business partners or referrals; and
  • From legitimate publicly available sources.

Where reasonably practicable, we collect personal information directly from the person concerned.

5. How we use personal information

We may process personal information to:

  • Respond to enquiries and requests;
  • Arrange consultations and meetings;
  • Prepare quotations, proposals and agreements;
  • Provide branding, marketing, website, content, social media, SEO, advertising, email marketing and related services;
  • Manage client projects and relationships;
  • Conduct marketing audits, research and strategic planning;
  • Create, manage, measure and optimise campaigns;
  • Process payments, invoices and financial records;
  • Communicate operational or service-related information;
  • Send newsletters, insights, event invitations and marketing communications;
  • Manage suppliers, contractors and business partners;
  • Improve our website, services and customer experience;
  • Analyse website traffic, campaign performance and user behaviour;
  • Protect our website, systems, staff, clients and business;
  • Prevent fraud, misuse and security incidents;
  • Establish, exercise or defend legal claims;
  • Comply with legal, regulatory, tax and accounting obligations; and
  • Fulfil other purposes that are compatible with the reason the information was collected.

We may also create aggregated or de-identified information that cannot reasonably identify a person. We may use such information for research, reporting, planning and service improvement.

6. Lawful reasons for processing

We process personal information only where there is a lawful justification, including where:

  • You have consented to the processing;
  • Processing is necessary to enter into or perform a contract;
  • Processing is required by law;
  • Processing protects your legitimate interests;
  • Processing protects the legitimate interests of another person; or
  • Processing is necessary for our legitimate business interests, provided those interests do not unjustifiably interfere with your privacy.

You may withdraw consent at any time. Withdrawal will not affect processing that occurred lawfully before consent was withdrawn.

7. Direct marketing

We may send you marketing communications about Brightside’s services, events, insights and resources where:

  • You have consented to receive them;
  • You are an existing client and the communication relates to similar services, where permitted by law; or
  • Another lawful basis allows us to contact you.

Every electronic marketing communication will provide a reasonable way to unsubscribe or opt out.

You may object to direct marketing at any time by:

We will not charge you for opting out, although your network provider’s ordinary communication costs may apply.

Operational communications about active projects, contracts, accounts or services are not marketing messages and may continue where necessary.

8. Cookies and similar technologies

Our website may use cookies, pixels, tags and similar technologies to operate correctly, remember preferences, understand website usage and measure marketing performance.

These technologies may include:

Essential cookies

These are required for core website functionality, security, form submission and user preferences.

Analytics cookies

These help us understand how visitors use the website, which pages perform well and where the experience can be improved.

Functional cookies

These may remember preferences or enable embedded content and enhanced website features.

Advertising cookies

Where used, these may help measure campaigns, limit repeated advertising and show more relevant content on third-party platforms.

You can control cookies through your browser or the website’s cookie controls, where available. Blocking some cookies may affect website functionality.

Where non-essential cookies process personal information, we will seek consent where required.

9. When we share personal information

We may share personal information with trusted third parties where reasonably necessary, including:

  • Website hosting, IT support and cybersecurity providers;
  • Cloud storage and business software providers;
  • Email, newsletter and customer relationship management platforms;
  • Analytics, advertising and social media platforms;
  • Designers, developers, copywriters, researchers and other contractors;
  • Payment, banking and accounting providers;
  • Auditors, insurers, lawyers and other professional advisers;
  • Clients where information is processed as part of an authorised campaign;
  • Regulators, courts, law-enforcement agencies and public authorities; and
  • A purchaser, investor or successor in connection with a proposed business transaction.

Service providers processing information for us must process it only for authorised purposes and apply appropriate confidentiality and security safeguards.

We do not sell personal information.

10. Client-provided information

Clients may provide Brightside with personal information relating to their customers, prospects, employees, suppliers or other stakeholders.

When processing this information on a client’s instructions:

  • The client is generally the responsible party;
  • Brightside acts as an operator;
  • We process the information only for the agreed services;
  • We apply appropriate confidentiality and security measures; and
  • The client is responsible for ensuring that the information was collected lawfully and that appropriate notices or consent were provided.

11. International transfers

Some service providers, cloud platforms or technology systems may process or store information outside South Africa.

Where personal information is transferred internationally, we will take reasonable steps to ensure that the recipient is subject to:

  • A law providing an adequate level of protection;
  • Binding corporate rules;
  • A binding agreement providing appropriate safeguards;
  • Consent, where appropriate; or
  • Another lawful basis permitted by POPIA.

12. Information security

We use reasonable technical and organisational safeguards appropriate to the nature of the information we process. These may include:

  • Access controls and password protection;
  • Multi-factor authentication where available;
  • Secure hosting and encrypted connections;
  • Software, plugin and security updates;
  • Data backup and recovery measures;
  • Confidentiality obligations;
  • Restricted access based on business need;
  • Supplier and operator agreements; and
  • Procedures for responding to suspected security incidents.

No internet transmission or storage system is completely secure. We therefore cannot guarantee absolute security, but we will take reasonable steps to protect personal information in our possession or control.

Where a security compromise affects personal information, we will investigate and notify the Information Regulator and affected persons where required by law.

13. How long we keep personal information

We retain personal information only for as long as reasonably necessary to:

  • Fulfil the purpose for which it was collected;
  • Provide services and maintain business records;
  • Meet contractual obligations;
  • Comply with legal, tax, accounting or regulatory requirements;
  • Resolve disputes;
  • Enforce agreements; or
  • Establish, exercise or defend legal claims.

When information is no longer required, we will securely delete, destroy, anonymise or de-identify it, subject to applicable law and reasonable backup cycles.

14. Your rights

Subject to POPIA and other applicable laws, you may have the right to:

  • Ask whether we hold personal information about you;
  • Request access to your personal information;
  • Request correction or updating of inaccurate information;
  • Request deletion or destruction of information that we are no longer authorised to retain;
  • Object to certain processing;
  • Object to direct marketing at any time;
  • Withdraw consent;
  • Request that processing be restricted where appropriate;
  • Ask about the identity of third parties who have had access to your information; and
  • Lodge a complaint with the Information Regulator.

We may need to verify your identity before fulfilling a request. Certain rights may be limited where we are legally required or permitted to retain or process the information.

Requests can be sent to nadia@brightsidemarketing.co.za.

15. PAIA requests

Requests for access to records under the Promotion of Access to Information Act 2 of 2000 (“PAIA”) may be subject to Brightside’s PAIA Manual, prescribed forms, identity-verification requirements and applicable fees.

PAIA requests may be submitted using the contact details below.

16. Children’s personal information

Our website and services are intended primarily for businesses and adults.

We do not knowingly collect personal information from children without the consent of a competent person or another lawful justification. Please contact us if you believe that a child has provided personal information without proper authorisation.

17. Third-party websites and platforms

Our website may contain links to third-party websites, social networks, embedded content or external platforms.

Those third parties operate under their own privacy policies and practices. Brightside is not responsible for how an independent third party collects or processes personal information.

18. Changes to this policy

We may update this Privacy Policy to reflect changes in our services, technology, business practices or legal requirements.

The latest version will be published on our website with an updated effective date. Material changes may also be communicated through other reasonable channels.

19. Contact Brightside Marketing

For privacy questions, objections, complaints or requests relating to personal information, contact:

Brightside Marketing

Building A, Ground Floor
Freestone Business Park
135 Patricia Road
Sandown, Sandton
2031
South Africa

Email: nadia@brightsidemarketing.co.za
Website: brightsidemarketing.co.za

20. Information Regulator

You may lodge a complaint with the Information Regulator if you believe your personal information has been processed unlawfully.

Information Regulator South Africa

Woodmead North Office Park
54 Maxwell Drive
Woodmead, Johannesburg
2191

POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Toll-free: 0800 017 160