Legal
Privacy Policy
Last updated: 6 July 2026
This Privacy Policy explains how DRMR Digital (“we”, “us”, “our”), the South African business behind NexaDesk, collects and uses personal information through the nexadesk.tech website and the NexaDesk licensing platform. We are the “responsible party” under the Protection of Personal Information Act 4 of 2013 (“POPIA”) and, where the EU/UK General Data Protection Regulation (“GDPR”) applies to a visitor or customer, the “controller” for that processing.
You can contact our Information Officer at [email protected] (subject line: “Privacy”) for anything related to this policy, including access, correction or deletion requests.
1. What we collect
Enquiries
When you use our contact form or email us, we collect the details you submit — typically your name, email address and message. Submissions are stored securely in our website system so we can respond and keep a record of the conversation.
Orders and billing
When you buy a subscription or add-on we collect your name, email address, billing address, phone number and company name (if provided), together with your order history. We use WooCommerce to run the checkout on our own server.
Payments
Card payments are processed by Yoco, a South African payment services provider. Your card number and security details are entered on and processed by Yoco’s secure payment infrastructure — we never receive or store your full card details. We receive only a payment confirmation and reference. Yoco’s own privacy policy is available at yoco.com.
Licence validation (telemetry)
Licensed NexaDesk instances contact our licensing platform periodically (including a daily check-in) to validate the licence. This transmits the licence key, an instance identifier and URL, product version, technician seat usage, enabled features and timestamps. It does not transmit ticket content, attachments or the personal information of your instance’s end users.
Technical data
Like most websites, our servers and our network provider (Cloudflare) record technical data such as IP address, browser type and pages requested, used for security, debugging and abuse prevention.
2. Why we use it, and our lawful bases
- Responding to enquiries — on the basis of your consent and our legitimate interest in responding to you (POPIA s 11(1)(a) and (f); GDPR art 6(1)(a) and (f)).
- Processing orders, issuing licences, billing and support — necessary to perform our contract with you (POPIA s 11(1)(b); GDPR art 6(1)(b)).
- Tax and accounting record-keeping — necessary to comply with legal obligations (POPIA s 11(1)(c); GDPR art 6(1)(c)).
- Licence enforcement, security and fraud prevention — our legitimate interests in protecting the Service (POPIA s 11(1)(f); GDPR art 6(1)(f)).
- Service communications (order confirmations, renewal and licensing notices) — necessary to perform our contract.
- Direct marketing — only with your consent as required by section 69 of POPIA, and every message will include a working opt-out. We do not send unsolicited marketing.
3. Your helpdesk instance: you are the responsible party
NexaDesk is self-hosted. All tickets, contacts, attachments and end-user personal information inside your NexaDesk instance are processed on your infrastructure, under your control. For that information, you (our customer) are the responsible party under POPIA and/or the controller under the GDPR — DRMR Digital does not have access to it and is not a processor of it. This policy covers only the information described in section 1.
4. Cookies
This Site uses only functional cookies that are necessary for it to work — we do not use advertising or cross-site tracking cookies:
- WooCommerce cookies (woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*) — remember your cart and checkout session; kept for up to 2 days.
- WordPress cookies (wordpress_logged_in_*, wordpress_sec_*) — set only for staff members who log in to administer the Site.
- Cloudflare cookies (e.g. __cf_bm) — set by our network provider for bot protection and security.
Because these cookies are strictly necessary, they do not require prior consent. If we ever introduce analytics or marketing cookies, we will update this policy and ask for consent first.
5. Who we share personal information with
We do not sell personal information. We share it only with service providers (“operators” under POPIA, “processors” under the GDPR) who need it to run the Service, under obligations of confidentiality and security:
- Yoco (South Africa) — payment processing.
- Cloudflare, Inc. (USA/global) — content delivery, DNS and security in front of our website and licensing platform.
- Email service providers — delivery of transactional email such as order confirmations.
We may also disclose personal information where required by law, court order or a competent public authority, or to protect our legal rights.
6. International transfers
Our servers are located in South Africa. Some providers (such as Cloudflare) route traffic through infrastructure outside South Africa. Where personal information leaves South Africa we rely on section 72 of POPIA — the recipient is subject to a law, binding corporate rules or a contract providing substantially similar protection, or the transfer is necessary to perform our contract with you. For individuals in the EEA/UK, our providers rely on recognised GDPR transfer mechanisms such as adequacy decisions and Standard Contractual Clauses.
7. How long we keep it
- Enquiries: up to 24 months after the conversation ends, then deleted.
- Orders, invoices and billing records: at least 5 years, as required by South African tax legislation.
- Licence and telemetry records: for the life of the subscription plus 12 months.
- Server and security logs: typically 30–90 days.
When a retention period ends, records are deleted or de-identified.
8. Security
We protect personal information with appropriate, reasonable technical and organisational measures as required by section 19 of POPIA, including TLS encryption in transit, access controls, hardened and patched infrastructure, rate limiting, and payment processing delegated to a PCI-DSS compliant provider. If a data breach occurs that compromises your personal information, we will notify the Information Regulator and affected individuals as required by section 22 of POPIA and, where the GDPR applies, the relevant supervisory authority within 72 hours where feasible.
9. Your rights
Under POPIA you have the right to: request confirmation of whether we hold personal information about you and access to it (section 23); request correction or deletion of inaccurate, irrelevant, excessive, out-of-date or unlawfully obtained information (section 24); object to processing, including for direct marketing (sections 11(3) and 69); withdraw consent at any time; and not be subject to a decision based solely on automated processing (section 71). Access requests are handled under the Promotion of Access to Information Act 2 of 2000 (PAIA).
If the GDPR applies to you, you additionally have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent without affecting prior processing, and to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email [email protected]. We will respond within a reasonable time and at most within one month. You will not be charged for a reasonable request.
You also have the right to complain to the South African Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: [email protected] (enquiries) / [email protected] (complaints)
Website: inforegulator.org.za
10. Children
The Site and Service are aimed at businesses and are not directed at children under 18. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The current version, with its “Last updated” date, is always published at this address. Material changes will be highlighted on the Site or notified to active customers by email.
12. Contact
DRMR Digital — Information Officer
Email: [email protected]
Website: https://nexadesk.tech
South Africa