Privacy Policy
Last updated 2 August 2026
We try to keep our policies as clear, fair, and readable as possible. This Privacy Policy explains how Atomic (Pty) Ltd (“Atomic”, “we”, “us”, “our”) collects, uses, stores, shares, and protects your personal information.
As a member of the Internet Service Providers’ Association of South Africa (ISPA), we have committed to respecting the constitutional right of our customers to personal privacy, including the privacy of their communications. This policy is intended to give effect to our obligations under the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and other applicable South African laws.
Related documents:
1. What is personal information?
POPIA defines “personal information” broadly as any information relating to an identifiable living natural person, or where applicable an identifiable juristic person. This includes things like your name, contact details, identity number, address, financial information, online identifiers (such as IP addresses), and your communications with us.
2. Personal information we collect
We collect personal information in the following circumstances:
- When you complete a form on our website โ including order, contact, support, and enquiry forms.
- When you become and remain a customer โ including identifying information (such as your name, identity or passport number where required, and date of birth), contact details, service address, billing and payment information, and account credentials.
- When you use our services โ including communications-related information such as connection logs, IP address assignments, session times, and traffic volumes, which we are required to retain under the Regulation of Interception of Communications and Provision of Communication-Related Information Act, 70 of 2002 (“RICA”).
- When you communicate with us โ including correspondence with our support, billing, sales, or accounts teams.
- When you use our website โ including information collected through cookies and similar technologies (see clause 8 below).
3. Why we collect and process personal information
The purpose for which information is collected is indicated at the point of collection. In general, we process personal information for the following purposes:
- To establish, verify, and maintain your identity as a customer of Atomic for the duration of your service relationship with us.
- To provide, manage, support, and bill for the services you have ordered.
- To respond to enquiries, complaints, and support requests.
- To comply with our legal obligations, including those imposed by RICA, the Tax Administration Act, the Electronic Communications and Transactions Act, the Companies Act, the Financial Intelligence Centre Act (“FICA”) where applicable, and any other applicable law.
- To protect our legitimate interests and those of our customers, including network security, fraud prevention, abuse mitigation, and debt recovery.
- Where you have consented, or where you are an existing customer in respect of similar products or services, to send you marketing communications about our products and services.
We will not use collected information for any purpose other than that stated upon collection, unless we have your consent or unless the further processing is required or authorised by law.
4. Providing your information is voluntary
It is not mandatory for you to provide personal information through our website forms. However, if you choose not to provide requested information, we may be unable to fulfil your order, resolve your query, or provide you with services.
5. When we share your personal information
We share personal information with third parties only as necessary to provide services to you, to operate our business, or to comply with our legal obligations. Recipients may include:
- Fibre Network Operators (“FNOs”) โ to fulfil or support your order with the relevant FNO. FNOs may share your contact details with their third-party contractors who provide on-site services related to the fibre service.
- Our service providers โ including support, accounts, legal, regulatory, communications platform, hosting, and financial service providers.
- Law enforcement, regulatory authorities, and courts โ where required or authorised by law, including under RICA.
- Professional advisors โ such as auditors and attorneys, under obligations of confidentiality.
Where we engage a third party to process personal information on our behalf (an “operator” in POPIA terminology), we require that operator to process the information only in accordance with our instructions and to maintain appropriate security safeguards.
We will not sell your personal information to third parties.
6. Cross-border transfers
Some of our service providers (including communications platforms and cloud hosting providers) may process personal information outside South Africa. Where this occurs, we take reasonable steps to ensure that the recipient is bound by laws, binding corporate rules, or contractual terms that provide a level of protection for personal information substantially similar to that required under POPIA.
7. How long we keep your personal information
We retain personal information only for as long as is necessary to fulfil the purpose for which it was collected, or for longer where required or authorised by law. Different categories of information are subject to different retention periods:
- Customer account and identifying information โ retained for the duration of your service relationship with Atomic, and thereafter for the period required by applicable law, our reasonable operational requirements, or any unresolved dispute or claim.
- Billing, tax, and accounting records โ retained for at least five years from the relevant tax year, as required by the Tax Administration Act and related legislation.
- Communications-related information โ retained for the minimum period prescribed by RICA, and in any event for as long as required by law.
- Website form submissions (including general enquiries, contact requests, and support requests not linked to an active customer account) โ retained for three years from the date of submission, unless a longer period is required by law or is reasonably necessary for our operations.
- Records relating to ongoing or anticipated disputes, complaints, or legal proceedings โ retained until the matter is resolved and any applicable appeal or limitation period has expired.
Once we are no longer authorised or required to retain personal information, we will destroy, delete, or de-identify it in a manner that prevents its reconstruction in an intelligible form.
8. Cookies and website tracking
Our website uses cookies and similar technologies to help us provide a better experience and to understand how the site is used.
A cookie is a small file placed on your device that keeps a record of your interaction with the website. We use cookies to:
- Enable core website functionality.
- Compile anonymised statistics about how the website is used, so we can improve it.
- Tailor advertising and content where relevant. We may use third-party cookies from advertising or analytics providers for this purpose.
Cookies on their own are not used to identify individual users. If you do not want cookies to be used, you can change your browser settings to block or delete them. Please note that some features of our website may not work properly if cookies are disabled.
9. Network monitoring and security
To ensure that we provide a secure service and to protect both you and us from fraudulent and unlawful activity, we may monitor network traffic and service usage to the extent permitted by applicable law. We do not monitor the content of your communications except where required by law (for example, under a lawful interception direction issued under RICA).
10. How we keep your personal information secure
Atomic takes appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information in our possession or under our control. These measures are designed to prevent loss of, damage to, or unauthorised destruction of personal information, and to prevent unlawful access to or processing of personal information. We periodically review our security measures and update them where necessary.
Protecting your personal information is also a shared responsibility. The internet is not always a friendly place, so please take care to safeguard your account credentials, identity documents, and other personal information when using our services and online generally.
11. If something goes wrong
If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify you and the Information Regulator as soon as reasonably possible after becoming aware of the compromise, in accordance with section 22 of POPIA.
12. Direct marketing
We will only send you direct marketing communications by electronic means (including email, SMS, or automated calls) if you have given us your consent to do so, or if you are an existing customer of ours in respect of similar products or services. You may opt out of direct marketing at any time, and every direct marketing communication we send will include a clear means for you to do so.
13. Your rights
In relation to your personal information, you have the following rights under POPIA:
- To be notified that your personal information is being collected and processed, and the purposes for which it is being processed.
- To request access to the personal information we hold about you.
- To request correction of inaccurate, irrelevant, excessive, outdated, incomplete, misleading, or unlawfully obtained personal information.
- To request that we delete or destroy personal information that we are no longer authorised to retain.
- To object, on reasonable grounds relating to your particular situation, to the processing of your personal information.
- To object to the processing of your personal information for the purpose of direct marketing.
- Not to be subject to a decision based solely on the automated processing of your personal information that has legal consequences for you or affects you to a substantial degree.
- To lodge a complaint with the Information Regulator if you believe we have not complied with POPIA.
To exercise any of these rights, please contact our Information Officer using the details in clause 14 below.
14. Contact us โ Information Officer
Atomic has registered an Information Officer with the Information Regulator. To exercise your rights under this policy, request access to your personal information, or raise any concerns regarding our processing of your personal information, please contact:
Atomic (Pty) Ltd โ Information Officer
2 Gordon Street, Gardens, Cape Town
Email: michael@atomic.co.za
General enquiries: hello@atomic.co.za
15. Complaints to the Information Regulator
If you believe that Atomic has not complied with POPIA, you have the right to lodge a complaint with the Information Regulator:
The Information Regulator (South Africa)
Email (POPIA complaints): POPIAComplaints@inforegulator.org.za
Website: https://inforegulator.org.za
Complaints are submitted on POPIA Form 5, available from the Information Regulator’s website.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. If we make significant changes, we will post a prominent notice on our website or notify you by email. The current version will always be available at https://www.atomic.co.za/privacy-policy/, and the “Last updated” date at the top of this policy will reflect when it was last changed.