Mosaic Studio is committed to safeguarding your privacy and ensuring your personal information is processed lawfully, transparently, and securely in full alignment with the 8 Lawful Conditions for Processing set out in the Protection of Personal Information Act (POPIA).
Responsible Party & Contact Details
This Privacy Notice governs the processing of personal information by Mosaic Studio(“we”, “us”, “our”), acting as the Responsible Party in terms of Section 1 of POPIA.
| Registered Trading Entity | Mosaic Studio |
|---|---|
| Physical & Postal Address | 8 Akker Lane, Kriel, Mpumalanga, 2271, Republic of South Africa |
| Designated Information Officer | Mosaic Studio Information Officer |
| General & Privacy Enquiries | info@mmso.co.za / privacy@mmso.co.za |
| Telephone / Direct WhatsApp | +27 (0)78 405 4651 |
| VAT Registration Number | 2114642180 |
Personal Information We Collect
We only collect personal information that is adequate, relevant, and strictly limited to what is necessary for our web engineering, digital consulting, client management, and billing services.
Project Enquiries & Briefs
Full name, business name, business email address, direct phone/WhatsApp number, physical/operating location, website URL, industry sector, project scope, budget parameters, and brand collateral provided via our contact and project brief forms.
Client Accounts & Portal
Primary contact details, company registration numbers, VAT numbers, physical billing addresses, authorized portal logins, magic-link token identifiers, support message histories, and project approval timestamps.
Financial & Billing Data
Invoicing records, VAT calculation logs, Proof of Payment (POP) files uploaded for EFT reconciliations, PayFast recurring subscription token identifiers, and sequential tax invoice numbers. (Note: We do not store raw credit card numbers; card transactions are processed securely via PayFast PCI-DSS Level 1 infrastructure).
Technical & Telemetry Data
IP addresses, browser type, device specifications, operating system, network telemetry, Core Web Vitals (LCP, FID, CLS via Vercel Speed Insights), and consent-gated aggregated analytics (Google Analytics 4 / Microsoft Clarity).
Lawful Bases & Purposes of Processing
In accordance with Section 11 of POPIA, Mosaic Studio processes personal information under the following lawful justifications:
- Performance of a Contract (POPIA s11(1)(b)): To review project briefs, draft proposals and quotes, develop and deploy custom websites, configure client portals, deliver maintenance retainers, and execute agreed service level agreements.
- Compliance with Legal Obligations (POPIA s11(1)(c)): To maintain statutory accounting and tax records in accordance with the South African Tax Administration Act (Act 28 of 2011) and the Value-Added Tax Act (Act 89 of 1991) for VAT No: 2114642180.
- Legitimate Interests (POPIA s11(1)(d)): To protect system integrity, prevent fraud, debug technical faults, ensure zero downtime across server infrastructure, and secure client communication channels.
- Consent (POPIA s11(1)(a)): To process non-essential website analytics, user experience session recording, and voluntary opt-in marketing newsletters. Consent may be revoked at any time.
Third-Party Operators & Cross-Border Transfers
We engage trusted third-party service providers (Operators in terms of Section 20 & 21 of POPIA) to support our technical infrastructure. Under Section 72 of POPIA (Transfers of personal information outside the Republic), we ensure all international operators adhere to laws or binding corporate rules providing an adequate level of protection substantially similar to POPIA.
| Operator / Sub-Processor | Purpose & Service | Location / Safeguards |
|---|---|---|
| Supabase Inc. | PostgreSQL Database, Authentication & Storage | AWS EU Region · AES-256 Encryption at rest · POPIA s72 compliant DPA |
| Vercel Inc. | Next.js Cloud Hosting, Edge Routing & Speed Insights | Global Edge Network (USA/EU) · SOC 2 Type II certified · Standard Contractual Clauses |
| PayFast / Network International | Payment Gateway & Tokenized Retainer Subscriptions | South Africa (Local PASA & SARB compliant) · PCI-DSS Level 1 certified |
| Resend Inc. | Transactional Email & Magic Link Delivery | USA · TLS 1.3 Transport Security · DPA with Standard Contractual Clauses |
| Meta Platforms (WhatsApp Cloud API) | Automated Client Notifications & Project Updates | South African E.164 routing · End-to-end transport encryption |
| Google LLC & Microsoft Corp. | Optional Consent-Gated Analytics (GA4 / Clarity) | USA/EU · Anonymized IP masking · Only activated upon explicit user consent |
Cookies & Tracking Technologies
Mosaic Studio uses essential cookies to enable platform functionality, secure authentication tokens, and preserve user preferences. We do not load non-essential tracking cookies or third-party analytics until you grant explicit consent via our cookie banner. For full itemized details, please review our dedicated Cookie Notice.
Data Retention & Secure Disposal
In accordance with Section 14 of POPIA, personal information is retained only for as long as is necessary to achieve the specific purpose for which it was gathered, unless a longer retention period is required or authorised by law:
- Unconverted Project Briefs: Retained for a maximum of 12 months for follow-up feasibility, after which records are automatically archived or securely destroyed.
- Active Client Accounts & Codebases: Retained throughout the duration of the active contract and maintenance retainer period.
- Financial & VAT Tax Invoices: Retained for a minimum of 5 (five) years to comply with the South African Revenue Service (SARS) Tax Administration Act requirements.
- Analytics & Telemetry Logs: Aggregated and anonymized logs are retained for up to 14 months for capacity planning and performance optimization.
Your Statutory Rights Under POPIA
As a data subject under South African law, you hold comprehensive rights regarding your personal information:
Request confirmation of whether we hold your personal information and obtain a copy of the record.
Request the correction of inaccurate, misleading, or outdated personal data, or the destruction of records held unlawfully.
Object on reasonable grounds to the processing of your personal information, including for direct marketing purposes.
Withdraw previously granted consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise any of your rights, submit a written request using the prescribed POPIA Form 1 or Form 2 to our Information Officer at privacy@mmso.co.za. We will process and respond to verified requests within 3 to 5 business days.
Information Security & Safeguards
Mosaic Studio implements rigorous technical, administrative, and physical safeguards to preserve the confidentiality, integrity, and availability of personal information against unauthorized access, loss, destruction, or alteration:
- Encryption: AES-256 encryption for database records and secure vault secrets at rest; TLS 1.3 encryption for all data in transit across HTTPS.
- Access Control: Strict role-based access controls (RBAC) and mandatory two-factor authentication (2FA) for all administrative workspaces.
- Continuous Auditing: Regular vulnerability scanning, dependency auditing, and strict environment variable secret separation.
- Security Incident Response: In the unlikely event of a security breach involving personal data, we will notify both the Information Regulator and affected data subjects as required under Section 22 of POPIA.
Lodging a Complaint with the Information Regulator
If you believe that your personal information has been processed in contravention of POPIA or if you are dissatisfied with our response to a privacy request, you have the right to lodge a formal complaint with the Information Regulator of South Africa: