CATDOG · https://catdogdigital.com
- Effective date
- Last updated
1. Who we are
CATDOG is a South African technology business. “CATDOG”, “we” and “our” refer to that business, not to its clients or independent service providers.
2. Scope of this policy
This policy covers the CATDOG public website, direct enquiries and CATDOG’s own client administration. A client application, hosted system or reporting project may need a separate privacy notice and processing agreement. Those documents should explain that service’s actual data flows and the parties’ roles.
3. Personal information we collect
Information you choose to send through the website form, by email or by telephone may include your name, business, contact details and project requirements. Do not send passwords, payment-card details, identity documents or sensitive customer records with an initial enquiry.
The website form asks for your name, email, desired outcome and enquiry consent. Business name, phone, current difficulties, service, timeline and budget are optional or selectable context. Technical request information and the limited browser storage described below are separate from form content.
4. How information reaches us
You may provide information directly through the website enquiry form, email, telephone, project discussions or agreed support channels. In an engagement, an authorised client may supply information or permit access to a system. The public website has no account registration, newsletter signup or payment checkout.
Opening an email or telephone link uses your chosen communications application. Submitting the website form sends the entered information to CATDOG through the AWS services described below.
5. Why information is processed
Relevant information may be used to understand an enquiry, prepare a proposal, communicate about work, deliver an agreed service, investigate a support issue, administer billing or meet applicable obligations. Access to client systems should be limited to the purpose and scope agreed with that client.
6. Justification for processing
Depending on the circumstances, processing may rely on consent, steps to conclude or perform a contract, a legal obligation, or a legitimate interest recognised by POPIA. The appropriate justification must be assessed for the particular purpose; consent is not assumed merely because you browse this site.
Where consent is the basis, you may withdraw it for future processing. Other lawful grounds may still require some records to be retained.
7. Website enquiries
When you submit the form, the browser sends the entered information over HTTPS to an Amazon API Gateway endpoint in the EU (Ireland) Region. An AWS Lambda function validates the submission and asks Amazon SES to deliver it to CATDOG’s published Gmail mailbox. The form data is not written to an application database. AWS may retain limited service and delivery metadata, and the delivered message remains in Gmail according to CATDOG’s retention requirements and Google’s service operation.
The checkbox records consent for CATDOG to use the submitted information to respond to that enquiry. It is not permission to add you to a marketing list. Browser autofill or session restoration may retain values independently of this application.
8. Clients and prospective clients
During a service relationship, records may include business contacts, requirements, quotations, approvals, invoices, support correspondence and delivery records. Infrastructure configuration and technical logs may also be needed for authorised work. These are potential engagement records, not categories collected automatically by the public website.
9. Technical and usage information
Delivering a web page necessarily involves technical request information, such as an IP address and requested URL. Hosting, network or security providers may record request times, response codes, browser details and related connection data. Logging depends on the hosting configuration and the service concerned.
The application has no configured audience analytics, advertising pixels, session replay or remote error-monitoring SDK.
10. Cookies and browser storage
The application does not set cookies. It uses localStorage to remember a selected colour theme. A sessionStorage flag exists in the development-only intro preview but is inactive in production. The Cookie Policy identifies the keys, purposes and duration.
Season previews use URL query parameters, not persistent preference storage. Device and motion preferences are used locally to adapt presentation; these preferences are not reported to a tracking service.
11. Hosting and service providers
The site uses AWS Amplify Hosting. Website enquiries use AWS Lambda and Amazon SES in the EU (Ireland) Region and are delivered to CATDOG’s Gmail mailbox. Google’s email infrastructure and the sender’s provider may process email information. Information relevant to an engagement may also reach providers selected for that engagement.
12. AWS and cloud infrastructure
This public website uses AWS Amplify Hosting and an Amplify Gen 2 backend. Its enquiry form uses Amazon API Gateway, AWS Lambda and Amazon SES in the EU (Ireland) Region. The function has a fixed recipient and does not store form entries in S3 or an application database. AWS service logs and SES delivery records may contain technical metadata but the function is designed not to log the message body. Other agreed services may use different AWS services or regions and must be defined for their own architecture.
13. Business intelligence and reporting
A reporting engagement may involve datasets, business records and dashboard access, including through Amazon QuickSight. Whether information identifies people depends on the supplied data and report design. Data selection, access, exports, refreshes and any aggregation or de-identification should be agreed before importing client data.
14. Client-provided data
Clients should provide only data and access needed for the agreed work, and ensure they have authority and an appropriate basis to do so. Customer, employee, supplier or user information should not be included in test datasets by default. Where practical, use synthetic or suitably de-identified data for development.
15. Processing on behalf of clients
Depending on who determines the purpose and means of processing, a client may be the responsible party and CATDOG may act as its operator. This is not the role allocation for every service. CATDOG may separately be responsible for its own billing and relationship records.
Where CATDOG acts as an operator, a written processing agreement should address authorised instructions, confidentiality, security, other providers, incident reporting, assistance with rights requests and return or deletion.
16. Retention
Records should be kept only for the period justified by their purpose and applicable contractual or legal requirements. A dispute or required record-keeping obligation may justify longer retention of relevant records, not indefinite retention of everything. When no longer justified, information should be securely deleted or appropriately de-identified, including through defined backup expiry procedures.
17. Security
The intended approach is reasonable technical and organisational safeguards suited to the information and service. Relevant controls may include HTTPS, limited access, authentication, least privilege, updates, monitoring and agreed backup arrangements. Controls depend on the deployed service; a policy is not evidence that each control is implemented.
No network or storage system can be guaranteed completely secure. Security concerns can be reported through the contact details below.
18. Cross-border processing
Cloud hosting, email, technical support or other providers may involve processing outside South Africa. CATDOG does not promise that all information stays in South Africa. The location depends on the chosen service and architecture.
Transfers must have a permitted basis and protections required by applicable law.
19. Sharing information
Information may need to be shared with authorised project participants, contracted providers, professional advisers or authorities where justified for the stated purpose or required by law. Access should be limited to what is relevant. The application contains no advertising-data sale or sharing integration.
20. Direct marketing
No mailing list or marketing automation is configured on this website. An enquiry is not permission to add you to a marketing list. Any future direct marketing must meet the applicable POPIA requirements and provide appropriate identification and objection or opt-out mechanisms.
An opt-out from marketing does not necessarily stop essential communications about an existing project.
21. Your rights
Subject to applicable conditions, you may request information about processing, access to your personal information, correction, or deletion, and may object to certain processing. These rights are not unlimited; legal record-keeping requirements may affect what can be deleted. You may also raise a complaint with the Information Regulator.
22. Access, correction and deletion requests
Please contact CATDOG through the Contact page or the published email or telephone. Describe the information or processing concerned and how to reach you; do not include unnecessary sensitive documents. Reasonable identity checks may be needed before releasing or changing records.
If the information is controlled by a client for whom CATDOG acts as an operator, the request may need to be coordinated with that client.
23. Complaints
You may contact CATDOG about a privacy concern and may also approach South Africa’s Information Regulator. Contacting CATDOG first is not stated here as a condition of making a POPIA complaint. The official complaints page linked below explains the Regulator’s current process.
24. Children
The website is intended for business enquiries and is not designed to collect children’s information. Do not send a child’s personal information through an initial enquiry. If an agreed service would involve children’s information, its legal basis and safeguards must be assessed before that processing starts. Contact us if you believe such information was provided unintentionally.
25. Other websites
Links may take you to independently operated websites or communications services. Their processing is governed by their own notices and settings. This website does not currently embed social feeds, maps or videos; following a link is different from loading an embedded tracker.
26. Changes to this policy
This policy should be updated when data practices or service arrangements change. The last-updated date identifies the current revision. Material changes should be communicated appropriately; publishing a revised policy does not itself supply consent or authorise a new use of information.
27. Contact information
Please contact CATDOG through the Contact page or the published email or telephone for questions about this policy or your personal information.
CATDOGhttps://catdogdigital.commalanvanwyk.aws@gmail.com082 399 8535