Privacy Policy

This policy explains what the Maritz Lab website collects, why, and what you can ask us to do about it. It is written to comply with the Protection of Personal Information Act 4 of 2013 (POPIA).

Last updated

Scope

This policy governs maritzlab.com and nothing else. By using the site, or by sending us a message through it, you confirm that you have read this policy and understand how we handle what you send. If you do not accept it, please do not use the contact form.

In this policy:

  • we, us and our mean the Maritz Lab, in the Department of Biodiversity & Conservation Biology at the University of the Western Cape;
  • you means anyone who visits the site or writes to us through it;
  • personal information carries the meaning section 1 of POPIA gives it — information identifying a living person, or an existing juristic person. Visitors in the European Union and the United Kingdom know the same idea as personal data under Article 4(1) of the GDPR;
  • processing means anything done with personal information, from collecting and storing it to using, sharing or deleting it;
  • operator means a third party that processes personal information on our behalf — what the GDPR calls a processor.

What we collect

We collect personal information in one place only: the contact form. When you submit it, we receive the name, email address, and message you typed.

We do not set cookies. We do not run analytics. We do not track you across sites, build a profile of you, or use your information for advertising.

Our host records ordinary server data for every request — your IP address, the page requested, the time, and the browser and operating system you used. We do not read these logs to identify visitors and we do not join them to anything you send us through the form.

Why we collect it

To read your message and reply to it. Nothing else. We do not use third-party analytics, advertising trackers, or externally hosted fonts.

Submitting the form is your consent to that use, as contemplated in section 11(1)(a) of POPIA and Article 6(1)(a) of the GDPR. Server logs are kept for the security and integrity of the site, which is a legitimate interest under section 11(1)(f) and Article 6(1)(f). You may withdraw your consent at any time by writing to us, though that does not undo processing already carried out.

What we don’t collect

We do not ask for and do not want special personal information. This includes categories protected by section 26 of POPIA, such as race, health, religious or political belief, biometrics, or criminal history.

This site is not directed at children, and we do not knowingly collect the personal information of anyone under 18 without the consent of a competent person, as section 34 of POPIA requires. If you believe a child has sent us information, write to us and we will delete it.

We will never sell, rent or trade your information. We will not add you to a mailing list or send you unsolicited electronic marketing, which section 69 of POPIA prohibits without your consent.

Who processes it

Three service providers act as operators for us under section 21 of POPIA:

  • Formspree passes contact form submissions straight through to our email. It forwards them rather than storing them: we have disabled submission archiving, so no copy stays behind on their servers, as per their privacy policy.
  • Cloudflare routes email sent to info@maritzlab.com to Prof. Maritz.
  • Netlify hosts this site and processes visitor IP addresses and other request data in accordance with its own retention policies.

Beyond these, we disclose your information only where the law requires it, or where it is necessary to establish or defend a legal claim. Within the lab, only Prof. Maritz and anyone he specifically asks to help with an enquiry can read what you send.

Cross-border transfers

All three providers store and process information outside South Africa, so submitting the form involves a cross-border transfer as contemplated in section 72 of POPIA. Each is bound by contractual terms — including the GDPR’s standard data protection clauses — that give your information a level of protection substantially similar to POPIA’s.

Keeping it secure

We take reasonable technical and organisational steps to protect what you send us, as section 19 of POPIA requires: the site is served over HTTPS, form submissions travel encrypted and are not archived in transit, and the mailbox they arrive in is protected by a strong unique password and multi-factor authentication.

No system on the internet is completely secure, and we cannot guarantee that yours will never be compromised. If a breach does affect your personal information, we will notify you and the Information Regulator as soon as reasonably possible, as section 22 of POPIA requires.

This site links out to journals, publishers, funders, university pages and social media. Those sites are not ours, we do not control them, and this policy does not apply once you leave. Read their policies before giving them anything.

How long we keep it

Once forwarded, a submission exists in one place: Prof. Maritz’s mailbox. It is kept there while the enquiry is live and for up to two years afterwards, then deleted — the limit section 14 of POPIA sets on holding a record longer than the purpose needs. Netlify server logs follow Netlify’s retention schedule.

Your rights

Under sections 5, 23, 24 and 11(3) of POPIA, you may ask us to:

  • confirm, free of charge, whether we hold personal information about you, and give you a copy of it;
  • correct or complete anything inaccurate or out of date;
  • delete information we no longer have a reason to keep;
  • stop or restrict our processing of it;
  • withdraw a consent you previously gave; or
  • object to processing we carry out on the basis of legitimate interest.

Write to the information officer below. We will respond within a reasonable time, and will ask you to confirm your identity before we act on a request.

If you are in the EU or UK

The GDPR gives you the same protections in different words, and we honour them on the same terms. Articles 15 to 21 cover access, rectification, erasure, restriction, portability and objection; Article 7(3) covers withdrawing a consent you have given. The lawful bases we rely on are named in Why we collect it above.

We have not appointed a representative under Article 27. We are an academic research group: we offer no goods or services for payment in the Union, and we do not monitor anyone’s behaviour there. Write to the information officer below and your request reaches the same desk.

Complaints

If you are unhappy with how we have handled your personal information, tell us first — it is usually the fastest way to fix it. You also have the right, under section 74 of POPIA, to complain directly to the Information Regulator of South Africa: inforegulator.org.za, complaints.IR@inforegulator.org.za. Visitors in the European Union may complain instead to their own national supervisory authority, and visitors in the United Kingdom to the Information Commissioner’s Office at ico.org.uk.

Who operates this site

Set out as section 43(1) of the Electronic Communications and Transactions Act 25 of 2002 requires:

  • Site: maritzlab.com
  • Operated by: the Maritz Lab, Department of Biodiversity & Conservation Biology, University of the Western Cape, Bellville, South Africa
  • Information officer: Prof. Bryan Maritz
  • Email: info@maritzlab.com

Enquiries, access requests and objections all go to that address.

Changes to this policy

We update this policy when the site changes or the law does. The revision date at the top of the page is the one that counts, and the current version is always the one published here.