Privacy Policy

Website: https://www.astechlms.com/

Responsible Party: LIPTECH CC (trading as Astech)

Registered Address: 8 Tennyson Avenue, Senderwood, Johannesburg, South Africa

Contact: info@astechlms.com | admin@astechlms.com

Last updated: 27 July 2026


1. Introduction

LIPTECH CC, trading as AstechLMS (“AstechLMS”, “we”, “us”, “our”), respects your right to privacy. This Privacy Policy explains what personal information we collect through https://www.astechlms.com/ (the “Website”), why we collect it, how we use and protect it, and what rights you hold over it.

This policy is issued in line with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and the Promotion of Access to Information Act 2 of 2000 (“PAIA”).

For the purposes of POPIA, LIPTECH CC is the responsible party that determines the purpose and means of processing your personal information.

By using the Website or submitting a contact form, you confirm that you have read this policy and agree to the processing of your personal information as set out below.


2. Key terms

To keep this policy readable, the following POPIA terms are used throughout:

TermMeaning
Personal informationInformation relating to an identifiable, living natural person or an identifiable, existing juristic person (a company, close corporation or trust)
ProcessingAny activity involving personal information, including collection, storage, use, sharing, updating and deletion
Data subjectThe person to whom the personal information relates — in most cases, you
Responsible partyThe party that decides why and how personal information is processed — LIPTECH CC
OperatorA third party that processes personal information on our behalf, under our instruction (for example, our email or hosting provider)
Information RegulatorThe South African statutory body that enforces POPIA and PAIA

3. Scope of this policy

This policy applies to personal information collected through the Website. It does not apply to third-party websites you reach through links on our pages. Those sites operate under their own privacy policies, and we accept no responsibility for their content or data practices.

Where you are already an AstechLMS client, personal information processed under a signed services agreement is governed by that agreement read together with this policy.


4. How we apply the POPIA conditions for lawful processing

POPIA sets out eight conditions for the lawful processing of personal information. Our commitments against each are set out below.

  1. Accountability — LIPTECH CC accepts responsibility for compliance with POPIA in respect of all personal information under our control.
  2. Processing limitation — We collect the minimum information needed, lawfully, and in a manner that does not intrude unreasonably on your privacy. Where we rely on consent, you may withdraw it at any time.
  3. Purpose specification — We collect personal information for the specific, lawful purposes set out in section 6, and we tell you what those purposes are at the point of collection.
  4. Further processing limitation — We do not use your personal information for a new purpose that is incompatible with the purpose for which it was originally collected, unless you consent or the law allows it.
  5. Information quality — We take reasonable steps to keep personal information complete, accurate and current, and we welcome corrections from you.
  6. Openness — We maintain a record of our processing operations and publish this policy so that you know what we do with your information.
  7. Security safeguards — We apply appropriate technical and organisational measures to protect personal information against loss, damage and unauthorised access. See section 11.
  8. Data subject participation — You may ask what personal information we hold about you, and request correction or deletion. See section 14.

5. Personal information we collect

5.1 Information you give us directly

We collect personal information only when you choose to submit it to us. This happens when you complete a contact, demo request or enquiry form on the Website. The fields collected are:

  • Full name
  • Email address
  • Contact number
  • Company or organisation name
  • Your enquiry or message

You may include additional information in the free-text enquiry field. Please do not submit sensitive or special personal information (such as health, financial account, biometric or identity number details) through our web forms. We do not need it, and we do not ask for it.

5.2 Information collected automatically

When you browse the Website, limited technical information is collected through cookies and server logs:

  • IP address (truncated or anonymised where our analytics configuration allows)
  • Browser type and version, device type and operating system
  • Pages viewed, time on page, referral source and exit pages
  • Approximate geographic region derived from IP address
  • Date and time of access

This information is used in aggregate to measure Website performance. It is not used to identify you personally.

5.3 Information collected through reCAPTCHA

The Website uses Google reCAPTCHA to distinguish human visitors from automated bots and to protect our forms against spam and abuse. reCAPTCHA collects hardware and software information — including device and application data, browser behaviour and mouse movements — and sends it to Google for analysis. See section 9 for further detail.

5.4 Information we do not collect

  • We do not collect payment card or banking details through the Website.
  • We do not knowingly collect personal information from children under the age of 18. Where the personal information of a child is required, we obtain the prior consent of a competent person, as POPIA requires.
  • We do not display third-party advertising on the Website.

6. Why we process your personal information, and on what legal basis

Section 11 of POPIA permits processing on defined grounds. The table below sets out our purposes and the matching ground.

PurposePersonal information usedPOPIA justification
Responding to your enquiry or demo requestName, email, number, company, enquiryConsent — s11(1)(a); performance of a contract or steps prior to a contract — s11(1)(b)
Sending follow-up correspondence relating to your enquiryName, email, numberLegitimate interest of the responsible party — s11(1)(f); consent — s11(1)(a)
Preparing quotations, proposals and scoping documents for the AstechLMS solutionName, email, number, company, enquirySteps prior to a contract — s11(1)(b)
Measuring Website traffic and improving content and structureCookie and log dataLegitimate interest — s11(1)(f); consent for non-essential cookies
Protecting our forms and infrastructure against spam and abusereCAPTCHA and technical dataLegitimate interest — s11(1)(f)
Meeting legal, tax, accounting and regulatory obligationsContact and transaction recordsCompliance with an obligation imposed by law — s11(1)(c)
Retargeting and remarketing (planned — see section 8)Cookie and pseudonymised identifiersConsent — s11(1)(a)

7. Consent and how to withdraw it

Where our processing rests on your consent, that consent is voluntary, specific and informed.

You may withdraw consent at any point by emailing info@astechlms.com or admin@astechlms.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it does not affect processing we are required to continue under another lawful ground — for example, retaining records for tax purposes.


8. Electronic communications and direct marketing

We send emails in response to enquiries and as follow-up correspondence on active or recent enquiries. We do not operate an email marketing or newsletter programme, and we do not sell, rent or trade your contact details to any third party for marketing purposes.

Should we introduce electronic direct marketing in future, we will comply with section 69 of POPIA:

  • Unsolicited electronic direct marketing will be sent only with your prior consent, or to existing customers in respect of similar products and services, where you were given a reasonable opportunity to object at the point of collection.
  • Requests for consent will be made no more than once, using Form 4 prescribed under the POPIA Regulations, 2018.
  • Every marketing message will identify the sender and carry a working opt-out mechanism.

We currently do not run remarketing or retargeting advertising. We may introduce it. Should that happen, we will update this policy and our Cookie Policy before any remarketing tags are activated, and advertising cookies will be set only where you have given consent through our cookie banner.


9. Who we share your personal information with

We do not sell your personal information. We share it only where necessary, and only with parties bound by confidentiality and data protection obligations.

Operators acting on our instruction

  • Website hosting provider — stores Website files and form submissions on our behalf
  • Email service provider — delivers and stores our business correspondence
  • CRM and business systems — records enquiries and manages the sales pipeline
  • Google LLC (Google Analytics) — measures Website usage. Data is processed under Google’s terms and, where configured, IP anonymisation
  • Google LLC (reCAPTCHA) — protects forms against automated abuse. Governed by Google’s Privacy Policy at https://policies.google.com/privacy and Terms at https://policies.google.com/terms

Professional advisers — legal, accounting, audit and IT security advisers, where required.

Regulators and law enforcement — where disclosure is required by law, court order, or is needed to establish, exercise or defend a legal claim.

Business transfer — should LIPTECH CC be involved in a merger, acquisition or sale of assets, personal information may transfer to the acquiring party. You will be notified of any such change and of any material change to how your information is handled.

Every operator we appoint is required, under section 21 of POPIA, to process personal information only on our documented instruction and to maintain appropriate security safeguards.


10. Cross-border transfers of personal information

Some of our service providers — notably Google — process data on servers located outside South Africa.

Section 72 of POPIA permits such transfers where at least one of the following applies:

  • The recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, substantially similar to POPIA
  • You have consented to the transfer
  • The transfer is necessary for the performance of a contract between you and us, or for the conclusion or performance of a contract concluded in your interest
  • The transfer benefits you and it is not reasonably practicable to obtain your consent

Where we transfer personal information outside South Africa, we satisfy ourselves that one of these grounds applies and that contractual safeguards are in place with the recipient.


11. Security safeguards

In line with section 19 of POPIA, we maintain appropriate, reasonable technical and organisational measures to protect personal information against loss, damage, unlawful access and unauthorised processing. These include:

  • Encryption in transit — the Website is served over HTTPS using a valid TLS certificate
  • Access control — access to enquiry data is limited to personnel with a genuine business need, on a least-privilege basis
  • Authentication — strong password policies and, where supported, multi-factor authentication on business systems
  • Bot protection — reCAPTCHA on all public-facing forms
  • Patching and maintenance — regular updates to Website software, plugins and server infrastructure
  • Backups — routine backups held under equivalent security controls
  • Vendor due diligence — security and data protection review of operators before appointment
  • Staff obligations — confidentiality undertakings and internal handling procedures for personal information

No system connected to the internet can be guaranteed entirely secure. We continue to review and improve our safeguards as risks and technology change.


12. Security compromises

Should there be reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will comply with section 22 of POPIA. We will notify:

  • the Information Regulator, and
  • you, as soon as reasonably possible after discovering the compromise, unless a public body responsible for detecting or investigating offences asks us to delay notification.

Our notification to you will describe the possible consequences of the compromise, the measures we intend to take or have taken to address it, what we recommend you do to reduce the potential harm, and the identity of the unauthorised person where known.


13. How long we keep your personal information

Section 14 of POPIA requires that records of personal information not be retained for longer than necessary.

Record typeRetention period
Enquiry and contact form submissions that do not convert24 months from last contact
Prospect and lead records under active discussionDuration of the discussion, plus 24 months
Client contract and project recordsDuration of the relationship, plus the periods required under the Companies Act, the Tax Administration Act and other applicable law (commonly 5 to 7 years)
Website analytics dataIn line with the retention setting configured in Google Analytics, typically 14 months
Email correspondenceIn line with our internal mailbox retention schedule

Once a retention period lapses, records are deleted or de-identified in a manner that prevents reconstruction.


14. Your rights as a data subject

POPIA grants you the following rights. There is no charge for exercising them, other than a prescribed fee that may apply to certain access requests.

Right to be notified — to be told that we are collecting your personal information, and to be notified where it has been accessed by an unauthorised person.

Right of access — to ask whether we hold personal information about you, and to request a description of that information together with the identity of third parties who have had access to it. Access requests are handled under PAIA and may attract the prescribed fee.

Right to correction or deletion — to request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. Requests may be submitted on Form 2 prescribed under the POPIA Regulations, 2018.

Right to object — to object, on reasonable grounds, to the processing of your personal information where we rely on legitimate interest or on the protection of a legitimate interest. Objections may be submitted on Form 1.

Right to object to direct marketing — to object at any time to the use of your personal information for direct marketing.

Right to withdraw consent — as set out in section 7.

Right not to be subject to automated decision-making — not to be subject to a decision with legal consequences for you that is based solely on automated processing intended to profile you. We do not carry out automated decision-making of this kind.

Right to complain — to lodge a complaint with the Information Regulator. See section 17.

Right to civil remedy — to institute civil proceedings in a competent court regarding alleged interference with the protection of your personal information.

How to exercise your rights

Send your request to info@astechlms.com or admin@astechlms.com, marked for the attention of the Information Officer. Please state clearly which right you are exercising and provide enough detail for us to locate your records. We may ask for proof of identity before acting on a request, to protect your information against disclosure to the wrong person.

We aim to respond within 30 days of receiving a valid request. Where a request is complex, we will tell you and give a revised timeframe.


15. Information Officer

LIPTECH CC has designated an Information Officer, as section 55 of POPIA requires, registered with the Information Regulator.

Email: admin@astechlms.com

Postal address: 8 Tennyson Avenue, Senderwood, Johannesburg, South Africa

The Information Officer is responsible for encouraging compliance with POPIA, dealing with requests made to LIPTECH CC, working with the Information Regulator on investigations, and maintaining our internal compliance framework.


16. PAIA Manual

LIPTECH CC maintains a manual in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, setting out the categories of records we hold and the procedure for requesting access to them. A copy is available on request from admin@astechlms.com.


17. Complaints to the Information Regulator

Should you believe we have processed your personal information unlawfully, please raise it with us first at info@astechlms.com — most matters are resolved quickly at this stage.

You retain the right to lodge a complaint directly with the Information Regulator using Form 5 prescribed under the POPIA Regulations, 2018, or through the Regulator’s eServices portal.

The Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Toll free: 0800 017 160

Landline: 010 023 5200

General enquiries: enquiries@inforegulator.org.za

POPIA complaints: POPIAComplaints@inforegulator.org.za

PAIA complaints: PAIAComplaints@inforegulator.org.za

Website: https://inforegulator.org.za

eServices portal: https://eservices.inforegulator.org.za


18. Cookies

The Website uses cookies and similar technologies. Full detail on the cookies we set, their purpose and duration, and how to control them, appears in our separate Cookie Policy.


19. Links to third-party websites

The Website contains links to external sites, including the AstechLMS parent site at https://www.as-tech.co.za, Sage resources and partner pages. Following such a link takes you outside our control. We recommend reading the privacy policy of any site you visit before submitting personal information to it.


20. Changes to this Privacy Policy

We review this policy periodically and update it as our processing activities, technology or the law changes. The current version is always published at https://www.astechlms.com/privacy-policy with the effective date at the top.

Material changes — such as the introduction of remarketing — will be signalled through a notice on the Website. Continued use of the Website after an update constitutes acceptance of the revised policy.


21. Contact us

Questions about this policy, our data handling practices, or a request relating to your personal information:

LIPTECH CC t/a Astech 8 Tennyson Avenue, Senderwood, Johannesburg, South Africa

Email: info@astechlms.com | admin@astechlms.com

Website: https://www.astechlms.com/