Privacy Notice (POPIA)
Last updated: August 2026
This notice explains how Hotwireless collects, uses, and safeguards personal information. It applies to our website, our sales and support interactions, and to the captive portal software we operate on behalf of our venue customers.
Who we are
Hotspot & Wifi Specialists (Pty) Ltd t/a Hotwireless
Company registration number 2016/437869/07
VAT registration number 4830317733
Cape Town, South Africa
Our Information Officer
POPIA requires us to appoint an Information Officer. Ours is Russell Ball. You can reach him at admin@hotwireless.co.za or on +27 76 540 1099 (Monday to Friday, 08:00–17:00 SAST). Please send any access, correction or deletion request, or any privacy complaint, to that address.
Information we collect
When you contact us via this website
- Name, business name, email, phone, venue type, message content.
- Necessary technical metadata (IP address, browser, referral source) to deliver and secure the service.
When you connect to a guest WiFi network we operate
What we collect depends on the package the venue has chosen.
- On our Basic package, you are not asked for any personal details. We record your device identifier (MAC address) and connection metadata (timestamp, data volume, session duration) so that we can run the session, apply the venue's time and bandwidth limits, and keep the network secure.
- Where the venue has chosen the Data Collection package, the login page asks you for your name, email address and cell number before it lets you online. We collect these so that the venue can identify who used its WiFi, contact you about its own business, and — where the venue has Guest Insights — count new versus returning visits. We ask for your consent on the login page at the moment you give these details, and you can decline and use the venue's other services instead.
- We also record your device identifier and connection metadata on every package, as described above.
- We do not inspect the content of your traffic and we do not sell your details to anyone.
How we use it
- To provide the service you've asked for — whether a demo call, a proposal, or WiFi access.
- To send marketing communications if — and only if — you opt in.
- To comply with our legal and regulatory obligations.
- To secure and improve our services.
Our role vs the venue's role
When you use guest WiFi at one of our customer venues, the venue is the Responsible Party for your data and Hotwireless acts as the Operator. We process data only under instruction from the venue. If you want to exercise your rights in respect of data captured at a venue, please contact the venue directly; we will support them in responding.
Who we share it with
- Service providers necessary to deliver our platform (cloud hosting, captive portal infrastructure, transactional email, SMS gateway, website analytics) — all bound by confidentiality and processing agreements.
- Your data is not sold, leased, or shared with marketing partners.
- We comply with lawful requests from regulatory authorities.
Where we store it, and transfers outside South Africa
We are a South African business, but the platform we run is built on international cloud and communications services. Your personal information may therefore be processed on servers outside South Africa. We cannot guarantee that it is held in a South African region.
Where personal information leaves South Africa, we do so on the basis allowed by section 72 of POPIA: the recipient is bound by a written agreement with us that requires a level of protection substantially similar to POPIA, and that does not permit them to use the data for their own purposes or pass it on further. If you ask our Information Officer, we will tell you which categories of processor handle your data and where they are based.
Traffic to our platform is encrypted in transit. Stored data sits within the security controls of the cloud services we use.
How long we keep it
We keep personal information only for as long as it is needed for the purpose it was collected for, and we delete it on request unless the law requires us to keep it.
- Connection logs (device identifier, session times, data volume): kept while they are needed to run and troubleshoot the service, and to meet any legal obligation that applies to us.
- Guest details captured at a venue login (name, email, cell number): for as long as the venue remains our customer and your consent remains valid. When a venue closes its account, we remove its guest list from our systems.
- Marketing opt-in contact data: for as long as your consent remains active.
- Business correspondence: 5 years for accounting and tax purposes.
If you want your information removed, write to our Information Officer and we will remove it, and confirm to you that we have.
Cookies and analytics
This website uses Google Analytics to understand how visitors find and move around the site. Google Analytics sets cookies in your browser and collects your IP address, the pages you view, roughly where in the world you are, and what kind of device and browser you use. We use it only to see which pages are useful and where people give up. We do not use it to identify you personally, and we do not use it for advertising.
Google Analytics is operated by Google, which processes this information outside South Africa. That transfer is covered by the cross-border position set out above.
If you would rather not be measured, you can:
- Install Google's Analytics opt-out browser add-on;
- Block or delete cookies in your browser settings, or use a private window; or
- Turn on your browser's tracking protection, which most modern browsers include.
Blocking these cookies does not stop you from using this website. The captive portal itself also sets a small number of cookies that are strictly necessary to keep your WiFi session alive — those cannot be switched off without breaking the login.
Your rights
Under POPIA you have the right to access the personal information we hold about you, to request correction, and in many cases to request deletion. You may also object to us processing your information, and withdraw a consent you have given at any time. Contact our Information Officer to exercise these rights. We respond within 30 days.
Remember that for data captured at a venue, the venue is the Responsible Party — see "Our role vs the venue's role" above.
Complaints
If you are not satisfied with our response, you may lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.
Changes to this notice
We'll update this notice from time to time and will post the current version at this URL. Material changes will be flagged.