Privacy Policy
Effective 21 August 2026.
Awaiting legal review
This document describes our actual current practice in good faith, but it has not yet been reviewed by an admitted attorney. It is not a substitute for legal advice, and the sections marked [TO CONFIRM] need company details filled in before this can be relied on. If anything here matters to a decision you're making, email legal@etra.co.za and we'll give you a straight answer.
This policy explains what personal information Etra collects through this website, why we collect it, and what you can do about it. It is written to meet our obligations under South Africa's Protection of Personal Information Act 4 of 2013 (POPIA).
It covers etra.co.za only. GraceVault and Orion Marketplace each process personal information under their own terms — see GraceVault & Orion below.
Who we are
Etra (Pty) Ltd is the responsible party for the personal information described here. We are a TutoConsulting company based in Johannesburg, South Africa.
- Registered entity
- Etra (Pty) Ltd — registration number [TO CONFIRM]
- Information Officer
- [TO CONFIRM — name and designation of the registered Information Officer]
- Contact for privacy matters
- privacy@etra.co.za
- Postal address
- [TO CONFIRM — registered physical address, Johannesburg]
What we collect
Information you give us directly
When you submit the contact form on this site, we collect the fields you fill in:
- Your name
- Your email address
- Your company or organisation, if you choose to provide it
- The subject category you select
- The content of your message
Supplying this information is voluntary. If you don't provide a name, email address, and message, we can't process or reply to your enquiry — those three are the minimum required for the form to do anything useful.
Information collected automatically
Our content delivery network records standard technical request logs. These include your IP address, the pages you requested, timestamps, your browser user-agent string, and the referring page. We do not use these logs to build a profile of you.
What we deliberately do not collect
- No analytics or tracking cookies. This site sets no cookies of its own and runs no third-party analytics, advertising, or session-recording scripts.
- No special personal information. We do not ask for and have no use for information about your health, race, religion, political affiliation, biometrics, or sexual life.
- No children's information. This site is directed at businesses and adults. We do not knowingly collect personal information from anyone under 18.
If you contact us about a bereavement, please share only what you need to. You do not have to give us details about a deceased person or their family in order to get a reply.
Why we process it
POPIA requires a lawful basis for each purpose. Ours are:
- Replying to your enquiry
- Processing is necessary to take steps at your request, and we rely on your consent in submitting the form. This is the only reason we use your contact details.
- Keeping the site secure and available
- Technical logs and rate limiting serve our legitimate interest in preventing abuse, diagnosing faults, and keeping the site online.
We do not send marketing email. We will not add you to a mailing list because you used the contact form, and we do not sell, rent, or trade personal information to anyone.
Who we share it with
We share personal information only with operators who process it on our behalf under contract, and only as far as needed:
- Amazon Web Services (AWS) — hosts this site and stores our server logs.
- Our internal notification service — where configured, contact form submissions are forwarded to the Etra team so someone actually sees them.
- TutoConsulting — our parent company. Personal information is shared only where a specific enquiry needs their involvement, such as a partnership discussion.
We will disclose personal information if the law requires it — a court order, a statutory request, or a regulatory investigation.
Where your data is stored
Our infrastructure runs primarily in AWS's Cape Town (af-south-1) region, so your data stays in South Africa by default.
Two exceptions involve processing outside the country:
- Our content delivery network and web application firewall are global services configured from AWS's North Virginia (us-east-1) region. Requests are served from the nearest edge location, which may be outside South Africa.
- Where a notification service is used to relay enquiries, that provider may process data outside South Africa.
POPIA permits these transfers where the recipient is bound by contractual terms upholding comparable protection. AWS provides this through its data processing addendum.
How long we keep it
- Contact form submissions
- Retained for up to 24 months after our last correspondence with you, then deleted. Kept in application logs with a matching retention period.
- Technical request logs
- Retained for 90 days, then automatically deleted by a storage lifecycle rule.
If a record becomes part of a live contract, dispute, or legal obligation, we keep it for as long as that requires and no longer.
How we protect it
POPIA requires appropriate, reasonable technical and organisational measures. In practice, for this site:
- All traffic is encrypted in transit over HTTPS, with HTTP Strict Transport Security enforced.
- Stored data is encrypted at rest.
- A content security policy and standard security response headers are applied at the network edge.
- A web application firewall applies rate limiting and blocks known-malicious request patterns.
- Access to logs and infrastructure is restricted to named team members and is itself audited.
- Submitted content is validated and length-capped before it is stored or forwarded.
No system is perfectly secure. If we discover a compromise affecting your personal information, we will notify you and the Information Regulator as POPIA section 22 requires.
Your rights under POPIA
You are entitled to:
- Access — ask what personal information we hold about you.
- Correction — have inaccurate or incomplete information fixed.
- Deletion — ask us to delete information we no longer have grounds to keep.
- Objection — object to processing that relies on legitimate interest.
- Withdraw consent — at any time, without affecting processing already carried out.
- Not be subject to automated decision-making — we don't do any, but the right stands.
Email privacy@etra.co.za to exercise any of these. We aim to respond within 30 days. We may need to verify your identity first, so that someone else can't obtain your information by asking. We do not charge for access requests.
Complaints
If you are unhappy with how we have handled your personal information, tell us first at privacy@etra.co.za — most issues are faster to fix directly.
You also have the right to complain to the regulator at any point:
- The Information Regulator (South Africa)
- inforegulator.org.za
- Complaints email
- POPIAComplaints@inforegulator.org.za
GraceVault & Orion Marketplace
This policy does not cover the products themselves. They handle materially different and more sensitive information — case records, deceased persons' details, next-of-kin contacts, payment status — under separate agreements:
- GraceVault. Funeral parlours are the responsible party for information they enter. Etra acts as an operator on their instruction. Terms are set out in each parlour's service agreement, which includes an operator agreement as POPIA section 21 requires.
- Orion Marketplace. Governed by the privacy notice presented when you create an account. Where a family shares information with a parlour through Orion, that parlour becomes an independent responsible party for what it receives.
Changes to this policy
We will update this page when our practices change. The effective date at the top always reflects the current version. If a change materially affects how we handle information you have already given us, we will contact you directly rather than relying on you noticing this page.