POPIA clarity for sensitive board-evaluation environments.
This page explains how BoardEvaluator™ by Celagenix® approaches POPIA-aligned handling of personal information in a South African governance context. It is designed to help governance teams, boards, procurement, legal reviewers, and participants understand how lawful processing, purpose limitation, operator relationships, security safeguards, retention, and data-subject rights fit into the product and website trust model.
What POPIA actually means for a board-evaluation platform.
BoardEvaluator™ operates in a context where board evaluations, oversight concerns, committee performance, independence questions, and governance reporting can involve sensitive personal information. POPIA relevance therefore needs to be explained in a way that is practical for company secretaries, boards, pension-fund stakeholders, legal teams, and enterprise buyers.
Lawful processing
POPIA-aligned handling starts with a clear reason for collecting and using personal information rather than processing it by default.
Minimal and relevant collection
Only the information reasonably required for the service, the engagement, governance reporting, support, or legal obligations should be processed.
Data-subject rights
POPIA relevance includes giving individuals a clear path to ask about access, correction, deletion, or related handling concerns where applicable.
Governance-grade sensitivity
Board-related workflows can surface sensitive context, which makes security safeguards, confidentiality, and controlled access especially important.
The practical concepts most buyers and stakeholders care about.
This is not a legal textbook section. It is a trust section that helps the reader understand how POPIA fits the BoardEvaluator™ environment.
Core concepts in context
- Responsible party logic matters because accountability for lawful processing must be clear
- Operator relationships matter where service providers support hosting, infrastructure, delivery, or processing
- Personal information can include contact, participation, evaluation, workflow, and support-related data
- Purpose limitation matters because governance-sensitive information should not be used in an unrelated way
- Retention matters because evidence needs and legal obligations do not justify indefinite keeping by default
Responsible partyOperatorPersonal informationRetention
How POPIA connects to site and platform use
- Public website enquiries and demo requests may involve contact and organisation information
- Platform workflows may involve participant, evaluation, and reporting-related information
- Security safeguards support POPIA-aligned handling but do not replace lawful-processing discipline
- Commercial, privacy, and legal documentation work together rather than as isolated pages
WebsitePlatformSecurity safeguardsTrust framework
POPIA, mapped to the real BoardEvaluator™ workflow.
The point here is to show that POPIA is not just a policy label. It connects to the real BoardEvaluator™ journey from enquiry to evaluation delivery and reporting.
| Stage | POPIA-aligned question | What that means in practice |
|---|---|---|
| Collect | Why is this information needed | Limit collection to what is reasonably required for the enquiry, the product, the evaluation workflow, or the legal/commercial context. |
| Use | Is the purpose clear and appropriate | Use information for defined service, governance, support, reporting, or compliance purposes rather than vague future uses. |
| Share | Who needs access and on what basis | Access and sharing should be limited to roles, operators, providers, or obligations that are actually relevant. |
| Protect | Are safeguards appropriate to sensitivity | Apply security safeguards, controlled access, and governance-aware administration to reduce misuse or unnecessary exposure. |
| Retain | How long is continued retention justified | Keep information only for a justified period linked to service, evidence, legal, or operational needs. |
| Respond | Can data-subject concerns be raised | Provide a contact route for POPIA-related access, correction, deletion, objection, or related privacy requests where applicable. |
The POPIA detail this page is required to state.
BoardEvaluator™ is owned and operated by Celagenix Holdings (Pty) Ltd, the responsible party under POPIA for personal information processed through this site and platform.
Responsible party
- Celagenix Holdings (Pty) Ltd, registration number 2014/073666/07
- Registered address: 4th Floor West Wing, Nelson Mandela Square, Sandton City, Sandton, Johannesburg, 2196
- Telephone: +27 12 755 5528 · Email: popi@celagenix.com
Information Officer
- Information Officer: Martin Louw
- Deputy Information Officer: Johann Koen
- Complaints unresolved at this level may be raised with the Information Regulator of South Africa at inforegulator.org.za
What stakeholders usually want clarified before moving forward.
This section is especially important for procurement, company secretariat, pension-fund governance, and legal review teams.
Data-subject rights
Where applicable, individuals may wish to request access to personal information, ask for correction, seek deletion, object to certain processing, or ask questions about how personal information is being handled in a specific context.
Raise a POPIA or privacy request
Security safeguards
POPIA relevance and security posture work together. Hosting, encryption, role-based access, and audit-aware administration support more responsible handling of board-evaluation and website data.
Cross-border and operator considerations
Where infrastructure, operators, or service arrangements extend beyond one environment, governance teams often want clarity on how responsibilities, access, and safeguards are structured. That discussion is usually completed alongside commercial and privacy review.
What a POPIA review often includes
- The purpose for which personal information is collected and used
- Whether collection is proportionate to the evaluation or support context
- Which parties may act as operators or supporting providers
- How rights requests, objections, or corrections are handled
- How retention, deletion, and security safeguards are approached
Pages that support the POPIA discussion
- Privacy for the wider data-handling model
- Terms for legal framework and site use
- Cookies for browser-level transparency
- Security for safeguards and control posture
- Methodology for how sensitive evaluation data becomes board-ready output
Where to go next in the trust and product picture.
This keeps the legal and privacy layer aligned with the wider boardevaluator.com architecture, messaging, and internal linking model.
Review the wider legal and privacy layer
POPIA usually sits inside a broader review of privacy, security, and commercial clarity.
Understand what the POPIA posture is supporting
POPIA makes more sense when the platform and module context are also clear.
- Platform for the operating workflow
- Modules for evaluation architecture
- Data Privacy / POPIA Gap Assessment for a dedicated readiness evaluation
- Board-as-a-Whole and AI Governance for module continuity
- Packages for engagement depth
Move into a live privacy or procurement discussion
If the legal and trust posture looks right, the next step should be straightforward.
- POPIA or privacy enquiry
- General contact route
- Book a Demo
- Resources for supporting material
The POPIA questions South African governance teams actually ask.
The objective is practical clarity for South African governance stakeholders, legal reviewers, and privacy-conscious buyers.
Why is POPIA relevant to BoardEvaluator™
Because BoardEvaluator™ can involve personal information in a governance-sensitive setting, including enquiry data, participant data, workflow data, and evaluation-related information. POPIA relevance matters especially in South African legal and governance contexts.
What kinds of personal information may be involved
Depending on the interaction, this can include contact information, organisation information, participation details, evaluation workflow information, reporting-related content, and support or commercial records connected to the service.
How does POPIA connect to privacy and security
Privacy explains the wider handling model, while Security explains safeguards and control posture. POPIA provides a South African legal lens through which those practices are reviewed.
Can someone raise a POPIA-related request or concern
Yes. Use Contact us about POPIA or privacy if you need to raise a request relating to access, correction, deletion, objection, or another POPIA-related concern where applicable.
If the POPIA posture looks right, the next move is to test platform fit and governance scope.
POPIA clarity helps build trust, but the buying decision still depends on module fit, reporting needs, security posture, workflow design, and the right engagement model.