Legal · Privacy

Privacy Policy

Effective date · February 2026
01
Section

Introduction

Pinnacle Strategy Partners (Pty) Ltd ("Pinnacle Strategy Partners", "PSP", "we", "us" or "our") is committed to protecting the personal information of our clients, partners, employees and website visitors.

This Privacy Policy explains how we collect, process, store and protect personal information in accordance with the Protection of Personal Information Act, 2013 (POPIA) and other applicable data-protection laws.

By using our website, engaging our services or otherwise interacting with us, you consent to the practices described in this Privacy Policy.

02
Section

The Responsible Party

The Responsible Party in terms of POPIA is:

  • ·Pinnacle Strategy Partners (Pty) Ltd
  • ·Johannesburg Office: 533 Long Avenue, Ferndale, Randburg, 2194, South Africa
  • ·Cape Town Office: 18 William St, Woodstock, Cape Town, 7915, South Africa
  • ·Email: admin@pinnaclestrategypartners.co.za
  • ·Telephone: +27782206680

Our Information Officer can be contacted using the details above.

03
Section

Personal Information We Collect

We collect only the personal information that is necessary to deliver our services and operate our website. This may include:

  • ·Identity data: full name, professional title, employer, country of operation.
  • ·Contact data: email address, telephone number, postal address.
  • ·Engagement data: enquiries, mandate details, correspondence with our team.
  • ·Financial data: information necessary for the delivery of advisory, capital or transaction mandates (collected only where relevant).
  • ·Technical data: IP address, browser type, device type, referring URL and pages visited on our website.
  • ·Marketing preferences: subscription status for our institutional briefings.

We do not intentionally collect the personal information of children. If you believe we hold such information, please contact us and we will delete it.

04
Section

Why We Process Personal Information

We process personal information for the following purposes:

  • ·To respond to enquiries and schedule consultations.
  • ·To deliver advisory, technology, education, capital and transaction mandates to our clients.
  • ·To perform due diligence, know-your-client (KYC) and anti-money-laundering checks where required.
  • ·To distribute institutional research, briefings and thought leadership to subscribers.
  • ·To comply with legal, regulatory and professional obligations.
  • ·To improve the security, functionality and content of our website.

We will not process personal information for purposes materially different from those described above without your consent, unless required or permitted by law.

05
Section

Lawful Basis for Processing

We process personal information on one or more of the following lawful bases recognised by POPIA:

  • ·Consent — where you have given clear consent for us to process your personal information for a specific purpose.
  • ·Contractual necessity — where processing is required to conclude or perform a contract to which you are a party.
  • ·Legal obligation — where processing is required by law or professional regulation.
  • ·Legitimate interest — where processing is necessary for our legitimate business interests, balanced against your rights and freedoms.
06
Section

How We Share Personal Information

We do not sell personal information. We may share personal information with:

  • ·Members of our group of companies, on a need-to-know basis for the delivery of services.
  • ·Professional advisors (legal, audit, tax, compliance) bound by confidentiality obligations.
  • ·Trusted third-party service providers acting as Operators (as defined in POPIA), including hosting, email delivery, analytics, and payment processors.
  • ·Regulatory, government or law-enforcement authorities where required by law.
  • ·Counterparties, funders or acquirers where necessary to progress a mandate you have engaged us for, and only with your knowledge.

All third parties acting as Operators are required by contract to process personal information only on our instructions and to maintain appropriate security safeguards.

07
Section

International Transfers

Certain of our service providers (for example, cloud hosting and analytics providers) may process personal information outside the Republic of South Africa.

Where we transfer personal information across borders, we ensure that the receiving jurisdiction provides an adequate level of protection, or that the transfer is subject to appropriate contractual safeguards consistent with POPIA.

08
Section

Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law or professional standards.

Records related to advisory, capital and transaction mandates are typically retained for a minimum of five (5) years after the conclusion of the engagement, in line with professional and regulatory requirements.

Once retention is no longer required, personal information is securely destroyed, deleted or de-identified.

09
Section

Security

We implement appropriate technical and organisational security measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.

These measures include access controls, encryption in transit, secured devices, staff training and confidentiality obligations.

No system is completely secure. If we become aware of a security incident affecting your personal information, we will notify you and the Information Regulator as required by law.

10
Section

Your Rights

Subject to the requirements and limitations of POPIA, you have the right to:

  • ·Be informed about the personal information we hold about you and how we process it.
  • ·Request access to your personal information.
  • ·Request correction or deletion of your personal information where appropriate.
  • ·Object to the processing of your personal information in certain circumstances.
  • ·Withdraw any consent you have previously given.
  • ·Lodge a complaint with the Information Regulator (South Africa).

To exercise any of these rights, please contact our Information Officer using the details in this Privacy Policy.

11
Section

Cookies & Tracking

Our website may use cookies and similar technologies to operate correctly, remember your preferences, and measure how visitors use the site.

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.

We do not use cookies to build advertising profiles.

12
Section

Complaints

If you believe we have not handled your personal information in accordance with POPIA or this Privacy Policy, please contact our Information Officer in the first instance so that we can attempt to resolve the matter.

You are also entitled to lodge a complaint with the Information Regulator (South Africa): www.inforegulator.org.za.

13
Section

Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in law, our operations or best practice.

The current version, together with its effective date, will always be published on our website.

This Privacy Policy is provided in good faith and describes Pinnacle Strategy Partners' current data-protection practices. It does not constitute legal advice. For queries relating to the processing of your personal information, please contact our Information Officer using the details above.

Questions
For enquiries about this document, contact us via the details on our contact page.
Contact PSP