Legal

Privacy policy

How Comodex collects, uses, shares and protects personal information, and how to exercise your rights under the Protection of Personal Information Act.

Who is responsible

Comodex Consultancy (Pty) Ltd (registration number 2022/317332/07) is the responsible party for the personal information described in this policy.

Information Officer: Tanya Graham, Chief Executive Officer
Address: Plot 541 Mooiplaats, Pretoria, Gauteng, South Africa
Email: admin@comodex.co.za
Telephone: +27 76 691 4245

Whose information we process

This policy covers three groups of people: enquirers who contact us through this website or by phone or email; client contacts at the organisations we work for; and delegates — the learners who attend our training and assessments, usually sent to us by their employer.

What we collect, and why

From enquirers. Your name, organisation, email address, telephone number and whatever you tell us in your message. We use this only to respond to your enquiry and to prepare a proposal.

From client contacts. Name, job title, contact details and correspondence, used to manage the engagement, arrange delivery and invoice for it.

From delegates. Full name, identity or passport number, employee number, employer, job title, contact details, attendance records, assessment results and the certificates issued. Where a course requires it, we may also process information about physical fitness or a medical certificate of fitness, and details of previous qualifications or prior learning. This information is needed to register delegates, run and assess the training, issue certificates, and produce the competence records the Mine Health and Safety Act and the Occupational Health and Safety Act require your employer to keep.

From behavioural assessments. Where an engagement includes Shadowmatch or SkillsGrid profiling, we process the responses and the resulting profile. Profiling is carried out with the participant’s knowledge, and results are discussed with the participant.

From this website. Standard server logs, and cookies needed to make the site work. We do not run advertising trackers on this site.

On what legal basis

We process personal information where it is necessary to conclude or perform a contract with you or your employer; where we have a legal obligation, such as producing training and competence records; where it is necessary for our legitimate interests in running and improving our training services; and, where none of those apply, on the basis of your consent. Where we rely on consent, you may withdraw it at any time, although that may mean we can no longer provide the service.

Who we share it with

Your employer, where you attend training as an employee. Attendance, assessment outcomes and certificates are reported back to the employer who commissioned and paid for the training. Please assume your results will be shared with them.

SETAs, the MQA and accreditation bodies, where learner data must be submitted to support a discretionary grant application or to register a learner or a programme.

Facilitators and assessors contracted to deliver or assess a programme, under confidentiality obligations.

Service providers who process information on our behalf — hosting, email, assessment platforms and accounting — under written operator agreements that require them to keep it secure and use it only for us.

We do not sell personal information, and we do not share it for anyone else’s marketing.

Sending information across borders

Comodex operates in South Africa, Namibia, the Democratic Republic of Congo, Zambia and Botswana, and some of the services we use store data outside South Africa. Where personal information is transferred outside the Republic, we do so only where POPIA permits it — because the recipient is bound by a law, binding rules or a contract that provides an adequate level of protection, because the transfer is necessary to perform a contract with you, or with your consent.

How long we keep it

Enquiries that do not become engagements are kept for up to two years and then deleted.

Training records — attendance, assessment results and certificates — are kept for as long as they may be needed as competence evidence, and no less than the period required by the applicable health and safety legislation and by our accreditation obligations. This is typically several years after the training, and in some cases longer, because the record’s purpose is to prove competence long after the course.

Accounting records are kept for the period required by tax and company law.

How we protect it

We apply reasonable technical and organisational measures appropriate to the risk: access controls, encrypted connections to this website, restricted access to learner records, confidentiality obligations on staff and facilitators, and written agreements with the operators who process information for us.

If a security compromise affects your personal information, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after establishing what happened, as POPIA requires.

Your rights

You have the right to be told what personal information we hold about you and to receive a copy of it; to have information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained corrected or deleted; to object, on reasonable grounds, to our processing; to withdraw consent where we rely on it; and not to be subject to a decision based solely on automated processing that has legal consequences for you.

To exercise any of these, write to admin@comodex.co.za. Requests for access or correction are made on the prescribed POPIA forms, which we will send you. We may need to verify your identity first. We will respond within the period POPIA allows.

Some requests we may have to decline — for example, we cannot delete a training record that your employer is legally required to hold as competence evidence. If we decline, we will tell you why.

Direct marketing

We will only send you electronic marketing about our training if you are an existing client, or if you have consented. Every message includes an unsubscribe option, and you can opt out at any time by replying or writing to admin@comodex.co.za.

Cookies

This website uses cookies that are necessary for it to function, and may use basic analytics to understand which pages are read. You can block or delete cookies in your browser settings, though parts of the site may then not work as intended.

Complaining to the Regulator

If you believe we have not handled your personal information lawfully, please raise it with us first — most issues are resolved quickly.

You also have the right to complain to the Information Regulator of South Africa at any time. Complaints are lodged on the Regulator’s eServices portal at inforegulator.org.za.

Changes to this policy

We may update this policy as our services or the law change. The current version is always the one published on this page, and the date it was last updated appears below.


Last updated 8 August 2026.