Responsible party FHI Consulting Engineers (Pty) Ltd
Registration number 2020/165528/07
Effective date 7 August 2026
Website fhiconsult.co.za
Privacy contact Information Officer | info@fhiconsult.co.za | +27 21 300 1006

FHI respects the privacy of its clients, project partners, suppliers, employees, applicants, website visitors and other people whose personal information it processes. This policy explains what FHI collects, why it uses it, who it may share it with and how data subjects may exercise their rights.

1. About this policy

FHI Consulting Engineers (Pty) Ltd ("FHI", "we", "us" or "our") is a South African structural and civil engineering consultancy. For the personal information described in this policy, FHI is generally the "responsible party" as defined in POPIA because it determines why and how that information is processed.

This policy applies to personal information processed through our website, enquiry forms, email and telephone communications, professional appointments, project delivery, site activities, supplier and consultant relationships, recruitment, marketing, social media and normal business administration. It applies to information relating to identifiable natural persons and, where POPIA provides, identifiable juristic persons.

This policy must be read with any project-specific notice, employee or applicant notice, contractual confidentiality term, website cookie notice, consent form or PAIA Manual issued by FHI. If a more specific notice applies to a particular processing activity, that notice will supplement this policy.

2. Key definitions

Personal information: information relating to an identifiable living natural person and, where applicable, an identifiable juristic person. It includes contact, identity, financial, employment, technical, location, online and correspondence information.

Processing: any operation involving personal information, including collection, receipt, recording, organisation, storage, use, updating, sharing, retrieval, restriction, deletion and destruction.

Data subject: the person or organisation to whom personal information relates.

Operator: a third party that processes personal information for FHI under a mandate or contract, without determining the purpose of the processing.

Special personal information: information that POPIA treats as particularly sensitive, including certain health, biometric, religious, philosophical, political, trade union, sex-life and criminal behaviour information.

3. Personal information FHI may collect

Depending on how a person interacts with FHI, we may collect the following categories of personal information:

  • Identity and contact information: names, initials, job title, organisation, identity or registration number where necessary, telephone number, email address, postal or physical address and signature.

  • Client and project information: details contained in appointments, briefs, proposals, tenders, contracts, meeting records, instructions, drawings, reports, site records, photographs, property or erf details, project addresses, professional registrations and correspondence.

  • Professional and employment information: employer, role, qualifications, professional body membership, registration number, work history, references and information included in a CV or job application.

  • Financial and commercial information: quotation and invoice details, billing address, purchase orders, tax information, payment status, bank details where reasonably required and records needed for accounting or audit purposes.

  • Supplier and consultant information: onboarding and due-diligence records, contact details, contractual information, B-BBEE or compliance documentation, insurance information and performance records.

  • Site, visitor and safety information: site access details, attendance records, vehicle registration details, induction records, emergency contacts and health or safety information where required for lawful site management.

  • Communications: emails, telephone notes, meeting minutes, complaints, requests, feedback and other correspondence with FHI.

  • Website and device information: IP address, browser and device type, operating system, referring pages, pages viewed, approximate location derived from an IP address, dates and times of visits, cookie identifiers, security logs and information submitted through website forms.

  • Marketing and public engagement information: communication preferences, consent records, event attendance, social media interactions and public professional profile information.

  • Special personal information: limited health, injury, disability, biometric or criminal information only where this is relevant, lawful, proportionate and appropriately authorised, for example for workplace safety, site access or a legal obligation.

4. How FHI collects personal information

FHI may collect personal information:

  • directly from the data subject, including through the website contact form, email, telephone, meetings, contracts, project documents, site visits, applications or other correspondence;

  • from a client, employer, colleague, representative, project manager, architect, contractor, quantity surveyor, developer, subconsultant, supplier, referee or other member of a professional team;

  • from public sources such as professional registers, CIPC records, property or planning records, tender portals, company websites, social media and professional networking platforms;

  • from service providers that support FHI's website, email, document management, accounting, security, recruitment or business administration; and

  • automatically when a person uses the website, through server logs, cookies and similar technologies where these are enabled.

Where FHI receives personal information from another source, we will process it only where there is a lawful basis and, where required, will tell the data subject the source or category of source.

5. Why FHI processes personal information

FHI may process personal information for the following purposes:

  • responding to enquiries, preparing proposals or quotations and communicating about possible or active projects;

  • entering into, managing and performing professional appointments, contracts and project instructions;

  • providing structural and civil engineering services, coordinating with project teams, conducting inspections and administering project records;

  • confirming identity, authority, qualifications, professional registration, supplier suitability or other information relevant to a business relationship;

  • managing billing, payments, tax, insurance, audit, recordkeeping and financial administration;

  • managing suppliers, consultants, contractors, employees, applicants and workplace or site safety;

  • protecting FHI's systems, premises, personnel, projects, confidential information, legal rights and professional interests;

  • meeting legal, regulatory, professional, contractual, reporting and insurance obligations;

  • investigating and responding to complaints, disputes, incidents, claims or suspected unlawful conduct;

  • maintaining and improving the website, understanding how it is used, preventing misuse and measuring communications where analytics are enabled;

  • sharing relevant company news, engineering insights, project updates or invitations in accordance with direct marketing law; and

  • using project photographs or descriptions in FHI's portfolio, website or social media where FHI has the necessary authority and takes reasonable steps to avoid unnecessary personal information.

6. Lawful grounds for processing

FHI will rely on one or more lawful grounds recognised by POPIA, depending on the circumstances:

  • the data subject has consented to the processing;

  • the processing is necessary to conclude or perform a contract to which the data subject is a party;

  • the processing is required to comply with an obligation imposed by law;

  • the processing protects a legitimate interest of the data subject;

  • the processing is necessary for the proper performance of a public-law duty by a public body, where applicable; or

  • the processing is necessary to pursue the legitimate interests of FHI or a third party, provided those interests are balanced against the data subject's rights and reasonable expectations.

Where consent is the lawful ground, the data subject may withdraw it at any time. Withdrawal does not affect processing that was lawful before the withdrawal, and FHI may continue processing where another lawful ground applies.

7. Whether providing information is voluntary or mandatory

In most enquiry and marketing contexts, providing personal information is voluntary. Certain information becomes mandatory where FHI needs it to verify identity or authority, prepare or perform a contract, issue an invoice, manage a site safely, comply with professional or legal obligations, or respond to a lawful request.

If required information is not provided, FHI may be unable to respond fully, provide a quotation, appoint or pay a supplier, consider an application, grant site access, enter into or perform a contract, deliver engineering services, or meet a legal obligation.

8. Accuracy and minimality

FHI aims to collect only personal information that is adequate, relevant and not excessive for the stated purpose. We take reasonably practicable steps to keep information complete, accurate, not misleading and updated where necessary. Data subjects should tell FHI when their information changes or appears to be incorrect.

9. Sharing and disclosure

FHI does not sell personal information. We may disclose it only where reasonably necessary and lawful, including to:

  • FHI's directors, employees and authorised contractors who need it to perform their duties;

  • clients and members of a project team, including architects, project managers, quantity surveyors, contractors, developers, owners, subconsultants and other professional advisers;

  • website hosting, email, cloud storage, document management, IT support, cybersecurity, communications, analytics, accounting, payroll, banking, payment, recruitment and records-management providers acting as operators or independent responsible parties;

  • auditors, accountants, insurers, brokers, attorneys, advocates, debt-recovery providers and other professional advisers;

  • professional bodies, regulators, municipalities, government departments, courts, law-enforcement bodies or other authorities where disclosure is required or permitted by law;

  • a prospective purchaser, investor, funder or successor in connection with a lawful restructuring, merger, sale or transfer of all or part of FHI's business, subject to appropriate confidentiality; and

  • any other person authorised by the data subject or otherwise permitted by law.

Where a service provider acts as an operator for FHI, FHI will take reasonable steps to require confidentiality, appropriate security safeguards and processing only under FHI's authority, as required by POPIA.

10. Cross-border transfers

Some technology, cloud, email, data-storage, software or professional service providers may process or store personal information outside South Africa. FHI will transfer personal information to another country only where the transfer is permitted by section 72 of POPIA, for example where the recipient is subject to a law, binding corporate rules or agreement that provides an adequate level of protection; the data subject consents; the transfer is necessary for a contract; or another statutory ground applies.

FHI will take reasonably practicable steps to understand where important information is hosted and to apply contractual, organisational or technical safeguards appropriate to the risk.

11. Website forms, cookies and analytics

The FHI website contact form may collect a person's name, email address, subject and message. FHI uses this information to respond to the enquiry, maintain a record of the communication and take related steps requested by the person.

The website and its hosting environment may use cookies, server logs and similar technologies. These can include:

  • essential and security technologies needed to operate the website, route traffic, remember privacy choices and protect forms or systems;

  • preference technologies that remember settings selected by a visitor;

  • analytics technologies that help FHI understand website traffic, performance and usage; and

  • third-party technologies connected with embedded content, maps, fonts, videos or social media features, if those features are used.

Where non-essential cookies require consent, FHI will request it through an appropriate cookie banner or settings tool. A visitor can also restrict or delete cookies through browser settings, although doing so may affect website functionality. Third-party providers process information under their own privacy terms where they act as independent responsible parties.

12. Direct marketing

FHI may send relevant company news, project updates, engineering insights, event invitations or information about its services where POPIA and other applicable law permit. For unsolicited electronic direct marketing, FHI will obtain consent where required or rely on the limited existing-customer circumstances allowed by law.

Every marketing communication will identify FHI and provide a reasonable way to opt out. A person may object to direct marketing or withdraw marketing consent at any time by using the unsubscribe method provided or contacting info@fhiconsult.co.za. FHI will not charge a fee for an objection or opt-out request.

13. Security safeguards

FHI applies reasonable technical and organisational measures appropriate to the nature of the information and the risk of loss, damage, unauthorised destruction, unlawful access or unlawful processing. Measures may include access controls, password and device safeguards, role-based access, backups, secure cloud or hosting arrangements, confidentiality obligations, supplier controls, staff awareness, physical security and secure disposal.

No internet transmission or storage system can be guaranteed completely secure. FHI therefore reviews safeguards where reasonably necessary and expects data subjects and project partners to use appropriate security when sending or storing confidential information.

14. Security compromises

If FHI has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, FHI will investigate, take reasonable containment and remedial steps, and notify the Information Regulator and affected data subjects as soon as reasonably possible where POPIA requires. A notification may describe what occurred, the possible consequences, measures taken or planned, practical steps the data subject can take, and the identity of the unauthorised person where known and lawful to disclose.

15. Retention and destruction

FHI retains personal information only for as long as reasonably necessary to achieve the purpose for which it was collected, comply with a law or professional obligation, perform or enforce a contract, resolve a complaint or dispute, support an insurance or legal claim, or protect a legitimate interest consistent with POPIA.

Records connected with engineering services, design decisions, professional appointments, construction projects and potential claims may need to be retained for extended periods due to contractual, professional, insurance, evidential or legal requirements. Retention periods may therefore differ by record category.

When information is no longer required and no lawful reason for retention remains, FHI will delete, destroy or de-identify it in a manner that reasonably prevents reconstruction in an intelligible form.

16. Recruitment, employees and contractors

FHI may process applicant, employee and contractor information to assess suitability, verify qualifications and references, manage appointments and remuneration, administer benefits and leave, meet tax and labour obligations, protect health and safety, manage performance and discipline, maintain records and end the relationship lawfully.

Unsuccessful applicant information will be retained only for a lawful and reasonable period, or longer with appropriate consent where FHI wishes to consider the person for future opportunities. More detailed internal notices or policies may apply to employees and contractors.

17. Children's personal information

FHI's website and engineering services are not directed at children. FHI does not knowingly collect or process a child's personal information unless a competent person has consented, the processing is required or permitted by law, or another authorisation under POPIA applies. If a parent, guardian or competent person believes that FHI has received a child's information without proper authority, they should contact the Information Officer so that FHI can investigate and take appropriate action.

18. Automated decision-making

FHI does not currently make decisions that have legal or similarly significant effects on a person based solely on automated processing of personal information. If this changes, FHI will provide any notice, explanation and safeguards required by POPIA.

19. Data subject rights

Subject to POPIA, PAIA and any lawful limitations, a data subject may:

  • ask whether FHI holds personal information about them and request access to that information;

  • request correction or updating of inaccurate, irrelevant, excessive, out-of-date, incomplete or misleading information;

  • request deletion or destruction of information that FHI is no longer authorised to retain;

  • object, on reasonable grounds relating to their particular situation, to processing based on certain lawful grounds;

  • object at any time to processing for direct marketing;

  • withdraw consent where processing depends on consent;

  • request information about the identity of third parties that have had access to their information where POPIA gives that right;

  • not be subject to certain decisions based solely on automated processing; and

  • lodge a complaint with the Information Regulator or pursue another remedy available by law.

Some rights are not absolute. FHI may lawfully refuse or limit a request, for example where access would reveal another person's information, legal privilege applies, retention is required by law, or a PAIA ground of refusal applies. FHI will explain a refusal where required.

20. How to exercise a privacy right

A request may be sent to FHI's Information Officer at info@fhiconsult.co.za. The requester should provide enough detail to identify themselves, the information or processing concerned, the right being exercised and the preferred contact method. FHI may request reasonable proof of identity or authority before releasing or changing information.

FHI will respond within the periods required by applicable law. Access to records may require a prescribed PAIA form and may be subject to a lawful fee. Requests to object, correct or delete personal information may require the forms prescribed under POPIA. FHI will provide reasonable assistance where appropriate.

21. Access to records under PAIA

The Promotion of Access to Information Act 2 of 2000 (PAIA) governs formal requests for access to records held by private bodies where the record is required for the exercise or protection of a right. This Privacy Policy does not replace FHI's PAIA Manual. A PAIA request must be made in the prescribed form and sent to FHI's Information Officer using the contact details below. FHI may grant, refuse or defer access only as permitted by law.

22. Third-party websites and platforms

The FHI website may link to social media platforms, professional bodies, project partners or other third-party websites. FHI does not control those services and is not responsible for their privacy practices. A person should read the relevant third party's privacy notice before providing information or using its service.

23. Changes to this policy

FHI may update this policy to reflect changes in law, guidance, technology, service providers or business practices. The current version will be published on the FHI website with its effective or last-updated date. Material changes may also be communicated directly where reasonably practicable or legally required.

24. Contact FHI

Responsible party: FHI Consulting Engineers (Pty) Ltd

Registration number: 2020/165528/07

Information Officer: FHI's duly registered Information Officer / Head of Private Body

Email: info@fhiconsult.co.za

Telephone: +27 21 300 1006

Postal address: Suite #41, Private Bag X22, Tyger Valley, 7536, South Africa

Satellite office: Workshop 17, 32 Kloof Street, Cape Town, 8000, South Africa

Website: fhiconsult.co.za

25. Complaints to the Information Regulator

FHI encourages data subjects to contact the Information Officer first so that concerns can be investigated and, where possible, resolved. A person also has the right to lodge a complaint with the Information Regulator (South Africa):

POPIA complaints: POPIAComplaints@inforegulator.org.za

General enquiries: enquiries@inforegulator.org.za

Telephone: 010 023 5200

Toll free: 0800 017 160

Physical address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191, South Africa

Postal address: PO Box 31533, Braamfontein, Johannesburg, 2017, South Africa

Website: inforegulator.org.za