Custos™ by GovernX
  • Home
  • Custos DSPM
  • Add-Ons
  • Capabilities
  • Contact
  • Portal
Sign In Schedule POV
Home › Privacy Policy
SOVEREIGN PRIVACY COMPLIANCE | POPIA, MAURITIUS DPA 2017 & EU GDPR

PRIVACY POLICY

POPIA, MAURITIUS DATA PROTECTION ACT 2017, EU GDPR, NIGERIA NDPA, AND KENYA DPA PRIVACY POLICY FOR GOVERNX (PTY) LTD

Effective Date: September 2026 | Legal Entity: GovernX (Pty) Ltd | Cape Town, South Africa | Reference: GX-POL-PRIV-001

1. Foundational Commitment: Zero-Knowledge Data Architecture

GovernX (Pty) Ltd ("GovernX", headquartered in Cape Town, South Africa) is dedicated to upholding the highest standards of data protection under the Protection of Personal Information Act No. 4 of 2013 (POPIA) of South Africa, the Mauritius Data Protection Act 2017 (DPA 2017), the Bank of Mauritius (BoM) & Financial Services Commission (FSC) Data Residency Directives, the European Union General Data Protection Regulation (EU GDPR Regulation 2016/679), the Nigeria Data Protection Act (NDPA 2023), the Kenya Data Protection Act (2019), and the African Union Malabo Convention.

[CUSTOS ZERO-KNOWLEDGE ARCHITECTURAL GUARANTEE]
GovernX does NOT store, replicate, inspect, or ingest your enterprise operational data.
Custos DSPM operates strictly as an in-place, air-gapped on-premises software daemon inside your private data center.
Zero outbound WAN telemetry. Zero cloud replication. Zero foreign jurisdiction exposure.

2. What Information GovernX Collects & How It Is Used

GovernX processes limited personal and business contact information solely for:

  • Commercial Onboarding & Proof-of-Value (POV): Corporate business email, legal entity name, designated cluster identifiers, and billing contact details to generate cryptographic Ed25519 evaluation licenses.
  • Partner Management: Reseller partner accreditation, sales representative contact details, deal registration records, and commission settlements.
  • Technical Support & Operations: Ticketing history, license renewal notifications, and authorized administrator credentials.

3. Legal Bases for Processing Under POPIA, Mauritius DPA 2017 & EU GDPR

GovernX processes information in terms of Section 11 of POPIA, Section 28 of Mauritius DPA 2017, and Article 6 of EU GDPR on the grounds of: (a) Performance of a contract to which the data subject or enterprise is party; (b) Compliance with statutory legal obligations; and (c) Legitimate commercial interests in securing enterprise software integrity.

4. Data Subject Rights (POPIA, Mauritius DPA 2017 & GDPR)

Data subjects and enterprise clients have the right to:

  • Inquire whether GovernX holds personal information about them (POPIA Sec 23, Mauritius DPA Sec 37, GDPR Art 15).
  • Request the correction, destruction, or deletion of personal information that is inaccurate, irrelevant, excessive, or obtained unlawfully (POPIA Sec 24, Mauritius DPA Sec 39, GDPR Art 16-17).
  • Object to the processing of personal information on reasonable statutory grounds (POPIA Sec 11(3), Mauritius DPA Sec 40, GDPR Art 21).
  • Lodge a complaint with their respective supervisory regulatory authority.

5. Supervisory Regulatory Authorities

For any privacy inquiries or to exercise your statutory rights, please contact our Information Officer via our Statutory Inquiries Portal →

South Africa: The Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 • Email: [email protected]

Mauritius: Data Protection Office, 5th Floor, SICOM Tower, Wall Street, Ebène Cybercity, Mauritius • Email: [email protected]

European Union: European Data Protection Board (EDPB) • Web: edpb.europa.eu

© 2026 GovernX (Pty) Ltd. Cape Town, South Africa. All rights reserved.

PAIA Manual Privacy Policy Terms of Service Contact Us