Legal

Privacy policy

How Soteria Cloud collects, uses, shares and protects personal information, and how you can exercise your rights under South African and international data-protection law.

POPIA and GDPR aligned

We process personal information in line with the Protection of Personal Information Act 4 of 2013 and, where it applies, the GDPR.

We do not sell your data

Your personal information is never sold, rented or traded. It is shared only with the operators and partners described below.

You stay in control

You can request access, correction or deletion of your information, and withdraw marketing consent at any time.

South African infrastructure

Protected workloads are held on local infrastructure in Johannesburg and Cape Town unless a partner selects otherwise.

Last updated: 11 August 2026Applies to: soteriacloud.com and all Soteria Cloud services

1. Who we are

Soteria Cloud is a South African cyber-resilience enabler for managed service providers. We supply backup, disaster recovery, cyber protection, email security and related services to MSPs, resellers and business customers, largely built on the Acronis Cyber Protect Cloud platform and supported by local infrastructure.

For the purposes of the Protection of Personal Information Act 4 of 2013 (POPIA), Soteria Cloud is the responsible party for the personal information described in this policy. Where the General Data Protection Regulation (GDPR) applies, we act as the controller for that same information. Where we process data on behalf of an MSP partner, we act as an operator (processor) — see section 6.

Questions about this policy, or requests to exercise your rights, can be sent to our Information Officer at [email protected].

2. Scope of this policy

This policy applies when you:

  • visit or interact with this website;
  • complete a contact, trial, quote, newsletter or content-download form;
  • engage with us as a partner, reseller, customer, supplier or job applicant;
  • contact our sales or support teams by email, telephone or ticket; or
  • receive marketing or service communications from us.

It does not cover third-party websites we link to. Those sites operate under their own privacy policies, and we encourage you to read them.

3. Information we collect

We collect only what we need for a clearly defined purpose. The table below sets out the categories of personal information we process, why we process each category, and the lawful basis we rely on.

CategoryExamplesPurposeLawful basis
Identity and contact detailsName, job title, company name, work email address, telephone numberResponding to enquiries, quoting, onboarding partners, account administrationContract, legitimate interest, consent
Commercial and account informationPartner or reseller details, service subscriptions, billing and payment records, support historyProviding and administering services, billing, support and service reviewsContract, legal obligation
Technical informationIP address, device and browser type, operating system, referring pages, approximate locationSite security, fraud prevention, diagnostics and performance monitoringLegitimate interest
Usage and analytics informationPages viewed, time on page, navigation paths, content downloaded, campaign source, approximate location (country, region, city) and network operator derived from a truncated, anonymised IP addressUnderstanding how the site is used so we can improve content and structureConsent
Marketing preferencesSubscription status, topic interests, communication opt-ins and opt-outsSending newsletters, product updates and enablement material you asked forConsent, legitimate interest
Recruitment informationCV, employment history, qualifications, referencesAssessing applications where you apply to work with usConsent, steps prior to a contract

We do not deliberately collect special personal information as defined in POPIA (such as health, religious or biometric data), and we ask that you do not send it to us in enquiry or support messages.

4. How we collect it

  • Directly from you — when you complete a form, request a trial, download a resource, subscribe to updates, log a support ticket or speak to our team.
  • Automatically — through cookies, server logs and analytics when you browse the site.
  • From your organisation — where your employer or MSP partner provides your work contact details so we can administer a service.
  • From public and third-party sources — such as company websites, business directories and professional networks, where this is lawful and relevant to a business relationship.

5. Why we process it and our lawful basis

We process personal information where at least one of the following applies:

  • Performance of a contract — to deliver, support and bill for the services you or your organisation have taken up.
  • Legitimate interests — to run and secure our business, understand demand, prevent fraud and abuse, and communicate with business contacts about relevant services, provided your rights do not override those interests.
  • Consent — for optional analytics cookies, newsletters and marketing communications. You may withdraw consent at any time.
  • Legal obligation — to meet tax, accounting, regulatory and lawful-request requirements.
  • Protection of a legitimate interest of the data subject — for example, notifying you of a security issue that affects you.

6. Partner and end-customer data

When an MSP partner uses our platform to protect their customers’ systems, that partner remains the responsible party for the end-customer data held in those workloads. Soteria Cloud acts as an operator under POPIA (a processor under the GDPR) and processes that data only on the partner’s documented instructions and in terms of the agreement between us.

In that role we:

  • do not access backup or workload content except where required to deliver support, resolve a fault or comply with the law;
  • apply encryption in transit and at rest as configured within the platform;
  • maintain administrative access controls and audit logging; and
  • return or delete data at the end of the engagement in line with the agreement and applicable retention rules.

If you are an end customer of one of our partners, please direct data-subject requests to that partner in the first instance. We will support them in responding.

7. Who we share information with

We share personal information only where it is necessary, and always subject to confidentiality and data-protection obligations. Recipients may include:

  • Technology vendors and operators — including Acronis and the hosting, email, ticketing, CRM and analytics providers that support our services.
  • Data-centre and connectivity providers — for the local infrastructure on which protected workloads are held.
  • Professional advisers — auditors, accountants, insurers and legal advisers, where required.
  • Authorities — where we are legally obliged to disclose information, or to establish, exercise or defend legal claims.
  • A successor entity — in the event of a merger, acquisition or business reorganisation, subject to equivalent protection.

We do not sell, rent or trade personal information, and we do not share it with third parties for their own independent marketing.

8. Cross-border transfers

Protected workloads are held on local infrastructure in Johannesburg and Cape Town unless a partner expressly selects a different region. Some of our operational tools — for example email, CRM and analytics platforms — are operated by providers outside South Africa.

Where personal information is transferred across a border, we do so in terms of section 72 of POPIA, and rely on one or more of the following: a recipient bound by binding rules or an agreement giving substantially similar protection; standard contractual clauses; your consent; or the transfer being necessary to perform a contract with you.

9. How long we keep information

We keep personal information only for as long as it is needed for the purpose it was collected for, or as long as the law requires. In practice:

  • Enquiries that do not progress — retained for up to 24 months so we can pick up the conversation, then deleted.
  • Partner and customer account records — retained for the life of the relationship and for a further five years thereafter, to meet tax, accounting and contractual requirements.
  • Marketing subscriptions — retained until you unsubscribe, plus a suppression record so we do not contact you again in error.
  • Website analytics — retained in aggregated or pseudonymised form according to the retention settings of the analytics platform.
  • Backup and workload data — retained according to the retention policy configured by the responsible partner or customer.

10. How we protect information

We apply appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information, and we review them as risks change. These include:

  • encryption of data in transit and at rest across our platform services;
  • role-based access control, least-privilege administration and multi-factor authentication for administrative access;
  • network protection, endpoint protection and monitoring across managed infrastructure;
  • segregated environments, logging and change control;
  • vendor due diligence and written operator agreements; and
  • staff confidentiality obligations and security awareness training.

No system can be guaranteed completely secure. We ask that you protect your own account credentials and notify us immediately if you suspect unauthorised access.

11. Security compromise notification

If we reasonably believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, as required by section 22 of POPIA. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours where the breach is notifiable. Where we act as an operator for a partner, we will notify that partner without undue delay so they can meet their own obligations.

12. Cookies and analytics

We use a limited set of cookies. Essential cookies are needed for the site to function and for security. Analytics cookies are loaded only where you have given consent, and they help us understand how the site is used so we can improve it. You can change or withdraw your choice at any time through your browser settings or the consent controls on the site.

Full detail is set out in our cookie policy.

13. Marketing and direct communications

We send newsletters, product updates and enablement material only to people who have asked for them, or to existing business contacts where the content is directly relevant to the services they take from us. Every marketing email includes an unsubscribe link, and you can also opt out at any time by emailing [email protected].

Service messages — such as billing notices, incident notifications and changes to terms — are not marketing and will continue for as long as you hold an account with us.

14. Your rights

Subject to the conditions and exemptions in POPIA and, where applicable, the GDPR, you have the right to:

  • Be informed that we hold personal information about you and what we do with it.
  • Access the personal information we hold about you.
  • Correct or complete information that is inaccurate, misleading, out of date or incomplete.
  • Request deletion or destruction of information we are no longer entitled to retain.
  • Object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Withdraw consent where processing is based on consent, without affecting processing carried out before the withdrawal.
  • Restrict processing in defined circumstances, such as while an accuracy dispute is being resolved.
  • Data portability — to receive certain information in a structured, commonly used, machine-readable format where the GDPR applies.
  • Not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you.
  • Complain to the Information Regulator or another competent supervisory authority.

To exercise any of these rights, email [email protected]. We may ask for proof of identity before acting on a request, and we will respond within a reasonable period and in any event within the timeframes set by law. Requests under POPIA may need to be made on the prescribed Form 2, which we will provide on request. There is no charge for a straightforward request, although a reasonable fee may apply where a request is manifestly excessive or repetitive.

15. Complaints and how to contact us

We would prefer the opportunity to resolve any concern directly, so please contact us first. You are, however, entitled to lodge a complaint with the Information Regulator (South Africa) at any time.

Information Regulator (South Africa)

Soteria Cloud Information Officer

Contact our team

16. Children

Our website and services are intended for business users. We do not knowingly collect personal information of children under the age of 18 without the consent of a competent person. If you believe we hold such information, please contact us and we will delete it.

17. Changes to this policy

We review this policy regularly and may update it to reflect changes in our services, technology or legal obligations. The “last updated” date at the top of this page shows when it was last revised. Where a change materially affects how we use your personal information, we will tell you directly or place a prominent notice on the site.

This policy should be read together with our cookie policy and our terms of service.