Full Privacy Policy

LERETHA LEGAL (PTY) LTD

ELECTRONIC COMMUNICATIONS, DIGITAL COMMUNICATIONS, PRIVACY, CYBERSECURITY AND ARTIFICIAL INTELLIGENCE POLICY

Approved by: Board of Directors

TABLE OF CONTENTS

  1. Purpose
  2. Definitions and Interpretation
  3. Application of this Policy
  4. Electronic Communications
  5. Confidentiality
  6. Legal Professional Privilege
  7. Professional Engagements and Mandates
  8. Electronic Communications under the Electronic Communications and Transactions Act
  9. Protection of Personal Information
  10. Artificial Intelligence and Automated Technologies
  11. Cybersecurity
  12. Banking Details and Payment Fraud
  13. Electronic Signatures
  14. Monitoring of Communications
  15. Intellectual Property
  16. Website and Digital Platforms
  17. Social Media and Messaging Platforms
  18. Record Retention
  19. Limitation of Liability
  20. Governing Law
  21. Amendment of this Policy/General Provisions
  1. PURPOSE

1.1 The purpose of this Policy is to establish a comprehensive governance framework regulating electronic communications issued by or on behalf of Leretha Legal (Pty) Ltd (“Leretha Legal” or “the Consultancy”).

1.2 This Policy seeks to—

(a) safeguard confidential and privileged information;

(b) protect the interests of clients and the Consultancy;

(c) regulate the use of electronic communications;

(d) promote sound corporate governance;

(e) minimise cybersecurity risks;

(f) ensure compliance with applicable South African legislation; and

(g) establish clear standards governing digital communications and emerging technologies.

1.3 This Policy forms part of Leretha Legal’s governance framework and shall be read together with all engagement letters, consultancy agreements, privacy notices and website terms and conditions.

  1. DEFINITIONS AND INTERPRETATION

Unless the context indicates otherwise—

“Artificial Intelligence” or “AI” means any software, algorithm, large language model, machine learning application, generative AI platform or automated decision-making technology capable of processing, analysing or generating information.

“Business Day” means any day other than a Saturday, Sunday or public holiday in the Republic of South Africa.

“Client” means any natural or juristic person who has entered into a written consultancy agreement with Leretha Legal.

“Confidential Information” includes all information, whether written, verbal or electronic, relating to clients, legal matters, commercial transactions, business operations, financial affairs, intellectual property and proprietary methodologies.

“Consultancy” means Leretha Legal (Pty) Ltd.

“Electronic Communication” bears the meaning assigned to it in the Electronic Communications and Transactions Act 25 of 2002 and includes emails, attachments, electronic documents, cloud-based documents, electronic signatures, instant messaging, WhatsApp messages, Microsoft Teams communications, SMSs, electronic file transfers and any similar form of digital communication.

“POPIA” means the Protection of Personal Information Act 4 of 2013.

“ECT Act” means the Electronic Communications and Transactions Act 25 of 2002.

“RICA” means the Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002.

Words importing one gender include the others, the singular includes the plural and vice versa, and references to legislation include any amendment or replacement thereof.

  1. APPLICATION OF THIS POLICY

3.1 This Policy applies to—

(a) all directors;

(b) consultants;

(c) employees;

(d) contractors;

(e) temporary personnel;

(f) authorised representatives; and

(g) any person communicating electronically on behalf of the Consultancy.

3.2 The Policy governs all electronic communications irrespective of the device, platform or application utilised.

3.3 This Policy applies to communications transmitted by email, cloud platforms, collaboration software, websites, electronic portals, messaging platforms and any future digital communication technology adopted by the Consultancy.

  1. ELECTRONIC COMMUNICATIONS

4.1 Electronic communications constitute an important component of the Consultancy’s professional services and business operations.

4.2 Recipients are reminded that electronic communications are transmitted across public communication networks and may be susceptible to interception, corruption, unauthorised access or delay despite reasonable security measures.

4.3 No recipient may assume that an electronic communication is complete unless expressly confirmed by the Consultancy.

4.4 Electronic communications shall be interpreted together with this Policy, which is incorporated by reference into every communication issued by the Consultancy.

  1. CONFIDENTIALITY

5.2 Communications may contain confidential commercial information, privileged legal advice, proprietary methodologies, strategic recommendations, financial information or personal information protected by law.

5.3 A person receiving any communication in error shall immediately—

(a) notify the sender;

(b) permanently delete the communication and all copies;

(c) refrain from copying, disclosing or relying upon its contents; and

(d) take all reasonable steps to preserve confidentiality.

5.4 Unauthorised disclosure of confidential information may constitute a breach of contract, a delict, an infringement of intellectual property rights, a breach of statutory obligations or any combination thereof.

  1. LEGAL PROFESSIONAL PRIVILEGE

Where applicable, communications issued by the Consultancy may attract legal professional privilege recognised under South African law.

Nothing contained in an electronic communication shall constitute a waiver of such privilege.

The inadvertent transmission of privileged material shall not diminish or extinguish any rights available to the Consultancy or its clients.

Recipients becoming aware that privileged information has been received in error are expected to act in accordance with their legal and ethical obligations.

  1. PROFESSIONAL ENGAGEMENTS AND MANDATES

No electronic communication shall—

  • constitute formal legal advice;
  • create a consultancy agreement;
  • establish a fiduciary relationship;
  • amount to acceptance of instructions;
  • vary an existing agreement; or
  • constitute any undertaking on behalf of the Consultancy,

unless expressly confirmed in writing by a duly authorised representative.

No person shall become a client merely through correspondence with the Consultancy.

Professional engagements shall arise only upon the execution of a written engagement letter or consultancy agreement.

  1. ELECTRONIC COMMUNICATIONS UNDER THE ELECTRONIC COMMUNICATIONS AND TRANSACTIONS ACT

In accordance with the Electronic Communications and Transactions Act 25 of 2002—

(a) data messages are capable of creating legally enforceable rights and obligations;

(b) information incorporated by reference through hyperlinks may form part of an electronic communication;

(c) electronic signatures may satisfy statutory signature requirements where permitted by law; and

(d) electronic communications shall be interpreted in accordance with the provisions of the ECT Act.

The Consultancy may incorporate this Policy by reference in electronic communications by means of a hyperlink directing recipients to the current version published on its official website.

  1. PROTECTION OF PERSONAL INFORMATION

9.1 Commitment to Privacy

The Consultancy recognises that personal information is a valuable asset requiring lawful, responsible and secure processing. The Consultancy is committed to protecting the privacy of its clients, employees, service providers and all persons whose personal information is processed in the course of its business.

9.2 Legislative Compliance

The Consultancy processes personal information in accordance with—

(a) the Protection of Personal Information Act 4 of 2013;

(b) the Promotion of Access to Information Act 2 of 2000, where applicable;

(c) the Electronic Communications and Transactions Act 25 of 2002;

(d) any applicable regulations issued under the above legislation; and

(e) any other applicable South African legislation governing privacy, information security and data protection.

9.3 Lawful Processing

Personal information shall be collected and processed only where there is an appropriate legal basis, including—

(a) the performance of a consultancy agreement;

(b) compliance with a legal obligation;

(c) the protection of a legitimate interest;

(d) the pursuit of the legitimate interests of the Consultancy or its clients; or

(e) the consent of the data subject where required by law.

9.4 Security Safeguards

The Consultancy shall implement reasonable technical and organisational measures to safeguard personal information against accidental loss, unauthorised access, destruction, misuse, alteration or disclosure.

9.5 Recipient Obligations

Recipients of communications containing personal information shall not—

(a) disclose such information without lawful authority;

(b) retain information for longer than reasonably necessary;

(c) process information for purposes unrelated to the original communication; or

(d) permit unauthorised persons access thereto.

  1. ARTIFICIAL INTELLIGENCE AND AUTOMATED TECHNOLOGIES

10.1 General Principles

The Consultancy recognises that artificial intelligence has become an integral component of modern professional practice. The use of such technologies shall always be consistent with applicable legislation, professional ethics and the duty of confidentiality owed to clients.

10.2 Confidential Information

Without the prior written consent of the Consultancy, recipients shall not upload, submit or disclose communications received from the Consultancy to—

  • public artificial intelligence platforms;
  • large language models;
  • automated document review systems;
  • publicly accessible machine learning tools; or
  • similar technologies capable of storing, analysing or reproducing confidential information.

10.3 Preservation of Privilege

Recipients are reminded that uploading confidential legal communications to external artificial intelligence platforms may compromise confidentiality, waive legal professional privilege and expose confidential information to unauthorised third parties.

10.4 Internal Use

The Consultancy may utilise artificial intelligence technologies to improve efficiency, legal research, drafting and operational processes, provided that such use complies with—

  • POPIA;
  • professional ethical obligations;
  • confidentiality requirements;
  • internal governance standards; and
  • applicable cybersecurity controls.

Artificial intelligence shall not replace professional legal judgment.

  1. CYBERSECURITY

11.1 Information Security

The Consultancy is committed to maintaining an appropriate information security framework designed to protect its systems, information assets and electronic communications.

11.2 Security Measures

Reasonable safeguards may include—

(a) multi-factor authentication;

(b) encryption technologies;

(c) secure cloud storage;

(d) access controls;

(e) password management protocols;

(f) endpoint protection;

(g) malware detection;

(h) routine software updates; and

(i) cybersecurity awareness training.

11.3 Security Incidents

Any suspected cybersecurity incident affecting communications originating from the Consultancy should be reported immediately to the Consultancy.

Recipients should not rely upon suspicious communications requesting urgent payments, amended banking details or confidential information.

  1. BANKING DETAILS AND PAYMENT FRAUD

12.1 Warning

Cyber fraud and Business Email Compromise continue to present significant commercial risks.

12.2 Banking Details

 The Consultancy shall not accept liability for payments made to fraudulent bank accounts where banking details have not been independently verified.

12.3 Verification

Before making payment, recipients are required to verify banking details telephonically using independently obtained contact information.

Recipients should never rely solely upon banking details contained in an email.

12.4 No Liability

The Consultancy shall not be liable for losses arising from—

(a) phishing attacks;

(b) spoofed email addresses;

(c) fraudulent payment instructions;

(d) cyber impersonation;

(e) unauthorised interception of communications; or

(f) similar criminal conduct beyond its reasonable control.

12.4 No Liability

The Consultancy shall not be liable for losses arising from—

(a) phishing attacks;

(b) spoofed email addresses;

(c) fraudulent payment instructions;

(d) cyber impersonation;

(e) unauthorised interception of communications; or

(f) similar criminal conduct beyond its reasonable control.

  1. ELECTRONIC SIGNATURES

13.1 Recognition

Where permitted by law, electronic signatures may be utilised by the Consultancy in accordance with the Electronic Communications and Transactions Act.

13.2 Exclusions

Nothing contained in this Policy shall require the Consultancy to execute any document electronically.

The Consultancy reserves the right to require original signatures where appropriate.

13.3 Authority

No electronic signature shall bind the Consultancy unless applied by a duly authorised representative acting within the scope of his or her authority.

  1. MONITORING OF COMMUNICATIONS

Subject to applicable legislation, including RICA, electronic communications transmitted to or from the Consultancy may be—

  • monitored;
  • filtered;
  • archived;
  • reviewed;
  • intercepted where authorised by law; or
  • retained,

for purposes including—

(a) regulatory compliance;

(b) quality assurance;

(c) cybersecurity;

(d) fraud prevention;

(e) business continuity;

(f) litigation management; and

(g) operational administration.

Nothing in this clause authorises unlawful interception contrary to applicable legislation.

  1. INTELLECTUAL PROPERTY

15.1 Ownership

All copyright, intellectual property rights, legal precedents, templates, reports, opinions, memoranda, methodologies, policies and other proprietary material created by or for the Consultancy remain the exclusive property of Leretha Legal (Pty) Ltd unless otherwise agreed in writing.

15.2 Restrictions

Recipients shall not—

(a) reproduce;

(b) publish;

(c) distribute;

(d) modify;

(e) commercialise; or

(f) exploit,

any material originating from the Consultancy without prior written consent.

15.3 No Licence

No communication shall be interpreted as granting any licence or intellectual property rights except where expressly recorded in writing.

  1. LIMITATION OF LIABILITY

Electronic communications are transmitted through third-party communication networks over which the Consultancy exercises no control.

Accordingly, the Consultancy does not warrant that electronic communications will—

(a) be uninterrupted;

(b) be delivered without delay;

(c) remain confidential during transmission;

(d) be free from malicious software;

(e) remain unaltered after transmission; or

(f) always reach the intended recipient.

To the fullest extent permitted by law, the Consultancy excludes liability for any direct, indirect, incidental or consequential loss arising from—

  • delayed communications;
  • corrupted data;
  • communication failures;
  • cybercrime;
  • malware;
  • network outages;
  • unauthorised access;
  • interception by third parties; or
  • reliance upon incomplete or altered electronic communications.

Nothing contained in this Policy excludes liability where such exclusion is prohibited by law.

  1. WEBSITE, DIGITAL PLATFORMS AND ONLINE SERVICES

17.1 Application

This Policy applies to all electronic information made available by the Consultancy through its website, client portals, cloud-based platforms, collaboration tools and other digital services used in the ordinary course of business.

17.2 Website Content

The information published on the Consultancy’s website is provided for general information purposes only and does not constitute legal advice, a legal opinion or any form of professional undertaking.

No person shall act or refrain from acting solely on the basis of information published on the Consultancy’s website without first obtaining professional advice appropriate to the particular circumstances.

17.3 Hyperlinks

For convenience, the Consultancy’s website may contain hyperlinks to third-party websites or digital platforms.

The inclusion of any hyperlink does not constitute an endorsement, recommendation or approval of the relevant website, its owners, products, services or content.

The Consultancy accepts no responsibility for the accuracy, security, availability or privacy practices of any third-party website.

17.4 Availability

Whilst every reasonable effort is made to maintain uninterrupted access to the Consultancy’s website and digital platforms, no warranty is given that such services will be continuously available or free from interruption, technical malfunction or cybersecurity threats.

The Consultancy reserves the right to suspend, modify or discontinue any online service without prior notice where reasonably necessary.

  1. SOCIAL MEDIA, INSTANT MESSAGING AND COLLABORATION PLATFORMS

18.1 Approved Platforms

The Consultancy may utilise various electronic communication platforms, including email, Microsoft Teams, Microsoft SharePoint, Microsoft OneDrive, WhatsApp Business, Zoom and other approved business collaboration tools.

18.2 Informal Communications

Communications transmitted through instant messaging applications are intended to facilitate efficient communication and shall not, unless expressly stated otherwise, constitute—

  • legal advice;
  • acceptance of instructions;
  • contractual undertakings;
  • settlement agreements; or
  • amendments to existing agreements.

Formal legal advice shall ordinarily be communicated by way of written correspondence, memorandum, opinion or other approved documentation.

18.3 Social Media

No statement published on any social media platform by an employee, consultant or representative shall bind the Consultancy unless expressly authorised.

Views expressed on personal social media accounts remain those of the individual concerned and shall not be attributed to the Consultancy.

The Consultancy reserves the right to take appropriate disciplinary or contractual action where electronic communications damage its reputation, disclose confidential information or otherwise breach this Policy.

  1. RECORD RETENTION AND DOCUMENT MANAGEMENT

19.1 Records

Electronic records generated or received by the Consultancy shall be retained in accordance with applicable legislation, regulatory requirements and the Consultancy’s internal records management procedures.

19.2 Storage

Electronic records may be stored using secure cloud-based or on-premises systems maintained by the Consultancy or approved service providers.

19.3 Integrity of Records

Reasonable measures shall be implemented to preserve the integrity, authenticity and accessibility of electronic records throughout their retention period.

19.4 Destruction

Where records are no longer required and there is no legal obligation to retain them, they shall be securely destroyed or permanently deleted in accordance with the Consultancy’s document retention policy and applicable legislation.

  1. GOVERNING LAW AND JURISDICTION

This Policy shall be governed by and interpreted in accordance with the laws of the Republic of South Africa.

Subject to any mandatory statutory provisions, the courts of the Republic of South Africa shall have jurisdiction in respect of any dispute arising from or connected with this Policy or any electronic communication issued by the Consultancy.

Nothing contained herein shall preclude the Consultancy from seeking urgent or interim relief before any court of competent jurisdiction.

  1. GENERAL PROVISIONS

21.1 Amendment

The Consultancy reserves the right to amend this Policy from time to time to reflect developments in legislation, technology, professional practice or operational requirements.

The most recent version published on the Consultancy’s official website shall constitute the prevailing version.

21.2 Severability

Should any provision of this Policy be found to be invalid, unlawful or unenforceable, such provision shall, to the extent necessary, be severed from the remainder of the Policy without affecting the validity or enforceability of the remaining provisions.

21.3 Waiver

No relaxation, indulgence or failure by the Consultancy to enforce any provision of this Policy shall constitute a waiver of any rights.

21.4 Entire Policy

This document constitutes the Consultancy’s official policy governing electronic communications, digital communications, cybersecurity, privacy and the use of artificial intelligence.

Where incorporated by reference, this Policy shall be read together with the Consultancy’s engagement letters, consultancy agreements, privacy notices and website terms and conditions.