Last updated: 19 August 2026
This Privacy Policy (“Policy”) is issued by KTH Projects (Pty) Ltd t/a KTH-Tech (Registration No. 2025/627290/07) (“Company”, “we”, “us”, “our”), the operator of the SENTRIX™ Intelligent PMO Command Centre (“Platform”). This Policy explains how we collect, use, store, disclose, and protect personal information in accordance with the Protection of Personal Information Act, 2013 (Act 4 of 2013) (“POPIA”), the Electronic Communications and Transactions Act, 2002 (Act 25 of 2002) (“ECTA”), and other applicable South African and international data protection legislation.
In terms of Section 55 of POPIA, the Company has appointed the following Information Officer:
All data subject requests, complaints, and enquiries should be directed to the Information Officer at the above contact details.
We collect and process the following categories of personal information, depending on your interaction with the Platform:
In terms of Section 11 of POPIA, we process personal information on the following lawful grounds:
| Lawful Basis | Processing Activity |
|---|---|
| Consent (s11(1)(a)) | Marketing communications, optional analytics, benchmark contributions, demo requests |
| Contract (s11(1)(b)) | Providing the Platform services, account management, billing, support |
| Legal Obligation (s11(1)(c)) | Tax and financial reporting, regulatory compliance (PFMA, MFMA), responding to lawful requests from authorities |
| Legitimate Interest (s11(1)(f)) | Platform security, fraud prevention, service improvement, aggregated analytics, AI model improvement |
| Protecting Vital Interests (s11(1)(d)) | Emergency security incidents affecting data subjects |
Where processing is based on consent, you may withdraw your consent at any time by contacting the Information Officer. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
We process personal information for the following specific purposes:
The Project Fingerprint™ engine analyses your project profile across 7 dimensions (sector, budget, team, methodology, risk profile, compliance requirements, and technology stack) and matches it against a database of 100,000+ anonymised global project benchmarks. This matching produces risk predictions, timeline estimations, and governance recommendations.
Only anonymised, aggregated project patterns are incorporated into the benchmark database. This includes statistical patterns such as budget-to-timeline ratios, risk materialisation frequencies, and methodology success rates. No individually identifiable project data, personal information, organisation names, or Confidential Information is included.
You may opt out of contributing anonymised patterns to the benchmark database at any time by contacting sentrix@kth-tech.com. Opting out does not affect your ability to receive Fingerprint matching and recommendations based on the existing benchmark database.
The Platform uses artificial intelligence and machine learning to generate risk assessments, benchmark comparisons, notification escalations, project guidelines, and recommendations. These outputs are generated algorithmically and are intended as decision-support tools only.
All critical escalations, notifications, and risk alerts generated by the Platform require human review and approval before action is taken. No automated decision with legal or similarly significant effect is made without human oversight. The Platform is designed with a mandatory human-in-the-loop architecture for all escalation workflows.
In terms of Section 71 of POPIA, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects you. If you believe an AI-generated output has had such an effect, contact the Information Officer to request human review of the decision.
We may share personal information with the following categories of third parties, solely for the purposes described in this Policy:
| Category | Purpose | Safeguards |
|---|---|---|
| Cloud Infrastructure (Microsoft Azure SA North) | Hosting, storage, compute | SOC 2 Type II, ISO 27001, POPIA-compliant DPA |
| Payment Processors | Subscription billing | PCI DSS Level 1, tokenised card storage |
| Analytics Services | Aggregated usage analytics | No personal information shared; anonymised telemetry only |
| Support Tools | Customer support ticket management | Contractual confidentiality, access controls |
| Connector Partners | Third-party integrations (Jira, Azure DevOps, SAP, Teams) | OAuth-based access, user-configured, revocable |
| Professional Advisors | Legal, audit, tax compliance | Professional privilege, contractual obligations |
| Law Enforcement / Regulators | Compliance with lawful requests | Only as required by South African law |
We do not sell, rent, lease, or trade your personal information to any third party for their own marketing purposes.
All Project Data and personal information is hosted on Microsoft Azure infrastructure within the South Africa North region (Johannesburg). By default, no personal information is transferred outside the Republic of South Africa.
If you configure integrations with systems hosted outside South Africa (e.g., Jira Cloud, Azure DevOps Global), data may be transferred to the jurisdiction where that service is hosted. In such cases:
Certain ancillary services (e.g., email delivery, error monitoring) may involve limited processing by sub-processors in jurisdictions outside South Africa. In all cases, we ensure compliance with Section 72 of POPIA through standard contractual clauses, binding corporate rules, or confirmation that the receiving jurisdiction provides an adequate level of protection.
Where SENTRIX processes personal data of individuals located in the European Economic Area (EEA) or the United Kingdom, the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”) and/or the UK Data Protection Act 2018 (“UK GDPR”) apply in addition to POPIA. In the event of any conflict between POPIA and the GDPR/UK GDPR with respect to EEA/UK data subjects, the provision offering the higher level of protection shall prevail.
In addition to the rights listed in Section 12, EEA and UK data subjects have the following additional rights under the GDPR:
Where personal data is transferred from the EEA/UK to South Africa (which does not currently hold an EU adequacy decision), we rely on EU Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914), supplemented by a Transfer Impact Assessment. For UK transfers, we use the UK International Data Transfer Addendum to the EU SCCs. Copies of executed SCCs are available on request from legal@sentrix-pmo.com.
As required by Article 27 of the GDPR, details of our appointed EU and UK representative will be published on this page upon appointment. Until appointment, all enquiries from EEA/UK data subjects should be directed to the Information Officer at privacy@sentrix-pmo.com.
EEA data subjects have the right to lodge a complaint with their local Data Protection Authority (DPA). UK data subjects may complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Our infrastructure provider (Microsoft Azure) maintains SOC 2 Type II certification. We conduct annual security audits and maintain an information security management system (ISMS) aligned with international standards.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account Information | Duration of subscription + 12 months | Contractual + legal (tax records) |
| Project Data | Duration of subscription + 90 days export window | Contractual |
| Audit Logs | 7 years | PFMA, Companies Act compliance |
| Financial Records | 7 years | Tax Administration Act, Companies Act |
| Usage Analytics | 24 months (aggregated, anonymised) | Legitimate interest |
| Support Correspondence | 36 months from last interaction | Contractual + service improvement |
| Marketing Consent Records | Duration of consent + 12 months | POPIA accountability |
| Security Logs | 12 months | Security, fraud prevention |
| Trial Account Data | 30 days after trial expiry | Contractual |
Upon expiry of the relevant retention period, personal information is permanently and irreversibly deleted or anonymised using industry-standard data destruction methods.
Under POPIA, you have the following rights regarding your personal information:
| Right | POPIA Section | Description |
|---|---|---|
| Access | s23 | Request confirmation of whether we hold personal information about you, and access to that information |
| Correction | s24 | Request correction or deletion of inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained personal information |
| Deletion | s24 | Request deletion of personal information that is no longer necessary for the purpose for which it was collected |
| Objection | s11(3) | Object to the processing of your personal information on reasonable grounds |
| Restrict Processing | s11(3) | Request restriction of processing in certain circumstances |
| Data Portability | s23 | Request a copy of your personal information in a structured, commonly used, machine-readable format |
| Withdraw Consent | s11(2) | Withdraw consent previously given for processing, without affecting the lawfulness of prior processing |
| Automated Decisions | s71 | Not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects |
| Complaint | s74 | Lodge a complaint with the Information Regulator of South Africa |
To exercise any of the above rights, submit a written request to the Information Officer at privacy@sentrix-pmo.com. We may request proof of identity before processing your request. We will respond within 30 days of receiving a valid request. Where a request is complex or voluminous, we may extend the response period by a further 30 days, with written notice and explanation.
Access requests are free of charge. Where requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee based on the administrative cost of providing the information, or refuse to act on the request, in accordance with POPIA.
In the event of a security compromise that results in the unauthorised access to, or acquisition of, personal information, we will notify:
Breach notifications will include: (a) a description of the nature of the breach; (b) the categories and approximate number of data subjects affected; (c) the categories and approximate number of personal information records affected; (d) a description of the measures taken or proposed to address the breach; (e) recommendations for affected data subjects to mitigate potential adverse effects; (f) contact details of the Information Officer.
We use strictly necessary cookies to ensure the Platform functions correctly. These cookies are required for authentication, session management, and security. They cannot be disabled without affecting Platform functionality.
| Cookie Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| sentrix_session | SENTRIX (1st party) | Session authentication token | Essential | Session |
| sentrix_csrf | SENTRIX (1st party) | Cross-site request forgery protection | Essential | Session |
| sentrix_consent | SENTRIX (1st party) | Records your cookie consent preference | Essential | 12 months |
| sentrix_analytics | SENTRIX (1st party) | Anonymous usage analytics (page views, feature usage) | Analytics (consent required) | 30 days |
We do not use any third-party advertising, retargeting, or social media tracking cookies.
On your first visit, the Platform presents a cookie consent banner. Non-essential cookies (analytics) are only set after you explicitly accept. You may decline non-essential cookies and still use all Platform functionality. For users in the EEA/UK, no non-essential cookies are set without prior opt-in consent, in accordance with the ePrivacy Directive (Directive 2002/58/EC) and GDPR.
You can manage your cookie preferences through your browser settings or the consent banner (accessible via the cookie icon in the Platform footer). Disabling essential cookies may prevent you from using certain features. We respect the “Do Not Track” (DNT) browser signal — when detected, no non-essential cookies are set.
The Platform uses browser sessionStorage to maintain your active session state. Session data is automatically cleared when you close your browser tab. No persistent local storage is used for tracking purposes.
The SENTRIX Platform is not designed for or directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe that a child under 18 has provided personal information to us, please contact the Information Officer immediately. We will take steps to delete such information from our systems.
In terms of Section 35 of POPIA, where a data subject is a child (as defined by POPIA), the consent of a competent person (parent, guardian, or other authorised person) is required for the processing of personal information. The Platform does not process personal information of children.
The Platform may contain links to third-party websites or integrate with third-party services. This Policy does not apply to third-party websites or services. We encourage you to review the privacy policies of any third-party service before providing personal information. We are not responsible for the privacy practices of third-party services, even when accessed through the Platform.
We will only send you marketing communications (product updates, newsletters, promotional offers) with your prior opt-in consent, in accordance with Section 69 of POPIA and Section 45 of ECTA.
Every marketing communication includes a clear and functional unsubscribe mechanism. You may also opt out of marketing at any time by contacting privacy@sentrix-pmo.com or by updating your notification preferences within the Platform. We will process your opt-out request within 5 business days.
Service-related communications (system alerts, security advisories, maintenance notices, billing notifications, and Fingerprint-driven escalations) are not marketing and cannot be opted out of while you maintain an active Subscription. These communications are necessary for the performance of our contract with you.
Where we process personal information on your behalf (i.e., where you are the Responsible Party and we are the Operator under POPIA), processing is governed by a Data Processing Agreement that sets out:
Where GDPR applies, the DPA also satisfies Article 28 requirements, including sub-processor management, audit rights, and data deletion obligations. All subscribers may request a copy of the Data Processing Agreement template from legal@sentrix-pmo.com.
In terms of Section 51 of the Promotion of Access to Information Act, 2000 (Act 2 of 2000) (“PAIA”), the Company maintains a PAIA Manual that describes the records held by the Company and the process for requesting access to those records. A copy of the PAIA Manual is available upon request from the Information Officer at privacy@sentrix-pmo.com.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. Material changes will be communicated via:
We encourage you to review this Policy periodically. Continued use of the Platform after changes constitutes acceptance of the updated Policy. If you do not agree with the updated Policy, you must stop using the Platform and cancel your Subscription.
This Privacy Policy is governed by the laws of the Republic of South Africa, including the Protection of Personal Information Act (POPIA), the Electronic Communications and Transactions Act (ECTA), the Promotion of Access to Information Act (PAIA), and the Consumer Protection Act (CPA) where applicable. Any dispute relating to this Policy shall be subject to the exclusive jurisdiction of the High Court of South Africa, Gauteng Division (Johannesburg).
For questions, complaints, or requests relating to this Privacy Policy or our data practices:
Information Officer: Karli Thebe
Company: KTH Projects (Pty) Ltd t/a KTH-Tech
Registration No: 2025/627290/07
Email: privacy@sentrix-pmo.com
General: sentrix@kth-tech.com
Location: Johannesburg, Gauteng, South Africa
Information Regulator (South Africa):
Email: enquiries@inforegulator.org.za
Website: inforegulator.org.za
Complaints: complaints.IR@justice.gov.za