

Privacy Policy
DC Lab
Last updated: 2026/06/10 • Effective date: 2026/06/10
This Privacy Policy explains how DC LAB (PTY) LTD (“DC Lab”, “we”, “us” or “our”) collects, uses, shares and protects your personal information when you visit https://www.dclab.co.za (the “website”) or otherwise engage with our services.
We are committed to protecting your privacy in line with the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa and, where it applies to you, the General Data Protection Regulation (EU) 2016/679 (GDPR). By using our website you agree to the practices described in this policy. If you do not agree, please do not use the website.
1. Who we are
DC Lab is a digital marketing agency operating from South Africa. We act as the Responsible Party (under POPIA) and Data Controller (under GDPR) for the personal information described in this policy.
Legal entity: DC LAB (PTY) LTD
Registered address: 129 Golden Mile Blvd, Golden Mile, St Helena Bay, 7390, South Africa
Website: https://www.dclab.co.za
Information Officer
Our Information Officer is responsible for overseeing compliance with this policy and with applicable data protection law. For GDPR purposes, the same person serves as our point of contact for data protection matters.
Name: Gareth Monkley
Email: gareth@dclab.co.za
2. What personal information we collect
We collect the following categories of personal information directly from you, for example when you complete a form, request a quote, contact us, or use our services:
-
First name and last name
-
Email address
-
Phone number
-
Postal or physical address
We also automatically collect certain technical information when you visit the website, such as your IP address, browser type, device information, pages viewed, and the dates and times of your visits. This is collected through cookies and similar technologies (see section 7).
We do not knowingly collect special categories of personal information (such as health, religious, or biometric data) through the website. Please do not send us this information unless we specifically request it for a legitimate purpose.
3. How we collect your information
-
Directly from you when you fill in a form, email us, call us, or sign up to receive communications.
-
Automatically through cookies and analytics tools as you interact with the website.
-
From third parties such as advertising and analytics platforms, where you have interacted with our ads or content on their services.
4. Why we use your information and our lawful basis
We process your personal information for the following purposes:
-
To respond to your enquiries and provide the services you request.
-
To manage our relationship with you as a client or prospective client.
-
To send you marketing communications where you have opted in or where we are otherwise permitted to do so.
-
To measure and improve the performance of our website and marketing.
-
To display and measure advertising, including remarketing (see sections 6 and 7).
-
To comply with our legal obligations and to protect our legitimate business interests.
Under POPIA, we process personal information on the basis of your consent, the performance of a contract with you, compliance with a legal obligation, or our legitimate interests. Under the GDPR, we rely on the equivalent lawful bases in Article 6: consent, contract, legal obligation, and legitimate interests. Where we rely on consent, you may withdraw it at any time (see section 9).
Where we send you marketing or otherwise rely on your consent, we obtain it through a clear, opt-in action, such as ticking an unticked checkbox on a form. We keep marketing consent separate from any request you make for our services, and we keep a record of what you agreed to and when.
5. How we share your information
We do not sell your personal information. We share it only in the following circumstances:
-
Service providers and processors who perform services on our behalf (for example analytics, email delivery, and advertising platforms described below). These parties act as Operators (POPIA) or Processors (GDPR) and may only process your information on our instructions.
-
Legal and regulatory bodies where we are required to disclose information by law or to protect our rights.
-
Business transfers in the event of a merger, acquisition, or sale of assets, in which case we will notify you.
6. Third-party tools and platforms
We use the following third-party services, each of which has its own privacy practices. We encourage you to review their privacy policies.
Analytics
We use Google Analytics 4 (GA4) to understand how visitors use our website. GA4 uses cookies and may process your data outside South Africa. See Google’s Privacy Policy. You can opt out using the Google Analytics Opt-out Browser Add-on.
Email marketing
Where you opt in, we send marketing and informational emails using HubSpot. Their privacy policy is available at HubSpot’s privacy policy. Every marketing email includes an unsubscribe link, and you can opt out at any time.
Advertising
We display advertising through Google Ads and Meta (Facebook and Instagram) Ads. We may add further platforms such as TikTok Ads or Microsoft Ads in future, and will update this policy accordingly. These platforms may use cookies and identifiers to deliver and measure ads. See Google’s Privacy Policy and Meta’s Privacy Policy.
Remarketing
We use remarketing (also called retargeting) through Google Ads and Meta to show you relevant ads on other websites and platforms after you have visited our site. These services use cookies and tracking pixels to recognise your device. You can manage your preferences through Google Ads Settings, Meta Ad Preferences, and industry tools such as Your Online Choices.
Conversion measurement and data matching
To understand which of our marketing activities lead to enquiries and sales, we measure conversions, including conversions that happen offline (for example a sale concluded by phone or email after an online enquiry). To do this we may share hashed identifiers with Google and Meta. A hashed identifier is created by converting information such as your email address or phone number into a scrambled value using a one-way process (SHA-256) before it leaves our systems, so we do not share your details in plain, readable form.
These platforms use the hashed identifier only to match a conversion to an advertising interaction and to report on and improve the performance of our campaigns. Where you are in the EU or EEA, we rely on your consent for this matching, and elsewhere we rely on consent and/or our legitimate interest in measuring our marketing. You can withdraw your consent at any time (see section 9), and we apply consent signals through Google Consent Mode and equivalent controls for visitors who decline.
7. Cookies and tracking technologies
Cookies are small text files stored on your device. We use them to make the website work, to remember your preferences, to measure traffic through GA4, and to support advertising and remarketing.
We group cookies into strictly necessary cookies, which are needed for the website to function, and non-essential cookies, which include analytics, advertising, and remarketing. Where required by law, we do not place non-essential cookies until you have given consent through our cookie banner. The banner lets you accept or reject non-essential cookies, and rejecting is as easy as accepting. You can change your choice at any time through the banner or your browser settings.
Blocking some cookies may affect how the website functions. For visitors in the EU and EEA, your cookie choices are passed to our analytics and advertising tools through consent controls so that those tools respect your decision.
8. International transfers of personal information
Some of our service providers are located outside South Africa and the European Economic Area (EEA), including in the United States. This means your personal information may be transferred to, and processed in, countries with different data protection laws.
When we transfer personal information across borders, we take steps required by POPIA (section 72) and the GDPR (Chapter V) to ensure it receives an adequate level of protection. This may include relying on Standard Contractual Clauses, adequacy decisions, or the recipient being subject to laws or binding agreements that provide comparable protection.
9. Your rights
Subject to applicable law, you have the following rights in relation to your personal information:
-
Right of access – to request a copy of the personal information we hold about you.
-
Right to correction – to ask us to correct or update inaccurate or incomplete information.
-
Right to deletion – to ask us to delete your personal information where there is no legal reason for us to keep it.
-
Right to object – to object to processing based on legitimate interests or to direct marketing.
-
Right to withdraw consent – to withdraw consent at any time where we rely on it, without affecting prior lawful processing.
-
Right to restriction and portability (GDPR) – to restrict processing in certain cases and to receive your data in a portable format.
-
Right to lodge a complaint – to complain to the relevant supervisory authority (see section 12).
-
To exercise any of these rights, contact our Information Officer at privacy@dclab.co.za. We will respond within the timeframes required by law. We may need to verify your identity before acting on your request.
10. How long we keep your information
We keep your personal information only for as long as necessary to fulfil the purposes set out in this policy, including to meet legal, accounting, or reporting requirements. When we no longer need it, we will securely delete or anonymise it.
11. How we protect your information
We take appropriate, reasonable technical and organisational measures to safeguard your personal information against loss, unauthorised access, and misuse, as required by POPIA and the GDPR. While no method of transmission over the internet is completely secure, we work to protect your information and to review our measures regularly.
If a security breach affects your personal information, we will notify you and the relevant regulator where the law requires us to do so.
12. Children’s privacy
Our website and services are not directed at children. Under POPIA, a child is anyone under the age of 18. We do not knowingly collect personal information from children without the consent of a parent or guardian. If you believe we have collected information from a child, please contact us so we can remove it.
13. Complaints
If you have a concern about how we handle your personal information, please contact our Information Officer first so we can try to resolve it. You also have the right to complain to a regulator.
In South Africa, you may contact the Information Regulator:
-
Information Regulator (South Africa)
-
Website: https://inforegulator.org.za
If you are in the EU or EEA, you have the right to lodge a complaint with your local data protection supervisory authority.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. We will post the updated version on this page and revise the “Last updated” date above. Where changes are significant, we will take reasonable steps to notify you.
15. Contact us
If you have any questions about this Privacy Policy or how we handle your personal information, please contact us:
DC LAB (PTY) LTD
Attention: Gareth Monkley, Information Officer
Email: privacy@dclab.co.za
Address: 129 Golden Mile Blvd, Golden Mile, St Helena Bay, 7390, South Africa
.