Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains how RDA Deliverability collects, uses, stores, shares and protects personal information when you visit our website, contact us, request a free review or paid service, become a client, work with us as a provider or specialist, or otherwise interact with our business.
RDA provides remote specialist services relating to email authentication, domain trust, technical assurance, remediation and ongoing monitoring. Because our work is technical, some information we process is ordinary business contact information and some is machine-generated technical data associated with domains, email systems, sending sources and service providers.
We aim to collect only what is reasonably necessary, use it for clear purposes and protect it with appropriate safeguards.
1. Who we are
RDA Deliverability is an independently operated online specialist service business focused on email authentication, domain trust and related technical assurance.
RDA Deliverability is currently operated as a sole proprietorship and provides services remotely to business clients, including clients in other countries.
For the personal information described in this Policy, RDA is generally the party responsible for deciding why and how that information is processed. In some client engagements, RDA may instead process limited information on the client’s instructions as a service provider or operator. Section 17 explains this distinction in more detail.
You can contact us at:
RDA Deliverability
Email: info@rdadeliverability.com
Telephone: +27 76 3111 590
Website: rdadeliverability.com
Formal operator identity and service details may also be provided in a separate legal disclosure and in contracting documents where required.
2. Scope of this Policy
This Policy applies to personal information processed through or in connection with:
- the RDA Deliverability website;
- contact, enquiry, request and onboarding forms;
- free reviews, preliminary checks and service enquiries;
- Email Trust Health Checks;
- Remediation & Strengthening engagements;
- Trust Monitor and other ongoing services;
- proposals, contracts, invoices and payment administration;
- client support and business communications;
- business development and professional outreach;
- relationships with suppliers, specialists and professional advisers; and
- other legitimate business operations reasonably connected with RDA’s services.
This Policy does not govern a third party’s independent handling of information merely because we link to, work alongside or recommend that third party. Their own privacy terms apply to their independent processing.
3. The privacy principles we follow
We aim to process personal information in a manner that is:
- lawful and reasonable;
- limited to information that is adequate, relevant and not excessive for the purpose;
- connected to a specific and legitimate business purpose;
- transparent to the people and organisations affected;
- reasonably accurate and kept up to date where necessary;
- retained only for as long as there is a legitimate reason to keep it; and
- protected by appropriate technical and organisational safeguards.
Our primary South African privacy framework is the Protection of Personal Information Act, 2013, commonly referred to as POPIA. Additional privacy rights may apply depending on where a person is located and the circumstances of the processing.
4. Information you provide directly
Depending on how you interact with RDA, you may provide:
- your name and surname;
- business email address;
- telephone number;
- job title, role or department;
- company or organisation name;
- website and domain names;
- country or general business location;
- information included in an enquiry or message;
- onboarding answers;
- names and details of authorised IT contacts or providers;
- information about email platforms, sending systems and business applications;
- screenshots, exports, reports or other technical evidence;
- approval, instruction and change-management records;
- billing and invoicing details;
- transaction references and payment-status information;
- support communications and feedback; and
- other information you choose to provide for a legitimate business purpose.
Providing information for a general enquiry is normally voluntary. However, we may not be able to respond, provide an accurate scope, issue an invoice or perform a service if essential information is not provided.
5. Technical information collected during our services
Our work may require the collection or review of technical information relating to an agreed domain and its email trust environment.
Depending on the service, this may include:
- domain names and relevant subdomains;
- public DNS records;
- SPF records and authorised sending-source information;
- DKIM selectors, public keys and deployment status;
- DMARC records, policy settings and reporting configuration;
- authentication and alignment results;
- mail-provider and service-provider identifiers;
- IP addresses associated with sending infrastructure or technical logs;
- sending-source names and platform relationships;
- machine-generated authentication reports;
- failure counts, policy results and aggregate technical statistics;
- DNS history or observed configuration changes where available;
- monitoring events, alerts and evidence of drift; and
- other technical evidence reasonably necessary for the agreed work.
Standard services do not require mailbox passwords
Do not send passwords, private keys, recovery codes, authentication tokens or other secret credentials through our public website forms.
We also do not normally need the contents of your mailboxes or ordinary email message bodies to perform a standard Email Trust Health Check. If unusually sensitive access or information is genuinely required for separate work, the need, scope and transfer method should be agreed first.
6. Information collected automatically when you use our website
When you visit or interact with the website, our website, hosting environment and security tools may automatically process technical information such as:
- IP address;
- browser type and version;
- device type and operating system;
- date and time of access;
- pages requested and basic navigation information;
- referring page or source;
- approximate location derived from an IP address;
- server logs and error records;
- security and anti-abuse signals; and
- cookie or similar identifiers where those technologies are used.
Some of this information is necessary to deliver the website, maintain security, prevent abuse, diagnose failures and understand whether the website is functioning properly.
7. Information from public and third-party sources
RDA may receive or collect business and technical information from sources other than the person concerned.
These sources may include:
- public DNS and domain information;
- public company websites;
- professional profiles and business directories;
- business data and prospecting providers;
- publicly available business records;
- referrals and introductions;
- clients, their authorised representatives and technology providers;
- service providers used in an agreed technical environment; and
- other lawful public or business sources.
We may combine public technical information, such as DNS or email-authentication signals, with business contact information where relevant to service delivery, investigation, risk assessment or lawful business development.
Public availability does not mean that information is free from privacy obligations. We aim to use public and third-party information proportionately and for relevant business purposes.
8. Free reviews, domain checks and enquiries
If you submit a domain, request a free review or ask us to investigate a potential issue, we may:
- review public DNS and authentication information;
- record the domain and associated business contact details;
- generate internal findings, notes or technical results;
- contact you about the request;
- decide whether the matter falls within RDA’s service scope; and
- retain a reasonable record of the request and outcome.
A free review or public scan may be limited and should not be treated as a complete diagnosis. Our use of information for a preliminary review does not create a paid client relationship by itself.
9. Information processed during an Email Trust Health Check
For a paid Email Trust Health Check, we may process information needed to understand the technical trust environment behind the agreed domain.
This may include:
- onboarding information;
- known legitimate sending systems;
- relevant business and IT contacts;
- technical evidence and screenshots;
- public DNS and authentication records;
- machine-generated authentication data;
- confirmed findings and unresolved evidence gaps;
- internal working notes; and
- the final report and recommendations.
Information is used to assess the agreed environment, distinguish confirmed findings from unknowns, prepare the deliverable and communicate with authorised people involved in the engagement.
10. Information processed during remediation
Remediation work may require additional information because configuration changes can affect live business systems.
Depending on the agreed implementation route, we may process:
- authorised contact and approval records;
- implementation plans;
- change records and tickets;
- technical configuration evidence;
- platform and account identifiers;
- temporary or delegated access information;
- pre-change and post-change verification results;
- rollback information where relevant; and
- communications with authorised internal or external technical teams.
We aim to request the least access reasonably necessary for the work. Delegated, role-based or temporary access should be used where practical.
11. Information processed by Trust Monitor
For an ongoing monitoring service, we may regularly process information needed to compare the current environment with an established baseline.
This may include:
- authentication and policy status;
- changes to relevant DNS records;
- new or unexpected sending sources;
- technical events and alerts;
- investigation notes;
- client communications about meaningful changes; and
- periodic assurance summaries.
Monitoring is limited to the agreed scope and available data. It is not continuous surveillance of individual employees and is not intended to inspect ordinary mailbox content.
12. How we use personal information
We may use personal information to:
- operate, secure and maintain the website;
- respond to enquiries and requests;
- assess whether RDA can assist;
- prepare proposals, scopes and quotations;
- complete onboarding and verify instructions;
- perform agreed assessments, remediation and monitoring;
- prepare reports, findings and implementation records;
- communicate with clients and authorised technical contacts;
- coordinate with client-appointed providers;
- provide support and resolve service issues;
- issue invoices and administer payments;
- maintain contractual, accounting and tax records;
- protect our systems, clients and business against abuse or fraud;
- investigate incidents and enforce agreements;
- manage legal claims and comply with law;
- improve our processes, tools and service quality;
- keep appropriate internal records;
- manage suppliers, specialists and advisers;
- conduct relevant business development and professional outreach where permitted; and
- carry out another compatible purpose that is reasonably connected with the original purpose or separately authorised.
13. Why we are allowed to process information
The justification for processing depends on the information and the context.
RDA may process personal information where one or more of the following applies:
- you have consented to the processing;
- processing is necessary to take steps at your request before entering into a contract;
- processing is necessary to perform or administer a contract;
- processing is required by law;
- processing protects a legitimate interest of the person concerned;
- processing is necessary for RDA’s legitimate interests or those of a client or third party, where the law permits and the interests are not overridden by stronger privacy rights; or
- another lawful justification applies in the circumstances.
Examples of legitimate interests may include securing systems, responding to business enquiries, maintaining service records, preventing fraud, improving service quality, establishing or defending legal claims and conducting proportionate business-to-business development.
Where we rely on consent, consent may be withdrawn for future processing. Withdrawal does not make earlier lawful processing unlawful and may not affect processing that is justified on another lawful ground.
14. Business development and professional outreach
RDA may use relevant business contact information to introduce our services, follow up on an enquiry, maintain professional relationships or communicate about a technical issue that appears relevant to a business.
Business development information may come from:
- information you provide to us;
- existing client or professional relationships;
- public company websites;
- professional directories and profiles;
- lawful business data providers;
- referrals; and
- public technical signals relating to a business domain.
Where applicable law requires consent or limits unsolicited electronic direct marketing, RDA will apply the legal requirements relevant to the communication and relationship. Marketing communications should identify the sender and provide a reasonable way to object or ask that further marketing communications stop.
If you ask us to stop marketing communications, we may retain limited information on a suppression record so that we can respect that request in the future.
Service communications, security notices, invoices and messages necessary to administer an active engagement are not treated as optional marketing merely because they are sent electronically.
15. Email delivery and engagement information
Business emails may generate technical information such as:
- delivery and bounce status;
- reply status;
- spam or complaint signals made available to us;
- link activity where link measurement is enabled; and
- other limited engagement signals supported by the communication system in use.
We may use this information to manage communications, protect sender reputation, reduce unwanted messages, identify inaccurate contact information and understand whether business communications are useful.
We do not use ordinary email-engagement information to make decisions that produce legal or similarly significant effects on individuals.
16. Payments and financial information
RDA may process information needed to issue invoices, confirm payment and maintain business records, including:
- billing contact details;
- company and tax information where applicable;
- invoice amounts and currency;
- payment status;
- transaction or payment references;
- refund records; and
- correspondence about payment or billing.
Where payment is made through a bank or third-party payment service, that provider may independently process payment credentials and transaction information under its own terms. RDA does not normally need to receive full payment-card details when a third-party payment page or payment link is used.
17. When RDA acts for itself and when it acts for a client
For ordinary website, enquiry, contracting, billing, business-development and relationship information, RDA generally decides the purpose and means of processing and is responsible for that processing.
In some service engagements, a client may provide information that RDA processes only to perform agreed work on the client’s instructions. In that situation:
- the client may remain responsible for the primary purpose of the processing;
- RDA will process the information for the agreed service purpose;
- the applicable proposal, scope or other written arrangement may contain additional data-processing terms; and
- the client remains responsible for ensuring it has authority to provide the information and instruct the work.
RDA may still process certain related information for its own legitimate purposes, such as invoicing, maintaining service records, security, legal compliance and the establishment or defence of claims.
18. Client responsibilities when providing information
Clients and other business contacts should provide only information that is reasonably necessary for the relevant purpose.
You are responsible for:
- avoiding unnecessary disclosure of sensitive or unrelated information;
- ensuring that you have authority to provide information about employees, IT contacts, providers or other people;
- telling us if information is materially inaccurate or outdated;
- using an agreed secure method for sensitive technical evidence;
- not submitting passwords or secret credentials through public forms; and
- complying with your own privacy obligations where you ask RDA to process information on your behalf.
19. Special or sensitive personal information
RDA’s standard services are not designed to collect special or highly sensitive personal information such as health information, biometric information, detailed financial account credentials, private mailbox content or information about children.
Please do not provide this kind of information unless it is genuinely necessary, lawful and specifically agreed.
If an engagement unexpectedly involves sensitive information, we may pause, request that unnecessary material be removed, agree a different transfer method, limit access or require additional safeguards before continuing.
20. Children
RDA provides business and professional services and does not direct its website or services to children.
We do not knowingly seek to collect personal information from children through the website. If you believe a child has provided personal information to us without appropriate authority, please contact us so that we can assess and address the matter.
21. Cookies and similar technologies
The website may use cookies or similar technologies for purposes such as:
- providing core website functionality;
- maintaining security and preventing abuse;
- remembering limited user or technical preferences;
- understanding website performance; and
- measuring use of the website where analytics tools are enabled.
Essential and security technologies
Some technologies may be necessary for the website to function, maintain sessions, process forms, prevent automated abuse or protect the website and its visitors.
Analytics and non-essential technologies
If RDA enables analytics or another non-essential technology that requires notice, consent or an opt-out under applicable law, we will aim to provide the required information and controls.
You can also use browser settings to block or delete cookies. Blocking essential cookies may affect website functionality.
22. Website forms and anti-abuse protection
Our contact and onboarding forms may use technical controls to reduce spam, bots, fraudulent submissions and attacks.
These controls may process information such as:
- IP address;
- browser and device information;
- timing and interaction signals;
- security identifiers; and
- other technical information used to distinguish legitimate activity from abuse.
We use this information to protect the website, our inboxes and legitimate users. A suspicious submission may be blocked, quarantined or reviewed.
23. Service providers and other recipients
RDA may share personal information with trusted third parties where reasonably necessary for a legitimate business purpose.
Categories of recipients may include:
- website hosting and infrastructure providers;
- website security and anti-abuse providers;
- email and communication providers;
- cloud storage and document tools;
- invoicing, accounting, banking and payment providers;
- monitoring, reporting and technical service providers;
- business administration and workflow tools;
- authorised specialists or contractors supporting an engagement;
- the client’s authorised IT team or technology providers;
- lawyers, accountants, insurers and other professional advisers;
- regulators, courts, law-enforcement bodies or public authorities where lawfully required; and
- a genuine buyer, successor or adviser in connection with a proposed or completed sale, restructuring or transfer of the business.
We aim to limit disclosure to information reasonably necessary for the purpose and to use appropriate confidentiality, contractual or security safeguards where required.
24. Specialists and contractors
RDA may use appropriately skilled specialist support where the complexity or risk of an engagement reasonably requires it.
Where a specialist engaged by RDA may access confidential or personal information, we aim to:
- use the specialist for a legitimate and defined purpose;
- limit access to what is reasonably necessary;
- require appropriate confidentiality;
- consider relevant security and privacy safeguards; and
- remain the primary point of coordination unless another arrangement is agreed.
A third party selected, instructed and controlled directly by the client is responsible for its own independent processing unless a different arrangement is expressly agreed.
25. Artificial intelligence and automated tools
RDA may use automation and AI-assisted tools for limited business purposes such as drafting, summarisation, classification, workflow support, technical pattern review or internal quality assistance.
Where such tools are used, we aim to:
- minimise the personal and confidential information involved;
- avoid entering passwords, private keys or other secret credentials;
- consider the sensitivity of the information and the tool being used;
- apply human review to material client findings and recommendations; and
- use appropriate provider and account settings where reasonably available.
Automated scans, scoring and technical classifications may assist our work, but RDA does not intend to make decisions producing legal or similarly significant effects on individuals solely through automated processing.
26. We do not sell personal information
Our position on personal information
RDA does not sell personal information for money, rent personal mailing lists or operate a business model based on selling client data.
We also do not knowingly disclose personal information for cross-context behavioural advertising. If our practices materially change, this Policy will be updated and any rights required by applicable law will be provided.
27. International processing and cross-border transfers
RDA operates online, serves international clients and may use service providers whose systems or personnel are located outside South Africa.
As a result, personal information may be processed in another country.
Where South African cross-border transfer requirements apply, RDA will seek to rely on an appropriate basis for the transfer, which may include:
- adequate protection provided by applicable law, binding rules or a binding agreement;
- the data subject’s consent where appropriate;
- necessity for a contract with the data subject or pre-contractual steps requested by the data subject;
- necessity for a contract concluded in the data subject’s interest; or
- another transfer basis permitted by law.
Privacy laws and government-access rules differ between countries. Cross-border processing therefore cannot always provide identical legal protections in every location.
28. How long we keep information
We keep personal information only for as long as there is a legitimate reason to retain it, subject to legal, contractual, accounting, security and dispute-related requirements.
Factors considered include:
- the original purpose of collection;
- whether an enquiry became a client engagement;
- the duration of an active or ongoing service;
- the sensitivity and volume of the information;
- whether the information is needed to support a report or technical decision;
- legal and tax recordkeeping requirements;
- applicable limitation periods and potential disputes;
- security and fraud-prevention needs; and
- whether a person has requested that marketing stop.
Our normal retention approach
Unless a longer or shorter period is justified, our general operating targets are:
- ordinary enquiries that do not become engagements: generally up to 24 months after the last meaningful interaction;
- client contracts, scopes, approvals and core service records: generally for the engagement and a reasonable period afterwards, commonly up to 5 years;
- technical working evidence: for as long as needed to complete, verify and support the relevant work, with unnecessary sensitive material removed earlier where practical;
- ongoing monitoring data: for the duration needed to maintain a useful baseline and history for the service;
- invoice, transaction and accounting records: for the period required by applicable tax, accounting and legal obligations;
- website security logs: generally for a shorter operational period unless needed for an incident, investigation or legal obligation; and
- marketing suppression records: limited information may be retained as long as reasonably necessary to honour an opt-out.
These are general targets, not promises that every record is deleted on an identical date. Backups, legal holds, active disputes, security incidents and technical limitations may affect final deletion timing.
When retention is no longer justified, we aim to delete, destroy, de-identify or otherwise place information beyond ordinary use as appropriate.
29. Security safeguards
RDA takes reasonable technical and organisational measures designed to protect personal information against loss, damage, unauthorised destruction, unlawful access and unlawful processing.
Depending on the system and risk, measures may include:
- access controls and account permissions;
- multi-factor authentication where supported and appropriate;
- password-management practices;
- encryption in transit where supported;
- secure cloud and hosting providers;
- anti-abuse and security controls;
- limited access to client information;
- segregation of information by purpose or engagement where practical;
- careful handling of technical evidence;
- backup and recovery arrangements appropriate to the system;
- review of foreseeable risks; and
- updating safeguards in response to material risks or deficiencies.
No internet transmission, cloud service, email system or storage method can be guaranteed to be completely secure. Security is therefore a risk-management process rather than an absolute guarantee.
30. Security incidents and personal information compromises
If RDA has reasonable grounds to believe that personal information under our responsibility has been accessed or acquired by an unauthorised person, we will assess the incident and take reasonable steps to contain and investigate it.
Where required by applicable law, we will notify the relevant regulator and affected people or organisations as soon as reasonably practicable, subject to lawful delay or restrictions.
A notification may include available information about:
- what happened;
- when the incident occurred or was identified;
- the information involved;
- the steps taken or planned;
- actions the affected person can consider; and
- how to contact us.
If RDA is acting as a service provider or operator for a client, we will also communicate with the responsible client as required by the applicable arrangement and law.
31. Your privacy rights
Depending on applicable law and the circumstances, you may have the right to:
- be informed that personal information is being collected or has been compromised;
- ask whether RDA holds personal information about you;
- request access to personal information;
- request correction of inaccurate, incomplete, excessive, outdated or misleading information;
- request deletion or destruction where the law permits;
- object to certain processing on reasonable grounds;
- object to direct marketing;
- withdraw consent for future processing where consent is the relevant justification;
- request restriction of processing in circumstances recognised by law;
- complain to an appropriate privacy regulator; and
- exercise additional rights provided by a law that applies to your particular situation.
Privacy rights are not absolute. A request may be limited by legal privilege, another person’s rights, contractual or legal obligations, records we must retain, the need to establish or defend claims or another lawful exception.
32. How to make a privacy request
Send privacy requests to:
RDA Deliverability
Email: info@rdadeliverability.com
Telephone: +27 76 3111 590
Please describe the request clearly and provide enough information for us to identify the relevant records.
Before releasing, correcting or deleting information, we may need to verify identity, authority or the connection between the requester and the information. We will not ask for more verification information than is reasonably necessary.
If a request concerns information that RDA processes only on behalf of a client, we may refer the request to that client or coordinate with the client as appropriate.
We aim to respond within the period required by applicable law and may communicate if a request is complex, unusually broad or requires clarification.
33. Direct marketing opt-outs
You may ask RDA to stop sending marketing communications at any time by:
- using an unsubscribe or opt-out method included in the communication, where available;
- replying and asking us to stop; or
- emailing info@rdadeliverability.com.
Please allow a reasonable period for systems and active communication sequences to be updated.
An opt-out from marketing does not prevent us from sending necessary communications about an active engagement, payment, legal matter, security issue or request that you initiated.
34. Complaints
If you have a concern about our handling of personal information, please contact RDA first so that we have an opportunity to understand and address the issue.
You may also have the right to lodge a complaint with the privacy or data-protection authority that has jurisdiction over your situation.
In South Africa, complaints about alleged interference with personal information may be submitted to the Information Regulator (South Africa). Current complaint methods and contact details are available on the Information Regulator’s official website.
RDA does not restrict a right to complain to a regulator where applicable law provides that right.
35. Third-party websites and services
The RDA website or service communications may contain links to third-party websites, reports, platforms, payment pages or other services.
A link does not mean that RDA controls the third party’s privacy practices. You should review the third party’s own privacy information before providing personal information to it.
RDA is not responsible for the independent privacy practices of a third party that determines its own purposes and methods of processing.
36. Business transfers
If RDA is genuinely sold, restructured, incorporated, merged or transferred, relevant business information may be disclosed to professional advisers and a prospective or actual successor where reasonably necessary.
We would seek to protect confidential and personal information during the process and require the successor to handle transferred personal information in accordance with applicable law.
37. Changes to this Privacy Policy
RDA may update this Policy to reflect changes in our website, services, technology, providers, business practices or legal obligations.
The latest version will show the date of the most recent update.
Material changes will apply from the date stated in the updated Policy. Where applicable law requires additional notice or consent for a change, we will aim to provide it.
38. Contact us
Questions, privacy requests and complaints about this Policy may be sent to:
RDA Deliverability
Email: info@rdadeliverability.com
Telephone: +27 76 3111 590
Website: rdadeliverability.com
Formal legal notices relating to an active engagement should also follow the notice provisions in the applicable agreement or the Terms of Use.
This Privacy Policy should be read together with the RDA Deliverability Terms of Use and the specific written scope for any paid engagement.