1. Who We Are & Responsible Party
Quadrastar (Pty) Ltd (“Quadrastar”, “we”, “us”, “our”) is a private company incorporated in the Republic of South Africa. We operate the website at https://quadrastar.co.za and provide software products including CoolPDF, a free browser-based PDF toolkit, and custom software development services.
We are the Responsible Party as defined in the Protection of Personal Information Act, No. 4 of 2013 (POPIA). This means we determine the purpose and means of processing your personal information.
Information Officer
Our designated Information Officer is responsible for ensuring compliance with POPIA.
Contact: hello@quadrastar.co.za
2. Information We Collect
We collect personal information only when you voluntarily provide it to us, or when it is technically necessary to deliver our services. We never collect more than we need.
| Source | Information Collected | Purpose |
|---|---|---|
| Contact form | Name, email address, message content | To respond to your enquiry |
| CoolPDF uploads | PDF files you upload for processing | Processed on our server and deleted immediately after the job completes |
| Technical / server logs | IP address, browser type, pages visited, timestamps | Security, fraud prevention, and rate limiting only. Not linked to identity. |
We do not collect:
- South African ID numbers, passport numbers, or biometric data.
- Racial or ethnic origin, political opinions, religious beliefs, or health information.
- Card numbers or banking details (these are handled directly by our payment processors).
3. How We Use Your Information
We use your personal information only for the purposes for which it was collected:
- To respond to your contact form enquiry or provide a quote.
- To deliver and improve our free online tools (such as CoolPDF).
- To discuss custom software or AI projects you enquire about.
- To maintain the security and integrity of our services (fraud detection, rate limiting, abuse prevention).
- To comply with legal obligations under South African law.
We do not use your information for unsolicited marketing, profiling, or automated decision-making that affects you without your prior explicit consent.
4. Legal Basis for Processing
Under POPIA, we process your personal information on the following grounds:
- Consent — when you voluntarily submit a contact form or sign-up form.
- Contract performance — when processing is necessary to deliver custom software or professional services you have engaged us for.
- Legitimate interest — for security logging and fraud prevention, where our interest does not override your rights.
- Legal obligation — where processing is required by South African law.
5. Sharing of Information
We do not sell, rent, trade, or share your personal information with third parties for their own marketing purposes.
We share information only in the following limited circumstances:
- Service providers: Hosting, email delivery, or other infrastructure partners who process data only on our instructions and under appropriate safeguards.
- Legal compliance: Where required by a valid court order, subpoena, or applicable South African law.
- Business succession: In the event of a merger, acquisition, or sale of business assets, your information may transfer to the successor entity, subject to equivalent privacy protections.
6. CoolPDF & File Uploads
When you use CoolPDF, you upload PDF files to our server for processing. Files are stored only in a temporary workspace for the duration of the job and are deleted immediately afterward. We do not keep copies for marketing, training, or unrelated purposes.
Do not upload documents containing information you are not permitted to share with us. For highly sensitive material, contact us about offline or on-premise alternatives.
7. Cookies & Tracking
We use session cookies only — small, temporary files that are essential to the functioning of our forms (CSRF protection and flash messages). These cookies are not used for tracking, advertising, or analytics. They expire when you close your browser.
We do not use:
- Third-party advertising cookies or tracking pixels.
- Google Analytics or similar analytics platforms (a GA4 placeholder exists in our code but is not active).
- Persistent fingerprinting or cross-site tracking.
Because we use only strictly necessary session cookies, we are not required to display a cookie consent banner under POPIA. We will update this section if our cookie usage changes.
8. Data Retention
We retain your personal information only for as long as necessary for the purpose it was collected, or as required by law:
| Data Type | Retention Period |
|---|---|
| Contact form submissions | 12 months from submission |
| CoolPDF usage | Deleted immediately after processing (not retained) |
| Server and security logs | 90 days |
After the applicable retention period, personal information is securely deleted or anonymised.
9. Cross-Border Transfers
Our servers are hosted in South Africa. In the ordinary course of business, your personal information is not transferred outside the Republic of South Africa.
Any email delivery infrastructure we use may route messages through international servers; however, email content is limited to responses to enquiries you initiate.
Should cross-border transfers become necessary in future, we will ensure the destination country provides adequate protection as required by section 72 of POPIA, or obtain your prior consent.
10. Data Security
We implement reasonable and appropriate technical and organisational measures to protect your personal information, including:
- HTTPS encryption on all pages — data in transit is encrypted using TLS.
- CSRF protection on all forms — prevents cross-site request forgery attacks.
- Rate limiting — prevents brute-force and spam submissions.
- Restricted access — core system files are blocked from public web access via server configuration.
- Password hashing — account passwords are stored using bcrypt (one-way hashing).
- No card data stored — payment card details are never stored on our servers.
No system is 100% secure. While we take your privacy seriously, we cannot guarantee absolute security of information transmitted over the internet. Please ensure your own devices and passwords are kept secure.
11. Data Breach Notification
In the event of a security compromise that involves your personal information and that poses a real risk of harm to you, we will:
- Notify the Information Regulator of South Africa as soon as reasonably possible after discovering the breach.
- Notify you as soon as reasonably possible, in writing, with a description of the breach and the steps we are taking.
This is consistent with our obligations under section 22 of POPIA.
12. Children’s Privacy
Our services are not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18 without the consent of a parent or competent person as defined by POPIA. If you believe a minor has submitted personal information to us without appropriate consent, please contact us immediately and we will delete it.
13. Your Rights Under POPIA
As a data subject under POPIA, you have the right to:
- Access — request a copy of the personal information we hold about you.
- Correction — request that inaccurate, incomplete, or outdated information be corrected.
- Deletion — request that your personal information be deleted, subject to our legal retention obligations.
- Objection — object to the processing of your personal information on grounds relating to your particular situation.
- Withdrawal of consent — where processing is based on your consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint — file a complaint with the Information Regulator of South Africa if you believe your rights have been violated.
To exercise any of these rights, contact us via our contact form at https://quadrastar.co.za/#contact or email hello@quadrastar.co.za. We will respond within 30 days of receiving your request.
Note: We may ask you to verify your identity before actioning a request to protect your information from unauthorised disclosure.
14. How to Contact Us & the Information Regulator
Quadrastar (Pty) Ltd
Email: hello@quadrastar.co.za
Website: Contact Form
Republic of South Africa
Est. 2011
Information Regulator (South Africa)
JD House, 27 Stiemens Street
Braamfontein, Johannesburg, 2001
inforeg@justice.gov.za
complaints.IR@justice.gov.za
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. When we do, we will update the “Last updated” date at the top of this page.
For material changes, we will make reasonable efforts to notify you where we have your contact details. Continued use of our services after the effective date of any change constitutes your acceptance of the updated policy.
We encourage you to review this policy periodically. Previous versions are available upon request.
Disclaimer: This Privacy Policy has been prepared in good faith to reflect our actual practices and POPIA requirements. It does not constitute legal advice. Quadrastar (Pty) Ltd recommends that businesses obtain independent legal counsel regarding their own POPIA obligations when handling personal information in their operations.