Privacy
Privacy notice
This notice describes what Onward Africa collects through this website, what the client portal holds during an engagement, and how both are handled.
Last updated 10 September 2026.
Draft notice. Company details below are pending confirmation. Retention periods, hosting and service providers are recorded in the engagement documentation.
1. Who this notice is from
Onward Africa is a public relations, strategic communications and online reputation management firm. It is the controller for the information described in section 2 and, for information handled inside a client engagement, its role is set by the engagement contract, which usually makes it a processor acting on the client's instructions.
- Registered entity and number
- To be completed.
- Registered address
- To be completed.
- Data protection contact
- To be completed. Until it is published, use the enquiry form and mark the message as a data protection request.
- Supervisory authority registration
- To be completed.
2. What this website collects
The enquiry form
The enquiry form is the only place on this site that asks you for information. It collects your name, your organisation if you give one, your email address, your telephone number if you give one, your country if you give one, the service your enquiry is about, how pressing it is, and the message you write. Every field except your name, your email address and your message is optional.
We use these details to respond to your enquiry, maintain correspondence and send an acknowledgement.
Technical records
Running the site produces ordinary server records: the request made, the time, the response, and network level details such as an IP address. They are used to keep the service available and secure, and to investigate faults and abuse. The site does not run advertising trackers, and cookies are limited to what the site needs to function, including a session cookie and a cross site request forgery token when you use a form or sign in.
Sensitive information
Use the enquiry form for a brief description of your needs. Contact the team to arrange secure transfer of confidential documents or sensitive personal information.
3. What the client portal holds
During an engagement, the client portal holds the working record of that engagement. Depending on the scope, that can include:
- The items and sources in scope, with the date and method of each observation
- Evidence captured about those sources, including stored copies of what was observed
- Requests sent to publishers, platforms, search providers or other third parties, and the responses received
- Approvals, instructions and decisions, with who made them and when
- Reports and the underlying records each figure is drawn from
- Accounts for the people a client authorises to use the portal, and a log of what those accounts did
Where the subject matter involves individuals, which reputation work frequently does, that material is personal data and is handled as personal data, whether the person is a client contact, a complainant, an author or the subject of an article.
4. Client information is private by default
Publication of client information requires written permission for the specific use. Naming a client requires separate permission.
Client data is not used to train models, is not sold, and is not shared with other clients. Access inside the firm is limited to the people working on that engagement.
5. Evidence handling and hashes
Reputation work depends on being able to say what a source showed on a given date. When we capture evidence, we record what was fetched, when, by what method and what the source returned, and we compute a cryptographic hash of the stored file. The hash lets us demonstrate later that the stored copy has not been altered since capture.
Corrections to evidence are recorded alongside the original. Evidence may contain publicly available personal data about third parties. Its use and access are limited to the relevant engagement.
6. How long we keep things
Enquiries that do not become engagements are kept while they are still useful for answering you and for our own record of who approached us, then deleted. Engagement records are kept for the period set in the engagement contract, which takes account of the client's own obligations and any professional or legal requirement that applies to them.
Retention periods are set per engagement. Records subject to a legal hold are preserved until the hold is lifted.
7. Hosting, sub-processors and international transfers
The hosting region and the sub-processors used for an engagement, for example infrastructure, email delivery and storage providers, are recorded in that engagement's documentation, along with the transfer safeguards that apply.
If you are a prospective client and the hosting region or the sub-processor list is material to your decision, ask before you contract and you will be given the current list in writing.
8. Your rights
Depending on the law that applies to you, you may have the right to ask for a copy of the personal data we hold about you, to have inaccurate data corrected, to ask for deletion, to object to or restrict certain handling, and to complain to a supervisory authority.
To make a request, use the enquiry form and say what you are asking for. Requests concerning data processed for a client are referred to that client. Retention obligations may affect deletion requests; we will explain any applicable restriction.
9. Security
Access to client material is limited to the people working on the engagement, actions in the portal are logged, and evidence integrity is protected by the hashing described in section 5. Clients are notified of incidents affecting their material.
10. Changes to this notice
When this notice changes materially, the date at the top changes with it. Where the change affects an active engagement, the client is notified directly.