NJH INSTITUTE

Privacy Policy

NoraJiks (Pty) Ltd trading as NJH Institute · Effective 01 August 2026

1. Purpose and scope

NoraJiks (Pty) Ltd trading as NJH Institute is the responsible party for personal information processed through NJH Institute services. This policy explains what we collect, why we use it, who receives it, how long it is retained and how data subjects can exercise their rights. It applies to website visitors, learners, applicants, members, certification candidates, employers, employees, facilitators and business contacts.

We process information in accordance with POPIA and other applicable South African law. This policy does not replace a specific consent or notice presented for an optional use; where a specific notice gives more detail, both apply.

2. Information we collect

Identity and contact information, including names, identification or passport details where required, date of birth, address, email, telephone number, profile photo and account credentials.

Application and professional information, including qualifications, experience, employment, supporting documents, membership category, employer relationship and eligibility evidence.

Learning, assessment and credential information, including enrolments, activity, attendance, submissions, marks, feedback, CPD records, certificates, verification history and disciplinary or appeal records.

Employer and consent information, including invitations, authenticated employment links, sponsorship arrangements, permissions, withdrawals and audit logs.

Payment and transaction information, including invoices, amounts, payment status, payment-provider references and limited billing details. Payment providers ordinarily handle full card or bank credentials.

Technical and usage information, including IP address, device/browser details, authentication events, portal activity, logs, cookies and communications preferences.

Communications and support records, including enquiries, complaints, calls or messages and responses.

3. Sources of information

We collect information directly from you; from an employer or sponsor that invites or pays for you; from facilitators, assessors and verification sources; from payment and technology providers; and from lawful public or regulatory sources. Where information comes from an employer, we will authenticate the relationship and seek any required employee consent before exposing detailed records.

4. Why and on what basis we process information

We process information to create and secure accounts; assess applications; deliver courses, assessments, memberships and certifications; issue and verify records; administer employer links and sponsorships; process payments; communicate service information; provide support; prevent fraud; maintain audit and legal records; improve services; and comply with legal obligations.

The justification depends on the activity and may include consent, performance of a contract, compliance with law, protection of a legitimate interest of the data subject, or pursuit of our or a third party’s legitimate interests where the interests and rights of the data subject are appropriately balanced. Consent may be withdrawn, but withdrawal does not invalidate earlier lawful processing and may affect an optional feature.

5. Employer verification and CPD access

An employer may request verification only through an approved organisational account. We disclose detailed membership and CPD information only after the employee authenticates and gives recorded, informed permission for that employer relationship, unless a different disclosure is required or expressly permitted by law.

The employee can withdraw permission. Withdrawal prevents future employer access but does not erase lawful audit evidence or information already used for a legitimate employment process. Employer users must use records only for the stated verification purpose, restrict internal access, keep information secure and stop using it when the purpose ends. Testimonials, public profiles and unrelated disclosures require separate permission.

6. Sharing and operators

We may share information with contracted hosting, learning-platform, communications, identity, assessment, storage, support and payment providers that process it for defined purposes and subject to confidentiality and security obligations.

We may also share information with approved employers or sponsors within recorded permissions; facilitators, assessors and verification bodies as necessary; professional, accreditation or regulatory bodies where required or authorised; advisers and auditors; authorities or courts where lawfully required; and a successor involved in a legitimate business reorganisation, subject to appropriate safeguards.

We do not sell personal information.

7. Cross-border processing

If information is processed outside South Africa, we will use a recipient subject to a law, binding agreement, corporate rules or consent that provides an adequate level of protection as required by POPIA, and will limit the transfer to what is necessary.

8. Retention

We retain information only as long as reasonably necessary for the stated purpose, contractual and legal requirements, dispute periods, academic or credential integrity and legitimate recordkeeping. Retention periods differ by record type. When retention is no longer justified, information is securely deleted, destroyed or de-identified. Some credential and audit records may be retained for the life of the credential or longer where verification and fraud prevention require it.

9. Security and incident response

We use reasonable technical and organisational safeguards appropriate to the nature of the information, including access controls, authentication, least-privilege permissions, logging, backups, secure transmission where supported, provider due diligence and staff confidentiality. No system is completely risk-free.

If there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will investigate, contain the incident and notify the Information Regulator and affected data subjects as required by POPIA, unless notification is lawfully delayed.

10. Your rights

Subject to applicable law, you may ask whether we hold your personal information; request access; ask for correction or deletion of inaccurate, excessive, outdated, incomplete, misleading or unlawfully obtained information; object to certain processing; withdraw consent; request evidence of an authorisation; and complain to us or the Information Regulator.

Send requests to tuli.martines@njholdings.co.za. We may need to verify identity and may refuse or limit a request only where the law permits. Access requests may be administered under PAIA where applicable.

11. Cookies and electronic marketing

We may use essential cookies for authentication, security, preferences and service delivery, and optional analytics cookies where enabled. Browser settings can restrict cookies, but essential functions may then fail.

We send direct electronic marketing only where permitted. You may opt out through the unsubscribe mechanism or by contacting us. Opting out does not stop transaction, security, membership or course communications.

12. Children and special personal information

We do not knowingly collect children’s information without a lawful basis and required competent-person authorisation. Where a programme is intended for minors, a specific notice and consent process will apply. We limit collection of special personal information and criminal-behaviour information to what is authorised and necessary.

13. Complaints and contact

Information Officer: Tuliswa Martines
Email: tuli.martines@njholdings.co.za
Address: 10a Davidson Street Berea East London Eastern Cape 5241
Telephone: 0430509112

You may lodge a complaint with the Information Regulator (South Africa) using its current complaints process at https://inforegulator.org.za/complaints/. We encourage you to contact us first so that we can try to resolve the matter.

14. Changes to this policy

We may update this policy to reflect legal, operational or service changes. The current version and effective date will be published on the website, and material changes will be communicated where reasonably required.

Official legal references