Last Updated: June 2026
IDEAS21 ("we", "our", or "us") is committed to protecting the privacy and confidentiality of our clients, research partners, and website visitors. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information in compliance with the South African Protection of Personal Information Act (POPIA) and the European Union General Data Protection Regulation (GDPR).
1. Information We Collect
We only collect personal information that is voluntarily provided by you or necessary to deliver our specialized advisory services and research insights. This includes:
Contact Data: Name, email address, phone number, and geographic location.
Professional Data: Organization name, job title, institutional affiliations, and the nature of your systemic or consulting inquiries.
Subscription Data: Email addresses provided explicitly to subscribe to our newsletter, Substack updates, or research releases.
2. Legal Basis for Processing (GDPR Compliance)
If you are located within the European Economic Area (EEA), our legal basis for collecting and using your personal data depends on the specific context:
Consent: You have given clear consent for us to process your data (e.g., signing up for our newsletter or submitting a contact form).
Contractual Necessity: Processing is necessary to fulfill a consulting brief, engagement contract, or advisory agreement with you or your organization.
Legitimate Interests: Processing supports our legitimate business interests in maintaining institutional relationships, improving our research distribution, and preventing spam.
3. How We Use Your Data
We utilize the collected data strictly for the following professional purposes:
To respond to your advisory, speaking, or research inquiries.
To manage client engagements, project workflows, and contractual obligations.
To distribute relevant research papers, white papers, and academic insights (only when explicitly requested or subscribed to).
To comply with legal, financial, and regulatory obligations.
4. Data Retention & Third-Party Processors
We do not sell, rent, or lease your personal data to third parties. Your data is retained only for as long as necessary to fulfill the purposes outlined in this policy or to comply with statutory retention laws.
We utilize secure, GDPR- and POPIA-compliant third-party infrastructure to facilitate our operations (such as premium web hosting providers, contact form processors, and email distribution networks like Substack). These processors are contractually bound to maintain absolute confidentiality and data security.
5. Your International Data Rights (GDPR & POPIA)
Regardless of your location, you hold the following rights regarding your personal data:
The Right to Access: You may request a copy of the personal data we hold about you.
The Right to Rectification: You may request that we correct any inaccurate or incomplete information.
The Right to Erasure ("Right to be Forgotten"): You may request that we delete your personal data from our systems entirely.
The Right to Object/Restrict: You may object to direct marketing or withdraw your processing consent at any time.
6. Security Measures
We implement appropriate technical and organizational security protocols to safeguard your personal data against unauthorized access, alteration, disclosure, or destruction.
7. Contact Us
For any inquiries regarding this Privacy Policy, or to exercise your data rights, please contact us directly at: Email: jeremy@ideas21.com
Website: https://ideas21.com/