Legal

Privacy Policy

Last updated: January 2025  ·  Version 1.0

POPIA Compliant
GDPR Compliant
CCPA Compliant
Secure Data Handling

Orian Advisory ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, who we share it with and your rights — whether you're in South Africa, Australia, the United States or anywhere else in the world.

1. Who We Are

Orian Advisory is a financial services consultancy based in Johannesburg, South Africa, providing remote bookkeeping, tax compliance, payroll, accounts payable and related services to businesses in South Africa, Australia and the United States.

Data Controller: Orian Advisory, Johannesburg, Gauteng, South Africa
Contact: info@orianadvisory.com

2. What Information We Collect

We collect the following categories of personal information:

CategoryExamplesHow Collected
Contact InformationName, email address, phone numberEnquiry form, email
Business InformationCompany name, industry, countryEnquiry form, onboarding
Financial RecordsInvoices, bank statements, payroll dataProvided by client during service delivery
Usage DataIP address, browser type, pages visitedGoogle Analytics (anonymised)
CommunicationsEmail message contentDirect communication

3. How We Use Your Information

We use your personal information for the following purposes:

We will never sell, rent or trade your personal information to third parties for marketing purposes. Full stop.

4. Legal Basis for Processing

We process your personal data on the following legal grounds:

5. Who We Share Your Information With

We only share your information with trusted parties necessary for service delivery:

RecipientPurposeLocation
Xero / QuickBooks / Zoho / SAPAccounting platform for bookkeepingCloud — varies by platform
Google (Analytics)Anonymised website analyticsUSA (SCCs in place)
Tax authorities (SARS, ATO, IRS)Statutory compliance submissionsSA / AU / USA
Email / communication providersDelivering service communicationsCloud

All third parties are contractually required to protect your data and may only use it for the specified purpose.

6. International Data Transfers

As a firm operating across South Africa, Australia and the United States, your data may be processed in multiple jurisdictions. Where data is transferred internationally, we ensure appropriate safeguards are in place including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.

7. How Long We Keep Your Data

8. Your Rights

Depending on your location, you have the following rights regarding your personal information:

RightSA (POPIA)AU (Privacy Act)US (CCPA)
Access your data
Correct inaccurate data
Delete your data
Object to processing
Data portability
Opt out of data saleN/AN/A✓ (we don't sell data)

To exercise any of these rights, contact us at info@orianadvisory.com. We will respond within 30 days.

9. Cookies & Tracking

Our website uses the following cookies and tracking technologies:

10. Data Security

We take the security of your personal information seriously and implement the following measures:

In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant regulator within the legally required timeframe (72 hours under GDPR; as soon as reasonably practicable under POPIA).

11. Children's Privacy

Our services are directed at businesses and adults only. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected such information, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page will always reflect the most recent version. Material changes will be communicated to active clients by email.

Questions About This Policy?

If you have any questions, concerns or requests regarding your personal data, please contact us directly:

Email: info@orianadvisory.com

Address: Johannesburg, Gauteng, South Africa

You also have the right to lodge a complaint with the relevant data protection authority in your country — the Information Regulator (SA), the Office of the Australian Information Commissioner (AU), or your State Attorney General (US).