Privacy
Privacy information for website visitors and initial enquiries.
International privacy information
How we handle information across international enquiries and assignments.
This notice explains how Aperture Research Works handles information received through the website, email, WhatsApp progress communication and accepted research assignments. Aperture works internationally, including on US-facing and cross-border matters, so information may originate in or relate to more than one country.
Information we may receive
This may include identity and contact details, organisation details, country and jurisdiction, the questions submitted, intended use, documents, source references, deadlines, billing information, correspondence, technical website data and other information voluntarily supplied.
Purpose and lawful handling
Information is used to assess suitability, communicate, define scope, prepare estimates and quotations, establish a case reference, perform accepted work, maintain records, protect legal and commercial interests, meet payment and accounting duties and improve service delivery. Processing is limited to legitimate professional purposes, contractual steps, legal obligations, consent where applicable and other lawful bases recognised in the relevant jurisdiction.
Written communication and case references
Official communication is handled by email. Voice calls are not accepted. Written records, including the unique client reference, help preserve traceability, reduce misunderstanding and connect future correspondence to the correct matter. WhatsApp is reserved for urgent attention and progress checks and is not the substantive case record.
International transfers and service providers
Website hosting, email, payment, document, security or technology providers may process information in countries different from the client’s location. Reasonable contractual, technical and organisational controls are used where available. No internet or cross-border system can be represented as risk-free.
Payments
Payments are currently facilitated through Payfast in South Africa. Payment providers and financial institutions process their own transaction and verification data under their own privacy terms. Aperture does not need or request a client’s full card credentials.
Sensitive, privileged and personal information
Do not send passwords, unrestricted identity records, medical records, privileged documents, trade secrets or highly sensitive personal information at initial enquiry stage. Appropriate handling, necessity, minimisation and transfer arrangements should be discussed first.
Research subjects and public-source information
Accepted assignments may require lawful collection and analysis of public, client-supplied or properly accessible information about organisations, individuals, markets, public officials, litigation, publications or events. Relevance, lawful access, accuracy, proportionality and professional boundaries are considered in context.
Retention
Enquiries, case references, accepted assignment records, invoices and research materials may be retained for as long as reasonably necessary for communication, delivery, evidence traceability, legal obligations, dispute management, security, professional records and legitimate business purposes. Retention periods may differ by matter and jurisdiction.
Security
Reasonable safeguards are used, but absolute security cannot be guaranteed. Clients must use secure channels and avoid unnecessary sensitive disclosure. Aperture may decline or pause handling where the security or legal risk is disproportionate.
Your requests and rights
Depending on applicable law, a person may request access, correction, deletion, restriction, objection, portability or information about processing. Rights are not absolute and may be limited by legal duties, legitimate interests, research integrity, evidential preservation, disputes or third-party rights.
Children and students
The service is not directed to children. Student assistance may be considered only in exceptional verified circumstances and must comply with academic integrity and applicable privacy requirements.
Contact
Privacy enquiries must be sent in writing to info@apertureforensic.com. Include the relevant client or case reference where available.
Human review of enquiries
Initial enquiries and accepted assignments may be reviewed by Paul Hattingh, Xandro Hattingh and authorised contributors where necessary for scoping, administration, research or delivery. Client information is not intentionally placed into unrestricted public AI systems as a substitute for the agreed human-directed service.
Regulated and restricted data
Public-source sector research does not authorise the transfer of regulated or restricted information. Protected health information, non-public consumer-financial information, classified material, Controlled Unclassified Information, export-controlled technical data, restricted source code and similar material must not be submitted unless Aperture has expressly approved the information type, transfer method, contractual controls and security arrangements in writing.
Where a client requires processing on its behalf, a separate data-processing and security addendum may be required. The applicable engagement documents will identify the approved purpose, access limits, retention, deletion, incident procedure and service-provider conditions.
Personal information across jurisdictions
Aperture Research Works handles personal information according to the lawful purpose, agreed scope and applicable jurisdiction. We minimise collection, restrict access, avoid unnecessary sensitive data, and assess cross-border handling where applicable law requires additional safeguards. Do not send passports, banking details, medical information, children's data or other highly sensitive material in an initial enquiry unless specifically requested through an appropriate route.
Website analytics and privacy
We may measure page views, engagement, scroll depth, traffic source, device and language, and interactions with services, scenarios, case studies and enquiry routes. Analytics must not intentionally capture the substance of your matter, documents, names, email addresses or confidential enquiry text.