Trust & transparency

Privacy Notice

Updated · July 2026

Privacy in plain English

Operative.law collects the information you choose to submit through a matter or resource form, together with limited technical information needed to deliver and secure the site. When the production Neon database is configured, matter and resource enquiries are stored in Neon Postgres. Resource requests use a short-lived access cookie and store the request and any marketing choice. We do not intentionally use advertising or analytics cookies and we do not sell personal information. Do not submit documents, confidential information or unnecessary personal detail through the website forms.

1. Responsible party and contact

Responsible party for website enquiries. Threshold 0 (Pty) Ltd is responsible for personal information submitted through the general website and resource forms. Paul Kruger, an admitted attorney practising for his own account, is the contact for those enquiries. Operative.law is a shared public brand used by independent admitted attorneys practising for their own accounts; it is not a law firm. Each attorney remains responsible for information processed in connection with that attorney’s accepted matter.

Registered address. 7 Bergh Rd, Stellenbosch.

Information Officer. Paul Kruger. Privacy requests can be sent to paul@operative.law.

Privacy contact. paul@operative.law.

This notice applies to personal information processed through the Operative.law website, its matter-enquiry form, its gated resource forms and related correspondence. An accepted client matter may also be governed by a matter-specific privacy or engagement notice.

2. What we collect

Depending on how you use the website, we may process:

  • Matter-enquiry information: your name, work email, company, selected contract need, proposed deadline, short context, source page and a technical submission identifier.
  • Resource-request information: your email address, requested resource, marketing choice, intended contact methods, source and landing pages, campaign parameters, request timestamps and a hashed temporary access token.
  • Correspondence: information you send by email or provide during preliminary discussions.
  • Technical information: request, device, browser, IP-address, approximate-location, security and diagnostic data ordinarily processed when Vercel delivers and protects a website.
  • Client information: if a matter is accepted, information needed to identify the client, conduct conflicts and verification checks, provide the agreed services, invoice, keep required records and meet professional or legal obligations.

The website forms do not ask for document uploads. Matter context is limited to 2,000 characters. Please provide only enough non-confidential information for an initial response.

We receive information directly from you, from your browser or device and from providers involved in delivering the website or communications.

3. Why and how we use information

We use personal information where permitted by applicable law, including to:

  • respond to an enquiry and decide whether Operative can consider or accept a matter;
  • conduct conflict, identity, suitability and risk checks;
  • prepare a proposed scope, fee and timing;
  • provide a requested resource and maintain its temporary access control;
  • contact you about Operative’s services where you have consented or another lawful basis applies;
  • operate, secure, troubleshoot and improve the website;
  • prevent duplicate submissions, misuse, fraud and technical failure; and
  • meet professional, accounting, tax, regulatory, dispute and other legal obligations.

The applicable basis may include taking steps at your request before a contract, performing an accepted engagement, complying with law, protecting legitimate operational or security interests, or your consent.

Marketing consent is optional. Withdrawing it does not affect the lawfulness of processing that occurred before withdrawal and does not prevent service or matter-related communication where another lawful basis applies.

4. Cookies and temporary resource access

The current resource-gate implementation sets a secure, HTTP-only, SameSite=Lax cookie after a valid resource request. The cookie contains a random access token and expires after 30 minutes. The database stores only a SHA-256 hash of that token together with the resource-request record.

The access cookie is used to open the requested protected resource. It is not an advertising cookie.

The current site does not intentionally set advertising or analytics cookies. If analytics, embedded scheduling, payment or other optional tracking is introduced, this notice and any consent mechanism must be updated before activation where required.

Google Fonts is currently requested from Google’s servers. That request may expose ordinary technical request information, such as your IP address and browser details, to Google under its own privacy terms.

5. Service providers and transfers

The current implementation uses or anticipates the following provider categories:

Vercel and Neon: website delivery, server-side processing and Postgres storage

The website routes matter and resource submissions through Vercel Functions and stores the relevant records in Neon Postgres when the production database is configured. Vercel and Neon may also process security, network and request-log data under their applicable terms.

Google Fonts: font delivery

The current pages load Newsreader, Archivo and IBM Plex Mono from Google Fonts. Google processes the technical request needed to deliver those files.

Business email provider: correspondence

If you email Operative directly, the mailbox and infrastructure providers used for that address process the correspondence under their applicable privacy and security terms.

Providers may process information in countries outside South Africa. Where POPIA or other applicable law requires it, the responsible party must use an appropriate transfer basis and reasonable contractual, organisational and technical safeguards.

We do not sell personal information. We may disclose it where necessary to professional advisers, correspondent or specialist counsel, technology providers, regulators, courts, law-enforcement bodies or another person where authorised or required by law, an accepted engagement or your instructions.

6. Retention and security

Unsuccessful or unaccepted matter enquiries and resource-request records are retained for no longer than 24 months after the last meaningful interaction, unless a longer period is reasonably required for conflicts, complaints, disputes, fraud prevention or law. Accepted client-matter records are retained under the engagement terms and applicable professional, tax and legal requirements. Marketing choices are retained only while the permission or other lawful basis remains relevant and no longer than the applicable retention period unless a longer period is required by law.

The 30-minute access cookie expires automatically. A scheduled Vercel cleanup function deletes eligible matter-enquiry and resource-request records after the retention period; the database stores only a hash of the temporary access token rather than the raw token.

Vercel, Neon and other providers control some security logs and retention under their own terms. We use, or intend to use, HTTPS, access controls, token hashing, honeypot checks, input limits and other measures appropriate to the service. No internet transmission or storage system can be guaranteed completely secure.

If a security compromise involving personal information occurs, the responsible party will investigate, take reasonable containment measures and notify the Information Regulator and affected people where required by law.

7. Your choices and rights

Subject to applicable law and lawful retention duties, you may ask us to confirm whether we hold your personal information, request access, ask for inaccurate information to be corrected, request deletion, object to certain processing, withdraw consent or ask for an explanation of how information is used.

To make a request or withdraw marketing consent, email paul@operative.law. We may need to verify your identity before acting. We will respond within the period required by applicable law or explain any lawful reason for delay or refusal.

You may complain to the South African Information Regulator through inforegulator.org.za. Depending on where you live or how information is processed, additional rights may apply.

The website and services are directed at businesses and adults. Do not submit a child’s personal information unless you have lawful authority and it is genuinely necessary for an accepted matter.

8. Contact and changes

Privacy questions and requests can be sent to paul@operative.law.

We may update this notice when the website, services, providers or legal requirements change. The date at the top identifies the current version. Material changes will be posted on this page.