Legal

Privacy Policy

Last updated: 13 September 2026

1. Introduction

Brand Protocol Engineer ("we," "us," "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use it, how we protect it, and your rights regarding it.

This policy complies with the Protection of Personal Information Act 4 of 2013 (POPIA) of South Africa, and where applicable, the UAE Federal Decree-Law No. 45 of 2021 (PDPL) and the EU General Data Protection Regulation (GDPR).

2. Responsible Party and Information Officer

Under POPIA, the "responsible party" is the entity that determines the purpose and means of processing personal information.

  • Responsible party: Brand Protocol Engineer
  • Information Officer: Jesse A. Jobe
  • Email: jesse@brandprotocol.engineer
  • WhatsApp (UAE): +971 55 753 2969
  • WhatsApp (SA): +27 62 109 7361
  • Business registration: South Africa
  • Operating location: Dubai, United Arab Emirates

The Information Officer is registered with the South African Information Regulator in accordance with Section 55 of POPIA.

3. What Information We Collect

Data typeHow collectedPurpose
Website URLsYou submit a URL to the MEP Scan toolTo generate a preliminary website evaluation
Email addressYou email us, subscribe to the Journal, or submit a contact formTo respond to your enquiry or deliver Journal essays
Phone numberYou contact us via WhatsAppTo respond to your enquiry
NameYou provide it during an engagement or enquiryTo identify you and personalise communication
Business informationYou provide it during an engagementTo scope and deliver services
Analytics dataAutomatically via Google Analytics (cookies)To understand how visitors use the website
Device and browser dataAutomatically via server logsTo ensure the website displays correctly
IP addressAutomatically via server logs and analyticsSecurity, analytics, and geographic insight
Cookie preferencesYour consent choice on the cookie bannerTo remember your preference

What we do NOT collect

We do not collect financial information (credit card numbers, bank details), identity documents, biometric data, or information about children under 18. We do not purchase personal information from third parties.

4. Legal Basis for Processing

Under POPIA, we process personal information on the following lawful grounds:

  • Consent (Section 11(1)(a)) — you consent when you submit information through our contact channels or accept cookies
  • Contractual necessity (Section 11(1)(b)) — processing is necessary to perform a service you requested
  • Legitimate interest (Section 11(1)(f)) — we process analytics data to improve the website, provided this does not prejudice your rights
  • Legal obligation (Section 11(1)(c)) — we may process information to comply with South African law

5. How We Use Your Information

  • To respond to your enquiries via email or WhatsApp
  • To deliver services under a formal engagement agreement
  • To generate MEP Scan reports when you submit a URL
  • To send quarterly Journal essays if you subscribe (and only then — no marketing sequences, no follow-ups, no tracking pixels)
  • To understand how visitors use this website (via Google Analytics) so we can improve it
  • To protect the security of this website (via Wordfence)
  • To create anonymised and aggregated performance data for marketing, case studies, and educational content (e.g., publishing MEP score improvements without identifying the client unless permission is granted)
  • To improve our services, methodology, and tools based on aggregated engagement data

We do not sell, rent, trade, or share your personal information with third parties for their marketing purposes. Ever.

Portfolio and Case Study Data

By engaging Brand Protocol Engineer, you consent to the use of anonymised engagement data (such as industry category, MEP score progression, and before/after metrics) in marketing materials. If you wish to be excluded from identifiable case studies, you may notify us in writing. Full terms are described in Section 6 of the Terms of Service.

6. Cookies

This website uses cookies. A cookie is a small text file stored on your device when you visit a website.

CookieTypePurposeDuration
bpe_consentFunctionalRemembers your cookie consent choice1 year
_ga, _gidAnalyticsGoogle Analytics — measures traffic and behaviourUp to 2 years
wordfence_*SecurityWordfence firewall — protects against attacksSession / 24 hours
lscache_*PerformanceLiteSpeed Cache — speeds up page loadingVaries

Analytics cookies are only set after you click "Accept" on the cookie consent banner. If you click "Decline," no analytics cookies are set. Security and performance cookies are essential for the website to function and are set regardless of your choice.

You can also control cookies through your browser settings. Note that disabling essential cookies may affect website functionality.

7. Third-Party Services

We use the following third-party services that may process your data:

  • Google Analytics (Google LLC, USA) — website traffic analysis. Google Privacy Policy
  • Google Search Console (Google LLC, USA) — search performance monitoring. No personal visitor data is shared.
  • Hostinger (Hostinger International Ltd, Lithuania) — website hosting and server infrastructure. Hostinger Privacy Policy
  • WhatsApp (Meta Platforms Inc, USA) — messaging when you contact us via WhatsApp. WhatsApp Privacy Policy
  • Wordfence (Defiant Inc, USA) — website security and firewall. Wordfence Privacy Policy

We have no control over the privacy practices of these third parties. We encourage you to review their policies.

8. Cross-Border Data Transfers

Brand Protocol Engineer is registered in South Africa and operates from Dubai, UAE. Our hosting servers are managed by Hostinger. Your information may be processed in:

  • South Africa — where the business is registered
  • United Arab Emirates — where the principal operates
  • European Union / Lithuania — where Hostinger's infrastructure is located
  • United States — where Google and WhatsApp process analytics and messaging data

In accordance with Section 72 of POPIA, we ensure that any cross-border transfer of personal information is subject to either: (a) adequate data protection laws in the receiving country, (b) binding agreements that provide substantially similar protection to POPIA, or (c) your explicit consent.

9. Data Retention

  • Enquiry data (emails, WhatsApp messages): retained for the duration of any resulting engagement plus 24 months, then deleted. This allows us to reference prior conversations if you return for a new engagement.
  • Client engagement data: retained for 7 years after the engagement ends, as required for tax records and potential disputes under South African law (Prescription Act 68 of 1969)
  • Journal subscriptions: retained until you unsubscribe. Unsubscribe in one click from any Journal email.
  • Analytics data: retained by Google for up to 26 months (configured in Google Analytics settings)
  • MEP Scan submissions: URLs submitted are processed in real-time. We may retain anonymised scan results (without the submitter's identity) for research and product improvement purposes.
  • Aggregated performance data: anonymised and aggregated engagement metrics (MEP scores, industry benchmarks, before/after comparisons) are retained indefinitely for marketing, case studies, and methodology improvement. This data cannot be used to identify individual clients.
  • Cookie consent: your preference is stored in a cookie on your device for 1 year

10. Your Rights

Under POPIA, you have the right to:

  • Access — request confirmation of whether we hold your personal information and request a copy of it (Section 23)
  • Correction — request that we correct or update inaccurate personal information (Section 24)
  • Deletion — request that we delete your personal information where it is no longer necessary (Section 24)
  • Object — object to the processing of your personal information on reasonable grounds (Section 11(3))
  • Withdraw consent — withdraw any consent you previously gave (this does not affect the lawfulness of processing before withdrawal)
  • Lodge a complaint — submit a complaint to the South African Information Regulator
To exercise any of these rights: email jesse@brandprotocol.engineer with the subject line "POPIA Data Request" and describe what you need. We will respond within 30 days as required by POPIA. We may ask you to verify your identity before processing your request.

For EU residents (GDPR)

If you are located in the European Union, you additionally have the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority.

For UAE residents (PDPL)

If you are located in the UAE, you have rights under Federal Decree-Law No. 45 of 2021, including the right to access, correct, and request deletion of your personal data.

11. Information Regulator (South Africa)

If you are not satisfied with how we handle your personal information, you have the right to lodge a complaint with:

  • The Information Regulator (South Africa)
  • JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
  • PO Box 31533, Braamfontein, Johannesburg, 2017
  • Email: complaints.IR@justice.gov.za
  • Tel: +27 10 023 5200

12. Data Security

We take appropriate technical and organisational measures to protect your personal information, including:

  • SSL/TLS encryption on all pages (HTTPS)
  • Wordfence web application firewall
  • Security headers (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy)
  • Daily automated backups
  • Restricted admin access with strong authentication
  • Regular security scanning

No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

13. Children's Privacy

This website is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Changes take effect upon publication on this page. The "Last updated" date at the top reflects the most recent revision. We encourage you to review this page periodically.

15. Contact

For questions about this Privacy Policy or to exercise your data rights:

  • Information Officer: Jesse A. Jobe
  • Email: jesse@brandprotocol.engineer (subject: "POPIA Data Request")
  • WhatsApp: +971 55 753 2969
  • Response time: Within 24 hours (formal POPIA requests within 30 days)