POPI ACT POLICY
1. PURPOSE
1.1 This privacy policy undertakes to promote the protection of Personal Information processed by Cape Kindred Tours (Pty) Ltd and comply with the conditions for processing as set out in POPIA.
1.2 To recognize the Data Subject’s right to privacy as enshrined in section 14 of the Constitution of the Republic of South Africa, 1996, which includes the right to protection against the unlawful collection, retention, dissemination and use of personal information.
1.3 The Company and its Employees are obligated to treat Personal Information concerning all Data Subjects, including their health information, as private and confidential.
2. DEFINITIONS
2.1 Data Subject “means the Person to whom Personal Information relates. As it relates to the Company, a Data Subject further includes clients, guardian, guarantor, visitor and / or competent person who consents on behalf of a minor.”
2.2 Operator “means a person who processes Personal Information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party.”
2.3 Person “means a natural person or juristic person.”
2.4 Personal Information “means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including the following that relates to the Company, but not limited to: information relating to the race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person, information relating to financial history of the person such as banking details and / or payment card details; any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person; the personal opinions, views or preferences of the person; correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence. Technical data including internet protocol address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Company’s website.”
2.5 Processing “means any operation or activity or any set of operations, whether or not by automatic means, concerning Personal Information, including:
2.5.1 the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use;
2.5.2 dissemination by means of transmission, distribution or making available in any other form; or
2.5.3 merging, linking, as well as restriction, degradation, erasure or destruction of information;”
2.6 PAIA “means the Promotion of Access to Information Act 2 of 2000 (as amended).”
2.7 POPIA “means Personal Information in the Protection of Personal Information Act 4 of 2013 (as amended).”
2.8 Responsible Party “means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing Personal Information.”
2.9 Services “means to the services indicated on our website and promoted via other sites of ours (if any).”
2.10 Special Personal Information “means Personal Information of a Data Subject concerning he religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information, criminal behavior related to alleged commission of any offence or related proceedings.”
3. DATA SUBJECT RIGHTS
A Data Subject has the right to have his, her or its Personal Information processed in accordance with the conditions for the lawful processing of Personal Information, which including the right:
3.1 To be notified that personal information is being collected by the Company, or has been accessed or acquired by an unauthorized person.
3.2 To establish whether the Company holds Personal Information of a Data Subject and to request access to his, her, its Personal Information.
3.3 To request, where necessary, the correction, destruction or deletion of Personal Information. Data Subjects are requested to ensure that their Personal Information is accurate and up to date.
3.4 To object, on reasonable grounds, to processing Personal Information.
3.5 Not to have Personal Information processed for purposes of direct marketing by means of unsolicited electronic communication, unless consent is granted by the Data Subject.
3.6 To submit a complaint to the Regulator regarding the data breach of a Data Subject’s Personal Information. The contact details of the Information Regulator are available on its website at: https://justice.gov.za/inforeg/. However, the Company requests the Data Subject to first attempt to resolve the matter internally with the Information Officer and / or Deputy Information Officer for a speedier resolution.
3.7 To restrict processing of Personal Information in the event that you require the Company to establish the accuracy of your data or where by law, the Company is required to delete or withhold information.
3.8 To withdraw your consent to process your Personal Information.
3.9 To a response within 30 (thirty) days. However, please note the Company may take longer than 30 (THIRTY) days given the surrounding circumstances of your request. The Company will endeavor to keep you informed accordingly.
4. RETENTION AND RESTRICTION OF RECORDS
The Company will retain the Data Subject’s Personal Information:
4.1 In terms of section 14 of POPI, records of Personal Information must not be retained any longer than is necessary for achieving the purpose for which the information was collected and processed. Records should not be retained on an indefinite basis.
4.2 Statutory and regulatory obligations to keep certain types of records for specific periods must be complied with.
4.3 Should it be required in terms of a contract.
5. HOW DOES THE COMPANY COLLECT PERSONAL INFORMATION?
5.1 Directly from Data Subjects in writing and / or electronically.
5.2 By means of providing feedback on the Company’s website.
5.3 When you visit the Company’s website and / or social media platforms.
5.4 By completing certain forms that Company may require from time to time as prescribed by law or the Company’s policy.
6. WHO ELSE GETS TO PROCESS YOUR PERSONAL INFORMATION?
The Company may make your Personal Information available:
6.1 The companies listed under the definition of the Company, together with their employees.
6.2 To third party service providers involved in the treatment of the Data Subject or to the extent that such Personal Information is necessary to render services to the Data Subject, whether in respect of Service’s rendered to the Data Subject during the admission or at future admissions of the Data Subject to the Company.
6.3 Law enforcement, government officials, fraud agencies or other third parties when the disclosure of Personal Information is necessary or appropriate in connection with an investigation of fraud, intellectual property infringements, or other activity that is illegal or may expose the Company to legal liability or financial loss, to report or support the investigation with the South African Police Services and / or any similar statutory body such a court of law.
7. DIRECT MARKETING
You have the right be requested to be added and / or “opt-in”, alternatively removed and / or “opt-out” for purposes of direct marketing by any form of electronic communication from time to time, including but not limited to telephone, email and SMS notifications.
8. SOCIAL MEDIA
Please note that the Company does not own any of the social media platforms it may interact with Data Subjects from time to time, such as, including but not limited to, Facebook, Instagram, LinkedIn. The Company and Data Subjects must comply with the terms and conditions, as well as the privacy policies of each respective social media platform.
9. SECURING YOUR PERSONAL INFORMATION
9.1 The Company securely stores the Data Subject’s Personal Information in our possession or under our control by taking the appropriate, technical and organizational measures to prevent loss, damage or unauthorised use and / or destruction of Personal Information.
9.2 The Company does not permit any Person to access Personal Information without complying with the requirements as set out POPI, PAIA.
9.3 The Company strictly prohibits the unlawful processing of Personal Information.
9.4 The Company has in place policies, controls and processes to secure your Personal Information, which includes but is not limited to:
9.4.1 Security measures, whether this be of a physical, technical, network and / or electronic nature.
9.4.2 Access control and monitoring.
9.4.3 Secure storage of physical records of Personal Information and encryption of electronic records regarding Personal Information.
9.4.4 Personal Information data breach reporting structure.
9.5 Our website, social media pages and / or any electronic means of communication may include links to third party’s. Data Subjects, not the Company, may therefore enable third parties to collect or share their Personal Information by clicking on third party links. The Company will not in any way be held responsible or liable for any data breach as a result of the Data Subject clicking on third party links. The Company will not be liable for any loss, damage or destruction to Personal Information, howsoever that loss, damage or destruction may arise.