- MDOT Consulting (Pty) LTD (2019/116287/07)
This policy details how we collect, store, protect and use personal information – that is information that can be used to identify an individual or a company (juristic person).
Personal information includes:
- certain information that is collected automatically when you visit our website,
- certain information collected on registration;
- certain information collected on submission; and
- optional information that you provide to us voluntarily.
Additional information captured on the website that does not classify as personal information may also be collected and processed, including but not limited to:
- anonymised information,
- de-identified information that cannot be associated with an individual,
- statistical information,
- information that is public knowledge, which has been publicly and voluntarily disclosed.
Lawful Processing of Personal Information
The conditions for the lawful processing of personal information by or for a responsible party are the following, as per the Protection of Personal Information Act of 2013 (POPIA):
- Processing Limitation
- Purpose Specification
- Further Processing Limitation
- Information Quality
- Security Safeguards
- Data Subject Participation
- This policy applies to all personal information processed by the company and its related entities.
- The Information Officer shall take responsibility for compliance with this policy.
- The policy will be reviewed annually.
Lawful, fair and transparent processing
- To ensure its processing of data is lawful, fair and transparent, a Register of Systems and Activities will be maintained.
- The Register shall be reviewed at least annually.
- Individuals have the right to access their personal data and any such requests made to us shall be dealt with in a timely manner.
- All data processed must be done on one of the following lawful bases: consent, contract, legal obligation, public task or legitimate interests.
- We shall note the appropriate lawful basis in the Register of Systems.
- Where consent is relied upon as a lawful basis for processing data, evidence of opt-in consent shall be kept with the personal data.
- Where communications are sent to individuals based on their consent, the option for the individual to revoke their consent will be clearly available and systems should be in place to ensure such revocation is reflected accurately.
- We shall ensure that personal information collected is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
- We shall take reasonable steps to ensure personal information is accurate.
- Please update us via online forms, registrations, email or phone should your information need to be corrected or updated.
- Where necessary for the lawful basis on which data is processed, steps shall be put in place to ensure that personal information is kept up to date.
Archiving / Removal
- To ensure that personal data is kept for no longer than necessary, archiving policies are in place for each area in which personal data is processed.
- Archiving policies are reviewed annually.
- The archiving policy shall consider what data should/must be retained, for how long, and why.
- Campaign data is only retained and used for one year.
- We shall ensure that personal information is stored securely using modern software and systems that are kept up-to-date.
- Access to personal information shall be limited to personnel who need access and appropriate security is in place to avoid unauthorised sharing of information.
- When personal information is deleted this will be done safely such that the data is irrecoverable.
- Appropriate back-up and disaster recovery solutions are in place.
- Vulnerability assessments and hardening are performed on systems where personal information is stored.
- In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data, we shall promptly assess the risk to people’s rights and freedoms and if appropriate report this breach to the appropriate authorities and subjects as required by law.
- You may decline the installation of cookies; however, this may degrade your website experience.
- Third party cookies may be in use in order to deliver a service via our website by means of a third-party online service – such as YouTube or Google Analytics.
Collection of Information
- We will obtain your consent when collecting personal information for processing purposes.
- On registration for services or promotions, you may provide us with the following information:
- Name and surname
- Email address
- Contact numbers
- Physical address
- Company name
- Company address
- Company VAT number
- Company contact person
- Company phone number
- By using our website, we receive and may record details such as:
- Your IP address
- Bounce rate
- Page time
- Cost per Click
- Most Visited Pages
- Device Information
- From time to time, we may run promotional campaigns in which additional details are collected. This information would be provided voluntarily by you in order to participate or receive a prize delivery.
Purpose of Collection
- We may process your information for provision of services that you agreed to when providing it to us.
- We may process your information for billing purposes.
- We may process your information for ongoing communication during the course of regular business.
- We may process your information for lawful marketing purposes.
Marketing and Targeted Content
Sharing of Information
- We will not sell personal information. No personal information will be disclosed to anyone except as provisioned in this Policy.
- We may disclose personal information if required by court order or to comply with the law.
- Information may be shared between the groups indicated on this policy in order to provide a service to clients.
Cross Border Transfers
- We may transfer your information outside of the country in which it was collected for processing.
- You consent to us processing your personal information in a foreign country where required for completion of our obligations.
- For any queries relating to our policy, please contact us on firstname.lastname@example.org.