DATA PROCESSING POLICY

DATA PROCESSING POLICY OF RESTORATION CONCEPTS (PTY) LTD T/A CORPORATE BUSINESS SECURITY (“CBS”)

Definitions:

In this policy unless the context requires otherwise, the following terms will have the meanings given to them:

  • Applicable laws – Any laws applicable to personal data and personal information, including any statute, regulation, notice, policy, directive, ruling or subordinate legislation, the common law, any binding court order, judgment or ruling, any applicable industry code, policy or standard enforceable by law, or any applicable direction, policy or order that’s given by any regulator, competent authority or organ of state or statutory industry body.
  • Child – Any natural person under the age of 18 years.
  • Client – Any natural person (or, where applicable) juristic person, who’s concluded an agreement with Restoration Concepts (PTY) Ltd, Trading as Corporate Business Security (CBS)
  • Competent person – Anyone who’s legally competent to consent to any action or decision being taken by any matter concerning a juristic person or child, for example a director, parent or legal guardian.
  • Controller – Restoration Concepts (PTY) Ltd, Trading as Corporate Business Security (CBS), in circumstances where it processes personal data. The Controller will be referred to by the abbreviated name of CBS
  • Data subject – CBS’s clients. potential clients or any third party in respect of whom CBS processes personal information/personal data.
  • Operator – A person or entity who processes personal information/data for a responsible party.
  • Personal data – Any information relating to an identified or identifiable natural person (data subject).
  • Personal information – Will have the same meaning as is given in Section 1 of POPIA.
  • Policy – This data protection policy.
  • POPIA – The Protection of Personal Information Act No. 4 of 2013.
  • Processing – Any operation or activity or any set of operations, whether or not by automatic means, concerning personal information/personal data, including:

– Its collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use.
– Dissemination by means of transmission, distribution or making available in any other form by electronic communications or other means.
– Merging, linking, blocking, degradation, erasure, or destruction.

  • Regulator/s – Any applicable regulatory authority, including the Information Regulator established in terms of POPIA.
  • Responsible party – In the context of this policy, Restoration Concepts (PTY) Ltd, Trading as Corporate Business Security, CBS in short.
  • Special personal information/data Personal information/personal data concerning, amongst other aspects contemplated in terms of Section 26 of Part B of POPIA, a data subject’s religious beliefs, race or ethnic origin, trade union membership, political persuasion, health, sex life, biometric data, or criminal behaviour.
  • Third party – Any employee, independent contractor, agent, supplier, sub-contractor, regulator/s, user of CBS’s websites or other representative of CBS.
  • Website – The website/s owned and operated by CBS.

Purpose

The purpose of this POLICY is to explain the way in which Restoration Concepts (Pty) Ltd T/A Corporate Business Security (CBS’) deals with personal information of Data subjects and to establish a standard by which CBS and its employees and representatives will comply in as far as the processing of personal information/personal data is concerned.

The policy demonstrates CBS’s commitment to observe and comply with its obligations under POPIA when it processes personal information/ personal data from or in respect of any data subject.

Introduction

This policy regulates the processing of personal information/personal data by CBS and sets forth the requirements with which CBS undertakes to comply when processing personal information/personal data pursuant to undertaking its operations and fulfilling its contractual obligations in respect of data subjects and third parties in general. CBS places a high premium on the privacy of every person or organisation with whom it interacts or engages with and therefore acknowledges the need to ensure that personal information/personal data is handled with a reasonable standard of care as may be expected from it. CBS is therefore committed to ensuring that it complies with the requirements of POPIA. When a data subject or third party engages with CBS, whether it be physically or via any digital, electronic interface such as CBS’s website, self-service portal or mobile app, the data subject or third party acknowledges that they trust CBS to process their personal information/personal data. All data subjects and third parties have the right to object to the processing of their personal information/ personal data. Acceptance of the terms and conditions contained in this policy is voluntary. CBS does however require the data subject or third party’s acceptance to enable CBS to effectively advise/quote and deliver products to a data subject. liaise with a data subject, exercise its right, or enforce obligations as they arise from the applicable relationship and comply with applicable laws.

Collecting and processing of personal information/personal data

Whenever any data subject contacts CBS electronically or telephonically, or uses 1 of the products, services, facilities, tools or utilities offered by CBS through its website, self-service portal or mobile app. CBS will in effect be processing the data subject’s personal information/personal data.

From time to time, it may be that CBS has collected a data subject’s personal information/personal data from other sources. In the event that a data subject has shared their personal information/personal data with any third parties, CBS will not be responsible for any loss suffered by the data subject, their dependents, beneficiaries, spouse/s or employees (as the case may be).

CBS will process personal information/personal data in order to facilitate and enhance the delivery of products and services to its clients, as well as safeguard the personal information/personal data relating to any data subjects which it in fact holds.

In such an instance, the data subject providing CBS with such personal information/personal data will confirm that they are a competent person and that they have authority to give the requisite consent to enable CBS to process such personal information/personal data. CBS undertakes to process any personal information/ personal data in a manner which promotes the data subject’s constitutional right to privacy, retains accountability and data subject participation.

In supplementation of the above, CBS will process personal information/ personal data for the following purposes:

  • To provide or manage any information, products, or services requested by data subjects.
  • To establish a data subject’s needs, wants and preferences in relation to the products/services provided by CBS.
  • To identify a data subject’s risk profile and make an election as to whether CBS wishes to enter into a contractual relationship with the data subject and if so, on what terms.
  • To help CBS identify data subjects when they contact CBS.
  • To facilitate the delivery of products/services to clients.
  • To allocate unique identifiers to clients for the purpose of securely storing, retaining and recalling such data subject’s personal information/personal data from time to time.
  • To maintain records of data subjects and specifically client records.
  • To maintain third party records.
  • For general administration purposes.
  • For legal/contractual purposes.
  • For health and safety purposes.
  • To monitor access, secure, and manage any facilities owned or operated by CBS regardless of location in South Africa.
  • To transact with third parties.
  • To improve the quality of CBS’s products and services.
  • To analyse the personal information/personal data collected for research and statistical purposes.
  • To carry out analysis and client profiling.
  • To identify other products and services which might be of interest to our clients and data subjects in general, as well as to inform them of such products/services.
  • To obtain and share information about a data subject’s creditworthiness and risk profile with any credit bureau or credit provider’s industry association or industry body, which includes information pertaining to a data subject’s credit history, financial history, judgements, default history and sharing information for purposes of risk analysis, tracing, and related purposes.

CBS will collect and process personal information/ personal data in compliance with the conditions as set out in POPIA, to ensure that it protects the data subject’s privacy.

CBS won’t process the personal information/ personal data of a data subject for any purpose other than for the purposes set forth in this policy, unless CBS is permitted or required to do so in terms of applicable laws or otherwise by law.

Personal information/personal data for direct marketing purposes

CBS acknowledges that it may only use personal information/personal data to contact data subjects for purposes of direct marketing where CBS has complied with the provisions of POPIA and when it’s generally permissible to do so in terms of applicable laws.

CBS will ensure that a reasonable opportunity is given to all data subjects to object (opt-out) to the use of their personal information/personal data for CBS’s marketing purposes when collecting the personal information/personal data and on the occasion of each communication to the data subject for purposes of direct marketing.

Storage and retention of personal information/personal data

CBS will retain personal information/personal data it has processed, in an electronic or hard copy file format, with a third-party service provider appointed for this purpose. Personal information/personal data will only be retained by CBS for as long as necessary to fulfil the purposes for which that personal information/personal data was collected, or as permitted in terms of applicable law.

It is specifically recorded that any data subject has the right to object to the processing of their personal information and CBS will retain and store the data subject’s personal information/personal data for the purposes of dealing with such an objection or enquiry as soon and as swiftly as possible.

Failure to provide personal information

Where CBS is required to collect personal information/personal data from a data subject by law or in order to fulfil a legitimate business purpose of CBS, and the data subject fails to provide such personal information/personal data, CBS may, on notice to the data subject, decline to render services without any liability to the data subject.

Securing personal information/personal data

CBS has implemented appropriate, reasonable, physical, organisational, contractual and technological security measures to secure the integrity and confidentiality of personal information/personal data.

In further compliance with applicable laws, CBS will take steps to notify the relevant regulator/s and any affected data subjects in the event of a security breach and will provide such notification as soon as reasonably possible after becoming aware of any such breach.

Notwithstanding any other provisions of this policy, it should be acknowledged that the transmission of personal information/personal data, whether it be in person, via the internet or any other digital data transferring technology, isn’t completely secure. While CBS has taken all appropriate, reasonable measures to secure the integrity and confidentiality of the personal information/personal data it processes, in order to guard against the loss of, damage to, or unauthorised destruction of, personal information/personal data and unlawful access to (or processing of) personal information/personal data, CBS in no way guarantees that its security system is 100% secure or error-free.

Therefore, CBS doesn’t guarantee the security or accuracy of the information (whether it be personal information/personal data or not) which it collects from any data subject.

Any transmission of personal information/personal data will be solely at the ow risk of the data subject. Once CBS has received the personal information/personal data, it’ll deploy and use strict procedures and security features to try and prevent unauthorised access to it. As indicated above, CBS reiterates that it restricts access to personal information/personal data to third parties who have a legitimate operational reason for having access to such personal information/personal data. CBS also maintains electronic and procedural safeguards that comply with the applicable laws to protect your personal information from any unauthorised access.

By accepting the terms and conditions to which this policy relates, the data subject agrees to indemnify and hold CBS harmless for any security breaches which may potentially expose the personal information/personal data in CBS’s possession to unauthorised access or the unlawful processing of such personal information/personal data by any third party.

Provision of personal information/personal data to third parties

CBS may disclose personal information/personal data to third party service providers where necessary to achieve the purpose/s for which the personal information/ personal data was originally collected and processed.

Transfer of personal information/personal data outside of South Africa

CBS may, under certain circumstances, transfer personal information/personal data to a jurisdiction outside of South Africa in order to achieve the purpose/s for which the personal information/personal data was collected and processed, including for processing and storage by third party service providers.

CBS will obtain the data subject’s consent to transfer the personal information/personal data to such foreign jurisdiction unless consent isn’t required by applicable law. The data subject should also take note that, where the personal information/personal data is transferred to a foreign jurisdiction, the processing of personal information/personal data in the foreign jurisdiction may be subject to the laws of that foreign jurisdiction.

Access to personal information/personal data

A data subject has the right to a copy of the personal information/personal data which is held by CBS (subject to a few limited exemptions as provided for under applicable law. The data subject must make a written request (which can be sent by email to the information officer designated by CBS from time to time.

CBS will provide the data subject with any such personal information/personal data to the extent required by applicable law.

Keeping personal information/personal data accurate

CBS will take reasonable steps to ensure that personal information/personal data that it processes is kept updated where reasonably possible. CBS may not always expressly request the data subject to verify and update their personal information/ personal data and expects that the data subject will notify CBS from time to time in writing:

  • Of any updates or amendments required in respect of their personal information/personal data.
  • Where the data subject requires CBS to delete their personal information/personal data.
  • Where the data subject wishes to restrict the processing of their personal information/personal data.

Complaints to the Information Regulator

In the event that any data subject or third party is of the view or belief that CBS has processed their personal information/personal data in a manner or for a purpose which is contrary to the provisions of this policy, the data subject is required to first attempt to resolve the matter directly with CBS, failing which the data subject or third party will have the right to lodge a complaint with the Information Regulator, under the provisions of POPIA.

The contact details of the Information Regulator are:

Physical address 33 Hood Street, Forum Ill, 3rd Floor Braampark, Johannesburg, 2001
Contact person Marks Thibela
Position Chief executive officer
Work no. +27 10 023 5207
Phone no. 082 746 4173
Email inforeg@justice.gov.za

Contacting us

All comments, questions, concerns or complaints regarding personal information/personal data or this policy, should be forwarded to CBS’s information officer.

The detail of our Information Officer is as follows:
Name: Jonathan Kruger
Telephone number: 010 7300 265 / 082 600 7378
Postal Address: Postnet #48B, Private Bag X4006, Ferndale,2160
Physical Address: Unit 10, Sandton View Office Park
E-Mail Address: accounts@cbsec.co.za