1. DEFINITIONS
In this Privacy Policy, all capitalised terms will have the meaning as defined in the POPIA, unless otherwise defined below.
- 1.1. “Apostil.co.za” / “we” / “our” / “us” means Evergration CC t/a Apostil.co.za, a close corporation incorporated in terms of the law of the Republic of South Africa, with registration number: 2010/117569/23 ;
- 1.2. “POPIA” means the Protection of Personal Information Act, 4 of 2013, as amended from time to time and includes any regulations promulgated thereunder;
- 1.3. “Privacy Policy” means this privacy policy (as amended from time to time) and including any annexures hereto, published by Apostil.co.za, which is available at its registered place of business, or copy of which can be requested from the Information Officer at officer@apostil.co.za;
- 1.4. “Tax” means any and all taxes (including VAT), duties and other charges imposed or levied by any regulatory authority in connection with the Services; and
- 1.5. “Terms” means the standard terms of service of Apostil.co.za, as published on the Apostil.co.za website from time to time.
2. SUMMARY
- 2.1. We are committed to protecting the privacy of our website users, clients and any other Data Subjects (“you” / “your”) whose Personal Information we Process or which is Processed on our behalf by sub-contractors and third-party agents.
- 2.1. This Privacy Policy is a simple, plain English summary of:-
- 2.1.1. how and why we collect, hold, use, store, disclose, destroy and protect your Personal Information;
- 2.1.2. the nature of our business;
- 2.1.3. our approach to advertising, marketing and security; and
- 2.1.4. the choices available to you regarding our use of your Personal Information and how you can contact us to access, update or correct your Personal Information; object to its Processing; withdraw your consent to its Processing; make a complaint or ask a question;
- 2.1.5. the Processing of Personal Information and Special Personal Information of Data Subjects, whether such Data Subjects are our clients (existing or potential), suppliers, agents, contractors or our employees or job applicants or any other person that engages with us in respect of the business activities we conduct.
- 2.2. We are the Responsible Party in respect of your Personal Information, which means that we determine the purpose of and means for, Processing your Personal Information. The details of the Responsible Party are as follows:
Evergration CC, trading as Apostil.co.za
409 Key West, 3 Kildare Road, Milnerton, Western Cape
Email: officer@apostil.co.za
3. PRECEDENCE
- 3.1. To the extent permitted by law, we may modify or amend the provisions of this Privacy Policy from time to time, in our sole discretion, and any updated versions will be published on the Apostil.co.za website.
- 3.2. This Privacy Policy forms part of the Terms and in the event of any conflict, ambiguity or inconsistency between this Privacy Policy and the Terms, this Privacy Policy shall take precedence, only to the extent of such conflict, ambiguity or inconsistency.
4. WHY DO WE NEED TO COLLECT YOUR PERSONAL INFORMATION
- 4.1. In order to:
- 4.1.1. Provide you with information regarding our business;
- 4.1.2. Engage with you if you are interested in our business;
- 4.1.3. Conduct our business with you and supply services to you;
- 4.1.4. Employ you as an independent contractor, sub-contractor or third-party agent to provide services to our clients on our behalf; or
- 4.1.5. Interact with you in the ordinary course of our business;
- we are required to Process your Personal Information, including but not limited to, for the following purposes (as applicable):-
- 4.1.6. to be able to sell and supply services to you, in accordance with the Terms;
- 4.1.7. to account to you in respect of those services supplied;
- 4.1.8. for the provision of goods and/or services to us, at our instance;
- 4.1.9. to communicate with you in accordance with the Terms;
- 4.1.10. loading and storing your Personal Information on a central database;
- 4.1.11. compliance with our obligations to Process your Personal Information in accordance with any law or legislation, including but not limited to the Value-Added Tax Act, 89 of 1991 and the Income Tax Act, 58 of 1962. Our Processing in terms of this purpose may, where permitted or required, be without your knowledge or consent, if sufficient grounds of justification are present and same will be done in accordance with POPIA and this Privacy Policy;
- 4.1.12. for our financial and Tax related reporting and accounting requirements;
- 4.1.13. in order to assist us to follow our debt recovery processes;
- 4.1.14. in relation to supplier information, to create supplier profiles on our systems, pay suppliers, and for general supplier administration;
- 4.1.15. to maintain and update our client, or potential client databases;
- 4.1.16. to maintain and update our supplier database;
- 4.1.17. to retain information as required by applicable law;
- 4.1.18. to maintain and update our employee/ contractor /consultant database;
- 4.1.19. to detect, prevent or manage actual or alleged fraud, security breaches or the abuse, misuse or unauthorised use of our systems and files and/or contraventions of this Privacy Policy and/or the Terms;
- 4.1.20. to inform you about any changes to our Terms, services, policies or other changes that are relevant to you;
- 4.1.21. to directly market our business and provide you with the latest information about our products and services or events;
- 4.1.22. for security, administrative and legal purposes;
- 4.1.23. to fulfil any contractual obligations that we may have to you or any third party;
- 4.1.24. to conduct recruitment and hiring processes, which includes conducting criminal record and credit checks (where appropriate), the capturing of a job applicant’s details and providing status updates to job applicants;
- 4.1.25. to engage with you, as is applicable, in an employment relationship and to comply with our obligations as an employer;
- 4.1.26. to maintain personal contact details, to comply with applicable legislation;
- 4.1.27. for payroll and remuneration;
- 4.1.28. performance appraisal;
- 4.1.29. occupational health and safety;
- 4.1.30. security and access control;
- 4.1.31. implementation of medical aid schemes, administration of benefits of employees;
- 4.1.32. succession and contingency planning; and
- 4.1.33. for other activities and/or purposes which are lawful, reasonable and adequate, relevant and not excessive in relation to the provision of our services and/or supply of our products, our business activities or such other purpose for which it was collected.
- 4.2. We may process Special Personal Information about you or your child if this is necessary to fulfil our obligations under the Terms, applicable law or on your instruction and in this regard, by engaging us to provide services to you, you consent to such processing of Special Personal Information.
- 4.3. The purposes for which we may Process your Special Personal Information include the following:-
- 4.3.1. our services offered, we may Process Special Personal Information only to the extent strictly necessary;
- 4.3.2. the recruitment and hiring process, we may Process information relating to criminal checks, for example;
- 4.3.3. complying with our obligations in terms of any medical aid schemes or pension or provident funds, of which you are members, through your employment with us.
- 4.4. We will not collect more of your Personal Information than we reasonably need to fulfil the purposes set out above.
- 4.5. You have the right to object to the processing of your Personal Information where it is voluntary to provide your Personal Information. However, should you not provide your Personal Information, as is required, we may be unable to engage with you further or continue to provide services to you. If you are concerned about any aspect of this Privacy Policy as it relates to your Personal Information, please do not continue to engage with us, use our website or use our products and services.
5. HOW DO WE PROCESS YOUR PERSONAL INFORMATION
- 5.1. The type of Personal Information that we may collect is as follows:-
- 5.1.1. your full name and prefix (e.g. Mr, Mrs, Dr) / the registered name of your business;
- 5.1.2. your mobile number and telephone number/s;
- 5.1.3. your email address, so that we can authenticate you electronically and administer your account;
- 5.1.4. your identity / registration number;
- 5.1.5. your date and place of birth;
- 5.1.6. your tax residency;
- 5.1.7. your criminal history;
- 5.1.8. your marital status and details of marriage, if applicable;
- 5.1.9. your citizenship/s;
- 5.1.10. your biometric data;
- 5.1.11. your physical address / registered address, billing address and any delivery addresses;
- 5.1.12. your bank account details and details about payments made to or from you;
- 5.1.13. your VAT registration details and Tax clearance certificates;
- 5.1.14. your internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to use our products and services or engage with us;
- 5.1.15. any other Personal Information required in terms of the services requested; and
- 5.1.16. records that may contain or evidence your Personal Information, as aforementioned.
- 5.2. We receive your Personal Information directly from you and from various third parties including recruitment agencies, suppliers of background checks services and publicly available sources.
- 5.3. We also collect your Personal Information through cookies on our website, online contact forms, CCTV cameras installed at our premises or that of our sub-contractors, third-party service providers or government departments, for safety and security reasons.
- 5.4. We may also process, collect, store and/or use aggregated data, which may include historical or statistical data (“Aggregated Data“) for any purpose, including for know-how and research purposes. Aggregated Data may be derived from your Personal Information but is not always considered Personal Information, as this data does not directly or indirectly reveal your identity. However, if we combine or connect Aggregated Data with your Personal Information in a manner that has the result that it can directly or indirectly identify you, we will treat the combined data as your Personal Information, which will be managed in accordance with this Privacy Policy.
- 5.5. We store your Personal Information on:-
- 5.5.1. At our premises, in the form of hard drive backups;
- 5.5.2. At the premises of third-party service providers such as document storage service providers; and
- 5.5.3. Our servers, of our own or hosted by third party service providers, including cloud storage.
- 5.6. To the extent that Personal Information is Processed by our sub-contractors and third-party service providers, will ensure that we have entered into written agreements with those service providers governing our relationship with them that require them to secure the integrity and confidentiality of your Personal Information in their possession by taking appropriate, reasonable technical and organisational measures.
- 5.7. If the location to which your Personal Information is transferred and/or is stored is outside the Republic of South Africa and does not have substantially similar laws to those of the Republic of South Africa, which provide for the protection of your Personal Information, we will take reasonably practicable steps, including the imposition of appropriate contractual terms to ensure that your Personal Information is adequately protected in that jurisdiction.
6. HOW DO WE DISCLOSE YOUR PERSONAL INFORMATION
- 6.1. Generally, we will only disclose your Personal Information:-
- 6.1.1. to the extent that we are required to do so, in compliance with any legal obligation that we may have in terms of any applicable laws, including any legislation;
- 6.1.2. to our consultants, agents, contractors, suppliers, technical support, government departments issuing required documents and other service providers relating to the operation of our business. To the extent that we have a direct contractual relationship with such third parties, we will ensure that such written contracts contain data protection provisions aligned to the POPIA (or equivalent legislation).;
- 6.1.3. to enable us to enforce or apply our Terms;
- 6.1.4. to protect our rights, property or the safety of our clients, employees, contractors, suppliers, agents and any other third party;
- 6.1.5. detect, prevent or manage actual or alleged fraud, security breaches, technical issues, or the abuse, misuse or unauthorised and/or contraventions of this Privacy Policy. We will not sell your Personal Information. Your Personal Information will not be disclosed to anyone except as provided in this Privacy Policy and/or the Terms.
- 6.2. By using our website and/or engaging us to provide you with services, you consent to the Terms and this Privacy Policy.
7. SECURITY
- 7.1. We are committed to protecting your Personal Information by taking all reasonable technical and organisational measures to secure the integrity and confidentiality of your Personal Information including from misuse, interference, damage or loss, and from unauthorised access, modification, disclosure or destruction, which protection includes access control procedures, network firewalls, anti-virus software, password protection and physical security measures.
- 7.2. Despite the above measures being taken when Processing your Personal Information, as far as the law allows, we will not be liable for any loss, claim and/or damage arising from any unauthorised access, disclosure, misuse, loss, alteration or destruction of your Personal Information and by engaging us to provide services to you, you acknowledge and understand the risks.
8. ACCESS TO YOUR INFORMATION
- 8.1. You are entitled to:-
- 8.1.1. request a copy of the Personal Information that we have on record;
- 8.1.2. notify us of any updates or corrections to such Personal Information so that we may amend our records;
- 8.1.3. request the deletion of such records, which we will delete, subject to applicable laws on data retention, and provided that we may be obliged to cease any service provision to you on deletion of such Personal Information.
- 8.2. You may make exercise the above by contacting our Information Officer with details of your request.
9. HOW LONG WE WILL KEEP YOUR PERSONAL INFORMATION FOR
- 9.1. We will only retain your Personal Information for as long as it is necessary to fulfill the purposes explicitly set out in this Privacy Policy and/or the Terms, unless:-
- 9.1.1. further retention is required under applicable law;
- 9.1.2. we reasonably need it for lawful purposes related to the performance of our functions and activities.
- 9.2. Notwithstanding the above, you agree that we may keep your Personal Information for as long as you continue to engage with us, and/or use our products and/or services, for as long as reasonably necessary in terms of our requirements (including in respect of any debt recovery processes that we institute against you) or until you ask us to delete or destroy it.
- 9.3. During the period of retention, we will continue to abide by this Privacy Policy.
10. DATA BREACH
- 10.1. Where there are reasonable grounds to believe that your Personal Information has been accessed or acquired by any unauthorised person, we shall notify:-
- 10.1.1. the Information Regulator; and
- 10.1.2. you.
- 10.2. The notification will be made within the timeframes set out in the POPIA.
11. COMPLAINTS AND QUERIES
- 11.1. If you would like to contact us, including to ask a question or make a complaint, our Information Officer may be reached at the details below:-
Email: officer@apostil.co.za
Attention: Information Officer (Mr J Green)
Tel: +27 21 825 9940 / +27 11 083 9830
- 11.2. If you are not satisfied after the process in contacting our Information Officer, you have the right to lodge a complaint with the Information Regulator using the contact details below:-
The Information Regulator (South Africa)
Address: JD House, 27 Siemens Street, Braamfontein, Johannesburg, 2001
Email: PAIAComplaints@inforegulator.org.za / POPIAComplaints@inforegulator.org.za
Website: https://justice.gov.za/contact/contact_list.html
- 11.3. You can also find out more about the way we manage your Personal Information that we hold, by contacting us via officer@apostil.co.za.