- Introduction
- Misfitz (Pty) Ltd (“Misfitz, we, us, our”) is sensitive to the personal nature of the information you provide to us.
- This Privacy Policy (“this Policy”) explains how we protect and use your personal information.
- By providing us with your personal information, you –
- Agree to this policy and authorise us to process such information as set out herein; and
- Authorise Misfitz, its Associates, our Service Providers and other third parties to process your Personal Information for the purposes stated in this Policy.
- We will not use your Personal Information for any other purpose than that set out in this Policy and will endeavour to protect your Personal Information that is in our possession from unauthorised alteration, loss, disclosure or access.
- Please note that we may review and update this Policy from time to time. The ltest version of this Policy is available upon request.
- The Policy applies to all external parties with whom we interact, including but not limited to individual clients, representatives of client organisations, users of our website and other users of our professional services (“you”).
- COLLECTION OF PERSONAL INFORMATION
- We may collect or obtain Personal Information about you –
- Directly from you;
- In the course of our relationship with you or your organisation;
- When you make your Personal Information public;
- When you visit and/or interact with our Website or our various social media platforms;
- When you register to make use of any of our packages or professional services including, but not limited to, newsletters and legal updates.
- We may also receive Personal Information about you from third parties.
- In addition to the above, we may create Personal Information about you such as records of your communication and interactions with us, including, but not limited to, mailings and interactions with you during the course of our digital marketing campaigns.
- We may collect or obtain Personal Information about you –
- CATAGORIES OF PERSONAL INFORMATION WE MAY PROCESS
We may, in the ordinary course of business, process the following categories of Personal Information about you –
- personal details: full name;
- demographic ingormation: gender, date of birth / age; nationality; salutation; title; and language preferences:
- identifier information: passport and national identification number; bank details:
- contact details: correspondence address; telephone number; email address; and details of your public social media profile(s);
- instruction details; details of individuals instructing our Company; Personal Information included in correspondence, documents or other materials that we process in the course of providing packages or professional services;
- consent records; records of any consents you may have given, together with the date and time, means of consent and any related information;
- payment details: billing address; payment method; bank account number or card number; invoice records; payment records; payment amount and date;
- data relating to your visit to our Website: your device type; operating system; browser type; browser settings; date and time of connecting to a website; and other technical communications information;
- Employer details: where you interact with us in your capacity as an employee of an organisation, the name, address, telephone number and email address of your employer, to the extent relevant; and
- Content and advertising data: records of your interactions with our online advertising and content, records oof advertising and content displayed on pages displayed to you, and any interaction that you may have had with such content or advertising (including, but not limited to, mouse hover, mouse clicks and any forms you complete)
- SENSETIVE PERSONAL INFORMATION AND PERSONAL INFORMATION OF CHILDREN
- Where we need to process your Sensitive Personal Information, we will do so in the ordinary course of our business, for a legitimate purpose, and in accordance with applicable law.
- We will not collect any personal information of children in the ordinary course of our work. The Company does not permit anyone under 18 years of age to use our services. By using our services and/or purchasing our products, you confirm that you are over the age of 18.
- PURPOSES OF PROCESSING AND LEGAL BASIS FOR PROCESSING
- We will process your Personal Information in the ordinary course of the business providing our services. We will primarily use your Personal Information only for the purpose for which it was originally or primarily collected. We will use your Personal Information for a secondary purpose only if such purpose constitutes a legitimate interest and is closely related to the original or primary purpose for which Personal Information was collected. We may subject your Personal Information to processing during the course of various activities, including, without limitations, the following –
- Operating our business;
- Analysis, evaluation, review and collation of information in order to fulfil contracted obligations to our clients and client contracts, and provide professional advice, packages, services and recommendations (whether in electronic or any other medium whatsoever);
- Compliance with applicable law and fraud prevention;
- Attending to the legitimate interest of Data Subjects;
- Tracking Data Subject activity on the Company websites, various social media platforms and through direct transactions with the business;
- Transfer of information to our Service Providers and other third parties or
- Recruitment.
- We may process your Personal Information for relationship management and marketing purposes in relation to our services (including, but not limited to, processing that is necessary for the development and improvement of our services), for accounts management, and for marketing activities in order to establish, maintain and/or improve our relationship with you and with our Service Providers. We may also analyse your Personal Information for statistical purposes.
- We may process your Personal Information for internal management and management reporting purposes, including, but not limited to conducting internal audits/ investigations, implementing internal business controls, providing central processing facilities, for insurance purposes and for management reporting analysis.
- We may process your Personal Information for safety and security purposes.
- We will process your Personal Information in the ordinary course of the business providing our services. We will primarily use your Personal Information only for the purpose for which it was originally or primarily collected. We will use your Personal Information for a secondary purpose only if such purpose constitutes a legitimate interest and is closely related to the original or primary purpose for which Personal Information was collected. We may subject your Personal Information to processing during the course of various activities, including, without limitations, the following –
- DISCLOSURE OF PERSONAL INFORMATION TO THIRD PARTIES
- We may disclose your Personal Information to our Associates and Service Providers, for legitimate business purposes, in accordance with the applicable law and subject to applicable professional and regulatory requirements regarding confidentiality. In addition, we may disclose your Personal Information –
- If required by law;
- To legal and regulatory authorities, upon request, or for the purpose of reporting any actual or suspected breach of applicable law or regulation.
- To third party Operators (including, but not limited to, data processors such as providers of data hosting services), located anywhere in the world, subject to 6.2;
- Where it is necessary for the purpose of, or in connection with, actual or threatened legal proceedings or establishment, exercise or defence of legal rights;
- to any relevant party for the purpose of the prevention, investigation, detection or prosecution of criminal offenses or the execution of criminal penalties, including, but not limited to, safe guarding against and the prevention of threats to, public scrutiny.
- To any relevant party acquirer(s), in the event that we sell or transfer all or any portion of our business or assets (including, but not limited to, in the event of a reorganisation, dissolution or liquidation); and
- To any relevant third party provider, where our website uses third party advertising, plugins or content.
- If we engage a third party Operator to process any of your Personal Information, we recognise that any Operator who is in a foreign country must be subject to a law, binding corporate rules or binding agreements which provide an adequate level of protection similar to POPIA. We will review our relationship with Operators we engage and, to the extent required by any applicable law if force, we will require such operators to be bound by contractual obligations to –
- Only process such Personal Information in accordance with or prior written instructions; and
- Use appropriate measures to protect the confidentiality and security of such Personal Information.
- We may disclose your Personal Information to our Associates and Service Providers, for legitimate business purposes, in accordance with the applicable law and subject to applicable professional and regulatory requirements regarding confidentiality. In addition, we may disclose your Personal Information –
- INTERNATIONAL TRANSFER OF PERSONAL INFORMATION
- We may transfer your Personal Information to recipients outside of the Republic of South Africa.
- Subject to 6.2, Personal Information may be transferred outside of the Republic of South Africa provided that the country to which the data is transferred has adopted a law that provides for an adequate level of protection substantially similar to the POPI Act, the Operator/third party undertakes to protect the Personal Information in line with applicable data protection legislation and the transfer is necessary in order to provide the legal and other related services that are required by Misfitz clients.
- DATA SECURITY
- We implement responsible and appropriate technical and organisational security measures to protect your Personal Information that is in our possession, against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, in accordance with applicable law.
- Where there are reasonable grounds to believe that your Personal Information that is in our possession has been accessed or acquired by an unauthorised person, we will notify the relevant regulator and you, unless a public body responsible for detection, prevention or investigation of offences or the relevant regulator informs us that notifying you will impede a criminal investigation.
- Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement all reasonable measures to protect your Personal Information that is in our possession, we cannot guarantee the security of any information transmitted using the internet and we can not be held liable for any loss of privacy occurring during the course of such transaction.
- DATA ACCURACY
- The Personal Information provided to our business should be accurate, complete and up-to-date. Should Personal Information change, the onus is on the provider of such data to notify Misfitz of the change and provide us with accurate data. We will endeavour to monitor and keep Personal Information relevant and up-to-date. Wherever possible, to the best of our knowledge.
- DATA MINIMISATION
- Simple POPI will restrict its’ processing of Personal Information to data which is sufficient for the fulfilment of the primary purpose and applicable legitimate purpose for which it was collected.
- DATA RETENTION
- Simple POPI shall only retain and store Personal Information for the period which the data is required to serve its primary purpose or a legitimate interest or for the period required to comply with an applicable legal requirement, whichever is longer.
- YOUR LEGAL RIGHTS (ACCESS TO YOUR PERSONAL INFORMATION)
- Data subjects have rights under the South African POPI Act, and other laws, to have access to your Personal Information and to ask us to rectify, erase and restrict use of, any of it. You may also have rights to object to your Personal Information being used, to ask for the transfer of Personal Information you have made available to us and to withdraw consent to the use of your Personal Information.
- If you would like to access, amend, erase or restrict use of your Personal Information, please contact admin@misfitz.co.za
- COOKIES AND SIMILAR TECHNOLOGIES
- We may process your Personal Information by our use of Cookies and similar technologies but only for the necessary function of our Website. When you visit our Website we may place Cookies onto your device or read Cookies already on your device, subject always to obtaining your consent where required, in accordance to applicable law.
- DIRECT MARKETING
- We may process your Personal Information for the purpose of providing you with information regarding services that may be of interest to you. You may unsubscribe for free at any time.