MAHALA MINUTE PRIVACY STATEMENT

This Privacy Statement, together with the Cookie Notice applies to any person or persons accessing the Mahala Minute website, associated platforms (further expanded upon in the Statement) and management systems. By access and transacting on the afore mentioned, you—the user—indicate acceptance and understanding of this Statement.

Mahala Minute (The Company) processes Personal Information (PI)—as defined in the Protection of Personal Information Act (POPIA)—of clients, employees, and various affected stakeholders to conduct its business. The Company utilises various platforms for such information processing, including—but not limited to—channels such as its website, email, mobile sites and applications, social media platforms, data processed/collected via Google, physical forms, and management information systems.

All PI collected by the Company is treated as confidential and various safeguards are in place to protect such data from loss, unauthorised destruction, access, damage, or access by unauthorised third parties . Safeguards include, but are not limited to, Company Processes and Procedures, adherence to data security best practice, firewalls, SSL Certification, data encryption, and regular testing of system robustness.

The Company is aware of, observes, and exercises its duties under legislation, insofar as the governance of collection of data, protection of PI, and privacy is applicable. The protection and privacy of South African Citizen’s PI is a Constitutional right and, as such, the Company is cognisant of its responsibilities in this regard.

Lawful processing of personal information

The Company processes PI in a manner that upholds the conditions for lawful processing of PI, as defined in Chapter 3 Part A of the POPI Act.

Consent and authorisation

By providing us with your PI, you agree to this Statement and authorise the Company to process such information—for the purpose of which it is intended.

You also undertake to only share your personal information over channels and platforms, as well as officials authorised by the Company, to receive your PI in the prescribed manner.

Collection

The Company collects and processes personal information and special personal information as defined in the POPIA from employees, clients, service providers, and other stakeholders. This may include, but is not limited to, a person’s name, identity or passport number, biometric data, personal interests, contact details, personal profile related to business, services or products, and current or historic transactional details.

Business activities for which personal information is processed

Transacting, administering, managing, and developing our business activities, including sales and services; security, quality analysis, and risk management activities.

Reasons for processing personal information

The Company will use your personal information to:

  • Meet its responsibilities to you, and to comply with our legal obligations in such regard.
  • To respond to your queries or complaints.
  • Carry out statistical and other analyses to identify potential markets and trends, evaluate and improve our business, including improving existing and developing new products and services.
  • Tell you about similar services and products available within the Mahala Minute service offering environment. If you wish, you may opt out from receiving such information at any time by choosing to “Unsubscribe” electronically on communication that we send to you, or in writing to info@mahalaminute.co.za

Sharing or transfer of personal information

Authorised Employees of the Company may, from time to time, access your PI in order to deliver the goods and/or services required by you. The Company will not disclose your PI with third parties (other than service providers acting on our behalf) unless we have a lawful basis for doing so.

Third parties

To any court of justice, law enforcement, taxation authorities, regulatory and other government agencies and to professional bodies, as required by and/or in accordance with applicable law or regulation. We may also review and use your personal information to determine whether disclosure is required or permitted.

Storing personal information

The Company will store and keep your personal information according to the retention (holding) periods defined by law for legitimate business purposes and will take reasonably practicable steps to make sure that it is kept up to date and deleted and archived according to our defined retention schedules.

Access to information

You have the right to request a copy of your PI, as held by the Company. Where such a request is made, this must be formalised and submitted in writing via any of the channels provided on this Statement. Such request must be accompanied by proof of identification and/or authorisation, such as a copy of your identity document (in isolation), together with a picture—dated—with you and your identity document. Note that access requests will be open to scrutiny. Such scrutiny may be instituted to uphold the integrity of your data.

Data accuracy

Requests to update, correct, or remove your PI from our records, and the manner in which we may contact you, must be shared via the channels and manner described above.

Cookie notice

The Company may utilise small text files, referred to as ‘cookies’ on your device when browsing the Company website. Cookies do not contain personal data. Cookies convert information to de-identified data. This means that no PI identifiers can be obtained using cookies.

The Company makes use only of functional (required) cookies that enable, and may enhance, the website functionality. These include such cookies required for Google Analytics. Various measures and analysis practices are adopted by the Company and cookies may be used for these purposes, such as measuring the website usage and audience type.

By accepting or dismissing the pop-up cookie notice on the Company website, users consent to, or deny the request of, the Company using the necessary cookies.