East Rand Walling (Pty) Ltd – (ERW)
1 INTRODUCTION
- 1.1 In our continued commitment to protect individual and corporate Personal Information, we as East Rand Walling (Pty) Ltd (“ERW/we/us/our”) have compiled this Privacy Statement (“Statement”) to set out our Processing activities and to ensure compliance with the applicable laws and regulations when Processing your Personal Information. We will only Process your Personal Information in accordance with this Statement and the Applicable Legislation.
- 1.2 We recognise that everyone has the right to privacy which includes protection against the unlawful collection, retention, dissemination and use of Personal Information. Consequently, this Statement sets out to achieve the following –
- 1.2.1 establish the principles that govern the lawful processing of Personal Information and promote ethical standards including, but not limited to, protecting confidential information, guarding against security threats and maintaining best practices;
- 1.2.2 provide a description of how we will collect, Process and store your Personal Information as well as your rights in relation thereto;
- 1.2.3 protect the Personal Information rights of ERW, our Employees, customers, and partners and/or affiliates;
- 1.2.4 clarify the practices and procedures that will enable us to monitor and audit compliance with the Statement and set out the consequences of non compliance; and
- 1.2.5 minimise the inherent risks of non compliance, including but not limited to reputational damage and regulatory sanctions.
- 1.3 This Statement is not intended to reproduce laws or regulations but rather set out guidelines for our conduct in any operations which involve the Processing of your Personal Information.
2 APPLICATION OF STATEMENT
This Statement applies to –
- 2.1 East Rand Walling (Pty) Ltd (“ERW”) throughout South Africa;
- 2.2 all of our Employees and/or subcontractors (which includes potential employees and/or subcontractors) where applicable;
- 2.3 all of our customers (which includes potential customers);
- 2.4 all of our suppliers and service providers (which includes potential suppliers and service providers); and
- 2.5 any other natural or juristic person who interacts with us, over the phone, online, via email, mobile applications, social media or otherwise by using any of our websites.
3 ERW AND YOUR PERSONAL INFORMATION
- 3.1 ERW will be responsible for Processing your Personal Information.
- 3.2 Where appropriate and permissible in law, we will share your Personal Information with our head office, East Rand Walling (Pty) Ltd, which is situated in Benoni, South Africa.
- 3.3 We also use a number of sub-contractors, third parties and affiliates to process your Personal Information on our behalf (“Operators”) and where we do so, we will ensure compliance with the law. See paragraph 7 for further detail.
- 3.4 ERW will mainly Process your Personal Information in the following respects –
Customers | ||
What We Process | Why We Process | Legal Basis |
Name and surname; Contact details; Request for Information/Quote Forms; Physical and postal address;Floor/ Ground/ Site plans;Website usage data; and Special Personal Information as set out in paragraph 4. | Identification and verification audits and procedures; Marketing and promotions; Delivery of products and services; Provision of access to our premises; Complaints resolution; and Improving our products and services. | Legitimate Interest; Consent; Contractual Performance; and/or Legal Obligation; Legislative/Regulatory requirements (e.g. FICA). |
Suppliers/Service Providers | ||
What We Process | Why We Process | Legal Basis |
Company details (e.g. registration number and documents, VAT number, Tax clearance certificate BBBEE certificate, physical address, contact details); Quotes and invoices; Banking details; Employee details; Financial statements; List of competitors; List of customers; Business plans; Proposals; and List of directors and their details | Due diligence audits; Payment processes; Communication; Record keeping; Provision of access to our premises; and Review of products/services. | Contractual Performance; Legitimate Interest; and/or Legal Obligation; Legislative/regulatory requirements. |
Employees/Potential Employees | ||
What We Process | Why We Process | Legal Basis |
Name and surname; Date of birth; Contact details; Physical and postal address; Qualifications; Employment history; Banking details; and Special Personal Information as set out in paragraph 4. | Identification/verification, conduct audits and procedures; Contact purposes; Provision of access to our premises; Review of work experience and performance; Employment equity; and Recruitment processes. | Consent; Legitimate Interest; Contractual Performance; Legal Obligation; and/or Legislative/regulatory requirements. |
Authorised Subcontractors | ||
Company details (e.g. registration number and documents, VAT number, Tax clearance certificate BBBEE certificate, physical address, contact details); Quotes and invoices; Banking details; Employee details; Financial statements;Customer/competitor data; Details of directors; | Due diligence audits;Payment of incentives and refunds; Contact Purposes; Provision of access to our premises; and Review and evaluation of Subcontractor’s financial position. | Legitimate Interest; Contractual Performance; Legal Obligation; and/or Legislative/regulatory requirements. |
3.5 ERW Website
- 3.5.1 ERW makes use of cookies on our website (www.erw.co.za) (“Website”) for identification, analysis and advertising purposes. By using the Website, you consent to the storing and accessing of cookies on your device. To find out more about the cookies we use and how to set your preferences, please see our Cookie Policy https://www.erw.co.za/cookies.html
- 3.5.2 In order to provide better content and service, the Website uses Google Analytics. This is not used to collect any information that may be personally identifiable to you. Google Analytics may record mouse actions and scrolling movement, as well as basic interactions with website forms.
- 3.5.3 Google Analytics does not track your browsing habits across other third-party websites. For more information about the data practices of Google Analytics, please visit their privacy policy: https://policies.google.com/privacy?hl=enTo review and adjust important privacy settings, visit: https://policies.google.com/privacy?hl=en#info choices
4 SPECIAL PERSONAL INFORMATION
4.1 Special Personal Information relates to Personal Information concerning –4.1.1 your religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health, sexual orientation or biometric information; or4.1.2 any criminal investigation or ongoing legal proceedings against you.4.2 ERW will only Process Special Personal Information if we have –4.2.1 your Consent;4.2.2 lawful basis;4.2.3 public interest grounds; or4.2.4 where it is publicly available.
5 SECURITY SAFEGUARDS
- 5.1 We limit physical access to our buildings and user access to our systems to only those that we believe are entitled to be there.
- 5.2 We use Google Cloud storage controls for our IS/IT Systems, such as firewalls, user verification, strong data encryption, and separation of roles, systems and data.
- 5.3 We utilise industry “good practice” standards to support the maintenance of a robust information security management system.
- 5.4 We further enforce a “need to know” policy, for access to any data or systems.
6 HOW LONG WILL WE KEEP YOUR PERSONAL INFORMATION FOR?
- 6.1 We will not retain your Personal Information longer than the period for which it was originally needed, unless we are required by law to do so, or you Consent to us retaining such information for a longer period.
- 6.2 We may also retain your Personal Information to the extent and duration that we have a Legitimate Interest to Process your Personal Information depending on, amongst others, the nature and lifespan of the services or products purchased from us.
- 6.3 We will, upon your request, promptly return or destroy any and all of your Personal Information in our possession or control, save for that which we are legally obliged to retain.
7 USE OF OPERATORS TO PROCESS INFORMATION
When Operators are used to Process Personal Information on behalf of ERW, we will enter into agreements that will provide for the protection of your Personal Information in line with the law.
8 SHARING OF INFORMATION
We may share or transfer your Personal Information as follows or as otherwise described in this Statement –
- 8.1 with suppliers, service providers, consultants, subcontractors and other vendors who need access to such information to carry out work on our behalf. Any such parties only have access to such information as is necessary to perform their functions and may not use it for any purpose other than to provide services to us;
- 8.2 any suppliers, service providers, consultants, subcontractors and other vendors will act on our instructions and be contractually bound to take all reasonable steps to secure your Personal Information;
- 8.3 in response to a request for information if we believe disclosure is in accordance with any applicable law, regulation, or legal process, or as otherwise required by any applicable law, rule or regulation; and
- 8.4 in connection with, or during negotiations of, any merger, sale of our assets, financing, or acquisition of all or a portion of our business to another company (we will request a purchaser to treat our data under the privacy statement in place at the time of its collection).
9 CROSS BORDER INFORMATION TRANSFERS
Where ERW transfers Personal Information about you to a company outside of South Africa, we will ensure that –
- 9.1 the company receiving the information is subject to a law, binding corporate rules or binding agreement which provides an adequate level of protection of your Personal Information;
- 9.2 we obtain your Consent if need be; or
- 9.3 there is a contractual necessity/obligation to transfer the Personal Information.
10 YOUR RIGHTS
10.1 As the Data Subject, you have a number of rights under law which, in certain circumstances, you may exercise in relation to the Personal Information we Process about you.
10.2 These rights include –
- 10.2.1 the right to access a copy of the Personal Information that we have about you;
- 10.2.2 the right to correction of inaccurate Personal Information we hold about you;
- 10.2.3 the right to restrict our use of your Personal Information;
- 10.2.4 the right to request that your Personal Information be deleted; and
- 10.2.5 the right to object to our use of your Personal Information.
- 10.3 Further information on these rights can be found at the Information Regulator’s website at https://www.justice.gov.za/inforeg
- 10.4 Please see our Procedure for Data Subject Objection to, Correction or Deletion of Personal Information Processed by NSA https://www.erw.co.za/data-management.html for further details on the steps to be taken by a Data Subject under this paragraph.
- 10.5 Where we rely on Consent as the legal basis on which we Process your Personal Information, you may also withdraw that Consent at any time.
11 WHO TO CONTACT IN CASE OF CONCERNS
11.1 ERW has designated an Information Officer who shall be responsible for –
- 11.1.1 the administration of this Statement and ensuring the lawful Processing of Personal Information by ourselves;
- 11.1.2 dealing with requests made to ERW for access to Personal Information held by us;
- 11.1.3 liaising with local regulators; and
- 11.1.4 providing training to our employees.
- 11.2 Should you wish to raise any questions, concerns, possible violations, and reportable conditions, please contact our Information Officer at – io@erw.co.za
12 KEEPING YOU INFORMED ABOUT OUR PRODUCTS AND SERVICES
- 12.1 We would like to tell you about the great offers, ideas, products and services we have for you from time to time. Where we have your Consent or it is in our Legitimate Interests to do so, we may contact you via email, text message, telephone, online advertising or any other electronic means.
- 12.2 We may also ask you to participate in surveys via our marketing channels which you may opt out of at any time. Please take note that it may take a while for all marketing communications to stop once you have either withdrawn your Consent or opted out. This is because some marketing may have been identified as relevant to your interests and may already be in transit at the time of withdrawal of Consent or opting out.
- 12.3 You may also subscribe to our newsletter to stay updated on our latest products and services. Please note that we also Process Personal Information provided by you in connection with the newsletter registration (e.g. name and surname, email address, etc.) for the purposes of staying in touch with you and making sure you don’t miss any updates.
13 CONSEQUENCES OF NON COMPLIANCEERW
reserves the right to exercise any appropriate form of legal action against any party which may cause us harm and/or damages by way of non compliance with this Statement. Parties also risk statutory penalties.
14 STATEMENT REVISION
This Statement is subject to review and amendment without prior notice. However, ERW undertakes to ensure that any amendments hereto are communicated on our publicly available platforms such as our website, for the benefit of our customers, suppliers, Dealers, service providers and any other persons who may be affected by this Statement.
15 CONTACT US
If you have any questions about this Statement, our treatment of your Personal Information or you wish to exercise any of your rights please address an email to – io@erw.co.za
16 INTERPRETATION
For the purposes of this Statement, the following definitions apply –
- 16.1 “Consent” means an informed, unconditional, specific and voluntary expression of will in terms of which permission is given for the Processing of Personal Information;
- 16.2 “Contractual Performance” – means we must Process your Personal Information in order to be able to provide you with one of our products or services;
- 16.3 “Data Subject” means the natural or juristic person to whom Personal Information relates;
- 16.4 “Subcontractor” means a juristic entity duly appointed by ERW;
- 16.5 “Device(s)” includes printers, facsimile machines, computers, servers, laptops, notebooks, smartphones, tablet computers, memory sticks, any other external storage devices, and for the avoidance of any doubt, also includes personal Devices where those Devices are used for work related purposes and/or contain or have contained any information which belongs to ERW;
- 16.6 “Employee” means any such person as defined in the Labour Relations Act 66 of 1995, under the employ of ERW, and any other such person who may conduct work for or on behalf of ERW on a once off or ongoing basis, as the case may be;
- 16.7 “Information Officer” means the person/s designated by ERW to direct compliance with POPI within ERW;
- 16.8 “Information Regulator” means the body established in terms of section 39 of POPI;
- 16.9 “IS/IT Systems” means collectively and individually –
- 16.9.1 ERW’s IS/IT infrastructures, telecommunications systems and all its components; and
- 16.9.2 Devices as well as the applications running on and services provided via such Devices, including e-mail, voicemail, internet and intranet;
- 16.10 “Legal Obligation” – means we are required by law to Process your Personal Information;
- 16.11 “Legitimate Interests” – means where Processing is necessary for us to conduct our business, but not where our interests are overridden by your interests or rights;
- 16.12 “East Rand Walling (Pty) Ltd” means East Rand Walling (Pty) Ltd as defined in terms of the Companies Act 71 of 2008, as amended, or any other applicable legislation;
- 16.13 “ERW” means East Rand Walling (Pty) Ltd, a company duly incorporated under the laws of South Africa with registration number 2008/026244/07 and registered office at 2 Jones Street, Putfontein, Benoni, South Africa, and all its branches across South Africa;
- 16.14 “Operator” means any person who Processes Personal Information for or on behalf of ERW in terms of a contract or mandate concluded between ERW and such person;
- 16.15 “Personal Information” means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person, and includes the meaning given to it in the POPI;16.16 “POPI” means the Protection of Personal Information Act, 4 of 2013, as amended, and all regulations promulgated thereunder;
- 16.17 “Process/Processing” means any operation or activity or any set of operations, whether or not by automatic means, concerning Personal Information, and includes the meaning given to it in the POPI;
- 16.18 “South Africa” means the Republic of South Africa.