The right to privacy and this privacy "Policy" is important to us. Sudonum Proprietary Limited ("Sudonum", "us" or "we") is committed to taking steps to protect your privacy when we process your personal information. We therefore implement business practices that comply with applicable data protection laws, including the Protection of Personal Information Act 4 of 2013 ("POPI") and the General Data Protection Regulation ((EU) 2016/679) ("GDPR") (collectively "Applicable Law"). This Policy applies to all processing of personal information.
Where we refer to "Personal Information" in this Policy, we mean personal information as defined in Applicable Law, being information that may be used to directly or indirectly identify you. Personal Information includes, for example, your name, surname, email address, identity number (or company registration number), contact details, photograph and location.
In this Policy, we explain how we will use and protect your Personal Information in compliance with Applicable Law. "You" means any natural or legal person whose Personal Information we process. Depending on whether you are a customer of Sudonum ("Customer") or a client of our Customers ("End User") or not, additional terms may also apply to our relationship. The terms of this Policy will prevail if there is any conflict. We may change the terms of this Policy and will always process Personal Information in accordance with the latest version.
In terms of Applicable Law, Sudonum processes information in two capacities: when we process personal information of our Customers for the purposes of managing our relationship and offering our services, we are the responsible party (POPI) / controller (GDPR); and when we process personal information provided by our Customers for us to perform the services, we are the operator (POPI) / processor (GDPR). When we act as an operator/processor, we act on the instructions of our client, the Customer, who will be the responsible party/controller in respect of the Personal Information that they have instructed us to process to render the services. We also process certain Personal Information as a responsible party when someone visits our website (even if they are not a Customer or End User).
Parts of this Policy will apply to you if you are:
We collect Personal Information about you from the following sources:
We collect various categories of Personal Information depending on our relationship with you, and therefore, we might not collect all of the below categories of information from or about you.
We process adequate and relevant Personal Information for the following purposes and legal bases:
Carry out market research and surveys, business and statistical analysis and necessary audits;
In addition to the above purposes, we may use your Personal Information for other purposes if the law allows for it, if you consent to it, or if it is in the public interest to do so. All purposes for the processing of your Personal Information will be legal in terms of Applicable Law.
We may process your Personal Information to contact you to provide you with information regarding updates about services and new features and products that may be of interest to you. Where we provide services to you (where you are a Customer of ours), we may send information to you regarding our services and other information that may be of interest to you, using the contact details that you have provided to us. We will only send you direct marketing communications where you have consented to us sending you direct marketing or otherwise in compliance with Applicable Laws.
You may unsubscribe from any direct marketing communications at any time by clicking on the unsubscribe link that we include in every direct marketing communication or by contacting us and requesting us to do so. You can also ask us to not send you direct marketing communications when you register with us as a Customer. After you unsubscribe, we will not send you any direct marketing communications, but we will continue to contact you when necessary in connection with providing you with the services or in connection with our business.
If as part of the service, we process Personal Information for the Customer relating to direct marketing for the Customer's purposes, the Customer as the responsible party has the obligation to comply with all direct marketing requirements in terms of Applicable Laws.
We will not sell your personal information or provide it to third parties for their marketing purposes.
We will keep your Personal Information confidential and only share it with others in terms of this Policy, or if you consent to it, or if the law allows or requires from us to share it. We may disclose your Personal Information to:
If we engage third party processors to process your Personal Information, the processors will only be appointed in terms of a written agreement which will require the third party processors to only process Personal Information on our written instructions, use appropriate measures to ensure the confidentiality and security of your Personal Information and comply with any other requirements set out in the agreement and required by Applicable Law.
Due to the nature of the Services and our business operations, we may need to transfer Personal Information to and from different countries for our business purposes.
In accordance with Applicable Law, we may transfer your Personal Information to recipients in other countries. We will only transfer Personal Information to third parties in countries with adequate data protection laws or do so in terms of a written agreement with the recipient which imposes data protection requirements on that party as required by Applicable Law.
Please note that when you transfer any Personal Information directly to a third party in another country (i.e. we do not send your Personal Information to the third party), Sudonum is not responsible for that transfer of Personal Information (and such transfer is not based on or protected by this Policy). Any Personal Information that we receive from a third party country will nevertheless be processed in terms of this Policy.
We have implemented appropriate technical and organisational security measures designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, disclosure, access and other unlawful or unauthorised forms of processing. These measures are in accordance with Applicable Law.
The internet is an open and often vulnerable system and the transfer of information via the internet is not completely secure. Although we will implement all reasonable measures to protect Personal Information, we cannot guarantee the security of your Personal Information transferred to us using the internet. Therefore, you acknowledge and agree that any transfer of Personal Information via the internet is at your own risk and you are responsible for ensuring that any Personal Information that you send is sent securely.
You have certain rights in relation to your Personal Information. As available and except as limited under Applicable Law, you have the following rights in respect of your Personal Information:
Note that where we process Personal Information as an operator/processor for our Customers, these rights will be applied against the Customer. We will fully co-operate with our Customer on any request relating to these rights.
Where you have provided consent for us to process your Personal Information, you may also withdraw your consent where our processing is based on your consent. However, we may continue to process your Personal Information if another legal justification exists for the processing.
When you use our website, we automatically receive and record information on our server logs from your browser. This information may include, amongst others, browser type, language preference, referring site, and the date and time of each visitor request, your location, IP address, cookie information and Google Analytics information. This is statistical data about browsing actions and patterns. We may also obtain information about your general internet usage through a cookie file which is stored on the hard drive of your computer. Cookies enable us to improve our website and services, estimate our audience size and usage patterns, store information about your preferences and recognise when you return to our website.
In some instances, we may collect and store information about your location through cookies (other than when you share your location with us). We convert your IP address into a rough geo-location, and we may use location information to improve and personalise our website and services for you.
You can set your web browser to refuse cookies, but if you do this you may not be able to enjoy the full use of the services and you may not be able to take advantage of certain promotions we may run.
Please note that third parties may also use cookies, but we do not have access to, or control over them, and therefore cannot take responsibility for them.
Our website may include links to other apps or third party websites which do not fall under our supervision. We cannot accept any responsibility for your privacy or the content of these third party sites, but we display these links in order to make it easier for you to find information about specific subjects. Your use of and reliance on these links is at your own risk.
You may, on reasonable grounds, object to us using your Personal Information for certain purposes. If you object, we will stop using your Personal Information, except if Applicable Law allows its use. To exercise this right or to discuss it with us, please contact us at legal@sudonum.com.
We do not intentionally collect or use children's Personal Information. If we do collect Personal Information of children, it will be as a result of the service that we provide to our Customers. Our Customer as the responsible party / controller will have the obligation to obtain consent or ensure that the processing takes place on a justification ground allowed in terms of Applicable Laws.
Similarly, we do not intentionally collect or process special/sensitive Personal Information and will only do so on the instructions of our Customer, with consent or if allowed by Applicable Law.
Quality. Where we are the responsible party / controller, we want to ensure that your Personal Information is accurate and up to date. You may ask us to correct or remove any Personal Information that you think is inaccurate, by sending us an email to legal@sudonum.com.
Access. You have the right to request us to provide you with Personal Information that we hold about you. You must contact us directly to do so or send an email to legal@sudonum.com. This request may be subject to an access to information request in terms of Applicable Laws and may require you to verify your identity, identify the rights you are wishing to exercise and pay a fee. If our Customer is the responsible party/controller for the information, any request will need to be addressed to our Customer.
The right to access your Personal Information may further be limited in terms of Applicable Law.
We take every reasonable step to ensure that your Personal Information is only processed for the minimum period necessary for the purposes set out in this Policy.
We retain Personal Information in accordance with the required retention periods of our Customers, in terms of Applicable Law or for legitimate business purposes. We will only retain your Personal Information for the purposes explicitly set out in this Policy or on the instruction of our Customers. We may keep Personal Information indefinitely in a de-identified format for statistical purposes, which may include for example statistics of how you use the services.
This Policy also applies when we retain your Personal Information. We may also retain your Personal Information for the duration of any period necessary to establish, exercise or defend any legal rights.
We will report any security breach to the applicable regulatory authority in terms of Applicable Law and to the individuals or companies whose Personal information is involved in the breach. If your Personal Information as an End User is affected by a security breach, we will inform our Customer about the breach. If you want to report any concerns about our privacy practices or if you suspect any breach regarding your Personal Information, kindly notify us by sending an email to legal@sudonum.com.
If you want to raise any objection or have any queries about our privacy practices, you can contact our data protection officer at legal@sudonum.com.
You also have the right to formally lodge a complaint in terms of applicable laws as follows:
POPI
The Information Regulator
Website: https://www.justice.gov.za/inforeg/
Address: 33 Hoofd Street, Forum III, 3rd Floor Braampark, P.O Box 31533, Braamfontein, Johannesburg, 2017, South Africa
Tel: +27 10 023 5207
Email: inforeg@justice.gov.za
GDPR
The European Data Protection Supervisor
Online complaint procedure: https://edps.europa.eu/data-protection/our-role-supervisor/complaints_en
In addition to the above purposes, we may use your Personal Information for other purposes if the law allows for it, if you consent to it, or if it is in the public interest to do so. All purposes for the processing of your Personal Information will be legal in terms of Applicable Law.