PRIVACY POLICY
A trading division of DAY 1 Motor Retail (PTY) Ltd
Reg: 2016/299735/07 | VAT Number: 4460193461
Cnr Cedar Road, Campbell Rd, Fourways, Sandton, 2191
Email: infor@mgfourways.co.za | Tel: 010 900 5554
General Manager: Lloyd Quinn
Directors: V. Vermaak, G. Vermaak, M. Vermaak
1. Introduction
We at MG Fourways are committed to protecting your privacy and ensuring that your personal information is handled in compliance with the Protection of Personal Information Act, Act No. 4 of 2013 (as amended). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you interact with our website (http://www.mgfourways.co.za/) and services.
2. Definitions
In this Policy, unless the context indicates a contrary intention, the following words and expressions bear the meanings assigned to them and cognate expressions bear corresponding meanings:
- “Act” means the Protection of Personal Information Act, Act No. 4 of 2013 (as amended);
- “Company” means Day 1 Motor Retail (Pty) Ltd t/a MG Fourways, with registration number 2016/299735/07, a private company duly registered and incorporated in the Republic of South Africa;
- “Website User” means the person to whom personal information relates;
- “Directors” means directors of the Company appointed to the Board;
- “Website User/s” means the individual accessing or using the service, or an entity or other legal entity on whose behalf such access is made;
- “Information Officer” means the designated compliance officer appointed by the Company to address compliance with the Act, from time to time;
- “this Policy” means this Protection of Personal Information (“POPI”) policy and any addendum thereto as may be amended by the Company from time to time;
- “Responsible Party” means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information.
3. Purpose of This Policy
This policy describes the Company’s guidelines with regard to:
- The use of personal information gained through the website;
- Access to and disclosure of personal information sent or received by Website User;
- The processing of personal information; and
- How to protect the Company and the Website User from the risks of breach of security and/or unauthorized access to personal information.
4. Applicability
This policy applies to all Website Users and/or contractors of the Company.
5. Information Officer
The Company duly appoints Sean Michael Bermingham as its Information Officer from 1 May 2024.
All Website Users and/or entities may refer any queries, concerns or information of potential or actual breaches of personal information to the Information Officer.
6. Information Officer Responsibilities
- To encourage compliance, by the Company and Website Users alike, with the conditions for the lawful processing of personal information;
- To handle requests made to the Company pursuant to this Act;
- To work with the Regulator (established in terms of the Act) in relation to investigations conducted pursuant to Chapter 6 of the Act in relation to the Company;
- To ensure compliance by the Company with the provisions of POPI, and as may be prescribed.
7. Understanding What Is Meant by “Personal Information”
Personal information refers to a wide array of data belonging to a natural or juristic person, including but not limited to:
- Identity and/or passport number
- Date of birth and age
- Phone number(s) (including cellular phone number)
- Email address(es)
- Physical address
- Postal address
- Age, gender, race and ethnicity
- Photos, voice recordings, video footage (including CCTV), biometric data
- Marital/relationship status and family relations
- Criminal record
- Private correspondence
- Religious or philosophical beliefs including personal and political opinions
- Employment history and salary information
- Financial information
- Education information
- Medical history including blood type
- Membership to organisations/unions
The types of personal information listed above are not a closed list. Information not listed may still be deemed personal information under the Act.
8. Processing of Personal Information
The Company is fully compliant with the Act and has invested resources to ensure that employees and/or contractors understand how to handle a Website User’s personal information.
Employees and/or contractors must follow these guidelines:
- Personal information must only be used for lawful purposes;
- Processing must be adequate, relevant and not excessive;
- Personal information may only be collected with the Website User’s consent;
- Only information necessary for a specific purpose may be collected;
- Personal information must not be retained longer than necessary, except where required by law or contractual agreement;
- Records must be updated when new or revised information is provided.
9. Processing Limitations
No employee and/or contractor may use personal information in a manner deemed insulting, disruptive, offensive, or harmful.
Processing of special personal information is limited in accordance with the Act.
Unless carried out with consent, processing must be:
- Necessary for the establishment, exercise or defence of a right in law;
- Necessary to comply with an obligation of international public law;
- For historical, statistical or research purposes in the public interest;
- Information deliberately made public by the Website User; or
- Carried out with prior authorisation.
10. De-Identifying Personal Information
The Company must ensure that outdated or unnecessary information is discarded in a manner that prevents identification.
Archived records are stored securely and certificates of destruction are obtained where applicable.
Complaints must be reported to the Information Officer immediately.
11. Website User’s Right to Access Personal Information
Website Users may request:
- Access to their personal information
- A description of the information held
- The identity of third parties with access
A formal request form (Annexure B) must be completed.
12. Forbidden Uses of Personal Information
Employees or contractors may not use personal information for personal gain, commercial ventures, religious or personal causes.
Misuse may result in disciplinary action, including dismissal.
13. Company’s Right to Access Information
Employees and contractors should not assume communications are confidential. Back-up copies of email may be maintained for business and legal purposes.
14. Breach of Security / Unauthorised Access
If a security breach occurs, the Company will notify:
- The Information Regulator; and
- Affected Website Users (where identifiable).
Employees must report any known or suspected breaches immediately.
15. Corporate Policy Guideline
15.1 Acceptable Uses of Personal Information
- To provide and maintain the website
- For the performance of a contract
- To contact you regarding updates
- To provide information about similar goods and services
- To manage enquiries
- For data analysis and improving services
- To comply with legal obligations
15.2 Unacceptable Uses
Personal information may not be processed without required consent and compliance with POPIA.
16. Possible Offences
Failure to adhere to this policy may result in disciplinary action and potential liability under the Act.
17. Your Rights Under POPIA
You have the right to:
- Determine whether we hold your personal information
- Request access to it
- Request correction or deletion
- Object to processing
- Object to direct marketing
- Lodge a complaint with the Information Regulator
- Institute civil proceedings
You may access, correct, or delete your personal information by contacting:
Email: infor@mgfourways.co.za
