Privacy - Personal Information and Access to Information

1. Introduction

1. When you use our website this policy should be used as a guideline. We suggest that you have a look at the provisions of the Protection of Personal Information Act 4 of 2013 (“POPI”) and its Regulations to understand your rights to privacy as contained in the Constitution of the Republic of South Africa, 1996.

2. This Policy deals with the processing of Personal Information of Data Subjects (“you / your”) who make use of the website, online purchasing of produts and social media pages of OceanSA (Pty) Ltd (“OceanSA”).  In processing your Personal Information, OceanSA will protect privacy rights and comply with POPI and the relevant Regulations.

3. This Policy further aims to help you understand how we process Personal Information when you use our website, join, access or use our social media pages.

4. We review our policies regularly and may need to change or update them when necessary.  Any updated versions of this Policy will be posted on our Website and will be effective from the date of posting. 

2. Why we have this policy

1. This Policy applies to Personal Information processed by us through our Website, your online purchases and social media pages.

2. The Personal Information processed by us includes information collected directly from you while you are making use of our website or social media pages, or indirectly through our direct marketing campaigns on third party platforms and applications which are operated by or on behalf of us.

3. This Policy does not apply to any third-party websites which may be accessible through links on the our website and/or Social Media Pages. We do not accept any responsibility for the privacy practices of, or content displayed on third party websites. Third party website providers are responsible for informing you of their own privacy policies.

3. Definitions

In this Policy, unless the context requires otherwise, the following words and expressions are defined as follows:-

1. “Biometric” means   a technique of personal identification that is based on physical, physiological or behavioural characterisation including blood typing, fingerprinting, DNA analysis, retinal scanning and voice recognition;

2. “Child” means a natural person under the age of 18 (eighteen) years who is not legally competent without the assistance of a competent person, to take any action or decision in respect of any matter concerning him or herself;

3. “Consent” means any voluntary, specific and informed expression of will in terms of which permission is given for the processing of Personal Information;

4. “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Information under the control of or in the possession of OceanSA;

5. “Data Subject” means you, the person to whom Personal Information relates and in this context, refers to any user of the OceanSA website and social media pages;

6. “Deputy Information Officer” means any person(s) who has been designated by the Information Officer to perform certain delegated duties and responsibilities of the Information Officer;

7. “Direct Marketing” means to approach you either in person or by mail or by electronic communication, for the purpose of promoting or offering to supply, in the ordinary course of business, any goods or services to you;

8. “Employees” means any employee of OceanSA;

9. “GDPR” means the General Data Protection Regulation (EU) 2016/679 which is a regulation on the protection of Personal Information of persons under the European Union;

10. “Information Officer” means the head of a private body being either the Chief Executive Officer, the acting Chief Executive Officer or an equivalent officer or any person duly authorized by that officer. The duly appointed Information Officer is [insert];

11. “Operator” means a person or entity who processes Personal Information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that Responsible Party;

12. “Personal Information” information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to: –

1. Information relating to race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person;

2. Information relating to education or the medical, financial, criminal or employment history of the person;

3. Any identifying number, names, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person;

4. any biometric information;

5. personal opinions, views, or preferences;

6. correspondence that is implicitly or expressly of a personal, private or confidential nature or further correspondence that would reveal the contents of the original correspondence.

13. “Policy” means this Website Privacy Policy;

14. “POPI” means the Protection of Personal Information Act 4 of 2013;

15. “Processing” means any operation or activity or any set of operations, whether by automatic means, concerning Personal Information, including:-

1. the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation, or use;

2. dissemination by means of transmission, distribution or making available in any other form; or

3. merging, linking, blocking, degradation, erasure, or destruction of information;

16. “Process” and “Processed” has the same meaning;

17. “Regulator” means the Information Regulator of South Africa established in terms of section 39 of POPI;

18. “Responsible Party” means a public or private body or any other person which alone, or in conjunction with others, determines the purpose of and means for Processing Personal Information. In the circumstances, OcenaSA is the Responsible Party;

19. “Special Personal Information” means Personal Information referred to in terms of section 26 of POPI, namely Personal Information concerning a Data Subject’s religious or philosophical beliefs, race or ethnic origin, trade union membership, political opinions, health or sex  life, sexual orientation, biometric information, or criminal behaviour.

20. “Third Party” means a representative of OceanSA such as a contractor, agent, consultant, sub-contractor etc;

21. “Website” means the OceanSA website which is accessible at [insert]

4. Lawful processing of personal information

1. We are required, in the normal exercise of our functions and obligations as a business entity, to process your Personal Information from time to time.

2. We, as the Responsible Party, will only Process your Personal Information in accordance with the eight conditions of lawful processing as set out in POPI.

3. You may withdraw consent or may object to our processing of the Personal Information at anytime.

4. In circumstances where the consent is withdrawn or if there is a justified objection against the processing of such Personal Information, we may no longer process the Personal Information.

5. Where you withdraw your consent to the processing of Personal Information or object to the processing of your Personal Information where we require it, you may not be able to access the Website or join, access or use the social media pages or enjoy the full use and benefit of our website.

5. Collecting personal information

1. We will always collect Personal Information in a fair, lawful and reasonable manner which does not adversely affect your rights.

2. As a general rule, we will always collect Personal Information directly from you, unless in circumstances where you have made the Personal Information public, or the Personal Information is contained in or derived from a public record, or in the event that any other exception is applicable in terms of POPI.

3. Where we collect Personal Information from Third Parties, we will ensure that we firstly obtain your consent.

6. Purpose for processing personal information

1. We will only process Personal Information for a specific, explicitly defined and lawful purpose related to the exercise of our functions and obligations as a business entity. We will ensure that such purpose is identified and explained to you.

2. We will process Personal Information for one or more of the following purposes: –

1. carrying out any actions necessary for the conclusion or performance of the contract and when you purchase services, products and accept other offers on or through the Website;

 2. updating our records;

3. processing and responding to any correspondence from you;

4. marketing, subject to paragraph 7 below and POPI;

5. any other purposes to which you may consent from time to time; and

6. for any other lawful purpose.

7. Direct marketing

1. We may only use Personal Information to contact you for purposes of Direct Marketing where it is permissible to do so and in accordance with POPI.

2. We may use your Personal Information to contact you for direct marketing purposes under the following circumstances:-

1. If you are one of our existing clients; or

2. You have requested or consented to receiving marketing material from us.

3. You may object to the use of your Personal Information for our marketing purposes and we must ensure that a reasonable opportunity is given to you to object.

4. If you request that we stop Processing their Personal Information for marketing purposes, we will gladly do so. We encourage you to make use of the opt-out links or forms should you no longer wish to have your Personal Information processed for direct marketing purposes.

8. Internal information flows

1. We may only transfer your Personal Information for some of the purposes listed in POPI and where other relevant legislation permits.

2. We acknowledge that we may not transfer Personal Information to jurisdictions which do not have laws governing the protection of Personal Information or whose laws are not of an equivalent status to POPI.

3. Where your Personal Information is transferred outside of South Africa, we will take all reasonable steps to ensure that any transferred Personal Information is safeguarded and is afforded a similar level of protection as that which it receives in South Africa.

9. Special personal information

1. We will seek to obtain your specific consent to the processing of their Special Personal Information.

2. We acknowledge that we will generally not process Special Personal Information unless it is for one of following reasons:-

1. You have explicitly consented; or

2. the Special Personal Information has made public by the Data Subject; or

3. processing is necessary for reasons of public interest; or

4. processing is necessary for the establishment, exercise or defence of a right or legal claim or obligation in law;

5. processing is for historical, statistical or research purposes, subject to stipulated safeguards; or

6. For any other lawful reason.

10. Safegaurding of your personal information

1. We treat any and all Personal Information processed by us as confidential and shall make every effort to ensure the security and integrity of such Personal Information is not compromised.

2. We will ensure that reasonable, technical and organisational measures are put in place in order to mitigate or prevent loss, unlawful and unauthorised access and destruction of Personal Information.

3. We will ensure that it maintains and regularly verifies that the security measures are effective and regularly update same in response to new risks.

11. Keeping of personal information

1. We will not retain Personal Information for a period longer than is necessary to achieve the purpose for which it was collected or processed. The exception to this rule shall apply is as follows:

1. where the retention of the record is required or authorised by law;

2. you have consented to retaining the Personal Information for a longer period;

3. We retain the record in order to fulfil our lawful functions or activities;

4. the retention of the record for extended periods is required by a contract between you and the Responsible Party;

5. the record is retained for historical, research or statistical purposes on condition that the necessary measures and  safeguards are implemented so as to prevent the use of the information for any other purpose.

2. Once the purpose for which the Personal Information was initially collected and processed no longer applies, We will ensure that the Personal Information is deleted, destroyed or de-identified sufficiently so that it cannot be reconstructed to identify you.

12. Storage and processing of personal information by us and third-party service providers

1. Personal Information may be stored by us or Third Parties, by way of hard copy devices or formats, electronic platforms, cloud services or other technology.

2. Third Parties may only have access to your Personal Information in circumstances where they have contracted with us and serve to support our business operations.

3. We will ensure that such Third-Party service providers will process the Personal Information in accordance with the provisions of this Policy, read with POPI, and where applicable, the GDPR.

13. Breaches of personal information

1. Data Breaches refer to incidents or allegations of unlawful or unauthorised processing of Personal Information, which would also include the loss of, destruction of, access to Personal Information by any unauthorised person.

2. We will address any Data Breach in accordance with the terms of POPI, its Breach Policy and GDPR (where applicable).

3. We will notify the Regulator and you in writing in the event of a Data Breach, or a reasonable belief of a Data Breach. In circumstances where there is a breach, you will be informed by our Information Officer or Deputy Information Officer.

4. We will notify the Regulator as soon as reasonably possible and, where practicable, no later than 72 (seventy-two) hours after becoming aware of such Data Breach.

5. In circumstances where we act as an Operator, we will notify the Responsible Party of any Data Breaches. 

14. Information quality

1. We will take reasonably practicable steps to ensure that all Personal Information is complete, accurate, not misleading, and updated where necessary, having regard to the purpose for which the Personal Information has been collected.

2. It is important to note that we require you to notify it in writing of any updates of your Personal Information.

15. Data Subject Participation

1. You may, after providing adequate proof of your identity, request access to relevant Personal Information in our possession which must be provided to you. 

2. You may request that your Personal Information be corrected or deleted or that a record containing your Personal Information be destroyed or deleted if you believe that the Personal Information or record of the Personal Information is inaccurate, irrelevant, excessive, incomplete, outdated or obtained unlawfully.

3. We must, when in receipt of a request to correct, update or delete Personal Information, do so in compliance with POPI. 

4. We will try to provide you with suitable means of accessing information, where you are entitled to it, by for example, posting or emailing it to you.

5. We may refuse you access to your Personal Information if your access would interfere with the privacy of others or would result in a breach of confidentiality. If we refuse access, we will give written reasons for our refusal.

6. We may charge a reasonable fee to cover its administrative and other reasonable costs in providing the information to you. The prescribed fees to be paid for copies of your Personal Information are listed in the PAIA Manual.

16. Time Periods

We will endeavour to respond to each written request to update, delete or correct your personal information within 30 (thirty) days of such requests being made. Where necessary, we may extend the 30 (thirty) day period for a further period. 

17. Use of website cookies

1. Our website uses cookies, which are small text files are often used by websites or other platforms to recognise your repeat visits and are also used to ensure that the website functions properly.

2. We makes use of “cookies” to automatically collect information and data about you.

3. You may elect to block cookies. However, this may result in you being unable to fully access and enjoy parts of our website.

4. As the website and social media pages are accessible via the internet, and the internet is inherently insecure, we cannot provide any assurance regarding the security of the transmission of information that you communicate to us online. 

5. We also cannot guarantee that the information that you supply will not be intercepted while being transmitted.  Accordingly, any of your Personal Information or other information which you transmit to us online is transmitted at your own risk. We will however ensure that the Personal Information in our possession is protected. 

18. OceanSA contact details

OceanSA (PTY) LRD

Email: support@oceansa.co.za

Physical and postal address:
Shop G04 Clocktower
V and A Waterfront,
Cape Town,
Western Cape 8002

Scroll to Top