Privacy Notice

1. BACKGROUND

The PBS Company Group understands that your privacy is important to you and that you care about how your personal information is used. We respect and value the privacy of all those that we have dealings with and use personal information in ways that are described here, and in a way that is consistent with our obligations and your rights under the law

2. INFORMATION ABOUT US

The PBS Company Group consist of the following entities:
PETROS BUSINESS SOLUTIONS HOLDINGS (PTY) LTD and
PETROS BUSINESS SOLUTIONS (PTY) LTD owns and operates the S-CUBED SOFTWARE and MYLIFE PLATFORM.
The above entities are duly registered as private companies in terms of the laws of the Republic of South Africa and are collectively referred to as the PBS Company Group, and to which this Privacy Notice applies.

             2.1  Information Officer – S-Cubed

Eugene Volschenk
Email address: popia@scubed.co.za
Telephone number: +27 12 667 4886
Address: 1st Floor, Block B, Trent Bridge Office Park, 183 Leonie Street,
Centurion, Gauteng, 0157

             2.2  Deputy Information Officer – S-Cubed

Fagan Nicholson
Email address: popia@scubed.co.za
Telephone number: +27 12 667 4886
Address: 1st Floor, Block B, Trent Bridge Office Park, 183 Leonie Street,
Centurion, Gauteng, 0157

              2.3  Information Officer – MyLife

Johan Olivier
Email address: popia@mylife.co.za
Telephone number: +27 12 942 5111
Address: 1st Floor, Block B, Trent Bridge Office Park, 183 Leonie Street,
Centurion, Gauteng, 0157

              2.4  Deputy Information Officer – MyLife

Annetjie Krynie
Email address: popia@mylife.co.za
Telephone number: +27 12 942 5111
Address: 1st Floor, Block B, Trent Bridge Office Park, 183 Leonie Street,
Centurion, Gauteng, 0157
3. WHAT DOES THIS NOTICE COVER?

This Privacy Notice explains how we use your personal information: how it is collected, how it is held, and how it is processed. It also explains your rights under the law relating to your personal information.

4. WHAT IS PERSONAL INFORMATION?

Personal information is defined by the Protection of Personal Information Act (“POPIA”), as ‘any information relating to an identifiable living natural or existing juristic person’.

Personal information is, in simpler terms, any information about you that enables you to be identified. Personal information covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.

We process personal information by non-automated means.

The personal information that we use is set out in Part 5, below.

5. WHAT ARE MY RIGHTS?

Under POPIA, you have the right to have your personal information processed according to 8 processing conditions that are summarized as follows:

       5.1  Condition 1

Accountability – we must ensure that the conditions set out in Chapter 3 of the Act and all the associated measures are complied with.

       5.2  Condition 2

Personal information must be collected and processed lawfully in a reasonable manner that does not infringe on your rights.  Personal information may only be processed if it is adequate, relevant, and not excessive.

Personal information may only be processed if you consent thereto, alternatively where it is necessary to do so for the conclusion or performance of a contract, an obligation in terms of law, to protect your legitimate interest/s, or to pursue our legitimate interest/s.
Personal information must as far as possible be collected directly from you.

      5.3  Condition 3

This requires that personal information must be collected for a specific explicitly defined and lawful purpose related to a function or activity of ours. Such personal information may not be retained any longer than necessary for achieving the purposes for which the information was collected and/or subsequently processed.

      5.4  Condition 4

This prohibits the further processing of your personal information unless such processing is compatible with the initial purpose of collecting the information.

      5.5  Condition 5

This requires us to take reasonable, practicable steps to ensure that your personal information is complete, accurate, and not misleading. Such persona information must also be kept up to date, taking into consideration the purpose of the personal information.

The nature and purpose of your personal information will dictate how often such information must be updated.

      5.6  Condition 6

This requires that we must, as far as it is practicable, inform you before your personal information is collected and the purpose of collecting and from where your personal information will be collected.

You are entitled to our details and must be made aware of the consequences of not disclosing personal information to us where it is required for a specific purpose.
You must also be made aware of your personal information is collected and processed as a requirement established in law.
As per Section 72 of the Act, you will be advised if your personal information will be transferred across the borders of South Africa.

     5.7  Condition 7

This requires that we must secure the integrity and confidentiality of your personal information by taking appropriate reasonable, technical, and organizational measures, to prevent the loss thereof or unlawful access thereto.

     5.8  Condition 8 

You have the right to establish whether your personal information is held by us and to have it corrected or destroyed if it is inaccurate, irrelevant, excessive, of date, incomplete, misleading, or have been obtained unlawfully.

    5.9  Other Rights

You further have the following rights, which we will always work to uphold:

5.9.1  The right to be informed about our or collection and use of your personal information. This Privacy Notice should tell you everything you need to know, but you can always contact us to find out more or to ask any questions using the details in Part 14.

5.9.2  The right to access the personal information we hold about you. Part 13 will tell you how to do this.

5.9.3  The right to have your personal information rectified if any of your personal information held by us is inaccurate or incomplete. Please contact us using the details in Part 14 to find out more.

5.9.4  The right to be forgotten, for example, the right to ask us to delete or otherwise dispose of any of your personal information that we hold. Please contact us using the details in Part 14 to find out more.

5.9.5  The right to restrict (i.e. prevent) the processing of your personal information.

5.9.6  The right to object to us using your personal information for a particular purpose  or purposes.

5.9.7  The right to withdraw consent. This means that, if we are relying on your consent as the legal basis for using your personal information, you are free to withdraw that consent at any time.

5.9.8  The right to not have your personal information processed for direct marketing through electronic communication without your consent.

5.9.9  Rights relating to automated decision-making and profiling. We do not user your personal information in this way.

For more information about our use of your personal information or exercising your rights as outlined above, please contact us using the details provided in Part 14.
Your personal information must be kept accurate and up to date. If any of the personal information we hold about you changes, please keep us informed as long as we have that information.
Further information about your rights can also be obtained from the Information Regulator’s Office at https://www.justice.gov.za/inforeg.
If you have any cause for complaint about our use of your personal information, you have the right to lodge a complaint with the Information Regulator’s Office. We would welcome the opportunity to resolve your concerns ourselves, so please contact us first, using the details in Part 14.
6. WHAT PERSONAL INFORMATION DO YOU COLLECT AND HOW?
We may collect and hold some or all of the personal information set out in the table below, using the methods also set out in the table. We do collect ‘special personal information’ where so required by law’ and / or personal information relating to children, younger than 18 years of age, in so far as it relates to the children of our employees and for medical insurance.

 

Special personal information may include information relating to race, ethnic origin, health, biometric information and criminal behaviour of a data subject.

 

The personal information of children may include the name, surname and date of birth or identity number of the child.

 

Information Collected How We Collect the Personal Information
Identity Information including but is not limited to identity numbers, date of birth, drivers licences, passport numbers, work permit details, gender, race, photos, marital status, employment history, disability nature, names, surnames, company / entity names and registration details, vehicle registration numbers, CCTV footage, biometric information such as fingerprint images for access control. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Contact and location information including but not limited to telephone and fax numbers, email addresses, physical addresses, postal addresses, geographical location data. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Business information including but is not limited to ownership, shareholding, job titles, professions, email communication of an implicit or explicit private and confidential nature, affiliations, products, services, statutory registration information. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Payment information including but is not limited to transaction history, bank statements, invoices, credit notes, credit / debit card details, bank account numbers, credit ratings.
As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.

 

Banks and credit rating / consumer data verification agencies.
Profile information including but is not limited to preferences, customer profiles, transaction history, etc. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Data from third parties including the verification of information, consumer profiles, etc. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Financial information including but is not limited to bank account details, salary information, statutory payroll information such as PAYE, UIF, SDL, and garnishee orders. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
Financial product information including but not limited to Group Risk, Retirement Planning, Risk Cover, Short-Term and Long-Term Investments and Insurance. As far as practicably possible directly from the data subject. If not practicable possible to obtain such information directly from you, we will obtain such personal information from third parties or public forums where you may have made your personal information deliberately public.
7. HOW DO YOU USE MY PERSONAL INFORMATION?

Under POPIA, we must always have a lawful basis for using personal information. We may use your personal information for one or all of the following purposes:

  • The administration of our business.
  • Supplying our products and / or services to you.
  • Managing payments for our products and / or services.
  • Personalizing and tailoring our products and / or services for you.
  • Communicating with you.
  • Supplying you with information by electronic communication if you have agreed thereto (you may opt-out at any time by using the details in Part 14.
  • With your permission, we may also use your personal information for marketing purposes, which may include contacting you by email and / or telephone and / or text message with information, news, and offers on our products and / or services. You will not be sent any unlawful marketing or spam. We will always work to fully protect your rights and comply with our obligations under POPIA, and you will always have the opportunity to opt-out.

Automated decision-making takes place when an electronic system uses personal information to decide without human intervention. We currently do not make use of automated decision-making but if we make an automated decision based on any particularly sensitive personal information, we must have either your explicit written consent or it must be justified in the public interest, and we must also put in place appropriate measures to safeguard your rights.

We will only use your personal information for the purpose(s) for which it was originally collected unless we reasonably believe that another purpose is compatible with that or those original purpose(s) and need to use your personal information for that purpose. If we do use your personal information in this way and you wish us to explain how the new purpose is compatible with the original, please contact us using the details in Part 14.

If we need to use your personal information for a purpose that is unrelated to, or incompatible with, the purpose(s) for which it was originally collected, we will inform you and explain the legal basis which allows us to do so or obtain permission from you to do so.

In some circumstances, where permitted or required by law, we may process your personal information without your knowledge or consent. This will only be done within the bounds of POPIA and your legal rights.

You may visit our website and access information while remaining anonymous and without revealing any personal information. When you enter our website, we can determine your domain name and your browser and operating system. We are using cookies (an alphanumeric identifier) only to ascertain technical implementation to ensure our users get the best possible experience for the browser. It enables our website to recognize you as the user when visiting our website again. Cookies may also be used to compile aggregate information about pages of our website that is visited most frequently. This information can be used to enhance the content of our website. We do not monitor the pages looked at by you as the User whilst visiting our website. You can disable the use of cookies by configuring your browser accordingly.

8. HOW LONG WILL YOU KEEP MY PERSONAL INFORMATION?

We will not keep your personal information for any longer than is necessary in light of the reason(s) for which it was first collected. Your personal information will therefore be kept for:

  • as long as it serves the purpose it was collected and intended for,
  • such periods as prescribed in any legislation applicable to our business,
  • any period agreed to in a contract,
  • the purposes of fulfilment of a contract, or
  • any period you may have agreed to.
9. HOW AND WHERE DO YOU STORE OR TRANSFER MY PERSONAL INFORMATION?

We will endeavor to store your personal information in South Africa. This means that it will be fully protected under POPIA.

We may however transfer your personal information across the borders of South Africa for storage, the performance of a contract, an obligation in terms of international law or for internal purposes. These are referred to as “third countries”. We will take additional steps to ensure that your personal information is treated just as safely and securely as it would be within South Africa and under POPIA as follows:

9.1  We will ensure that your personal information is protected under binding corporate rules. Binding corporate rules are a set of common rules which all our group companies are required to follow when processing personal information.

 

OR

9.2   We will only store or transfer personal information in or to countries that are deemed to provide an adequate level of protection for personal information.

OR

9.3  We will use contracts and / or service agreements that ensure the same levels of personal information protection that apply under POPIA

Please refer to our Protection of Personal Information Policy or contact us using the details below in Part 14 for further information about the personal information protection safeguard/s used by us when transferring your personal information to another country.

The security of your personal information is essential to us, and to protect your information, we take several important measures, including the following:

  • Limiting access to your personal information to those employees, agents, contractors, and other third parties with a legitimate need to know and, where applicable, ensuring that they are subject to duties of confidentiality.
  • Procedures for dealing with data breaches (the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, your personal information) including notifying you and the Information Regulator’s Office where we are legally required to do so.
  • We have identified all reasonable and foreseeable internal and external risks and introduced safeguards to mitigate such risks.
  • Continuous maintenance and updating of such safeguards to secure your personal information.
10. DO YOU SHARE MY PERSONAL INFORMATION?

We will not share any of your personal information with any third parties for any purposes, subject to the following exception/s.

  • For the purposes of inter alia fulfilment of an application, contract, rendering of a service or goods.
  • If we sell, transfer, or merge parts of our business or assets, your personal information may be transferred to a third party. Any new owner of our business may continue to use your personal information in the same way(s) that we have used it, as specified in this Privacy Notice.
  • In some limited circumstances, we may be legally required to share certain personal information, which might include yours, if we are involved in legal proceedings or complying with legal obligations, a court order, or the instructions of a government authority.
  • We may share your personal information with other companies in our group to provide our products and services to you. This includes our holding company and its subsidiaries.

If any of your personal information is shared with a third party, as described above, we will take reasonable steps to ensure that your personal information is handled safely, securely, and under your rights

11. OPERATORS

We may make use of third-party service providers to process personal information on our behalf. To protect such personal information, we will enter into a formal written agreement with the service provider. In terms of such agreement, the service provider will be required to process personal information in accordance with conditions as prescribed by us, including measures to protect the security and integrity of such personal information

12. THIRD PARTY LINKS AND PAYGATES

Our website may contain links to other third-party websites. We are not responsible for the privacy practices of third party websites or how they use cookies. You should familiarise your self with and read the privacy statements of other third party websites and web pages.

Any payments made on our website by the User in respect of online services shall be done by using a third party payment portal that is Peripheral Component Interconnect (PCI) compliant. We do not store any of your credit or debit card details. We shall inform the User by means of its payment procedures of the third party service provider by whom payments will be managed and processed. We shall only use registered financial service providers in respect of online payments.

13. HOW CAN I ACCESS MY PERSONAL INFORMATION?

If you want to know what personal information we have about you, you can ask us for details of that personal information and for a copy of it (where any such personal information is held). This is known as a Subject Access Request (“SAR”).

All SARs should be made in writing and sent to the email or postal addresses shown in Part 14. To make this as easy as possible for you, a Subject Access Request Form is available for you to use (SAR Form 1). You do not have to use this form, but it is the easiest way to tell us everything we need to know to respond to your request as quickly as possible.

There may be a fee charged for a Subject Access Request, especially if your request is ‘manifestly unfounded or excessive (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.

We will respond to your data subject access request within one month. Normally, we aim to provide a complete response, including a copy of your personal information within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress

14. HOW DO I CONTACT YOU?

To contact us about anything to do with your personal information and the protection of your personal information, including to make a data subject access request, please use the following details (for the attention of The Information Officer):

14.1  S-Cubed:

Email address: popia@scubed.co.za
Telephone number: +27 12 667 4886
Address: 1st Floor, Block B, Trent Bridge Office Park, 183 Leonie Street,
Centurion, Gauteng, 0157
  14.2  MyLife:
           Email address: popia@mylife.co.za
           Telephone number: +27 12 942 5111
           Address: 1st Floor, Block B, Trent Bridge Office Park, 183 Leonie Street,
           Centurion, Gauteng, 0157
15. CHANGES TO THIS PRIVACY NOTES

We may change this Privacy Notice from time to time. This may be necessary, for example, if the law changes, or if we change our business in a way that affects personal information protection.

Any changes will be made available on our website.