Customer Privacy Notice
The purpose of this Privacy Policy is to set out how, why
and when MAL Group, its subsidiaries and business units use your Personal
Information so as to comply with the Protection of Personal Information Act 4
of 2013 (“POPIA”).
About M.A.L. Group
1. Purpose of This Policy
This Privacy Policy explains how we collect, use, store, and
protect your personal information, as well as your rights under the Protection
of Personal Information Act (POPIA). It also outlines how you can access,
update, or request the removal of your information.
By using our website or providing personal information, you
agree to the terms of this Privacy Policy.
2. Information We Collect
We collect and process personal information to understand
your needs, provide quotations, deliver goods and services, and maintain
ongoing communication. The types of information we may collect include:
- Name,
company name, and contact details
- Delivery
and billing addresses
- Order
and payment history
- Correspondence
with our team
- Website
analytics and browsing data (via cookies)
- CCTV
footage when visiting our premises
Where possible, we collect information directly from you and
will indicate which fields are required and which are optional.
3. Lawful Basis for Processing
We process personal information on one or more of the
following lawful bases:
- Consent: where you have given us explicit permission to process your data.
- Contractual
necessity: where processing is required to perform or enter into a
contract with you.
- Legal
obligation: to comply with legal or regulatory requirements.
- Legitimate
interest: for business operations such as improving services, fraud
prevention, or network security.
4. How We Use Your Information
Your information is used solely for lawful and agreed
purposes, including:
- Creating
and maintaining customer or supplier accounts
- Providing
quotations, invoices, and processing payments
- Delivering
goods and managing returns or refunds
- Performing
identity verification or credit checks (if applicable)
- Purchasing
goods and services from suppliers
- Complying
with statutory or regulatory obligations
- Conducting
research, analysis, or customer satisfaction surveys
- Detecting
and preventing fraud or unauthorised access
- Providing
product information, updates, and support
- Maintaining
internal records and audits
We do not knowingly collect personal information from minors
without parental or guardian consent.
5. Storage and Retention of Information
Your personal information is stored securely in:
- Locked
physical storage where applicable
- Encrypted
electronic databases and servers
- Trusted
third-party banking and payment platforms
6. Sharing and Disclosure
Your information may be shared with:
- Trusted
third-party service providers involved in fulfilling orders, deliveries,
or payments
- Credit
Guarantee Insurance Corporation of Africa Limited (CGIC) for credit
insurance purposes (if applicable)
- Legal
or regulatory authorities when required by law
All third parties are contractually bound to maintain strict
data protection standards in line with POPIA.
We also use Google Analytics to monitor website
traffic. You can opt out by installing the Google Analytics Opt-Out Browser
Add-On.
7. Cross-Border Data Transfers
As part of our business operations, some data may be
processed or stored outside South Africa (for example, in cloud-based systems).
In such cases, we ensure that adequate safeguards are in place and that all
international data transfers comply with POPIA and relevant international
standards such as the EU’s General Data Protection Regulation (GDPR).
8. Information Security
We take reasonable technical and organisational measures to
protect personal data against unauthorised access, loss, or misuse. These
include:
- Physical
security measures at all premises
- Access
controls and user authentication
- Data
encryption and firewalls
- Secure
data disposal and backup protocols
- Ongoing
staff training and compliance monitoring
All third parties who process data on our behalf are
required to meet the same security standards.
9. Marketing Communication
We may send you information about our products, promotions,
or updates where you have provided consent or where a legitimate interest
exists.
You may withdraw your consent or opt out of marketing
communications at any time by following the unsubscribe link in our emails or
contacting us directly.
10. Cookies and Tracking Technologies
Our website uses cookies to enhance user experience and
monitor site performance. Cookies are small text files stored on your browser
that help us understand site usage and improve functionality.
Cookies do not collect personally identifiable data or run
programs on your device. You may disable cookies in your browser settings, but
some website functions may not work correctly if you do.
11. Automated Decision-Making
We currently do not use automated decision-making or
profiling processes that produce legal or significant effects on individuals.
If this changes in future, we will update this policy accordingly.
12. Your Rights Under POPIA
You have the right to:
- Request
access to the personal information we hold about you
- Ask
for corrections or updates to inaccurate data
- Request
deletion or restriction of processing where applicable
- Object
to the processing of your information
- Withdraw
consent at any time
- Lodge
a complaint with the Information Regulator if you believe your information
has been mishandled
To exercise these rights, please contact our Information
Officer. Proof of identity may be required to process your request.
13. Third-Party Links
Our website may contain links to other sites. Please note
that we are not responsible for the privacy practices or content of external
websites. We encourage users to review the privacy policies of any third-party
sites they visit.
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect
changes in legislation or business operations. The most recent version will
always be available on our website. Continued use of our website signifies
your acceptance of any changes.
15. Contact Information
Responsible Party: M.A.L. Group
Information Officer: Lindsay Lazarus
Email: lindsay@malinvestments.co.za
16. Information Regulator of South Africa
If you are not satisfied with how we have handled your
personal information, you may contact the Information Regulator:
Telephone: 012 406 4818
Email: inforeg@justice.gov.za