PROTECTION OF PERSONAL INFORMATION AND PRIVACY POLICY FRAMEWORK
1. What is the purpose of this Framework?
1.1 The purpose of this Protection of Personal Information and Privacy Framework (“Framework”) is to inform data subjects about the types of personal information that Expand Live (Pty) Ltd (“Expand”, “we”, “us”) processes by collecting, receiving, recording, storing, updating, distributing, erasing, destroying, using and disclosing such Personal Information. Data subjects include any private, public, juristic or natural persons — customers, suppliers, contractors, subcontractors, associates, consultants, job applicants, users of our products and services, prospects, partners, website users or clients (“you”, “your”).
1.2 This Framework explains how we process your Personal Information, the choices you have regarding its use and disclosure, and how you may correct the Personal Information we have on record.
1.3 We comply with applicable privacy laws in South Africa, specifically the Protection of Personal Information Act, No. 4 of 2013 (POPIA). We may change this Framework from time to time and will treat Personal Information consistent with the Framework under which it was collected unless you consent otherwise. It applies to any information we collect or receive about you, from any source.
1.4 Expand recognises its obligations to adhere to the highest standards of decency, fairness and integrity in all operations and is dedicated to protecting consumer privacy.
2. To whom does this Framework apply?
This Framework applies to the processing of your Personal Information by Expand and its subsidiaries and affiliates.
3. What is Personal Information?
Personal Information is any information identifiable with you, which may include (not limited to): name, race, gender, pregnancy, marital status, mailing address, phone number, email address, business facsimile number, education, employment history, and financial history (e.g., credit history, credit facilities, shares).
4. How do we collect your Personal Information?
4.1 We collect Personal Information by fair, lawful and reasonable means and only on legitimate grounds, in ways you would reasonably expect and that do not adversely affect you.
4.2 We may collect Personal Information directly from you or from third parties where we have your consent or as permitted by law (e.g., from public records, information you made public, or where your legitimate interests are not prejudiced).
5. When and how do we obtain your consent?
5.1 We obtain your consent before collecting/using/disclosing your Personal Information unless permitted without consent (e.g., to conclude or perform a contract to which you are a party). Consent may be electronic or in writing.
5.2 We will explain the manner and reason for processing before obtaining consent. You may withdraw consent or object at any time via the contact details in paragraph 20; we may have legal/legitimate grounds not to uphold such withdrawal/objection.
5.3 By visiting our website you agree that we may: collect operational information via “cookies” (pages visited, IP, domain, referrer URL, browser/platform) to measure usage and improve content; and use email links you choose to use to contact us (we treat HR submissions as confidential where reasonable). We do not guarantee the security of data submitted via the site. We are an equal opportunity employer.
5.4 We do not knowingly collect personal information from children under 13. Guests aged 13–17 should seek parental consent before providing information. We do not collect email addresses or personally identifiable information without permission.
6. Where do we store your Personal Information?
We store Personal Information on site at 2 Federation Road, Parktown, Johannesburg, and off site. Our service providers (in South Africa and, in some cases, outside South Africa) may also hold your information for agreed purposes. We ensure our processors comply with this Framework.
7. How do we use your Personal Information?
7.1 We identify purposes at the time of collection.
7.2 We collect only for specific, lawful, clear purposes we inform you about and will not process for other purposes without consent.
7.3 Typical purposes include: providing/obtaining services or products; responding to emails; contacting you where you consent to follow-ups/newsletters/push messages/other commercial information; subscriptions; website browsing; events/PR participation; job applications; questions/complaints; other purposes to which you consent or as authorised by law.
7.4 Personal Information processed may include: identity (name, preferred salutation, IDs, date of birth where necessary); contact details (email, phone, mobile); identifiers for account subscriptions (subscriber number, secret code); transactions and payment information (transaction details, bank cheque, bank account information); job application information (CV, motivation, interview notes); technical and browsing information (cookies, web beacons); and any other information you directly and voluntarily provide in using our websites/services/contracts.
8. Do we use your Personal Information for direct marketing?
8.1 Only where you have consented.
8.2 We may market our or our partners’/affiliates’/clients’ products directly to you. If you are an existing user, we may use your information for similar products/services to those previously provided.
8.3 We will give you a reasonable opportunity to object to marketing when we collect your information.
9. What is Special Personal Information and when do we process it?
Special Personal Information includes sensitive data such as race/ethnic origin, trade union membership or criminal behaviour. We process it only if you expressly consent, if required by law or to exercise/defend a legal claim, or for historical/statistical purposes.
10. How long will we utilise or retain your Personal Information?
10.1 We may keep records of your Personal Information/correspondence/comments as long as necessary for the purposes collected and as permitted/required by law.
10.2 We may retain for longer for statistical/historical/research purposes with appropriate safeguards to prevent other use.
10.3 When the purpose no longer applies, we will delete/destroy or de-identify the information.
11. To whom do we provide your Personal Information?
11.1 We identify recipients and purposes at collection and obtain your consent for such disclosures.
11.2 We may disclose to third-party service providers under contracts with appropriate privacy standards (e.g., support, marketing, order completion, contests, storage/backups) and only with your consent.
11.3 We may disclose to a potential acquirer in a transaction involving the sale of Expand’s business or as otherwise permitted/required by law.
11.4 We may send information outside the original jurisdiction for processing/storage. While abroad, it is subject to local laws and may be disclosed to government/courts/law enforcement/regulators under those laws.
11.5 Access may be provided to group companies, authorities, partners and third-party operators acting on our instructions for IT/hosting/storage/analytics/data processing/database/maintenance, under the same security/confidentiality obligations.
11.6 We may also disclose: in a merger or acquisition; in response to legal/administrative proceedings or enforcement by competent authorities; and to comply with legal obligations, protect individuals’ safety/rights, protect Expand’s rights/property, ensure this Framework is respected, and prevent technical/security/fraud issues.
