The Culture Foundry Co

PRIVACY NOTICE

PRIVACY

NOTICE

(This is an ever-evolving document, please see our website from time to time for the latest version

Culture Foundry (Pty) Ltd, having its registered address at The Culture Foundry Co, C/O Workshop17, 146 Campground Rd, Newlands Cricket Grounds, Gate 24 Entrance, 3rd Floor, Snakepit Building, Newlands, 7700, South Africa (“Culture Foundry”, “we”, “our”).

We are committed to complying with applicable data protection laws and set out below details
regarding our approach to data protection in all our operations.

Information we collect when you complete a research survey and/or enter a competition we run

When you participate in a research survey we run, we generally collect the information in the survey
for the purposes of aggregating the data and providing our customers with insights into particular consumer segments and customer brand engagement.

Sometimes we may collect what is deemed special personal information in a survey, including race, ethnicity, health, sexual orientation, religion and/or political persuasion. We collect this information for the purposes of determining consumer demographics for our customers. We rely on your consent to process this information for this purpose.

When you enter our competitions, we process your personal information for the purposes of contacting you if you have won and for facilitating the provision of your reward.

Information we collect from customers
We collect names, contact details, billing financial and tax information for the purposes of onboarding you as a customer, managing your account, delivering the services, invoicing you and performing the
contract we have with you.

Information we collect from suppliers and professional service providers
We collect names, contact details, financial and tax information from suppliers and professional service providers so that we can place orders/instruct you and make payment in respect of any goods or services we receive. We do this on the basis of the intention of contracting with you or for the performance of a contract we have with you.

Information we collect from you when you apply for a job
We process the information you provide in your curriculum vitae, in our application form and supporting documentation/information during the recruitment process purely for the purposes of assessing your suitability for the role, for contacting you to progress your application and to take up any references you have provided. The basis for the processing of this information is that a potential employment contract may be concluded, depending on the outcome of our assessment and we have a legitimate interest in finding candidates for roles that we have. In the event that you are successful,
this data will form part of your employee file.

Information we collect from you when you visit our website
Our website uses automatic systems of data collection, such as cookies. A cookie is a device transmitted to the hard disk of a user. Cookies do not contain intelligible information but allow linking between you and your personal information, such as your IP address and other information about your experience on the website. The information and data are gathered directly and automatically by the website. We process information collected by cookies in a collective and anonymous way in order to optimize the website for the needs and preferences of the users. Please access the information on your Internet browser if you wish to delete cookies after using the website. If you have started the procedure of deleting cookies, we can’t ensure that all of our web pages will be displayed and that all of our services will be available to you.

We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses cookies to help a website’s operator analyse how users use the site. The non-personal information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers located around the world. Google will use this
information for evaluating your use of the website, compiling reports on website activity for website operators, and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by them. You may refuse the use of cookies by selecting the appropriate settings in your web browser; however, please note that if you do this, you may not be able to use the full functionality of the website. By using the website, you consent to the processing of data about you by Google in the manner and for the purposes set forth above.

Google Analytics collects information anonymously. It reports website usage trends without identifying individual visitors. You can opt out of Google Analytics without affecting how you use the website. For more information on opting out of being tracked by Google Analytics across all websites you use, visit https://support.google.com/analytics/answer/181881. For more information on the Google Privacy Policy, visit https://policies.google.com/privacy.

Processing, protecting and transferring personal information

We may share your information with third parties such as:

● professional advisors e.g. accountants and lawyers;
● IT providers
● our customers
● direct marketing providers
● government bodies/regulators
● research providers
● competition rewards providers
● a prospective buyer buyer or seller in the event that we intend selling or buying any business or assets

Sometimes when we share your personal information with the third parties described in above, it may
be transferred to countries outside of the Republic of South Africa.

We will do our best to ensure that your personal information is stored and transferred in a way which is secure. When we transfer your personal information outside the Republic of South Africa, we do so in compliance with the law and we take appropriate steps to protect that information, which include:

● entering into agreements with third parties;
● transferring to organisations within countries that offer adequate protection for your information.

Retention of your Data

We will not retain your personal information longer than the period for which it is needed and in compliance with applicable law. We determine retention periods in respect of information we hold based on:

● Legal obligations relating to minimum periods to retain data;
● The purposes for which we process the personal information and whether we can achieve those purposes through other means;
● Whether the information is required for reporting and analysis purposes relating to our operations;
● The amount, nature, and sensitivity of the personal information;
● The potential risk of harm from unauthorised use or disclosure of the personal information.

What if you don’t provide us with the information?
Provided you do not supply more information than we request, we generally only collect the mandatory information required for our purposes. Where possible, we will indicate whether information requested is mandatory or voluntary.

In certain circumstances if you do not provide us with the information we require for our onboarding procedures, we may not be able to enter into a contract with you. Furthermore, during our relationship
if you do not provide certain information, we may not be able to meet our obligations under the contract we have with you or engage with you.

General Description of Information Security Measures
We take appropriate technical and organisational steps to ensure the security of your personal information including policies and procedures around use of technology and devices, IT security, document retention and destruction and data breach procedures. Only persons within our organisation which require your personal information for the performance of their work have access to that information and we do not transfer your information outside of the organisation or your resident country unless we are satisfied that the personal information will be afforded an equivalent level of protection.

We employ up to date technology to ensure the confidentiality, integrity and availability of the personal information under our care. Measures include, but are not limited to:

● Firewalls.
● Virus protection software and update protocols.
● Encryption where possible.
● Electronic and physical access control.
● Secure setup of hardware and software making up the IT infrastructure.
● Outsourced service providers who process personal information on behalf of us are contracted to implement security controls.
● Policies and procedures are implemented to ensure the security of your information.

Your rights in relation to your information
Subject to certain limitations on certain rights, you have the following rights in relation to your information:

Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal inform and to check that we are lawfully processing it.
Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it.
You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
Withdraw consent to our use of your information at any time where we rely on your consent to use or process that information. Please note that if you withdraw your consent, this will not affect the lawfulness of our use and processing of your information on the basis of your consent before the point in time when you withdraw your consent.

Should you have any queries regarding this privacy notice or would like to enforce any rights you may
have under applicable data protection laws, please contact us at:

Information Officer
Bradley Shrimpton
[email protected]

We will endeavour to respond to any such requests as soon as is reasonably practicable and in any event within statutory time-limits in the applicable country. In some instances, we may be able to charge a fee for responding to your request and will advise you of this and any applicable amount prior to responding.

You should be aware that certain information is exempt from the right of access. This may include information which identifies other individuals, or information which is subject to legal privilege.

You should also be aware that in some instances, if you do not provide information or you exercise any rights regarding the deletion or restriction of your information or object to the processing of your information or withdraw consent, we may not be able to perform the contract we have with you or comply with our legal obligations.

Where you request access to your information, we are required by law to use all reasonable measures to verify your identity before doing so. These measures are designed to protect your information and to reduce the risk of identity fraud, identity theft or general unauthorised access to your information.

You also have the right to lodge a complaint with the relevant supervisory authority, details of which
are set out below:

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O Box 31533, Braamfontein, Johannesburg, 2017
Complaints email: [email protected]
General enquiries email: [email protected].

Automated decision-making
You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

We do not envisage that any decisions will be taken about you using automated means, however, we will notify you in writing if this position changes.

Changes to our Privacy Notice
Any changes made to this privacy notice in the future will be posted on the website and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to this notice.

January 2023, Version 1

BPC REPORT 4: 1.2.0 Free 01/02/2023 17:33:26 Active Has SSL Checklist Table Built