Privacy Policy

1.    Introduction
Welcome to our privacy policy. We respect your privacy and take the protection of personal information very seriously. We are EXSA (Pty) Ltd (Registration number 1996/016607/07) and this is our plan of action when it comes to protecting your privacy. It describes how we collect, disclose, store, use, and protect information that can be associated with you or another specific natural or juristic person and can be used to identify you or that person (personal information).
The purpose of this policy is to describe the way that we handle your personal information.

2. Audience
This policy applies to you if you are:
• a visitor to our website;
• a customer who has ordered or requested the goods or services that we provide; or
• our data subject.
This policy applies to you under certain circumstances.

3.    Personal information

Your personal information includes information we collect:
• automatically when you visit our website;
• via email;
• via WhatsApp communication;
• on registration (see below);
• on submission;
• through an order or purchase and
• optional information that you provide to us voluntarily (see below).
but excludes:
• information that has been made anonymous so that it does not identify a specific person;
• permanently de-identified information that does not relate or cannot be traced back to you specifically;
• non-personal statistical information collected and compiled by us; and
• information that you have provided voluntarily in an open, public environment or forum including any blog, chat room, community, classifieds, or discussion board (because the information has been disclosed in a public forum, it is no longer confidential and does not constitute personal information subject to protection under this policy).
Personal information includes information we collect (i) automatically when you visit our website, (ii) on registration, (iii) on submission, and (iv) from you voluntarily. It excludes (i) anonymous, (ii) de-identified, (iii) non-personal statistical, and (iv) public information.
3.1  Common examples
Common examples of the types of personal information which we may collect and process include your:
• identifying information – such as your name, date of birth, or identification number of any kind;
• contact information – such as your phone number or email address;
• address information – such as your physical or postal address; or
• demographic information – such as your gender or marital status.
3.2  Sensitive personal information
Depending on the goods or services that you require, we may also collect sensitive personal information including your:
• financial information – such as your bank account details;
• sensitive demographic information – such as your race or ethnicity;
• medical information – such as information about your physical or mental health;
• criminal information – such as information about your commission or alleged commission of any offence or about any related legal proceedings;
• employment information – including your membership of a trade union; and
3.3  Your obligations.
You may only send us:
• your own personal information if you are 18 years or older;
• someone else’s personal information if they are older than 18 and you have their permission to do so; or
• a child’s personal information provided you are regarded as a competent person under POPIA.

4.    Acceptance
4.1  Acceptance required
You must accept all the terms of this policy when you order our goods or request our services. If you do not agree with anything in this policy, then you may not order our goods or request our services.
You may not order our goods or request our services if you do not accept this policy.
4.2  Legal capacity
You may not access our website, order our goods or request our services if you are younger than 18 years old or do not have legal capacity to conclude legally binding contracts.
4.3  Deemed acceptance
By accepting this policy, you are deemed to have read, understood, accepted, and agreed to be bound by all of its terms.
4.4  Your obligations
You may only send us:
• your own personal information if you are 18 years or over; or
• someone else’s personal information if they are older than 18 and you have their permission to do so.

5. Changes
We may change the terms of this policy at any time and will notify you of any changes by placing a notice in a prominent place on the website or by email detailing the changes that we have made and indicating the date that they were last updated. If you do not agree with the changes, then you must stop using the website or our goods or our services. If you continue to use the website and our goods or our services following notification of a change to the terms, the changed terms will apply to you and you will be deemed to have accepted those updated terms.

6. Collection
6.1  On registration or submission
Once you register on, or submit information through our website, you will no longer be anonymous to us. You will provide us with certain personal information when you register on our website.
This personal information will include:
• your name and surname;
• your email address;
• your telephone number;
• your company name, company registration number, and VAT number;
• your postal address or street address; and
• your username and password.
We will use this personal information to fulfil your account, provide additional services and information to you as we reasonably think appropriate, and for any other purposes set out in this policy.
We collect certain information on registration on or submission of information through our website.
6.2  Automatically through website
We automatically receive and record Internet usage information on our server logs from your browser, such as your Internet Protocol address (IP address), browsing habits, click patterns, version of software installed, system type, screen resolutions, colour capabilities, plug-ins, language settings, cookie preferences, search engine keywords, JavaScript enablement, the content and pages that you access on the website, and the dates and times that you visit the website, paths taken, and time spent on sites and pages within the website (usage information). Please note that other websites visited before entering our website might place personal information within your URL during a visit to it, and we have no control over such websites. Accordingly, a subsequent website that collects URL information may log some personal information.
We collect certain information from your web browser, including your Internet usage information when you visit our website.
6.3  Web beacons
Our website may contain electronic image requests (called a single-pixel gif or web beacon request) that allow us to count page views and to access cookies. Any electronic image viewed as part of a web page (including an ad banner) can act as a web beacon. Our web beacons do not collect, gather, monitor or share any of your personal information. We merely use them to compile anonymous information about our website.
We collect certain information from web beacons on our website to compile anonymous information about our website.
6.4 Through an order or request
When you order our goods or request our services, we ask you to provide us with certain information.
6.5 Optional details
You may also provide additional information to us on a voluntary basis (optional information). This includes content that you decide to upload or download from our website or when you enter competitions, take advantage of promotions, respond to surveys, obtain certain additional goods or services, or otherwise use the optional features and functionality of our website.
We collect certain optional information, that you provide when you upload or download content from our website or when you enter competitions, take advantage of promotions, respond to surveys or register and subscribe for certain additional goods or services.
6.6  Recording calls
We may monitor and record any telephone calls that you make to us, unless you specifically request us not to.
6.7  Purpose for collection
We may use or process any goods or services information, or optional information that you provide to us for the purposes that you indicated when you agreed to provide it to us. Processing includes gathering your personal information, disclosing it, and combining it with other personal information. We generally collect and process your personal information for various purposes, including:
• goods or services purposes – such as collecting orders or requests for and providing our goods or services;
• business purposes – such as internal audit, accounting, business planning, and joint ventures, disposals of business, or other proposed and actual transactions; and
• legal purposes – such as handling claims, complying with regulations, or pursuing good governance.
• administration and maintenance – such as records relating to our employees, vendors, customers, consumers;
• management planning, forecasting, research and statistical analysis;
• audit and record keeping purposes;
• research purposes in accordance with the Informed Consent Form of the Study Participant, which will relate to the purpose of the Clinical Trial or research study;
We may use your usage information for the purposes described above and to:
• remember your information so that you will not have to re-enter it during your visit or the next time you access the website;
• monitor website usage metrics such as total number of visitors and pages accessed; and
• track your entries, submissions, and status in any promotions or other activities in connection with your usage of the website.
We may use any of your personal information that you provide to us for the purposes that you indicated when you agreed to provide it to us.
6.8  Consent to collection
We will obtain your consent to collect personal information:
• in accordance with applicable law;
• when you provide us with any registration information or optional information.
We will get your consent to collect your personal information in accordance with applicable law when you provide us with it.

7.    Use
7.1  Our obligations
We may use your personal information to fulfil our obligations to you.
7.2  Messages and updates
We may send administrative messages and email updates to you about the website. We may wish to provide you with information about new goods or services in which we think you may be interested. This means that in some cases, we may also send you primarily promotional messages. We will not send you promotional messages unless you have chosen to opt-into them. But, we may send you one message asking you to opt-into promotional messages without you having opted-into promotional messages.
We may use your information to send you administrative messages and email updates to you regarding the website and for marketing purposes where lawful.
7.3  Targeted content
While you are logged into the website, we may display targeted adverts and other relevant information based on your personal information. In a completely automated process, computers process the personal information and match it to adverts or related information. We never share personal information with any advertiser, unless you specifically provide us with your consent to do so. Advertisers receive a record of the total number of impressions and clicks for each advert. They do not receive any personal information. If you click on an advert, we may send a referring URL to the advertiser’s website identifying that a customer is visiting from the website. We do not send personal information to advertisers with the referring URL. Once you are on the advertiser’s website however, the advertiser is able to collect your personal information.
We may use your information for targeted content in certain, specified instances.

8. Disclosure
8.1 Sharing
We may share your personal information with:
• other divisions or companies within the group of companies;
• our goods or services providers under contract who help provide certain goods or services or help with parts of our business operations, including fraud prevention, bill collection, marketing, technology services (our contracts dictate that these goods or services providers only use your information in connection with the goods or services they supply or services they perform for us and not for their own benefit);
• our contractors who help us meet our obligations to you, including those that help us understand your personal information;
• other third parties or regulators as required by applicable law.
We may share your personal information with third parties for the purposes of fulfilling our obligations to you among other purposes.

8.2 Honour this policy
We will require anyone that we share your personal information with to honour this policy whenever possible in terms of applicable law.
8.3  Regulators
We may disclose your personal information as required by law or governmental audit.
8.4  Law enforcement
We may disclose personal information if required:
• by a subpoena or court order;
• to comply with any law;
• to protect the safety of any individual or the general public; and
• to prevent violation of our customer relationship terms.
We may disclose personal information to third parties if required for legal reasons.
8.5  No selling
We will not sell personal information. No personal information will be disclosed to anyone except as provided in this privacy policy.
8.6  Marketing purposes
We may disclose aggregate statistical information that we derive from your and other people’s personal information to our advertisers or business partners.
8.7  Personnel
We may need to disclose personal information to our personnel to do their jobs, but will not do so unnecessarily. These include our responsible management, human resources, accounting, audit, compliance, information technology, or other personnel.
8.8  Change of ownership
If we undergo a change in ownership, or a merger with, acquisition by, or sale of assets to, another entity, we may assign our rights to the personal information we process to a successor, purchaser, or separate entity. We will disclose the transfer on the website. If you are concerned about your personal information migrating to a new owner, you may request us to delete your personal information.

9. Security
We take the security of personal information very seriously and always do our best to comply with applicable data protection laws. Our hosting company will host our website in a secure server environment that uses a firewall and other advanced security measures to prevent interference or access from outside intruders. We authorize access to personal information only for those employees who require it to fulfil their job responsibilities. We implement disaster recover procedures where appropriate.
Our website is hosted on a secure server and uses security measures to prevent interference by intruders.

10. Access
You may ask us to provide you with a description of the personal information that we hold on you, correct or update it or delete it (provided that we do not need it to fulfil our obligations to you or applicable law does not require us to keep it). We will take all reasonable steps to verify your identity before doing so. We may charge a fee to recoup our costs associated with this request if there is a cost to us associated with it and provided that applicable law allows us to do so. Please contact us with your name and any other information needed to identify you correctly if you want access to information or want us to correct, update or delete it.

11. Accurate and up to date
We will try to keep the personal information we collect as accurate, complete and up to date as is necessary for the purposes defined in this policy. From time to time we may request you to update your personal information on the website. You are able to review or update any personal information that we hold on you by accessing your account online, emailing us, or phoning us. Please note that in order to better protect you and safeguard your personal information, we take steps to verify your identity before granting you access to your account or making any corrections to your personal information.
Please keep your personal information accurate and up to date by accessing your account online, emailing us, by phoning us.

12. Retention
We will only retain your personal information for as long as it is necessary to fulfil the purposes explicitly set out in this policy, unless:
• retention of the record is required or authorised by law; or
• you have consented to the retention of the record.
During the period of retention, we will continue to abide by our non-disclosure obligations and will not share or sell your personal information.
We may retain your personal information in physical or electronic records at our discretion.
We will only retain your personal information for as long as is necessary.

13. Transfer to another country
We may transmit or transfer personal information outside of the country in which it was collected to a foreign country and process it in that country. Personal information may be stored on servers located outside the country in which it was collected in a foreign country whose laws protecting personal information may not be as stringent as the laws in the country in which it was collected. You consent to us processing your personal information in a foreign country whose laws regarding processing of personal information may be less stringent.
We may not transfer your personal information outside the country in which it was collected to a foreign country without your permission. OR We may transfer your personal information outside the country in which it was collected to a foreign country.

14. Updating or removing
You may choose to correct or update the personal information you have submitted to us, by clicking the relevant menu in any of the pages on our website or contacting us by phone or email.
You may choose to update or remove the personal information you have submitted to us.

15. Notification of breach
Where we have reasonable grounds to believe that an unauthorised third party has accessed your personal information and if required by law, we will notify the relevant Regulator and you of the breach. If the law requires us to notify you, we will provide you with sufficient information to allow you to take protective measures against the potential consequences of the breach.

16. Limitation
We are not responsible for, give no warranties, nor make any representations in respect of the privacy policies or practices of linked or any third party websites.

17. Enquiries
If you have any questions or concerns arising from this privacy policy or the way in which we handle personal information, please contact us by email at info@exsa.com.