d
Skip to main content

Privacy Policy

Last updated 13 October 2022

This privacy notice explains how we obtain, use, collect and disclose your personal information, in accordance with the requirements of the Protection of Personal Information Act ("POPIA").

At Notto SA (Pty) Ltd (and including this website) we are committed to protecting your privacy and to ensure that your personal information is collected and used properly, lawfully and transparently.

1. About the Company

Notto SA (Pty) Ltd, conducting business as an authorised credit bureau.

2. The information we collect

We collect and process your personal information mainly to conduct our business as a credit bureau and delivering services to you. Your personal information will be collected and processed by us when you create an account with us to access the services on our website.

We also collect and process information directly from you where you provide us with your personal details. Where possible, we will inform you what information you are required to provide to us and what information is optional for us to provide the services. We also collect any information form public databases, social media platforms and other outside sources.

Your website usage information may be collected using "cookies" which allows us to collect standard internet visitor usage information.

If you elect to register and log into our website and use our services, using your third-party social media account details (i.e. Facebook, Instagram, WhatsApp, Twitter, Gmail) we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, friends list, profile picture as well as other information you choose to make public on such social media platform.

We will use the information we receive only for the purposes that are described in this privacy notice or that are otherwise made clear to you on the relevant website.

3. How we use your information

We will use and process your personal information only for purposes for which it was collected and agreed with you. In addition, where necessary your information may be retained for legal, regulatory compliance or research purposes. For example, we collect your personal information:

  • To comply with all applicable laws and legislations such as but not limited to POPIA, the Financial Intelligence Centre Act 38 of 2001and the National Credit Act 34 of 2005;
  • To facilitate account creation, logon process and verify your identity or to verify that you are an authorised user for security purposes;
  • To give effect to and fulfil the contractual relationship between us and for us to provide the services to you;
  • For the detection and prevention of fraud, crime, money laundering or other malpractice;
  • To protect the legitimate interest of the parties and / or third parties;
  • To conduct market or customer satisfaction research or for statistical analysis;
  • For audit and record keeping purposes;
  • In connection with legal proceedings;
  • Subject to clause 10 and in compliance with the relevant provisions of POPIA, for marketing and promotional purposes and delivery of targeted advertisement to you; and
  • For any other legitimate business operations.

Subject to the exceptions below, we will only keep your personal information for as long as it is necessary for the Company to provide services to you or for the purposes set out in this privacy notice.

The exceptions to the above principle specifically provided in POPIA are where –

  • the retention of the record is required or authorised by law;
  • we reasonably require the record for lawful purposes related to its functions or activities;
  • the retention of the record is required in terms of an agreement between the parties; or
  • the record is retained for historical purposes, with us having established appropriate safeguards against the record being used for any other purpose.

When we are no longer authorised to retain your Personal Information, it shall destroy or delete such Personal Information or records of Personal Information or de-identify them in a manner that prevents their reconstruction in an intelligible form.

4. Disclosure of information

We may disclose your personal information to our service providers (which shall include our vendors, consultants, advisors, agents etc.) who are involved in the delivery of services to you. We have agreements in place with each service provider to ensure that they comply with the our terms and conditions, this privacy notice as well as the privacy requirements as required by the POPIA. We may also share and disclose your information:

  • With our affiliates, in which case we will require those affiliates to adhere to this privacy notice. Affiliate includes our parent company and any subsidiary, joint venture partners or other companies that we control or that are under the common control with us; or
  • with our business partners; or
  • With regards to or in connection with or during negotiations of, merger, sale of company assets, financing or acquisition of all or a portion of our business to another company; or
  • Where we have a duty or a right to disclose in terms of law or industry code of conduct; or
  • Where we believe it is necessary to protect our rights; or
  • Where you have provided us with your consent.

5. Information Security

We are legally obliged to provide adequate protection for the personal information we hold and to stop unauthorized access and use of personal information. We will, on an on-going basis, continue to review our security controls and related processes to ensure that your personal information remains secure.

Our security policies and procedures cover:

  • Physical security;
  • Computer and network security;
  • Access to personal information;
  • Secure communications;
  • Security in contracting out activities or functions;
  • Retention and disposal of information;
  • Acceptable usage of personal information;
  • Governance and regulatory issues;
  • Monitoring access and usage of private information;
  • Investigating and reacting to security incidents.

When we contract with third parties, we impose appropriate security, privacy and confidentiality obligations on them to ensure that personal information that we remain responsible for, is kept secure.

We will ensure that anyone to whom we pass your personal information agrees to treat your information with the same level of protection as we are obliged to.

We are based in South Africa and our server is located in South Africa. Please take note that, subject to compliance with the relevant legislation, your information may be transferred to, stored and processed by us in our other facilities/ servers and by those third parties with whom we may share your information with.

6. Your Rights: Withholding consent

You are within your rights to withhold consent for us to collect and process your personal information. In the event that you withhold consent (by electing not to sign a consent document or explicitly informing us of your refusal) to allow us to process your personal information, we will not be able to engage with you or to enter into an agreement or relationship with you. If you elect to withhold consent, we reserve the right to deny, withhold and / or terminate your access to our website and / or the provision services provided to you.

7. Your Rights: Objection to the processing of your information

You have the right, unless legislation provides for such processing, to object at any time the processing of your Personal Information, on reasonable grounds and relating to your particular situation.

On receipt of your notice of objection together with the reasons thereof, we will place any further processing of your personal information on hold until the reason for the objection has been addressed and either:

  • the objection is resolved and withdrawn, or
  • the objection is upheld and accepted by us.

In the event that the objection is upheld, no further processing of your personal information will be done by us and as a result thereof, we shall be entitled to terminate the rendering of the services to you.

In addition to the right to notify us of your objection to the processing of your personal information, you have the right to submit a complaint directly to the Information Regulator in terms of Section 74 of POPIA, alleging interference with the protection of your personal information.

8. Your Rights: Access to information

You have the right to request a copy of the personal information we hold about you. To do this, simply contact us at the numbers/addresses as provided on our website and specify what information you require. We will need you to provide identifiable documentation such as but not limited to, a copy of your ID document and proof of address to confirm your identity before providing details of your personal information.

Please note that any such access request may be subject to a payment of a legally allowable fee.

9. Your Rights: Correction of your information

You have the right to ask us to update, correct or delete your personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. We will need you to provide identifiable documentation such as but not limited to, a copy of your ID document and proof of address to confirm your identity before making changes to personal information we may hold about you. We would appreciate it if you would keep your personal information accurate.

10. Your Rights: Withdraw your consent to the processing of your personal information

You have the right to withdraw your consent to us processing your personal information, provided that the lawfulness of the processing of your personal information before such withdrawal or the processing of personal information (to the extent that the processing is necessary to carry out actions for the conclusion or performance of a contract to which you are a party) will not be affected.

11. Direct Marketing, advertising and promotional activities

Unless you signed and completed a Consent for Direct Marketing (or a document substantially similar to the Form 4 of Regulation 6 of the POPIA), we undertake not to further process your Personal Information for the purpose of marketing to you or providing you with third party products or other optional products/ services.

12. Definition of personal information

According to the POPIA (as amended):

''personal information'' means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including but not limited to:

  • information relating to the race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person;
  • information relating to the education or the medical, financial, criminal or employment history of the person;
  • any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person;
  • the biometric information of the person;
  • the personal opinion, views or preference of the person;
  • correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence;
  • the views or opinion of another individual about the person; and
  • the name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person.

In addition, we also collect the following items as personal information:

  • all addresses including residential, postal and email addresses.
  • the details and name of the property that has been leased or let;
  • payment data such as but not limited to rental payment information;
  • data related to your social media accounts; and
  • any feedback, reviews and submissions that you may provide on our website or any social media platform administered by us.

"process" means any operation or activity or any set of operations, whether or not by automatic means, concerning personal information, including:

  • the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use;
  • dissemination by means of transmission, distribution or making available in any other form; or
  • merging, linking, as well as restriction, degradation, erasure or destruction of information.

13. Revisions and updates

Supplemental terms and conditions or documents that may be posted on our website from time to time are hereby expressly incorporated herein by reference. We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.

14. Our Terms and Conditions

Please also review our Terms and Conditions which can be found on our website (https://www.nottoafrica.com/index) or can be requested by you directly from us by contacting the person specified in clause 15 below. By accessing our website or using our services , you also agree to be bound by our Terms and Conditions, which is incorporated into this privacy notice by reference. In the event of conflict between this privacy notice and the Terms and Conditions and such conflict cannot be reconciled, the provisions contained in the Terms and Conditions shall prevail.

15. How to contact us

If you have any queries about this privacy notice; or you need further information about our privacy practices; or wish to object, withdraw consent; exercise access or correct your personal information, please contact us at the numbers/addresses listed below:

Notto SA (Pty) Ltd.
Address: 1st Floor – Sandton Gate, 25 Minerva Avenue, Sandton, Gauteng, 2196
Phone: +27 71 989 6268
Email: hello@notto.co.za