[gap] [row] [col span__sm=”12″] [button text=”VIEW OUR PAIA MANUAL” color=”white” link=”https://enova.africa/wp-content/uploads/2022/05/PAIA-Manual_Enova.pdf”]

 

Privacy Statement

As required by the POPI ACT of South Africa

 

You, as the Disclosing Party, hereby consent to and are bound by this POPI Policy / Privacy Statement (“Privacy Statement”) of Enova Energy (Pty) Ltd 2020/158612/07 (“Recipient”) in relation to the processing by the Recipient of the personal information of the Disclosing Party. This Privacy Statement is effective as of the date of consent hereto or the effective date of any main agreement incorporating the terms of this Privacy Statement by reference (“Agreement”), whichever is earlier.

 

  1. DEFINITIONS
  1. PROCESSING OF PERSONAL INFORMATION
  1. SCOPE OF PROCESSING

The nature and purpose of Processing of Personal Information by the Recipient is as set out in the table at the end of this Privacy Statement.

  1. RIGHTS OF DATA SUBJECTS

unless Processing is otherwise permissible under the Data Protection Laws and Regulations or this Privacy Statement;

  1. ASSOCIATED PERSONNEL

The Recipient shall ensure that its Associated Personnel engaged in the Processing of Personal Information are informed of the confidential nature of the Personal Information, have received appropriate training on their responsibilities and have executed written confidentiality agreements or are under general obligations of confidentiality towards the Recipient.

The Recipient shall take commercially reasonable steps to ensure the reliability of the Associated Personnel engaged in the Processing of Personal Information.

The Recipient shall ensure that access to Personal Information is limited to those Associated Personnel of the Recipient directly involved in the fulfilling of the purpose.

  1. OPERATORS

Disclosing Party acknowledges and agrees that:

Except as otherwise provided in this Privacy Statement, the Recipient shall not provide any third party with access to Disclosing Party Personal Information without the prior express approval of Disclosing Party. The Recipient shall provide advanced written notice to the Disclosing Party should it desire to provide a third-party access to Disclosing Party’s Personal Information. Where approval has been granted by Disclosing Party in accordance this section, the Recipient shall:

  1. SECURITY MEASURES, NOTIFICATIONS REGARDING PERSONAL INFORMATION, CERTIFICATIONS AND AUDITS, RECORD

Taking into account the state of art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Recipient shall implement appropriate organizational and technical measures towards a level of security, appropriate to the risk (including risks that are presented by Processing, in particular from accidental or unlawful destruction, loss alteration, unauthorized disclosure of, or access to Personal Information transmitted, stored or otherwise Processed), including but not limited to:

The Recipient shall maintain complete and accurate written records of the Processing it undertakes on behalf of Disclosing Party in accordance with Data Protection Laws and Regulations.

  1. RETURN OF PERSONAL INFORMATION, COMMUNICATION

Unless otherwise required by law, the Recipient and Operators, shall if required in terms of Data Protection Laws and Regulations, upon termination or expiry of the Agreement for whatever reason, either securely delete or return all the Disclosing Party Personal Information to Disclosing Party in accordance with the Agreement, or in the absence of a specific destruction provision, the Recipient will ensure it follows its standard Personal Information destruction practices. If the Recipient or its Affiliates are required to retain a copy of the Personal Information by law, it shall retain that which is required by applicable Data Protection Laws and Regulations for not longer than is reasonably necessary.

  1. COOPERATION WITH SUPERVISORY AUTHORITY

The Disclosing Party and the Recipient as applicable, shall cooperate, on request, with the Supervisory Authority in the performance of its tasks.

  1. CONFLICT

If this Privacy Statement is incorporated into and forms part of any other Agreement, for matters not addressed under this Privacy Statement, the terms of the Agreement apply to the extent of any inconsistency. With respect to the rights and obligation of the parties to each other insofar as it pertains to the Processing of Personal Information, in the event of a conflict between the terms of the Agreement and this Privacy Statement, the terms of this Privacy Statement will prevail to the extent of such inconsistency.

Nature and purpose of Processing

 

This table includes certain details of the Processing of Personal Information as required by section 18 of the POPI Act.

Nature and purpose of Processing

The Recipient and Operators will/may Process Personal Information as necessary to provide account statements and usage reports. Failure to provide the Personal Information may mean that the Recipient will be unable to fulfil this purpose, and as such, it is mandatory.

Categories of third parties

Personal Information may be shared with the following categories of third parties:

  • Third-party vendors or service providers providing crucial services and necessary to provide the Service;
  • Business partners, contractors, channel partners, or other affiliated entities;
  • Medical provides as may be necessary as a part of providing medical services to residents;

·        Government agencies or other parties in response to legal process or other requests, where permitted by law.

Types of Personal Information to be Processed in terms of this Privacy Statement

·        First name

·        Last name

·        Email address

·        Phone number

·        Address

 

 

 

 

[/col] [/row]