EASY CLEAR DATA PRIVACY & PROTECTION POLICY
Responsible Party: Easy Clear (Pty) Ltd
Trading As: Easy Clear
Information Officer: Michael Henning
Email: [mike@easyclear.co.za]
Telephone: +27 11 043 1400
Physical Address: Unit 2, Highway Gardens Office Park, 71 Minauch Road Highway Gardens, Edenvale 1609,
1. PURPOSE OF THIS POLICY
Easy Clear is committed to protecting the privacy and security of personal information entrusted to us by our customers, prospective customers, suppliers, employees, users of our software, website visitors and other persons whose personal information we process.
This Data Privacy & Protection Policy (“Policy”) explains how Easy Clear collects, uses, stores, protects and otherwise processes personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), applicable regulations and other applicable data protection legislation.
POPIA establishes conditions for the lawful processing of personal information by public and private bodies. Easy Clear is committed to implementing appropriate measures to ensure that personal information is processed lawfully, reasonably and transparently.
This Policy is intended to provide transparency regarding Easy Clear’s privacy practices and to explain the rights available to individuals whose personal information we process.
2. ABOUT EASY CLEAR
Easy Clear provides web-based software solutions to businesses operating in the customs clearing, freight forwarding, logistics, warehousing, courier, e-commerce and related industries.
Our services may include, depending on the services subscribed to by a customer:
- customs clearing and forwarding functionality;
- SARS and electronic data interchange (“EDI”) integrations;
- cargo reporting and related customs functionality;
- financial and accounting functionality;
- warehouse management;
- purchase order and shipment management;
- perishables export functionality;
- courier and e-commerce workflows;
- document management;
- client portals and tracking;
- acquittals;
- API integrations; and
- related software support, training and services.
Because our software may be used by customers to process information relating to their own employees, customers, suppliers, consignees, consignors, importers, exporters, agents and other persons, Easy Clear may process personal information on behalf of its customers.
3. DEFINITIONS
For purposes of this Policy:
3.1 “Data Subject”
Means the person to whom personal information relates.
3.2 “Easy Clear”, “we”, “us” or “our”
Means Easy Clear (Pty) Ltd, including its employees, representatives and authorised service providers where applicable.
3.3 “Information Officer”
Means the person appointed by Easy Clear in terms of applicable legislation to oversee compliance with POPIA and deal with requests relating to personal information.
3.4 “Operator”
Means a person who processes personal information for a responsible party in terms of a mandate, without coming under the direct authority of that responsible party.
3.5 “Personal Information”
Has the meaning given to it in POPIA and includes information relating to an identifiable, living natural person and, where applicable, an identifiable existing juristic person.
Examples may include names, contact details, identification information, addresses, financial information, employment information, transaction information, correspondence and information relating to a person’s interactions with Easy Clear.
3.6 “Processing”
Includes any operation or activity concerning personal information, including collection, recording, organisation, storage, updating, retrieval, use, transmission, distribution, disclosure, deletion or destruction.
3.7 “POPIA”
Means the Protection of Personal Information Act 4 of 2013, together with applicable regulations and amendments.
3.8 “Responsible Party”
Means the party which determines the purpose of and means for processing personal information.
4. SCOPE OF THIS POLICY
This Policy applies to personal information processed by Easy Clear in connection with:
- our website;
- enquiries and requests for information;
- quotations and demonstrations;
- customer onboarding;
- software subscriptions and licensing;
- customer support and helpdesk services;
- software implementation and training;
- customer account administration;
- communications and marketing;
- supplier and service-provider relationships;
- recruitment and employment;
- business administration;
- contractual relationships;
- software and system security; and
- the provision and operation of Easy Clear software and related services.
Where Easy Clear processes personal information on behalf of an Easy Clear customer, the customer may be the responsible party and Easy Clear may act as an operator.
In such circumstances, Easy Clear will process such personal information in accordance with the customer’s lawful instructions, applicable contractual arrangements and POPIA.
5. OUR COMMITMENT TO PRIVACY
Easy Clear is committed to:
- processing personal information lawfully and reasonably;
- processing personal information only for legitimate and specified purposes;
- limiting the collection of personal information to information that is necessary for the relevant purpose;
- maintaining reasonable accuracy of personal information;
- maintaining appropriate security safeguards;
- preventing unauthorised access, loss, misuse, alteration or disclosure;
- maintaining confidentiality;
- respecting the rights of data subjects;
- providing appropriate transparency regarding the processing of personal information; and
- continually reviewing our privacy and information-security practices.
6. PERSONAL INFORMATION WE MAY COLLECT
Depending on the nature of our relationship with you, Easy Clear may collect and process the following categories of personal information.
6.1 Identification Information
This may include:
- name and surname;
- identification or passport information where legitimately required;
- job title;
- company or organisation;
- username or account identification information; and
- other information required to establish or administer a business relationship.
6.2 Contact Information
This may include:
- physical address;
- postal address;
- email address;
- telephone number;
- mobile number; and
- business contact details.
6.3 Business and Transaction Information
This may include:
- company information;
- customer and supplier details;
- transaction information;
- customs-related information;
- shipment information;
- import and export information;
- documentation;
- correspondence;
- account information;
- invoicing information; and
- information required to provide or support our services.
6.4 Technical Information
When you use our website or software, we may process certain technical information, which may include:
- IP address;
- browser type;
- device information;
- operating system;
- login information;
- access dates and times;
- system activity;
- audit logs;
- security information; and
- other technical information necessary for security, administration and operation of our services.
6.5 Support and Communications Information
When you contact Easy Clear, we may retain:
- emails;
- telephone correspondence;
- support requests;
- helpdesk records;
- training records;
- technical queries;
- feedback;
- meeting records; and
- other communications relating to our services.
6.6 Marketing Information
Where applicable, we may process:
- name;
- business name;
- email address;
- telephone number;
- job title;
- marketing preferences; and
- information relating to interactions with our marketing communications.
Marketing communications will be conducted in accordance with applicable law.
7. INFORMATION PROCESSED THROUGH THE EASY CLEAR SOFTWARE
Easy Clear provides software that may enable customers to process information relating to their own customers, employees, suppliers, consignors, consignees, importers, exporters and other third parties.
The customer remains responsible for ensuring that it has an appropriate legal basis and authority to provide personal information to Easy Clear for processing.
Where Easy Clear acts as an operator:
- Easy Clear will process information only for the purposes authorised by the customer;
- Easy Clear will not use customer data for unrelated purposes;
- Easy Clear will maintain appropriate confidentiality obligations;
- Easy Clear will implement reasonable security safeguards;
- Easy Clear will assist the customer where reasonably required to meet applicable POPIA obligations; and
- Easy Clear will comply with applicable contractual requirements governing the processing of personal information.
Customers remain responsible for determining what information they upload into the Easy Clear system and for ensuring that such information is processed lawfully.
8. PURPOSES FOR WHICH WE PROCESS PERSONAL INFORMATION
Easy Clear may process personal information for the following purposes:
8.1 Providing our services
To:
- provide and administer our software;
- create and manage user accounts;
- provide customer support;
- perform implementation and training;
- maintain and improve our systems;
- process transactions;
- provide requested functionality; and
- manage customer relationships.
8.2 Contractual purposes
To:
- enter into agreements;
- administer subscriptions and licences;
- manage billing;
- process payments;
- perform contractual obligations; and
- manage contractual disputes.
8.3 Business administration
To:
- maintain business records;
- communicate with customers and suppliers;
- manage internal operations;
- conduct audits;
- manage risks;
- maintain records; and
- comply with legal and regulatory requirements.
8.4 Security
To:
- authenticate users;
- monitor system activity;
- prevent fraud;
- detect unauthorised access;
- investigate security incidents;
- protect our systems; and
- maintain the integrity and availability of our services.
8.5 Legal and regulatory compliance
To comply with:
- POPIA;
- SARS and customs requirements where applicable;
- tax legislation;
- accounting and financial requirements;
- court orders;
- regulatory requirements; and
- other applicable laws.
8.6 Marketing and communications
Where permitted by law, we may use contact information to communicate with existing and prospective customers about:
- Easy Clear products and services;
- product updates;
- events;
- educational information;
- industry developments;
- promotions; and
- other relevant business communications.
Individuals may opt out of direct marketing communications where applicable.
9. LAWFUL PROCESSING
Easy Clear will process personal information only where there is a lawful basis for doing so.
Depending on the circumstances, this may include:
- consent;
- performance of a contract;
- taking steps at the request of a data subject prior to entering into a contract;
- compliance with a legal obligation;
- protection of legitimate interests;
- protection of a legitimate interest of the data subject; or
- another lawful basis permitted by applicable legislation.
Consent, where relied upon, may be withdrawn subject to legal or contractual limitations.
Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
10. COLLECTION DIRECTLY FROM DATA SUBJECTS
Where reasonably practicable, Easy Clear will collect personal information directly from the data subject.
There may, however, be circumstances where information is lawfully obtained from other sources, including:
- our customers;
- employers;
- suppliers;
- service providers;
- publicly available sources;
- regulatory authorities;
- business partners;
- authorised representatives; or
- other lawful sources.
Where personal information is provided to Easy Clear by a customer for processing through our software, the customer is responsible for ensuring that the information has been lawfully collected and that the necessary notices or consents have been provided where required.
11. VOLUNTARY PROVISION OF INFORMATION
Where possible, Easy Clear will indicate whether the provision of particular personal information is mandatory or voluntary.
Certain information may be necessary for us to:
- provide a requested service;
- enter into a contract;
- establish a customer account;
- process an enquiry;
- provide support; or
- comply with a legal obligation.
If required information is not provided, Easy Clear may not be able to provide the relevant service or respond fully to a request.
12. ACCURACY AND QUALITY OF INFORMATION
Easy Clear takes reasonable steps to ensure that personal information in our possession is:
- accurate;
- complete where necessary;
- not misleading; and
- updated where reasonably necessary.
Data subjects and customers are encouraged to notify Easy Clear of changes to their information.
Where Easy Clear processes information on behalf of a customer, the customer remains responsible for the accuracy and quality of information submitted to the system.
13. DISCLOSURE OF PERSONAL INFORMATION
Easy Clear will not sell personal information.
Personal information may be disclosed where reasonably necessary for legitimate business purposes and in accordance with applicable law.
Recipients may include:
- authorised employees;
- authorised representatives;
- Easy Clear customers;
- service providers;
- technology providers;
- hosting providers;
- professional advisers;
- auditors;
- payment providers;
- regulatory authorities;
- government departments;
- SARS and customs authorities where applicable;
- law-enforcement authorities where legally required; and
- other parties where disclosure is authorised or required by law.
Where appropriate, Easy Clear will require service providers processing personal information on our behalf to comply with appropriate confidentiality and information-security obligations.
14. OPERATORS AND THIRD-PARTY SERVICE PROVIDERS
Easy Clear may appoint third-party service providers to assist in providing our services.
These may include providers of:
- cloud hosting;
- software infrastructure;
- database services;
- cybersecurity services;
- communication services;
- email services;
- customer support systems;
- payment services;
- backup services;
- professional services; and
- other technology or business services.
Where a third party processes personal information on our behalf, Easy Clear will take reasonable steps to ensure that appropriate contractual, confidentiality and security measures are in place.
15. CLOUD HOSTING AND INFORMATION SECURITY
Easy Clear operates a web-based software environment and uses third-party technology and infrastructure providers where required to deliver its services.
Easy Clear will take appropriate and reasonable technical and organisational measures to protect personal information against:
- loss;
- damage;
- unauthorised destruction;
- unlawful access;
- unauthorised processing;
- alteration;
- disclosure; and
- other unlawful or unauthorised forms of processing.
Security measures may include, depending on the circumstances:
- access controls;
- authentication mechanisms;
- user permissions;
- password controls;
- system monitoring;
- audit logging;
- backups;
- vulnerability management;
- security updates;
- restricted administrative access;
- confidentiality obligations; and
- other appropriate technical and organisational safeguards.
No electronic transmission or storage system can be guaranteed to be completely secure. Easy Clear will nevertheless take reasonable measures to protect personal information against foreseeable risks.
16. CONFIDENTIALITY
Employees, contractors and service providers who have access to personal information will be required to maintain appropriate confidentiality regarding such information.
Personal information will only be accessed by persons who require access for legitimate business or service-delivery purposes, subject to applicable access controls.
17. SECURITY COMPROMISES AND DATA BREACHES
Easy Clear maintains procedures for identifying, assessing and responding to actual or suspected security compromises involving personal information.
If Easy Clear becomes aware of a security compromise that triggers obligations under POPIA, Easy Clear will take reasonable steps to:
- identify and contain the incident;
- assess the nature and extent of the compromise;
- mitigate potential harm;
- investigate the circumstances;
- notify the Information Officer and relevant internal personnel;
- notify affected customers or data subjects where legally required and reasonably possible; and
- notify the Information Regulator where required by applicable law.
Notifications will contain information reasonably necessary to assist affected parties in understanding the nature of the compromise and taking appropriate protective measures.
The Information Regulator has specifically indicated that responsible parties should take measures to mitigate the impact of a security compromise and notify affected data subjects as soon as reasonably possible where required.
18. RETENTION OF PERSONAL INFORMATION
Easy Clear will not retain personal information for longer than is necessary for the purpose for which it was collected or processed, unless:
- retention is required by law;
- retention is required for contractual or legitimate business purposes;
- retention is necessary for legal proceedings;
- retention is required for regulatory purposes;
- the information is required for legitimate historical or statistical purposes; or
- another lawful basis for retention exists.
Retention periods may therefore vary depending on the type of information and the purpose for which it is processed.
When personal information is no longer required, Easy Clear will take reasonable steps to securely delete, destroy or anonymise it, subject to applicable legal, contractual and operational requirements.
19. DATA SUBJECT RIGHTS
Subject to applicable law, a data subject may have the right to:
- request confirmation as to whether Easy Clear holds personal information about them;
- request access to personal information held by Easy Clear;
- request correction or updating of inaccurate or incomplete information;
- request deletion of personal information where legally permissible;
- object to certain processing;
- object to direct marketing;
- withdraw consent where processing is based on consent;
- request information about the processing of their personal information; and
- lodge a complaint concerning the processing of their personal information.
POPIA provides data subjects with rights relating to access, correction and objection to processing, among other protections.
These rights are subject to applicable legal limitations and Easy Clear may need to verify the identity of the person making a request before responding.
20. REQUESTS FOR ACCESS, CORRECTION OR DELETION
Requests concerning personal information should be submitted to the Easy Clear Information Officer using the contact details contained in this Policy.
Requests should provide sufficient information to enable Easy Clear to:
- identify the requester;
- identify the relevant information;
- understand the nature of the request; and
- verify the requester’s identity where necessary.
Easy Clear will process requests in accordance with applicable legal requirements.
Where information is processed by Easy Clear on behalf of an Easy Clear customer, the request may need to be referred to the relevant customer as the responsible party.
21. DIRECT MARKETING
Easy Clear may communicate with existing or prospective customers regarding Easy Clear’s products, services and related business offerings where permitted by law.
Electronic direct marketing will be conducted in accordance with applicable legal requirements.
Recipients may request that Easy Clear stop sending direct marketing communications.
Every electronic marketing communication should provide an appropriate mechanism for opting out where required.
22. COOKIES AND WEBSITE TECHNOLOGIES
The Easy Clear website may use cookies and similar technologies to:
- operate the website;
- improve website functionality;
- understand website usage;
- maintain security;
- remember preferences; and
- obtain statistical information.
Where applicable, third-party analytics or website technologies may also be used.
Users may be able to control cookies through their browser settings. Disabling certain cookies may affect website functionality.
Easy Clear will process information obtained through cookies in accordance with applicable privacy legislation and this Policy.
23. THIRD-PARTY WEBSITES
The Easy Clear website may contain links to third-party websites or services.
Easy Clear is not responsible for the privacy practices, security or content of third-party websites.
Users should review the privacy policies of third-party websites before providing personal information to them.
24. SPECIAL PERSONAL INFORMATION
Easy Clear generally does not require special personal information to provide its core software services.
Where special personal information is processed, Easy Clear will ensure that such processing is undertaken only where there is an appropriate lawful basis and in accordance with the additional requirements applicable to special personal information.
25. CROSS-BORDER TRANSFERS
Easy Clear may use service providers or technology infrastructure located outside South Africa.
Where personal information is transferred outside South Africa, Easy Clear will take reasonable steps to ensure that the transfer is undertaken in accordance with applicable legal requirements, including the requirements applicable to cross-border transfers of personal information.
This may include appropriate contractual, technical or organisational safeguards.
26. AUTOMATED DECISION-MAKING
Easy Clear does not ordinarily make decisions about individuals solely through automated processing that would have significant consequences for the individual.
Where automated decision-making is introduced that is subject to specific legal requirements, Easy Clear will implement appropriate measures to comply with applicable legislation.
27. EMPLOYEE AND INTERNAL PERSONAL INFORMATION
Easy Clear also processes personal information relating to:
- employees;
- applicants;
- contractors;
- consultants;
- directors; and
- other personnel.
Such information may be processed for:
- recruitment;
- employment administration;
- payroll;
- benefits;
- performance management;
- training;
- security;
- compliance;
- legal obligations; and
- other legitimate employment and business purposes.
Access to employee information will be restricted to authorised persons who require such access.
28. SUPPLIER AND BUSINESS PARTNER INFORMATION
Easy Clear may process personal information relating to representatives and employees of suppliers, service providers and business partners.
Such information may be processed for:
- supplier onboarding;
- contractual administration;
- communication;
- procurement;
- payment;
- service management;
- compliance; and
- other legitimate business purposes.
29. INFORMATION OFFICER
Easy Clear has appointed an Information Officer responsible for overseeing the organisation’s compliance with POPIA and applicable information-protection requirements.
The Information Officer’s responsibilities include, among other things:
- encouraging compliance with POPIA;
- overseeing the development and implementation of privacy policies and procedures;
- dealing with requests relating to personal information;
- assisting with compliance assessments;
- working with the Information Regulator where required; and
- overseeing the implementation of appropriate privacy and information-security measures.
The Information Regulator states that Information Officers of private and public bodies must be registered with the Regulator and have responsibilities relating to POPIA compliance and data-subject requests.
Information Officer
Name: Mike Henning
Email: mike@easyclear.co.za
Telephone: 011 043 1400
30. PRIVACY COMPLAINTS
If you believe that Easy Clear has processed your personal information in a manner that is inconsistent with this Policy or applicable law, you are encouraged to contact the Easy Clear Information Officer in the first instance.
Easy Clear will investigate legitimate complaints and take appropriate steps where necessary.
If a complaint cannot be resolved directly with Easy Clear, a data subject may have the right to lodge a complaint with the Information Regulator.
The Information Regulator provides a complaints process for individuals who believe their personal information has been processed in a manner that violates POPIA.
Information Regulator – South Africa
Website: Information Regulator South Africa
31. PAIA AND ACCESS TO INFORMATION
Easy Clear recognises that privacy and access to information are complementary legal rights.
Requests for access to records held by Easy Clear may be dealt with in accordance with the Promotion of Access to Information Act 2 of 2000 (“PAIA”), where applicable.
Easy Clear maintains or will maintain an appropriate PAIA manual and related procedures.
This Privacy Policy should therefore be read together with Easy Clear’s PAIA Manual.
32. CHANGES TO THIS POLICY
Easy Clear may amend this Policy from time to time to reflect:
- changes in legislation;
- regulatory requirements;
- changes to our services;
- changes to our technology;
- changes to our information-processing practices; or
- improvements to our privacy practices.
The most recent version will be published on the Easy Clear website.
The “Last Updated” date at the beginning of this Policy will indicate when the Policy was most recently amended.
33. ACCOUNTABILITY, AGREEMENT TO BE BOUND & CONSENT TO PROCESS
Easy Clear accepts responsibility for complying with the principles and obligations applicable to the processing of personal information under POPIA.
By submitting personal information or by accessing or using the electronic platforms and facilities, including all websites, mobile applications, URL’s and any sites housed under its domain names and / or social media platforms and when sending or receiving emails the Data subject acknowledges that it has read and understood this privacy notice and related provisions.
The Data subject agrees to be bound by the terms and conditions of this privacy notice and agrees to comply with this privacy notice, giving Easy Clear (Pty) Ltd explicit consent to process personal information for the required purposes, in accordance with this privacy notice.
Easy Clear (Pty) Ltd will take reasonable steps to ensure that employees, contractors and service providers who process personal information on our behalf understand and comply with applicable privacy and confidentiality requirements.
34. GOVERNING LAW
This Policy is governed by the laws of the Republic of South Africa.
Any dispute relating to this Policy will be subject to the jurisdiction of the applicable courts of the Republic of South Africa, subject to any mandatory provisions of applicable law.
35. CONTACT US
If you have any questions about this Policy, wish to exercise your rights, or have concerns regarding the processing of your personal information, please contact:
Easy Clear Chief Information Officer
36. POLICY APPROVAL
This Policy has been approved by the management of Easy Clear and is effective from the date specified above.
