GUVON HOTELS & SPAS
POPI ACT
THE PARTIES AGREE AS FOLLOWS:
In the case of any Contract or ongoing relationship between the Parties, and where the provisions of POPIA apply to the Processing of Personal Information in relation to the Services, these terms and conditions shall apply to and supplement the terms and conditions of such Contract.
In the event of a conflict between the provisions of this Agreement and the Contract, the provisions of this Agreement shall prevail and take precedence about all aspects pertaining to any Processing of Personal Information by the Customer of any Data Subjects for or on behalf of the Company.
1. DEFINITIONS AND INTERPRETATION
In this Agreement, unless the context indicates a contrary intention, the following words and expressions bear the meanings assigned to them and cognate expressions bear corresponding meanings –
1.1. “Agreement” means this POPI Agreement;
1.2. “Affiliate” means with respect to a Party any person, partnership, joint venture, corporation or other form of enterprise, domestic or foreign, including but not limited to Subsidiaries and associates that directly or indirectly, Control, are Controlled by, or are under common Control with a Party. For purposes of this Agreement, the term “Subsidiaries” shall have the meaning ascribed thereto in the Companies Act 71 of 2008, as amended;
1.3. “Business Day“ means any day from Monday to Friday and excludes any public holiday as gazetted in the Republic of South Africa;
1.4. “Confidential Information“ means any information or data of any nature, tangible or intangible, oral or in writing and in any format or medium, which (i) by its nature or content is, or ought reasonably to be identifiable as, confidential and/or proprietary to the Company or a third party associated to the Company, or (ii) is provided or disclosed in confidence, and which the Company or any person acting on behalf of the Company may disclose to the Customer, or (iii) may come to the knowledge of the Customer by whatsoever means. Without limitation, Confidential Information shall include the following –
1.4.1. information relating to the Company’s business activities, business relationships, products, services, processes, data, and Staff, including agreements to which the Company is a party (including this Agreement);
1.4.2. information contained in or constituting or relating to the Company’s technology and telecommunications systems including third party hardware and software, and associated material, and information or incidents concerning faults or defects therein;
1.4.3. the Company’s technical, scientific, commercial, financial and market information, methodologies, formulae and trade secrets;
1.4.4. the Company’s architectural information, demonstrations, plans, designs, drawings, processes, process maps, functional and technical requirements and specifications and the data relating thereto;
1.4.5. intellectual property that is proprietary to the Company or that is proprietary to a third party;
1.4.6. information relating to the Company’s current and existing strategic objectives, strategy documents and plans for both its existing and future information technology, processing, business processing and business process outsourcing; and
1.4.7. Personal Information as defined in this Agreement.
1.5. “Contract” means any agreement and any annexures thereto, entered into between the Parties in respect the provision of Services by the Customer to the Company;
1.6. “Control” means the ability, by virtue of ownership, right of appointment, voting rights, management agreement, or agreement of any kind, to control or direct, directly or indirectly, the board or executive body or decision-making process or management of such entity;
1.7. “Data Subject” means any person to whom the specific Personal Information relates, as contemplated in POPIA;
1.8. “Information Officer” means the Company’s Information Officer, as referred to in the Company’s Manual in terms of Section 51 of the Promotion of Access to Information Act 2 of 2000 (as may be amended from time to time);
1.9. “Operator” has the meaning set out in POPIA and for purposes of this Agreement means the Customer and any authorised subcontractor of the Customer;
1.10. “Party” or “Parties” means either the Customer or the Company or both, as the context may require;
1.11. “Personal Information” has the meaning set out in section 1 of POPIA, and includes special personal information as defined in section 26 of POPIA and relates only to the Personal Information of which the Company is the Responsible Party and in relation to which the Customer renders the Services;
1.12. “POPIA” means the Protection of Personal Information Act No. 4 of 2013, as amended from time to time;
1.13. “Processing” or “Process” has the meaning set out in POPIA;
1.14. “Responsible Party” has the meaning ascribed thereto in POPIA, and for purposes of this Agreement shall mean the Company;
1.15. “Services” means any supply or rendering of services by the Customer for the Company in terms of a Contract and in terms of which the Customer, among others, Processes Personal Information of Data Subjects;
1.16. “Signature Date” means the date of signature of this Agreement by the last Party to do so in time;
1.17. “Staff” means any employee, independent contractor, agent, consultant, sub-contractor or other representative of either Party;
1.18. In this Agreement –
1.18.1. Any substantive provision, conferring rights or imposing obligations on a Party and appearing in any of the definitions in this clause, or elsewhere in this Agreement, will be given effect to as if it were a substantive provision in the body of this Agreement.
1.18.2. Words and expressions defined in any clause will, unless the application of any such word or expression is specifically limited to that clause, bear the meaning assigned to such word or expression throughout this Agreement.
1.18.3. Defined terms appearing in this Agreement in title case will be given their meaning as defined, while the same terms appearing in lower case will be interpreted in accordance with their plain English meaning.
1.18.4. A reference to any statutory enactment will be construed as a reference to that enactment as at the Signature Date and as amended or substituted from time to time.
1.18.5. Reference to “days” will be construed as calendar days unless qualified by the word “business”.
1.18.6. Unless specifically otherwise provided, any number of days prescribed will be determined by excluding the first day and including the last day or, where the last day falls on a day that is not a business day, the next succeeding business day.
1.18.7. Where figures are referred to in numerals and in words, and there is any conflict between the two, the words will prevail, unless the context indicates otherwise or a contrary intention.
1.18.8. No provision herein will be construed against or interpreted to the disadvantage of a Party by reason of such Party having or being deemed to have structured, drafted or introduced such provision.
1.18.9. The words “include” and “including” mean “include without limitation” and “including without limitation”. The use of the words “include” and “including” followed by a specific example or examples will not be construed as limiting the meaning of the general wording preceding it. The application of the eiusdem generis rule is therefore excluded.
2. COMMENCEMENT AND DURATION
This Agreement shall commence on the Signature Date and shall endure for as long as the Customer remains in possession of any
Personal Information of the Data Subjects, regardless of the termination of the Contract.
3. AUTHORISATION TO PROCESS
3.1. It is recorded that, pursuant to its obligations under this Agreement, the Customer will Process Personal Information of Data Subjects in connection with and for the purposes of the provision of the Services and will act as the Company’s Operator for purposes of POPIA.
3.2. Unless required by law, the Customer shall Process the Personal Information only:
3.2.1. in compliance with this Agreement;
3.2.2. for the purposes connected with the provision of the Services or as specifically otherwise instructed or authorised by the Company in writing; and
3.2.3. according to the technical and organisational security measures determined in terms of clause 4.2, unless specific standards are otherwise agreed to by the Parties.
3.3. The Customer shall treat the Personal Information that comes to its knowledge or into its possession as confidential and shall not disclose it without the prior written consent of the Company, unless required to do so by law. For avoidance of doubt, the provisions of the Contract
in relation to Confidential Information or any non-disclosure agreement, or the provisions regarding confidentiality contained in any Contract, as the case may be, entered into between the Parties shall with the necessary changes, apply to this Agreement.
3.4. Without limiting the Customer’s obligations under this Agreement, the Customer shall comply with applicable industry or professional rules and regulations, in relation to the safeguarding of Personal Information, which may apply to it.
4. PROTECTION OF PERSONAL INFORMATION
4.1. The Customer acknowledges and agrees that the Company retains all right, title and interest in and to the Personal Information and that the Personal Information shall constitute the Company’s Confidential Information.
4.2. The Customer shall, by 1 July 2021, implement and maintain reasonable technical and organizational security measures to protect Personal Information Processed on behalf of the Company at a level of security appropriate to the Customer’s risk.
4.3. In determining the level of security appropriate to the Customer’s risk, the Customer shall take into consideration:
4.3.1. the costs of implementing security measures;
4.3.2. the nature, scope, context and purposes of Processing the relevant Personal Information;
4.3.3. the type of Personal Information, its sensitivity and the likelihood of unauthorised disclosure or access thereto; and
4.3.4. the likely harm to suffered by the Data Subject arising from unauthorised disclosure or access thereto.
4.4. Within 5 (five) Business Days of a request from the Company, the Customer shall provide to the Company a written explanation and full details of the technical and organisational measures taken by or on behalf of the Customer to demonstrate and ensure compliance with clause 4.2 hereof.
4.5. The Customer shall also:
4.5.1. take steps to keep abreast and ensure that it and its Staff comply fully with all applicable laws and regulations that are applicable to the Services;
4.5.2. limit the Processing of and access to the Personal Information to those Staff who:
4.5.2.1. strictly need to know the Personal Information to enable the Customer to render the Services to the Company; and
4.5.2.2. have entered into appropriate confidentiality agreements with the Customer.
4.5.3. within 5 (five) Business Days, deal with all reasonable inquiries from the Company relating to its Processing of the Personal
Information and provide the Company with copies of the Personal Information in the format reasonably specified by the Company;
4.5.4. immediately inform the Company of its inability to comply with the Company’s instructions and this clause (Authorisation to Process), in which case the Company is entitled to suspend the Customer’s Processing of Personal Information and/or terminate the Contract;
4.5.5. provide the Company with full co-operation and assistance in relation to any requests for access to, correction of or complaints made by the Data Subjects relating to their Personal Information.
5. NOTIFICATION OF DATA BREACH
5.1. The Customer shall notify the Company’s Information Officer in writing within 24 (twenty-four) hours or otherwise as soon as reasonably possible, where there are reasonable grounds to believe that Personal Information under the control of the Customer as a result of this Agreement has been accessed, destroyed or acquired by an unauthorised person or if the Customer’s use of the Personal Information is in breach of this Agreement.
5.2. The Customer shall, simultaneously with its notification of a data breach, furnish the Company with details of the Data Subjects affected by the compromise and the nature and extent of the compromise, including details of the identity of the unauthorised person who may have accessed or acquired the Personal Information as well as with daily reports on progress made at resolving the compromise.
6. DATA-SUBJECT REQUESTS
6.1. The Customer shall notify the Company’s Information Officer:
6.1.1. within 3 (three) Business Days of receiving any request for access to or correction of the Personal Information or complaints received by the Customer relating to the Company’s obligations in terms of POPIA, and provide the Company with full the details of such request or complaint; and
6.1.2. promptly of any legally binding request for disclosure of Personal Information or any other notice or communication that relates to the Processing of the Personal Information from any supervisory or governmental body.
6.2. The Customer shall not respond to a request in terms of clauses 6.1.1 or 6.1.2 except:
6.2.1. on the documented instructions of the Company; or
6.2.2. as required by law to which the Customer is subject, in which case the Customer shall to the extent permitted by the applicable law inform the Company of that legal requirement before the Customer responds to such request.
7. AUDIT RIGHTS
7.1. The Company or its agent shall have the right to audit the Customer at any time, with reasonable notice, if there is a reasonable suspicion that the Customer is not complying with the provisions of this
Agreement or where there is a suspicion that the confidentiality, integrity and accessibility of Personal Information is likely to be compromised. Such audit rights shall include the right of access to systems, procedures and software, and inspection of the physical security of the Customer’s premises. The Customer shall offer reasonable assistance and co-operation to the Company and/or its auditors or inspectors in the carrying out of such auditing exercise. To the extent that the Customer engages an independent auditor in relation to the provisions of applicable personal data protection legislation to carry out an audit of its operations, the Customer agrees to provide the Company with copies of the audit reports of all such audit exercises. Nothing in this clause 7 (Audit Rights) should be read as providing the Company with unlimited access to audit the Customer without just cause.
7.2. The costs of any such audit, review and/or inspection shall be borne by the Company, unless a material misstatement or understatement is identified as a result therefrom, and in which case the Customer shall be solely liable for such costs.
8. SEPARATION OF PERSONAL INFORMATION
The Customer shall Process the Personal Information in relation to the Services separately from Personal Information, data and property relating to the Customer or any third party, and may not be combined or merged with the information of another party unless otherwise agreed to in writing by the Company.
9. RETURN AND RETENTION OF PERSONAL INFORMATION
9.1. The Company may, at any time on written request to the Customer, require that the Customer:
9.1.1. immediately return to it any Personal Information and may, in addition, require that the Customer furnish a written statement to the effect that upon such return, it has not retained in its possession or under its control, whether directly or indirectly, any such Personal Information or material; or
9.1.2. destroy all such Personal Information and material and furnish the Company with a certificate of destruction, unless the law prohibits the Customer from doing so. In that case, the Customer agrees that it will maintain the confidentiality of the Personal Information considering clause 2 (Commencement and Duration) and will not actively Process the Personal Information any further.
9.2. The Customer shall comply with any request in terms of this clause 9 within 10 (ten) days of receipt of such request.
10. SUBCONTRACTING AND SUB-OPERATORS
10.1. The Customer may not subcontract the performance of any of its obligations under this Agreement to any service provider (sub-operator) without the Company’s prior written consent having been obtained. All references to the Customer’s Staff shall be deemed to include the employees of any sub-contractor of the Customer.
10.2. In the event that the Company agrees to the Customer sub-contracting certain or all of the Customer’s obligations under this Agreement, the Customer must only do so by way of a written contract with the sub-contractor which contract must impose the same obligations on the sub-contractor as are imposed on the Customer in terms of this Agreement insofar as the Processing of Personal Information by the sub-contractor is concerned.
10.3. In the event that the Customer intends to change or substitute any of its sub-contractors permitted in terms of this Agreement, the Customer shall:
10.3.1. notify the Company 30 (thirty) days prior to changing or
substituting the sub-contractor;
10.3.2. allow the Company an opportunity to object to the engagement of the new sub-contractor within 5 Business Days of such notification and such objection must describe the Company’s legitimate reason(s) for objection; Provided that if the Company does not object during such time period, the new sub-contractor shall be deemed accepted.
10.3.3. If the Company objects to the Customer’s use of a new sub-contractor following the process provided in clause 10.3 of this Agreement, the Customer shall have the right to cure the objection through one of the following options, which shall be selected by the Customer in its sole and absolute discretion:
10.3.3.1. the Customer will not use the new sub-contractor and will make alternative arrangements where possible with regard to the Personal Information being processed in its role as an Operator; or
10.3.3.2. the Customer will take the corrective steps requested by the Company noted in its objection (which steps will be deemed to resolve the Company’s objection) and proceed to use the new sub-contractor to process the Personal Information; or
10.3.3.3. the Customer will provide the Company with an election to unconditionally suspend or terminate the Services rendered under the Contract subject to clause 15 (Consequences of Termination).
11. INDEMNITIES
Subject to the Contract, the Customer hereby indemnifies and holds harmless the Company from any and all losses arising from any claim or action brought against the Company arising from or due to the Customer’s breach of its obligations set out in this Agreement or any law with respect to the protection of Personal Information and Confidential Information.
12. CONFIDENTIALITY
12.1. The Customer agrees and undertakes –
12.1.1. except as permitted by this Agreement, not to disclose or publish any Confidential Information in any manner for any reason or purpose whatsoever without the prior written consent of the Company and provided that in the event of the Confidential Information being proprietary to a third party, it shall also be incumbent on the Customer to obtain the consent of such third party;
12.1.2. except as permitted by this Agreement, not to utilise, employ, exploit or in any other manner whatsoever use the Confidential Information for any purpose whatsoever without the prior written consent of the Company and provided that in the event of the Confidential Information being proprietary to a third party, it shall also be incumbent on the Customer to obtain the consent of such third party;
12.1.3. to restrict the dissemination of the Confidential Information to only those of its Staff who are actively involved in activities for which use of Confidential Information is authorised and then
only on a “need to know” basis, and the Customer shall initiate, maintain and monitor internal security procedures reasonably acceptable to the Company to prevent unauthorised disclosure by its Staff; and
12.1.4. to take all practical steps, both before and after disclosure, to inform its Staff who are given access to Confidential Information, the secret and confidential nature of such information.
12.2. The obligations of the Customer with respect to each item of Confidential Information shall endure for an indefinite period from receipt of that item of Confidential Information. The obligations referred to in this clause 12 (Confidentiality) shall endure notwithstanding any termination of this Agreement or any other agreement entered into between the Parties.
12.3. The Customer hereby indemnifies and holds the Company harmless from any and all losses arising from, or in connection with, any claim or action arising from the Customer’s breach of any obligation with respect to Confidential Information.
13. COMPANY AFFILIATE
Unless otherwise agreed to the contrary, the Parties hereby agree that any Company Affiliate shall be entitled to rely on all the provisions of this Agreement, which provisions are binding between the Company Affiliate and the Customer, in respect of any contract that might be entered into between the Customer and the Company Affiliate in terms of which the Customer will be Processing Personal Information on behalf of the Company Affiliate. For the avoidance of doubt, this Agreement is applicable and binding in respect of all contracts concluded between the Customer and Company or Company Affiliate where the Customer Processes Personal Information on behalf of the Company or the Company Affiliate.
14. BREACH AND TERMINATION
14.1. In the event of either of the Parties committing a breach of any of the conditions of this Agreement and failing to remedy such breach within 7 (seven) Business Days of receipt of a notice from the other Party requesting it to remedy such breach, then the other Party shall be entitled to cancel this entire Agreement forthwith and claim such losses as it may have suffered. In the event of termination of this Agreement, the Party terminating this Agreement shall have a right to also exercise its rights of termination under the Contract.
14.2. Notwithstanding anything to the contrary contained in this Agreement, the Parties shall be entitled to terminate this Agreement by mutual agreement in writing.
14.3. The provisions of this clause 14 (Breach and Termination) shall not affect or prejudice any other rights/remedies which the Parties may have in law or in any other Contract between the Parties.
15. CONSEQUENCES OF TERMINATION
15.1. The termination of this Agreement shall not affect the rights of either of the Parties that accrued before termination of this Agreement or which specifically survives the termination of the Agreement.
15.2. Upon termination of this Agreement or upon request by the Company, the Customer shall return or destroy any material containing, pertaining or relating to the Personal Information disclosed pursuant to this Agreement to the Company in terms of clause 9 (Return and Retention of Personal Information) unless the law prohibits the Customer from doing so. In that case, the Customer agrees that it will maintain the confidentiality of the Personal Information and will not, under any circumstance, Process the Personal Information any further.
16. WAIVER
16.1. Failure or delay by either Party in exercising any right will not constitute a waiver of that right.
16.2. No waiver of any of right under this Agreement will be binding unless it is in writing and signed by the Party waiving the right.
17. SEVERABILITY
If any part of this Agreement is found to be invalid or unenforceable, it shall be severed from the remainder of this Agreement, which shall remain valid and enforceable.
18. CESSION AND DELEGATION
The Customer may not cede its rights or delegate its obligations in terms of this Agreement, without the prior written consent of the Company, which consent shall not be unreasonably withheld.
19. GOVERNING LAW
This Agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed exclusively in accordance with South African law. The Customer consents and submits to the jurisdiction of the High Court of South Africa, Gauteng Local Division, in any dispute arising from
or in connection with this Agreement. Without prejudice to any other rights or remedies which the Company may have, the Customer acknowledges that nothing herein shall preclude the Company from seeking urgent relief or specific performance from a court of competent jurisdiction.
20. NOTICES AND DOMICILIUM
20.1. The Parties select as their domicilium citandi et executandi the physical addresses appearing on page 1 to this Agreement, and for the purposes of giving or sending any notice provided for or required hereunder, the addresses and email addresses appearing on the first page or such other addresses or email addresses as may be substituted by notice given.
20.2. The Customer acknowledges that any notice it sends to the Company relating to this Agreement shall be marked for the attention of the Company’s Information Officer.
20.3. Any notice addressed to a Party at its physical or postal address shall be sent by prepaid registered post, or delivered by hand, or sent by email.
20.4. Any notice shall be deemed to have been given and received –
20.4.1. if posted by prepaid registered post, 14 (fourteen) days after the date of posting thereof;
20.4.2. if hand delivered, on the day of delivery; and
20.4.3. if sent by email on the date of sending of such email, provided that such email shall be confirmed by a proof of delivery.
20.5. Notwithstanding anything to the contrary contained in this clause 20 (Notices and Domicilium) a written notice or communication actually received by a Party shall constitute adequate written notice or communication to it notwithstanding that it was not sent or delivered to its chosen domicilium citandi et executandi or in the manner provided.
21. COUNTERPARTS
This Agreement may be executed in any number of counterparts and by different Parties hereto in separate counterparts, each of which, when so executed, shall be deemed to be an original and all of which, when taken together, shall constitute one and the same agreement.
