top of page

MONKEYNASTIX CAPE TOWN WEBSITE DATA PROTECTION POLICY

             

Introduction

​

Monkeynastix Cape Town needs to gather and use certain information about individuals to register for the online classes.

These can include customers, business contacts, employees and other people the organisation has a relationship with or may need to contact.

​

This policy describes how this personal data must be collected, handled and stored to meet the company’s data protection standards — and to comply with the law.

​

Why this policy exists.

​

This data protection policy ensures Monkeynastix Cape Town:

  • Complies with data protection law and follow good practice.

  • Protects the rights of staff, customers and partners.

  • Protects itself from the risks of a data breach.

 

Data protection law (POPI and Data Protection Act)

​

Monkeynastix Cape Town will not share and/or make available the user data stored, for online registration, with any person or company unless with written permission and consent from the registrant. The Data Protection Act 1998 describes how organisations — including Monkeynastix Cape Town — must collect, handle and store personal information. These rules apply regardless of whether data is stored electronically, on paper or on other materials. To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully.

The Data Protection Act is underpinned by eight important principles. These say that personal data must:

  1. Be processed fairly and lawfully.

  2. Be obtained only for specific, lawful purposes.

  3. Be adequate, relevant and not excessive.

  4. Be accurate and kept up to date.

  5. Not be held for any longer than necessary.

  6. Processed in accordance with the rights of data subjects.

  7. Be protected in appropriate ways.

 

People and Responsibilities

​

This policy applies to:

  • The head office of Monkeynastix Cape Town

  • All staff and volunteers of Monkeynastix Cape Town

  • All contractors, suppliers and other people working on behalf of Monkeynastix Cape Town

 

It applies to all data that the company holds relating to identifiable individuals, even if that information technically falls outside of the POPI and Data Protection Act 1998. This can include:

  • Names of individuals

  • Email addresses

  • Telephone numbers

  • …plus, any other information relating to registrants.

 

Responsibilities

 

This policy helps to protect Monkeynastix Cape Town from some very real data security risks, including:

​

Key areas of responsibility:

  • The management is ultimately responsible for ensuring that Monkeynastix Cape Town meets its legal obligations.

  • The data protection officer is responsible for:

    • Keeping the management updated about data protection responsibilities, risks and issues.

    • Handling data protection questions from staff and anyone else covered by this policy.

    • Dealing with requests from individuals to see the data Monkeynastix Cape Town holds about them (also called ‘subject access requests’).

 

  • The IT manager is responsible for:

    • Ensuring all systems, services and equipment used for storing data meet acceptable security standards.

    • Performing regular checks and scans to ensure security hardware and software is functioning properly.

 

  • The marketing manager is responsible for:

    • Approving any data protection statements attached to communications such as emails and letters.

 

Data storage

​

The site's data complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework.

​

Wix.com Ltd is considered by the European Commission to be offering an adequate level of protection for the Personal Information of EU Member State residents.

​

Wix affiliates and service providers that store or process your Personal Information on Wix’s behalf are each contractually committed to keep it protected and secured, in accordance with industry standards and regardless of any lesser legal requirements which may apply in their jurisdiction.

​

Wix may store and process Personal Information in the USA, Europe, Israel, or other jurisdictions, whether by ourselves or with the help of our affiliates and service providers.

​

EU-U.S. Privacy Shield & Swiss-U.S. Privacy Shield Disclosure: Wix.com participates in, and has certified its compliance with, the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework. Wix.com is committed to subjecting all Personal Information received from European Union (EU) member countries and Switzerland, respectively, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles.

​

Wix.com is responsible for the processing of Personal Information it receives, under the Privacy Shield Framework, and subsequent transfers to a third party acting as an agent on its behalf. Wix.com complies with the Privacy Shield Principles for all onward transfers of Personal Information from the EU, including the onward transfer liability provisions.

 

Data accuracy

 

The law requires Monkeynastix Cape Town to take reasonable steps to ensure data is kept accurate and up to date.

The more important it is that the personal data is accurate, the greater the effort Monkeynastix Cape Town should put into ensuring its accuracy.

  • Staff should take every opportunity to ensure data is updated. For instance, by confirming a customer’s details when they call.

  • Monkeynastix Cape Town will make it easy for data subjects to update the information Monkeynastix Cape Town holds about them. For instance, via the website.

  • Data should be updated as inaccuracies are discovered. For instance, if a customer can no longer be reached on their stored telephone number, it should be removed from the database.

 

Disclosing data for other reasons

​

In certain circumstances, the Data Protection Act allows personal data to be disclosed to law enforcement agencies without the consent of the data subject.

​

Under these circumstances, Monkeynastix Cape Town will disclose requested data. However, the data controller will ensure the request is legitimate, seeking assistance from the management and from the company’s legal advisers where necessary.

bottom of page