Planned Weddings and Gifts (Pty) Ltd
Registration No. 2021/461235/07
Version 1.0
Effective Date: 25 June 2026

1. Purpose

This Policy sets out how Planned Weddings and Gifts (Pty) Ltd (‘Planned’) collects, processes, stores, secures, retains and disposes of Personal Information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) (‘POPIA’). The Policy applies to all directors, employees, contractors, suppliers, operators and any person processing Personal Information on behalf of Planned.

2. Scope

This Policy applies to all Personal Information processed by Planned in the course of conducting its business, including information relating to customers, employees, suppliers, service providers, website visitors and other stakeholders.

3. Legislative Framework

Planned complies with POPIA, the Promotion of Access to Information Act, 2000 (PAIA), the Consumer Protection Act, 2008 (CPA), the Electronic Communications and Transactions Act, 2002 (ECTA), the Companies Act, 2008 and any other applicable South African legislation.

4. POPIA Principles

Planned processes Personal Information lawfully, minimally, for a specific purpose, accurately, securely and transparently. Personal Information will only be retained for as long as necessary or as required by law.

5. Categories of Personal Information

Information may include names, identity numbers, company information, addresses, email addresses, telephone numbers, banking details, payment information, order history, employment information, website usage data, IP addresses and any other information required to conduct business.

6. Purpose of Processing

Personal Information is processed to fulfil orders, deliver products, administer accounts, communicate with customers, comply with legal obligations, detect fraud, manage employment relationships, conduct marketing with consent where required, improve services and protect Planned’s legitimate business interests.

7. Lawful Basis

Processing takes place only where there is consent, a contractual necessity, a legal obligation, protection of a legitimate interest, Planned’s legitimate interests or another lawful basis recognised under POPIA.

8. Sharing Information

Planned may disclose Personal Information to payment processors, courier companies, IT providers, auditors, legal advisers, regulators or other approved operators where necessary. Operators are contractually required to maintain appropriate confidentiality and security safeguards.

9. Cross-Border Transfers

Where Personal Information is transferred outside South Africa, Planned will ensure appropriate contractual or legal safeguards are in place and that the recipient provides an adequate level of protection substantially similar to POPIA.

10. Information Security

Planned maintains reasonable technical and organisational security measures including access controls, password protection, encryption where appropriate, secure payment systems, staff confidentiality obligations, secure destruction of records and periodic review of security controls.

11. Data Retention

Records are retained only for the period necessary to satisfy business, legal, tax and regulatory requirements and are securely destroyed or anonymised thereafter unless further retention is required by law.

12. Data Subject Rights

Data Subjects may request access to, correction of, deletion of or objection to the processing of their Personal Information, withdraw consent where applicable and lodge complaints with the Information Regulator, subject to POPIA and other applicable legislation.

13. Direct Marketing

Electronic marketing communications will only be sent where permitted by law. Individuals may opt out at any time without affecting transactional communications relating to existing orders or contractual obligations.

14. Data Breaches

Any suspected or confirmed Personal Information security compromise must be reported immediately. Planned will investigate, mitigate the impact and notify affected persons and the Information Regulator where required by POPIA.

15. Information Officer

The Information Officer is responsible for overseeing compliance with POPIA, maintaining privacy governance, handling requests from Data Subjects, coordinating breach responses and ensuring ongoing compliance.

16. Responsibilities

All directors, employees and contractors must comply with this Policy, maintain confidentiality, report incidents promptly and complete privacy awareness training where required.

17. Contact Details

Information Officer
Planned Weddings and Gifts (Pty) Ltd
368 Voortrekker Road
Maitland
Cape Town
7425
Email: gifts@planned.co.za
Website: www.planned.co.za

18. Policy Review

This Policy shall be reviewed at least annually or whenever legislative or operational changes require amendment.