Planned Weddings and Gifts (Pty) Ltd
Registration No. 2021/461235/07
Version 1.0
Effective Date: 25 June 2026
1. Purpose
This Policy sets out how Planned Weddings and Gifts (Pty) Ltd (‘Planned’) collects, processes, stores, secures, retains and disposes of Personal Information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) (‘POPIA’). The Policy applies to all directors, employees, contractors, suppliers, operators and any person processing Personal Information on behalf of Planned.
2. Scope
This Policy applies to all Personal Information processed by Planned in the course of conducting its business, including information relating to customers, employees, suppliers, service providers, website visitors and other stakeholders.
3. Legislative Framework
Planned complies with POPIA, the Promotion of Access to Information Act, 2000 (PAIA), the Consumer Protection Act, 2008 (CPA), the Electronic Communications and Transactions Act, 2002 (ECTA), the Companies Act, 2008 and any other applicable South African legislation.
4. POPIA Principles
Planned processes Personal Information lawfully, minimally, for a specific purpose, accurately, securely and transparently. Personal Information will only be retained for as long as necessary or as required by law.
5. Categories of Personal Information
Information may include names, identity numbers, company information, addresses, email addresses, telephone numbers, banking details, payment information, order history, employment information, website usage data, IP addresses and any other information required to conduct business.
6. Purpose of Processing
Personal Information is processed to fulfil orders, deliver products, administer accounts, communicate with customers, comply with legal obligations, detect fraud, manage employment relationships, conduct marketing with consent where required, improve services and protect Planned’s legitimate business interests.
7. Lawful Basis
Processing takes place only where there is consent, a contractual necessity, a legal obligation, protection of a legitimate interest, Planned’s legitimate interests or another lawful basis recognised under POPIA.
8. Sharing Information
Planned may disclose Personal Information to payment processors, courier companies, IT providers, auditors, legal advisers, regulators or other approved operators where necessary. Operators are contractually required to maintain appropriate confidentiality and security safeguards.
9. Cross-Border Transfers
Where Personal Information is transferred outside South Africa, Planned will ensure appropriate contractual or legal safeguards are in place and that the recipient provides an adequate level of protection substantially similar to POPIA.
10. Information Security
Planned maintains reasonable technical and organisational security measures including access controls, password protection, encryption where appropriate, secure payment systems, staff confidentiality obligations, secure destruction of records and periodic review of security controls.
11. Data Retention
Records are retained only for the period necessary to satisfy business, legal, tax and regulatory requirements and are securely destroyed or anonymised thereafter unless further retention is required by law.
12. Data Subject Rights
Data Subjects may request access to, correction of, deletion of or objection to the processing of their Personal Information, withdraw consent where applicable and lodge complaints with the Information Regulator, subject to POPIA and other applicable legislation.
13. Direct Marketing
Electronic marketing communications will only be sent where permitted by law. Individuals may opt out at any time without affecting transactional communications relating to existing orders or contractual obligations.
14. Data Breaches
Any suspected or confirmed Personal Information security compromise must be reported immediately. Planned will investigate, mitigate the impact and notify affected persons and the Information Regulator where required by POPIA.
15. Information Officer
The Information Officer is responsible for overseeing compliance with POPIA, maintaining privacy governance, handling requests from Data Subjects, coordinating breach responses and ensuring ongoing compliance.
16. Responsibilities
All directors, employees and contractors must comply with this Policy, maintain confidentiality, report incidents promptly and complete privacy awareness training where required.
17. Contact Details
Information Officer
Planned Weddings and Gifts (Pty) Ltd
368 Voortrekker Road
Maitland
Cape Town
7425
Email: gifts@planned.co.za
Website: www.planned.co.za
18. Policy Review
This Policy shall be reviewed at least annually or whenever legislative or operational changes require amendment.