PRIVACY NOTICE

(This is an ever-evolving document, please see our website from time to time for the latest version)

Graça Machel Trust, having its registered address at Investment Place Block C, 10th Road, Hyde Park, 2196 (“GMT”, “we”, “our”).

We are committed to complying with applicable data protection laws and set out below details regarding our approach to data protection in all our operations.

 

Information we collect from donors

We collect names and contacts details so that we engage with you regarding our programmes. We do so with your consent, and you are always able to opt out of receiving communications from us regarding donations.

 

Information we collect from beneficiaries

Depending on the programme, we may collect information regarding names, contact details, demographics, photographs, business registrations and financial information. We do so on the basis that it is in our legitimate interest to ensure that we are dealing with beneficiaries that fall within the scope of our programmes and meet our objectives.

 

Information we collect from volunteers

Names and contact details so that we can communicate with you regarding your volunteering. We do this as we have a legitimate interest in engaging with volunteers in the different programmes for us to meet our objectives.

 

Information we collect from partners

Names, contact details, financial and corporate information so that we can communicate and liaise with you regarding our programmes and connect you with other partners where necessary.

 

Information we collect from suppliers and professional service providers

We collect names, contact details, financial and tax information from suppliers and professional service providers so that we can place orders/instruct you and make payment in respect of any goods or services we receive. We do this on the basis of the intention of contracting with you or for the performance of a contract we have with you.

 

Information we collect from you when you sign up to our newsletter or complete our contact form

If you have opted in to receive our newsletter, we collect your name, surname and email in order that we can direct market to you. We will only use the information you provide for this purpose and you will be able to opt-out of receiving this at any time.

If you have completed our contact form, we collect your name, surname, email and telephone number and any other information you provide in order that we can contact you or respond to your question. We will only use the information you provide for this purpose.

 

Information we collect from you when you visit our website

Our website uses automatic systems of data collection, such as cookies. A cookie is a device transmitted to the hard disk of a user. Cookies do not contain intelligible information but allow linking between you and your personal information, such as your IP address and other information about your experience on the website. The information and data are gathered directly and automatically by the website. We process information collected by cookies in a collective and anonymous way in order to optimize the website for the needs and preferences of the users. Please access the information on your Internet browser if you wish to delete cookies after using the website. If you have started the procedure of deleting cookies, we can’t ensure that all of our web pages will be displayed and that all of our services will be available to you.

We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses cookies to help a website’s operator analyse how users use the site. The non-personal information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers located around the world. Google will use this information for evaluating your use of the website, compiling reports on website activity for website operators, and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by them. You may refuse the use of cookies by selecting the appropriate settings in your web browser; however, please note that if you do this, you may not be able to use the full functionality of the website. By using the website, you consent to the processing of data about you by Google in the manner and for the purposes set forth above.

Google Analytics collects information anonymously. It reports website usage trends without identifying individual visitors. You can opt out of Google Analytics without affecting how you use the website. For more information on opting out of being tracked by Google Analytics across all websites you use, visit https://support.google.com/analytics/answer/181881. For more information on the Google Privacy Policy, visit https://policies.google.com/privacy.

 

Information we collect from you when you apply for a job

We process the information you provide in your curriculum vitae, in our application form and supporting documentation/information during the recruitment process purely for the purposes of assessing your suitability for the role, for contacting you to progress your application and to take up any references you have provided. The basis for the processing of this information is that a potential employment contract may be concluded, depending on the outcome of our assessment and we have a legitimate interest in finding candidates for roles that we have. In the event that you are successful, this data will form part of your employee file.

 

Processing, protecting and transferring personal information

Personal information held by us is processed by appropriate members of staff for the purposes for which the information was provided. We may share your personal information within our organisation and outside the country of your residence with including:

  • With our donors
  • With our partners
  • With beneficiaries
  • With volunteers

We may share your information with third parties such as professional advisors such as accountants and lawyers, IT Providers, email providers, HR providers and government bodies/regulators.

We share your information for the purposes of:

  • Complying with a legal obligation;
  • Performing the contract we have with you; or
  • Our legitimate interest in the effective running of our organisation.

All our third party service providers and partners are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third party service providers to use your personal information for their own purposes. We only permit them to process your personal information for specified purposes and in accordance with our instructions.

We may disclose your personal information to a prospective buyer or seller in the event that we intend selling or buying any of our business or assets.

 

Retention of your Data

We will not retain your personal information longer than the period for which it is needed and in compliance with applicable law. We determine retention periods in respect of information we hold based on:

  • Legal obligations relating to minimum periods to retain data;
  • The purposes for which we process the personal information and whether we can achieve those purposes through other means;
  • Whether the information is required for reporting and analysis purposes relating to our operations;
  • The amount, nature, and sensitivity of the personal information;
  • The potential risk of harm from unauthorised use or disclosure of the personal information.

 

General Description of Information Security Measures

We take appropriate technical and organisational steps to ensure the security of your personal information including policies and procedures around use of technology and devices, IT security, document retention and destruction and data breach procedures. Only persons within our organisation which require your personal information for the performance of their work have access to that information and we do not transfer your information outside of the organisation or your resident country unless we are satisfied that the personal information will be afforded an equivalent level of protection.

We employ up to date technology to ensure the confidentiality, integrity and availability of the personal information under our care. Measures include, but are not limited to:

  • Virus protection software and update protocols.
  • Encryption where possible.
  • Electronic and physical access control.
  • Secure setup of hardware and software making up the IT infrastructure.
  • Outsourced service providers who process personal information on behalf of us are contracted to implement security controls.
  • Policies and procedures are implemented to ensure the security of your information.
  • Ongoing security awareness training of employees and contractors.

 

Your rights in relation to your information

Subject to certain limitations on certain rights, you have the following rights in relation to your information:

  • Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
  • Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Withdraw consent to our use of your information at any time where we rely on your consent to use or process that information. Please note that if you withdraw your consent, this will not affect the lawfulness of our use and processing of your information on the basis of your consent before the point in time when you withdraw your consent.

Should you have any queries regarding this privacy notice or would like to enforce any rights you may have under applicable data protection laws, please contact us at:

Melizsa Mugyenyi: privacy@gracamacheltrust.org

 

We will endeavour to respond to any such requests as soon as is reasonably practicable and in any event within statutory time-limits in the applicable country. In some instances, we may be able to charge a fee for responding to your request and will advise you of this and any applicable amount prior to responding.

You should be aware that certain information is exempt from the right of access. This may include information which identifies other individuals, or information which is subject to legal privilege. 

You should also be aware that in some instances, if you do not provide information or you exercise any rights regarding the deletion or restriction of your information or object to the processing of your information or withdraw consent, we may not be able to perform the contract we have with you or comply with our legal obligations.

Where you request access to your information, we are required by law to use all reasonable measures to verify your identity before doing so. These measures are designed to protect your information and to reduce the risk of identity fraud, identity theft or general unauthorised access to your information.

You also have the right to lodge a complaint with the relevant supervisory authority, details of which are set out below:

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

P.O Box 31533, Braamfontein, Johannesburg, 2017

Complaints email: complaints.IR@justice.gov.za

General enquiries email: inforeg@justice.gov.za.

 

Automated decision-making 

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

We do not envisage that any decisions will be taken about you using automated means, however, we will notify you in writing if this position changes.

 

Changes to our Privacy Notice

Any changes made to this privacy notice in the future will be posted on the website and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to this notice.