Kleynox takes the privacy and security of personal information very seriously. Thus, we have implemented multiple policies, procedures, and technical safeguards to protect your data from unauthorised access, use, disclosure, and destruction. We also comply with applicable data protection laws, including the Protection of Personal Information Act, 2013 in South Africa.
Collection and use of personal information.
We collect and use your personal information only for the purposes for which it was collected, and we obtain your consent for any additional purposes. We do not sell or disclose your personal information to third parties for marketing purposes without your consent. We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
Storage of personal data.
All personal and sensitive data is stored securely on encrypted servers that are regularly updated and maintained to ensure the highest level of security. Access to personal and sensitive data is limited to authorized personnel only and is subject to strict access controls and monitoring. We also ensure that personal and sensitive data is not retained for longer than necessary and is disposed of securely in accordance with our data retention and disposal policies.
Security of personal information.
We have implemented technical and organisational measures to protect your personal information from unauthorised access, use, disclosure, or destruction, including encryption, firewalls, access controls, and employee training. We regularly review and update our security measures to ensure they remain effective.
Breach response plan.
In the event of a data breach, we will take the following steps to mitigate the impact and notify affected individuals and regulatory authorities:
Identify and contain the breach: We will immediately investigate and contain the breach to prevent further unauthorized access or disclosure of personal information.
Assess the risk: We will assess the nature and extent of the breach, including the types of personal information involved, the number of individuals affected, and the potential harm or impact.
Notify affected individuals: If we determine that the breach poses a high risk of harm to individuals, we will notify affected individuals as soon as possible, providing them with information on the nature of the breach, the types of personal information involved, and the steps they can take to protect themselves.
Notify regulatory authorities: If the breach poses a high risk of harm to individuals or is required by law, we will notify the relevant regulatory authorities as soon as possible, providing them with information on the nature of the breach, the types of personal information involved, and the steps we are taking to mitigate the impact.
Review and update our policies and procedures: We will review and update our privacy policies and procedures to prevent similar breaches from occurring in the future.
