Privacy Policy
WiMSA Data Privacy and Protection Policy
1. Introduction
Women in Mining South Africa (“WiMSA”, “we”, “us” or “our”) is committed to protecting the privacy and personal information of its members, event attendees, partners, stakeholders and website users.
This policy explains how WiMSA collects, uses, stores, shares and protects personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (“POPIA”) and, where applicable, the General Data Protection Regulation (“GDPR”).
By registering as a WiMSA member, attending a WiMSA event, subscribing to our communications or otherwise providing us with personal information, you acknowledge that your information may be processed in accordance with this policy.
2. Personal information we collect
Depending on your relationship with WiMSA, we may collect and process information including:
-
first name and surname;
-
email address;
-
mobile or business telephone number;
-
organisation, job title and industry information;
-
physical or postal address;
-
membership information;
-
event registration and attendance information;
-
communication preferences;
-
payment or billing information, where applicable;
-
photographs, video recordings or other event-related content, where notice has been provided;
-
correspondence and enquiries submitted to WiMSA; and
-
any other information you voluntarily provide to us.
We aim to collect only the information reasonably necessary for the purpose for which it is required.
3. How we collect personal information
We may collect personal information:
-
directly from you when you register, subscribe, attend an event, complete a form or contact us;
-
through our website, registration platforms, surveys, email communications and event-management tools;
-
from WiMSA committee members, service providers or authorised representatives where appropriate;
-
from publicly available sources; or
-
from partner organisations where you have consented to the sharing of your information.
-
4. Why we use personal information
WiMSA may process personal information for the following purposes:
-
administering membership;
-
managing event registrations and attendance;
-
communicating event, membership and organisational information;
-
responding to enquiries and requests;
-
issuing invoices, receipts or payment confirmations;
-
sending newsletters, updates and promotional communications where permitted;
-
maintaining membership, stakeholder and event records;
-
improving our programmes, events, communications and services;
-
conducting surveys, reporting and internal analysis;
-
complying with legal, regulatory and governance obligations;
-
protecting the rights, safety and interests of WiMSA and its community; and
-
preventing or investigating misuse, fraud or unlawful activity.
WiMSA will not use personal information for a purpose that is materially different from the purpose for which it was collected unless there is a lawful basis to do so.
5. Legal basis for processing
WiMSA processes personal information where:
-
you have provided consent;
-
processing is necessary to provide a service, membership benefit or event you requested;
-
processing is necessary to perform or enter into an agreement;
-
processing is required by law;
-
processing is necessary to protect a legitimate interest of WiMSA or a third party, provided that your rights are not unfairly affected; or
-
another lawful basis applies under POPIA or other applicable legislation.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent will not affect processing that lawfully took place before the withdrawal.
6. Marketing and communications
WiMSA may send members, subscribers and event participants information about WiMSA activities, events, programmes, opportunities and related initiatives.
You may unsubscribe from marketing communications at any time by using the unsubscribe option provided or by contacting WiMSA.
WiMSA will not provide your personal information to sponsors, partners or other third parties for their own direct marketing purposes unless:
-
you have been clearly informed of the intended use;
-
you have expressly consented to the sharing; or
-
another lawful basis permits the disclosure.
Consent to receive communications from WiMSA does not automatically constitute consent to receive marketing communications from a sponsor, partner or third party.
7. Sharing personal information with third parties
WiMSA may share personal information with trusted service providers that assist us with:
-
website hosting;
-
event registration and management;
-
email distribution;
-
data storage;
-
payment processing;
-
accounting and administration;
-
marketing and communications; and
-
technical support.
These service providers may process information only for the purpose of providing services to WiMSA and must apply appropriate confidentiality, security and data-protection safeguards.
WiMSA may also disclose personal information:
-
where required by law, regulation or court order;
-
to regulatory, law-enforcement or government authorities;
-
where necessary to protect the rights, safety or interests of WiMSA or another person;
-
in connection with legal proceedings;
-
where you have expressly consented to the disclosure; or
-
where another lawful basis permits the disclosure.
WiMSA will not sell personal information.
8. Event sponsors and partners
WiMSA may acknowledge and promote event sponsors and partners through its own communication channels.
Where a sponsor or partner wishes to contact attendees directly, WiMSA will obtain the appropriate consent before sharing attendee contact information, unless another lawful basis clearly applies.
Attendance at a WiMSA event does not automatically authorise a sponsor or partner to contact an attendee for marketing or sales purposes.
9. Storage and security
Personal information may be stored electronically or in physical form, including within:
-
email systems;
-
spreadsheets and documents;
-
cloud-storage platforms;
-
event-registration systems;
-
membership databases;
-
accounting systems;
-
communication and mailing platforms; and
-
secure physical records.
WiMSA takes reasonable technical and organisational measures to protect personal information against loss, unauthorised access, misuse, alteration, disclosure or destruction.
Access to personal information is limited to authorised individuals who require it for legitimate WiMSA purposes.
10. Data breaches and security incidents
WiMSA will investigate any suspected loss, unauthorised disclosure, access or misuse of personal information.
Where required by law, WiMSA will notify the Information Regulator and affected individuals as soon as reasonably possible after becoming aware of a security compromise.
WiMSA may also require any service provider, sponsor, partner or third party involved in an incident to:
-
stop processing the information;
-
provide details of the affected records;
-
preserve relevant evidence and audit logs;
-
delete or return the information; and
-
provide written confirmation of the corrective action taken.
-
11. Data retention
WiMSA will retain personal information only for as long as reasonably necessary to fulfil the purpose for which it was collected or to meet legal, regulatory, financial, reporting or governance requirements.
Certain records may be retained for up to seven years or for another period required by law.
When personal information is no longer required, WiMSA will take reasonable steps to delete, destroy or de-identify it securely.
12. Your rights
Subject to applicable law, you may have the right to:
-
request access to the personal information WiMSA holds about you;
-
request correction or updating of inaccurate information;
-
request deletion of information where WiMSA is not legally required to retain it;
-
object to certain processing activities;
-
withdraw consent;
-
request restriction of processing;
-
request information about third parties that have received your personal information;
-
unsubscribe from marketing communications; and
-
lodge a complaint with the Information Regulator or another applicable supervisory authority.
WiMSA may request proof of identity before responding to a request.
13. Cross-border processing
Some WiMSA service providers may store or process personal information outside South Africa.
Where this occurs, WiMSA will take reasonable steps to ensure that appropriate safeguards are in place and that the information receives an adequate level of protection.
14. Privacy responsibilities
WiMSA committee members, employees, contractors, volunteers and service providers who have access to personal information must handle it confidentially and only for authorised purposes.
Personal information, including event attendee and membership lists, may not be shared with sponsors, partners or third parties without appropriate authorisation and a lawful basis.
15. Changes to this policy
WiMSA may update this policy from time to time to reflect changes in legislation, operations or data-processing practices.
The latest version will be made available through WiMSA’s website or other appropriate communication channels.
16. Contact and complaints
Questions, requests or complaints relating to this policy or WiMSA’s handling of personal information may be submitted to WiMSA through its official contact channels.
Individuals also have the right to lodge a complaint with the Information Regulator of South Africa.
17. Governing law
This policy is governed by the laws of the Republic of South Africa.
Any dispute arising from this policy will be dealt with in accordance with applicable South African law.