1.2. This Policy applies to any and all interactions with us where we process Personal Information including your use of any of our websites, mobi-sites, any online application software that is provided by EGG that you install or download from an online application store and access via a mobile device (“EGG App”), our free Wi-Fi service or engaging with us telephonically or in person and forms part of our agreement with you. You should read it along with the terms and conditions that apply. By visiting or using our website and/or EGG App or using any other Communication Channels (as defined in terms of clause 3.2 below), you agree to the terms of this Policy as updated from time to time and consent to the processing of your Personal Information by EGG on the basis set out herein. We will let you know of any material changes to the Policy.
2. RESPONSIBLE PARTY
2.1. EGG will be the party who will be collecting and processing your Personal Information and is the responsible party for the purposes of this this Policy. EGG’s contact details are:
EGG’s Head Office is located at:
Shop F40, Cavendish Connect,
Dreyer Street, Claremont,
Cape Town 7708
Tel: 021 493 2891
Email: [email protected]
Information Officer: Paul Simon
2.2. EGG may instruct third party operators from time to time to undertake certain processing activities relating to your Personal Information. We will ensure that any contract entered into with any such third party operator include the following obligations:
2.2.1. the operator shall not process any personal information without our knowledge and authority;
2.2.2. the operator shall treat all Personal Information given to it as confidential and shall not disclose it to any unauthorised third parties;
2.2.3. the operator shall establish and maintain adequate security measures which are the same or offer similar protection over the Personal Information as that employed by us;
2.2.4. the operator shall notify us immediately where there are reasonable grounds to believe that any Personal Information has been leaked to or accessed by any unauthorised person;
2.2.5. if the operator is situated in another country, it must comply with the data protection laws in that country and be able to provide verification that it is so compliant;
2.2.6. if an operator is legally obliged to disclose any Personal Information processed by them on our behalf to other parties, it must notify us beforehand to enable us and/or individual users to protect their rights if necessary.
3. SCOPE OF THE POLICY
3.1. This Policy applies to all data subjects (persons, whether a natural or juristic person, to whom the Personal Information relates) (“you”, “your”), whose Personal Information we collect.
3.2. This Policy applies to all Personal Information, whether it was provided to us through our websites, EGG Apps or through any other form of communications with you such as email, WhatsApp, social media, telephone, or otherwise (“Communication Channels”), through or by third parties or tools that collect Personal Information.
4. PERSONAL INFORMATION COLLECTED BY US
4.1. The Personal Information we collect about you is dependent on:
4.1.1. the transaction you are completing;
4.1.2. the reason you are communicating with us; and
4.1.3. the Application used to communicate with us.
4.2. Personal Information collected by us may include your:
4.2.1. name and surname,
4.2.2. contact information including e-mail address, postal address, physical address, mobile number;
4.2.3. date of birth;
4.2.4. biometric information (for us to identify you when you contact us);
4.2.5. billing information;
4.2.6. information relating to your personal preferences, interests and opinions, a record of the date and time you visited any of the EGG stores, a record of your visits to a Geofence, provided location services are enabled and the App is installed on your device, your dwell time within the EGG store and Geofences. For the purposes hereof, a “Geofence” is a virtual geographic boundary, defined by GPS or RFID technology, that enables software to trigger a response when a mobile device enters or leaves a particular area.
4.2.7. Data collected when accessing specific store content. If you click on specific content, we record that. If the content is interactive, and permits you to choose from multiple options, we record your choices;
4.2.8. Data collected regarding permissions: If you enable Bluetooth, push notification or macro location (Geofence) permissions, the APP posts that to our content management system (CMS) for analytical analysis;
4.2.9. additional information which we are required or permitted by applicable legislation to collect and process, as well as any additional information you may choose to provide to us, publicly through social media or any other customer forums.
4.3. Supplying this personal information to EGG is voluntary and not mandatory. However, your failure to provide this personal information may prevent you from using all the services and/or features available on the Website and/or EGG Apps properly.
4.4. Personal Information excludes:
4.4.1. information that has been made anonymous so that it does not identify a specific person;
4.4.2. permanently de-identified information that does not relate or cannot be traced back to you specifically; and
4.4.3. non-personal statistical information collected and compiled by us.
5. ACCEPTANCE AND CAPACITY
5.1. You must accept all the terms of this Policy when you order any of our Goods (as defined in our Terms and Conditions) or, register for, or use our website or EGG App or any of our services. By accepting this Policy, you are deemed to have read, understood, accepted, and agreed to be bound by all of its terms.
5.2. Only persons aged 18 years or older may engage with any of our Communication Channels. To the extent required by any applicable law, users under the age of 18 years must obtain the consent of a parent or guardian. We will afford the same level of protection to all Personal Information processed, regardless of the age of the person the Personal Information pertains to.
6. WHERE DO WE COLLECT PERSONAL INFORMATION FROM
6.1. As far as possible, we will always collect personal information about you directly from you, except in the following circumstances:
6.1.1. Where personal information about you is collected from a public record, or from another source if the information has already been made public by you or on your behalf with your consent;
6.1.2. where you have given us your express consent to collect your personal information from another source;
6.1.3. where the collection of your personal information from another source will not prejudice any of your legitimate interests;
6.1.4. where the collection of personal information from another source is necessary to maintain our legitimate interests or those of any third party we are permitted to share that information with;
6.1.5. where the collection of personal information directly from you would prejudice the purpose for that collection; or
6.1.6. where the collection of personal information directly from you is not reasonably practicable in the circumstances.
7. WHEN DO WE COLLECT YOUR PERSONAL INFORMATION?
7.1. We collect your Personal Information when you:
7.1.1. browse, visit or participate in our various Communication Channels;
7.1.2. register an online profile or complete any forms on our websites and/or EGG App;
7.1.3. purchase Goods on our website and/or EGG App;
7.1.4. purchase, return, exchange or enquire about Goods and services from us;
7.1.5. voluntarily provide us with information when you interact with us, for example when you make general enquiries either on line, in person, through the EGG App or telephonically, lodge complaints, and communicate with us, or you subscribe to or consent to receiving newsletters or other communications from us;
7.1.6. apply for vacancies on our Careers portal by submitting your cv and thereafter should you be employed by EGG;
7.1.7. apply to be an EGG supplier or partner on our Partners portal by submitting your application and thereafter should you be accepted as a partner by EGG;
7.1.8. Follow specific EGG partners or activate certain functionality offered on the App;
7.1.9. subscribe for a service, enter into a competition or promotion or participate in a survey offered via the App, social media or our website;
7.1.10. participate in any of our events.
7.2. From time to time we may collect your Personal Information from trusted third parties, in such event we will ensure that you have provided your consent to those third parties for your Personal Information to be disclosed to us.
7.3. We do not collect or retain the bank card details used by you to purchase Goods or services for us. This information is collected by financial institutions that have their own privacy policies. If you receive emails, that appear to be from us, requesting bank card details, you are advised not to respond, as this request is most likely fraudulent and should be reported to us immediately.
We do not collect your Personal Information when using cookies about when and how you use our websites or when you click on an advert of ours that is on another website. A cookie is a small text file that is stored on your computer or mobile device when you use it. Cookies hold information such as the identity of the computer or device you used to access our Communication Channels, your server address, domain name, the time and date that you visited our Communication Channels, pages, product and documentation that you accessed or viewed and which internet browser you used.
We do this so that we can:
8.1. provide you with more personalised service, communication and products by better understanding your browsing and purchasing behaviour;
8.2. track, count and analyse website visits and usage data;
8.3. understand product preferences and popularity; and
8.4. provide you with a better website and improve your online shopping experience.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. You can also delete cookies manually. However, no longer accepting cookies or deleting them may prevent you from taking full advantage of the website. You can find out more about cookies at www.allaboutcookies.org.
9. THIRD-PARTY SERVICES
We use trusted third-party services including Google Analytics and Flurry that collect, monitor and analyse our users’ usage. To prevent your Personal Information from being used by Google Analytics and/or Flurry you can install an opt-out browser add-on (visit https://tools.google.com/dlpage/gaoptout for details).
Most web browsers can be adjusted to inform you when a cookie has been sent to you and provide you with the opportunity to refuse that cookie. Refusing a cookie may, in some cases, prevent you from taking full advantage of, or negatively impact, the display or function of our websites or certain areas or features of our websites.
You may only send us your own personal data or the information of another data subject where you have their permission to do so.
10. RECORDING CALLS AND CCTV SYSTEMS
We may monitor and record any telephone calls that occur between EGG and yourself, including when you contact any to our head office. We record calls for quality control and record keeping purposes. When you contact our head office, the information that we collect from you will be used to investigate and resolve your query, complaint or request and/ or to meet any regulatory requirement.
We may also record your movements where we have CCTV systems in our stores.
11. REASONS WHY WE PROCESS YOUR PERSONAL INFORMATION
11.1. We collect and process your Personal Information to:
11.1.1. to enter into a contract with you;
11.1.2. to perform our obligations under a contract with you;
11.1.3. to provide our products and services to you, this includes, processing your payment card details in order to complete any purchase, delivering Goods that you order from our website or EGG App, sending statements and any other legal documents and for any other purpose relating to providing our products and services to you;
11.1.4. to communicate with you regarding new product features, personalised products, services, offers and events that we think may be of interest to you;
11.1.5. to analyse, develop, continually improve and enhance the use, functionality and performance of our websites, EGG App products and services to manage the security of our sites, networks and systems;
11.1.6. to comply with our legal obligations;
11.1.7. for direct marketing purposes (unless you have opted out of receiving any such direct marketing material)
11.1.8. for credit reporting purposes;
11.1.9. to protect your legitimate interests (unless you have specifically objected in writing to all or some of such processing activities on reasonable grounds);
11.1.10. to comply with applicable laws, including our obligations to make disclosures to authorities, regulators and government bodies; and
11.1.11. to engage in our legitimate business, related interests, and legal purposes, including but not limited to detecting and preventing fraud and conducting our business;
11.1.12. to present content to you in the most effective way, for you and for your device and/or browser;
11.1.13. to customise and display content including, but not limited to products, articles, listings and advertisement to you according to your interests or in any other manner most beneficial to you;
11.1.14. to send content including, but not limited to products, articles, listings and advertisement content to you via the App, or by email or other electronic media, where you have chosen to be contacted by EGG with such content;
11.1.15. to enable you to voluntarily participate in interactive features on the EGG App;
11.1.16. to notify you about changes to the website and/or EGG App;
11.1.17. to contact you for purposes relating to your use of the website, App or any of the Communication Channels;
11.1.18. to collect technical information regarding the use of the website and/or EGG App, which information is aggregated for analytical purposes, technical maintenance and for improving the functionality and content offered on the websites and/or EGG App.
11.3. We will not use your Personal Information other than for the purpose for which it was provided or collected, and in accordance with our legitimate interests and legal obligations.
11.4. TRANSFERRING YOUR PERSONAL INFORMATION
Your Personal Information will be processed mainly in South Africa, however it may be transferred to countries outside of South Africa, for example where we make use of cloud based software services, in which case we will ensure that the necessary security measures are in place relating to the processing and storage of your Personal Information.
12. WHEN WE WILL DISCLOSE OR SHARE YOUR PERSONAL INFORMATION
12.1. We may provide access to or share some of your Personal Information, when necessary and for the reasons that it was provided or collected, to:
12.1.1. our merchandise suppliers, service providers, auditors, constants and agents that help us to provide our services to you and who are required under contract to process it for us or to provide services for or to us, including product deliveries and returns, e-mail service providers, analytics companies, distribution and courier companies, information hosting, communication providers, development and administration, information technology and related infrastructure services, technical support and other support services relating to our legitimate business interests and our contractual obligations to you (our contracts with our merchandise suppliers or Partners dictate that these merchandise suppliers or service providers comply with all data protection legislation applicable to them);
12.1.2. credit bureaus to report account information, as permitted by law;
12.1.3. banking partners as required by credit card association rules for inclusion on their list of terminated merchants (in the event that you utilise the services to receive payments and you meet their criteria); and
12.1.4. other third parties who provide us with relevant services where appropriate.
12.2. CHANGE OF OWNERSHIP
We may share Personal Information with third parties in the event of a reorganisation, merger, sale, joint venture, assignment, transfer or other type of sale of all or any portion of our business, assets or stock.
12.3. REGULATORS AND LAW ENFORCEMENT
We may provide access to or share your Personal Information as required by law, court order or other lawful reasons, where we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to government requests, including public and government authorities.
When we share or provide access to your Personal Information with third parties, they are contractually restricted from using or disclosing your Personal Information except as necessary to perform services on our behalf or to comply with legal requirements.
12.4. NO SELLING OF PERSONAL INFORMATION
We will not sell your Personal Information. No Personal Information will be disclosed to anyone except as provided for in this Policy.
13. ACCURATE AND UP TO DATE
We will try to keep the Personal Information we collect as accurate, complete and up to date as is necessary for the purposes defined in this Policy. From time to time, we may request you to update
your Personal Information. Where the Personal Information has been shared by EGG with a third party and subsequently updated or corrected, we shall ensure that all third parties with whom that information was shared receives the updated and/or corrected version of the information as soon as it has been updated or corrected.
14. STORAGE, RETENTION AND DELETION OF PERSONAL INFORMATION
14.1. We will keep your Personal Information for different periods of time depending on the use or purpose your Personal Information was provided or collected for, as well as your preferences regarding marketing, recruitment and other correspondence.
14.2. We will only keep your Personal Information for as long as necessary to fulfil the purposes set out in this Policy, unless:
14.2.1. retention of the Personal Information is required or authorised by law; or
14.2.2. you have consented to the retention of the Personal Information.
14.3. We will safely delete or destroy Personal Information which we are no longer required or not permitted to retain, or for which we do not have your consent.
15. SECURING YOUR PERSONAL INFORMATION
We take the security of personal data very seriously and always do our best to comply with the applicable data protection laws. We secure the integrity and confidentiality of your Personal Information that is in our possession and under our control by taking the appropriate reasonable technical and organisational measures to prevent loss, damage, unauthorised destruction, unlawful access, or unlawful processing of your Personal Information. We authorise access to Personal Information only for those employees who require it to fulfil their job responsibilities. In doing so we have due regard to generally accepted industry information security practices and procedures.
16. YOUR RIGHTS
16.1. You have the following rights in respect of your Personal Information that we process:
16.1.1. you may ask us (at no cost) whether we hold your Personal Information, (we will only provide you with this information when you provide us with satisfactory proof of your identity) and where that is the case, you have the right to request and get access to the personal information;
16.1.2. where necessary, request that your Personal Information be updated, corrected or deleted (partially or completely);
16.1.3. object to, restrict or limit the processing of your Personal Information;
16.1.4. object to the use of your Personal Information for the purposes of direct marketing;
16.2. You can exercise any of your rights listed in 6.1.1 - 6.1.4 above by sending an email to [email protected]. Where we have reasonable doubt as to the identity of the person making an enquiry we may request additional information to confirm the identity of the person, such as an identity document, including a driver’s licence or passport.
16.3. Please note that the above rights are not absolute, and we may be entitled to refuse requests where exceptions apply. Should we determine that you are not entitled to exercise a specific right, we will provide you with the reasons why.
16.4. Should we have reasonable grounds to believe that your Personal Information has been accessed or acquired by any unauthorised person, we will, as soon as is reasonably possible and lawfully required, notify the applicable regulator, as well as yourself, unless we are unable to establish the identity of the Personal Information that has been unlawfully accessed.
17. LIMITATION OF LIABILITY
We are not responsible for, give no warranties, nor make any representations in respect of the privacy policies or practices of linked or any third-party websites.
18. DIRECT MARKETING
18.1. You hereby consent to the processing of your personal information for the purpose of direct marketing by means of electronic communications including automatic calling machines, facsimile machines, SMS’s or electronic mail.
18.2. You may object, free of charge, and without unnecessary formality, to the use of your details for direct marketing purposes, either when the information was first collected from you or on receipt of any electronic communication sent to you by EGG.
18.3. You may also opt out of receiving further marketing communications by un-checking certain boxes on the Website or EGG App, or by contacting EGG at [email protected].
20. DISPUTE RESOLUTION OR LODGING A COMPLAINT
20.1. Should you have any concerns relating to our Policy you may email your concerns to [email protected] We will review your concerns and attempt to resolve any complaint relating to the protection of Personal Information, in this Policy and applicable law.
20.2. We will acknowledge your request as required under applicable data protection laws. However, the rights mentioned in this Policy are not absolute: the rights do not always apply, and exemptions may be applicable. We will ask you to verify your identity and/or ask you information to assist us in better understanding your request. In the event we do not comply with your request, we will give you reasons why.
20.3. You may also lodge a complaint with the Information Regulator (South Africa), whose contact details are:
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2017
PO Box 31533
Braamfontein, Johannesburg, 2017
Complaints email: [email protected]
General enquiries email: [email protected].
21. CHOICE OF LAW
This Policy shall be governed and interpreted in accordance with the laws of the Republic of South Africa.