SOUTH AFRICAN DATA PROTECTION
POPIA Notice.
A practical section 18 style notice explaining who processes personal information, why it is processed and the choices available to data subjects.
CommExcellence processes information for the purposes described here.
CommExcellence operates from South Africa and acts as the responsible party for the website processing described in this notice unless a feature identifies another responsible party.
Privacy, POPIA and information access enquiries can be sent to gideon@commexcellence.com. The legal entity, Information Officer registration and PAIA Manual applicable to the operating body must be maintained and made available as required by South African law.
Who the processing can relate to.
Data subjects may include Scorecard participants, research participants, Commercial Signal subscribers, website visitors, commenters, publication readers, prospective advertisers or partners, business contacts, suppliers and future CXC participants.
Records may include identity and contact details, professional context, Scorecard answers and results, research segment information, subscription and consent records, messages and comments, partnership enquiries, access records, security and technical logs, and CXC activity if that system is enabled.
The information is connected to a defined service or obligation.
- Calculate, display and email Commercial Scorecard results and reports.
- Build and publish aggregated research about commercial patterns, strengths, gaps and recurring problems.
- Administer Commercial Signal subscriptions and send communications requested by the subscriber.
- Provide publication access, moderate comments and respond to website, research and advertising enquiries.
- Operate and secure future CXC participation features, including eligibility and misuse controls, if enabled.
- Maintain records, investigate incidents, enforce terms, comply with legal obligations and protect legitimate rights.
POPIA permits processing in defined circumstances.
Depending on the activity, processing may be based on consent, necessity to carry out a request or agreement with the data subject, compliance with law, protection of a legitimate interest, the legitimate interests of CommExcellence or a third party, or another ground permitted by POPIA.
Where consent is the basis, it should be specific enough for the purpose and capable of being withdrawn. Withdrawal does not invalidate processing that was lawful before withdrawal.
Automated scoring is diagnostic, not a legally significant decision.
The Scorecard applies automated scoring logic to participant answers to generate a diagnostic result. It is not intended to make a decision that produces legal consequences or similarly significant effects concerning the participant.
Research may analyse Scorecard responses and disclosed context in aggregate. Public findings are intended to avoid identifying individual participants. Early or small samples should be labelled with appropriate limitations rather than presented as established market benchmarks.
Where research data is de identified rather than fully anonymised, access controls and re identification restrictions should remain in place.
Astrobot captures questions for service delivery and research analysis.
When a visitor uses Astrobot, CommExcellence may process the conversation text, Astrobot responses, page context, timestamps and derived topic or commercial-dimension classifications to provide the interaction, maintain a research record, improve the service and analyse recurring commercial challenges.
Astrobot does not require a visitor to provide a name or email address for ordinary use. If the visitor asks for a transcript to be emailed, the supplied address is processed for that requested delivery. A transcript request is not treated as consent to direct marketing. Any Commercial Signal opt in is requested separately.
CommExcellence intends to use conversation-derived research in aggregated, anonymised or appropriately de identified form. Visitors should not submit confidential, personal or commercially sensitive information in free text.
Commercial Signal consent is separate from service delivery.
Submitting a Scorecard, contact form, research response or advertising enquiry does not by itself consent to electronic direct marketing.
Commercial Signal and other electronic marketing should be sent only where section 69 of POPIA permits it, including valid consent or the limited existing customer circumstances allowed by law. Recipients must be able to identify the sender and object or unsubscribe without unnecessary difficulty.
The platform does not seek sensitive data.
CommExcellence does not intentionally request special personal information, criminal behaviour data, health information, biometric information or information about children through ordinary Scorecard and website flows.
Free text fields should not be used to submit sensitive, confidential or third party personal information unless it is genuinely necessary and lawful to do so.
Service providers may act as operators.
Authorised providers may process personal information for hosting, databases, server functions, email delivery, security, publication access and other platform operations. Operator arrangements should require appropriate confidentiality and security measures.
Where personal information is transferred outside South Africa, CommExcellence will use a transfer mechanism or safeguard permitted by POPIA section 72, taking account of the destination, provider obligations and nature of the information.
Reasonable safeguards and purpose based retention.
CommExcellence takes reasonable steps to preserve the confidentiality, integrity and availability of personal information. Security controls may include access restrictions, authenticated services, encrypted transport, logging, backups and service provider controls appropriate to the risk.
Records are kept only for as long as reasonably required by the original purpose, legal duties, research integrity, security, disputes or legitimate business records. Information that is no longer required should be deleted, destroyed or de identified where appropriate.
Security compromises involving personal information will be assessed and notified to the Regulator and affected data subjects where POPIA requires notification.
You can ask questions about your information.
Subject to the law, data subjects may request access, correction, deletion or destruction, object to certain processing, withdraw consent, object to direct marketing and complain about unlawful processing. Requests may require reasonable identity verification.
Send requests to gideon@commexcellence.com. Complaints may also be lodged with the Information Regulator. Access to records under PAIA is separate from ordinary privacy requests and may require the prescribed PAIA process.
Privacy compliance is more than a website notice.
The operating private body should maintain an up to date PAIA Manual, applicable Information Officer registration, operator arrangements, security controls, direct marketing records and internal processes for data subject requests and security incidents.
This notice will be updated when material processing changes, including new research methods, advertising technology, CXC earning, purchase or redemption functionality, payment processing, new platform tools or new categories of service providers.