[vc_row][vc_column][vc_column_text css=””]Mapesu Private Game Reserve
POPIA Compliance Manual
Effective Date: 18 August 2025
Last Updated: 19 August 2025
- Introduction
Mapesu Private Game Reserve (“Mapesu”, “we”, “us”, or “our”) is committed to protecting the privacy and personal information of all our guests, employees, and stakeholders. This manual outlines our policies and procedures in accordance with the Protection of Personal Information Act (POPIA) 4 of 2013, South Africa, and where applicable, the General Data Protection Regulation (GDPR) of the European Union.
The purpose of this manual is to guide Mapesu staff and partners on the correct handling, processing, storage, and protection of personal data to ensure full compliance with POPIA and relevant international laws.
- Definitions
- Personal Data: Any information that identifies or can identify a living individual (e.g., name, contact details, ID numbers).
- Processing: Any operation performed on personal data, including collection, storage, usage, and sharing.
- Data Subject: The individual whose personal data is processed (e.g., guests, employees).
- Data Controller: The entity (Mapesu) that determines why and how personal data is processed.
- Service: All services provided by Mapesu, including website, bookings, and lodge operations.
- Service Providers: Third-party vendors who process data on our behalf (e.g., payment gateways, marketing platforms).
- Accountability & Governance
- Mapesu appoints a Chief Privacy Officer responsible for overseeing POPIA compliance and privacy governance.
- All staff handling personal data will receive appropriate POPIA and GDPR training.
- Regular audits and reviews of data protection practices will be conducted.
- Data Collection
We collect personal data through:
- Direct bookings via website, email, or phone.
- Third-party booking platforms.
- Communication with guests and visitors (emails, phone calls).
- Website interactions including cookies and analytics tools.
- Public sources (e.g., tagged social media posts).
Categories of Personal Data Collected:
- Personal details (name, gender, DOB, nationality).
- Identification numbers (ID, passport, driver’s license).
- Contact details (email, phone, emergency contacts).
- Booking & travel data (stay dates, preferences).
- Technical data (IP address, browser type, website usage).
- Purpose and Legal Basis for Processing
Mapesu processes personal data for the following reasons:
- To fulfil booking and contractual obligations.
- To respond to enquiries and provide customer service.
- To send marketing and promotional communications (with consent).
- To improve our website and service experience.
- To comply with legal, tax, and regulatory obligations.
- To ensure security and safety of guests and staff.
Legal basis includes:
- Consent of the data subject.
- Performance of contract.
- Compliance with legal obligations.
- Legitimate interests, balanced against individual rights.
- Data Sharing and Disclosure
We share personal data only with:
- Payment processors (e.g., PayGate, Stripe).
- Booking platforms and travel agents.
- Marketing and email service providers (e.g., Mailchimp).
- Legal, accounting, and government authorities where legally required.
- Third-party service providers such as tour guides or transport companies.
All third parties are bound by confidentiality and must comply with POPIA and applicable laws.
- International Transfers
- Data may be transferred outside South Africa (e.g., to service providers abroad).
- Transfers comply with Section 72 of POPIA and applicable GDPR safeguards (e.g., Standard Contractual Clauses).
- We ensure data protection measures are adequate in destination countries.
- Data Retention
- Personal data is retained only as long as necessary to fulfil the purpose, comply with law, or resolve disputes.
- Retention periods comply with South African statutory requirements.
- Data subjects may request deletion, subject to legal or contractual constraints.
- Data Security
- We implement physical, technical, and administrative security measures, including:
- Secure servers and firewalls.
- Role-based access controls.
- Encrypted communication where applicable.
- We acknowledge no internet transmission is entirely risk-free and strive to mitigate vulnerabilities.
- Data Subject Rights
Individuals have the right to:
- Access their personal data.
- Correct or update inaccurate or incomplete data.
- Request deletion of data within legal boundaries.
- Object to or restrict processing.
- Withdraw consent at any time for marketing communications.
- Lodge complaints with Mapesu or the Information Regulator.
Requests should be directed to:
📧 bookings@mapesu.com
If unsatisfied, complaints can be escalated to:
Information Regulator South Africa
📧 inforeg@justice.gov.za
🌐 https://www.justice.gov.za/inforeg
- Cookies and Tracking
- We use cookies and tracking technologies to improve user experience and analyse traffic.
- Users can control cookie settings through their browser.
- For full details, see our Cookie Policy.
- Staff Training and Awareness
- Regular training on POPIA and GDPR for all relevant personnel.
- Clear instructions on data handling, security, and breach reporting.
- Breach Management
- Procedures for identifying, reporting, and managing data breaches.
- Notification of affected data subjects and the Information Regulator as required by law.
- Updates to This Manual
- This manual will be reviewed and updated regularly to reflect legal developments or operational changes.
- Employees will be notified of material changes.
- Contact Information
Chief Privacy Officer
Mapesu Private Game Reserve
📧 bookings@mapesu.com
📍 R572 Pontdrif Road, Musina, 0900, South Africa
🌐 https://mapesu.com
[/vc_column_text][/vc_column][/vc_row]
