Last Updated: July 1, 2026
1. INTRODUCTION
Welcome to Orange River Rafting (“we”, “us”, “our”). We are committed to protecting your privacy and ensuring that your personal information is collected, used, and stored in a lawful, fair, and transparent manner in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
By using our website or contacting us, you acknowledge that your personal information may be processed as described in this Privacy Policy.
1.1 POPIA Section 18 Notification
This Privacy Policy serves as the notification required by section 18 of the Protection of Personal Information Act 4 of 2013 (“POPIA”). The information required under section 18 is provided throughout this Privacy Policy, including details of the personal information we collect, the purposes for which it is processed, whether the provision of information is voluntary or mandatory where applicable, the consequences of failing to provide information, recipients of personal information, international transfers, and your rights as a data subject.
1.2 Your Acknowledgement
By accessing or using our website, contacting us, requesting a quotation or making use of our services, you acknowledge that you have read this Privacy Policy and understand how your personal information may be collected, used and protected.
Where your consent is required by POPIA or any other applicable law for specific processing activities, we will request that consent separately.
Your continued use of our website and services constitutes your acknowledgement of this Privacy Policy as updated from time to time.
2. SCOPE OF THIS PRIVACY POLICY (WHO IT COVERS)
This Privacy Policy applies to all individuals whose personal information we process in the course of our business operations.
This includes, but is not limited to:
- Website visitors who browse or interact with our website
- Individuals who submit contact or enquiry forms for support, enquiries, or feedback
- Guests or prospective guests making enquiries or bookings
- Guests participating in rafting excursions, events, or related recreational services
- Group organisers, tour operators, schools, corporate clients, and event coordinators making bookings on behalf of participants
- Individuals who subscribe to our marketing communications
- Job applicants, contractors, or prospective employees (where applicable)
This Privacy Policy applies to personal information collected through our website, contact forms, email communications, telephone interactions, booking enquiries, accommodation reservations, activity bookings, indemnity forms, guest registrations, and any related services operated by us.
3. KEY DEFINITIONS
To make this Privacy Policy easier to understand, the following key terms are used:
Personal Information
Any information relating to an identifiable, living natural person or juristic person, as defined under the Protection of Personal Information Act 4 of 2013 (“POPIA”).
POPIA
The Protection of Personal Information Act 4 of 2013, which regulates how personal information is collected, used, stored, and shared in South Africa.
Responsible Party
The entity that determines the purpose and means of processing personal information. In this case, Orange River Rafting.
Service Provider/ Operator
A third party natural or legal person who processes personal information on behalf of the Responsible Party under contract and instruction.
Country
Refers to the Republic of South Africa.
Device
Any electronic device used to access our services, including computers, smartphones, tablets, or similar devices.
Processing
Any operation or activity performed on personal information, including collection, storage, use, transfer, alteration, or deletion.
Consent
Any voluntary, specific, and informed expression of will in terms of which permission is given for the processing of personal information.
Services
All services provided by us, including but not limited to accommodation (chalets and camping), rafting, guided outdoor activities, adventure experiences, bookings, reservations, guest services, and our website and related systems.
Website
The official website operated by us, accessible at https://orangeriverrafting.co.za.
Account
Means a registered profile created by a user (if applicable) to access booking systems, reservations, or other online services provided by us.
Usage Data
Data collected automatically when using our website or systems, including IP address, browser type, device information, pages visited, booking interactions, and system performance data.
You / Data Subject
Any individual accessing or using our services, including guests, visitors, customers, participants, employees, contractors, or any person whose personal information we process.
4. UNDERSTANDING OUR PRIVACY PRACTICES
This Privacy Policy explains how we collect, use, and protect personal information in accordance with POPIA.
We act as the Responsible Party when processing personal information for our own business purposes, including handling enquiries, managing accommodation bookings, customer communication, marketing, and website operations.
Where we engage third-party service providers to assist in delivering our services, such providers act as Operators and process personal information on our behalf in accordance with POPIA.
5. RESPONSIBLE PARTY
The Orange River Rafting is the Responsible Party for purposes of POPIA.
Company Details
The company details are as follows:
- Orange River Rafting
- Registration Number: CK 89/029121/23
- Email Address: info@orangeriverrafting.co.za
- Telephone Number: +27 (0) 21 975 9727
Information Officer
The Information Officer is responsible for overseeing compliance with POPIA and handling all requests relating to personal information.
They are appointed in accordance with the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”).
- Name: P.W Rode
- Email: info@orangeriverrafting.co.za
- Telephone: +27 (0) 21 975 9727
6. INFORMATION WE COLLECT
What Personal Data We Collect
We collect personal information directly from you when you interact with our website or services, including when you submit a contact form, make a booking enquiry, subscribe to communications, or contact us for support.
Where required by law, or where you have given us your consent, we may process your personal information in order to provide our services, manage bookings and respond to enquiries or communicate with you regarding your stay, adventure trip or request.
6.1 Information You Provide Directly
When you interact with us directly, we may collect personal information such as:
- Full name
- Email address
- Telephone number
- Booking or accommodation enquiry details
- Arrival/departure dates (if applicable)
- Number of guests
- Messages or enquiries submitted via forms or email to our bookings or customer support team.
We collect this information to respond to your enquiries, process bookings, and provide accommodation services.
6.2 Activity, Safety and Special Personal Information
For accommodation bookings, rafting, and other outdoor activities, we may collect and process additional personal information where reasonably necessary for operational, safety, legal, insurance, emergency response, or risk management purposes.
This information may include:
- Emergency contact and next-of-kin information;
- ID or Passport details
- Date of birth or age information where required for safety, legal, or booking purposes;
- Participant registration information;
- Safety acknowledgements and indemnity forms;
- Swimming ability or fitness-related information where relevant to participation in water-based activities;
- Incident, accident, injury, or safety-related reports;
- Medical information voluntarily disclosed by guests that may be relevant to participation in activities or emergency response;
- Information relating to allergies, dietary requirements, food intolerances, disabilities, injuries, medical conditions, medication requirements, physical limitations, or other health-related information reasonably necessary for guest safety, meal planning, accommodation arrangements, or participation in activities; and
- Any other information reasonably required to facilitate participation in our services, ensure guest safety, comply with legal obligations, or respond to emergencies.
Where any of the above information constitutes Special Personal Information under POPIA, including health-related information, we will process such information only where permitted by law and where reasonably necessary for guest safety, emergency response, insurance requirements, legal compliance, risk management, participation in activities or where otherwise authorised under POPIA.
We process Special Personal Information only where:
- the data subject has consented;
- processing is necessary to protect the life or physical health of the data subject or another person;
- processing is necessary for the establishment, exercise, or defence of a legal claim;
- processing is required by law; or
- another lawful exception under POPIA applies.
We implement appropriate technical and organisational safeguards to protect such information and restrict access to authorised staff/personnel who require access for operational, safety, emergency response, legal, insurance or administrative purposes.
Where meals, catering, accommodation packages, or hospitality services are provided, we may process information relating to dietary requirements, food allergies, food intolerances, religious dietary requirements, or other relevant dietary preferences in order to prepare meals, reduce health and safety risks, accommodate reasonable guest requirements, and provide suitable alternatives where reasonably possible.
Guests remain responsible for notifying us of any dietary restrictions, allergies, intolerances, or medical conditions that may affect their participation in activities or consumption of food provided by us. While we take reasonable steps to accommodate disclosed dietary requirements, we cannot guarantee the complete absence of allergens or cross-contamination in food preparation environments.
6.3 Information About Other Individuals
In some circumstances, you may provide us with personal information relating to another individual, such as a spouse, partner, family member, dependant, employee, authorised representative, recipient of a delivery, or emergency contact.
By providing us with another person’s personal information, you confirm that you are authorised to do so and, where required by law, that you have informed the individual about the collection and processing of their personal information and have obtained any necessary consent.
We will process such personal information in accordance with this Privacy Policy and applicable data protection laws.
6.4 Information Collected Automatically
When you browse our website, we may automatically collect certain technical information about your device and browsing activity. This may include your IP address, browser type, device information, website usage activity, cookie identifiers, shopping cart activity, and referral sources.
We collect this information to understand how visitors use our website, to improve its performance and usability, and to support the proper functioning of our services.
6.5 Payment Information
Our website enables customers to submit tour, accommodation, booking, and general enquiry requests. Where online booking and payment are available, card payments are processed securely through approved third-party payment service providers. Payments may also be made by electronic funds transfer (EFT), card payment using authorised payment terminals at our base camp premises, approved third-party payment service providers, or any other payment methods that we may make available.
We do not process or store customers’ credit or debit card details. All payment card information is processed directly by the relevant payment service provider in accordance with applicable payment security standards and its own privacy policies.
For accounting, booking administration, legal compliance, fraud prevention, and record-keeping purposes, we may retain limited payment-related information, including payment confirmations, invoices, transaction reference numbers, billing details, the payment method used, records of amounts paid, and proof of payments where applicable. This information is processed only for lawful purposes, retained only for the period required by applicable legislation or our legitimate business needs, and protected by appropriate technical and organisational safeguards in accordance with the Protection of Personal Information Act, 2013 (POPIA).
6.6 Messaging and Communication Data
Where you communicate with us via messaging platforms such as WhatsApp or similar services, we may process the content of those communications, including text messages, images, documents, and voice notes, in order to respond to enquiries, manage bookings, provide customer support, confirm services, and maintain records of our interactions with you.
These communications may be stored and retained as part of our business records and are subject to the same security, access control, and retention principles set out in this Privacy Policy.
6.7 Sources of Personal Information
We generally collect personal information directly from you. However, in certain circumstances, we may receive personal information from other lawful sources, including:
- Parents, legal guardians, or authorised representatives;
- Schools, educational institutions, youth organisations, or tour operators;
- Group organisers, employers, corporate clients, or event coordinators making bookings on behalf of participants;
- Emergency contacts or next of kin;
- Referees or previous employers in connection with recruitment processes;
- Service providers acting on our behalf; and
- Publicly available sources or regulatory authorities where permitted by law.
Where personal information is not collected directly from you, we will process such information in accordance with POPIA and this Privacy Policy.
7. HOW WE COLLECT INFORMATION
We collect personal information in several ways when you interact with our business.
This includes when you:
- Submit a contact or enquiry form
- Make a booking enquiry or reservation request
- Contact us via email or telephone
- Browse our website
- Subscribe to marketing communications
- Participate in promotions or surveys (if applicable)
8. PURPOSE OF PROCESSING YOUR INFORMATION
We process personal information for legitimate, specific, and lawful business purposes in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
We may process personal information for the following purposes:
- to communicate or respond to you regarding your bookings, enquiries, or other guest requests;
- to process, confirm, fulfil booked services/activities;
- to record details of payments and verify transactions;
- to provide customer service and respond to complaints or feedback;
- to ensure the safety of guests, participants, employees, contractors, volunteers, and visitors;
- to maintain and improve the functionality, security, and performance of our website and services;
- to detect, investigate, prevent, and address fraud, unauthorised activity, security incidents, or misuse of our services;
- to verify your identity and the accuracy of information provided to us where necessary;
- to investigate, document and manage accidents, incidents, injuries, complaints, and safety-related matters where required;
- to comply with legal, regulatory, tax, accounting, tourism, consumer protection and record-keeping obligations;
- to conduct internal business analysis, reporting, research, auditing, and service improvement activities;
- to administer promotions, competitions, surveys, marketing campaigns, or customer engagement initiatives where applicable;
- to send marketing communications, newsletters, promotions, or special offers where permitted by law or where consent has been obtained;
- to manage disputes where necessary;
- to maintain operational records and internal administrative processes; and
- for any other lawful purpose reasonably related to the operation of our business and services.
9. PROCESSING OF PERSONAL INFORMATION
We process personal information in accordance with the applicable conditions for lawful processing under the Protection of Personal Information Act 4 of 2013 (“POPIA”), including accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.
We may process your personal information where:
- processing is necessary to conclude or perform a contract with you;
- processing complies with an obligation imposed by law;
- you have provided consent for processing;
- processing protects a legitimate interest of the data subject; or
- processing is necessary for pursuing the legitimate interests of the Responsible Party or a third party to whom the information is supplied.
Where processing is based on consent, you may withdraw your consent at any time.
Certain personal information is required in order for us to provide accommodation, activities, bookings, customer support, and related services, verify payments, communicate with you, and comply with legal and regulatory obligations. Where the provision of such information is mandatory and you choose not to provide it, we may be unable to process bookings, provide services, respond to enquiries, comply with legal requirements, or otherwise fulfil our obligations to you.
In certain cases, we may also be legally required to collect and retain personal information in accordance with applicable tax, consumer protection, accounting, fraud prevention, or other regulatory obligations.
Legitimate Interests Safeguard
Where we process personal information based on legitimate interests, we ensure that these interests do not override your rights and freedoms in accordance with POPIA principles.
Data minimisation
We apply data minimisation principles by limiting the collection, use, and retention of personal information to what is reasonably necessary for the lawful purposes described in this Privacy Policy.
Fraud Prevention and Security
We may process personal information where reasonably necessary to detect, prevent, investigate, or respond to fraud, unauthorised activities, security incidents, or other unlawful conduct affecting our business, customers, employees, or service providers.
To support these activities, we use appropriate access controls, monitoring, and security measures designed to help protect personal information and identify unauthorised or suspicious activity. Where appropriate, we may use automated systems to assist in detecting potentially fraudulent transactions or activities. Such systems are used to support decision-making and are not intended to replace appropriate human oversight where required.
Service Improvement and Analytics
We may use aggregated or pseudonymised data to understand how our website and services are used, in order to improve performance, functionality, and user experience.
Where required, we provide mechanisms for users to opt out of non-essential analytics processing and we limit the retention of analytics data to what is reasonably necessary.
Customer Support and Dispute Resolution
We retain customer support communications where necessary to respond to enquiries, maintain service quality, and resolve disputes.
These records are retained only for as long as reasonably necessary for these purposes and are subject to access controls, restricted internal access, and appropriate security safeguards.
10. DIRECT MARKETING
We may send you direct marketing communications such as newsletters, promotional offers, product updates, or special promotions where:
- you have consented to receiving such communications; or
- you are an existing customer and applicable law permits us to market similar products or services to you.
- Where required by law, we will obtain your consent before sending direct electronic marketing communications.
- You may opt out of receiving marketing communications at any time by:
- clicking the unsubscribe link included in marketing emails; or
- contacting us directly using the contact details provided in this Privacy Policy.
11. COOKIES AND TRACKING TECHNOLOGIES
Our website uses cookies and similar tracking technologies, including web beacons, tags and pixels, to improve website functionality, analyse website usage, remember user preferences, support booking or online enquiry activity, ecommerce functionality, and, where applicable, deliver relevant marketing content.
Cookies may be temporary (session cookies), which are deleted when you close your browser, or persistent cookies, which remain on your device until they expire or are deleted.
Cookies may include:
- essential cookies required for website functionality;
- analytics cookies used to understand website traffic and usage patterns;
- functionality cookies used to remember preferences and settings; and
- marketing or advertising cookies used to deliver relevant advertisements and marketing content.
Some cookies may be placed by third-party service providers such as analytics providers, advertising platforms, payment processors, or ecommerce service providers. Where our website includes embedded content or social media features, those third parties may also place cookies or collect information in accordance with their own privacy policies.
Where required, we use cookie consent mechanisms to allow users to accept or reject non-essential cookies. We may also use cookies to remember your cookie preferences and consent choices.
You may manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality and performance of the website.
Cookie Policy
For more detailed information about the cookies and similar tracking technologies we use, including third-party cookies where applicable, please refer to our Cookie Policy available at: https://orangeriverrafting.co.za/cookie-policy.
12. SHARING OF PERSONAL INFORMATION
We may share personal information with trusted third parties where it is necessary for the operation of our business, the provision of our products or services, compliance with legal obligations, guest safety requirements, or the protection of our legitimate interests.
Categories of recipients may include accommodation staff, activity guides, instructors, transport providers, booking and reservation platforms, payment processors, website hosting providers, IT support providers, email and communication service providers, insurers, emergency medical service providers, rescue personnel, operational personnel located in South Africa and Namibia and legal or regulatory authorities where disclosure is required by law.
Personal information may also be accessed internally by authorised employees, management, contractors, or administrative personnel where such access is reasonably necessary for the performance of their duties, the provision of services, customer support, operational management, security, compliance, or other legitimate business purposes. Access is restricted to individuals who require the information for authorised purposes and is subject to appropriate confidentiality and security controls.
We only share the minimum amount of personal information necessary for these service providers to perform their functions. Where they process personal information on our behalf as Operators, we take reasonable steps to ensure that they process such information only for authorised purposes, maintain appropriate confidentiality, implement reasonable security measures, and comply with POPIA.
12.1. Legal Disclosures to Authorities
We may disclose personal information where we are legally required or authorised to do so in order to comply with applicable laws, regulations, court orders, legal processes, or lawful requests from competent authorities.
This may include disclosures to law enforcement agencies, regulatory authorities, tax or financial authorities, courts, tribunals, or other public bodies.
We will take reasonable steps to verify the validity and legal basis of any request before disclosing personal information. Where legally permitted, we may notify affected individuals of such disclosures unless we are prohibited from doing so by law or court order.
We do not sell, rent, trade, or otherwise make personal information available to third parties for their own independent commercial purposes.
12.2 Emergency Disclosures
In emergency situations involving injury, illness, rescue operations, medical treatment, evacuation, or threats to life or safety, we may disclose relevant personal information to emergency service providers, medical practitioners, rescue personnel, law enforcement authorities, insurers, or other persons reasonably necessary to protect the life, health, or safety of an individual.
12.3 Third-Party Ecommerce and Marketing Platforms
Our website and business operations may make use of third-party ecommerce, analytics, advertising, payment processing, communication, cloud hosting, customer support, and marketing platforms.
These service providers may process personal information on our behalf as Operators in accordance with our instructions, POPIA, and any applicable contractual obligations.
Where personal information is processed by third-party providers located outside South Africa, such processing will be subject to the safeguards described in Section 13 (International Transfers).
12.4 Business Transfers and Corporate Transactions
We may disclose, transfer, or make available personal information as part of a proposed or completed merger, acquisition, restructuring, reorganisation, financing transaction, sale of assets, change of ownership, joint venture, or other corporate transaction involving all or part of our business.
Where personal information is transferred as part of such a transaction, we will take reasonable steps to ensure that the recipient is bound by appropriate confidentiality, security, and data protection obligations.
Any such transfer will be carried out only where it is lawful and necessary for the purposes of the transaction and subject to any applicable legal requirements.
13. INTERNATIONAL TRANSFERS
Our bookings office is located in the Republic of South Africa. Some of our business operations, including accommodation, rafting, and related tourism activities, are conducted from our operational base in Namibia.
Accordingly, personal information may be transferred to, accessed from, stored, or processed in Namibia where reasonably necessary to administer bookings, communicate with guests, arrange accommodation and activities, coordinate transport and logistics, provide customer support, ensure guest health and safety, respond to emergencies, manage incidents, comply with legal obligations, and otherwise operate our business.
Personal information may also be processed by our employees, guides, accommodation staff, contractors, emergency response personnel, insurers, and service providers located in Namibia where this is necessary for the provision of our services.
Some of our third-party service providers may also process or store personal information in countries outside the Republic of South Africa.
Where personal information is transferred outside South Africa or accessed from another jurisdiction, we take reasonable steps, where appropriate, to ensure that such processing complies with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and to protect personal information through appropriate technical, organisational, contractual, or other lawful safeguards.
We will only transfer personal information across borders where such transfer is lawful under POPIA.
14. SECURITY MEASURES
We take the security of your personal information seriously and implement reasonable technical and organisational measures to protect it.
We regularly review and update our security measures in order to identify and address reasonably foreseeable internal and external risks to personal information. These measures include secure hosting environments, SSL encryption for data transmission, password-protected systems, restricted administrative access, and the use of secure payment processing systems.
Although we take reasonable precautions to protect your personal information, no electronic system or internet-based transmission can be guaranteed to be completely secure.
15. RETENTION OF INFORMATION
We retain personal information only for as long as it is necessary to fulfil the purposes for which it was collected.
This includes retaining information for the duration of your customer relationship with us, to respond to enquiries, manage bookings and guest communications and for as long as required by applicable tax, accounting, or legal obligations.
This may include records relating to enquiries, quotations, bookings, guest registrations, waivers and indemnities, activity participation, accommodation arrangements, transport arrangements, emergency contact information, incidents, accidents, insurance matters, financial transactions, employment, and any other records reasonably required for operational, legal, regulatory, insurance, safety, security, audit, or risk management purposes.
Certain categories of personal information may be retained for longer periods where required by law or where retention is reasonably necessary to establish, exercise, or defend legal claims, comply with insurance, health and safety, or other legal obligations, investigate incidents or accidents, maintain safety records, resolve disputes, or satisfy regulatory requirements.
Where personal information is no longer required for the purpose for which it was collected and there is no lawful basis requiring its continued retention, we will take reasonable steps to securely delete, destroy, anonymise, or de-identify such information in accordance with applicable legal requirements and our internal record management practices.
16. YOUR RIGHTS UNDER POPIA
We respect your privacy and are committed to giving you appropriate control over your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
Under POPIA, you have the following rights:
Access:
You may request access to the personal information we hold about you.
Correction:
You may request that we correct or update any inaccurate or incomplete personal information.
Deletion / Destruction:
You may request that we delete or destroy your personal information where we are no longer legally required to retain it, or where continued processing is not justified.
Objection to Processing:
You may object to the processing of your personal information where such processing is based on our legitimate interests, or where it relates to direct marketing.
Withdrawal of Consent:
Where processing is based on your consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing carried out before withdrawal.
Limitation of Processing:
Where permitted by POPIA, you may request that we limit or suspend the processing of your personal information in certain circumstances.
16.1 How to Exercise Your Rights
You may exercise any of your rights in relation to your personal information by submitting a request to our Information Officer using the contact details provided in this Privacy Policy.
Your request should include:
- Your full name
- Account / booking details (if applicable)
- A clear description of your request
- Proof of identity (for verification purposes)
Where applicable, requests for access, correction, deletion, objection, or other rights relating to personal information may be submitted using the prescribed forms issued under POPIA and PAIA. We may request that you complete or provide such forms where required by law or where reasonably necessary to process your request efficiently.
16.2 Identity Verification
In order to protect personal information and prevent unauthorised access, disclosure, deletion, or alteration of personal information, we may require reasonable proof of identity before processing a request.
Where necessary, we may request additional information or documentation to verify the identity and authority of the person submitting the request.
We reserve the right to refuse or delay requests where adequate verification cannot be obtained.
16.3 Response Timelines
We will acknowledge receipt of requests within a reasonable period and aim to respond to all requests as soon as reasonably possible. We will generally respond to requests within 30 days of receipt. Where a request is complex, involves multiple records, requires additional verification, or cannot reasonably be completed within this period, we may extend the response period where permitted by law and will notify you accordingly. Certain requests may be limited, deferred, or refused where we are legally entitled or required to do so.
16.4 Internal Request Handling and Tracking
We maintain internal procedures for the receipt, verification, assessment, tracking, and resolution of requests relating to personal information.
Requests may be logged and retained where necessary for compliance, audit, security, fraud prevention, dispute resolution, record-keeping, and to meet applicable legal, regulatory, contractual, tax, and accounting obligations.
All requests are reviewed by authorised personnel and handled in accordance with applicable legal, regulatory, and security requirements.
Where permitted or required by law, we may refuse, partially fulfil, limit, or defer certain requests. Where a request cannot be fully completed, we will provide reasons where legally required.
17. PAIA MANUAL
The Promotion of Access to Information Act 2 of 2000 (“PAIA”) provides individuals with the right to request access to certain records held by public and private bodies, subject to applicable legal requirements.
In accordance with the Promotion of Access to Information Act 2 of 2000 (“PAIA”), we maintain a PAIA Manual which describes the categories of records held by us and explains how requests for access to such records may be made.
A copy of our PAIA Manual is available on request. Requests for a copy of the PAIA Manual, or requests for access to records in terms of PAIA, may be directed to our Information Officer using the contact details provided in this Privacy Policy. We will reasonably assist requesters where necessary to ensure that requests are properly submitted and processed in accordance with applicable law.
18. SECURITY BREACHES
In the event of a security compromise involving personal information, we will take immediate steps to investigate, contain, and mitigate the impact of the incident.
Where required under POPIA, we will notify affected individuals and the Information Regulator of South Africa as soon as reasonably possible. Such notification will include details of the nature of the breach, possible consequences, and measures taken or recommended to address the breach.
Notification does not constitute an admission of fault or liability.
19. EMPLOYMENT AND RECRUITMENT DATA
Where you apply for employment, freelance work, or contract engagement with us, we may collect and process personal information provided during the recruitment process.
This may include your name, contact details, CV information, qualifications, employment history, and references.
Where necessary and permitted by law, we may conduct verification checks, which may include:
- Identity verification
- Qualification verification
- Reference checks
- Background screening relevant to the role
We process this information for the purposes of assessing suitability for employment or engagement, complying with legal obligations, and protecting the legitimate interests of the business.
Personal information collected during recruitment will only be retained for as long as necessary for recruitment purposes or as required by law.
If your application is unsuccessful, we may retain your information for future opportunities only where you have consented or where lawful retention is permitted.
20. CHILDREN’S PRIVACY
Our services may be used by minors, including children under the age of 18, where bookings, reservations, activity registrations, or participation arrangements are made by a parent, legal guardian, school, tour operator, corporate organiser, or another authorised adult.
We may collect and process personal information relating to minors where such processing is necessary for:
- Accommodation bookings and guest registrations;
- Participation in rafting, outdoor recreation activities, excursions, or events;
- Safety management and emergency response;
- Compliance with legal, regulatory, insurance, or operational requirements; and
- Any other lawful purpose permitted under POPIA.
Where personal information relating to a child or minor is collected or processed, we will do so in accordance with POPIA and only where the consent of a competent parent, legal guardian, authorised representative, or another lawful basis for processing exists, as required by applicable law.
We take reasonable steps to ensure that personal information relating to children is processed lawfully, securely, and only to the extent reasonably necessary for the purposes for which it was collected.
If a parent or guardian believes that we have collected personal information relating to their child unlawfully or without appropriate authorisation, they may contact our Information Officer using the contact details provided in this Privacy Policy. We will investigate the matter and, where appropriate, take reasonable steps to correct, delete, or restrict the processing of such information in accordance with applicable law.
20.1 School Groups and Minor Participants
Where bookings or activity registrations are made by schools, educational institutions, youth organisations, sports clubs, tour operators, or other authorised organisations on behalf of minors, we may receive and process personal information relating to participating children.
Such information may include participant names, ages, emergency contact details, medical information relevant to safety, dietary requirements, indemnity documentation, and other information reasonably necessary for participation and risk management.
We will process such information only for the purposes of administering bookings, ensuring participant safety, responding to emergencies, complying with legal obligations, and providing the services booked or requested.
21. THIRD-PARTY LINKS AND SERVICES
Our website may contain links to third-party websites, applications, or services that are not operated or controlled by us. These third parties operate independently and have their own privacy and data protection policies. If you choose to access or interact with these third-party services, any personal information you provide will be processed in accordance with their respective privacy policies.
We encourage you to review the privacy policies of any third-party websites or services before providing them with personal information.
While we take reasonable care in selecting trusted service providers and partners, we are not responsible for the privacy practices, security measures, or content of third-party websites or services and do not accept liability for how they handle your information.
Some third-party providers may be located in, or operate from, jurisdictions outside of South Africa. In such cases, your personal information may be subject to the data protection laws of those jurisdictions. Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.
22. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time in order to reflect changes in our practices, services, or legal obligations.
Whenever we make changes, we will update the “Last Updated” date at the top of this policy. Any significant changes will be clearly communicated on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information.
23. COMPLAINTS AND CONTACT DETAILS
If you believe that your personal information has been processed in a way that is not compliant with POPIA, we encourage you to contact us first so that we can attempt to resolve your concern.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa.
Website: https://inforegulator.org.za/
General Enquiries: enquiries@inforegulator.org.za
POPIA Complaints: POPIAComplaints@inforegulator.org.za
PAIA Complaints: PAIAComplaints@inforegulator.org.za
Telephone: 010 023 5200 / 0800 017 160
Physical Address:
Woodmead North Office Park
54 Maxwell Drive
Woodmead
Johannesburg
2191
For privacy-related questions, requests, or complaints, please contact our Information Officer using the contact details set out in Section 5 of this Privacy Policy.