What we collect, why we collect it, who we share it with, how long we keep it,
and what you can ask us to do with it.
Shumba Valley Hotel respects your privacy. This policy explains what personal information we collect, why we collect it, whether you have to give it to us, who we share it with, how long we keep it, and what you can ask us to do with it.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).
| Trading name | Shumba Valley Hotel |
| Registered name | Shumba Valley Lodge and Conference Centre |
| Registration number | 1999/007215/07 |
| Address | 53 Boeing Street, Lanseria, 1748, Gauteng |
| Telephone | +27 (0)11 790 8000 |
| Information Officer | Godfrey Noge, IT Manager |
| Privacy enquiries | privacy@shumbavalley.co.za |
| PAIA manual | https://inforegulator.org.za/paia/ |
privacy@shumbavalley.co.za is monitored for privacy, POPIA and PAIA matters only. For bookings, enquiries or anything else, please use info@shumbavalley.co.za or call us.
This policy applies to you if you visit our website, enquire with us, book with us, stay with us, attend a conference or function here, use our facilities, or deal with us as a travel agent, corporate client or event organiser.
Personal information means information that identifies you or can be linked back to you. Under POPIA it also includes information about a company, close corporation or trust, so if you deal with us on behalf of your organisation, your organisation’s information is protected too.
Personal information does not include:
What this policy does not cover. Applying for a job with us, and supplying goods or services to us, are covered by separate notices. Ask us and we will send you the relevant one.
Other people’s information. If you give us information about someone else, such as a fellow guest, a delegate or a family member, please make sure they know and are comfortable with it. We remain responsible for how we handle their information, and we will give them this policy if they ask.
What we collect depends on how you deal with us. In each section below we tell you whether the information is required or optional, and what happens if you do not give it to us.
Required. We cannot accommodate you without it.
| What we collect | Why |
|---|---|
| Name, email address, telephone number and address | To confirm and hold your reservation and contact you about your stay |
| Identity or passport number, nationality, residence status, residential address and signature, and a copy of your identity document or passport | To keep the guest register the law requires us to keep |
| Names of everyone staying in your party, including children | Same register requirement |
| Arrival and departure dates, room type, rate and charges | To prepare your room, bill you correctly and issue an invoice |
| Payment details | To take payment and process any refund |
Our legal basis. Performing our contract with you (section 11(1)(b)); complying with obligations imposed by law (section 11(1)(c)), specifically section 40 of the Immigration Act 13 of 2002 read with regulation 36 of the Immigration Regulations, which requires lodges to keep a register of everyone who is given accommodation, to record the particulars listed above, and to safeguard that register through a person we authorise for the purpose; and tax and company law record-keeping obligations. Where the register includes a child, we rely on section 35(1)(b) of POPIA, because keeping the register is a legal obligation.
If you do not provide it, we cannot check you in. This is not a commercial choice on our part. Section 40 makes it an offence for both the establishment and the guest.
Optional. Your stay goes ahead without it.
| What we collect | Why |
|---|---|
| Dietary requirements and food allergies | So the kitchen can cater for you safely |
| Accessibility and mobility needs | So we can allocate a suitable room and assist you |
| Other special requests | So we can try to meet them |
| Vehicle registration number | Only if you park on the property, for security and access control |
Our legal basis. Your consent (sections 11(1)(a) and 27(1)(a)).
Please note what this information is. Allergies and mobility needs are health information. Dietary requirements can reveal religious or philosophical belief. Under POPIA these are special personal information (section 26), which the law protects more strictly than ordinary information. We therefore collect it only with your consent, use it only to deliver the service you asked for, never for marketing, and restrict access to the staff who need it to look after you: the kitchen, housekeeping and front office. You can withdraw your consent at any time by telling us, and we will delete it.
If you do not provide it, we cannot cater to your dietary needs, cannot guarantee an allergy-safe meal, and cannot prepare an accessible room. Please tell us if any of this matters to you.
A note on payment cards.
We do not store your full card number. Card payments are processed by our payment provider, which returns a secure token to us. We handle card payments in line with the Payment Card Industry Data Security Standard (PCI DSS). Please do not send us card details by email, WhatsApp or fax. If you do, we will delete them and ask you to use our secure payment link instead.
What we collect
Why
To answer your enquiry, send you the information, quote or package you asked for, and follow up with you about that enquiry.
Our legal basis. Taking steps at your request before entering into a contract (section 11(1)(b)), and our legitimate interest in responding to people who contact us (section 11(1)(f)). Where you ask us to follow up on WhatsApp, we do so on the consent you give on the form.
Required or optional. Your contact details are required, because we cannot answer you without them. Everything else is optional.
We will only contact you about the enquiry you made. Following up on your enquiry is not marketing. If you would also like to hear about our specials and offers, we will ask you separately, and you are free to say no without it affecting your enquiry. See section 6.
What we collect
Why
To quote for, plan and run your event, cater for delegates, allocate rooms and invoice your organisation.
Our legal basis. Performing our contract with you or your organisation (section 11(1)(b)). Delegate dietary and accessibility information is special personal information and is handled as described in section 3.1, on the consent of the delegate concerned.
Required or optional. Contact and billing details are required. Delegate dietary and accessibility requirements are optional, but without them we cannot cater safely.
If you are an organiser, please make sure your delegates know their details are being shared with us and that this policy is available to them.
What we collect
Why
To keep the site and booking engine working, to understand how people find and use the site, and, where you have accepted advertising cookies, to measure and target our advertising.
Our legal basis. Our legitimate interest in operating and securing the website (section 11(1)(f)), and your consent for anything beyond what is strictly necessary (section 11(1)(a)).
Required or optional. Essential cookies are required for the site and booking engine to work. Analytics and advertising cookies are optional and are switched off until you accept them.
What we collect
What we do not collect
We do not read, record or store the content of anything you send or receive, not your emails, messages, calls or files, and we do not monitor which sites you visit for marketing purposes.
Why
To run and secure the network, manage bandwidth and troubleshoot faults.
Our legal basis. Performing our contract with you as a guest (section 11(1)(b)), and our legitimate interest in the security and proper functioning of our network (section 11(1)(f)).
Required or optional. Logging in is required to use the network. You are free not to use it.
If the portal asks for your email address, we will not add it to any marketing list unless you separately tick the marketing box on the login screen itself.
What we collect
CCTV footage in reception, restaurant, bar, terrace, pool area and main gate entrance of the lodge. Cameras are not placed in bedrooms, bathrooms, changing areas or any other place where you would reasonably expect privacy. Signs are displayed at each monitored area.
Why
The safety and security of guests, staff and property, and investigating incidents. Never for marketing. Not shared except with law enforcement, or where we need it to establish or defend a legal claim.
Our legal basis. Our legitimate interest in the security of the property and the people on it (section 11(1)(f)).
Most of what we hold, you give us. We also receive personal information from:
| Type | What it does | Needs your consent |
|---|---|---|
| Essential | Keeps the site working and holds a booking in progress | No |
| Analytics | Tells us how visitors find and move through the site | Yes |
| Advertising | Measures our advertising and lets us show you our ads again | Yes |
Analytics and advertising cookies do not run until you accept them. You can accept or decline them in the banner when you arrive, and change your mind at any time through the cookie settings link in the footer. You can also clear or block cookies in your browser, but blocking essential ones may stop parts of the site, including the booking engine, from working.
Our full cookie policy is at www.shumbavalleylodge.co.za
We advertise on Facebook, Instagram and Google. Some of that advertising is targeted. We explain how below, because it is the part of our processing that is least visible to you.
Advertising to people who have visited our website. If you accepted advertising cookies, the Meta Pixel and Google’s advertising tags record that you visited and which pages you viewed. We can then ask Meta or Google to show our advertising to you again. We do not learn your name this way, and we do not receive a list of who saw our ads.
Matching our lists to advertising platforms. We may upload email addresses and phone numbers we already hold to Meta or Google, so they can show our advertising to those people or to people whose interests resemble theirs. Contact details are converted into a coded form before they are sent, so the platform cannot read them and uses them only to find a match against accounts it already has. That coded form is still your personal information, and we remain responsible for it, so we do this only where you have agreed to receive marketing from us. You can ask us to remove you from any audience list at any time.
Lead advertising on Facebook and Instagram. Some of our advertisements carry a form you can complete without leaving the app. Meta passes your answers to us and we contact you about your enquiry. Meta also keeps a copy under its own privacy policy, at facebook.com/privacy/policy.
What we do not do
How to stop it. Decline advertising cookies on our site, or change your choice through the cookie settings link in the footer. You can also limit targeted advertising in your Facebook, Instagram and Google account settings, which applies to every advertiser and not only us. To come off our audience lists, write to privacy@shumbavalley.co.za.
We send marketing by email, WhatsApp or SMS only where:
Every marketing message carries a free and easy way to opt out. We ask for your agreement separately from your booking or enquiry, and saying no makes no difference to either. Not replying is not agreement.
Telephone calls. When we call you about an enquiry you made, that is not marketing and we will keep to the subject. We will not make marketing calls to you unless you have agreed to them.
Withdrawing at any time, at no cost. Use the unsubscribe link in any email, reply STOP to a WhatsApp or SMS, or write to privacy@shumbavalley.co.za. We keep an internal do-not-contact list so that a refusal is honoured across every channel, not just the one you used to tell us.
This does not affect a booking you have already made. We will still send you confirmations, invoices and arrival details.
The national opt-out registry. Separately from anything you tell us, you can register a pre-emptive block with the National Consumer Commission’s opt-out registry, which stops direct marketing from every registered marketer in South Africa. If you are on that registry, we will not market to you, whatever you may have agreed to before.
We do not sell your personal information, and we do not give it to third parties for their own marketing.
| Who | Why |
|---|---|
| HTI Nebula CRS, our booking engine and property management system provider | To hold and manage your reservation |
| ABSA, our payment processor, and our bank | To take payment and process refunds |
| Online travel agents and booking platforms | To manage a booking made through them |
| Meta Platforms (Facebook and Instagram) | Advertising, lead forms and audience matching |
| Website analytics, our Google Business Profile and advertising | |
| marketing@shumbavalley.co.za, our email marketing platform | To send marketing you have agreed to receive |
| Suppliers who deliver part of your stay, such as team-building facilitators, transfer operators and event contractors | To provide what you booked |
| Our accountants, auditors and legal advisors | Professional advice and statutory compliance |
| The South African Police Services law enforcement, regulators and courts | Where the law requires it, or to protect the safety of guests and staff |
If the hotel is ever sold or merged, personal information may transfer to the new owner. We will post notice of this on our website, and you may ask us to delete your information instead.
Some of the providers we use, including Meta, Google and our email marketing platform, store and process personal information on servers outside South Africa, including in the United States and the European Union.
South Africa does not publish a list of countries that are treated as safe for this purpose, so we do not rely on one. Instead, before personal information leaves the country, we put a binding written agreement in place with the provider that requires it to protect your information on principles substantially similar to those in POPIA, and that controls whether and how it can pass the information on again. This is what section 72(1)(a) of POPIA requires.
Where a transfer is instead necessary to perform our contract with you, or where you have specifically consented to it, we will say so. We do not rely on your consent alone to justify a transfer that has nothing else behind it.
| What | How long |
|---|---|
| Booking, guest and payment records | 5 years from the end of your stay. Tax law requires five years from the date we submit the relevant return, and longer where a return is outstanding or an audit, objection or appeal is under way. The Companies Act requires seven years for company records. We use the longer period so that one rule covers both. |
| Guest register entries and copies of identity documents or passports | Two years from the end of your stay. This is the period the Immigration Regulations require, and the register is safeguarded by a named person we authorise for that purpose, separately from our general records |
| Dietary, allergy, accessibility and health information | Deleted 30 days after you check out, unless you ask us to keep it on file, so you do not have to tell us again |
| Enquiries that did not become bookings | 12 months from your last contact with us |
| Marketing contact details | Until you unsubscribe, or 24 months of no engagement, whichever comes first |
| Record of your unsubscribe or objection | Kept indefinitely, so that we do not contact you again by mistake |
| Advertising audience lists held by Meta or Google | Refreshed at least every 6 months, and you are removed when you unsubscribe |
| Tokenised card references | Deleted at check-out / kept for the duration of the booking guarantee only |
| CCTV footage | 15 days, unless kept longer for a specific incident or investigation |
| Guest Wi-Fi connection records | 6 months |
| Call recordings, if we record calls | 6 months |
One exception to all of the above. Where information is relevant to a complaint, an insurance claim, a legal claim, an investigation or a request from a regulator or the police, we keep it until that matter is finally resolved, even if the period in the table has passed. We do not keep it for any other purpose in the meantime.
We take reasonable technical and organisational steps to prevent loss, damage and unauthorised access to your information. These include limiting access to the staff who need it, individual user accounts and passwords on our systems, encrypted transmission of payment details, secure hosting, restricted handling of identity documents and health-related information, confidentiality obligations on staff, and written security obligations on every supplier who handles personal information for us.
No system is completely secure. If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator, and we will notify you as well. We will do so as soon as reasonably possible after we discover it. We will only hold back from telling you if we genuinely cannot identify you, or if the police or the Information Regulator tell us that notifying you would get in the way of a criminal investigation, in which case we will tell you as soon as they allow.
When we notify you, we will tell you what happened, what it could mean for you, what we have done about it, and what we recommend you do to protect yourself.
Please tell us if anything we hold about you is wrong or out of date. You can correct your details:
We may verify your identity before making changes. There is no charge.
We collect a child’s personal information only where a parent, guardian or other competent person gives it to us as part of a booking, or where the law requires us to record it in the guest register. We do not market to children, and we do not use a child’s information for advertising.
If you believe we hold a child’s information without the consent of a competent person, and it is not information the register requires, write to privacy@shumbavalley.co.za and we will delete it.
Under POPIA you may:
How to exercise them. Email privacy@shumbavalley.co.za, write to us at the address in section 1, call us on +27 (0)11 790 8000, or send a WhatsApp or SMS to 062 611 5759. If you call, we will make a recording of the request and give you access to it if you ask. All of this is free.
There are prescribed forms for some of these, and we will send you the right one and help you complete it:
How long we take. We respond to requests for correction or deletion within 30 days. Requests for access to records are dealt with under the Promotion of Access to Information Act 2 of 2000, which gives us 30 days from receipt, extendable once by up to a further 30 days where the request is complex, in which case we will tell you.
Fees. Confirming whether we hold information about you is free. If you request access to records about yourself, no request fee is payable, though a fee for copies and search time may apply and we will tell you what it is before we start. Our PAIA manual, which sets out the full procedure and fee schedule, is at https://inforegulator.org.za/paia/.
Identity. We may ask you to confirm your identity before we act, so that we do not disclose your information to someone else.
Please raise it with us first, at privacy@shumbavalley.co.za. Most things are quicker to fix directly, and we would rather know.
You may also complain to the Information Regulator using Form 5, available on their website.
Information Regulator (South Africa) Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone: 010 023 5200 | Toll free: 0800 017 160
Enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
www.inforegulator.org.za
If your complaint is about marketing you did not ask for, you can also contact the National Consumer Commission.
We may update this policy. The current version is always at www.shumbavalleylodge.co.za, and the date at the top tells you when it last changed.
Where a change materially affects how we use your personal information, we will post notice on our website at least 30 days before it takes effect, and tell you directly where we hold your email address. Where the law requires your consent to a change, we will ask for it. We will not treat your continued use of our website as agreement.
Shumba Valley Lodge
53 Boeing Street, Lanseria, 1748, Gauteng
Attention: The Information Officer, Godfrey Noge
privacy@shumbavalley.co.za | 011 790 8000
Questions about anything on this page? Write to privacy@shumbavalley.co.za or call +27 (0)11 790 8000.