L’il Masters Diapers Manufacturers (Pty) Ltd (Registration Number 2007/034985/07) and LM Diapers Manufacturers (Pty) Ltd (Registration Number 2019/298460/07) (together referred to as “we”, “us”, “our”, “the Company”, or “L’il Masters”) are committed to protecting the privacy and personal information of every person and organisation we deal with. We manufacture and supply baby-care products, and in the course of our business we process personal information relating to our customers, suppliers, employees and other stakeholders.

This Privacy Policy explains how we obtain, use, share, store and protect personal information, and the rights available to you, in accordance with the Protection of Personal Information Act, No. 4 of 2013 (“POPIA”) and the Promotion of Access to Information Act, No. 2 of 2000 (“PAIA”). It applies to our customers, suppliers, contractors and service providers, employees and job applicants, business contacts, website visitors, and any other person whose personal information we process, whether at our Gauteng operations or our KwaZulu-Natal operations.

In addition to serving as our privacy policy, this document serves as the data subject notification contemplated in section 18 of POPIA – it tells you what personal information we collect, why we collect it, how we use it, who we share it with, and the safeguards in place to protect it.

By providing us with your personal information, or by using our website or services, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not submit personal information to us.

Key Terms

Words defined in POPIA carry the same meaning in this Policy. In particular:

  • “Personal information” means information relating to an identifiable, living natural person and, where applicable, an identifiable, existing juristic person (such as a company). It includes, for example, names, contact details, identity and registration numbers, banking details and correspondence.
  • “Special personal information” means information concerning a person’s health, biometrics, criminal behaviour, religious or philosophical beliefs, race or ethnic origin, or similar sensitive categories.
  • “Processing” means any operation performed on personal information, including collecting, receiving, recording, organising, storing, updating, using, sharing, disseminating, erasing and destroying it.
  • “Responsible party” means the Company, which determines why and how personal information is processed.
  • “Operator” means a third party that processes personal information on our behalf, under a written contract, without coming under our direct authority – for example our IT, cloud, payroll, verification, courier or marketing service providers.
  • “Data subject” means the person to whom the personal information relates.

Our Information Officer

The Company has appointed an Information Officer, registered with the Information Regulator, who is responsible for ensuring our compliance with POPIA and for dealing with requests and queries relating to personal information. Our Information Officer is Mr Preyesh Surendra Bhawan. You may contact the Information Officer using the details in section 17.

Personal Information We Collect

Depending on our relationship with you, and only to the extent necessary, we may collect and process the following categories of personal information:

Customers and business contacts

Business and trading names, holding-company details, company registration and VAT numbers, income-tax number, corporate structure, contact-person names, telephone, cell and email details, physical, postal and delivery addresses (including the customer’s domicilium address), banking and account details, credit application and credit-history information, trade and bank references, details of directors, members, partners or proprietors (including identity documents supplied for verification), surety details, auditor or accounting-officer details, purchase and order history, invoicing, statements and payment records, and related correspondence.

Suppliers, contractors and service providers

Company and contact-person details, registration and VAT numbers, banking and payment details, B-BBEE information, quality, SHEQ and compliance records, service-level and contract information, and, where relevant to the service (for example contractors performing work on our sites), medical or occupational-health information required for site access and safety.

Employees and job applicants

Names and contact details, identity and tax numbers, date of birth, CV, qualifications and employment history, the results of background and verification checks (including identity, credit (MIE), criminal (MIR), qualification, licence/PdP, reference and social-media checks), psychometric-assessment results (for senior and specialist roles), employment, disciplinary and performance records, payroll, benefits and pension-fund information, banking details, next-of-kin and emergency-contact details, biometric data used for access control and time-and-attendance (including photographs and facial images used for biometric identification), and images captured by CCTV on our premises.

Website visitors

Information you submit through our website or enquiry forms (such as your name, contact details and message), and website-usage information collected through cookies and similar technologies (see section 12).

How We Collect Personal Information

We collect personal information in a number of ways, including:

  • directly from you – for example when you complete a credit application, apply for a position, enter into a contract, place an order, visit our premises, or contact us;
  • from third parties, where the law allows – such as credit and verification bureaux (for example MIE and MIR), banks, trade and bank references, public registers, and recruitment agencies or job platforms (including where you apply for, or respond to, a position that we advertise or list through LinkedIn, other job or social-media platforms, or a recruiter); and
  • automatically – through cookies on our website, and through access-control and CCTV systems at our premises.

Where possible, we will tell you which information is required and which is optional, and the consequences of not providing it. Where we collect your information from another source, we will take reasonable steps to notify you as required by section 18 of POPIA, unless an exemption applies.

Why We Process Personal Information

We process personal information only for lawful purposes and only to the extent necessary, including to:

  • conclude and perform contracts, and process orders, invoices, deliveries and payments;
  • assess credit applications, conduct credit vetting, and manage customer and supplier accounts;
  • recruit, verify, employ and administer staff – including background checks, payroll, benefits, training and performance management;
  • manage the security of our premises, people and systems, including access control, time-and-attendance and CCTV;
  • manage quality, health, safety and environmental (SHEQ) obligations, including supplier and contractor assessments;
  • meet legal, regulatory, tax, company-law and audit obligations;
  • communicate with you, respond to your queries and requests, and conduct customer-satisfaction and supplier assessments; and
  • protect and enforce our rights, and prevent fraud and other unlawful activity.

We rely on one or more of the lawful bases recognised by POPIA – your consent, the conclusion or performance of a contract, compliance with a legal obligation, protection of a legitimate interest of you, us or a third party, or another basis permitted by law.

Special Personal Information and Children’s Information

Where we process special personal information (such as biometric data for access control, or the health or occupational-health information of contractors) or the personal information of children, we do so only where POPIA permits – for example with consent, where the processing is necessary for the establishment, exercise or defence of a right or obligation in law, or where it is otherwise authorised by law. Such information is subject to stricter safeguards and is accessed only by authorised personnel on a need-to-know basis. Photographs and facial images that we use to identify an individual (for example for access-control, time-and-attendance or identity-verification purposes) constitute biometric information and are treated as special personal information. Where we collect a photograph or facial image for such a purpose, we obtain the individual’s consent, and a photograph and biometric consent clause is included in the relevant employment and service contracts.

When We Share Personal Information

We do not sell your personal information. We may share it, subject to appropriate safeguards and only as necessary, with:

  • our operators – third parties who process information on our behalf, such as IT, cloud and hosting, payroll, marketing, accounting, recruitment, background-verification (for example MIE and MIR), auditing, training, courier and travel providers – each of whom is bound by a written Operator Agreement requiring them to process the information only on our instruction and to keep it secure;
  • our group and affiliated companies, where necessary for the purposes described in this Policy;
  • banks and financial institutions, credit and verification bureaux, and insurers, where relevant to the relationship;
  • trade and credit references you provide, for the purpose of assessing a credit application; and
  • professional advisors, regulators, courts and authorities, where required or permitted by law.

Before sharing information with an operator, we require a written Operator Agreement in terms of sections 20 and 21 of POPIA, obliging the operator to maintain appropriate security safeguards, to process information only with our knowledge or authorisation, and to notify us of any security compromise.

Cross-Border Transfers

Where personal information is transferred to a recipient in another country – for example a cloud-service provider or an affiliate – we do so in accordance with section 72 of POPIA. We take reasonable steps to ensure that the recipient is subject to a law, binding corporate rules or a binding agreement that provides a level of protection that is not less than that provided for under South African law, or that the transfer is otherwise permitted (for example with your consent or for the performance of a contract). This applies equally to any cross-border transfer of personal information in connection with the cross-border sale or supply of our products, or with our dealings with customers, suppliers or affiliates located outside South Africa, and in each such case the transfer is effected in accordance with section 72 of POPIA.

Direct Marketing and Your Right to Opt Out

We may send you information about our products, offers and services by electronic means (such as email or SMS) where the law permits or where you have consented. In line with section 69 of POPIA:

  • if you are an existing customer, we may market our own similar products to you, and you may object or opt out at any time;
  • where your consent is required, we will request it, and we will approach you for that consent only once;
  • every marketing communication identifies us and contains a simple mechanism (such as an “unsubscribe” option) allowing you to opt out; and
  • we maintain our databases so that the marketing preferences and objections of data subjects are recorded and respected.

We do not buy, sell or share databases for the direct-marketing purposes of others.

How Long We Keep Personal Information

We keep personal information only for as long as necessary to fulfil the purposes for which it was collected, or for longer where required or permitted by law (for example tax, employment and company-law retention periods). By way of example:

  • records of appointed employees are retained for at least 5 years after termination of employment;
  • the information of unsuccessful job applicants is retained for a maximum of 1 year and then securely destroyed, unless the applicant consents to a longer period so that we may consider them for future opportunities;
  • customer, supplier, financial and tax records are retained in line with the retention periods set out in our Data Protection Policy and applicable legislation (generally between 5 and 7 years, and longer where the law requires); and
  • CCTV and access-control records are retained only for the period necessary for security purposes.

When information is no longer required, it is securely deleted or destroyed in line with our Data Retention and Destruction Policy.

Cookies and Website Usage

Our website may use cookies and similar technologies to help the site function, remember your preferences, keep the site secure, and understand how the site is used so that we can improve it. Cookies are small text files placed on your device.

You can manage or disable cookies through your browser settings. If you disable cookies, the website will still work, although some features may not function properly. By continuing to use our website, you consent to our use of cookies as described in this Policy.

How We Protect Personal Information

We take appropriate, reasonable technical and organisational measures to safeguard personal information against loss, damage, unauthorised access and unlawful processing, as required by section 19 of POPIA. These measures include access controls and authentication, encryption, firewalls and network security, secure backups, physical security and CCTV, confidentiality undertakings and training for staff, secure disposal of records, and an incident-response and breach-notification procedure. Where an operator processes information on our behalf, we require them to apply security safeguards that are equivalent to our own.

If a security compromise affecting your personal information occurs, we will notify the Information Regulator and, where required, the affected data subjects, in accordance with section 22 of POPIA.

Your Rights

Subject to POPIA, you have the right to:

  • be notified that we are collecting your personal information, and where it is collected from another source;
  • request access to the personal information we hold about you;
  • request that we correct, update or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
  • object, on reasonable grounds, to the processing of your personal information;
  • object at any time to the processing of your personal information for purposes of direct marketing; and
  • submit a complaint to the Information Regulator.

Requests for access to, or correction or deletion of, personal information are dealt with in accordance with our PAIA Manual, which is available on our website or on request. We may require verification of your identity before actioning a request, and certain requests may be subject to the fees and grounds for refusal permitted by PAIA and POPIA.

Protection of Personal Information Act

Copy of Popi Act link herewith https://popia.co.za/

Complaints to the Information Regulator

You have the right to lodge a complaint with the Information Regulator if you believe we have not handled your personal information in accordance with POPIA. The Regulator’s details are:

Regulator The Information Regulator (South Africa)
Address JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal P.O. Box 31533, Braamfontein, Johannesburg, 2017
Complaints email POPIAComplaints@inforegulator.org.za
General enquiries enquiries@inforegulator.org.za Website www.inforegulator.org.za

How to Contact Us

To exercise any of your rights, or for any query about this Policy or your personal information, please contact our Information Officer:

Email Popicomplaints@lmdiapers.com
Telephone +27 11 938 9415
Gauteng address Klipriver Business Park, Erf 75 Technology Crescent, Midvaal, Johannesburg, Gauteng, 1871
KwaZulu-Natal address Dube Tradeport, Erf 777, 20 Hlawe Close Road, La Mercy, KwaZulu-Natal, 4399
Website www.lilmasters.co.za

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or the law. The current version is available on our website, and the effective date appears on the cover. We encourage you to review it periodically. This Privacy Policy replaces any previous privacy policy or notice published by the Company.