This Privacy Policy is effective as of the 31st of January 2024
This Privacy Policy governs the collection, use, and protection of personal information by:
NEXTTASK (Pty) Ltd
This policy applies to:
Website Users, Customers, Visitors, and all other Data Subjects whose personal information is processed by NEXTTASK.
Parties
- Users of NEXTTASK's website, applications, and services;
- Customers and prospective customers;
- Website visitors and subscribers;
- Individuals who communicate with NEXTTASK through any channel;
- Any other natural persons whose personal information comes into NEXTTASK's possession in the course of its business operations.
Data Controller: NEXTTASK, a technology company incorporated and operating under the laws of South Africas, having its registered address at 21 Milldene Avenue, 7700 ("we," "us," "our," or "the Company"). NEXTTASK acts as the data controller responsible for determining the purposes and means of processing personal data collected through its services and operations.
Data Subjects: All individuals whose personal data is collected, processed, stored, or otherwise handled by NEXTTASK ("you," "your," or "Data Subject"), including but not limited to:
Background
- NEXTTASK is committed to protecting the privacy and personal information of all individuals who interact with our services, in accordance with South African data protection laws, including the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) ("POPIA") and its regulations.
- As a technology company with limited resources but a strong commitment to data privacy best practices, NEXTTASK recognizes the fundamental right to privacy and the importance of transparent data handling practices in building trust with our users and stakeholders.
- This Privacy Policy serves as a comprehensive framework governing how NEXTTASK collects, uses, processes, stores, shares, and protects personal information obtained through all our business operations, services, websites, applications, and communications.
- This Policy applies to all personal information processed by NEXTTASK, regardless of the method of collection or the medium through which such information is obtained, including direct provision by data subjects, automatic collection through technology, and information received from third-party sources.
- NEXTTASK processes personal information only where there is a lawful basis to do so under POPIA and other applicable South African legislation, ensuring that all data processing activities are conducted in a manner that respects individual privacy rights while enabling us to provide quality services to our users.
- This Policy is designed to be easily understood by individuals without legal expertise, providing clear information about data subject rights, our data handling practices, and the measures we have implemented to safeguard personal information against unauthorized access, use, or disclosure.
- By using NEXTTASK's services or providing personal information to us through any means, data subjects acknowledge that they have read, understood, and agree to be bound by the terms of this Privacy Policy as it may be amended from time to time.
1. Definitions
- 1.1. Automated Processing means any form of automated processing of personal information, including profiling, automated decision-making, or any processing carried out by technological means without human intervention.
- 1.2. Biometric Information means any personal information relating to the physical, physiological or behavioral characteristics of a data subject which allows or confirms the unique identification of that person, including fingerprints, voice patterns, facial recognition data, or DNA profiles.
- 1.3. Consent means any voluntary, specific, and informed expression of will in terms of which permission is given for the processing of personal information, which must be obtained in accordance with the requirements of POPIA.
- 1.4. Cookies means small text files that are placed on a user's device by websites to store information about the user's browsing activities, preferences, and interactions with the website.
- 1.5. Data Breach means any unauthorized access to, acquisition of, or disclosure of personal information which compromises the security, confidentiality, or integrity of personal information held by NEXTTASK.
- 1.6. Data Controller means NEXTTASK as the party who, alone or jointly with others, determines the purpose of and means for processing personal information.
- 1.7. Data Processor means any natural or juristic person who processes personal information for or on behalf of NEXTTASK in terms of a contract or mandate, without coming under the direct authority of NEXTTASK.
- 1.8. Data Subject means any natural person to whom personal information relates, including users, customers, website visitors, and any other individuals whose personal information is processed by NEXTTASK.
- 1.9. Direct Marketing means to approach a data subject, either in person or by mail or electronic communication, for the direct or indirect purpose of promoting or offering to supply goods or services or for the purpose of requesting support for any cause.
- 1.10. Information Officer means the person designated by NEXTTASK in terms of section 56 of POPIA to take responsibility for ensuring compliance with the conditions for the lawful processing of personal information.
- 1.11. Personal Information means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person, including but not limited to information relating to race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language, birth, education, medical, financial, criminal or employment history, identifying number, location information, online identifier, or any other information that can be used to identify a specific person.
- 1.12. POPIA means the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) and its regulations, as may be amended from time to time.
- 1.13. Processing means any operation or activity or any set of operations, whether or not by automatic means, concerning personal information, including collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation, use, dissemination by means of transmission, distribution or making available in any other form, merging, linking, restriction, degradation, erasure or destruction of information.
- 1.14. Responsible Party means NEXTTASK as the public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information.
- 1.15. Special Personal Information means personal information concerning the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric information of a data subject, or the criminal behavior of a data subject to the extent that such information relates to the alleged commission by a data subject of any offence or proceedings in respect of any offence allegedly committed by a data subject or the disposal of such proceedings.
- 1.16. Third Party means any natural or juristic person other than NEXTTASK or the data subject, including but not limited to service providers, business partners, regulatory authorities, and other entities that may have access to or process personal information.
- 1.17. Tracking Technologies means technologies used to automatically collect information about users' online activities, including but not limited to cookies, web beacons, pixel tags, local storage objects, and similar technologies.
- 1.18. User Account means any account created by a data subject to access NEXTTASK's services, containing profile information, preferences, and historical data related to the use of such services.
- 1.19. Website means any website, mobile application, online platform, or digital service operated by NEXTTASK through which personal information may be collected or processed.
2. Data Collection
2.1. Types of Personal Information Collected
(a) NextTask collects the following categories of personal information from data subjects:
(b) Identity Information: Full name, username, email address, telephone number, physical address, and other contact details.
(c) Technical Information: Internet Protocol (IP) address, browser type and version, operating system, device identifiers, location data, and network access information.
(d) Usage Information: Pages visited, time spent on our services, clickstream data, search queries, feature usage patterns, and interaction history with our platforms.
(e) Account Information: Login credentials, account preferences, subscription details, payment information, and service configuration settings.
(f) Communication Information: Content of messages sent to us, feedback, support requests, and any other communications with NextTask.
2.2. Methods of Data Collection
(a) Direct Collection: Personal information provided voluntarily by data subjects through account registration, contact forms, service subscriptions, support requests, surveys, or direct communication with NextTask.
(b) Automatic Collection: Information collected automatically through cookies, web beacons, log files, and other tracking technologies when data subjects access or use our services.
(c) Third-Party Sources: Information received from third-party service providers, business partners, publicly available sources, or social media platforms where data subjects have made information publicly available.
2.3. Legal Basis for Processing
(a) NextTask processes personal information only where a lawful basis exists under POPIA and applicable South African law.
(b) Consent: Where data subjects have provided explicit, informed consent for specific processing purposes.
(c) Contractual Necessity: Where processing is necessary for the performance of a contract with the data subject or to take steps at the data subject's request prior to entering into a contract.
(d) Legitimate Interest: Where processing is necessary for NextTask's legitimate business interests, provided such interests do not override the data subject's fundamental rights and freedoms.
(e) Legal Compliance: Where processing is necessary to comply with legal obligations under South African law or court orders.
2.4. Collection Limitations
(a) NextTask will only collect personal information that is adequate, relevant, and not excessive in relation to the purpose for which it is collected.
(b) Personal information will be collected directly from the data subject unless collection from another source is authorized by law or the data subject has consented to such collection.
(c) Data subjects will be informed of the collection of their personal information and the purpose thereof, except where exempted by POPIA.
3. Purpose of Data Processing
3.1. Service Provision and Operations
(a) NextTask processes personal information to provide, maintain, and improve our technology services, including creating and managing user accounts, delivering requested services, and ensuring proper functionality of our systems.
(b) Personal information is used to authenticate users, personalize user experiences, and provide technical support and customer assistance when requested.
(c) We process data to troubleshoot technical issues, monitor system performance, and maintain the security and integrity of our services.
3.2. Communication Purposes
(a) Personal information is used to communicate with users regarding their accounts, service updates, security alerts, and administrative matters related to our services.
(b) We may use contact information to respond to user inquiries, feedback, and support requests in a timely and effective manner.
(c) Where users have provided explicit consent, we may send promotional communications, newsletters, and marketing materials about our services and related offerings.
3.3. Analytics and Business Intelligence
(a) NextTask processes usage data and analytics information to understand user behavior, improve our services, and make informed business decisions.
(b) Aggregated and anonymized data may be used for statistical analysis, research purposes, and to identify trends that help enhance user experience and service development.
(c) We analyze website traffic, user interactions, and system performance to optimize our technology infrastructure and service delivery.
3.4. Legal Compliance and Protection
(a) Personal information is processed to comply with applicable South African laws, regulations, and legal obligations, including but not limited to POPIA requirements.
(b) We may process data to establish, exercise, or defend legal claims, protect our legitimate business interests, and ensure compliance with contractual obligations.
(c) Personal information may be used to detect, prevent, and investigate fraudulent activities, security breaches, and other harmful or illegal activities that could affect our users or business operations.
3.5. Account Management and Verification
(a) We process personal information to verify user identities, manage account access, and maintain accurate user records in accordance with our terms of service.
(b) Personal information is used to implement and maintain appropriate access controls, user permissions, and account security measures.
3.6. Business Operations and Administration
(a) NextTask processes personal information for internal business administration, including record-keeping, financial management, and operational reporting.
(b) Personal information may be used in connection with business transactions such as mergers, acquisitions, or asset sales, subject to appropriate confidentiality and data protection safeguards.
3.7. Marketing and Business Development
(a) Where legally permitted and with appropriate consent, personal information may be used for direct marketing purposes, including promoting our services and communicating about new features or offerings.
(b) We may analyze user preferences and behavior to develop targeted marketing campaigns and improve our business development strategies.
(c) Personal information used for marketing purposes will only be processed in accordance with user preferences and applicable opt-out mechanisms.
4. Data Sharing and Disclosure
4.1. General Principles
-
NextTask may share or disclose Personal Information only in the limited circumstances outlined in this section, and only to the extent necessary for the specified purposes, in accordance with POPIA and applicable South African law.
4.2. Third-Party Service Providers
- Title: Information Officer
- Email: [email protected]
- General email: [email protected]
- Website contact form: www.nexttask.co.za/contact
- Website: www.justice.gov.za/inforeg
- Email: [email protected]
- Phone: 012 406 4818
- (a) The Constitution of the Republic of South Africa, 1996;
- (b) The Electronic Communications and Transactions Act, 2002 (Act No. 25 of 2002);
- (c) The Promotion of Access to Information Act, 2000 (Act No. 2 of 2000); and
- (d) Any other relevant privacy and data protection legislation enacted in South Africa.
(a) NextTask may share Personal Information with trusted third-party service providers who assist us in operating our business, providing our services, or conducting business on our behalf.
(b) Third-party service providers include but are not limited to:
(i) Google Analytics for website analytics and performance monitoring;
(ii) Cloud storage providers for secure data hosting and backup services;
(iii) Email service providers for communication and marketing purposes;
(iv) Payment processors for transaction processing and billing;
(v) Technical support and maintenance service providers.
(c) All third-party service providers are contractually bound to maintain the confidentiality and security of Personal Information and are prohibited from using such inform services to NextTask.
(d) NextTask conducts due diligence on all third-party service providers to ensure they maintain appropriate data protection standards consistent with this Privacy Policy and POPIA requirements.
4.3. Legal and Regulatory Requirements
(a) NextTask may disclose Personal Information where required or permitted by South African law, including but not limited to:
(i) Compliance with court orders, subpoenas, or other legal processes;
(ii) Cooperation with law enforcement agencies in criminal investigations;
(iii) Compliance with regulatory requirements imposed by government authorities;
(iv) Protection of NextTask's legal rights, property, or safety, or the rights and safety of others.
(b) Where legally permissible, NextTask will attempt to notify affected Data Subjects of such disclosures unless prohibited by law or court order.
4.4. Business Transfers and Corporate Transactions
(a) In the event of a merger, acquisition, sale of assets, bankruptcy, or other corporate transaction, Personal Information may be transferred to the acquiring entity or successor organization.
(b) Data Subjects will be notified of any such transfer through prominent notice on our Website or direct communication, and will be informed of any changes to this Privacy Policy resulting from the transfer.
(c) The acquiring entity or successor organization will be bound by the terms of this Privacy Policy unless Data Subjects are provided with notice and choice regarding any material changes to data handling practices.
4.5. Consent-Based Sharing
(a) NextTask may share Personal Information with third parties where Data Subjects have provided explicit, informed Consent for such sharing.
(b) Consent for data sharing will clearly specify the categories of Personal Information to be shared, the identity of the recipient, and the purpose of the sharing.
(c) Data Subjects may withdraw their Consent for data sharing at any time by contacting NextTask using the contact information provided in Section 15 of this Privacy Policy.
4.6. Data Processing by Data Processors
(a) Where NextTask engages Data Processors to process Personal Information on our behalf, such processing will be governed by written agreements that ensure compliance with POPIA requirements.
(b) Data Processors are contractually prohibited from processing Personal Information for their own purposes and must implement appropriate security measures to protect the Personal Information.
4.7. No Sale of Personal Information
NextTask does not sell, rent, or lease Personal Information to third parties for commercial purposes, nor do we receive monetary compensation in exchange for sharing Personal Information with third parties.
5. User Rights
5.1. Right of Access
(a) You have the right to request confirmation from NextTask as to whether we hold any of your Personal Information.
(b) Where NextTask processes your Personal Information, you may request access to such information and receive details about the purpose of processing, categories of Personal Information involved, and the recipients or categories of recipients to whom the Personal Information has been disclosed.
(c) NextTask will provide you with a copy of your Personal Information in a commonly used electronic format upon request, subject to verification of your identity.
(d) Access requests will be responded to within 30 (thirty) days of receipt, unless an extension is required due to the complexity of the request, in which case you will be notified of the delay.
5.2. Right to Correction
(a) You have the right to request the correction, updating, or completion of Personal Information that is inaccurate, outdated, incomplete, irrelevant, or misleading.
(b) NextTask will take reasonable steps to correct Personal Information within 30 (thirty) days of receiving a valid correction request.
(c) Where Personal Information has been disclosed to Third Parties, NextTask will notify such parties of the correction where reasonably practicable to do so.
5.3. Right to Deletion
(a) You may request the deletion of your Personal Information where the information is no longer necessary for the purpose for which it was collected, you withdraw Consent, or the Processing is unlawful.
(b) NextTask will assess deletion requests against legitimate business needs, legal obligations, and Data Retention requirements before proceeding with deletion.
(c) Where deletion is not possible due to applicable legal or legitimate business requirements, NextTask will restrict the Processing of such Personal Information.
5.4. Right to Data Portability
(a) Where technically feasible, you have the right to receive your Personal Information in a structured, commonly used, and machine-readable format.
(b) You may request that NextTask transmit your Personal Information directly to another Responsible Party where technically possible.
5.5. Right to Object
(a) You have the right to object to the Processing of your Personal Information for Direct Marketing purposes at any time.
(b) You may object to Processing based on legitimate interests by providing reasonable grounds relating to your particular situation.
(c) NextTask will cease Processing upon receiving a valid objection unless compelling legitimate grounds override your interests.
5.6. Right to Withdraw Consent
(a) Where Processing is based on your Consent, you have the right to withdraw such Consent at any time.
(b) Withdrawal of Consent will not affect the lawfulness of Processing based on Consent before its withdrawal.
(c) You may withdraw Consent by contacting NextTask using the details provided in Section 15.
5.7. Right to Lodge a Complaint
(a) You have the right to lodge a complaint with the Information Regulator of South Africa if you believe NextTask has violated your privacy rights.
(b) Contact details for the Information Regulator are available at www.justice.gov.za/inforeg.
5.8. Exercise of Rights
(a) All rights under this Section 5 may be exercised by contacting NextTask's Information Officer using the contact details in Section 15.
(b) NextTask may require reasonable verification of your identity before processing any rights request.
(c) Rights requests will be processed free of charge unless the request is manifestly unfounded, excessive, or repetitive, in which case a reasonable administrative fee may be charged.
6. Data Security Measures
6.1. General Security Commitment
NextTask implements appropriate technical and organizational security measures designed to protect Personal Information against unauthorized access, use, disclosure, alteration, or destruction, taking into account the nature of the Personal Information, the harm that might result from unauthorized processing, and available technology and implementation costs.
6.2. Technical Security Measures
(a) NextTask employs industry-standard encryption protocols to protect Personal Information during transmission and storage, including SSL/TLS encryption for data in transit and encryption at rest for sensitive data.
(b) Access controls are implemented to ensure that only authorized personnel can access Personal Information, with user authentication mechanisms including secure passwords and multi-factor authentication where appropriate.
(c) Regular security updates and patches are applied to all systems and software used in processing Personal Information to address known vulnerabilities and security threats.
(d) Automated backup systems are maintained to ensure data integrity and availability, with backups stored securely and tested regularly for restoration capabilities.
(e) Firewalls and intrusion detection systems are deployed to monitor and protect against unauthorized network access and malicious activities.
6.3. Organizational Security Measures
(a) All employees and contractors with access to Personal Information receive appropriate training on data protection requirements and security best practices under POPIA and this Privacy Policy.
(b) Confidentiality agreements are executed with all personnel who may have access to Personal Information in the course of their duties.
(c) Access to Personal Information is granted on a need-to-know basis and is regularly reviewed to ensure continued appropriateness.
(d) Clear data handling procedures and security protocols are established and regularly updated to reflect current best practices and regulatory requirements.
6.4. Third-Party Security Requirements
(a) NextTask requires all Third Party service providers and Data Processors to implement appropriate security measures and comply with contractual data protection obligations equivalent to those set out in this Privacy Policy.
(b) Due diligence assessments are conducted on Third Party providers before engagement to evaluate their security capabilities and compliance with applicable data protection laws.
6.5. Physical Security Measures
(a) Physical access to systems and facilities containing Personal Information is restricted to authorized personnel through appropriate access controls and monitoring systems.
(b) Secure disposal procedures are implemented for all physical media containing Personal Information, including secure destruction or wiping of data storage devices.
6.6. Security Monitoring and Incident Response
(a) NextTask maintains ongoing monitoring of security systems and conducts regular security assessments to identify and address potential vulnerabilities.
(b) An incident response plan is in place to promptly detect, assess, and respond to security incidents that may affect Personal Information.
6.7. Limitations of Security Measures
(a) While NextTask implements reasonable security measures appropriate to its size and resources, no security system is completely impenetrable, and NextTask cannot guarantee absolute security of Personal Information.
(b) Users are responsible for maintaining the security of their own devices and access credentials when using NextTask's services.
7. Data Retention
7.1. General Retention Principle
NextTask retains Personal Information only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
7.2. Standard Retention Periods:
NextTask has established the following standard retention periods for different categories of Personal Information:
(a) Account information and user profiles: retained for the duration of the active user account plus two (2) years after account closure or last activity.
(b) Transaction records and service usage data: retained for seven (7) years from the date of the transaction or service provision to comply with financial record-keeping requirements.
(c) Marketing communications and consent records: retained for three (3) years from the date of last interaction or until consent is withdrawn.
(d) Website analytics and technical logs: retained for thirteen (13) months from the date of collection.
(e) Customer support communications: retained for three (3) years from the date of the last communication.
(f) Legal compliance records: retained for the period required by applicable South African law or ten (10) years, whichever is longer.
7.3. Extended Retention
NextTask may retain Personal Information beyond the standard periods where:
(a) required by South African law, court order, or regulatory authority;
(b) necessary for ongoing legal proceedings or investigations;
(c) required to protect NextTask's legitimate business interests, subject to Data Subject rights under POPIA;
(d) the Data Subject has provided explicit consent for extended retention.
7.4. Retention Criteria
When determining retention periods for Personal Information not covered by standard periods, NextTask considers:
(a) the nature and sensitivity of the Personal Information;
(b) the purposes for which the information was collected and processed;
(c) applicable legal and regulatory requirements;
(d) legitimate business needs and operational requirements;
(e) the potential risks to Data Subjects from continued retention.
7.5. Secure Deletion Procedures
Upon expiry of the retention period, NextTask implements the following deletion procedures:
(a) Digital Data: Personal Information stored electronically is permanently deleted using industry-standard data wiping techniques that render the information irrecoverable.
(b) Physical Records: Hard copy documents containing Personal Information are securely destroyed through cross-cut shredding or incineration by authorized service providers.
(c) Backup Systems: Personal Information in backup systems is deleted according to the backup retention schedule, which does not exceed the primary data retention periods by more than six (6) months.
(d) Third-Party Systems: NextTask ensures that third-party service providers delete Personal Information in accordance with contractual obligations and this Policy's retention requirements.
7.6. Anonymization
Where Personal Information has legitimate ongoing value for statistical, research, or analytical purposes, NextTask may anonymize the data by removing all identifying elements, rendering it no longer Personal Information under POPIA.
7.7. Retention Register
NextTask maintains an internal register documenting retention periods for different categories of Personal Information and the legal basis for such retention periods.
7.8. Data Subject Requests
Data Subjects may request information about the retention period applicable to their Personal Information by contacting NextTask using the details provided in this Policy.
8. Data Breach Procedures
8.1. Data Breach Detection and Assessment
(a) NextTask maintains monitoring systems and procedures to detect potential data breaches affecting personal information under our control.
(b) Upon detection or notification of a suspected data breach, NextTask will immediately conduct an assessment to determine the nature, scope, and potential impact of the breach.
(c) The assessment will include identification of the personal information involved, the number of data subjects affected, the cause of the breach, and the potential risks to data subjects.
8.2. Notification to the Information Regulator
(a) Where a data breach is likely to result in harm to a data subject, NextTask will notify the Information Regulator within seventy-two (72) hours of becoming aware of the breach, as required under POPIA.
(b) The notification to the Information Regulator will include details of the breach, categories of personal information affected, approximate number of data subjects involved, likely consequences, and measures taken or proposed to address the breach.
(c) Where the notification cannot be made within 72 hours, NextTask will provide reasons for the delay along with the notification.
8.3. Notification to Data Subjects
(a) NextTask will notify affected data subjects of a data breach without undue delay where the breach is likely to result in a high risk of harm to the data subject.
(b) Data subject notifications will be made through email, direct communication, or public notice where individual notification is not reasonably practicable.
(c) The notification will include a description of the breach in clear and plain language, categories of personal information involved, likely consequences, and measures taken to address the breach and mitigate harm.
8.4. Remedial Actions and Response Measures
(a) NextTask will take immediate steps to contain the breach and prevent further unauthorised access to personal information.
(b) We will implement corrective measures to address the cause of the breach and strengthen our security measures to prevent similar incidents.
(c) NextTask will provide affected data subjects with information about steps they can take to protect themselves from potential harm resulting from the breach.
8.5. Documentation and Record Keeping
(a) NextTask will maintain detailed records of all data breaches, including the circumstances of the breach, its effects, and remedial actions taken.
(b) These records will be made available to the Information Regulator upon request and will be retained in accordance with our data retention policies.
9. Cookies and Tracking Technologies
9.1. Cookies Defined
Cookies are small text files that are placed on your device when you visit our website or use our services. These files contain information that is transferred to your device's hard drive and allow us to recognize your device and remember certain information about your visit.
9.2. Types of Cookies Used
(a) Essential Cookies: Strictly necessary cookies that enable basic website functionality and cannot be disabled without affecting the core operation of our services.
(b) Performance Cookies: Cookies that collect information about how visitors use our website, including which pages are visited most often and any error messages received.
9.3. Other Tracking Technologies
In addition to cookies, we may use other tracking technologies, including:
(a) Local storage technologies to store information locally on your device.
(b) Analytics tools such as Google Analytics to understand user behaviour and improve our services.
9.4. Purposes of Use
We use cookies and tracking technologies for the following purposes:
(a) To provide and maintain the functionality of our services.
(b) To analyse website traffic and user behaviour to improve our services.
(c) To detect and prevent fraud and security threats.
9.5. Cookie Duration
Cookies may be either:
(a) Session cookies: Temporary cookies that expire when you close your browser.
(b) Persistent cookies: Cookies that remain on your device for a predetermined period or until manually deleted.
9.6. Third-Party Cookies
Some cookies are placed by third-party service providers we work with, including Google Analytics, advertising networks, and social media platforms. These third parties have their own privacy policies governing their use of cookies.
9.7. User Control and Management
You have several options for managing cookies:
(a) You can modify your browser settings to accept, reject, or notify you when cookies are being used.
(b) You can delete existing cookies through your browser's settings or clear browsing data function.
(c) Most browsers allow you to block third-party cookies while still accepting first-party cookies.
(d) You can opt out of interest-based advertising through industry opt-out tools.
9.8. Cookie Consent
By continuing to use our website after being informed of our cookie use, you consent to our use of cookies as described in this policy. You may withdraw this consent at any time by adjusting your browser settings or contacting us directly.
9.9. Impact of Disabling Cookies
Please note that disabling certain cookies may limit your ability to use some features of our website or services, and may affect the overall functionality and user experience.
9.10. Cookie Policy Updates
We may update our use of cookies and tracking technologies from time to time. Any material changes will be communicated through our standard policy update procedures as outlined in Section 14 of this Privacy Policy.
10. International Data Transfers
10.1. Cross-Border Data Transfers
NextTask may transfer personal information outside the borders of South Africa to facilitate our business operations, including but not limited to cloud storage services, data analytics platforms, and third-party service providers located in other jurisdictions.
10.2. Lawful Basis for Transfer
All international transfers of personal information are conducted in accordance with Chapter 9 of POPIA and only occur where:
(a) The data subject has provided explicit consent to the transfer after being informed of the possible risks;
(b) The transfer is necessary for the performance of a contract between NextTask and the data subject;
(c) The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject;
(d) The transfer is for the benefit of the data subject and it is not reasonably practicable to obtain consent; or
(e) The Information Regulator has approved the transfer.
10.3. Adequacy Assessment
Before transferring personal information to any third country, NextTask conducts an assessment to determine whether the recipient country provides an adequate level of protection for personal information as required under POPIA.
10.4. Safeguards and Protections
Where personal information is transferred to countries that do not provide adequate protection, NextTask implements appropriate safeguards including:
(a) Binding corporate rules approved by the Information Regulator;
(b) Standard contractual clauses that include data protection obligations equivalent to those under POPIA;
(c) Codes of conduct or certification mechanisms that provide sufficient safeguards; or
(d) Other legally recognized adequacy mechanisms.
10.5. Current Transfer Arrangements
NextTask currently transfers personal information to the following jurisdictions for the stated purposes:
(a) United States: For cloud storage services and analytics platforms, protected by standard contractual clauses and Privacy Shield framework where applicable;
(b) European Union: For data processing services, relying on the European Commission's adequacy decision and GDPR compliance measures.
10.6. Third-Party Processor Obligations
All third-party processors receiving personal information from NextTask are contractually bound to:
(a) Process personal information only in accordance with NextTask's documented instructions;
(b) Implement appropriate technical and organizational security measures;
(c) Ensure confidentiality of personal information;(d) Assist NextTask in responding to data subject requests; and
(e) Notify NextTask immediately of any data breaches.
10.7. Data Subject Rights Regarding Transfers
Data subjects have the right to:
(a) Be informed of any international transfers of their personal information;
(b) Object to transfers that are not based on their consent or other lawful grounds;
(c) Withdraw consent for transfers where consent was the legal basis; and
(d) Request information about the safeguards in place for international transfers.
10.8. Monitoring and Review
NextTask regularly reviews and monitors international data transfers to ensure ongoing compliance with POPIA requirements and the effectiveness of implemented safeguards.
11. Third-Party Services
11.1. NextTask engages third-party service providers to support various aspects of our operations and service delivery, which may involve the processing of personal information on our behalf or independently.
11.2. We implement appropriate contractual safeguards with third-party processors to ensure personal information is processed in accordance with this Privacy Policy and applicable South African data protection laws.
11.3. The following categories of third-party services are commonly utilized by NextTask:
(a) Cloud hosting and storage providers for secure data storage and backup services.
(b) Analytics services including Google Analytics for website traffic analysis and user behavior insights.
(c) Email marketing and communication platforms for sending newsletters, updates, and service-related communications.
(d) Customer support and help desk software for managing user inquiries and technical support requests.
(e) Payment processing services for handling financial transactions where applicable.
(f) Security and monitoring tools for protecting our systems and detecting potential threats.
11.4. When personal information is shared with third-party service providers, such sharing occurs only:
(a) Where necessary for the provision of services to users.
(b) Under written agreements that require the third party to maintain appropriate security measures and use personal information solely for the specified purposes.
(c) Where the third party provides adequate protection for personal information equivalent to the standards required under POPIA.
11.5. We do not authorize third-party service providers to use personal information for their own marketing purposes without explicit user consent.
11.6. Users may access the privacy policies of our key third-party service providers through the following links, which will be updated as our service providers change:
(a) Google Analytics: https://policies.google.com/privacy
(b) Additional third-party privacy policies will be listed here as services are implemented.
11.7. NextTask remains responsible for ensuring that third-party processors comply with applicable data protection requirements and will take appropriate action if we become aware of any non-compliance.
11.8. Users may request information about specific third-party processors handling their personal information by contacting us using the details provided in Section 15 of this Privacy Policy.
12. Commercial Use of Data
12.1. Data Sale Policy: NextTask does not sell Personal Information to third parties for monetary consideration or other valuable consideration.
12.2. Commercial Use Limitations: NextTask does not use Personal Information primarily for profit-making activities beyond the provision of our core technology services to Users.
12.3. Service-Related Commercial Activities:
NextTask may use Personal Information for the following commercial purposes directly related to our services:
(a) Processing payments and managing User Accounts;
(b) Providing customer support and technical assistance;
(c) Developing and improving our technology services;
(d) Conducting business analytics to enhance user experience.
12.4. Marketing Communications:
NextTask may use Personal Information to send promotional materials and service updates only where:
(a) The Data Subject has provided explicit Consent for Direct Marketing; or
(b) Such communications relate directly to services previously purchased or enquired about by the Data Subject.
12.5. Third-Party Commercial Sharing:
NextTask does not share Personal Information with Third Parties for their independent commercial use, except:
(a) Where required by law or legal process;
(b) Where the Data Subject has provided specific Consent for such sharing;
(c) In connection with a business transfer, merger, or acquisition, subject to equivalent privacy protections.
12.6. Revenue Generation Disclosure:
Any revenue generated by NextTask through data-related activities is limited to fees charged directly to Users for services provided and does not involve monetization of Personal Information itself.
12.7. Consent Withdrawal:
Data Subjects may withdraw Consent for any commercial use of their Personal Information at any time by contacting NextTask using the details provided in Section 15 of this Policy.
13. Children's Privacy
13.1. Age Restrictions:
NextTask's services are not intended for, and we do not knowingly collect Personal Information from, children under the age of 18 years without appropriate parental or guardian consent as required by POPIA and other applicable South African laws.
13.2. Parental Consent Requirements:
Where we become aware that we are Processing Personal Information of a child under 18 years of age, we will:
(a) Immediately cease Processing such information unless we have obtained prior written consent from the child's parent or legal guardian;
(b) Take reasonable steps to verify the identity of the parent or guardian before obtaining such consent;
(c) Clearly explain to the parent or guardian what Personal Information we collect, how we use it, and with whom we may share it.
13.3. Limited Collection from Minors:
When we have obtained proper parental consent, we will only collect Personal Information from children that is reasonably necessary for the specific purpose for which consent was given.
13.4. Parental Rights:
Parents and legal guardians have the right to:
(a) Review any Personal Information we have collected from their child;
(b) Request correction or deletion of their child's Personal Information;
(c) Refuse to permit further collection or use of their child's Personal Information;
(d) Withdraw consent at any time by contacting us using the details provided in Section 15.
13.5. Age Verification:
While we do not actively verify the age of our users, we encourage parents to monitor their children's online activities and to contact us immediately if they believe their child has provided Personal Information to us without consent.
13.6. Deletion of Unauthorized Information:
If we discover that we have collected Personal Information from a child under 18 without proper parental consent, we will delete such information from our systems within 30 days of discovery.
13.7. Educational Use:
Where NextTask services are used in educational settings, we may rely on the school or educational institution to obtain appropriate consents and to act in the best interests of the child, subject to our agreement with such institution.
14. Policy Updates and Amendments
14.1. Right to Amend:
NextTask reserves the right to modify, update, or amend this Privacy Policy at any time to reflect changes in our business practices, legal requirements, or technological developments.
14.2. Types of Changes:
Policy updates may include changes to data collection practices, processing purposes, third-party integrations, user rights procedures, security measures, or contact information.
14.3. Material Changes:
Material changes that significantly affect how personal information is processed or user rights are exercised will be subject to enhanced notification procedures as outlined in clause 14.6.
14.4. Review Process:
NextTask will periodically review this Privacy Policy to ensure ongoing compliance with applicable laws and alignment with industry best practices. Reviews will consider user feedback, regulatory developments, and changes in our service offerings.
14.5. Effective Date:
Any amendments to this Privacy Policy will become effective on the date specified in the updated policy, which will be clearly indicated at the top of the document.
14.6. Notification Methods:
NextTask will notify users of material changes to this Privacy Policy through one or more of the following methods at least thirty (30) days prior to the effective date of the changes:
(a) Website Notice: Prominent notice displayed on our website homepage and service pages for a minimum of thirty (30) days.
(b) Email Notification: Direct email notification to all registered users with active accounts, sent to their registered email addresses.
(c) In-Service Notifications: Pop-up notifications or banner messages within our services requiring user acknowledgment before continued use.
(d) Account Dashboard: Updates posted to user account dashboards or control panels where applicable.
14.7. Version Control:
Each version of this Privacy Policy will be clearly marked with a version number and effective date to enable users to identify current and previous versions.
14.8. Archive Access:
Previous versions of this Privacy Policy will be archived and made accessible to users upon request for a period of at least two (2) years following the date of amendment.
14.9. Continued Use:
By continuing to use NextTask's services after the effective date of any amendments to this Privacy Policy, users acknowledge and agree to be bound by the updated terms.
14.10. Withdrawal Rights:
Users who do not agree with the amended Privacy Policy have the right to withdraw their consent and discontinue use of NextTask's services prior to the effective date of the changes.
14.11. Emergency Updates:
In exceptional circumstances where immediate changes are required to address urgent legal or security issues, NextTask may implement emergency updates to this Privacy Policy. In such cases, we will notify users as soon as practicable following the changes.
15. Contact Information
15.1. For all privacy-related inquiries, concerns, complaints, or requests regarding the processing of personal information under this Privacy Policy, data subjects may contact NextTask through the following channels.
15.2. Designated Information Officer:
(a) NextTask has appointed an Information Officer as required under POPIA to handle all privacy-related matters and data subject requests.
(b) The Information Officer can be contacted at:
15.3. Company Contact Information
(a) NextTask's registered business address for privacy-related correspondence: 21 Milldene Avenue, Cape Town, Western Cape, 7700 South Africa
(b) Alternative contact methods:
15.4. Response Timeframes
(a) NextTask will acknowledge receipt of privacy-related inquiries within 72 hours, excluding weekends and public holidays.
(b) Substantive responses to data subject requests will be provided within 30 days of receipt, or such other timeframe as may be required under POPIA.
15.5. Complaints to Regulatory Authority
(a) Data subjects have the right to lodge complaints with the Information Regulator of South Africa if they believe NextTask has not adequately addressed their privacy concerns.
(b) The Information Regulator can be contacted at:
16. Governing Law and Jurisdiction
16.1. This Privacy Policy and all matters arising from or relating to the processing of personal information by NextTask shall be governed by and construed in accordance with the laws of the Republic of South Africa.
16.2. The processing of personal information under this Privacy Policy is specifically subject to the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) and its regulations, as amended from time to time.
16.3. This Privacy Policy shall also be governed by other applicable South African legislation including but not limited to:
16.4. Any disputes arising from or in connection with this Privacy Policy or the processing of personal information shall be subject to the exclusive jurisdiction of the South African courts.
16.5. Where any provision of this Privacy Policy conflicts with applicable South African law, the law shall prevail and the conflicting provision shall be deemed amended to comply with such law.
16.6. NextTask's obligations as a responsible party under POPIA shall take precedence over any conflicting provisions in this Privacy Policy.
This Privacy Policy has been duly authorized and approved by NEXTTASK on 31/1/2024.