Privacy Policy

Monday Magic (Pty) Ltd ·

Registration number 2018/009467/07

Last updated: 23 July 2026

Effective from: 1 August 2026

About this Policy :

Monday Magic (Pty) Ltd (“Monday Magic”, “we”, “us”, “our”) is committed to protecting the personal information entrusted to us. This Privacy Policy explains how we collect, use, share, store and protect personal information, and sets out the rights available to data subjects.

This Policy is issued in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), and should be read together with our Terms of Use, our Cookie Policy, and our PAIA Manual.

Capitalised terms used in this Policy carry the meanings given to them in our Terms of Use, save where defined differently below.

Our role. In relation to personal information processed through the Platform, Monday Magic acts as the Responsible Party as contemplated in section 1 of POPIA. Our Partners act as Operators processing personal information on our instruction and on our behalf.

Where the Sponsor determines the purpose of processing in respect of its own employment or engagement records, the Sponsor acts as an independent Responsible Party in respect of that processing, and its own privacy notice applies.

Definitions :

In these terms:

“Data Subject”, means the person to whom personal information relates.

“Operator” means a person who processes personal information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party.

“Personal Information”bears the meaning given in section 1 of POPIA.

“Processing” bears the meaning given in section 1 of POPIA, and includes collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, erasure and destruction.

“Responsible Party” means the party that determines the purpose of and means for processing personal information.

“Special Personal Information” bears the meaning given in section 26 of POPIA, and includes information concerning a Data Subject’s health, biometrics, religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, sex life, or criminal behaviour.

“the Platform”, “the Sponsor”, “the User”, “a Benefit”, “a Partner” and “the Emergency Line” bear the meanings given in our Terms of Use.

Information Officer :

In accordance with sections 55 and 56 of POPIA, Monday Magic has designated an Information Officer who is registered with the Information Regulator.

Information Officer: ‍ ‍

Robyn Felicity Talbot

Director

Designation: ‍ ‍

Email :

Postal address:

[ADDRESS]

The Information Officer is responsible for encouraging compliance with the conditions for lawful processing, dealing with requests made to Monday Magic under POPIA and the Promotion of Access to Information Act 2 of 2000 (“PAIA”), working with the Information Regulator in relation to investigations, and otherwise ensuring compliance with POPIA.

The personal information we process :

Information received from the Sponsor :

We receive the following categories of personal information from the Sponsor in order to establish and maintain a User’s access to the Platform:

Examples

Service

Why we need it


Mobile telephone number, and where provided, email address

Contact data

To deliver Benefits, one-time PINs and service messages

Sponsor name, employee or reference number, date of commencement, date of birth, work anniversary date

Engagement data

To confirm eligibility and to determine when birthday and anniversary Benefits fall due

Active or inactive status on the Sponsor’s eligibility file

Status data

To determine whether access should continue

To verify eligibility and authenticate the User at login

Identity data

Full name, surname, identity number or passport number

The Sponsor warrants to us that it has a lawful basis for providing this information and that the information is accurate, complete and current.

Information generated through use of the Platform :

Examples

Service

Why we need it


Benefits issued, voucher and coupon codes issued, redemption records, dates and values

Transaction data

To administer Benefits, reconcile with Partners, and detect misuse

Messages sent to the User and delivery status

Communication data

To confirm delivery and resolve queries

Device type, browser type, operating system, IP address, and session information

Technical data

To operate and secure the Platform. See our Cookie Policy

To secure the Platform and prevent unauthorised access

Authentication data

Login records, one-time PIN issuance and verification records

To understand how the service is used and improve its performance. Configured not to receive names, identity or passport numbers or contact details

Analytics data

Support data

Pages viewed, referring source, approximate location and device information, collected across our website and the Platform

Records of queries, complaints and their resolution

To assist the User and improve the service

Information processed in connection with emergency assistance :

When a User contacts the Emergency Line, additional personal information is processed. Some of this constitutes Special Personal Information concerning the User’s health.

Service

Examples


Call recordingsDate, time, nature of the incident, and the location of the User

Incident data

Information disclosed during clinical triage, the nature of the medical condition or injury, the level of care determined to be appropriate, and the receiving medical facility

Clinical data

Vehicle description, registration number, and proof of ownership or lease, in the case of roadside assistance

Vehicle data

Vehicle description, registration number, and proof of ownership or lease, in the case of roadside assistance

Claim data

Telephone calls to the Emergency Line are recorded for quality assurance, case management and audit purposes

Call recordings

Lawful basis for processing health information. In terms of section 27(1)(d) of POPIA, the prohibition on processing Special Personal Information does not apply where processing is necessary for the establishment, exercise or defence of a right or obligation in law, and in terms of section 27(1)(b), where processing is necessary to protect a legitimate interest of the Data Subject and consent cannot be obtained. Processing of health information in an emergency is further justified under section 32(1) of POPIA, which permits processing of health information by medical professionals and healthcare institutions where such processing is necessary for the proper treatment and care of the Data Subject.

In addition, by accepting our Terms of Use the User consents in terms of section 27(1)(a) of POPIA to the processing of health information for the sole purpose of arranging and coordinating emergency assistance.

We do not use health information for any purpose other than arranging, coordinating, managing and reconciling the emergency assistance requested. It is never used for marketing, never shared with the Sponsor in identifiable form, and never used to make any decision about a User’s eligibility for any Benefit.

Information we do not process

We do not collect or process :

Financial account details, card numbers or banking information of Users

Biometric information

Information concerning race, ethnic origin, religious or philosophical beliefs, political persuasion, trade union membership, or sex life

Criminal behaviour information

Personal information of children under the age of 18

We do not operate advertising or marketing tracking technology, including Meta Pixel or any other social media tracking pixel, on our website or on the Platform. We do not provide a User’s name, identity number, passport number or contact details to any analytics provider

Purposes of processing

We process personal information only for the following purposes:

Service delivery. To establish and maintain User access, verify eligibility, authenticate Users, issue and deliver Benefits, coordinate emergency assistance, and administer the Platform.

Communication. To send one-time PINs, Benefit notifications, service messages, and responses to queries.

Reconciliation and administration. To reconcile Benefit issuance and redemption with Partners, verify invoices, and maintain accurate financial records.

Fraud prevention and misuse detection. To monitor for irregular patterns of Benefit usage, prevent unauthorised access, and investigate suspected misuse in accordance with our Terms of Use.

Reporting to the Sponsor. To provide the Sponsor with aggregated and de-identified reporting on Benefit uptake and engagement. We do not report individual Benefit usage to the Sponsor, save where required in terms of clause 6 of our Terms of Use in cases of suspected fraud, or where required by law.

Legal and regulatory compliance. To comply with our obligations under POPIA, PAIA, the Consumer Protection Act 68 of 2008, the Companies Act 71 of 2008, tax legislation, and any lawful request from a competent authority.

Service improvement. To analyse aggregated and de-identified usage patterns in order to improve the Platform and the Benefit mix.

Analytics and performance. To measure and analyse how our website and the Platform are used, in order to improve performance, fix problems and understand which Benefits are valued. Analytics information is used in aggregate and is not used to build a profile of, or make decisions about, any individual User.

We do not process personal information for any purpose incompatible with those listed above, and we do not sell personal information.

Lawful basis for processing

We rely on the following justifications under section 11 of POPIA:


Service

Where it applies

Section 11(1)(b) — necessary to conclude or perform a contract

Delivery of the Benefits the User has been given access to

Section 11(1)(c) — compliance with a legal obligation

Retention of records for tax, company law and regulatory purposes

Acceptance of our Terms of Use on first login; consent to processing of health information for emergency assistance

Section 11(1)(a) — consent of the Data Subject

Coordination of emergency assistance where the User may be unable to consent

Section 11(1)(d) — protection of a legitimate interest of the Data Subject

Fraud prevention, security of the Platform, aggregated reporting to the Sponsor

Section 11(1)(f) — legitimate interests of the Responsible Party or a third party

Where we rely on consent, the User may withdraw that consent at any time by contacting the Information Officer. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and may mean that we can no longer provide some or all of the Benefits.

Sharing personal information

Our Partners

Information shared

Partner category

Purpose


Name, identity number or passport number, mobile number, active status, and incident information disclosed during the call

Emergency assistance Partner

Name, identity number or passport number, mobile number, active status, and incident information disclosed during the call

Mobile number and a Benefit reference

Gifting and voucher Partner

To issue and deliver voucher codes

All Platform data, in encrypted form

Hosting and technology Partner

To host and operate the Platform

Pages viewed, device and approximate location information. No name, identity number, passport number or contact details

Analytics provider

To provide aggregated analytics on website and Platform performance

To verify that the User qualifies to receive coupons

Lifestyle savings Partner

Identity number or passport number, and active status

To deliver messages and one-time PINs

Communications Partner

Communications Partner

Each Partner is contractually bound as an Operator in terms of section 20 and section 21 of POPIA to process personal information only on our documented instruction, to establish and maintain appropriate security safeguards, to treat the information as confidential, and to notify us immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.

No Partner is permitted to use personal information for its own purposes, for marketing, or for onward disclosure, without our prior written authorisation.

The Sponsor

We provide the Sponsor with aggregated and de-identified reporting only.

We will disclose individual information to the Sponsor only where:

the User has consented to that disclosure;

disclosure is necessary to investigate suspected fraud or misuse in accordance with clause 6 of our Terms of Use; or

disclosure is required by law.

Other disclosures

We may disclose personal information where:

required by law, court order, or a lawful request from a competent regulatory or law enforcement authority;

necessary to establish, exercise or defend a legal right;

necessary to protect the life or health of the User or another person; or

in connection with a corporate transaction, provided that the recipient is bound to protect the information on terms no less protective than this Policy.

Cross-border transfers

Personal information relating to a User’s Benefits, account and use of emergency assistance is stored and processed within the Republic of South Africa. Our Partners are contractually prohibited from transferring that information outside South Africa without our prior written authorisation.

Website and Platform analytics are the exception. We use Google Analytics across both our website and the Platform to understand how the service is used and to improve its performance over time. Google Analytics is operated by Google LLC, and the information it collects, including IP address, device information and pages viewed, may be processed on servers located outside South Africa.

This transfer is permitted in terms of section 72(1)(a) of POPIA, on the basis that the recipient is subject to binding corporate rules and contractual terms which uphold principles for the reasonable processing of information substantially similar to the conditions for lawful processing under POPIA. We have concluded Google’s data processing terms, which incorporate the European Commission’s Standard Contractual Clauses. Where consent is required, the transfer is further justified in terms of section 72(1)(b) of POPIA, on the basis of consent obtained through our cookie banner.

We have configured our analytics so that it does not receive a User’s name, identity number, passport number or contact details. We do not use analytics to build a profile of any individual User, and we do not use it to make any decision about a User or their access to Benefits. Analytics information is used in aggregate.

We have enabled IP anonymisation and disabled Google Signals, advertising features, remarketing and data sharing with Google for its own purposes.

We do not use Meta Pixel or any other social media tracking technology, on our website or on the Platform.

Should our position change, we will amend this Policy, obtain any consent required, and ensure that any transfer complies with section 72 of POPIA.

Security safeguards :

In accordance with sections 19 to 21 of POPIA, we secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information, and unlawful access to or processing of personal information.

Our measures include:

Encryption of personal information in transit and at rest

Access control on a least-privilege, need-to-know basis, with unique user identifiers and no shared credentials

Authentication of Users by identity number or passport number together with a one-time PIN

Logging and monitoring of access to systems containing personal information

Vulnerability management, including regular internal and external scanning and timely patching

Contractual safeguards imposed on every Operator, including the right to audit

Confidentiality undertakings binding on all personnel with access to personal information

Backup and recovery procedures, with backups subject to the same controls as primary systems

Secure destruction of personal information when the retention period ends

We identify reasonably foreseeable internal and external risks, establish and maintain safeguards against those risks, regularly verify that the safeguards are effectively implemented, and update them in response to new risks.

Security compromises :

Should a security compromise occur in which there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will, in accordance with section 22 of POPIA:

Notify the Information Regulator as soon as reasonably possible after discovery, via the Regulator’s eServices Portal, as required since 1 April 2025;

Notify affected Data Subjects as soon as reasonably possible, unless the identity of affected Data Subjects cannot be established, or a public body responsible for detection or investigation of offences, or the Regulator, directs otherwise;

Provide sufficient information to allow affected Data Subjects to take protective measures, including a description of the possible consequences, the measures we intend to take or have taken, and our recommendation on steps the Data Subject should take; and

Where the identity of the unauthorised person is known, disclose that identity to the Data Subject if the Regulator so directs.

Notification will be delivered in writing by email or SMS to the contact details we hold, and where appropriate by prominent notice on the Platform.

Retention and destruction

In accordance with section 14 of POPIA, we retain personal information only for as long as necessary to achieve the purpose for which it was collected, unless a longer retention period is required or authorised by law.


Category

Retention period

Support and complaint records

3 years from resolution

Technical and security logs

12 months

For the duration of access, plus 12 months

Identity, contact and engagement data

5 years from the end of the financial year in which the transaction occurred, in accordance with the Companies Act and tax legislation

Transaction and Benefit records

5 years from the date of the incident, or such longer period as may be required in respect of a Road Accident Fund claim or potential legal proceedings

Emergency incident and clinical records

12 months, unless required for a specific case, claim or dispute

Emergency Line call recordings

Indefinitely, as it no longer constitutes personal information

De-identified and aggregated data

At the end of the applicable period, personal information is destroyed or de-identified in a manner that prevents its reconstruction in an intelligible form.

Data subject rights

Data Subjects have the following rights under POPIA:

12.1 The right to be notified that personal information is being collected, and where it has been accessed by an unauthorised person (sections 18 and 22).

12.2 The right of access — to request confirmation, free of charge, of whether we hold personal information about the Data Subject, and to request a record or description of that information, including the identity of third parties who have had access to it (section 23). A prescribed fee may apply to the provision of the record itself.

12.3 The right to correction or deletion — to request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully (section 24).

12.4 The right to object — to object, on reasonable grounds, to the processing of personal information where processing is based on section 11(1)(d), (e) or (f) (section 11(3)).

12.5 The right to withdraw consent where processing is based on consent (section 11(2)).

12.6 The right not to be subject to automated decision-making that results in legal consequences or substantially affects the Data Subject (section 71).

12.7 The right to complain to the Information Regulator (section 74).

12.8 The right to institute civil proceedings in respect of an alleged interference with the protection of personal information (section 99).

How to exercise these rights

Requests should be directed to the Information Officer at support@mondaymagic.co, using Form 2 prescribed under the POPIA Regulations for access requests, and Form 1 for objections to processing.

We will respond within 30 days of receipt. Where a request is complex or we require additional time, we will inform the requester of the extension and the reasons for it.

Where the personal information originated from the Sponsor, and the request concerns the accuracy of that information, we may direct the Data Subject to the Sponsor, as the Sponsor is the source and remains responsible for its accuracy.

Direct marketing

We do not send unsolicited direct marketing to Users.

Communications sent to Users through the Platform concerning the Benefits available to them are service communications necessary for the performance of the service, and are not direct marketing.

Should we wish to send electronic direct marketing in future, we will do so only in accordance with section 69 of POPIA and the amended POPIA Regulations which took effect on 17 April 2025, which require prior consent obtained in the prescribed manner, and a clear objection mechanism in every communication.

Children

The Platform is not intended for and is not made available to persons under the age of 18. We do not knowingly process the personal information of a child as contemplated in section 34 of POPIA.

Should we become aware that we hold the personal information of a child, we will delete it without undue delay.

Changes to this Policy

We may amend this Policy from time to time. The version in force is the version published on our website, and the “last updated” date reflects when it was changed.

Where an amendment materially affects the manner in which we process personal information, we will notify Users through the Platform before the amendment takes effect.

Complaints

A Data Subject who is dissatisfied with the manner in which we have processed personal information, or with our response to a request, may complain to us in the first instance at support@mondaymagic.co. We will acknowledge within one working day and respond substantively as soon as reasonably possible.

A Data Subject may also lodge a complaint directly with:

The Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 PO Box 31533, Braamfontein, Johannesburg, 2017 Complaints: complaints.IR@inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Telephone: 010 023 5200 Website: https://inforegulator.org.za

Contact

Information Officer :

Robyn Felicity Talbot

Email

Postal address

Adress

Registered office

Registered office

Monday Magic (Pty) Ltd, registration number 2018/009467/07.

Our PAIA Manual is available on request and is published on our website in accordance with section 51 of the Promotion of Access to Information Act 2 of 2000.