Privacy Policy
Monday Magic (Pty) Ltd ·
Registration number 2018/009467/07
Last updated: 23 July 2026
Effective from: 1 August 2026
About this Policy :
Monday Magic (Pty) Ltd (“Monday Magic”, “we”, “us”, “our”) is committed to protecting the personal information entrusted to us. This Privacy Policy explains how we collect, use, share, store and protect personal information, and sets out the rights available to data subjects.
This Policy is issued in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), and should be read together with our Terms of Use, our Cookie Policy, and our PAIA Manual.
Capitalised terms used in this Policy carry the meanings given to them in our Terms of Use, save where defined differently below.
Our role. In relation to personal information processed through the Platform, Monday Magic acts as the Responsible Party as contemplated in section 1 of POPIA. Our Partners act as Operators processing personal information on our instruction and on our behalf.
Where the Sponsor determines the purpose of processing in respect of its own employment or engagement records, the Sponsor acts as an independent Responsible Party in respect of that processing, and its own privacy notice applies.
Definitions :
In these terms:
“Data Subject”, means the person to whom personal information relates.
“Operator” means a person who processes personal information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party.
“Personal Information”bears the meaning given in section 1 of POPIA.
“Processing” bears the meaning given in section 1 of POPIA, and includes collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, erasure and destruction.
“Responsible Party” means the party that determines the purpose of and means for processing personal information.
“Special Personal Information” bears the meaning given in section 26 of POPIA, and includes information concerning a Data Subject’s health, biometrics, religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, sex life, or criminal behaviour.
“the Platform”, “the Sponsor”, “the User”, “a Benefit”, “a Partner” and “the Emergency Line” bear the meanings given in our Terms of Use.
Information Officer :
In accordance with sections 55 and 56 of POPIA, Monday Magic has designated an Information Officer who is registered with the Information Regulator.
Information Officer:
Robyn Felicity Talbot
Director
Designation:
Email :
Postal address:
[ADDRESS]
The Information Officer is responsible for encouraging compliance with the conditions for lawful processing, dealing with requests made to Monday Magic under POPIA and the Promotion of Access to Information Act 2 of 2000 (“PAIA”), working with the Information Regulator in relation to investigations, and otherwise ensuring compliance with POPIA.
The personal information we process :
Information received from the Sponsor :
We receive the following categories of personal information from the Sponsor in order to establish and maintain a User’s access to the Platform:
Examples
Service
Why we need it
Mobile telephone number, and where provided, email address
Contact data
To deliver Benefits, one-time PINs and service messages
Sponsor name, employee or reference number, date of commencement, date of birth, work anniversary date
Engagement data
To confirm eligibility and to determine when birthday and anniversary Benefits fall due
Active or inactive status on the Sponsor’s eligibility file
Status data
To determine whether access should continue
To verify eligibility and authenticate the User at login
Identity data
Full name, surname, identity number or passport number
The Sponsor warrants to us that it has a lawful basis for providing this information and that the information is accurate, complete and current.
Information generated through use of the Platform :
Examples
Service
Why we need it
Benefits issued, voucher and coupon codes issued, redemption records, dates and values
Transaction data
To administer Benefits, reconcile with Partners, and detect misuse
Messages sent to the User and delivery status
Communication data
To confirm delivery and resolve queries
Device type, browser type, operating system, IP address, and session information
Technical data
To operate and secure the Platform. See our Cookie Policy
To secure the Platform and prevent unauthorised access
Authentication data
Login records, one-time PIN issuance and verification records
To understand how the service is used and improve its performance. Configured not to receive names, identity or passport numbers or contact details
Analytics data
Support data
Pages viewed, referring source, approximate location and device information, collected across our website and the Platform
Records of queries, complaints and their resolution
To assist the User and improve the service
Information processed in connection with emergency assistance :
When a User contacts the Emergency Line, additional personal information is processed. Some of this constitutes Special Personal Information concerning the User’s health.
Service
Examples
Call recordingsDate, time, nature of the incident, and the location of the User
Incident data
Information disclosed during clinical triage, the nature of the medical condition or injury, the level of care determined to be appropriate, and the receiving medical facility
Clinical data
Vehicle description, registration number, and proof of ownership or lease, in the case of roadside assistance
Vehicle data
Vehicle description, registration number, and proof of ownership or lease, in the case of roadside assistance
Claim data
Telephone calls to the Emergency Line are recorded for quality assurance, case management and audit purposes
Call recordings
Lawful basis for processing health information. In terms of section 27(1)(d) of POPIA, the prohibition on processing Special Personal Information does not apply where processing is necessary for the establishment, exercise or defence of a right or obligation in law, and in terms of section 27(1)(b), where processing is necessary to protect a legitimate interest of the Data Subject and consent cannot be obtained. Processing of health information in an emergency is further justified under section 32(1) of POPIA, which permits processing of health information by medical professionals and healthcare institutions where such processing is necessary for the proper treatment and care of the Data Subject.
In addition, by accepting our Terms of Use the User consents in terms of section 27(1)(a) of POPIA to the processing of health information for the sole purpose of arranging and coordinating emergency assistance.
We do not use health information for any purpose other than arranging, coordinating, managing and reconciling the emergency assistance requested. It is never used for marketing, never shared with the Sponsor in identifiable form, and never used to make any decision about a User’s eligibility for any Benefit.
Information we do not process
We do not collect or process :
Financial account details, card numbers or banking information of Users
Biometric information
Information concerning race, ethnic origin, religious or philosophical beliefs, political persuasion, trade union membership, or sex life
Criminal behaviour information
Personal information of children under the age of 18
We do not operate advertising or marketing tracking technology, including Meta Pixel or any other social media tracking pixel, on our website or on the Platform. We do not provide a User’s name, identity number, passport number or contact details to any analytics provider
Purposes of processing
We process personal information only for the following purposes:
Service delivery. To establish and maintain User access, verify eligibility, authenticate Users, issue and deliver Benefits, coordinate emergency assistance, and administer the Platform.
Communication. To send one-time PINs, Benefit notifications, service messages, and responses to queries.
Reconciliation and administration. To reconcile Benefit issuance and redemption with Partners, verify invoices, and maintain accurate financial records.
Fraud prevention and misuse detection. To monitor for irregular patterns of Benefit usage, prevent unauthorised access, and investigate suspected misuse in accordance with our Terms of Use.
Reporting to the Sponsor. To provide the Sponsor with aggregated and de-identified reporting on Benefit uptake and engagement. We do not report individual Benefit usage to the Sponsor, save where required in terms of clause 6 of our Terms of Use in cases of suspected fraud, or where required by law.
Legal and regulatory compliance. To comply with our obligations under POPIA, PAIA, the Consumer Protection Act 68 of 2008, the Companies Act 71 of 2008, tax legislation, and any lawful request from a competent authority.
Service improvement. To analyse aggregated and de-identified usage patterns in order to improve the Platform and the Benefit mix.
Analytics and performance. To measure and analyse how our website and the Platform are used, in order to improve performance, fix problems and understand which Benefits are valued. Analytics information is used in aggregate and is not used to build a profile of, or make decisions about, any individual User.
We do not process personal information for any purpose incompatible with those listed above, and we do not sell personal information.
Lawful basis for processing
We rely on the following justifications under section 11 of POPIA:
Service
Where it applies
Section 11(1)(b) — necessary to conclude or perform a contract
Delivery of the Benefits the User has been given access to
Section 11(1)(c) — compliance with a legal obligation
Retention of records for tax, company law and regulatory purposes
Acceptance of our Terms of Use on first login; consent to processing of health information for emergency assistance
Section 11(1)(a) — consent of the Data Subject
Coordination of emergency assistance where the User may be unable to consent
Section 11(1)(d) — protection of a legitimate interest of the Data Subject
Fraud prevention, security of the Platform, aggregated reporting to the Sponsor
Section 11(1)(f) — legitimate interests of the Responsible Party or a third party
Where we rely on consent, the User may withdraw that consent at any time by contacting the Information Officer. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and may mean that we can no longer provide some or all of the Benefits.
Sharing personal information
Our Partners
Information shared
Partner category
Purpose
Name, identity number or passport number, mobile number, active status, and incident information disclosed during the call
Emergency assistance Partner
Name, identity number or passport number, mobile number, active status, and incident information disclosed during the call
Mobile number and a Benefit reference
Gifting and voucher Partner
To issue and deliver voucher codes
All Platform data, in encrypted form
Hosting and technology Partner
To host and operate the Platform
Pages viewed, device and approximate location information. No name, identity number, passport number or contact details
Analytics provider
To provide aggregated analytics on website and Platform performance
To verify that the User qualifies to receive coupons
Lifestyle savings Partner
Identity number or passport number, and active status
To deliver messages and one-time PINs
Communications Partner
Communications Partner
Each Partner is contractually bound as an Operator in terms of section 20 and section 21 of POPIA to process personal information only on our documented instruction, to establish and maintain appropriate security safeguards, to treat the information as confidential, and to notify us immediately where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.
No Partner is permitted to use personal information for its own purposes, for marketing, or for onward disclosure, without our prior written authorisation.
The Sponsor
We provide the Sponsor with aggregated and de-identified reporting only.
We will disclose individual information to the Sponsor only where:
the User has consented to that disclosure;
disclosure is necessary to investigate suspected fraud or misuse in accordance with clause 6 of our Terms of Use; or
disclosure is required by law.
Other disclosures
We may disclose personal information where:
required by law, court order, or a lawful request from a competent regulatory or law enforcement authority;
necessary to establish, exercise or defend a legal right;
necessary to protect the life or health of the User or another person; or
in connection with a corporate transaction, provided that the recipient is bound to protect the information on terms no less protective than this Policy.
Cross-border transfers
Personal information relating to a User’s Benefits, account and use of emergency assistance is stored and processed within the Republic of South Africa. Our Partners are contractually prohibited from transferring that information outside South Africa without our prior written authorisation.
Website and Platform analytics are the exception. We use Google Analytics across both our website and the Platform to understand how the service is used and to improve its performance over time. Google Analytics is operated by Google LLC, and the information it collects, including IP address, device information and pages viewed, may be processed on servers located outside South Africa.
This transfer is permitted in terms of section 72(1)(a) of POPIA, on the basis that the recipient is subject to binding corporate rules and contractual terms which uphold principles for the reasonable processing of information substantially similar to the conditions for lawful processing under POPIA. We have concluded Google’s data processing terms, which incorporate the European Commission’s Standard Contractual Clauses. Where consent is required, the transfer is further justified in terms of section 72(1)(b) of POPIA, on the basis of consent obtained through our cookie banner.
We have configured our analytics so that it does not receive a User’s name, identity number, passport number or contact details. We do not use analytics to build a profile of any individual User, and we do not use it to make any decision about a User or their access to Benefits. Analytics information is used in aggregate.
We have enabled IP anonymisation and disabled Google Signals, advertising features, remarketing and data sharing with Google for its own purposes.
We do not use Meta Pixel or any other social media tracking technology, on our website or on the Platform.
Should our position change, we will amend this Policy, obtain any consent required, and ensure that any transfer complies with section 72 of POPIA.
Security safeguards :
In accordance with sections 19 to 21 of POPIA, we secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information, and unlawful access to or processing of personal information.
Our measures include:
Encryption of personal information in transit and at rest
Access control on a least-privilege, need-to-know basis, with unique user identifiers and no shared credentials
Authentication of Users by identity number or passport number together with a one-time PIN
Logging and monitoring of access to systems containing personal information
Vulnerability management, including regular internal and external scanning and timely patching
Contractual safeguards imposed on every Operator, including the right to audit
Confidentiality undertakings binding on all personnel with access to personal information
Backup and recovery procedures, with backups subject to the same controls as primary systems
Secure destruction of personal information when the retention period ends
We identify reasonably foreseeable internal and external risks, establish and maintain safeguards against those risks, regularly verify that the safeguards are effectively implemented, and update them in response to new risks.
Security compromises :
Should a security compromise occur in which there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will, in accordance with section 22 of POPIA:
Notify the Information Regulator as soon as reasonably possible after discovery, via the Regulator’s eServices Portal, as required since 1 April 2025;
Notify affected Data Subjects as soon as reasonably possible, unless the identity of affected Data Subjects cannot be established, or a public body responsible for detection or investigation of offences, or the Regulator, directs otherwise;
Provide sufficient information to allow affected Data Subjects to take protective measures, including a description of the possible consequences, the measures we intend to take or have taken, and our recommendation on steps the Data Subject should take; and
Where the identity of the unauthorised person is known, disclose that identity to the Data Subject if the Regulator so directs.
Notification will be delivered in writing by email or SMS to the contact details we hold, and where appropriate by prominent notice on the Platform.
Retention and destruction
In accordance with section 14 of POPIA, we retain personal information only for as long as necessary to achieve the purpose for which it was collected, unless a longer retention period is required or authorised by law.
Category
Retention period
Support and complaint records
3 years from resolution
Technical and security logs
12 months
For the duration of access, plus 12 months
Identity, contact and engagement data
5 years from the end of the financial year in which the transaction occurred, in accordance with the Companies Act and tax legislation
Transaction and Benefit records
5 years from the date of the incident, or such longer period as may be required in respect of a Road Accident Fund claim or potential legal proceedings
Emergency incident and clinical records
12 months, unless required for a specific case, claim or dispute
Emergency Line call recordings
Indefinitely, as it no longer constitutes personal information
De-identified and aggregated data
At the end of the applicable period, personal information is destroyed or de-identified in a manner that prevents its reconstruction in an intelligible form.
Data subject rights
Data Subjects have the following rights under POPIA:
12.1 The right to be notified that personal information is being collected, and where it has been accessed by an unauthorised person (sections 18 and 22).
12.2 The right of access — to request confirmation, free of charge, of whether we hold personal information about the Data Subject, and to request a record or description of that information, including the identity of third parties who have had access to it (section 23). A prescribed fee may apply to the provision of the record itself.
12.3 The right to correction or deletion — to request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully (section 24).
12.4 The right to object — to object, on reasonable grounds, to the processing of personal information where processing is based on section 11(1)(d), (e) or (f) (section 11(3)).
12.5 The right to withdraw consent where processing is based on consent (section 11(2)).
12.6 The right not to be subject to automated decision-making that results in legal consequences or substantially affects the Data Subject (section 71).
12.7 The right to complain to the Information Regulator (section 74).
12.8 The right to institute civil proceedings in respect of an alleged interference with the protection of personal information (section 99).
How to exercise these rights
Requests should be directed to the Information Officer at support@mondaymagic.co, using Form 2 prescribed under the POPIA Regulations for access requests, and Form 1 for objections to processing.
We will respond within 30 days of receipt. Where a request is complex or we require additional time, we will inform the requester of the extension and the reasons for it.
Where the personal information originated from the Sponsor, and the request concerns the accuracy of that information, we may direct the Data Subject to the Sponsor, as the Sponsor is the source and remains responsible for its accuracy.
Direct marketing
We do not send unsolicited direct marketing to Users.
Communications sent to Users through the Platform concerning the Benefits available to them are service communications necessary for the performance of the service, and are not direct marketing.
Should we wish to send electronic direct marketing in future, we will do so only in accordance with section 69 of POPIA and the amended POPIA Regulations which took effect on 17 April 2025, which require prior consent obtained in the prescribed manner, and a clear objection mechanism in every communication.
Children
The Platform is not intended for and is not made available to persons under the age of 18. We do not knowingly process the personal information of a child as contemplated in section 34 of POPIA.
Should we become aware that we hold the personal information of a child, we will delete it without undue delay.
Changes to this Policy
We may amend this Policy from time to time. The version in force is the version published on our website, and the “last updated” date reflects when it was changed.
Where an amendment materially affects the manner in which we process personal information, we will notify Users through the Platform before the amendment takes effect.
Complaints
A Data Subject who is dissatisfied with the manner in which we have processed personal information, or with our response to a request, may complain to us in the first instance at support@mondaymagic.co. We will acknowledge within one working day and respond substantively as soon as reasonably possible.
A Data Subject may also lodge a complaint directly with:
The Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 PO Box 31533, Braamfontein, Johannesburg, 2017 Complaints: complaints.IR@inforegulator.org.za General enquiries: enquiries@inforegulator.org.za Telephone: 010 023 5200 Website: https://inforegulator.org.za
Contact
Information Officer :
Robyn Felicity Talbot
Postal address
Adress
Registered office
Registered office
Monday Magic (Pty) Ltd, registration number 2018/009467/07.
Our PAIA Manual is available on request and is published on our website in accordance with section 51 of the Promotion of Access to Information Act 2 of 2000.