Privacy Policy for Imbabali Retreat & Venue, Magaliesburg
Learn how we safeguard your information for a secure stay at Imbabali Retreat & Venue.
Last updated: December 2025
- INTRODUCTION
1.1 Imbabali Retreat & Venue (“Imbabali”, “we”, “us”, “our”) is committed to protecting the privacy and security of personal information and to processing personal information in a lawful, reasonable, transparent, and secure manner.
1.2 This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal information in the course of providing our services and operating our website and related systems.
1.3 This Privacy Policy is drafted with reference to the Protection of Personal Information Act 4 of 2013 (“POPIA”) and applies to processing activities where POPIA is applicable. Where you are located outside South Africa, additional local data protection laws may apply.
- INFORMATION OFFICER AND CONTACT DETAILS
2.1 We have appointed an Information Officer responsible for compliance and privacy-related enquiries.
2.2 You may contact our Information Officer at: accounts@imbabali.co.za
2.3 Further contact details, forms, and procedures are contained in our PAIA Manual (available on request or where published on our channels).
- OUR SERVICES
3.1 We provide travel, tourism, leisure, accommodation, venue, and related products and services (“Services”).
3.2 We may collect personal information when you:
- contract with us for Services;
- book, enquire, request quotations, or otherwise engage with us;
- access or use our website, applications, Wi-Fi, or related systems;
- communicate or interact with us (including by email, telephone, messaging platforms, or in person); and/or
- apply for work, become an employee, agent, broker, sales associate, or service provider.
- SCOPE OF THIS POLICY
4.1 This Privacy Policy applies to external parties with whom we interact, including (without limitation):
- applicants, customers, prospective customers, guests, and recipients of Services;
- representatives of corporate or organisational customers;
- individuals whose information is received from other entities (where lawful and/or consented);
- suppliers, operators, contractors, and service providers;
- visitors to our premises; and
- users of our website and digital platforms.
4.2 This Privacy Policy must be read together with our website terms and conditions and any specific privacy notices, booking terms, contracts, or disclosures provided to you in particular circumstances.
4.3 This Privacy Policy supplements those documents and does not replace them. If there is a conflict, the relevant agreement or specific notice will prevail to the extent of the conflict.
- CONSENT AND AUTHORISATION
5.1 By providing personal information to us, you:
- confirm that you have read and understood this Privacy Policy; and
- consent to the processing of your personal information as described herein, where consent is required by law.
5.2 Where you provide information relating to another person (e.g., a guest, family member, employee, or travel companion), you warrant that you are authorised to provide that information and to consent to its processing on that person’s behalf where required.
5.3 Where POPIA or other law permits processing on grounds other than consent (such as performance of a contract or compliance with legal obligations), we will process on those grounds without requiring consent.
- PERSONAL INFORMATION WE COLLECT
6.1 “Personal information” means information relating to an identifiable living natural person and, where applicable, an identifiable existing juristic person, as defined in POPIA.
6.2 We may process personal information including (without limitation):
- Identity information: name, title, date of birth, gender, nationality, language, ID/passport/registration numbers, legal status, and address;
- Contact information: email address, telephone number, physical and postal address, billing and service address;
- Booking and enquiry information: enquiries, preferences, quotations, accommodation/activity details, special requirements, guest lists, and correspondence;
- Transaction and payment-related information: payment records, invoices, proof of payment, and limited payment card details as required for processing (handled via compliant payment channels);
- Technical and usage information: IP address, browser type, device identifiers, location-related settings, operating system, logs, and website interaction data;
- Marketing and communications preferences: opt-in/opt-out status and channel preferences;
- Employment and recruitment information (where applicable): application details, references, employment records, and vetting information to the extent permitted by law;
- Compliance-related information: information needed for tax, regulatory, auditing, fraud prevention, or legal obligations.
6.3 We may also process aggregated or anonymised data for analytics and operational improvement. Where such data can be linked back to you, it will be treated as personal information.
- SPECIAL PERSONAL INFORMATION
7.1 We may process special personal information (as defined in POPIA) only where lawful and necessary, including where required to provide Services (e.g., dietary, mobility, disability, medical or religious requirements) or where permitted in recruitment processes.
7.2 Where required by law, we will obtain consent or apply lawful safeguards before processing special personal information.
- HOW WE COLLECT PERSONAL INFORMATION
8.1 We collect personal information through:
- direct interactions (forms, bookings, enquiries, email, telephone, in-person engagement);
- automated technologies (cookies, logs, analytics tools, and similar technology);
- third parties (operators and service providers, credit bureaus where lawful, and other sources where you have consented or where permitted by law).
8.2 If you contact us, we may keep records of communications, including call notes, emails, and messages, where lawful and reasonably necessary.
- PURPOSES FOR PROCESSING PERSONAL INFORMATION
9.1 We process personal information for legitimate business purposes, including:
- providing and administering Services, bookings, and enquiries;
- processing payments and maintaining accounts and records;
- customer support and communications;
- sharing necessary information with service providers involved in delivery (e.g., booking-related vendors);
- improving our website, operations, service offerings, and customer experience;
- direct marketing (subject to your rights and applicable law);
- detecting and preventing fraud, security breaches, misuse, and unlawful activity;
- compliance with legal, regulatory, tax, auditing, reporting, and recordkeeping obligations;
- establishing, exercising, or defending legal rights;
- recruitment, onboarding, and employment administration (where applicable); and
- any other lawful purpose disclosed when the information is collected.
9.2 We will not use personal information for materially different or incompatible purposes without providing notice or obtaining consent where required.
- DIRECT MARKETING (ELECTRONIC)
10.1 We may send you marketing communications about our services where permitted by POPIA, including where:
- we obtained your contact details in the context of a sale, enquiry, request, or booking; and
- the marketing relates to similar services.
10.2 If you are not an existing customer, we will only send direct marketing where you have provided express opt-in consent, and we will keep a record of that consent.
10.3 You may opt out at any time, free of charge:
- using the opt-out option in a message; or
- by emailing marketing@imbabali.co.za.
10.4 Opting out does not prevent us from sending non-marketing communications required for booking administration, contractual performance, or legal/regulatory reasons.
- LEGAL BASIS FOR PROCESSING
11.1 We process personal information where it is lawful to do so, including where processing is necessary:
- to perform a contract with you or take steps at your request before entering a contract;
- to comply with legal obligations;
- to protect your legitimate interests or those of another person;
- for our legitimate interests (including operations, fraud prevention, cybersecurity, and relationship management), provided your rights do not override those interests; and/or
- where you have provided consent, where consent is required.
- COMPULSORY INFORMATION AND CONSEQUENCES
12.1 Where personal information is required by law or contract and you do not provide it, we may be unable to provide Services, process a booking, or maintain the relationship.
12.2 Where applicable, this may result in cancellation or termination of the relevant contract or process, subject to the terms of that contract and applicable law.
- DISCLOSURE OF PERSONAL INFORMATION
13.1 We do not sell personal information. We will not intentionally disclose personal information for commercial gain.
13.2 We may disclose personal information to:
- our employees and authorised personnel on a need-to-know basis;
- our contracted operators, service providers, suppliers, advisors, and professional consultants who assist our operations;
- regulators, law enforcement, or governmental bodies where required by law or reasonably necessary; and/or
- third parties involved in booking fulfilment where disclosure is necessary to provide Services.
13.3 Where operators process information on our behalf, we take reasonably practicable steps to ensure they are bound by confidentiality and security obligations and may only process information under our instructions.
13.4 Cross-border disclosure (where applicable)
Where bookings or service fulfilment involves foreign entities (e.g., airlines or travel partners), personal information may be transferred outside South Africa. You acknowledge that foreign jurisdictions may not provide equivalent protection. We will take reasonably practicable steps to ensure appropriate safeguards consistent with POPIA, where required.
13.5 Insurance
If you apply for travel or related insurance through us, we may share necessary personal information with insurers. Insurers may record claims information to prevent fraud, subject to their own policies and legal obligations.
- STORAGE AND INTERNATIONAL TRANSFERS
14.1 We use reputable operators and hosting/cloud providers to store and process information securely.
14.2 Our primary systems are operated from secure environments, and where data is hosted or processed outside South Africa, we will implement reasonable safeguards, including contractual protections, to ensure an adequate level of protection.
- SECURITY MEASURES AND BREACH RESPONSE
15.1 We implement reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures may include access controls, encryption where appropriate, secure hosting, monitoring, staff training, and periodic testing.
15.2 Payment card information is handled using processes aligned to applicable PCI-DSS requirements.
15.3 No method of transmission or storage is completely secure. Accordingly, we do not guarantee absolute security. However, we remain responsible for taking reasonable safeguards and will be liable where required by law, including in cases of gross negligence where applicable.
15.4 We maintain data breach response procedures and will notify affected persons and the Information Regulator where required by law and within required time periods.
- RETENTION AND DELETION
16.1 We retain personal information only for as long as necessary for lawful purposes, including contractual performance, legal obligations, dispute resolution, and legitimate business needs.
16.2 We will delete or destroy personal information when it is no longer required, unless we are required or permitted by law to retain it.
16.3 Destruction is done using reasonable methods appropriate to the format of the information (including shredding and secure deletion).
- ACCURACY, ACCESS, CORRECTION, AND DELETION
17.1 We take reasonable steps to ensure personal information is accurate, complete, not misleading, and up to date.
17.2 You may request access to, correction of, or deletion of your personal information, subject to legal limitations and verification of identity and authority.
17.3 Requests may require completion of the relevant prescribed forms (including those referenced in our PAIA Manual and/or the Information Regulator’s processes).
- DATA MINIMISATION
18.1 We endeavour to collect and process only the personal information that is relevant and necessary for the stated purposes.
18.2 Where excess information is received, we may securely delete or anonymise it, unless retention is required by law.
- YOUR RIGHTS
19.1 Subject to applicable law, you may have the right to:
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion/erasure where there is no lawful basis to retain it;
- object to processing in certain circumstances;
- request restriction of processing in certain circumstances; and
- withdraw consent where consent was the lawful basis for processing (withdrawal does not affect processing already performed lawfully before withdrawal).
19.2 We will respond to requests within a reasonable period and, where applicable, within 30 calendar days, subject to verification and lawful exceptions.
- CHILDREN
20.1 Our website and Services are not intended for persons under 18.
20.2 We do not knowingly collect personal information from persons under 18 without appropriate consent, unless permitted by law.
- OPERATORS AND SUB-PROCESSORS
21.1 We may appoint third-party operators to process personal information on our behalf (including IT, hosting, HR, payroll, marketing distribution, and related services).
21.2 We may change operators from time to time. Where required, we will ensure operators are contractually bound to appropriate confidentiality and security obligations.
21.3 We conduct reasonable due diligence on operators before engagement.
- ARTIFICIAL INTELLIGENCE FEATURES
22.1 We may deploy AI-powered tools (“AI Features”) to assist with customer support, recommendations, summarisation, or other operational functions.
22.2 AI outputs are provided for convenience and may be inaccurate. AI outputs do not constitute professional advice.
22.3 You use AI Features at your own risk, and Imbabali is not liable for losses caused by reliance on AI outputs, except to the extent liability cannot lawfully be excluded.
- COOKIES
23.1 We may use cookies and similar technologies to:
- enable essential website functions;
- remember preferences (functional cookies);
- analyse website performance and improve user experience (analytics cookies).
23.2 You may disable cookies through your browser settings; however, doing so may limit functionality of the Website.
23.3 Where required by law, we will request consent for non-essential cookies.
- THIRD-PARTY WEBSITES
24.1 The Website may contain links to third-party websites, widgets, plug-ins, or tools.
24.2 We are not responsible for third-party privacy practices. You should review the privacy notices of those third parties before sharing information with them.
- GOVERNING LAW
25.1 This Privacy Policy is governed by the laws of the Republic of South Africa.
25.2 If any provision is found unlawful or unenforceable, it will be severed and the remainder will remain in force.
- CHANGES TO THIS POLICY
26.1 We may amend this Privacy Policy from time to time.
26.2 We may notify you of changes by reasonable means including email, website notice, pop-up notification, or notice when you access the Website.
- QUERIES, COMPLAINTS, AND INFORMATION REGULATOR
27.1 If you have queries or complaints, contact our Information Officer at info@imbabali.co.za.
27.2 If you are not satisfied with our response, you may lodge a complaint with the South African Information Regulator via its official channels.
27.3 If you are outside South Africa, you may also contact the relevant data protection authority in your country.
ANNEXURE: DEFINITIONS
“Associates” means our group entities (if applicable) and their directors, employees, and consultants.
“Operator” means a person/entity that processes personal information for a responsible party.
“Responsible Party” means the entity that determines the purpose and means of processing personal information.
“Service Provider” means third parties providing services to us (including hosting, IT, auditors, advisors, legal counsel, insurers, and payroll administrators).
“Special Personal Information” has the meaning assigned in POPIA and includes sensitive categories such as health information, religion, criminal history, biometrics, and similar protected categories.
