The intention of the Protection of Personal Information (POPI) and General Data Protection Regulation (GDPR) Policy is to clearly explain, define and guide the protection of personal information practice at RainTree Business Coaching. This policy aims to ensure consistent and appropriate protection of personal information practices are followed that guarantee the long-term sustainability of RainTree Business Coaching.
RainTree Business Coaching will:
Comply with both the laws and good practice.
Respect individuals’ rights.
Be open and honest with individuals whose data is held; and
Provide training and support for employees and contractors that handle personal data so that they can act confidently and consistently in line with this policy.
RainTree Business Coaching recognises that its priority under the POPI Act and GDPR is to avoid causing harm to individuals. In the main this means:
Keeping information securely in the right hands; and
Holding good quality information.
Secondly, both POPI and GDPR aim to ensure that the legitimate concerns of individuals about the ways in which their data may be used are considered. RainTree Business Coaching will seek to give individuals as much choice as is possible and reasonable over what data is held and how it is used aligned with all relative legislation and as required by POPI and GDPR Acts.
This policy outlines what and how RainTree Business Coaching will manage and implement these requirements. Non-compliance with the RainTree Business Coaching POPI and GDPR policy and expectations may lead to action that could lead to dismissal, penalties, or cancellation of contractor contracts.
1.2 Definitions
Back-up
Process of storing all electronic data saved on the RainTree Business Coaching computers, cloud storage, and mailboxes.
Breach
Where an individual or company has failed (intentionally or unintentionally) to comply with a law, contractual agreement, or policy.
Cloud storage
Online space that can be used to save data and documents for example Dropbox and OneDrive.
Consent
Any voluntary (not forced or pressured), specific (consent cannot be general but must be precise and detailed) and informed (the person must understand what they are agreeing to) agreement to RainTree Business Coaching that they can process personal information. The consent must be recorded and stored.
Data Subject
A data subject is the person to whom personal information relates. They can be natural (individuals) or juristic (companies/businesses) people. This relates to South Africans and non-South Africans.
De-identified Information
Information that has had all personal identifiers removed, thus removing the ability to identify the specific individual to which the information relates e.g., Michael Dlamini, Male, 27 years old, Birthdate 1 January 1989 de-identified is Male, 27 years old, 1989.
Disposal
The reselling, reassignment, recycling, donating, or discarding of IT equipment through responsible, ethical, and environmentally sound means.
Documents
For this policy, the term “documents” includes all books, registers, papers, documentary evidence, and other forms of records that are usually found at RainTree Business Coaching.
Electronic documents/records
Information that is generated electronically and stored by means of computer technology.
Hard Drive
A device used to store data or programs. In the context of this policy the hard drive refers to the storage device located in the personal computer (PC) of a user. This data is not backed-up as it is not information saved in the appointed RainTree cloud storage.
IT Service Provider (ITSP)
Technical Outsource is the IT Service Provider (ITSP) contracted to RainTree Business Coaching. Technical Outsource are committed to support RainTree to provide quality IT advice and support in the establishment of and IT operations.
Personal Information
Personal information is any information that reflects or refers to a juristic person (company) or individual or key details that relate to the juristic person or individual. Specifically, personal information includes: Name and contact details including physical address, e-mail address, telephone numbers and online identifiers (skype address).Race, gender, marital status, sexual orientation, religion, age, language, and birthplace.Education, medical, criminal or employment history.Biometrics including fingerprints, voice recognition, photographs, and blood type.Private or confidential correspondence; andOpinion or views of an individual.
Information Processing
Information processing is any operation or activity that works with and uses information. This includes but is not limited to collecting, modifying, merging, linking, altering, updating, receipting, recording, organising, collating, storing, retrieving, consulting (referring to), using, transmitting, and distributing information.
Record
A record is any recorded information that forms part of or is intended to form part of a filing system. This includes physical hard copy files and electronic files stored in cloud-based storage.
Retention period
The length of time that documents should be retained before they are either transferred into archival custody or destroyed/deleted.
Special Personal Information
Information on data subjects concerning: Information about child/ren.Religious or philosophical beliefs.Race or ethnic origin.Trade union membership.Political persuasion.Health or sex life and persuasion; andBiometric information.
Systems
Systems could be either manual or electronic. The parts/components of a system interact to achieve a specific goal. In the context of this policy the components of the system are both software and hardware combined to achieve a specific purpose.
1.3 POPI and GDPR Policy Review
This policy will be reviewed annually prior to the policy anniversary date. The Directors of the business will lead the revision process and consult with relevant stakeholders in the process.
2 POPI and GDPR Roles and Responsibilities
2.1 Directors
It is the responsibility of the Directors to manage the POPI and GDPR at RainTree Business Coaching. The Directors are ultimately responsible for the protection of personal information collected, used, and processed within RainTree Business Coaching and its Service Providers.
Every contractor, employee and Service Provider is responsible for protecting the privacy of information and for complying with the relevant Acts and RainTree Business Coaching policies.
2.2 RainTree Business Coaching Contractors, Employees and Service Providers
It is the responsibility of all RainTree Business Coaching contractors, employees, and Service Providers to protect personal information as defined in this policy. Contractors, employees, and Service Providers must ensure that documents and information are stored and protected in the appropriate manner and that documents that must be retained by the company are saved electronically according to the approved protocols.
As the primary users of personal information provided to RainTree Business Coaching, RainTree Business Coaching Employees are responsible for protecting, storing, and disposing of personal information as defined in this policy.
2.3 Information Administrator
The RainTree Administrator is the custodian of RainTree Business Coaching Information. The Information Administrator is responsible for the following where POPI and GDPR are concerned:
Manage that RainTree Business Coaching information storage complies with the POPI and GDPR requirements.
Support document development to comply with the POPI and GDPR standards.
Support systems and information process development to comply with POPI and GDPR requirements.
Identify POPI and GDPR training needs and provide or coordinate necessary training (when required).
Coordinate and supervise the destruction and de-identification of relevant data and records.
Identify and evaluate POPI and GDPR risks and make recommendations to mitigate these where possible; and
Investigate and make recommendations should there be any reported or identified POPI or GDPR transgressions or security breaches.
2.4 Technical Outsource
Technical Outsource is the IT Service Provider (ITSP) contracted to RainTree Business Coaching to enable decision making and provide support with the implementation of the operations. Technical Outsource is responsible for implementing the data storage and systems access parameters and systems that enable compliance with this policy and the POPI Act and GDPR.
3 POPI and GDPR Introduction
Records and documents created, received, or used by RainTree Business Coaching in the normal course of business are the property of the company unless otherwise agreed. This includes records and documents compiled by external consultants/SP’s commissioned by RainTree Business Coaching.
RainTree Business Coaching’s official records provide evidence of business activities and transactions. They provide support in making better decisions and improving business practice. They are an accurate record of previous actions and activities. All documents must therefore be managed consistently and in a structured manner.
Guidelines and procedures must be complied with for all records and document:
Management.
Storage; and
Disposal or permanent archiving.
3.1 Privacy of Personal Information Risks
The following potential risks have been identified. This policy aims to address these:
Breach of confidentiality (information being given out inappropriately).
Insufficient clarity about the range of data and data uses. This could lead to Data Subjects being insufficiently informed of the purposes for which their data is being used.
Failure to offer choice about data use when appropriate and/or required.
Breach of security by allowing unauthorised access.
Harm to individuals if personal data is not maintained and up to date; and
Appointed external operators processing personal information of data subjects on behalf of RainTree Business Coaching.
4 POPI Principles
4.1 Privacy and Data Retention
RainTree Business Coaching undertakes to maintain privacy of all personal information that it holds. RainTree Business Coaching undertakes to assess and identify all instances of personal information in the organisation and undertakes to gain consent, where appropriate, to access, use and store all personal information securely. Written consent will be filed as is appropriate for each data subject and the purpose for which the information is collected. RainTree Business Coaching will not be conducting audio consent at this time.
With the below categories of data, the following consent type will be collected and filed. In addition, the retention period as recommended in the Retention Period List will be applied for all data collected for each type.
Individual Role
Filing
Directors
Director’s file
Contractor/Service Providers
Supplier Database and File
Coachee/Client/Customer
Customer Files
Coach
Coach Management Files
RainTree Business Coaching will comply with the POPI Act regarding the uses for which personal information will be accessed and used. These are integrated into the various contracts signed by clients, customers, contractors, and service providers.
4.2 Openness and Transparency
RainTree Business Coaching is committed to ensuring that data subjects are aware that their data is being processed and
For what purpose the data is being used.
What types of disclosure are likely; and
How to exercise their rights in relation to their data.
Data Subjects are informed of these as shown below:
Data Subjects
Information Mechanism
Directors
POPI and GDPR Policy and Shareholder Agreement
Employee
POPI and GDPR Policy and Employment Contracts
Contractor/Service Providers
POPI and GDPR Policy and RainTree Business Coaching Service Provider Contract
Coachee/Client/Customer
RainTree Business Coaching Contract; and POPI and GDPR Policy
Whenever data is collected:
The number of mandatory fields will be kept to a minimum; and
Data Subjects will be informed which fields are mandatory and why.
4.3 Special Personal Information
Special personal information is not required by RainTree Business Coaching. If Special Personal Information is required, specific consent will be collected before gathering the information.
Should special personal information be shared during a coaching session, RainTree Business Coaching will destroy this information after the normal time limit is reached or upon request from the data subject. Confidentiality will always be maintained.
5 Key GDPR Principles
The GDPR is built on a foundation of core principles that guide how personal data should be handled to protect individual rights. These principles, outlined in Article 5 of the GDPR, shape all data protection obligations and provide a framework for responsible data management.
Those deciding how and why data is processed (Key Principle Controllers) must apply follow the below requirements:
Lawfulness, Fairness, and Transparency
Personal data must be processed legally and transparently.
Individuals should clearly understand how and why their data is being used, with information provided in simple, accessible language.
Purpose Limitation
Data must only be collected for specific, clear, and legitimate purposes.
Further processing must align with these initial purposes unless it is for public interest, research, or statistical purposes (under safeguards).
Data Minimisation
Data may only be collected that is relevant and necessary for the intended purpose.
Data must be regularly reviewed and unnecessary data deleted.
Accuracy
Personal data must be accurate and up to date.
Data must be promptly corrected and/or inaccurate information deleted.
Storage Limitation
Personal data must only be retained for as long as needed for its intended purpose.
When no longer required, data must be securely deleted or anonymized.
Integrity and Confidentiality
Personal data must be protected against unauthorized access, loss, or damage using appropriate security measures.
Protections must be updated, and the protections must be tested.
Accountability
Demonstrate compliance with all GDPR principles.
Implement policies, maintain records, and adopt measures like privacy impact assessments to ensure ongoing compliance.
These principles are not just guidelines—they are fundamental to fostering trust and ensuring fair treatment of individuals. Controllers are also encouraged to consider related rules, such as proportionality, data protection by design, and transparency obligations, to meet GDPR’s spirit and requirements.
RainTree Business Coaching adopts these principles as the cornerstone of compliance, ensuring respect for privacy while meeting legal obligations.
6 Personal Information Processing Parameters
As a rule, RainTree Business Coaching may not process personal information relating to a data subject unless:
Consent has been received and recorded.
The processing is required to conclude or perform the terms of a contract (e.g., Clients must provide certain information to enable RainTree Business Coaching to meet its contractual obligation as the coaching provider such as performance feedback or psychometric assessment feedback).
The information is to be used as instructed to comply with the right and obligation of the law.
The data is being used to protect the legitimate interests of the data subject.
The processing is for historical, statistical or research purposes and guarantees are in place that the data subject will not be negatively affected.
The information serves a public interest, or it is impossible to gain consent; and/or
The Data Subject has made their own information public.
RainTree Business Coaching may not process personal information of a child (under 18 years) without the proper consent of their parent or guardian.
6.1 Director and Employee Personal Privacy
All Directors and employees, when joining RainTree Business Coaching, give consent and understand that:
RainTree Business Coaching maintains the right to view and process all information passing through its systems.
All systems are constantly monitored for abuse and inappropriate use; and
All e-mail in and out of the RainTree Business Coaching is recorded and is available for access at any time by the RainTree IT Service Provider and RainTree Management.
Employee’s personal privacy is NOT guaranteed when accessing or utilising any RainTree Business Coaching systems as these systems are monitored by the RainTree Management and IT Service Provider .
6.1.1 Director and Employee Personal Privacy Guidelines
The following personal privacy guidelines must be complied with regarding potential and existing RainTree Business Coaching directors and employees:
All employees will be requested to give RainTree Business Coaching authorisation to utilise their personal information in line with these privacy guidelines. These are integrated into the signed Employment Contract. The Employment Contract is filed in the employee file for record keeping purposes.
Race can be confirmed with potential employees if the Employment Equity requirements make provision for this.
RainTree Business Coaching can ask and secure information relating to an individual’s criminal record if permission is given, and this is done in accordance with the relevant labour legislation. Allegations of criminal behaviour cannot be processed.
RainTree Business Coaching may not store Curriculum Vitae of unsuccessful applicants unless consent has been granted by the applicant.
RainTree Business Coaching may not keep personal information of ex-employees unless consent has been granted and there is a justifiable reason for keeping information (e.g., banking details for bonus payments). Once the reason is no longer valid, personal information must be disposed of within the specified timeline.
RainTree Business Coaching may not process personal health information unless the information informs legal or pension requirements or the information facilitates RainTree Business Coaching to provide support or reintegration benefits to an employee that is sick or found incapacitated.
RainTree Business Coaching may only use photographs of employees and/or distribute personal information if consent has been given, including celebration of special occasions and/or recognition processes. All employees will be provided with the opportunity to consent when joining RainTree Business Coaching.
RainTree Business Coaching will collect, update, and utilise the required employees and director information to process legislated and organisational reports.
6.1.2 RainTree Business Coaching Employee Clean Desk Policy
A clean desk policy is an important tool to ensure that all materials that contain sensitive/confidential information are secured when the items are not in use, or an employee leaves his/her workstation. It is one of the top strategies to utilize when trying to reduce the risk of security breaches in the workplace. Such a policy can also increase employee’s awareness about protecting sensitive information.
Desk Management
Employees are required to ensure that all sensitive/confidential information in hardcopy or electronic form is secure in their work area at the end of the day and when they are expected to be gone for an extended period.
All information and documents must be removed from the desk and locked in a drawer when the desk is unoccupied and at the end of the workday; and
Confidential documents must be shredded.
Hardware Management
Computer workstations must be locked when the workspace is unoccupied.
Computer workstations must be fully shut down at the end of the workday.
Laptops must be either locked with a locking cable or locked away in a drawer.
Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
Portable computing devices such as laptops and tablets must be secured in locked cupboards when not in use.
RainTree does not allow use of mass storage devices such as CDROM’s, DVD’s or USB drives. All data must be saved on the approved cloud storage. Should a mass storage device be used, this must be always secured when not in use. All data must be removed from the device once the reason for the saving is completed.
All printers and fax machines must be cleared of papers as soon as they are printed to ensure that confidential documents are not left in printer trays for the wrong person to pick up.
Secure File Cabinet and Area Management
File cabinets containing restricted, confidential or sensitive information must be kept closed and locked when not in use or when not attended.
Keys used for access to restricted, confidential or sensitive information must always be secured.
6.2 Client/Customer Personal Privacy
The following personal privacy guidelines must be complied with regarding RainTree Business Coaching potential and existing coachees/client/customers:
RainTree Business Coaching will only collect the information that is necessary to fulfil the intended purpose for which the information is collected.
All potential and existing coachees/client/customers will be asked to give consent to RainTree Business Coaching to use information to support any additional requirements. A record of this consent and the specifics related to it will be kept and available for the coachee/client/customer to view, should they request this.
RainTree Business Coaching may use information that has been de-identified;
Where information regarding children is concerned, consent will be secured from the legal guardian prior to utilizing information. Once children reach the age of 18, they will be classified as adults and their information will be treated with the same care as that of all other adult clients/customers. Consent will then be obtained from them and stored as per the usual process.
RainTree Business Coaching will give coachees/client/customers a reasonable opportunity to opt-out of marketing communication with each communication that is sent out. A record of the choice to unsubscribe will be maintained and will be available for the coachee/client/client/customer to view, should this be requested in writing as per the Promotion of Access to Information Act 2 of 2000.
RainTree Business Coaching will make every effort to maintain personal information to ensure completeness and accuracy and will implement steps to ensure the information is not misleading and is updated. Annual updates will be completed to ensure that the data is maintained at the required standards.
6.3 Contractor/Service Provider Personal Privacy
The following personal privacy guidelines must be complied with regarding potential and existing RainTree Business Coaching contractor/service providers:
All contractor/service provider will be requested to give RainTree Business Coaching authorisation to utilise their personal information in line with the below privacy guidelines. These will be signed and filed on the contractor/service provider file for record keeping purposes.
RainTree Business Coaching will collect, update, and utilise the contractor/service provider information to process legislated and organisational reports.
RainTree Business Coaching may not keep personal information of ex-contractor/service providers unless there is a justifiable reason for keeping information (e.g., banking details for payments). Once the reason is no longer valid, personal information must be disposed of within the specified timeline.
RainTree Business Coaching may only use photographs of contractor/service providers and/or distribute personal information if consent has been given. All contractor/service providers will be given the opportunity to consent when being appointed to work with RainTree Business Coaching.
7 Security of Personal Information
RainTree Business Coaching commits to protect personal information of its data subjects. Key security activities that are implemented to facilitate this are:
Access to information is controlled by rights to the RainTree Business Coaching cloud storage and systems. Only the functions for which the data is required are granted access to the relevant information.
Security levels required for each record have been evaluated and this has defined the level of rights that are allocated.
A register of information and people that have access to and use of information has been implemented and is updated to manage access to information. The register is reviewed for accuracy and completeness at least annually and when employees that are listed on the register change designation or leave RainTree Business Coaching:
All employees that have access to and responsibility for personal information will have their POPI and GDPR responsibilities outlined in the POPI and GDPR training.
Refresher and ongoing training will be conducted in training sessions, team meetings and management interventions. These will be initiated and supported by the Administrator, as and when necessary.
RainTree Business Coaching will only disclose personal information when required to do so:
By state bodies that maintain the law (e.g., instruction from the police or related legal entities).
By South African Revenue Services.
For legal court proceedings; and
In the case of National Security.
Personal information storage and removal as is defined in this policy; and
All hard copy documents containing personal information must be shredded prior to disposal.
8 Private Information Quality
RainTree Business Coaching commits to collect, capture, and maintain accurate data. The following steps will be followed to maintain this:
ICT systems will be utilised that enable and facilitate accurate data entry and capture.
Data on any individual will be held in as few places as necessary. All employees will be advised of this requirement and any additional data sets that need to be developed will be evaluated for necessity prior to developing.
Procedures are in place to support updating of all data sets should an individual’s data change.
Employees that are responsible for accessing, maintaining, and amending detailed individual data are trained on the importance of accuracy and RainTree Business Coaching record keeping. Compliance with these standards is checked regularly.
RainTree Business Coaching will review all personal information on an annual basis as outlined below:
Data Subject
Review period
Director/Shareholders
June
Employee
July
Individual Coaching Clients
July – August
Business Customers
September
Contractors /Service Providers
October
9 RainTree Business Coaching Records and Document Management
This policy covers:
The creation and naming of RainTree Business Coaching records.
The storage of RainTree Business Coaching records to:
Enable that official records are easily located, accessed, maintained, and retained/stored whilst ensuring appropriate security and confidentiality of information.
Enable that official records are disposed of in a manner that is appropriate to their content and function; and
Enable appropriate use and maintenance of communication methods offered by RainTree Business Coaching.
These guidelines apply to all records and documents and supporting systems, regardless of format, that have been created and used during RainTree Business Coaching business.
9.1 Document Creation and Naming
All documents must be stored in the RainTree Business Coaching One Drive Cloud Storage. Documents must be filed in the appropriate folder with a date and name of the document.
All documents must be named according to the naming conventions as defined below.
9.2 Document Storage
9.2.1 Electronic Document (Record) Storage
Documents and records must be scanned and filed securely on the system, linked to the appropriate records.
All documents and records must be saved in the approved cloud storage in the relevant folders. Confidential documents and records must be password protected.
Access to POPI/GDPR relevant electronic documents/records will be access restricted and only those that have been trained on how to apply the POPI/GDPR principles will be given access.
Main folders and various levels of subfolders are utilized to store documents for easy retrieval.
The principle of general to specific is applied when folders are created.
The naming conventions must be as follows: yyyymmdd document description (20241210 POPI and GDPR policy and procedure)
RainTree Business Coaching Directors, employees, contractors, and service providers must not save any documents on their personal computers or hard drives. These drives are not backed up.
Personal documents may be saved on the cloud storage in a private folder if the size of the folder does not impede RainTree Business Coaching storage requirements.
RainTree Business Coaching documents or information may only be stored using cloud storage services approved by RainTree Business Coaching and that comply with the defined RainTree Business Coaching document security requirements.
Prior to proceeding with tasks that will lead to RainTree Business Coaching documents being saved on the cloud, the Service Provider is required to agree in writing that they will comply with the RainTree Business Coaching Cloud Storage and Security requirements as well as the POPI and GDPR compliance requirements as defined in this policy.
The RainTree Business Coaching Cloud Storage and Security Requirements include:
OneDrive is the selected cloud storage site for RainTree Business Coaching.
Access rights to Cloud Storage must be carefully managed and audited and updated for accuracy at least annually.
Document security must be always maintained through passwords and access rights.
Sharing documents that are saved on the cloud must be authorized by the relevant manager and must only be done when access to the documents is required to support delivery of specific outputs.
9.2.2 Data Back-Up Storage
As all documents are stored on the approved cloud storage platform, the POPI and GDPR requirement that data is stored securely have been met.
10 Disposal
Documents must be disposed of in a manner that is appropriate to the type of document. If a document is confidential, it must be shredded. All disposal methods must make sure that the data is de-identified and that the data subject cannot be re-identified in any way.
11 RainTree Business Coaching System Security Breach
In the case of suspicion or identification of a systems or data breach, contact one of the RainTree Business Coaching Directors immediately via telephone.
An investigation will be conducted, and a written report drafted and presented to implement actions to prevent future risks. The Raintree Business Coaching Directors will report any breaches to the relevant authorities and to the data subjects involved immediately after the investigation is concluded and a definite breach has been identified.
12 Amendments and Updates
Amendment
Authorised
Date
Version 1
Full Draft
Section 1-10
Directors
28 June 2021
Version 2
Full Draft
Section 1-10
Directors
25 July 2022
Version 3
Full Draft
Section 1-11
Directors
13 RainTree Contacts Accessing RainTree Data
13.1 Directors and Employees
Name
Data Access Levels
Cloud Storage
Angela Heeley
Full
One Drive/Dropbox
Leoni Coetzee
Full
One Drive/Dropbox
Faranah Dildar-Mia
Administrator
One Drive/Dropbox
13.2 Contractors and Service Providers
Name
Data Access Levels
Contracts in Place
Cloud Storage
Eccountant
Financial Information
Yes
Dropbox
Technical Outsource
Website & Technical support through Teams Viewer (Permission based)
Yes
N/A
We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.