PRIVACY NOTICE
How we handle personal information.
This notice explains what personal information MUFK Integrated may collect, why we use it, when it may be shared, how it is protected, and the choices and rights available to you.
1. Who we are and the scope of this notice
“MUFK Integrated”, “we”, “us” and “our” refer to Mupo Projex (Pty) Ltd, registration number 2019/545521/07, trading as MUFK Integrated, with its principal office at Office 0005, Jardown 1, 377 Johannes Ramokhoase Street, Pretoria, 0002, South Africa.
This notice applies when we act as the responsible party for personal information processed through our public website, enquiry and demonstration forms, support channels, business communications, supplier and partner interactions, recruitment activities, and our own administration.
Where we process information for a client through a configured MUFK Integrated workspace, we may act as an operator on that client’s instructions. The client’s privacy notice and the applicable agreement may then provide additional information and should be read with this notice.
2. Personal information we may collect
The information we collect depends on how you interact with us and which services are configured. It may include:
- Identity and contact information: name, work email address, telephone number, organisation and job-related details.
- Enquiry information: enquiry type, message content, correspondence and follow-up records.
- Demonstration information: organisation type, estimated user numbers, preferred date, time and meeting format, evaluation stage, selected solutions and areas of interest.
- Support information: support category, priority, affected module and environment, reference number, issue description, authorised attachments and communications about the request.
- Website and technical information: IP address, browser and device details, timestamps, referring pages, diagnostic events and security or access logs where generated by our hosting or security services.
- Business relationship information: proposals, contracts, invoices, supplier or partner contacts, service records and professional correspondence.
- Marketing preferences: consent, objections, opt-outs and records needed to respect your communication choices.
- Platform information: where applicable, authorised-user account data and operational records relating to claims, incidents, assessments, suppliers, services or assets, as determined by the relevant client and implementation.
Please do not submit passwords, one-time codes, payment-card information, identity-document numbers, health information or other unnecessary sensitive information through a general website form.
3. Where we obtain personal information
We generally collect personal information directly from you. We may also obtain it from your employer or organisation, an authorised client user or administrator, a service provider acting for you or a client, configured integrations, public records or information you have deliberately made public, where collection from another source is lawful and appropriate.
If you provide another person’s information, you must be authorised to do so and should ensure that the person is appropriately informed about the processing.
4. Why and on what basis we process personal information
| Purpose | Typical information | Justification under POPIA |
|---|---|---|
| Respond to enquiries | Contact, organisation and message details | Your consent or request; steps connected with a potential agreement; our legitimate business interests |
| Prepare and arrange demonstrations | Contact details, organisation context, preferences and selected solutions | Your request; steps connected with a potential agreement; our legitimate business interests |
| Investigate and manage support requests | Contact, account, technical, operational and authorised attachment data | Performance of an agreement; client instructions; legal obligations; legitimate interests in providing and securing support |
| Provide and administer services | Authorised-user, client, supplier and operational records | Performance of agreements; client instructions; legal obligations; legitimate operational interests |
| Protect systems and prevent misuse | Access, device, network, audit and security-event information | Legal obligations and legitimate interests in security, fraud prevention, accountability and service integrity |
| Maintain business and legal records | Contracts, invoices, correspondence and transaction records | Legal obligations; performance of agreements; establishment or defence of legal claims |
| Send permitted business communications | Contact details and communication preferences | Consent where required, an existing-customer relationship where permitted, and our legitimate interests subject to your rights |
Where we rely on consent, you may withdraw it, but withdrawal does not affect processing that was lawful before withdrawal. Where we rely on legitimate interests, we consider the purpose, necessity and impact on your rights before processing.
5. Voluntary and mandatory information
Providing information through general website forms is voluntary. Fields marked as required are necessary to route, assess or respond to the relevant request. If you do not provide required information, we may be unable to process the enquiry, arrange a demonstration, provide support or administer the requested service.
Certain information may be mandatory under a contract, an applicable law, a security requirement or a client’s authorised workflow. Where practical, the relevant form, agreement or instruction will explain this.
6. When we share personal information
We may disclose personal information only where relevant and lawful to:
- authorised MUFK Integrated personnel who need it for their duties;
- the client or organisation responsible for the relevant workspace, request or business relationship;
- approved operators such as hosting, communications, meeting, support, document-storage, security, professional-advisory and integration providers;
- authorised suppliers or implementation partners where their involvement is necessary for the request or service;
- regulators, law-enforcement authorities, courts or other parties where disclosure is required or permitted by law; and
- a successor or transaction adviser in connection with a lawful corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal information. An affiliation or business relationship does not by itself authorise personal information to be shared.
Where an operator processes personal information for us, we require the operator to act with our knowledge or authorisation and to apply appropriate confidentiality and security obligations. Information about relevant operator categories may be requested through our privacy contact.
7. Cross-border processing
Some approved service providers or their infrastructure may be located outside South Africa. Where personal information is transferred to or accessible from another country, we will apply the requirements of section 72 of POPIA, including an applicable legal basis and appropriate contractual or legal protections.
We assess cross-border arrangements in light of the information involved, the recipient, the destination and the safeguards available. Further information about a transfer relevant to your information may be requested through our privacy contact.
8. Cookies, website logs and similar technologies
The website may use essential technologies needed for navigation, form operation, security and accessibility. Our hosting and security services may also create server logs containing technical information such as IP address, browser type, requested page and timestamp.
As at the effective date of this notice, the public website does not intentionally use advertising or behavioural-tracking technologies. If non-essential analytics, advertising cookies or similar tools are introduced, we will update this notice and obtain consent where required.
9. Security safeguards
We are required to use appropriate, reasonable technical and organisational measures to protect the integrity and confidentiality of personal information against loss, damage, unauthorised destruction, unlawful access or unlawful processing. Controls should be proportionate to the information and risks and may include access management, confidentiality obligations, secure configuration, monitoring, backups, incident handling and operator controls.
No system can be guaranteed completely secure. If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and make notifications as required by applicable law.
10. How long we retain personal information
We retain personal information only for as long as needed for the purpose for which it was collected, to meet contractual or client requirements, to comply with law, to resolve disputes, and to establish or defend legal rights. When information is no longer required, it should be securely deleted, destroyed or de-identified, subject to backup-expiry and lawful-hold arrangements.
Retention periods vary by record type. Website enquiries, demonstration requests, support records, platform records, financial records, security logs and marketing-preference records may each have different periods.
When setting an appropriate retention period, we consider the nature and sensitivity of the information, the purpose of processing, applicable contracts and client instructions, statutory record-keeping obligations, security and audit needs, and relevant limitation periods. Website enquiries, demonstration requests, support records, attachments, platform records, financial records, security logs and communication preferences are managed according to those criteria.
11. Your privacy rights
Subject to POPIA, PAIA and applicable limitations, you may:
- ask whether we hold personal information about you and request access to it;
- ask us to correct or update inaccurate, incomplete, excessive, outdated or misleading information;
- request deletion or destruction where the information is no longer authorised to be retained;
- object, on reasonable grounds, to certain processing;
- withdraw consent where consent is the basis for processing;
- object to direct marketing and opt out of future marketing communications; and
- lodge a complaint with the Information Regulator (South Africa).
To protect you and others, we may need to verify your identity and authority before acting on a request. We will explain if a request cannot be fulfilled or if an applicable fee or formal PAIA process is required.
12. Children and special personal information
The public website is directed at organisations and adult business users. It is not intended to collect children’s personal information through general enquiry, demonstration or support forms.
Please do not submit special personal information or children’s information unless it is necessary, authorised and supported by an applicable legal basis and approved workflow. Where such processing is required within a client implementation, it must be addressed through the relevant agreement, privacy information, access controls and any required authorisation.
13. Direct marketing
We will send electronic direct marketing only where permitted by POPIA, including where valid consent has been obtained or an applicable existing-customer relationship allows communication about similar services. Each eligible marketing communication should provide a reasonable way to opt out.
You may object to direct marketing at any time using the unsubscribe method in the communication or by contacting us. We may retain a minimal suppression record so that your preference continues to be respected.
14. Client platform information and automated processing
For information processed in a client’s MUFK Integrated workspace, the client generally determines the purposes, authorised users, workflows, categories of records and retention requirements. MUFK Integrated’s role must be confirmed in the applicable agreement and implementation documentation.
The public website forms do not make decisions that produce legal consequences or similarly significant effects solely through automated processing. If automated decision-making or profiling is introduced into a service, the responsible party must assess the legal requirements and provide appropriate information and safeguards.
15. Changes to this notice
We may update this notice when our services, processing practices, service providers or legal obligations change. The current version will be posted on this page with its effective and last-updated dates. Material changes may also be communicated through an appropriate additional channel.
16. Contact us or lodge a complaint
Questions, objections and requests about personal information can be directed to:
The Information Officer, Mupo Projex (Pty) Ltd t/a MUFK Integrated
Email: admin@mufk85.co.za
Telephone: 012 004 2004
Address: Office 0005, Jardown 1, 377 Johannes Ramokhoase Street, Pretoria, 0002, South Africa
If you believe that your personal information has been processed unlawfully, you may lodge a complaint with the Information Regulator (South Africa):
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Telephone: 0800 017 160 or 010 023 5200
Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Privacy enquiries
Contact MUFK Integrated about access, correction, deletion, objections or other privacy questions.
admin@mufk85.co.za
012 004 2004
Related information
PAIA and Access to Information
Security and Data Handling
Website Terms of Use