Privacy policy
Studio Broder Fine Jewellery Design
How we collect, use and protect your personal information (POPIA), and our manual under PAIA.
Part A — Privacy Notice
This Part explains how Studio Broder collects, uses, shares and protects your personal information, in terms of the Protection of Personal Information Act 4 of 2013 ("POPIA").
Who is responsible for your information
The responsible party is Studio Broder CC (registration number CK97/21154/23), trading as Studio Broder Fine Jewellery Design, of Shop 5, Beacon Bay Crossing, Bonza Bay Road, Beacon Bay, East London, Eastern Cape, 5241.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").
Information Officer
Our Information Officer is Broder Scharein, contactable at broderscharein@icloud.com or +27 43 726 0225.
What this policy covers
This policy applies to personal information we collect when you visit studiobroder.co.za, buy from us, contact us, subscribe to our mailing list, or visit our store. It does not cover third-party websites we link to.
What personal information we collect
- Identity and contact details — your name, email address, telephone number, delivery address and billing address.
- Order information — the items you view, add to your cart and buy, your order history, ring sizes and engraving or design preferences, and your correspondence with us about an order.
- Payment information — the fact and amount of a payment, the payment method used, and a partial card reference. We do not receive or store your full card number or CVV. Card data is captured and processed directly by Payfast.
- Account information — if you create an account, your username and encrypted password.
- Technical information — your IP address, device and browser type, and how you navigate our site, collected through cookies and similar technologies.
- Marketing preferences — whether you have consented to receive our newsletter, and whether you have opted out.
We do not deliberately collect special personal information as defined in POPIA (such as health, religious or biometric information). Please do not send us such information unless we specifically ask for it.
Where we get your information
- Directly from you, when you order, register, contact us, subscribe or visit our store.
- Automatically, through cookies and analytics when you use our site.
- From our service providers — for example, Payfast confirms whether a payment succeeded, and The Courier Guy confirms delivery.
Why we process your information, and on what basis
POPIA requires us to have a lawful justification for processing. Ours are:
- To perform our contract with you — processing your order, taking payment, arranging delivery or collection, handling returns, repairs and warranty claims, and communicating with you about your order.
- To comply with a legal obligation — keeping accounting and tax records, and responding to lawful requests from authorities.
- For our legitimate interests — preventing fraud, securing our site, keeping records of complaints, understanding how our site is used, and improving what we offer.
- With your consent — for our newsletter and marketing, and for non-essential cookies. You may withdraw consent at any time.
Direct marketing
Section 69 of POPIA governs electronic direct marketing.
If you are not an existing customer, we will only send you marketing if you have given consent — for example, by subscribing to our newsletter. Subscription boxes are never pre-ticked.
If you are an existing customer, we may send you information about similar jewellery and services. We give you the opportunity to object when we collect your details and in every message we send.
Every marketing email contains an unsubscribe link, and you may also unsubscribe at any time by emailing broderscharein@icloud.com. We will action it promptly and at no cost to you. Opting out of marketing does not stop transactional messages such as order confirmations and delivery notices.
Children
Under POPIA, a child is a person under 18 years of age. Our site is not intended for children, and we do not knowingly collect the personal information of children. If you believe we hold information about a child, please contact our Information Officer and we will delete it.
Who we share your information with
We share personal information only where it is necessary, and we require our operators to protect it and to use it only for the purpose we gave it to them. We share with:
- Shopify — our e-commerce platform and website host.
- Payfast — our payment gateway.
- The Courier Guy — for delivery, which requires your name, address and phone number.
- Our email and marketing provider — for order notifications and, where you have consented, our newsletter.
- Our accountants and professional advisors, and any authority or court where we are legally required to disclose.
- A purchaser of our business, if we sell or transfer it, subject to the same protections.
We do not sell your personal information.
Information sent outside South Africa
Shopify and some of our other service providers store and process information on servers outside South Africa. Section 72 of POPIA permits this where the recipient is subject to laws or binding agreements that provide an adequate level of protection, or where the transfer is necessary to perform our contract with you. We rely on the data processing terms in our agreements with these providers, which require standards comparable to POPIA.
Where our providers also process information under the European GDPR or UK data protection law, they apply recognised transfer mechanisms such as Standard Contractual Clauses.
Cookies and similar technologies
Cookies are small files placed on your device. We use:
- Strictly necessary cookies — to keep you logged in, remember your cart and process checkout. The site cannot function without these.
- Analytics cookies — to understand how the site is used so we can improve it.
- Marketing cookies — to measure and, where you consent, personalise our advertising.
When you first visit, you will see a banner allowing you to accept or decline non-essential cookies. You can change your choice at any time through that banner, and you can block or delete cookies in your browser settings — although parts of the site may then not work properly.
How we protect your information
As required by section 19 of POPIA, we take reasonable technical and organisational steps to safeguard personal information. These include encrypted connections (HTTPS) across the site, payment processing by a PCI-DSS compliant provider so that we never handle raw card data, access controls and strong passwords on our systems, and limiting access to those who need it.
No system is completely secure, and we cannot guarantee the security of information you send us over the internet. Please do not send card details, identity numbers or other sensitive information to us by email.
If something goes wrong
If we have reasonable grounds to believe your personal information has been accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and you as soon as reasonably possible, and to tell you what happened and what you can do to protect yourself. We will do so.
How long we keep your information
We keep personal information only for as long as we need it, as required by section 14 of POPIA:
- Order, invoice and payment records — five years from the end of the relevant tax year, as required by tax and company legislation.
- Warranty, repair and valuation records — for as long as needed to honour the warranty or service the piece, and to prove provenance.
- Complaint records — three years, in line with consumer industry practice.
- Marketing consents — until you unsubscribe, and a suppression record thereafter so that we do not contact you again.
- Website analytics — as configured in our analytics tools, ordinarily no longer than 26 months.
When we no longer need information, we delete it or de-identify it.
Your rights
Under POPIA you have the right to:
- be told what personal information we hold about you and to request a copy of it (sections 23 and 24);
- ask us to correct information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained;
- ask us to delete or destroy information we no longer have the right to keep;
- object to processing that we carry out on the basis of legitimate interests (section 11(3));
- withdraw your consent to marketing at any time; and
- complain to the Information Regulator.
To exercise any of these rights, contact our Information Officer. You may use the prescribed forms under the POPIA Regulations — Form 1 to object to processing, and Form 2 to request correction or deletion — which are available from us on request or from inforegulator.org.za, but you do not have to use them to make a request.
We may need to verify your identity before we act. We will respond as soon as reasonably possible. A request for access to information is dealt with under the Promotion of Access to Information Act 2 of 2000 and may attract the prescribed fee, as set out in our PAIA Manual.
Complaints
Please raise any concern with our Information Officer first — we would like the chance to put it right. If you are not satisfied, you may complain to:
The Information Regulator (South Africa)
Complaints are lodged through the Regulator’s eServices portal.
Changes to this policy
We may update this policy to reflect changes in how we work or in the law. The current version is always on this page, showing the date it was last updated. Where a change materially affects you, we will bring it to your attention.
Contact us
Studio Broder CC t/a Studio Broder Fine Jewellery Design
Part B — PAIA Manual
Access to information (PAIA)
The Promotion of Access to Information Act 2 of 2000 ("PAIA") gives you the right to request access to records we hold. Our PAIA Manual sets out the records we keep, how to request access, the fees that apply, and the grounds on which access may be refused.
Requests must be directed to our Information Officer at broderscharein@icloud.com.
Studio Broder CC (CK97/21154/23) · Privacy Policy