Who we are
MMI Multiply (Pty) Ltd (“Multiply”) is a subsidiary of MMI Holdings Limited (“MMI”), a listed entity on the Johannesburg Stock Exchange). Multiply will maintain the confidentiality of your personal information and comply with the Protection of Personal Information Act 4 of 2013 (POPIA) when processing your personal information.
This notice applies to South African entities within the MMI Holdings Limited of companies its subsidiaries, operating divisions, business units, licensed entities, management-controlled entities and activities.
Multiply is an incentivised wellness programme that rewards and encourages its members to become holistically well by arranging access to various wellness and leisure facilities and services. Multiply also offers members discounts at various providers and services to incentivise and reward their wellness behaviours.
The purpose of the notice
The purpose of this notice is to inform Multiply’s clients about the type of personal information which the company collects, the ways in which it is collected, shared, protected, used and stored.
What is personal information?
The term ‘personal information’, as used in this notice, applies to information that may be used to identify an individual or a juristic person (i.e. for example a registered company).
POPIA defines personal information as “information which relates to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person. The person to whom personal information relates is referred to as the “data subject”.
Examples of personal information include, but are not limited to, contact information, financial information, information relating to race, gender, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person.
What type of personal information does Multiply collect?
Personal information collected by Multiply can include, but not limited to, a data subject’s name, contact, birth date, identity number, gender, employment details, marital, family, policy, bank account, wearable device information, medical and/or health information.
When personal information is collected, Multiply will indicate the purpose for the collection and whether the information required is compulsory or voluntary.
How does Multiply collect personal information?
The company collects information either directly from the data subject, the employer or through financial services intermediaries. In certain instances, Multiply may collect information from Third Parties and Partners on its behalf. The source from which personal information was obtained, if not directly from the data subject, will be disclosed.
Use of personal information
After obtaining consent, the personal information collected or held by Multiply may be used, stored, transferred or disclosed or shared within MMI group of companies for the following purposes:
- Providing you with customised benefits and services across Multiply and the MMI Group;
- Administration and fraud prevention measures;
- Marketing, statistical and research purposes; and
- If permission is given, Multiply may use your personal or other information to tell you about its products, services and special offers or those of other subsidiaries of MMI.
Sharing of personal information
Multiply will only share your personal information with third parties if you have consented to such disclosure. If consent has been obtained, the company may share your personal information with persons or organisations within and outside of MMI.
Where Multiply discloses personal information to intermediaries, other financial institutions, insurers or any other third parties, the third parties will be obliged to use that personal information only for the reasons and purposes it was disclosed for. Multiply may be obliged to disclose your personal information to the extent that it is required to do so by law, in connection with any legal proceedings or prospective legal proceedings, or for the purposes of protecting the interest of clients, for example, fraud prevention or to give effect to an agreement.
Securing personal information
Multiply will take all reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. The company will store all the personal information in secured environments, for example on secured servers in a protected data centre.
How you can review and correct your personal information
You can request to review your personal information stored on Multiply’s records at any time to correct or update the information. If the purpose for which your personal information was requested initially does not exist anymore, for example you no longer have a contract with MMI or Multiply membership with Multiply, you may request information held by the company to be removed. However, Multiply can decline your request to delete the information from its records if other legislation requires the continued retention thereof or if it has been de-identified.
Updating of this processing notice
Multiply may update this notice periodically and an updated version may be requested, for example through a postal request or through an email notification addressed to the contact details provided below.
Managing Data Privacy at MMI Board Level and Reporting Frequency
The MMI Board Risk Capital and Compliance Committee (BRCC) is a sub-committee of the Board that is accountable to address and manage the risk of data privacy and cyber security. The BRCC follows the board cycle and convenes on a quarterly basis. The MMI Group Chief Operations Officer (COO) is the business representative on BRCC for data privacy, data security and cyber security. The MMI Chief Risk Officer also provides guidance and input regarding appropriate Risk Management.
Employee Training on Cyber Security and Data Privacy
Employee Training on Cyber Security and Data Privacy forms part of ongoing compliance training. Cyber Security training is currently further required as a basic compliance training that all employees must complete. As part of the POPIA management programme, there is a specific focus on training, awareness as well as communication that will cover data privacy, data security and more detailed cyber security training as mandatory compliance training to all staff. The POPIA management programme is actively managed at MMI Group level with participation of all business entities and subsidiaries of MMI.
Centralised Cyber Security and Data Security Functions and Coordination
To deal with Cyber Security and Data Security, two separate centralised functions exist within MMI. The IT Security environment includes managing cyber security as a capability and the Data Management environment deals with the aspects of data privacy and extended data security which is enabled through IT security.
These two functions report into the Group COO and is coordinated to work closely together to ensure coordinated efforts to best deliver on the relevant requirements.
If you have any questions about this notice or Multiply’s treatment of your personal information, please address an email to [email protected]