Privacy Policy ZA
DOLPHIN TELECOMS MOBILE SA
Privacy Policy
This Privacy Policy (“Policy”) explains how Dolphin Telecoms Mobile (Pty) Ltd (“Dolphin Telecoms Mobile SA”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use our network, products, services, website, and digital onboarding channels (including SIM registration), in compliance with the Protection of Personal Information Act, 2013 (“POPIA”) and the Regulation of Interception of Communications and Provision of Communication-related Information Act, 2002 (“RICA”). By using our services, you acknowledge that your personal information will be processed as described in this Policy.
1. About This Policy
1.1. This Policy applies to all personal information Dolphin Telecoms Mobile SA collects or receives from you, whether through our retail stores, website, mobile app, call centre, or digital onboarding tools used for SIM registration and identity verification.
1.2. This Policy should be read together with any other notice, term, or condition we give you when you use a specific product or service, including any service-specific terms and conditions.
1.3. By using our Services, you acknowledge that Dolphin Telecoms Mobile SA may process your Personal Information in accordance with this Policy. Where POPIA requires consent as a legal basis for Processing, we will obtain your consent. In other circumstances, we may rely on another lawful basis permitted under POPIA, including the performance of a contract, compliance with a legal obligation, protection of legitimate interests, or our legitimate business interests.
2. Definitions
- "Dolphin Telecoms Mobile SA / We / Us / Our" means Dolphin Telecoms Mobile (Pty) Ltd, its holding company, subsidiaries, and affiliated entities, together with their directors, employees, agents, service providers, and any Operators processing personal information on our behalf.
- "Data Subject / You" means any person to whom personal information relates, as defined in POPIA.
- "Information Officer / IO" means the person appointed by Dolphin Telecoms Mobile SA and registered with the Information Regulator to ensure compliance with POPIA.
- "Operator" means a person or entity that processes personal information for Dolphin Telecoms Mobile SA under a written contract, without falling under our direct authority, as defined in POPIA.
- "Personal Information" means information relating to an identifiable living person (and, where applicable, an identifiable existing juristic person), including name, race, gender, marital status, address, identification number, contact details, location data, and online identifiers, as defined in POPIA.
- "Special Personal Information" means personal information concerning religious or philosophical beliefs, race or ethnic origin, trade union membership, political opinions, health, sex life, biometric information, or criminal behaviour, as defined in POPIA.
- "Processing" means any activity involving personal information, including its collection, receipt, recording, organisation, storage, updating, retrieval, use, distribution, merging, restriction, or destruction.
- "Responsible Party" means the party that determines the purpose and means of processing personal information. Dolphin Telecoms Mobile SA is the Responsible Party for personal information processed in connection with its business.
- "RICA" means the Regulation of Interception of Communications and Provision of Communication-related Information Act, 2002, as amended.
- "POPIA" means the Protection of Personal Information Act, 2013, and any regulations or codes of conduct issued under it.
- "Services" means any product, network access, digital onboarding, or customer service Dolphin Telecoms Mobile SA provides, including SIM registration and identity verification services.
- "SIM Card" means the Subscriber Identity Module linked to your mobile number that allows you to access the Dolphin Telecoms Mobile SA network.
3. Who We Are: Responsible Party and Information Officer
3.1. Dolphin Telecoms Mobile SA is the Responsible Party for personal information processed as part of our business and is responsible for ensuring that such processing complies with POPIA.
3.2. Our Information Officer is registered with the Information Regulator and is responsible for encouraging compliance with POPIA within Dolphin Telecoms Mobile SA, dealing with requests from data subjects, and cooperating with the Information Regulator. The Information Officer can be contacted using the details in Section 17.
4. Personal Information We Collect
Depending on how you interact with us, we may collect:
- Identity information, such as your full name, date of birth, ID or passport number, and nationality;
- Contact information, such as your residential address, email address, and phone number;
- SIM registration and RICA information, including proof of residence, a copy of your ID or passport, a photograph or “selfie”, and facial or voice recognition data used to verify your identity;
- Account and billing information, such as your service plan, payment method, and billing history;
- Network and usage data, such as call, SMS, and data session records, and device/location information necessary to provide the service;
- Information you provide when contacting our call centre, visiting our website, or engaging with us on social media platforms; and
- Information from trusted third-party sources, used to verify the details you provide to us.
4.1. Where you connect a third-party device (such as a smartphone, smart speaker, or smart watch) to your SIM Card, that device manufacturer may separately collect information about your SIM Card or network usage, governed by their own privacy policy. Dolphin Telecoms Mobile SA is not responsible for the privacy practices of third-party device manufacturers.
5. SIM Registration (RICA) Requirements
5.1. RICA registration is mandatory for every SIM Card. We will not activate a SIM Card until the information RICA requires has been properly captured and verified.
5.2. To register a SIM Card, we may require your full name, residential address, a facial photograph or “selfie”, and copies of your ID or passport and proof of residence. We may also capture biometric data (such as facial or voice recognition information) to verify your identity, which is processed as Special Personal Information under Section 8.
5.3. If your SIM Card is lost, stolen, damaged, or destroyed, you must report this to the South African Police Service immediately. Failure to do so may constitute an offence under RICA and may result in a fine or imprisonment.
5.4. If you transfer your SIM Card to another person (other than a family member or dependant), RICA section 40(5) requires that you provide us with that person's registration details immediately, so that we can re-register the SIM Card in their name. Failure to do so is a criminal offence under RICA.
5.5. Dolphin Telecoms Mobile SA may suspend or terminate a SIM Card or any associated service, without notice, where a SIM Card is transferred without our consent or without the registration information required by RICA.
6. Lawful Basis for Processing Under POPIA
In line with POPIA's conditions for lawful processing, Dolphin Telecoms Mobile SA only processes personal information where:
- You have given your consent to the processing;
- Processing is necessary to conclude or perform a contract with you;
- Processing is required to comply with a legal obligation we are subject to (for example, RICA, FICA, or tax legislation);
- Processing protects a legitimate interest of yours;
- Processing is necessary to pursue our legitimate business interests, provided this does not unreasonably override your rights and interests; or
- Processing is necessary to perform a public law duty by a public body.
6.1. We process personal information for purposes including: providing and maintaining our services; complying with our obligations under RICA, the Financial Intelligence Centre Act, the Electronic Communications and Transactions Act, the Electronic Communications Act, the Consumer Protection Act, the Promotion of Access to Information Act, and the Cybercrimes Act; preventing and detecting fraud and financial crime; maintaining network and service security; improving our website and customer experience; direct marketing (subject to Section 9); and protecting your interests, including service notifications, emergency service alerts, and identity verification.
7. How We Collect Personal Information
7.1. We collect personal information directly from you when you use our products, services, website, or social media platforms, and directly from you during the SIM registration process.
7.2. We may supplement the information you give us with information that is publicly or commercially available, or obtained from trusted third-party verification sources, to confirm your identity and address details.
7.3. Information collected for RICA registration is used solely for that purpose, unless you separately consent to further processing for other purposes described in this Policy.
8. Special Personal Information
8.1. Where we collect Special Personal Information — including biometric data used for identity verification — we do so only where permitted under POPIA, such as where you have provided consent, where it is necessary to establish or verify your identity, or where another statutory exemption applies.
8.2. Special Personal Information is subject to additional security safeguards and is only accessible to personnel who need it to perform identity verification or fraud-prevention functions.
8.3. Where biometric information is collected for identity verification, fraud prevention, or compliance with RICA and other legal obligations:
- it will only be processed for those purposes;
- it will only be accessible to authorised personnel and approved service providers;
- it will not be used for automated decision-making that produces legal effects on you without appropriate safeguards; and
- it will be retained only for as long as required to fulfil verification, regulatory, audit, or legal obligations.
8.4. Where identity verification is performed by an authorised third-party provider on our behalf, that provider will act as a processor and will be contractually required to protect the information in accordance with POPIA.
9. Direct Marketing
9.1. We will only send you direct marketing communications by electronic means if you have given your consent, or if you are an existing customer and we are marketing similar products or services to those you have already acquired from us, in accordance with POPIA.
9.2. You may opt out of direct marketing at any time, free of charge, using the unsubscribe or opt-out option provided in each communication, or by contacting us using the details in Section 17.
10. Disclosure and Sharing of Personal Information
10.1. We do not sell your personal information to third parties for their own marketing purposes. We may share personal information, where applicable, with:
- Government bodies, regulators, law enforcement agencies, or courts, where required or authorised by law, including on receipt of a valid directive under RICA;
- Trusted third parties who assist us in verifying the information you provide;
- Our Operators and service providers who process personal information on our behalf, under a written contract that requires them to protect it to a standard consistent with POPIA;
- Third parties where disclosure is necessary to comply with any law or regulatory requirement; and
- Other organisations, with your knowledge, where you sign up for a third-party service that requires identity verification or fraud prevention through us.
11. Cross-Border Transfer of Personal Information
Any transfer of Personal Information outside South Africa will only occur where:
- the recipient is subject to laws, binding rules, or contractual obligations that provide a level of protection substantially similar to POPIA
- the transfer is necessary for the performance or conclusion of a contract with you;
- the transfer is necessary for the implementation of pre-contractual measures taken at your request;
- the transfer benefits you and it is not reasonably practical to obtain your consent; or
- you have consented to the transfer, as permitted by Section 72 of POPIA.
12. Data Retention
12.1. We retain Personal Information only for as long as necessary to fulfil the purposes for which it was collected, to provide Services to you, and to comply with applicable legal and regulatory requirements.
12.2. Certain information may be retained for longer periods where required by law, including:
- RICA registration records;
- telecommunications and communications-related records;
- tax and accounting records;
- anti-fraud and security records;
- records required to resolve disputes or enforce legal rights.
12.3. Where retention is no longer necessary, Personal Information will be securely deleted, destroyed, de-identified, or anonymised in accordance with POPIA and our internal records management procedures.
12.4. We may retain anonymised information indefinitely where it can no longer be used to identify an individual.
13. Security Safeguards
13.1. If Dolphin Telecoms Mobile SA has reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, we will investigate the incident and take appropriate remedial action.
13.2. Where required by law, we will notify the Information Regulator and affected Data Subjects as soon as reasonably possible after becoming aware of a security compromise.
13.3. Such notification may be provided by email, SMS, publication on our website, or any other method permitted by applicable law.
14. Your Rights as a Data Subject
Under POPIA, you have the right to:
- Request confirmation, free of charge, of whether we hold personal information about you;
- Request access to the personal information we hold about you;
- Request the identities of, or categories of, third parties to whom your personal information has been disclosed;
- Request that we correct, update, or delete personal information that is inaccurate, incomplete, misleading, excessive, or out of date;
- Object, on reasonable grounds, to the processing of your personal information;
- Withdraw any consent you have given for processing, at any time; and
- Lodge a complaint with the Information Regulator (see Section 17) if you believe we have not complied with POPIA.
14.1. Requests to exercise these rights may be submitted in writing using the contact details in Section 17.
14.2. If you object to the processing of your personal information, or withdraw consent, we may no longer be able to provide you with the product, service, or information you have requested.
14.3. Your rights under this Section may be limited in certain circumstances where we have a lawful basis to continue processing your personal information, such as a legal or regulatory obligation.
15. Cookies and Similar Technologies
15.1. Our digital platforms may use cookies, pixels, analytics tools, and similar technologies to:
- remember user preferences;
- improve website functionality and performance;
- understand how users interact with our website and applications;
- assist with fraud prevention and security monitoring.
15.2. You may configure your browser settings to refuse certain cookies; however, doing so may affect the functionality of our website or digital services.
15.3. To the extent required by law, we will obtain your consent before placing non-essential cookies on your device.
16. Intellectual Property
All intellectual property in our website, application, and services belongs to Dolphin Telecoms Mobile SA or its licensors. You may access and use this content for your own personal, non-commercial use only, and may not reproduce, adapt, modify, distribute, or publish it without our prior written consent.
17. Disclaimer and Limitation of Liability
17.1. While we take reasonable steps to ensure our services function properly and the information we provide is accurate, we do not guarantee, to the fullest extent permitted by law, that our services will be uninterrupted, error-free, or fault-free.
17.2. To the extent permitted by law, you indemnify Dolphin Telecoms Mobile SA against any loss, liability, claim, or cost arising directly or indirectly from your breach of this Policy, or from your use of our services, except where such loss results from our gross negligence or intentional misconduct.
17.3. We will not be liable for any failure or delay in performing our obligations due to circumstances beyond our reasonable control, including network faults, acts of government, force majeure, or the default of a supplier or sub-contractor.
18. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or in the law. Updates will be published on our website and take effect from the date of publication. We encourage you to review this Policy periodically.
19. General
19.1. This Policy is governed by the laws of South Africa, and you submit to the jurisdiction of the South African courts.
19.2. If any provision of this Policy is found to be invalid or unenforceable, that provision will be removed without affecting the enforceability of the remaining provisions.
19.3. Our failure to enforce any right or provision of this Policy does not waive that right or provision, unless we agree to the waiver in writing.
20. How to Contact Us
If you have any questions, requests, objections, complaints, or wish to exercise any rights under POPIA, please contact:
Dolphin Telecoms Mobile (Pty) Ltd
Physical Address: Suite 1217, Leonardo, 75 Maude Street, Sandton
Information Officer
Email: info@dolphintelecoms.com