POPIA

We comply with South Africa’s Protection of Personal Information Act (POPIA), which addresses the lawful processing conditions and other requirements for handling personal information.

Last Updated: September 2026
Website Policies

POPIA sections

The Protection of Personal Information Act, 4 of 2073 (POPIA) came into effect on 1 July 2020. POPIA regulates how personal information of natural and juristic entities must be processed (‘data subjects’) and sets out certain obligations that must be complied with when processing personal information.

POPIA provides for a 1-year grace period during which a responsible party (party responsible for processing the personal information of data subjects) must ensure compliance with the provisions of POPIA.

POPIA provides for eight lawful processing conditions which a responsible party must comply with when processing personal information of data subjects, which conditions are:

  • Accountability:  The responsible party must implement measures to ensure compliance with the lawful processing conditions.
  • Processing Limitation:  The purpose of the processing of personal information must be justifiable and must take place in a lawful, reasonable and non-excessive manner.
  • Purpose Specification:  Personal information must be collected and processed for a specific and defined purpose.
  • Further Processing Limitation:  Personal information may not be processed for a further purpose where such purpose is not compatible with the original purpose of the collection or where so authorised by the Information Regulator.
  • Information Quality:  The responsible party must ensure the personal information being processed is complete, accurate, not misleading, and updated where necessary.
  • Openness:  The responsible party must notify the data subject of its processing activities.
  • Security Safeguards:  The responsible party must implement security safeguards to ensure the integrity and confidentiality of the personal information is protected.
  • Data Subject Participation:  Data subjects have certain rights in terms of their personal information held by a responsible party, which includes requesting access thereto and the correction or deletion thereof.

  • Reviewed our internal processes and created new processes to ensure compliance with the lawful processing conditions, including processes related to the collection, storage, and destruction of personal information
  • Updated our internal policies to allow for the monitoring of compliance with the provisions of POPIA
  • Created a privacy policy, which will apply to us and any third parties processing personal information on our behalf, requiring compliance with the provisions of data privacy legislation, including POPIA
  • Reviewed and updated all our agreements to provide for data privacy and protection in accordance with the requirements of POPIA
  • Implementing new and updating current security safeguards to ensure the proper protection of personal information processed by us
  • Created a process which allows data subjects to request access to, or the correction or deletion of, their personal information held by us
  • Provided training to the various departments to ensure they remain aware and up to date of their obligations under POPIA
  • Created a privacy statement to ensure data subjects are notified of all of our processing activities in relation to their personal information
  • Improved our security and data breach processes to meet the requirements of POPIA

We commit to protect your privacy and to ensure that your personal information is used appropriately, transparently, securely and in accordance with applicable laws.

This privacy notice informs you of the information we collect from you. In collecting this information, we are acting as a responsible party and, by law, we are required to provide you with information about us, why and how we use your data, and what rights you have over your data.

The personal information that you provided us will be used solely to communicate with you and to manage your order. It will, under no circumstances, be used for any other reason, but to allow us to create a profile for you internally.

All personal information that is collected by our company is used in accordance with the purpose for which it was collected. Information collected will not be used for any other purpose before obtaining your approval, unless the new purpose is required by law.

All data received by our company adheres to the strictest data security, and no data is provided to any third party whatsoever without the proper consent.

By law, you can ask us what information we hold about you, you can see it, and you can ask us to correct it if it is inaccurate. You can also ask for it to be erased, and you can ask for us to give you a copy of the information.

You can also ask us to stop using your information at any time, either by clicking the unsubscribe link at the end of any email communication, or by emailing us using the following e-mail address: compliance@rune.boats.

If you have a complaint about our use of your personal information, we would prefer you to raise it with us in the first instance to give us the opportunity to put it right, but you can also contact the Information Regulator’s Office via their website at www.justice.gov.za/inforeg/contact.html or by email at inforeg@justice.gov.za. Alternatively, you can write to them at:

The Information Regulator (South Africa)

JD House
27 Stiemens Street
Braamfontein
Johannesburg
2001

Reach Out

We’re eager to respond to any POPIA enquiries you might have.

+27 (0)62 959 8412compliance@rune.boats

Rune (Pty) Ltd.
Registration: 2025/803183/07

Website Policies