SAMS - Privacy Notice
Privacy Notice
Data Controller
Mezzanine (Pty) Ltd is the controller of the personal data that you (the data subject) provide us. Once you consent to the collection of your personal data through the use of this product ("product") we collect the below-listed types of personal data from you the data subject.
The use and storage of your data are processed in accordance with this privacy notice.
Data Processing
Purpose of Processing
SAMS collects and stores your personal data securely in the SAMS database primarily for the following purposes:
- In order to register as a user on the Helium web platform and enroll as a user on the Journey mobile platform, your mobile phone number is used as user identity along with the Full Name and Email address. This further facilitates secure communication of login credentials.
- Physical or In Progress assets are recorded in the system and assigned to either a Room in a Building or a client Facility. In turn, the Room or Facility can be assigned to a custodian, who is the entity taking responsibility for those assets. We collect the Full Name, Mobile Number, and Email Addresses of registered custodians. A digital signature and location can be collected as confirmation of asset verification. The Full Name and Signature of Custodians appear on printed room reports.
- SAMS uses IoT-enabled sensors and devices to monitor performance indicators of physical assets. The collected real-time data can trigger Work Orders, Email and SMS alerts, and other actions assigned or directed to specific registered users. In order for users to register to receive these work orders, SMS, And Email Alerts, we collect their Full Name, Mobile Numbers and Email address.
- Service Requests and Work Orders are created by and assigned to registered users of SAMS and can be linked to physical assets in the system. Users can log their travel, labour and expenses as part of the work order completion process. Certain timestamps related to actions performed by the users are also captured for reporting purposes. Service requests also require capturing personal details relating to the requester of work, which may or may not be a user of SAMS and includes the Full Name, Telephone number and Email address.
- User activity is processed for audit, and product and process improvement purposes.
- All data can also appear on Grafana and Tableau Reports.
Legal Basis for Processing
The legal basis for the processing of the personal data of the data subject is:
- processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
Voluntary or Mandatory Provision of Personal Data
The personal data listed in section "Provision of Personal Data" is provided voluntarily and is provided voluntarily due to the below-listed reasons.
- User Email Address, if the email address is not provided users cannot receive login notifications, alerts and room reports via email.
- Custodian Email Address, not mandatory.
- Requester Department, not mandatory.
- Requester Email Address, not mandatory.
Provision of Personal Data
Once you consent (or due to the legal basis listed above) to the collection of your personal data through the use of this product we collect the below-listed types of personal data from you the data subject.
- First name, Last Name/surname
- Phone number
- Login username (not applicable for requesters)
- Password
Consequences of failure to provide information
The consequence of failure to provide the personal data listed in section "Provision of Personal Data" is disqualification from access to the product/service.
Data Transfer
Personal Data Recipients
The personal data of the data subject will be processed by the below-listed recipients.
- Mezzanine (Pty) Ltd
- EMS Solutions
- Data Subject Employer
Personal Data Storage
Personal data is stored until end of contract with client plus ten years.
Automated Decision-Making
The processing activities do not include automated decision-making.
Source of Personal Data
The personal information of the data subject was lawfully obtained from the below-listed sources.
- Data Subject
- EMS Solutions
- Data Subject Employer
Data Subject Rights
Data subjects have the below-listed rights with regards to the personal data of the data subject.
- Right of access to information regarding the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations, where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period
- Right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing
- Right to lodge a complaint with a supervisory authority
- Right to any available information as to their source where the personal data are not collected from the data subject
- Right to be informed of the existence of automated decision-making, including profiling, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
- Right to be informed of the appropriate safeguards where personal data are transferred to a third country or to an international organization
- Right to be provided with a copy of the personal data undergoing processing
- Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
- Right to object to the processing of personal information
- Right to be informed that and what personal information has been collected when not collected from the data subject
- Right to be informed that and what personal information has been accessed or acquired by an unauthorized person as well as security compromises
Data Subject Complaints
In the event that you wish to complain about how we have handled your personal data, please contact Data Protection Officer at data-protection-officer@mezzanineware.comor in writing atSuite 173, Private Bag x14, Die Boord, 7613.Our Data Protection Officer will then look into your complaint and work with you to resolve the matter.
If you still feel that your personal data has not been handled appropriately according to the law you can contact the Information Regulator: South Africa (POPIA) or the relevant Supervisory Authority (GDPR) of your region.