Last updated: Milprops 318 CC
This Operator / Processor Agreement records the privacy and personal information processing terms between Milprops 318 CC, trading as Trac-Mac Online, and the third-party provider or operator named below.
Responsible party / controller: Milprops 318 CC
Trading name: Trac-Mac Online
Address: Raglan St &, Aylesbury Rd, Bellville, Cape Town, 7441
Contact person: Kevin Spratley
Email: vincent@webshopdev.co.za
The operator may process personal information on behalf of the responsible party to provide agreed services, support the website, process customer or business records, maintain systems, provide hosting, provide accounting or operational tools, support WooCommerce workflows, or deliver other agreed business services.
This agreement is intended to support compliance with the Protection of Personal Information Act, 2013 (POPIA) and any other applicable privacy or data protection laws that apply to the parties.
The operator may process personal information only on documented instructions from the responsible party, unless the operator is required by law to process the information. The operator must inform the responsible party where a legal requirement affects the processing, unless prohibited by law.
The personal information processed under this agreement may include names, contact details, account details, billing details, shipping details, order details, payment references, support communications, website usage data, device or online identifiers, business records, and other information reasonably required for the agreed services.
The personal information may relate to customers, website visitors, account holders, employees, contractors, suppliers, leads, support contacts, or other persons whose information is processed through the website or business systems.
Processing may include collecting, receiving, storing, hosting, organising, retrieving, using, transmitting, backing up, securing, deleting, analysing, or otherwise handling personal information as required to provide the agreed services.
The operator must keep personal information confidential and must ensure that persons authorised to process the information are subject to appropriate confidentiality obligations.
The operator must use appropriate technical and organisational safeguards to protect personal information against loss, damage, unauthorised access, unauthorised disclosure, unlawful processing, alteration, or destruction. Safeguards should be appropriate to the nature of the information, the risk involved, and the services provided.
The operator may not appoint another operator, subcontractor, or service provider to process personal information on behalf of the responsible party unless this is permitted by the responsible party or required for the agreed services. Any approved sub-operator must be bound by privacy and security obligations that are no less protective than this agreement.
If personal information is transferred outside South Africa, the operator must ensure that the transfer is lawful and that appropriate safeguards are in place. The operator must provide reasonable information about international processing locations when requested by the responsible party.
The operator must provide reasonable assistance to the responsible party when a data subject requests access, correction, deletion, objection, withdrawal of consent, or another privacy-related action. The operator should not respond directly to a data subject request unless authorised by the responsible party or required by law.
The operator must notify the responsible party without undue delay after becoming aware of any actual or suspected security compromise affecting personal information processed under this agreement. The notice should include reasonable details about the incident, affected information, likely consequences, steps taken, and recommended mitigation where available.
The operator must keep reasonable records of processing activities, safeguards, and security incidents relevant to the services. The operator must provide reasonable information needed by the responsible party to demonstrate compliance, subject to confidentiality, security, and commercial limitations.
When the services end, or when reasonably requested by the responsible party, the operator must delete or return personal information processed on behalf of the responsible party, unless retention is required by law, legitimate business record obligations, backup processes, dispute handling, accounting requirements, or another lawful basis.
Where the operator supports WooCommerce or ecommerce workflows, the operator may process order, customer, payment, shipping, refund, tax, and support information only as required for the agreed services and lawful business operations.
Where accounting or business records are processed through Smart-IT Accounting Software or another provider, the operator must handle those records in line with this agreement, applicable law, and the agreed service terms.
This agreement applies for as long as the operator processes personal information on behalf of the responsible party and continues to apply to retained information after the services end, where applicable.
If this agreement conflicts with a signed service agreement, data processing addendum, or platform terms accepted by the parties, the stricter privacy and security requirement should apply unless the parties agree otherwise in writing.
Log in or create an account to manage orders, addresses, and wishlist items.