DATA DELETION POLICY

DERYAN SOUTH AFRICA

Last Updated: May 29, 2025

1. INTRODUCTION

Unimark Distributors (Pty) Ltd t/a deryan.co.za ("Deryan") is committed to protecting the privacy and security of personal information of our customers, employees, and other stakeholders. This Data Deletion Policy outlines our approach to the deletion and destruction of personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").
This Data Deletion Policy should be read in conjunction with our Privacy Policy, which provides comprehensive information about how we collect, use, and protect personal information. We recognize that the proper deletion of personal information when it is no longer required is a fundamental aspect of data protection and privacy.

2. PURPOSE

The purpose of this Data Deletion Policy is to:
2.1. Establish clear guidelines for the deletion and destruction of personal information when it is no longer required or when requested by data subjects;
2.2. Ensure compliance with POPIA and other applicable data protection laws;
2.3. Protect the rights of data subjects with respect to their personal information;
2.4. Minimize the risk of unauthorized access to or use of personal information; and
2.5. Promote transparency in our data handling practices.

3. SCOPE

This Data Deletion Policy applies to all personal information processed by Deryan, including but not limited to:
3.1. Customer information (names, email addresses, physical addresses, phone numbers, etc.);
3.2. Employee information;
3.3. Supplier and vendor information;
3.4. Marketing databases;
3.5. Electronic records stored in systems, databases, and email accounts;
3.6. Physical records containing personal information; and
3.7. Backup systems and archives.
This policy applies to all forms of personal information, whether maintained in electronic or physical form, and covers all processing activities conducted by Deryan or by third parties on our behalf.

4. DEFINITIONS

For the purposes of this policy, the following definitions apply:
4.1. "Personal Information" means information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person, as defined in POPIA.
4.2. "Processing" means any operation or activity or any set of operations, whether or not by automatic means, concerning personal information, including the collection, receipt, recording, organization, collation, storage, updating or modification, retrieval, alteration, consultation or use; dissemination by means of transmission, distribution or making available in any other form; or merging, linking, as well as restriction, degradation, erasure or destruction of information.
4.3. "Data Subject" means the person to whom personal information relates.
4.4. "Responsible Party" means a public or private body or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information.
4.5. "Deletion" means the removal of personal information such that it cannot be recovered or reconstructed.
4.6. "Destruction" means the physical or technical process of ensuring that physical or electronic records containing personal information are permanently destroyed and cannot be reconstructed.

5. RETENTION PERIODS

Deryan will retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by law. Specifically:
5.1. Customer information will be retained for the duration of the customer relationship and for a period thereafter as required for legal, tax, audit, and business purposes.
5.2. Personal information collected for marketing purposes will be retained until the data subject opts out or requests deletion.
5.3. Personal information required for tax or accounting purposes will be retained for the period required by applicable tax and financial laws.
5.4. Personal information related to contracts will be retained for the duration of the contract and for a period thereafter as required for legal and business purposes.
5.5. Personal information may be retained for longer periods for historical, statistical, or research purposes, provided appropriate safeguards are implemented to prevent its use for any other purpose.

6. DATA DELETION REQUEST PROCESS

6.1. Submission of Requests
Data subjects may request the deletion of their personal information by sending an email to the designated contact email address provided in Section 11 of this policy. The request should include:
  • Full name of the data subject
  • Contact details
  • Description of the personal information to be deleted
  • Reason for the deletion request (optional)
6.2. Verification of Identity
Upon receipt of a deletion request, Deryan will take reasonable steps to verify the identity of the data subject to ensure that the request is legitimate. This may include requesting additional information or documentation to confirm identity.
6.3. Assessment of Request
Deryan will assess each deletion request to determine:
  • Whether the request relates to personal information that Deryan processes
  • Whether there are any legal or business reasons that require the continued retention of the personal information
  • The appropriate method for deletion or destruction
6.4. Response to Request
Deryan will respond to deletion requests within a reasonable timeframe, acknowledging receipt of the request and providing information about the steps that will be taken. If Deryan is unable to comply with the deletion request, we will provide reasons for this decision.
6.5. Implementation of Deletion
If the deletion request is approved, Deryan will:
  • Delete the relevant personal information from all systems, databases, and backups
  • Ensure that any physical records containing the personal information are securely destroyed
  • Instruct any third-party processors to delete the relevant personal information
  • Document the deletion process and outcome
6.6. Confirmation of Deletion
Once the deletion process is complete, Deryan will provide confirmation to the data subject that their personal information has been deleted or, if applicable, explain why certain information could not be deleted.

7. GROUNDS FOR REFUSING DELETION REQUESTS

Deryan may refuse to delete personal information in the following circumstances:
7.1. When retention of the personal information is required or authorized by law;
7.2. When the personal information is reasonably required for lawful purposes related to Deryan's functions or activities;
7.3. When retention of the personal information is required by a contract between Deryan and the data subject;
7.4. When deletion would prejudice lawful purposes for which the personal information was collected;
7.5. When deletion would prejudice the legitimate interests of Deryan, the data subject, or a third party; or
7.6. When retention is necessary for the establishment, exercise, or defense of legal claims.
In such cases, Deryan will inform the data subject of the reasons for refusing the deletion request and, where appropriate, restrict the processing of the personal information as provided for in Section 14(6) of POPIA.

8. METHODS OF DELETION AND DESTRUCTION

8.1. Electronic Records
Electronic records containing personal information will be deleted using appropriate technical methods that prevent reconstruction, such as:
  • Secure deletion software that overwrites data multiple times
  • Encryption and destruction of encryption keys
  • Physical destruction of storage media when appropriate
8.2. Physical Records
Physical records containing personal information will be destroyed using methods such as:
  • Cross-cut shredding
  • Pulping
  • Burning
  • Pulverizing
8.3. Third-Party Systems
Where personal information is stored in third-party systems, Deryan will:
  • Maintain records of which third parties process personal information on our behalf
  • Include appropriate data deletion requirements in contracts with third parties
  • Verify that third parties have deleted personal information when requested

9. DOCUMENTATION OF DELETION

Deryan will maintain records of deletion activities, including:
9.1. The categories of personal information deleted;
9.2. The date and method of deletion;
9.3. The reason for deletion (e.g., end of retention period, data subject request);
9.4. Confirmation that the deletion has been completed; and
9.5. Any exceptions or limitations to the deletion.
These records will not include the actual personal information that has been deleted.

10. STAFF TRAINING AND RESPONSIBILITIES

10.1. All staff who handle personal information will receive training on this Data Deletion Policy and their responsibilities regarding the deletion of personal information.
10.2. The Information Officer is responsible for overseeing compliance with this policy and for ensuring that appropriate procedures and safeguards are in place.
10.3. Department managers are responsible for ensuring that personal information within their departments is deleted in accordance with this policy.
10.4. IT staff are responsible for implementing and maintaining technical measures for the secure deletion of electronic personal information.

11. CONTACT INFORMATION

For any questions about this Data Deletion Policy or to submit a deletion request, please contact us at:
Email: [INSERT CONTACT EMAIL]

12. POLICY REVIEW

This Data Deletion Policy will be reviewed annually, or more frequently if required, to ensure it remains current with applicable laws, technology, and organizational requirements.

13. RELATIONSHIP WITH OTHER POLICIES

This Data Deletion Policy forms part of Deryan's overall data protection framework and should be read in conjunction with other relevant policies, including:
13.1. Privacy Policy
13.2. Information Security Policy
13.3. Data Breach Response Policy

14. COMPLIANCE WITH INFORMATION REGULATOR

Deryan acknowledges that data subjects have the right to submit complaints to the Information Regulator if they believe that their requests for deletion have not been properly addressed. The contact details of the Information Regulator are available at: http://justice.gov.za/inforeg/

Note: This Data Deletion Policy is effective from the date of publication and supersedes any previous policies regarding the deletion of personal information.