Skip to content

Country

Privacy policy

Privacy Policy (POPIA)

Last updated: 24 July 2026

This Privacy Policy explains how MNE Waste Management (PTY) LTD, trading as MNE Waste Management (“MNE”, “we”, “us” or “our”), collects, uses, stores, shares and protects personal information. It is intended to support transparency under the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other requirements that apply to a particular processing activity.

This policy does not state that MNE has been certified, accredited or approved by the Information Regulator. It is a public description of our intended personal-information practices.

1. Responsible party and contact details

For personal information where MNE determines why and how it is processed, MNE generally acts as the responsible party.

MNE Waste Management (PTY) LTD
17 Muswell Road South
Wedgefield Office Park, Block A
Johannesburg, 2021
South Africa
Privacy enquiries: jeff@mnewaste.com
Telephone: +27 (11) 540 0117
Website: mnewaste.com

2. Who this policy applies to

This policy applies to visitors to our website, customers, prospective customers, account users, representatives of clinics and other organisations, suppliers, service providers, people who request quotations or guidance, and people who communicate with MNE.

Where you provide information about another person, you should have authority to do so and should make this policy available to that person where appropriate.

3. Personal information we may collect

Depending on the interaction, MNE may collect:

  • identity and contact details, such as a name, job title, telephone number, email address and communication preferences;
  • business, practice, facility and account details, including registration information and the authorised representatives of an organisation;
  • delivery, collection and service-location information, including a South African address, access instructions and contact persons;
  • order, quotation, invoice, payment-status, product, service, collection and support records;
  • waste-stream, container, collection-cadence, site-readiness and supporting-document information needed to assess or deliver a requested service;
  • communications with MNE, including email, telephone, website-form, chat and customer-support records;
  • marketing choices, consent records and opt-out requests;
  • website and device information, such as an IP address, browser type, device type, cookie identifiers, pages viewed and approximate interaction data; and
  • fraud-prevention, security, audit and transaction records.

MNE does not require patient clinical records for ordinary online orders, quotations or collection setup. Please do not submit patient names, identity numbers, medical records or other patient-level clinical information through ordinary storefront, email or chat channels. If unusual information is genuinely required for a specific lawful process, MNE should provide an appropriate authorised route and explain the purpose.

4. How we collect personal information

We may collect information directly from you; from an organisation you represent; through orders, forms, account activity and communications; from Shopify and other service platforms used to operate the store; from payment, delivery, collection and support providers; from publicly available business sources; and from cookies or similar technologies, subject to applicable choices.

5. Why we process personal information

We may process personal information to:

  • respond to enquiries, requests for guidance and quotation requests;
  • create and administer accounts and verify authorised representatives;
  • process orders, payments, deliveries, returns and refunds;
  • review site, waste-stream, service and supporting-document information;
  • schedule collections, send service notifications and maintain service cadence;
  • provide customer support and resolve complaints;
  • issue invoices, service records, Safe Disposal Certificates or related documents where applicable to the service;
  • maintain operational, audit, security, fraud-prevention and business records;
  • improve our website, products, services and communications;
  • send direct marketing where permitted and record consent or opt-out choices;
  • establish, exercise or defend legal rights; and
  • meet obligations or respond to lawful requests that apply to MNE.

6. Grounds for processing

Depending on the activity, processing may be based on consent; steps requested before entering into a contract; performance of a contract; an obligation imposed by law; protection of a legitimate interest of the data subject; or pursuit of a legitimate interest of MNE or a third party where permitted. MNE should process only information that is reasonably adequate, relevant and not excessive for the stated purpose.

Where processing depends on consent, consent may be withdrawn. Withdrawal does not automatically affect processing that was lawful before withdrawal or information MNE must retain on another lawful ground.

7. Special personal information and children

MNE does not intentionally collect special personal information or information about children through ordinary storefront transactions unless there is a specific lawful need and an appropriate processing basis. If such information is submitted without a valid purpose, MNE may restrict, delete or return it where appropriate.

8. Sharing and operators

MNE may share relevant personal information with operators and other recipients where reasonably necessary for the purposes described above. These may include:

  • Shopify and providers that host or support the online store;
  • payment gateways, banks and fraud-prevention providers;
  • Compass and its operational network where involved in delivery, fulfilment, waste collection, routing, service updates, or related records;
  • email, messaging, customer-support, analytics, document, security and IT providers;
  • accounting, insurance, audit, legal and other professional advisers;
  • suppliers where product sourcing or fulfilment requires it;
  • an acquiring, merged or reorganised business, subject to appropriate safeguards; and
  • regulators, law-enforcement bodies, courts or other parties where disclosure is authorised or required.

Operators process information on MNE's behalf. MNE should use appropriate contractual and security measures for operators according to the risk and the service involved. Some recipients, such as payment providers, service partners, or regulators, may act as responsible parties for their own processing.

MNE does not sell personal information as a standalone product.

9. Cross-border processing

Some technology, cloud, communications, payment or support providers may process information outside South Africa. Where section 72 of POPIA applies, MNE should use an available transfer basis and appropriate safeguards, which may include an adequate legal framework, binding contractual protections, consent where permitted, or a transfer necessary for a contract or the data subject's benefit.

10. Cookies and analytics

The website may use essential cookies for security, navigation, account and cart functions, and may use analytics, preference or marketing technologies subject to the available consent controls and applicable requirements. Browser settings can block or delete cookies, but essential website functions may then not work correctly.

11. Direct marketing

MNE may send direct marketing by electronic communication where the recipient has consented or where another basis permitted by POPIA applies, including the limited existing-customer context. Marketing messages should identify MNE and provide a reasonable way to opt out. A person may withdraw marketing consent or opt out at any time using the message instructions or by contacting MNE. Service, safety, account and transaction communications are not treated as marketing merely because they are sent electronically.

12. Retention and deletion

MNE retains personal information only for as long as reasonably needed for the purpose for which it was collected, a related compatible purpose, an agreed service or contract, dispute resolution, audit and security needs, or an applicable legal or regulatory requirement. Retention periods can differ by record type. When information is no longer authorised or required, MNE should delete, destroy or de-identify it in a reasonably practicable manner, subject to lawful exceptions.

13. Security safeguards

MNE aims to use reasonable and appropriate technical and organisational measures for the nature of the information and the foreseeable risks. Measures may include access controls, role restrictions, authentication, secure service providers, backups, monitoring, staff controls and incident response. No internet transmission or storage system can be guaranteed to be completely secure.

14. Security compromises

If MNE has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, MNE will assess the incident and follow the notification process required by section 22 of POPIA where applicable. This can include notifying the Information Regulator and affected data subjects as soon as reasonably possible, subject to any lawful delay or direction.

15. Your POPIA rights

Subject to POPIA and other applicable law, a data subject may:

  • ask whether MNE holds personal information about them and request access;
  • request correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading or unlawfully obtained information;
  • request destruction or deletion of a record MNE is no longer authorised to retain;
  • object to processing on reasonable grounds where the law allows;
  • withdraw consent where consent is the processing basis;
  • object to or opt out of direct marketing;
  • ask for information about the identity of third parties that have had access where applicable; and
  • lodge a complaint with the Information Regulator.

MNE may need to verify identity and authority before acting on a request. A request may be limited or refused where POPIA or another law permits or requires that result. Prescribed POPIA forms may be used where applicable.

16. How to make a privacy request

Send the request to jeff@mnewaste.com with enough information to identify the relevant records and the right being exercised. Do not send passwords, full payment-card details or unnecessary patient information. MNE will aim to acknowledge and handle the request within a reasonable period, taking account of its nature, identity verification and applicable requirements.

17. Complaints and the Information Regulator

You may raise a privacy concern with MNE using the contact details above. You may also lodge a POPIA complaint with the Information Regulator (South Africa).

Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
PO Box 31533, Braamfontein, Johannesburg, 2017
Telephone: 010 023 5200
Email: enquiries@inforegulator.org.za
eServices: https://eservices.inforegulator.org.za/
POPIA information: https://inforegulator.org.za/popia/

18. Changes to this policy

MNE may update this policy when its services, providers, processing activities or applicable requirements change. The current version and last-updated date will be published through the Shopify policy page.

19. Official POPIA source

The Protection of Personal Information Act 4 of 2013 is available from the South African Government at https://www.gov.za/documents/protection-personal-information-act.

Compare products

{"one"=>"Select 2 or 3 items to compare", "other"=>"{{ count }} of 3 items selected"}

Select first item to compare

Select second item to compare

Select third item to compare

Compare