
Privacy Policy & POPIA Notice
Protection of Personal Information Act (Act No. 4 of 2013) • Promotion of Access to Information Act (Act No. 2 of 2000) • Electronic Communications and Transactions Act (Act No. 25 of 2002)
Statutory Responsible Party Particulars (Section 18 POPIA)
Official registered identity & communication channels under POPIA Act 4 of 2013
Organization & General Inquiries
Verified Contact Channels
Document Sections & Statutory Table of Contents
01.Legislative Framework & Definitions
This Privacy Policy and Compliance Manual constitutes the statutory disclosure of Kampvuur Safaris (Pty) Ltd (“Kampvuur Safaris”, “the Responsible Party”, “we”, “us”, or “our”) pursuant to the provisions of:
- Section 14 of the Constitution of the Republic of South Africa, 1996 (the fundamental constitutional right to privacy);
- The Protection of Personal Information Act No. 4 of 2013 (“POPIA”);
- The Promotion of Access to Information Act No. 2 of 2000 (“PAIA”);
- The Electronic Communications and Transactions Act No. 25 of 2002 (“ECTA”);
- The Consumer Protection Act No. 68 of 2008 (“CPA”); and
- The National Environmental Management: Biodiversity Act 10 of 2004 (NEMBA) and relevant Provincial Conservation Ordinances governing professional hunting permits and guest registers.
“Data Subject” means the natural or juristic person to whom personal information relates, including safari guests, hunting clients, gear store purchasers, and bespoke itinerary planners.
“Personal Information” means information relating to an identifiable living person as defined in Section 1 of POPIA, including identity/passport numbers, emergency contacts, physical delivery addresses, dietary needs, and medical fitness notes.
“Special Personal Information” includes health/fitness data and dietary allergies required strictly for field safety in dangerous game territory, as contemplated in Sections 26 to 32 of POPIA.
“Processing” means any operation concerning personal data, including collection, recording, storage, updating, verification, transmission, and statutory record archival.
“Operator” means an authorized third party who processes information on our mandate, such as authorized payment gateways, courier delivery logistics, charter flight coordinators, and cloud hosting providers.
02.Lawful Grounds & Justification for Processing
In terms of Section 11(1) of POPIA, Kampvuur Safaris strictly processes personal information only where one or more of the following lawful grounds apply:
- Performance of a Contract (Section 11(1)(b)): Processing is necessary to organize and conduct your private safari expeditions, reserve luxury concession lodge suites, issue outfitter gear store shipments, and fulfill hunting contracts.
- Statutory & Regulatory Obligations (Section 11(1)(c)): Processing is mandatory to comply with South African law, including provincial nature conservation guest register mandates, the Tax Administration Act No. 28 of 2011 (maintaining commercial invoices for five years), and firearm licensing transport regulations.
- Vital & Legitimate Interests of the Traveler (Section 11(1)(d)): Processing medical fitness notes, emergency contact coordinates, and blood-group/allergy data to safeguard guest life and wellbeing in remote wilderness environments and dangerous game territory.
- Legitimate Operational Interests (Section 11(1)(f)): Processing is required to secure our digital platform, process fraud-screened payments, maintain outfitter inventory, and coordinate airport and airstrip transfers.
- Voluntary & Explicit Consent (Section 11(1)(a)): Where explicit consent is provided to receive custom safari proposals, subscribe to wilderness field journals, or request bespoke expedition itineraries.
03.Categories of Personal Information Collected
In compliance with the Principle of Minimality (Section 10 of POPIA), we collect only the personal information strictly necessary for safari operations, conservation compliance, and outfitter store orders:
A. Traveler Identification & Concession Manifests
Full legal names, nationality, passport or South African ID numbers (required for private game reserve entry permits), email address, WhatsApp/mobile telephone numbers, and physical country of residence.
B. Field Dossier, Dietary & Medical Safety Notes
Dietary allergies, medical conditions relevant to bush walks, emergency contact names and phone numbers, and rooming preferences captured in your confidential Traveler Dossier.
C. Outfitter Store Shipping & Courier Details
Recipient name, physical delivery street address, postal code, city, country, and contact details for nationwide and international express courier dispatch of outfitter gear and bush apparel.
D. Financial & Transactional Data
Payment gateway transaction reference numbers, order IDs, booking references, and settlement timestamps. We never capture, store, or process raw credit card numbers or banking PINs on our servers.
E. Technical & Telemetric Data
IP addresses, browser telemetry, device information, and anti-spam verification tokens collected via Google reCAPTCHA v3 to defend our booking systems against automated bots.
04.Compliance with the 8 Conditions for Lawful Processing
Our operations embed the eight statutory conditions of Chapter 3 of POPIA:
1. Accountability (Section 8): Kampvuur Safaris ensures all statutory measures under POPIA are actively implemented, audited, and maintained by our Information Officer.
2. Processing Limitation (Sections 9–12): Information is processed lawfully, minimally, and transparently, collected directly from the client wherever practicable.
3. Purpose Specification (Sections 13–14): Personal information is collected for explicit, defined purposes relating to luxury safari expeditions and gear orders.
4. Further Processing Limitation (Section 15): Any subsequent processing must be compatible with the initial purpose for which the information was gathered.
5. Information Quality (Section 16): We take reasonably practicable steps to ensure that personal records are accurate, complete, and kept current.
6. Openness (Sections 17–18): Full transparency through direct statutory Section 18 disclosures at the time of inquiry, booking, and checkout.
7. Security Safeguards (Sections 19–22): Modern technical, administrative, and cloud safeguards protecting traveler data from unauthorized loss, breach, or damage.
8. Data Subject Participation (Sections 23–25): Guaranteed statutory rights for travelers to access, review, correct, or request deletion of their personal records.
05.Traveler Dossiers, Hunting Permits & Health Records
Operating in remote African wilderness concessions with dangerous big game requires heightened safety and confidentiality standards:
- Confidential Traveler Dossier: Medical fitness disclosures, emergency contacts, and dietary preferences collected in the Traveler Portal are accessed strictly by our licensed Lead Outfitter & Professional Hunter (PH) and operational camp managers for safety. They are never shared with commercial marketing third parties.
- Provincial Hunting & Firearms Compliance: Where clients participate in hunting safaris, passport and firearm information is processed strictly to obtain mandatory provincial hunting permits, CITES documentation, and SAPS temporary import/export permits.
- Pastoral & Fireside Discretion: Personal conversations, family travel circumstances, and campfire discussions are held in the highest standard of personal and professional confidence.
06.Financial Transactions & Secure Payment Gateway Integrity
Every transaction across our website is governed by strict financial encryption standards:
- Server-Side Price Calculation: All transaction totals are calculated dynamically on the server from verified database prices with zero client-side manipulation.
- PCI-DSS Level 1 Encrypted Settlement: Online card payments, Instant EFT, and SnapScan transactions are processed through authorized payment gateway infrastructure on 256-bit SSL encrypted banking rails.
- Direct Bank Transfers (Bank Zero Mutual Bank EFT): For clients paying via direct bank wire, proof of payment receipts are processed directly by our finance desk into Bank Zero Mutual Bank (Branch 888000, Account 80204889621).
- Zero Local Storage of Card Details: Kampvuur Safaris never stores credit card numbers, CVV codes, or banking passwords on its servers.
07.Authorized Operators & Cloud Infrastructure (Section 72)
We do not sell, rent, or trade client information. Personal data is disclosed to authorized Operators solely to execute safari and outfitter services:
- Cloud Database (Supabase PostgreSQL): Encrypted database tables with Row Level Security (RLS) guaranteeing strict multi-tenant isolation.
- Web Platform Hosting (Google Firebase / GCP): Web application delivery under Section 72(1)(a) of POPIA governed by binding enterprise data protection standards.
- Authorized Payment Gateway Operators: Transaction settlement and instant payment clearing under PCI-DSS Level 1 compliance.
- Insured Express Courier & Logistics Partners: Delivery addresses and contact phone numbers provided to vetted domestic and international express couriers solely to fulfill local and worldwide merchandise deliveries.
- Authenticated Mail Servers (Truehost Cloud): Transactional vouchers and dispatch notifications dispatched through authenticated SSL SMTP servers (`mail.kampvuursafaris.co.za`).
08.Security Safeguards & Breach Protocol (Sections 19–22)
We implement comprehensive technical, administrative, and operational safeguards to defend traveler records against unauthorized loss, breach, or damage:
TLS 1.3 encryption in transit (HTTPS), AES-256 database encryption at rest, secure password hashing, bot protection, and least-privilege administrative access.
Restricted access to traveler dossiers, multi-factor authentication (MFA/TOTP) on administrative dashboards, authenticated SMTP delivery, and regular security audits.
Section 22 Breach Protocol: In the unlikely event of a suspected or confirmed security compromise, Kampvuur Safaris will notify the South African Information Regulator and affected travelers as soon as reasonably possible in writing.
09.Retention & Destruction of Records (Section 14)
Personal data is retained only as long as necessary to fulfill statutory, conservation, or contractual requirements:
- Financial & Invoicing Records: Retained for a mandatory statutory period of five (5) years under the Tax Administration Act No. 28 of 2011 and Companies Act 71 of 2008.
- Provincial Hunting Registers: Retained in accordance with Nature Conservation Ordinance requirements.
- Outfitter Store Order Records: Archived after delivery completion, retaining only the order reference for warranty and return tracking.
- Destruction Protocol: Expired digital records are purged using cryptographic deletion routines.
10.Data Subject Rights & Information Officer Contact
Under Sections 23, 24, and 25 of POPIA and the provisions of PAIA, you have the following enforceable statutory rights:
- Right of Access: Request confirmation whether we hold your personal information and obtain a formal copy.
- Right to Rectification: Request correction or updating of inaccurate, outdated, or incomplete records.
- Right to Erasure / Deletion: Request destruction or deletion of personal information where retention is no longer authorized.
- Right to Object: Object on reasonable grounds to the processing of your personal information (Form 1 of the POPIA Regulations).
- Right to Withdraw Consent: Withdraw consent for non-essential communications at any time.
Designated Information Officer Contact Details
All requests for access (PAIA Form 02), correction, or objection must be directed in writing to our designated Information Officer:
11.Direct Marketing, Cookies & reCAPTCHA v3
Electronic Direct Marketing (Section 69 POPIA): We strictly adhere to Section 69 of POPIA. We only send safari announcements or new outfitter gear release notifications where you have given explicit opt-in consent or where you are an existing customer who booked or ordered with us previously. Every newsletter contains an immediate 1-click unsubscribe link.
Essential Cookies & Local Storage: Our website uses minimal, strictly essential tokens:
- Shopping Cart Persistence (Zustand): Preserves your selected outfitter gear in your expedition pack across page navigation.
- Session Navigation State: Preserves your traveler account authentication session.
- Google reCAPTCHA v3: Evaluates risk scores to defend against malicious spam and automated bot submissions on our inquiry and booking forms.
12.Lodging a Complaint with the Information Regulator
While we encourage travelers and clients to resolve any concerns directly with our Information Officer, you have the statutory right under Section 74 of POPIA to lodge a formal complaint with the South African Information Regulator:
The Information Regulator (South Africa)
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
General Inquiries: [email protected]
POPIA Complaints: [email protected]
PAIA Complaints: [email protected]
Official Website: https://inforegulator.org.za/
© 2026 Kampvuur Safaris (Pty) Ltd. All statutory rights reserved.