De Arend Estate & Event Venue: Privacy Policy & POPIA Compliance
Last Updated: 1 June 2026 Version: 1.0
Introduction
At De Arend Estate & Event Venue, we are committed to protecting your privacy and ensuring that your personal information is collected and used properly, lawfully, and transparently. Data protection is a priority for the management of De Arend, and we take our obligations under South African law seriously.
The use of the De Arend website is possible without any indication of personal data; however, if you wish to make use of specific services ; such as submitting an enquiry, requesting a quotation, or making a booking ; the processing of personal information may become necessary. Where processing is required and no other statutory basis applies, we will obtain your consent.
This Privacy Policy explains how we obtain, use, disclose, and protect your personal information, as required by the Protection of Personal Information Act 4 of 2013 (“POPIA”). It also informs you of the rights you are entitled to exercise.
All references to “we”, “us”, “our”, or “De Arend” within this Policy refer to De Arend Estate & Event Venue, its management, staff, and any authorised processors acting on its behalf.
We reserve the right to modify this Policy at any time. We encourage you to review it periodically to stay informed of any updates.
1. Who We Are
De Arend Estate & Event Venue, is a proudly South African event and wedding venue situated in the Western Cape. We specialise in weddings, corporate events, conferences, festivals, and private functions.
De Arend Estate & Event Venue: Zoute River, Cape Farms, Western Cape, South Africa
Phone: +27 79 416 8362
Email: info@dearend.co.za
Website: www.dearend.co.za
For the purposes of POPIA, De Arend is the Responsible Party in respect of all personal information collected through our website, booking systems, and communications.
2. Application of This Policy
This Privacy Policy applies to all prospective, current, and past De Arend stakeholders, including:
- Visitors to our website at www.dearend.co.za
- Visitors to our physical venue or events
- Prospective and confirmed Clients
- Event guests whose information is provided to us by a Client
- External service providers and suppliers
- Employees and prospective employees
- Any other person who interacts with us digitally or in person
All of the above are collectively referred to as “you” or “Data Subjects” in this Policy.
By submitting your personal information to us, you will be treated as having given your permission ; where necessary and appropriate ; for the uses and disclosures described in this Policy. If you do not agree with these terms, you may choose not to use our website or services where personal information is required.
3. Definitions
The following terms are used throughout this Policy:
- a) Personal Information Any information relating to an identified or identifiable natural person, including a name, identity number, contact details, location, online identifier, or any factor specific to that person’s identity.
- b) Data Subject Any identified or identifiable natural person whose personal information is processed by De Arend as the Responsible Party.
- c) Processing Any operation performed on personal information, whether automated or not ; including collection, recording, storage, updating, retrieval, use, disclosure, deletion, or destruction.
- d) Responsible Party The entity that determines the purpose and means of processing personal information. For this Policy, that is De Arend.
- e) Operator A natural or legal person who processes personal information on behalf of the Responsible Party in terms of a contract or mandate.
- f) Consent A voluntary, specific, and informed expression of agreement by a Data Subject to the processing of their personal information.
- g) Special Personal Information Personal information concerning religious or philosophical beliefs, race or ethnic origin, trade union membership, political opinion, health or sex life, biometric information, or criminal behaviour. We collect this only to the limited extent necessary (such as dietary requirements that may indicate religious observance).
4. Information We Collect
The type of personal information we collect depends on the purpose for which it is collected. We collect only what is necessary, adequate, and relevant for that purpose. This may include:
- a) Identity information: full name, identity number or passport number, and date of birth. For weddings, the names of both parties to be married.
- b) Contact information: email address, telephone number(s), and physical address.
- c) Booking and event information: event date, event type, guest count, catering preferences, dietary and allergen requirements, accommodation requirements, special requests, and service provider details.
- d) Financial information: bank account details for refund purposes, proof of payment, and invoice records. Credit and debit card numbers are not stored on our own systems.
- e) Communications: enquiries, emails, WhatsApp messages, and all correspondence submitted through our website contact form or sent directly to us.
- f) Guest information: where provided by a Client on behalf of their guests: names, dietary requirements, and accommodation preferences.
- g) Service provider information: names, contact details, identity documents, company registration, VAT numbers, and insurance details of external contractors requiring venue access.
- h) Technical and usage data: IP address, browser type and version, operating system, referring website, pages visited, date and time of access, and internet service provider details, collected automatically when you visit our website (see section 8).
- i) Photographic and audiovisual media: photographs and video footage taken at events for marketing purposes, subject to consent (see section 11).
- j) Special personal information: dietary restrictions that may indicate religious beliefs or health conditions (e.g., Halaal, Kosher, allergen requirements), collected solely to facilitate catering services.
5. How We Collect Your Information
We collect personal information through the following means:
- a) Our website: via the contact and enquiry submission form, newsletter sign-up form, and any other digital data collection forms.
- b) Direct communication: when you contact us by email, telephone, or WhatsApp.
- c) Contractual documents: when you sign our Venue Hire Agreement, Booking Confirmation Form, or any other hardcopy agreement.
- d) In-person consultations: during site visits, planning meetings, and on the day of the event, including manual sign-in forms and verbal disclosures.
- e) Third parties: from event coordinators, wedding planners, or agents acting on your behalf. In such cases, the agent or coordinator is responsible for ensuring that you have been informed that your personal information will be shared with us.
- f) Automatically: via cookies and analytics tools when you browse our website (see section 8).
- g) Social media: when you interact with our pages on Instagram, Facebook, or Pinterest.
- h) Publicly available sources: where personal information is lawfully publicly recorded or accessible.
6. Why We Use Your Information
We will only use your personal information for the specific, lawful purpose for which it was collected, or as subsequently agreed with you. Purposes include:
- a) Booking and event management: to process your enquiry, issue a quotation, confirm your booking, manage your event, coordinate with your service providers, and fulfil all obligations under our Venue Hire Agreement.
- b) Identity verification: to confirm and verify your identity for security and contractual purposes.
- c) Communication: to respond to your enquiries and send event-related updates, reminders, and planning correspondence.
- d) Payment and financial administration: to issue invoices, process payments, process refunds, and maintain financial records as required by South African law.
- e) Catering and dietary management: to communicate dietary and allergen requirements to approved caterers and kitchen staff.
- f) Security and access control: to verify the identity of service providers accessing the Venue.
- g) Legal compliance: to comply with applicable legislation including the Companies Act, VAT Act, and POPIA; to enforce our Terms and Conditions; and to respond to lawful requests from regulatory authorities or courts.
- h) Fraud and crime prevention: for the detection and prevention of fraud, criminal activity, or other malpractice.
- i) Marketing and promotions: to send promotional content, venue updates, and special offers, only where you have consented or as otherwise permitted by POPIA (see section 11).
- j) Event photography and testimonials: to publish event photographs and client testimonials on our website and social media platforms, with your consent.
- k) Website optimisation: to analyse website usage, evaluate the effectiveness of our content, and improve your experience on our site.
- l) Competitions and promotions: to offer you the opportunity to participate in competitions or promotional activities.
- m) Dispute resolution and legal proceedings: to manage complaints, disputes, or legal claims relating to a booking or event.
We will never sell, rent, or trade your personal information to third parties for their own marketing purposes. You may opt out of receiving marketing communications from us at any time. Any marketing communication we send will include a clear and easy-to-use opt-out mechanism.
7. Legal Basis for Processing
Under POPIA, we are required to have a lawful basis for processing your personal information. Depending on the activity, our basis is one or more of the following:
- a) Consent: you have given specific, informed consent for a particular purpose, such as marketing communications, event photography, or the processing of special personal information.
- b) Contractual necessity: processing is necessary to conclude or perform our Venue Hire Agreement, or to take pre-contractual steps at your request.
- c) Legal obligation: processing is required to comply with a legal obligation, such as retaining financial records under the VAT Act or responding to a court order.
- d) Legitimate interest: processing is necessary for our legitimate business interests ; such as website analytics, fraud prevention, and security ; provided those interests are not overridden by your rights and freedoms.
Where we rely on your consent, you have the right to withdraw it at any time without affecting the lawfulness of any processing carried out before withdrawal. We do not use automated decision-making or profiling in respect of our clients or website visitors.
8. Cookies and Website Data
Our website uses cookies to enhance your experience and assist us in understanding how the website is used.
What cookies do: Cookies allow our website to recognise returning visitors, remember preferences, and provide a more user-friendly experience. For example, cookies prevent you from having to re-enter certain information each time you visit.
Types of cookies we use:
- Strictly necessary cookies: essential for the website to function. These cannot be disabled.
- Analytics cookies: we use Google Analytics (with IP anonymisation enabled) to collect anonymised, aggregate data about website usage. This does not identify you personally. You may opt out via the Google Analytics Opt-Out browser add-on.
- Preference cookies: remember your settings for return visits.
- Marketing cookies: used only where you have consented, for example for social media retargeting via platforms such as the Meta Pixel.
Server log data: When you access our website, we automatically collect general technical data including browser type and version, operating system, referring website, pages visited, date and time of access, IP address, and internet service provider. This data is used for website administration, security monitoring, and statistical analysis. It is stored separately from all personally identifiable information.
Managing cookies: You may prevent the setting of cookies through your browser settings at any time, or delete existing cookies. Note that disabling certain cookies may affect the functionality of our website. Third-party tools embedded on our site may also set their own cookies; we have no direct control over these, and we encourage you to review the privacy policies of those third parties.
9. Social Media and Third-Party Integrations
Our website may include components and links connected to the following third-party platforms. When you interact with these components or when you are logged into these platforms while visiting our website personal information may be transmitted to them regardless of whether you click on the component:
- Instagram: operated by Meta Platforms, Inc. Privacy policy: instagram.com/about/legal/privacy/
- Facebook: operated by Meta Platforms, Inc. Privacy policy: facebook.com/about/privacy/
- Pinterest: operated by Pinterest, Inc. Privacy policy: about.pinterest.com/privacy-policy
To prevent data transmission to these platforms, log out of your account on the relevant platform before visiting our website. De Arend has no control over the data collected by these third-party platforms and accepts no liability for their data practices. We encourage you to review each platform’s privacy policy directly.
10. Who We Share Your Information With
We share your personal information only where necessary and only with parties who are bound to handle it lawfully and securely. These include:
- a) Approved caterers and kitchen staff: dietary requirements, guest counts, and allergen information, shared solely to facilitate catering services at your event.
- b) De Arend approved service providers: event-relevant contact and scheduling details shared with photographers, florists, DJs, and other suppliers you have authorised, strictly for the purpose of delivering their services.
- c) Website hosting and software providers: our website hosting and platform service providers who process data on our behalf as operators under POPIA, bound by written data processing agreements.
- d) Payment processors and financial institutions: to facilitate secure payment transactions. These parties are subject to their own regulatory and privacy obligations.
- e) Professional advisors: attorneys, accountants, and auditors under confidentiality obligations, where necessary for legal and financial compliance.
- f) Regulatory and law enforcement authorities: SARS, SAPS, the Information Regulator, or any competent court, where required by law or court order.
- g) Business restructuring: in the event of a sale, merger, acquisition, or restructuring of De Arend, personal information may be transferred to relevant third parties. By providing your personal information to us, you consent to such transfer in these circumstances, provided that any recipient agrees to handle your information in accordance with this Policy.
We do not share your personal information with any other party without your prior consent, unless required or permitted by law. When we share information with third parties, we require them to honour this Policy to the full extent required by applicable law.
11. Marketing Communications and Event Photography
Marketing: We will only send you promotional emails, newsletters, or venue updates where you have opted in, or where you are an existing client and we are communicating about similar services to those previously provided. You may opt out at any time by clicking the unsubscribe link in any marketing communication, or by contacting us at info@dearend.co.za. We will action your opt-out request promptly and within no later than 5 business days. Opting out of marketing does not affect our ability to contact you for operational or contractual purposes.
Event photography: De Arend may photograph and video events for marketing and promotional purposes, including use on our website, social media platforms, and marketing materials. We notify Clients of this in our Venue Hire Agreement. If you object, please advise us in writing at least 14 days before your event. We will remove images from active marketing platforms upon a valid and timely request. We cannot guarantee removal from historical press publications or third-party media that has already been distributed.
12. How Long We Keep Your Information
We retain your personal information only for as long as is necessary for the purposes for which it was collected, or as required by law:
- Booking and contract records: 7 years from the date of the event, in accordance with the Prescription Act 68 of 1969 and VAT record-keeping requirements.
- Financial records: 5 years from the end of the relevant financial year, as required by SARS and the Companies Act.
- Enquiries not resulting in a booking: 12 months from the date of the enquiry, after which information is deleted.
- Marketing consent records: until consent is withdrawn. A record of withdrawal is retained indefinitely to demonstrate compliance.
- Event photography: indefinitely where consent has been given for marketing use. Images will be removed from active platforms upon valid withdrawal of consent.
- Website analytics data: anonymised or deleted after 26 months.
When personal information is no longer required, we will securely delete or anonymise it. Where information is deleted from our active systems, residual copies on backup servers may not be immediately removed but will be deleted in accordance with our standard backup retention cycle.
13. Cross-Border Transfers
Some of our service providers and IT platforms may be based outside South Africa. In such cases, your personal information may be transferred to or stored in another country. In accordance with section 72 of POPIA, we will only transfer personal information outside South Africa where the recipient country or recipient provides an adequate level of protection, or where you have consented, or where the transfer is necessary to perform your contract with us. Where we use internationally hosted platforms, we ensure those providers comply with recognised international data protection standards.
14. How We Protect Your Information
We have implemented appropriate technical and organisational security measures to protect your personal information against unauthorised access, loss, destruction, alteration, or disclosure. Our security practices include:
- Physical security over premises and filing systems
- Computer, network, and system security
- Access controls limiting personal information to authorised staff only
- Secure communications via SSL/TLS encrypted connections
- Secure disposal of physical documents by shredding
- Contractual security and privacy obligations imposed on all third-party operators
- Ongoing review and monitoring of security controls
When we contract with third parties, we impose appropriate security, privacy, and confidentiality obligations on them to ensure that personal information we remain responsible for is kept secure.
In the event of a data breach that is likely to result in harm to you, we will notify you and the Information Regulator as required by POPIA within the prescribed timeframes.
15. Your Rights as a Data Subject
As a Data Subject under POPIA, you have the following rights in respect of your personal information held by De Arend, subject to verification of your identity:
- a) Right of access: to request confirmation of whether we hold your personal information and to receive a copy.
- b) Right to rectification: to request that we correct or update inaccurate or incomplete personal information.
- c) Right to erasure: to request deletion of your personal information where it is no longer necessary for the original purpose, subject to our legal retention obligations.
- d) Right to restriction of processing: to request that we limit how we use your personal information in certain circumstances.
- e) Right to object: to object to the processing of your personal information, in particular for direct marketing purposes. Where you object to direct marketing, we will cease such processing immediately.
- f) Right to withdraw consent: to withdraw any consent you have previously given at any time, without affecting the lawfulness of prior processing.
- g) Right to lodge a complaint: to lodge a complaint with the Information Regulator of South Africa if you believe your personal information rights have been infringed.
To exercise any of these rights, please complete the contact form on our website at www.dearend.co.za. We will respond within 30 days of receiving your request.
16. Provision of Personal Information
Where the provision of personal information is required by law (for example, tax regulations) or by contract (for example, to confirm your identity and process your booking), failure to provide the required information may mean that we are unable to conclude or fulfil the contract with you. Where personal information is required for a specific purpose, our staff will clarify whether provision is mandatory or voluntary and what the consequences of non-provision may be.
17. Disclaimer
The information contained on the De Arend website is provided in good faith and for general informational purposes only. While we endeavour to keep the information accurate and current, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, or suitability of any information on the site. Any reliance you place on such information is strictly at your own risk.
De Arend and its management shall not be liable for any direct, indirect, incidental, consequential, or punitive loss or damage arising out of your use of, or inability to use, our website or its content. If you are dissatisfied with any portion of the website or with any of the terms of this Policy, your sole remedy is to discontinue use of the website.
