Tennant Privacy Policy

Website and Business Processing Privacy Policy

Website-facing policy aligned to POPIA and financial services conduct requirements

Original effective date 1 June 2021

Current version V1.2026

Review frequency Annually or as required

Reference framework Protection of Personal Information Act, 4 of 2013 (“POPIA”),

Promotion of Access to Information Act, 2 of 2000

(“PAIA”), and other applicable South African laws regulations and regulatory guidance

Introduction

This website is operated by Tennant Consolidated (Pty) Ltd, registration number 2021/396721/07.

Tennant is committed to protecting your privacy and processing personal information in a lawful, reasonable and transparent manner.

This Privacy Policy explains how Tennant collects, uses, stores, shares, protects and otherwise processes personal information when you visit our website, contact us, request information, apply for or use our products or services, participate in a membership, policy, claim or benefit process, engage with us as a representative of an organisation, or otherwise interact with us.

We process personal information in accordance with POPIA and applicable financial-sector, governance and record-management requirements.

This Privacy Policy operates within Tennant’s broader information governance, information security, incident management, records management and cyber-resilience framework.

2. Who this policy applies to

This Privacy Policy applies to personal information relating to website visitors; current, prospective and former clients; members, policyholders, beneficiaries and dependents, where applicable; representatives of service providers, intermediaries, employers, trustees and other counterparties;

job applicants and employees where relevant to the interaction concerned; and other individuals whose personal information Tennant lawfully processes in the course of its operations.

This Privacy Policy also applies, where relevant, to personal information processed through Tennant’s websites, digital channels, mobile applications, communication platforms, benefit-administration processes, product and service interactions, and related business operations.

3. Tennant entities and the responsible party

This Privacy Policy applies to the Tennant entities listed on our website or otherwise identified in our product, service, membership, claims, benefit, contractual or related documentation.

The Tennant entity that provides the relevant product or service to you, administers your membership, policy, claim or benefit, responds to your enquiry, or otherwise determines the purpose and means of processing your personal information, will usually be the responsible party for that processing.

Unless another Tennant entity is identified in the relevant documentation, the entity operating this website will be the responsible party for personal information collected through this website.

Where two or more Tennant entities jointly determine the purpose and means of processing personal information, they may act as joint responsible parties to the extent permitted by law.

If you would like to know which Tennant entity is the responsible party for your personal information, you may contact our Information Officer using the details below.

Depending on the Tennant entity involved, personal information may be processed for administration, consulting, payroll, health-benefit, legal, claims, underwriting, investment, tax, audit, compliance, employment and related financial-services purposes.

Personal information may be processed by relevant business units and Tennant entities within the Tennant Group in accordance with this Privacy Policy and applicable law. The details of how each division/ company makes use of the data received is outlined below:

Tennant Entity Principal processing purposes

Benefit Administration Membership, contributions, benefits, payments, tax, reporting and regulatory administration

Financial advice and intermediary services Quotations, advice, applications, policies, investments, claims and ongoing servicing

Retirement-fund consulting Fund consulting, governance support, risk benefits, transfers and trustee support

Payroll and HR services Payroll, tax, employee administration and employment-related services

Accounting services Accounting, tax, audit support, statutory reporting and client administration

4. What is personal information?

“Personal information” means information relating to an identifiable, living natural person and, where applicable, an identifiable existing juristic person, as contemplated in POPIA.

Depending on the nature of your relationship with us, this may include:

• name, surname, identity number, passport number or registration number;

• contact details such as your email address, telephone number and physical or postal address;

• demographic information;

• membership, policy, benefit, product and claims information;

• financial, banking and payment information;

• employment and business information;

• verification and compliance information;

• communications, complaints and enquiry records;

• website, device and usage information; and

• any other information you provide to us or that we are permitted or required by law to collect.

Where permitted or required by law, we may also process special personal information, including health information or other sensitive information relevant to benefits, underwriting, claims, employment, legal, regulatory or compliance purposes.

5. How we collect personal information

We may collect personal information in a number of ways, depending on the nature of your interaction with us.

We may collect personal information:

• directly from you, when you contact us, complete website forms, request information, apply for a product or service, submit a claim or benefit enquiry, lodge a complaint, provide documents, or otherwise communicate with us;

• from your authorised representative, employer, broker, intermediary, trustee, guardian or service provider, where they are acting on your behalf or are involved in the relevant product, service, claim, benefit or transaction;

• from product suppliers, insurers, underwriters, administrators, counterparties and other parties involved in providing or administering the relevant service, product, policy, claim, benefit or transaction;

• from publicly available sources and registers, where lawful and reasonably necessary;

• from third parties that assist with identity verification, due diligence, fraud prevention, compliance, sanctions screening, communications, information technology, website hosting, administration or record management; and

• automatically when you use our website, including through cookies, analytics tools, Squarespace Analytics, server logs, device information and similar technologies.

How do we collect your data?

We collect certain information on registration when you complete data fields on one of our group company websites or register on our mobile Tennant App. Upon visiting our website/registering on our App, you are informed of the data which needs to be entered and acknowledge you give us permission to make use of the personal information that you provide us with when you register.

If you are a member on one of the funds which we administer or provide brokerage services to; some of the personal information that you have provided to your employer will be provided to us by your employer. We may also request information directly from you if necessary. We only collect information which is necessary for us to effectively render consulting and administration services.

When you receive a membership certificate; paid-up membership certificate or when you fill in/update a beneficiary nomination form we will request your consent to collect and use the personal information that you provide us with in accordance with applicable law.

Where we collect personal information from a source other than directly from you, we will do so only where such collection is lawful, reasonably necessary for our functions or activities, and consistent with POPIA. The source of the information may include the categories of persons or entities listed above, depending on the circumstances.

6. Categories of personal information we collect

The categories of personal information we collect will depend on the Tennant entity involved, the nature of your relationship with us, and the product, service, membership, claim, benefit, enquiry or transaction concerned.

We do not necessarily collect all categories of information in every case.

• Depending on the circumstances, we may collect and process:

• identification information;

• contact information;

• demographic and biographical information;

• membership, policy, product, claims and benefit information;

• financial and banking information;

• employment and business information;

• compliance and verification information;

• correspondence and call records;

• website, device and communication usage information; and

other information that is necessary for lawful operational, contractual, insurance, benefit-administration, compliance or regulatory purposes.

Depending on the circumstances, this may also include identification and verification information, employment and payroll-related information, pension or retirement-fund information, medical-scheme or health-benefit information, beneficiary information, claims history, compliance-screening information, and other information reasonably necessary for lawful administration, advisory, intermediary, benefit, claims, employment or regulatory purposes.

7. Why we process personal information

We process personal information only where we have a lawful basis to do so, including where processing is necessary:

• to provide or administer products, services, memberships, benefits or claims;

• to communicate with you and respond to enquiries;

• to assess applications, instructions, claims and benefit requests;

• to verify identity and perform due diligence;

• to comply with legal, regulatory, governance and reporting obligations;

• to manage complaints, disputes, incidents and investigations;

• to prevent fraud, misconduct, unauthorised activity and other risk;

• to improve our services, systems, controls and website functionality;

• to manage employment, payroll, administration and internal business operations where applicable; and

• for any other lawful purpose connected to our business activities.

8. Lawful grounds for processing

We may process personal information on one or more of the following lawful grounds:

• with your consent;

• where processing is necessary to conclude or perform a contract;

• where processing is necessary to comply with a legal obligation;

• where processing protects your legitimate interests;

• where processing is necessary for our legitimate interests or those of a third party, as permitted by law; or

• where otherwise permitted or required by law.

9. When providing personal information is mandatory

Providing personal information may be voluntary in some cases and mandatory in others.

We may require personal information to verify your identity; provide a quotation, recommendation, product or service; administer membership, policy, claim or benefit processes; comply with legal, regulatory and reporting obligations; investigate complaints, disputes or incidents; or maintain our relationship with you.

Where we ask for personal information in order to respond to a general website enquiry, your provision of that information is usually voluntary. However, if you do not provide sufficient information, we may be unable to identify you, verify your request, communicate with you, or respond properly to your enquiry.

• In other cases, the provision of personal information may be mandatory because it is required:

• by law or regulatory requirements;

• to verify your identity;

• to assess an application, instruction, complaint, claim, benefit request or transaction;

• to provide a quotation, recommendation, product or service;

• to administer a membership, policy, product, claim or benefit;

• to conduct due diligence, fraud prevention, compliance or risk management checks; or

• to maintain and manage our relationship with you.

If you do not provide personal information that is required by law, contract, regulatory requirements, or operational necessity for the relevant service or function, we may be unable to provide the requested assistance, product, service, policy administration, benefit processing, claims handling, response or other functionality.

10. Laws that may require or authorise collection

Depending on the nature of the relevant product, service, membership, benefit, claim, employment relationship, website interaction or other interaction with us, the collection and processing of personal information may be required or authorised by applicable South African legislation.

• These laws may include, where applicable:

• the Protection of Personal Information Act, 4 of 2013;

• the Promotion of Access to Information Act, 2 of 2000;

• the Financial Advisory and Intermediary Services Act, 37 of 2002;

• the Financial Intelligence Centre Act, 38 of 2001;

• applicable insurance legislation;

• pension-fund legislation;

• tax legislation;

• employment legislation;

• electronic communications and transactions legislation; and

• any other law, regulation, directive, code or regulatory standard applicable to our business activities.

Whether any particular law applies will depend on the nature of your relationship with us and the service, product, transaction, claim, benefit, enquiry or process involved.

11. Disclosure of personal information

We may share personal information where lawful and reasonably necessary with other Tennant entities, product suppliers, insurers, underwriters, administrators, intermediaries, brokers, trustees, employers, service providers, professional advisers, regulators, law-enforcement bodies, courts, auditors and other parties involved in providing, administering, supporting, governing or reviewing the relevant product, service, benefit, claim, membership, employment or business function.

Where we use operators or other third-party service providers to process personal information on our behalf, they are subject to due diligence, contractual security and confidentiality obligations, and ongoing oversight appropriate to the sensitivity of the personal information and the risk of the service.

We require such parties to process personal information only on documented instructions where applicable, to maintain appropriate safeguards, and to notify us of security or privacy incidents affecting the personal information they process for us.

12. Confidentiality

We treat personal information as confidential and will not disclose confidential information except with your consent; where disclosure is required or permitted by law; where disclosure is necessary to provide a product, service, membership, benefit or claim process requested by you; where disclosure is necessary to protect legitimate interests; or where disclosure is necessary for legal, regulatory, compliance or dispute-resolution purposes.

13. Cross-border transfers

We may transfer personal information to service providers, operators, counterparties or other recipients in countries outside South Africa where this is reasonably necessary for our operations, for website hosting or support, cloud storage, communications, technology services, administration, claims or benefit processes, or for providing the products or services requested by you.

Where personal information is transferred outside South Africa, we will do so only where:

• the recipient is subject to a law, binding corporate rules, binding agreement or other obligation that provides an adequate level of protection substantially similar to that provided under POPIA;

• the transfer is necessary for the conclusion or performance of a contract;

• the transfer is for your benefit, and it is not reasonably practicable to obtain your consent, and it is likely that you would have given that consent if asked; or

• you have consented to the transfer.

Cross-border transfers may arise where our service providers, hosting providers, communications providers or technology platforms store or process personal information in other jurisdictions. Where required, we will take reasonable steps to ensure that appropriate contractual or other safeguards are in place.

14. Security safeguards

Tennant takes appropriate, reasonable technical and organisational measures to secure personal information against loss, misuse, unauthorised access, disclosure, alteration or destruction.

Our safeguards form part of a broader control environment that includes information security controls, access management, monitoring, incident detection, response, recovery and periodic review.

Where required by law, Tennant will notify the Information Regulator and affected data subjects of a security compromise involving personal information.

Tennant maintains incident response, breach management, escalation, investigation and corrective-action procedures to support compliance with section 22 of POPIA and other applicable legal, regulatory and governance requirements.

Where a security compromise involves an operator or third-party service provider, Tennant may require information, cooperation, containment and remediation measures appropriate to the incident.

15. Retention of personal information

We retain personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected or processed, or as required or permitted by law, regulation, contract, records-management requirements or legitimate operational need.

Retention periods may differ depending on the Tennant entity involved, the nature of the relationship, and the legal, regulatory, evidential or historical context of the information.

This may include long-term retention of benefit, policy, claim, member, beneficiary and supporting records where required to verify historical entitlements, respond to complaints or regulatory enquiries, manage disputes, or protect the interests of members, beneficiaries and Tennant.

When personal information is no longer required, we will delete, de-identify, anonymise or destroy it in accordance with applicable legal and governance requirements.

16. Your rights

Subject to POPIA and other applicable laws, you have the right to:

• request confirmation that we hold personal information about you;

• request access to your personal information;

• request correction, updating, deletion, destruction or restriction of personal information where appropriate;

• object, on reasonable grounds, to certain processing;

• object to processing for direct marketing at any time;

• withdraw consent where processing is based on consent, subject to the lawfulness of prior processing; and

• lodge a complaint with the Information Regulator.

You may also submit a request for access to records in terms of PAIA, where applicable. To exercise your rights, you may contact our Information Officer using the details below. Where prescribed by law, requests or objections must be submitted on the applicable Information Regulator form.

17. Direct marketing

Where we send direct marketing communications, we will do so in accordance with applicable law.

We will only send direct marketing communications by electronic means where permitted by POPIA. Where required, we will obtain your prior consent. If you are an existing customer, we may send you marketing relating to our own similar products or services, subject to applicable legal requirements and your right to opt out at the time of collection and with every subsequent communication.

You may opt out of receiving direct marketing communications at any time by using the unsubscribe facility in the communication or by contacting us using the details below. You may opt out at any time.

18. Cookies and website usage

Our website uses cookies and similar technologies to ensure the website functions properly, remember your preferences, improve performance and security, and analyse website traffic and usage patterns. We currently use Squarespace Analytics to monitor website traffic and better understand how visitors use the website.

We do not currently use advertising tracking pixels, and the website does not currently provide newsletter subscription functionality.

If you submit an enquiry through the website contact form, the information you provide will be transmitted to us by email for the purpose of responding to your enquiry.

You can control cookies through your browser settings, but disabling certain cookies may affect website functionality. Where required, additional cookie or consent notices may be provided on the website.

19. Third-party websites

Our website may contain links to third-party websites, platforms or services. We are not responsible for the privacy practices, content or security of those third parties, and you should review their privacy notices before providing them with personal information.

20. Children’s personal information

We do not knowingly collect personal information directly from children through our website unless this is lawful and appropriate for the service involved.

Where we process children’s personal information, we will do so only in accordance with POPIA and other applicable legal requirements.

21. Contact details and complaints

If you have questions about this Privacy Policy, wish to exercise any of your rights, or want to raise a concern about how your personal information has been processed, please contact:

Information Officer

Name: Stephen Richard Tennant

Email: Stephen.tennant@tennant.co.za

Telephone: 011-100-8100

Address: Baobab Block, Suite 3, Hurlingham Office Park, 59 Woodlands Drive, Hurlingham Manor, Sandton

Website: www.tennant.co.za

Deputy Information Officer

Name: Shelly Gaillard

Email: Shelley.gaillard@tennant.co.za

Telephone: 011-100-8100

Address: Baobab Block, Suite 3, Hurlingham Office Park, 59 Woodlands Drive, Hurlingham Manor, Sandton

Website: www.tennant.co.za

Information Regulator

General enquiries: enquiries@inforegulator.org.za

POPIA complaints: POPIAComplaints@inforegulator.org.za

PAIA complaints: PAIAComplaints@inforegulator.org.za

Telephone: 010 023 5200

Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191

Website: inforegulator.org.za

Complaints portal: Complaints may also be submitted through the Information Regulator’s eServices portal.

22. Access to records under PAIA

Requests for access to records held by Tennant must be submitted in accordance with PAIA using the prescribed form. Our PAIA Manual is available on request from the Information Officer and, where published, on our website.

23. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, regulation, our operations, services, technology, processing practices or governance requirements.

The latest version will be published on our website and will take effect from the date shown in the document-control section above.

Access to information and personal-information requests

To request access to a record under PAIA, please complete PAIA Form 2.

To object to the processing of your personal information, please complete POPIA Form 1.

To request correction or deletion of personal information, please complete POPIA Form 2.

Please identify the Tennant entity or retirement fund to which your request relates and submit the form using the contact details in the relevant PAIA Manual.