OR Tambo International Airport
Air-O-Airport Parking β€” OR Tambo International Airport Valet Parking & Fleet Dispatch
Your Privacy & Data Protection ✨
STATUTORY SOUTH AFRICAN LEGAL COMPLIANCE

Privacy Policy & POPIA Notice

Protection of Personal Information Act (Act No. 4 of 2013) • Promotion of Access to Information Act (Act No. 2 of 2000)

Effective Date: 14 December 2021 • Last Revised & Published: 12 September 2026 • Version 3.2

Zero data selling β€’ POPIA Act 4 of 2013 & SARS aligned πŸ”’
Β§

Statutory Responsible Party Particulars (Section 18 POPIA)

Registered corporate identity & facility particulars under the Companies Act 71 of 2008 & POPIA

CIPC REG: 2021/128342/07

Corporate Registration & Postal

Legal Entity AIR-O-AIRPORT PARKING (PTY) LTD
CIPC Registration & Incorporation 2021/128342/07 • Incorporated 14 December 2021
Official Postal Address PO Box 3327, Jeppestown, Gauteng, 2043
Tax / VAT Status Non-VAT Vendor (Section 23)

Operations, Security Yard & Dispatch

Curbside Operational Base
OR Tambo Int. Airport, Parkade 2 South Level 3 Block H
Security Yard & Holding Compound
459 Shamrock Road, Bredell, Kempton Park, 1619
Official Inquiries Email [email protected]
24/7 Dispatch Hotlines

01. Legislative Framework & Definitions

This Privacy Policy and Compliance Manual constitutes the statutory disclosure of AIR-O-AIRPORT PARKING (PTY) LTD ("Airoparking", "the Responsible Party", "we", "us", or "our") pursuant to the provisions of:

  • Section 14 of the Constitution of the Republic of South Africa, 1996 (the fundamental constitutional right to privacy);
  • The Protection of Personal Information Act No. 4 of 2013 ("POPIA");
  • The Promotion of Access to Information Act No. 2 of 2000 ("PAIA");
  • The Electronic Communications and Transactions Act No. 25 of 2002 ("ECTA");
  • The Cybercrimes Act No. 19 of 2020; and
  • The National Credit Act No. 34 of 2005 ("NCA") (governing credit reporting for corporate facilities).

"Data Subject" means the person or juristic entity to whom personal information relates, including private travelers, corporate flight coordinators, and fleet managers.

"Personal Information" means information relating to an identifiable, living natural person or existing juristic person as defined in Section 1 of POPIA.

"Processing" means any operation or activity concerning personal information, including collection, receipt, recording, organization, storage, updating, retrieval, alteration, dissemination, and destruction.

"Operator" means a person or entity who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party.

02. Lawful Grounds & Justification for Processing

In terms of Section 11(1) of POPIA, we strictly process personal information only where one or more of the following lawful grounds apply:

  • Performance of a Contract (Section 11(1)(b)): Processing is necessary for concluding or executing the vehicle bailment, valet parking custody, corporate fleet dispatch, or long-term vehicle storage agreement.
  • Statutory & Legal Obligation (Section 11(1)(c)): Processing is mandatory to comply with obligations imposed by South African law, including the Tax Administration Act No. 28 of 2011 (issuing commercial invoices and maintaining accounting records for five years), the Companies Act 71 of 2008, and the Financial Intelligence Centre Act 38 of 2001 ("FICA").
  • Legitimate Interests of the Data Subject (Section 11(1)(d)): Processing protects the traveler’s interests, such as real-time flight telemetry monitoring to ensure vehicle staging punctuality and prevent airport stranding.
  • Legitimate Interests of the Responsible Party (Section 11(1)(f)): Processing is necessary to protect physical compound perimeter security, prevent vehicle theft, investigate transit insurance claims, and manage corporate credit risk.
  • Voluntary Consent (Section 11(1)(a)): Where explicit consent is required, such as opt-in promotional communications, client surveys, or credit bureau vetting.

03. Categories of Personal Information Collected

In compliance with the Principle of Minimality (Section 10 of POPIA), we collect only the personal information strictly required to deliver safe, professional airport valet parking and vehicle custody:

A. Customer Identification & Contact Data

Full names, physical business/residential address, telephone number, mobile number, WhatsApp handle, email address, and company representation particulars.

B. Vehicle Custody & Physical Assets

Vehicle registration number (license plate), vehicle make, model, color, vehicle identification number (VIN), odometer readings at drop-off and return, fuel level, vehicle condition inspection photographs (360-degree digital pre-check), and parking bay allocations.

C. Aeronautical Flight Telemetry

Inbound and outbound flight numbers, airline identifiers, and scheduled landing times. This information is matched via automated aviation radar feeds strictly to time vehicle wash, staging, and driver dispatch at Parkade 2 South Level 3 Block H.

D. Financial & Transactional Data

Payment transaction confirmation tokens, PayFast reference numbers, customer account statement aging schedules, and Section 23 Non-VAT commercial invoices. We never store raw credit card numbers, debit card numbers, or CVV security codes on our infrastructure.

E. Security Surveillance & Biometric Imagery

24-hour high-definition CCTV security footage captured at our private holding compound in Bredell and at airport meet-and-greet blocks, as well as digital handwritten signatures captured on check-in/check-out operational manifests.

04. Compliance with the 8 Conditions for Lawful Processing

Our governance framework embeds the eight statutory conditions of Chapter 3 of POPIA:

1. Accountability (Section 8): The Responsible Party ensures all measures giving effect to the conditions of POPIA are implemented and audited.

2. Processing Limitation (Sections 9–12): Information is processed lawfully, in a reasonable manner that does not infringe on data subject privacy, and directly from the data subject wherever practicable.

3. Purpose Specification (Sections 13–14): Personal information is collected for explicit, defined, and lawful commercial purposes related to vehicle bailment and logistics.

4. Further Processing Limitation (Section 15): Further processing of personal information must be compatible with the initial collection purpose.

5. Information Quality (Section 16): We take reasonably practicable steps to ensure that personal records are complete, accurate, not misleading, and updated where necessary.

6. Openness (Sections 17–18): Transparent documentation of processing operations and direct Section 18 statutory notifications provided to all clients prior to vehicle handover.

7. Security Safeguards (Sections 19–22): State-of-the-art physical, operational, and digital safeguards protecting personal data against loss, damage, or unauthorized access.

8. Data Subject Participation (Sections 23–25): Full accessibility for data subjects to confirm, access, correct, or request deletion of their personal records.

05. CCTV, Telemetry & Digital Custody Pre-Check

Due to the nature of motor vehicle bailment and custody:

  • Compound CCTV Surveillance: Our 12,000 mΒ² off-airport compound in Bredell is under 24/7 high-definition CCTV video surveillance with infrared night recording. Footage is recorded solely for premises security, theft deterrence, and vehicle damage adjudication. Footage is overwritten on an automated 30-to-90 day loop unless flagged for formal police or insurance investigation.
  • Digital Pre-Check Inspection: At Parkade 2 South Level 3 Block H, our staff photograph vehicle body panels, record odometer readings, and document pre-existing defects. This imagery is uploaded to encrypted cloud storage to establish indisputable vehicle custody baselines protecting both customer and operator.
  • Driver PrDP Tracking: Vehicles in transit between the airport and the compound are driven exclusively by vetted drivers holding valid South African Professional Driving Permits (PrDP), tracked via real-time telemetry.

06. Corporate Termed Facilities & Credit Bureau Consent

For corporate fleet and corporate account applicants applying for deferred settlement terms (30/60/90 days):

FICA & KYB Verification: In accordance with statutory KYB requirements, applicants submit corporate registration documents (Cor14.3/CK), utility bills, bank verification letters, and director identification documents. These documents are stored under role-based administrative access controls.

Credit Bureau Transmissions (NCA Section 70 & POPIA Section 18): The applicant director or authorized officer expressly consents that Airoparking may transmit company payment performance records and director warranties to registered South African credit bureaus (including TransUnion, Experian, and XDS) to conduct risk assessments, verify trade references, and trace defaulting debtor accounts.

07. Operators & Cross-Border Data Transfers (Section 72)

We do not sell, rent, or trade client databases under any circumstances. We disclose personal information to authorized third-party Operators solely to fulfill our contractual services:

  • Cloud Infrastructure (Google Firebase / GCP): Web application, Firestore databases, and secure image storage are hosted on Google Cloud Platform infrastructure. In terms of Section 72(1)(a) of POPIA, transfers to these cloud regions are governed by binding data processing agreements providing equivalent or superior data protection standards.
  • Payment Gateways (PayFast by Network): Online payments are processed through PayFast (PASA and PCI-DSS Level 1 certified). Payment processing is subject to PayFast's regulated privacy covenants.
  • Accounting Software (Intuit QuickBooks Online): Invoicing and debtor statement generation synced through encrypted enterprise accounting APIs.
  • Aviation Telemetry APIs: Flight numbers transmitted anonymously to flight radar services to obtain aircraft arrival time estimates.

08. Security Safeguards & Breach Protocol (Section 19–22)

We implement comprehensive technical and organizational safeguards:

Digital Safeguards

TLS 1.3 encryption for all data in transit (HTTPS), AES-256 encryption for data at rest, salted password hashing, Google Cloud App Check bot defense, and least-privilege role-based access.

Physical Safeguards

24/7 fortified compound perimeter with electrified fencing, biometric and PIN staff access controls, armed response patrol links, and locked key safe management.

Section 22 Breach Notification Protocol: In the event of a confirmed or reasonably suspected security compromise involving personal data, we will notify the South African Information Regulator and affected data subjects as soon as reasonably possible, specifying the nature of the breach, suspected consequences, and remediation measures taken.

09. Retention & Destruction of Records (Section 14)

Personal information is retained only for as long as necessary to achieve the purpose for which it was collected:

  • Financial & Booking Records: Retained for a mandatory statutory period of five (5) years in compliance with the Tax Administration Act No. 28 of 2011 and Companies Act 71 of 2008.
  • Vehicle Condition Pre-Check Photos: Retained for one hundred and eighty (180) days post vehicle return to cover latent damage claims, after which they are automatically archived or purged.
  • CCTV Footage: Continuously overwritten on a 30-to-90 day loop, unless required for ongoing criminal prosecution or insurance settlement.
  • Destruction Protocol: Digital records scheduled for deletion are purged using cryptographic de-identification and deletion routines; physical records are incinerated or shredded.

10. Data Subject Rights & Information Officer

Under Sections 23, 24, and 25 of POPIA and the provisions of PAIA, you have the following enforceable statutory rights:

  • Right of Access: Request confirmation whether we hold your personal information and obtain a formal record thereof.
  • Right to Rectification: Request correction or updating of inaccurate, irrelevant, outdated, or incomplete records.
  • Right to Erasure / Deletion: Request destruction or deletion of personal information where we are no longer authorized to retain it.
  • Right to Object: Object on reasonable grounds to the processing of your personal information (Form 1 of the POPIA Regulations).
  • Right to Withdraw Consent: Withdraw consent for non-essential processing at any time without retroactive effect.

Designated Information Officer Contact Details

All requests for access (PAIA Form 02), correction, or objection must be directed in writing to our designated Information Officer:

Designation Information Officer, AIR-O-AIRPORT PARKING (PTY) LTD
Physical Address 459 Shamrock Road, Bredell, Kempton Park, 1619, Gauteng
Postal Address PO Box 3327, Jeppestown, Gauteng, 2043
Direct Official Email [email protected]
Support Desk [email protected]
Telephone Hotline +27 84 778 8530

11. Direct Marketing & Cookie Policy (Section 69 POPIA)

Electronic Direct Marketing: We strictly adhere to Section 69 of POPIA. We only send marketing communications (discounts, loyalty vouchers) where you have given explicit opt-in consent or where you are an existing customer who booked services with us previously. Every marketing communication contains a clear, functional opt-out/unsubscribe facility.

Cookies & Local Storage: Our website uses minimal, strictly essential first-party cookies:

  • Theme Preference Cookie: Persists your dark-mode visual interface preferences.
  • Session Navigation State: Anchors page scrolling to the main menu when navigating between tabs.
  • Google reCAPTCHA v3: Evaluates risk scores to prevent automated bot submissions and spam attacks on our contact forms.

12. Lodging a Complaint with the Information Regulator

While we encourage data subjects to resolve any concerns directly with our Information Officer, you have the statutory right under Section 74 of POPIA to lodge a formal complaint with the South African Information Regulator:

The Information Regulator (South Africa)

Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017

General Inquiries: [email protected]

POPIA Complaints Email: [email protected]

PAIA Complaints Email: [email protected]

Official Website: https://inforegulator.org.za/