Statutory Responsible Party Particulars (Section 18 POPIA)
Registered corporate identity & facility particulars under the Companies Act 71 of 2008 & POPIA
Protection of Personal Information Act (Act No. 4 of 2013) • Promotion of Access to Information Act (Act No. 2 of 2000)
Effective Date: 14 December 2021 • Last Revised & Published: 12 September 2026 • Version 3.2
Registered corporate identity & facility particulars under the Companies Act 71 of 2008 & POPIA
This Privacy Policy and Compliance Manual constitutes the statutory disclosure of AIR-O-AIRPORT PARKING (PTY) LTD ("Airoparking", "the Responsible Party", "we", "us", or "our") pursuant to the provisions of:
"Data Subject" means the person or juristic entity to whom personal information relates, including private travelers, corporate flight coordinators, and fleet managers.
"Personal Information" means information relating to an identifiable, living natural person or existing juristic person as defined in Section 1 of POPIA.
"Processing" means any operation or activity concerning personal information, including collection, receipt, recording, organization, storage, updating, retrieval, alteration, dissemination, and destruction.
"Operator" means a person or entity who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party.
In terms of Section 11(1) of POPIA, we strictly process personal information only where one or more of the following lawful grounds apply:
In compliance with the Principle of Minimality (Section 10 of POPIA), we collect only the personal information strictly required to deliver safe, professional airport valet parking and vehicle custody:
Full names, physical business/residential address, telephone number, mobile number, WhatsApp handle, email address, and company representation particulars.
Vehicle registration number (license plate), vehicle make, model, color, vehicle identification number (VIN), odometer readings at drop-off and return, fuel level, vehicle condition inspection photographs (360-degree digital pre-check), and parking bay allocations.
Inbound and outbound flight numbers, airline identifiers, and scheduled landing times. This information is matched via automated aviation radar feeds strictly to time vehicle wash, staging, and driver dispatch at Parkade 2 South Level 3 Block H.
Payment transaction confirmation tokens, PayFast reference numbers, customer account statement aging schedules, and Section 23 Non-VAT commercial invoices. We never store raw credit card numbers, debit card numbers, or CVV security codes on our infrastructure.
24-hour high-definition CCTV security footage captured at our private holding compound in Bredell and at airport meet-and-greet blocks, as well as digital handwritten signatures captured on check-in/check-out operational manifests.
Our governance framework embeds the eight statutory conditions of Chapter 3 of POPIA:
1. Accountability (Section 8): The Responsible Party ensures all measures giving effect to the conditions of POPIA are implemented and audited.
2. Processing Limitation (Sections 9β12): Information is processed lawfully, in a reasonable manner that does not infringe on data subject privacy, and directly from the data subject wherever practicable.
3. Purpose Specification (Sections 13β14): Personal information is collected for explicit, defined, and lawful commercial purposes related to vehicle bailment and logistics.
4. Further Processing Limitation (Section 15): Further processing of personal information must be compatible with the initial collection purpose.
5. Information Quality (Section 16): We take reasonably practicable steps to ensure that personal records are complete, accurate, not misleading, and updated where necessary.
6. Openness (Sections 17β18): Transparent documentation of processing operations and direct Section 18 statutory notifications provided to all clients prior to vehicle handover.
7. Security Safeguards (Sections 19β22): State-of-the-art physical, operational, and digital safeguards protecting personal data against loss, damage, or unauthorized access.
8. Data Subject Participation (Sections 23β25): Full accessibility for data subjects to confirm, access, correct, or request deletion of their personal records.
Due to the nature of motor vehicle bailment and custody:
For corporate fleet and corporate account applicants applying for deferred settlement terms (30/60/90 days):
FICA & KYB Verification: In accordance with statutory KYB requirements, applicants submit corporate registration documents (Cor14.3/CK), utility bills, bank verification letters, and director identification documents. These documents are stored under role-based administrative access controls.
Credit Bureau Transmissions (NCA Section 70 & POPIA Section 18): The applicant director or authorized officer expressly consents that Airoparking may transmit company payment performance records and director warranties to registered South African credit bureaus (including TransUnion, Experian, and XDS) to conduct risk assessments, verify trade references, and trace defaulting debtor accounts.
We do not sell, rent, or trade client databases under any circumstances. We disclose personal information to authorized third-party Operators solely to fulfill our contractual services:
We implement comprehensive technical and organizational safeguards:
TLS 1.3 encryption for all data in transit (HTTPS), AES-256 encryption for data at rest, salted password hashing, Google Cloud App Check bot defense, and least-privilege role-based access.
24/7 fortified compound perimeter with electrified fencing, biometric and PIN staff access controls, armed response patrol links, and locked key safe management.
Section 22 Breach Notification Protocol: In the event of a confirmed or reasonably suspected security compromise involving personal data, we will notify the South African Information Regulator and affected data subjects as soon as reasonably possible, specifying the nature of the breach, suspected consequences, and remediation measures taken.
Personal information is retained only for as long as necessary to achieve the purpose for which it was collected:
Under Sections 23, 24, and 25 of POPIA and the provisions of PAIA, you have the following enforceable statutory rights:
All requests for access (PAIA Form 02), correction, or objection must be directed in writing to our designated Information Officer:
Electronic Direct Marketing: We strictly adhere to Section 69 of POPIA. We only send marketing communications (discounts, loyalty vouchers) where you have given explicit opt-in consent or where you are an existing customer who booked services with us previously. Every marketing communication contains a clear, functional opt-out/unsubscribe facility.
Cookies & Local Storage: Our website uses minimal, strictly essential first-party cookies:
While we encourage data subjects to resolve any concerns directly with our Information Officer, you have the statutory right under Section 74 of POPIA to lodge a formal complaint with the South African Information Regulator:
The Information Regulator (South Africa)
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
General Inquiries: [email protected]
POPIA Complaints Email: [email protected]
PAIA Complaints Email: [email protected]
Official Website: https://inforegulator.org.za/