Vendor Privacy Policy
E-Book Shop Marketplace
This Vendor Privacy Policy (“Policy”) sets out the requirements for vendors regarding the collection, use, processing, storage, and protection of personal information obtained through the E-Book Shop Marketplace.
By registering as a vendor, you agree to comply with this Policy in addition to all other platform policies.
1. Purpose & Scope
This Policy applies to all vendors who access, receive, or process personal information relating to customers, including names, email addresses, purchase details, or support communications.
2. POPIA Compliance
Vendors must comply with the Protection of Personal Information Act, 4 of 2013 (POPIA) and any applicable data-protection laws.
Personal information must be:
- Processed lawfully and fairly
- Collected for a specific, lawful purpose
- Adequate, relevant, and not excessive
- Kept accurate and up to date
3. Permitted Use of Personal Information
Vendors may use customer personal information only for:
- Fulfilling orders
- Providing customer support
- Managing licensing or access to digital products
Use of personal information for marketing, resale, profiling, or unrelated purposes is prohibited without explicit customer consent.
4. Data Security Obligations
Vendors must implement appropriate technical and organisational safeguards to protect personal information against:
- Unauthorised access
- Loss or damage
- Disclosure or misuse
This includes secure storage, password protection, and limited access controls.
5. Confidentiality
All personal information must be treated as confidential. Vendors must ensure that employees, contractors, or agents with access to personal information are bound by confidentiality obligations.
6. Data Sharing Restrictions
Vendors may not:
- Share customer data with third parties
- Transfer personal information outside South Africa without lawful grounds
- Sell or monetise customer data
Any lawful data transfers must comply with POPIA cross-border transfer requirements.
7. Data Retention & Deletion
Vendors must:
- Retain personal information only for as long as necessary
- Securely delete or anonymise data once it is no longer required
8. Data Breach Notification
Vendors must notify E-Book Shop immediately upon becoming aware of any actual or suspected data breach involving customer information.
Vendors must cooperate fully with breach investigations and regulatory notifications.
9. Data Subject Rights
Vendors must respect customer rights under POPIA, including:
- Right of access to personal information
- Right to correction or deletion
- Right to object to unlawful processing
Requests must be handled promptly and lawfully.
10. Audits & Compliance Monitoring
E-Book Shop reserves the right to request confirmation of compliance or conduct reasonable audits where necessary to ensure data protection obligations are met.
11. Indemnification
Vendors agree to indemnify and hold harmless E-Book Shop from any claims, losses, penalties, or damages arising from vendor non-compliance with POPIA or this Policy.
12. Consequences of Non-Compliance
Breach of this Policy may result in:
- Immediate suspension of vendor access
- Termination of vendor account
- Legal action or regulatory reporting
13. Governing Law
This Policy is governed by the laws of the Republic of South Africa.
14. Policy Updates
E-Book Shop may amend this Policy from time to time. Continued use of the marketplace constitutes acceptance of any updates
