Privacy and Cookie Notice

Who are we

Smollan is a global group of companies (“Smollan”, “we”, “our”, “us”) providing retail, marketing, technology, and related services across multiple jurisdictions.

This Privacy Notice applies to personal data processed by Smollan and its affiliates worldwide. The relevant Smollan entity that collects and processes your personal information is the data controller (or responsible party under South Africa’s POPIA) and determines how and why your data is processed.

For visitors to https://www.smollan.com and associated services, Global Smollan Holdings registered in Mauritius at c/o BTG Management Services (Mauritius) Limited, Block 9A & 9B, Cascavelle Business Park, Petite Rivière Noire Road, Cascavelle, 90522, Republic of Mauritius, with Reg number 082910/GBC, acts as the primary data controller.

Where you engage with Smollan in another country, a local Smollan entity may act as the controller, joint controller, or data processor, depending on the purpose and context of processing.

For a complete list of Smollan’s global entities, their roles, and relevant contact details, please contact us via the details provided in the Contact Us section of this Privacy Notice.


What is this Privacy Notice for

This Privacy Notice explains how Smollan may collect, use, store, share, and protect your information when you interact with us.

It applies to personal information collected through our websites, mobile applications, recruitment platforms, vendor onboarding systems, and any other channels where we process your data as part of providing our products and services.

For the purposes of this Privacy Notice, “personal information” (also referred to as “personal data”) means:

  • Information relating to an identified or identifiable natural person, as defined under laws such as the General Data Protection Regulation (GDPR), the UK GDPR, and other international privacy frameworks; and
  • In jurisdictions where applicable, including South Africa’s Protection of Personal Information Act (POPIA), information relating to an identifiable juristic person (such as companies, vendors, or other legal entities).

By accessing our websites, engaging with us, or using our services, you acknowledge that your personal information will be processed in accordance with this Privacy Notice and applicable data protection regulations.

Smollan is committed to upholding globally recognised data protection standards and applying best practice principles across all our operations to ensure transparency, fairness, and the highest level of security wherever your data is processed.


What personal information may we collect

Depending on your relationship with Smollan and how you interact with us, we may collect the following categories of personal information:

Identity & Contact Information

Full name, title, job title, and business or personal contact details (email, phone, address).

Employer details where we engage with you in a business-to-business capacity (e.g., vendor, client, or partner).

Financial & Transactional Data

Payment details, banking information, and billing addresses where we process payments for services rendered or received.

Recruitment & Employment Information

CVs, qualifications, employment history, references, and supporting documents when you apply for a role.

Where applicable and with your explicit consent, we may collect Equity, Diversity, and Inclusion (EDI) data to monitor and promote equal opportunities.

Background Checks (where permitted by law)

As part of our recruitment, onboarding, and certain vendor or client onboarding processes, Smollan may collect and process information obtained through background screening, which may include:

  • Criminal record checks (where legally allowed)
  • Credit checks (where relevant to the role or engagement)
  • Professional memberships, qualifications, and employment references
  • Other due diligence results from third-party screening providers

Where required, we will obtain your explicit consent or ensure we have a valid legal basis before carrying out these checks.

Marketing & Preference Data

Communication preferences, marketing opt-ins and opt-outs, responses to campaigns, and engagement with surveys or events.

Information from Third Parties

Information provided by recruitment partners, analytics providers, advertising platforms, credit bureaus, background screening providers, and other service partners engaged to support Smollan’s operations.

Special Categories of Personal Information (processed only with explicit consent or where legally required):

Racial or ethnic origin, health or disability information, biometric data, and criminal conviction data collected during recruitment or employee/vendor onboarding.

Juristic Persons

In jurisdictions such as South Africa where local laws (e.g., POPIA) require additional coverage, “personal information” may also include details about juristic persons (e.g., company registration details, vendor information, or corporate contact data).

Children’s Data

Our websites, platforms, and services are not directed at individuals under the age of 18, and we do not knowingly collect personal information from children.

If we become aware that we have inadvertently collected personal information from a minor through our website or digital platforms, we will:

  • Delete the information from our systems as soon as reasonably possible; and
  • Where required by law, notify the parent, guardian, or applicable supervisory authority.

In jurisdictions where parental or guardian consent is legally required to process a minor’s data, Smollan complies with the relevant age thresholds.

If you believe we may have collected personal information from a child without the necessary consent, please contact our Data Privacy Team using the details provided in the Contact Us section of this Privacy Notice.

Online & Technical Information

IP address, browser type, device identifiers, time zone, location, and operating system.

Website analytics, clickstream data, browsing history, cookie preferences, and online identifiers.

We collect this information directly from you, through your interactions with Smollan platforms, through publicly available sources, or from trusted third-party partners where permitted by law.



How we use your data

We may use your personal information for the following purposes, depending on your relationship with Smollan and how you interact with us:

  • Service Delivery & Business Operations
  • To operate our business, fulfil our contractual obligations, and provide services you have requested.
  • To acknowledge, confirm, and respond to your enquiries, job applications, vendor requests, orders, or briefs.
  • To manage vendor onboarding, perform due diligence, and verify information provided to us, including credit and risk assessments.
  • To verify your identity when required for security, regulatory, or service-related purposes.

Recruitment, Background Checks & AI-Assisted Processing

  • To manage job applications and assess candidates for employment opportunities.
  • Where permitted by law and with appropriate safeguards, to conduct background screening, including criminal record checks, credit checks, employment references, and qualification verification.
  • To process sensitive information such as Equity, Diversity, and Inclusion (EDI) data where collected with your explicit consent and de-identified where possible.
  • To use AI-based tools in recruitment to assist with application assessments; however, all hiring decisions are reviewed by human recruiters, and no automated decisions are made without oversight.

Marketing, Analytics & Communications

  • To provide you with information about Smollan’s products, services, campaigns, and initiatives.
  • To conduct business-to-business marketing, including contacting companies and their employees to explore opportunities for mutual commercial benefit.
  • To deliver personalised content, analyse campaign effectiveness, and manage your marketing preferences.
  • To send marketing emails or updates, you may unsubscribe at any time.
  • To combine personal information, you have provided to us with information collected through our systems, analytics tools, and third-party sources to enhance insights and improve services.

Digital Platforms & Website Operations

  • To administer, manage, and secure our websites, mobile apps, and other platforms.
  • To ensure these platforms are presented effectively and tailored for your device.
  • To measure and improve functionality through data analytics, surveys, and performance monitoring.
  • To manage cookies, tag data, and tracking preferences in line with your consent.

Fraud Prevention, Security & Compliance

  • To protect against fraud, identity theft, and other unlawful activity.
  • To detect, investigate, and respond to security incidents or suspected breaches.
  • To comply with applicable laws, regulations, and industry standards, including financial, consumer protection, and employment-related requirements.
  • To establish, exercise, or defend legal rights and manage claims or disputes.
  • To share information with law enforcement, regulators, or courts where required by law or to protect our legitimate interests.

Customer, User & Vendor Insights

  • To conduct customer and vendor surveys and analyse feedback to improve our services.
  • To understand how individuals collectively use our websites, platforms, and services, including anonymised, aggregated analytics.
  • To confirm geolocation when conducting field marketing activities or other operational engagements.

Consent-Based Processing

  • To process data for purposes requiring your explicit consent, such as EDI data, criminal checks, marketing communications, and recruitment profiling.
  • Where required by law, we will request your consent and allow you to withdraw it at any time without impacting the lawfulness of processing before withdrawal.

Combining & Enriching Data Sources

  • We may combine personal information provided by you with information collected from other Smollan systems, trusted third parties, and analytics tools where permitted by law, for the purposes described in this Privacy Notice.

Notice of Right to Opt-Out of Sale/Sharing

Smollan does not sell your personal information to third parties for monetary consideration. Furthermore, we do not “share” your personal information for cross-content behavioural advertising purposes as defined under the California Consumer Privacy Act (CCPA). Because we do not engage in these practices, we do not provide a “Do Not Sell or Share My Personal Information” link on our website.


Disclosure of your personal information

We may share your personal information with trusted third parties where necessary to deliver our services, comply with our legal obligations, manage our business operations, or protect our legitimate interests.

We take appropriate steps to ensure that any third parties receiving your data apply equivalent levels of security and comply with applicable data protection laws, including through Data Processing Agreements or equivalent contractual safeguards. Below are the main categories of recipients:

Smollan Group Companies

Other companies within the Smollan Group that provide operational, administrative, HR, finance, IT, or marketing support.

These entities may act as data controllers, joint controllers, or processors, depending on the context.

Regions: South Africa, EU, UK, AFRICA, LATAM, MEA, SEA and other regions where Smollan operates.

Technology & Cloud Service Providers

Providers of secure hosting, collaboration, productivity, and data storage platforms (e.g., Microsoft, Google, OneTrust).

Used for internal communications, data processing, website operations, and productivity tools.

Regions: Global.

Recruitment & HR Partners

Service providers assisting with candidate applications, onboarding, background screening, and right-to-work verifications.

Includes third-party recruitment platforms and background-check providers, used only where legally permitted and with appropriate consent where required.

Regions: Regional or country-specific, depending on where the role or candidate is located.

Marketing, Analytics & Advertising Partners

Digital marketing, analytics, and social media platforms (e.g., LinkedIn, Google Analytics) that help us deliver campaigns, assess engagement, and improve content performance.

Regions: Global.

Professional Advisors & Consultants

Auditors, legal counsel, consultants, and other professional advisors engaged to support operational, financial, legal, or risk management matters.

Regions: Global.

Legal, Regulatory & Compliance Obligations

Where required by law, we may share your personal information with regulators, courts, law enforcement authorities, tax authorities, or public agencies to:

  • Comply with legal obligations,
  • Protect our legal rights,
  • Assist with investigations into suspected unlawful activities.

Regions: Country-specific depending on the jurisdiction involved.

Business Partners & Clients

Where Smollan provides services to clients, we may share limited personal information necessary for project delivery, vendor onboarding, or client-requested reporting.

Regions: Determined by client project locations.

Business Transfers

If Smollan undergoes a merger, acquisition, restructuring, or sale of assets, your personal information may be transferred to the acquiring organisation, subject to appropriate safeguards.

Fraud Prevention & Security

Credit reference agencies, fraud prevention bodies, and security service providers engaged to detect, investigate, and prevent identity theft, cyberattacks, and fraudulent activity.

Third-Party Processors

Smollan works with a range of trusted third parties to support our operations across multiple regions. Depending on your relationship with us, your personal information may be shared with the following categories of recipients:

  • Smollan Group Companies — Entities within the Smollan Group providing operational, HR, IT, and marketing support.
  • Technology & Cloud Service Providers — Providers of hosting, collaboration, storage, and productivity tools (e.g., Microsoft, Google).
  • Recruitment & HR Partners — Platforms and service providers assisting with candidate applications, onboarding, background checks, and right-to-work verifications.
  • Marketing, Analytics & Advertising Partners — Digital marketing platforms, analytics providers, and advertising networks.
  • Professional Advisors & Consultants — Legal advisors, auditors, risk consultants, and other specialists.
  • Legal, Regulatory & Compliance Authorities — Regulators, courts, tax authorities, and law enforcement where required by law.
  • Business Clients & Partners — Where necessary to deliver contracted services, manage vendor onboarding, or comply with client reporting requirements.

Regions: Global, depending on the nature of the processing and your engagement with Smollan.


Security

We take the security of your personal information seriously and implement appropriate technical, organisational, and administrative measures to protect it against unauthorised access, loss, alteration, or disclosure, in line with applicable data protection laws.

Where we share personal information with trusted third-party service providers, we require them to apply equivalent security standards through contractual agreements.

While we take reasonable steps to protect your data, no security system is completely infallible. If a personal data breach occurs, Smollan will respond in line with applicable legal requirements, including notifying affected individuals and regulators where necessary.


International Transfers

Smollan operates globally and may transfer your personal information to other Smollan group companies, affiliates, service providers, or trusted third parties located outside your country of residence.

Where your data is transferred internationally, we ensure that appropriate safeguards are in place to protect your information and comply with applicable data protection laws. These safeguards may include the use of Adequacy Decisions, Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement, Binding Corporate Rules (BCRs), or other permitted mechanisms under local law.

If you would like more information about these safeguards or wish to request a copy of the relevant contractual clauses, please contact us at informationofficer@smollan.com.

Local Variations

Some jurisdictions impose specific cross-border transfer requirements and require specific safeguards or authorisations for transfers. Smollan ensures that all international transfers comply with the local data protection requirements where your information is collected.


Lawful Basis for Processing

Smollan processes your personal information in compliance with applicable data protection laws in the regions where we operate, applying globally recognised privacy standards.

Depending on the context and purpose of processing, we may rely on one or more of the following lawful bases:

Lawful Basis Illustrative Processing Activities
Consent
  • Placing cookies and using analytics/tracking tools
  • Collecting Equity, Diversity & Inclusion (EDI) data during recruitment, where consent is required by law
  • Collecting sensitive personal information, such as health, disability, or biometric data, where consent is required by law
  • Conducting criminal or credit checks where required by local law, where consent is required by law
  • Sending direct marketing communications where consent is required by law
Performance of a Contract
  • Fulfilling obligations under contracts with clients, vendors, and employees
  • Managing recruitment, onboarding, and employment agreements
  • Processing payments, expense claims, and invoicing
  • Delivering Smollan’s products and services
Legitimate Interests
  • Delivering business-to-business marketing communications
  • Managing Smollan operations, reporting, and business forecasting
  • Improving products, services, and platform performance
  • Analysing website, apps, and campaign engagement
  • Monitoring geolocation via company-approved apps for field marketing activities
  • Using AI-driven recruitment tools with human oversight
  • Performing vendor onboarding, due diligence, and risk assessments
Compliance with Legal Obligations
  • Meeting obligations under tax, labor, financial reporting, procurement, and corporate governance requirements
  • Responding to regulatory requests, subpoenas, or court orders
  • Performing anti-bribery, sanctions, and anti-money laundering checks
Vital Interests (applies in limited cases)
  • Protecting your life, health, or safety in emergency situations
  • Supporting security or legal responses where urgent action is required


Special Categories of Personal Information

Smollan may process sensitive personal information, such as health data, disability status, racial or ethnic origin, biometric data, or criminal records, only where permitted by applicable data protection laws.

This typically occurs where:

  • We have your explicit consent (e.g., collecting EDI profiles or workplace accommodation data).
  • Processing is required to comply with legal obligations (e.g., employment reporting, workplace safety, or tax requirements).
  • Processing is necessary to establish, exercise, or defend legal claims.

For more detail on the lawful bases we rely on, please refer to the Lawful Basis for Processing section above.


Data Retention

Smollan retains personal information only for as long as necessary to fulfil the purposes described in this Privacy Notice or as required by applicable laws, regulations, or contractual obligations.

Where it is not possible to specify fixed retention periods, we determine retention based on factors such as:

  • The purpose for which the data was collected and whether it remains necessary;
  • Legal, regulatory, tax, and contractual requirements; and
  • The potential need to establish, exercise, or defend legal claims.

Once personal information is no longer required, we will securely delete, anonymise, or archive it in accordance with legal obligations.

You may request deletion of your personal information, where applicable, by contacting us via the details provided in the Contact Us section.


Artificial Intelligence (AI) in Recruitment

Use of AI in Recruitment

As part of our recruitment process, Smollan may use AI-assisted tools to support the assessment of candidate applications. These tools may analyse information you provide, including your CV, qualifications, application form responses, and screening results, to assist our recruitment team in identifying suitable candidates.

Key Safeguards and Human Oversight

Smollan uses AI-assisted tools to support recruitment but ensures that final hiring decisions are always made by human recruiters. We also require our AI service providers to comply with Smollan’s data protection and security standards and take reasonable steps to ensure AI tools are used fairly, transparently, and only for the purposes described in this Privacy Notice.

Your Rights

  • You can request meaningful information about how AI tools are used and the safeguards in place.
  • You can request human intervention, express your views, or contest an outcome where AI-assisted tools are used.

To exercise these rights, please contact us via the details provided in the Contact Us section of this Privacy Notice.


Your Data Protection Rights

Subject to applicable data protection laws in the country where you reside, you may have the following rights in relation to your personal information:

  • Right of Access — You can request confirmation of whether we process your personal information and, where applicable, receive a copy of that information.
  • Right to Rectification — You can request that we correct any inaccurate or incomplete personal information we hold about you.
  • Right to Erasure (“Right to be Forgotten”) — You may request that we delete your personal information where there is no lawful reason for us to continue processing it.
  • Right to Restrict Processing — You can request that we temporarily suspend processing of your personal information in specific circumstances.
  • Right to Object — You can object to the processing of your personal information where we rely on legitimate interests or where we process your data for direct marketing purposes.
  • Right to Data Portability — Where technically feasible and required by law, you may request a copy of your personal information in a structured, commonly used, machine-readable format and ask us to transfer it to another organisation.
  • Rights in Relation to Automated Decision-Making and Profiling — Smollan does not make decisions about you solely based on automated processing that produce legal or similarly significant effects.

Exercising Your Rights

If you wish to exercise any of these rights, please select this LINK and complete the online form. We may request additional information to verify your identity before fulfilling your request.

  • We aim to respond to valid requests within one month, or within the timeframe required by local law.
  • Where we are unable to fulfil your request due to legal, contractual, or regulatory obligations, we will explain the reason to you.

Withdrawing Your Consent

Where we process your personal information based on your consent, you have the right to withdraw your consent at any time. This will not affect the lawfulness of any processing carried out before withdrawal.


Change to our Privacy Notice

We may update this Privacy Notice from time to time. The latest version will always be available at https://smollan.com, and where required by law, we will notify you of significant changes.


Contact Us

Questions, comments or complaints regarding this Privacy Notice or any of our processing should be made to our Data Privacy Team by completing the form available via this LINK or post at: Data Privacy, Smollan, P.O. Box 51537, Raedene, Johannesburg, South Africa, 2124.

If you are located in the European Union or United Kingdom and wish to contact us regarding our data processing activities, you may do so via our designated representatives pursuant to Article 27 of the General Data Protection Regulation (GDPR).

European Union: Advantage Smollan BV LINK

United Kingdom: Advantage Smollan Limited LINK


The Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with the relevant data protection authority if you believe that your personal information has not been handled in accordance with applicable data protection laws.

A full list of supervisory authorities is available on request from our Data Privacy Team by contacting us via the details provided in the Contact Us section of this Privacy Notice.