PRIVACY POLICY

1. Introduction

1.1. This Privacy Policy tells you how we will process and protect your personal information.

1.2. Caica Pharmacies Limited (“Caica”, “we”, “us” or “our”) collects and processes the personal information of anyone who accesses our website and/or chooses to become our customer as well as from your day-to-day dealings with us (“you” or “your”).

1.3. By providing us with your Personal Information, you:

1.3.1. agree to this Policy and authorize us to process such information as set out herein; and

1.3.2. authorize Caica, our Service Providers and other third parties to Process your Personal Information for the purposes stated in this Policy.

1.4. Personal Information, in terms of the Protection of Personal Information Act, No.11 of 2022 (“POPIA”), means “information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person”. The United Republic of Tanzania Constitution, Act of 1977, Article 16 provides that everyone has the right to privacy. This includes the right to protection against the unlawful collection, retention, dissemination and use of your personal information.

1.5. Because of the sensitivity of some personal information, we ensure that the way we process your Personal Information complies fully with POPIA and have implemented reasonable organizational and technical controls as a result.

1.6. Our Privacy Policy terms may change from time to time. When we change them, the changes will be made on our website. Please ensure that you visit our website and regularly read this Privacy Policy.

1. Collection of Personal Information

2.1. We may collect or obtain Personal Information about you in the following ways:

2.1.1. Through direct or active interactions with you;

2.1.2. In the course of our relationship with you;

2.1.3. Through automated or passive interactions with you;

2.1.4. When you visit / or interact with our website or our various social media platforms;

2.1.5. From third parties;

2.1.6. Public sources;

2.1.7. Employment applications;

2.1.8. CCTV; and

2.1.9. Website usage information may be collected using “cookies” which allows us to collect standard internet visitor usage information.

2.2. Types of Personal Information we may collect:

2.2.1. Identity information;

2.2.2. Contact information;

2.2.3. Financial information;

2.2.4. Transaction information;

2.2.5. Technical information;

2.2.6. Usage Information;

2.2.7. Location information; and

2.2.8. Marketing and communications information.

3. Legal Basis for Processing

3.1. When we process your personal information in connection with the purposes set out in this Privacy Statement, we may rely on one or more of the following legal bases, depending on the purpose for which the processing activity is undertaken and the nature of our relationship with you:

3.1.1. Your consent to the processing of your Personal Information;

3.1.2. Processing of the information is necessary for the performance of a contract or of a legal obligation;

3.1.3. Processing is necessary for the protection of our and your legitimate interests.

3.1.4 Processing is necessary as per the court order

4. Purposes of Processing

4.1. We will primarily use your Personal Information only for the purpose for which it was originally collected. We will use your Personal Information for a secondary purpose only if such purpose constitutes a legitimate interest and is compatible with the primary purpose for which the Personal Information was collected.

4.2. You agree that we may process your Personal Information for the following, but not limited to, purposes, as relevant to our relationship with you:

4.2.1. Operating our business;

4.2.2. Complying with compulsory requirements under relevant laws;

4.2.3. to retain and make information available to you on our website;

4.2.4. to maintain and update our supplier database;

4.2.5. to establish and verify your identity on the website;

4.2.6. fraud prevention;

4.2.7. recruitment;

4.2.8. complying with information requests from the Information Regulator;

4.2.9. transfer of information to an associated third party of supplier;

4.2.10. for purposes of doing appropriate customer on boarding and credit vetting;

4.2.11. information may be shared with third parties for market research and to enable Caica (and its associated companies) to develop appropriate marketing strategies in respect of its customers.

4.2.12. to conduct market research, surveys and other marketing activities;

4.2.13. Account, payment and debt management and

4.2.14. for security, administrative and legal purposes.

4.3. We may also collect and process aggregated data, which may include historical or statistical data for any purpose, including for know-how and research purposes.

5. Sharing of Personal Information

5.1. In order for us to carry out our obligations and for legitimate business purposes, we may need to pass your personal information on to third parties, such as our service providers. This Privacy Policy records your consent to us passing your Personal Information onto those third parties.

5.2. We will ensure that your Personal Information is processed in a lawful manner and that the third parties or we do not infringe your privacy rights. In the event that we ever outsource the processing of your Personal Information to a third-party operator, we will ensure that the operator processes and protects your Personal Information using reasonable technical and organizational measures that are equal to or better than ours.

5.3. We may also disclose your Personal Information to third parties if we are under a duty to disclose or share such information in order to comply with any legal obligation or to protect the rights, property or safety of Caica, its customers and others.

6. Data Security

6.1. We have implemented appropriate technical and organizational security measures to protect your Personal Information that is in our possession against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, in accordance with applicable law.

7. Data Retention

7.1. We will retain your personal information for as long as is necessary to fulfil the purpose for which it was collected unless a longer retention period is required to comply with legal obligations or another legitimate obligation, unless we have your consent to process it indefinitely.

8. Data Accuracy

8.1. The Personal Information provided to us should be accurate, complete and up-to-date. Should Personal Information change, the onus is on the provider of such data to notify us of the change and provide us with the accurate data.

9. Your Rights under this Privacy Policy

9.1. You have the right to have your personal information processed lawfully. Your rights include the right:

9.1.1. to be notified that your Personal Information is being collected or that your Personal Information has been accessed or acquired by an unauthorized person e.g., where a hacker may have compromised our computer system;

9.1.2. to request us, where necessary, to correct, destroy or delete your Personal Information;

9.1.3. to object, on reasonable grounds, to the processing of your Personal Information;

9.1.4. to object to the processing of your Personal Information for purposes of direct marketing, including by way of unsolicited communications;

9.1.5. not to be subject, in certain circumstances, to a decision which is based solely on the automated processing of your Personal Information;

9.1.6. to submit a complaint to the Regulator if you believe that there has been interference with the protection of your Personal Information; and

9.1.7. to institute civil proceedings against us if you believe that we have interfered with the protection of your Personal Information.

10. Contact Details for Queries

14.1. You may contact our Information Officer at: ……………

14.2. You may contact the Information Regulator at

Tel: ………….

Email………………….