Last updated: July 3, 2026
Welcome to Bundi Africa, operating under Bundi River Adventurers CC (“we”, “us”, “our”). We are committed to protecting your privacy and ensuring that your personal information is collected, used, and stored in a lawful, fair, and transparent manner in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
By using our website or contacting us, you acknowledge that your personal information may be processed as described in this Privacy Policy.
This Privacy Policy serves as the notification required by section 18 of the Protection of Personal Information Act 4 of 2013 (“POPIA”). The information required under section 18 is provided throughout this Privacy Policy, including details of the personal information we collect, the purposes for which it is processed, whether the provision of information is voluntary or mandatory where applicable, the consequences of failing to provide information, recipients of personal information, international transfers, and your rights as a data subject.
By accessing or using our website, contacting us, requesting a quotation or making use of our services, you acknowledge that you have read this Privacy Policy and understand how your personal information may be collected, used and protected.
Where your consent is required by POPIA or any other applicable law for specific processing activities, we will request that consent separately.
Your continued use of our website and services constitutes your acknowledgement of this Privacy Policy as updated from time to time.
This Privacy Policy applies to all individuals whose personal information we process in the course of our business operations.
This includes, but is not limited to:
This Privacy Policy applies to personal information collected through our website, contact forms, email communications, telephone interactions, booking enquiries, accommodation reservations, activity bookings, indemnity forms, guest registrations, and any related services operated by us.
To make this Privacy Policy easier to understand, the following key terms are used:
Personal Information
Any information relating to an identifiable, living natural person or juristic person, as defined under the Protection of Personal Information Act 4 of 2013 (“POPIA”).
POPIA
The Protection of Personal Information Act 4 of 2013, which regulates how personal information is collected, used, stored, and shared in South Africa.
Responsible Party
The entity that determines the purpose and means of processing personal information. In this case, Bundi Africa, operating under Bundi River Adventurers CC.
Service Provider/ Operator
A third party natural or legal person who processes personal information on behalf of the Responsible Party under contract and instruction.
Country
Refers to the Republic of South Africa.
Device
Any electronic device used to access our services, including computers, smartphones, tablets, or similar devices.
Processing
Any operation or activity performed on personal information, including collection, storage, use, transfer, alteration, or deletion.
Consent
Any voluntary, specific, and informed expression of will in terms of which permission is given for the processing of personal information.
Services
All services provided by us, including but not limited to accommodation (chalets and camping), rafting, canoeing, fishing, guided outdoor activities, adventure experiences, bookings, reservations, guest services, and our website and related systems.
Website
The official website operated by us, accessible at https://bundi.africa.
Account
Means a registered profile created by a user (if applicable) to access booking systems, reservations, or other online services provided by us.
Usage Data
Data collected automatically when using our website or systems, including IP address, browser type, device information, pages visited, booking interactions, and system performance data.
You / Data Subject
Any individual accessing or using our services, including guests, visitors, customers, participants, employees, contractors, or any person whose personal information we process.
This Privacy Policy explains how we collect, use, and protect personal information in accordance with POPIA.
We act as the Responsible Party when processing personal information for our own business purposes, including handling enquiries, managing accommodation bookings, customer communication, marketing, and website operations.
Where we engage third-party service providers to assist in delivering our services, such providers act as Operators and process personal information on our behalf in accordance with POPIA.
Bundi Africa, operating under Bundi River Adventurers CCs is the Responsible Party for purposes of POPIA.
Company Details
The company details are as follows:
Information Officer
The Information Officer is responsible for overseeing compliance with POPIA and handling all requests relating to personal information.
They are appointed in accordance with the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”).
What Personal Data We Collect
We collect personal information directly from you when you interact with our website or services, including when you submit a contact form, make a booking enquiry, subscribe to communications, or contact us for support.
Where required by law, or where you have given us your consent, we may process your personal information in order to provide our services, manage bookings and respond to enquiries or communicate with you regarding your accommodation booking, stay, reservation, or enquiry.
When you interact with us directly, we may collect personal information such as:
We collect this information to respond to your enquiries, process bookings, and provide accommodation services.
Where required for accommodation bookings or optional activities offered by Bundi Africa, we may collect and process additional personal information for operational, safety, legal, insurance, emergency response, or risk management purposes.
This information may include:
Where any of the above information constitutes Special Personal Information under POPIA, including health-related information, we will process such information only where permitted by law and where reasonably necessary for guest safety, emergency response, insurance requirements, legal compliance, risk management, participation in activities or where otherwise authorised under POPIA.
We process Special Personal Information only where:
We implement appropriate technical and organisational safeguards to protect such information and restrict access to authorised staff/personnel who require access for operational, safety, emergency response, legal, insurance or administrative purposes.
Where meals, catering, accommodation packages, or hospitality services are provided, we may process information relating to dietary requirements, food allergies, food intolerances, religious dietary requirements, or other relevant dietary preferences in order to prepare meals, reduce health and safety risks, accommodate reasonable guest requirements, and provide suitable alternatives where reasonably possible.
Guests remain responsible for notifying us of any dietary restrictions, allergies, intolerances, or medical conditions that may affect their participation in activities or consumption of food provided by us. While we take reasonable steps to accommodate disclosed dietary requirements, we cannot guarantee the complete absence of allergens or cross-contamination in food preparation environments.
In some circumstances, you may provide us with personal information relating to another individual, such as a spouse, partner, family member, dependant, employee, authorised representative, recipient of a delivery, or emergency contact.
By providing us with another person’s personal information, you confirm that you are authorised to do so and, where required by law, that you have informed the individual about the collection and processing of their personal information and have obtained any necessary consent.
We will process such personal information in accordance with this Privacy Policy and applicable data protection laws.
When you browse our website, we may automatically collect certain technical information about your device and browsing activity. This may include your IP address, browser type, device information, website usage activity, cookie identifiers, shopping cart activity, and referral sources.
We collect this information to understand how visitors use our website, to improve its performance and usability, and to support the proper functioning of our services.
Our website enables customers to submit accommodation booking, reservation requests and general enquiry requests. Where online booking and payment are available, card payments are processed securely through approved third-party payment service providers. Payments may also be made by electronic funds transfer (EFT), card payment using authorised payment terminals at our base camp premises, approved third-party payment service providers, or any other payment methods that we may make available.
We do not process or store customers’ credit or debit card details. All payment card information is processed directly by the relevant payment service provider in accordance with applicable payment security standards and its own privacy policies.
For accounting, booking administration, legal compliance, fraud prevention, and record-keeping purposes, we may retain limited payment-related information, including payment confirmations, invoices, transaction reference numbers, billing details, the payment method used, records of amounts paid, and proof of payments where applicable. This information is processed only for lawful purposes, retained only for the period required by applicable legislation or our legitimate business needs, and protected by appropriate technical and organisational safeguards in accordance with the Protection of Personal Information Act, 2013 (POPIA).
Where you communicate with us via messaging platforms such as WhatsApp or similar services, we may process the content of those communications, including text messages, images, documents, and voice notes, in order to respond to enquiries, manage bookings, provide customer support, confirm services, and maintain records of our interactions with you.
These communications may be stored and retained as part of our business records and are subject to the same security, access control, and retention principles set out in this Privacy Policy.
We generally collect personal information directly from you. However, in certain circumstances, we may receive personal information from other lawful sources, including:
Where personal information is not collected directly from you, we will process such information in accordance with POPIA and this Privacy Policy.
We collect personal information in several ways when you interact with our business.
This includes when you:
We process personal information for legitimate, specific, and lawful business purposes in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
We may process personal information for the following purposes:
We process personal information in accordance with the applicable conditions for lawful processing under the Protection of Personal Information Act 4 of 2013 (“POPIA”), including accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation.
We may process your personal information where:
Where processing is based on consent, you may withdraw your consent at any time.
Certain personal information is required in order for us to provide accommodation, activities, bookings, customer support, and related services, verify payments, communicate with you, and comply with legal and regulatory obligations. Where the provision of such information is mandatory and you choose not to provide it, we may be unable to process bookings, provide services, respond to enquiries, comply with legal requirements, or otherwise fulfil our obligations to you.
In certain cases, we may also be legally required to collect and retain personal information in accordance with applicable tax, consumer protection, accounting, fraud prevention, or other regulatory obligations.
Legitimate Interests Safeguard
Where we process personal information based on legitimate interests, we ensure that these interests do not override your rights and freedoms in accordance with POPIA principles.
Data minimisation
We apply data minimisation principles by limiting the collection, use, and retention of personal information to what is reasonably necessary for the lawful purposes described in this Privacy Policy.
Fraud Prevention and Security
We may process personal information where reasonably necessary to detect, prevent, investigate, or respond to fraud, unauthorised activities, security incidents, or other unlawful conduct affecting our business, customers, employees, or service providers.
To support these activities, we use appropriate access controls, monitoring, and security measures designed to help protect personal information and identify unauthorised or suspicious activity. Where appropriate, we may use automated systems to assist in detecting potentially fraudulent transactions or activities. Such systems are used to support decision-making and are not intended to replace appropriate human oversight where required.
Service Improvement and Analytics
We may use aggregated or pseudonymised data to understand how our website and services are used, in order to improve performance, functionality, and user experience.
Where required, we provide mechanisms for users to opt out of non-essential analytics processing and we limit the retention of analytics data to what is reasonably necessary.
Customer Support and Dispute Resolution
We retain customer support communications where necessary to respond to enquiries, maintain service quality, and resolve disputes.
These records are retained only for as long as reasonably necessary for these purposes and are subject to access controls, restricted internal access, and appropriate security safeguards.
We may send you direct marketing communications such as newsletters, promotional offers, product updates, or special promotions where:
Our website uses cookies and similar tracking technologies, including web beacons, tags and pixels, to improve website functionality, analyse website usage, remember user preferences, support booking or online enquiry activity, ecommerce functionality, and, where applicable, deliver relevant marketing content.
Cookies may be temporary (session cookies), which are deleted when you close your browser, or persistent cookies, which remain on your device until they expire or are deleted.
Cookies may include:
Some cookies may be placed by third-party service providers such as analytics providers, advertising platforms, payment processors, or ecommerce service providers. Where our website includes embedded content or social media features, those third parties may also place cookies or collect information in accordance with their own privacy policies.
Where required, we use cookie consent mechanisms to allow users to accept or reject non-essential cookies. We may also use cookies to remember your cookie preferences and consent choices.
You may manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality and performance of the website.
Cookie Policy
For more detailed information about the cookies and similar tracking technologies we use, including third-party cookies where applicable, please refer to our Cookie Policy available at: https://bundi.africa/cookie-policy.
We may share personal information with trusted third parties where it is necessary for the operation of our business, the provision of our products or services, compliance with legal obligations, guest safety requirements, or the protection of our legitimate interests.
Categories of recipients may include accommodation staff, reservations personnel, housekeeping staff, maintenance providers, transport providers (where applicable), booking and reservation platforms, payment processors, website hosting providers, IT support providers, email and communication service providers, insurers, emergency medical service providers, rescue personnel, operational personnel located in South Africa and Namibia and legal or regulatory authorities where disclosure is required by law.
Personal information may also be accessed internally by authorised employees, management, contractors, or administrative personnel where such access is reasonably necessary for the performance of their duties, the provision of services, customer support, operational management, security, compliance, or other legitimate business purposes. Access is restricted to individuals who require the information for authorised purposes and is subject to appropriate confidentiality and security controls.
We only share the minimum amount of personal information necessary for these service providers to perform their functions. Where they process personal information on our behalf as Operators, we take reasonable steps to ensure that they process such information only for authorised purposes, maintain appropriate confidentiality, implement reasonable security measures, and comply with POPIA.
We may disclose personal information where we are legally required or authorised to do so in order to comply with applicable laws, regulations, court orders, legal processes, or lawful requests from competent authorities.
This may include disclosures to law enforcement agencies, regulatory authorities, tax or financial authorities, courts, tribunals, or other public bodies.
We will take reasonable steps to verify the validity and legal basis of any request before disclosing personal information. Where legally permitted, we may notify affected individuals of such disclosures unless we are prohibited from doing so by law or court order.
We do not sell, rent, trade, or otherwise make personal information available to third parties for their own independent commercial purposes.
In emergency situations involving injury, illness, rescue operations, medical treatment, evacuation, or threats to life or safety, we may disclose relevant personal information to emergency service providers, medical practitioners, rescue personnel, law enforcement authorities, insurers, or other persons reasonably necessary to protect the life, health, or safety of an individual.
Our website and business operations may make use of third-party ecommerce, analytics, advertising, payment processing, communication, cloud hosting, customer support, and marketing platforms.
These service providers may process personal information on our behalf as Operators in accordance with our instructions, POPIA, and any applicable contractual obligations.
Where personal information is processed by third-party providers located outside South Africa, such processing will be subject to the safeguards described in Section 13 (International Transfers).
We may disclose, transfer, or make available personal information as part of a proposed or completed merger, acquisition, restructuring, reorganisation, financing transaction, sale of assets, change of ownership, joint venture, or other corporate transaction involving all or part of our business.
Where personal information is transferred as part of such a transaction, we will take reasonable steps to ensure that the recipient is bound by appropriate confidentiality, security, and data protection obligations.
Any such transfer will be carried out only where it is lawful and necessary for the purposes of the transaction and subject to any applicable legal requirements.
Our head office is located in the Republic of South Africa. Some of our business operations, including accommodation services and related tourism and hospitality services, are conducted from our operational base in Namibia.
Accordingly, personal information may be transferred to, accessed from, stored, or processed in Namibia where reasonably necessary to administer bookings, communicate with guests, administer accommodation bookings, guest stays and any optional outdoor activities requested, respond to emergencies, manage incidents, comply with legal obligations, and otherwise operate our business.
Personal information may also be processed by our employees, accommodation staff, contractors, emergency response personnel, insurers, and service providers located in Namibia where this is necessary for the provision of our services.
Some of our third-party service providers may also process or store personal information in countries outside the Republic of South Africa.
Where personal information is transferred outside South Africa or accessed from another jurisdiction, we take reasonable steps, where appropriate, to ensure that such processing complies with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and to protect personal information through appropriate technical, organisational, contractual, or other lawful safeguards.
We will only transfer personal information across borders where such transfer is lawful under POPIA.
We take the security of your personal information seriously and implement reasonable technical and organisational measures to protect it.
We regularly review and update our security measures in order to identify and address reasonably foreseeable internal and external risks to personal information. These measures include secure hosting environments, SSL encryption for data transmission, password-protected systems, restricted administrative access, and the use of secure payment processing systems.
Although we take reasonable precautions to protect your personal information, no electronic system or internet-based transmission can be guaranteed to be completely secure.
We retain personal information only for as long as it is necessary to fulfil the purposes for which it was collected.
This includes retaining information for the duration of your customer relationship with us, to respond to enquiries, manage bookings and guest communications and for as long as required by applicable tax, accounting, or legal obligations.
This may include records relating to enquiries, quotations, bookings, guest registrations, waivers and indemnities, activity participation, accommodation arrangements, transport arrangements, emergency contact information, incidents, accidents, insurance matters, financial transactions, employment, and any other records reasonably required for operational, legal, regulatory, insurance, safety, security, audit, or risk management purposes.
Certain categories of personal information may be retained for longer periods where required by law or where retention is reasonably necessary to establish, exercise, or defend legal claims, comply with insurance, health and safety, or other legal obligations, investigate incidents or accidents, maintain safety records, resolve disputes, or satisfy regulatory requirements.
Where personal information is no longer required for the purpose for which it was collected and there is no lawful basis requiring its continued retention, we will take reasonable steps to securely delete, destroy, anonymise, or de-identify such information in accordance with applicable legal requirements and our internal record management practices.
We respect your privacy and are committed to giving you appropriate control over your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”).
Under POPIA, you have the following rights:
Access:
You may request access to the personal information we hold about you.
Correction:
You may request that we correct or update any inaccurate or incomplete personal information.
Deletion / Destruction:
You may request that we delete or destroy your personal information where we are no longer legally required to retain it, or where continued processing is not justified.
Objection to Processing:
You may object to the processing of your personal information where such processing is based on our legitimate interests, or where it relates to direct marketing.
Withdrawal of Consent:
Where processing is based on your consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing carried out before withdrawal.
Limitation of Processing:
Where permitted by POPIA, you may request that we limit or suspend the processing of your personal information in certain circumstances.
You may exercise any of your rights in relation to your personal information by submitting a request to our Information Officer using the contact details provided in this Privacy Policy.
Your request should include:
Where applicable, requests for access, correction, deletion, objection, or other rights relating to personal information may be submitted using the prescribed forms issued under POPIA and PAIA. We may request that you complete or provide such forms where required by law or where reasonably necessary to process your request efficiently.
In order to protect personal information and prevent unauthorised access, disclosure, deletion, or alteration of personal information, we may require reasonable proof of identity before processing a request.
Where necessary, we may request additional information or documentation to verify the identity and authority of the person submitting the request.
We reserve the right to refuse or delay requests where adequate verification cannot be obtained.
We will acknowledge receipt of requests within a reasonable period and aim to respond to all requests as soon as reasonably possible. We will generally respond to requests within 30 days of receipt. Where a request is complex, involves multiple records, requires additional verification, or cannot reasonably be completed within this period, we may extend the response period where permitted by law and will notify you accordingly. Certain requests may be limited, deferred, or refused where we are legally entitled or required to do so.
We maintain internal procedures for the receipt, verification, assessment, tracking, and resolution of requests relating to personal information.
Requests may be logged and retained where necessary for compliance, audit, security, fraud prevention, dispute resolution, record-keeping, and to meet applicable legal, regulatory, contractual, tax, and accounting obligations.
All requests are reviewed by authorised personnel and handled in accordance with applicable legal, regulatory, and security requirements.
Where permitted or required by law, we may refuse, partially fulfil, limit, or defer certain requests. Where a request cannot be fully completed, we will provide reasons where legally required.
In accordance with the Promotion of Access to Information Act 2 of 2000 (“PAIA”), we maintain a PAIA Manual which describes the categories of records held by us and explains how requests for access to such records may be made.
Requests for access to records may be submitted to our Information Officer using the contact details provided in this Privacy Policy.
We will reasonably assist requesters where necessary to ensure that requests are properly submitted and processed in accordance with applicable law.
Our PAIA Manual may be accessed on the Bundi main website here: https://bundi.co.za/paia-manual
In the event of a security compromise involving personal information, we will take immediate steps to investigate, contain, and mitigate the impact of the incident.
Where required under POPIA, we will notify affected individuals and the Information Regulator of South Africa as soon as reasonably possible. Such notification will include details of the nature of the breach, possible consequences, and measures taken or recommended to address the breach.
Notification does not constitute an admission of fault or liability.
Where you apply for employment, freelance work, or contract engagement with us, we may collect and process personal information provided during the recruitment process.
This may include your name, contact details, CV information, qualifications, employment history, and references.
Where necessary and permitted by law, we may conduct verification checks, which may include:
We process this information for the purposes of assessing suitability for employment or engagement, complying with legal obligations, and protecting the legitimate interests of the business.
Personal information collected during recruitment will only be retained for as long as necessary for recruitment purposes or as required by law.
If your application is unsuccessful, we may retain your information for future opportunities only where you have consented or where lawful retention is permitted.
Our services may be used by minors, including children under the age of 18, where accommodation bookings, reservations, activity registrations, or participation arrangements are made by a parent, legal guardian, school, tour operator, corporate organiser, or another authorised adult.
We may collect and process personal information relating to minors where such processing is necessary for:
Where personal information relating to a child or minor is collected or processed, we will do so in accordance with POPIA and only where the consent of a competent parent, legal guardian, authorised representative, or another lawful basis for processing exists, as required by applicable law.
We take reasonable steps to ensure that personal information relating to children is processed lawfully, securely, and only to the extent reasonably necessary for the purposes for which it was collected.
If a parent or guardian believes that we have collected personal information relating to their child unlawfully or without appropriate authorisation, they may contact our Information Officer using the contact details provided in this Privacy Policy. We will investigate the matter and, where appropriate, take reasonable steps to correct, delete, or restrict the processing of such information in accordance with applicable law.
Where bookings are made by schools, educational institutions, youth organisations, sports clubs, tour operators, or other authorised organisations on behalf of minors, we may receive and process personal information relating to participating children.
Such information may include participant names, ages, emergency contact details, medical information relevant to safety, dietary requirements, indemnity documentation, and other information reasonably necessary for accommodation management, guest safety and risk management.
We will process such information only for the purposes of administering bookings, ensuring participant safety, responding to emergencies, complying with legal obligations, and providing the services booked or requested.
Our website may contain links to third-party websites, applications, or services that are not operated or controlled by us. These third parties operate independently and have their own privacy and data protection policies. If you choose to access or interact with these third-party services, any personal information you provide will be processed in accordance with their respective privacy policies.
We encourage you to review the privacy policies of any third-party websites or services before providing them with personal information.
While we take reasonable care in selecting trusted service providers and partners, we are not responsible for the privacy practices, security measures, or content of third-party websites or services and do not accept liability for how they handle your information.
Some third-party providers may be located in, or operate from, jurisdictions outside of South Africa. In such cases, your personal information may be subject to the data protection laws of those jurisdictions. Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.
We may update this Privacy Policy from time to time in order to reflect changes in our practices, services, or legal obligations.
Whenever we make changes, we will update the “Last Updated” date at the top of this policy. Any significant changes will be clearly communicated on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information.
If you believe that your personal information has been processed in a way that is not compliant with POPIA, we encourage you to contact us first so that we can attempt to resolve your concern.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator of South Africa.
Website: https://inforegulator.org.za/
General Enquiries: enquiries@inforegulator.org.za
POPIA Complaints: POPIAComplaints@inforegulator.org.za
PAIA Complaints: PAIAComplaints@inforegulator.org.za
Telephone: 010 023 5200 / 0800 017 160
Physical Address:
Woodmead North Office Park
54 Maxwell Drive
Woodmead
Johannesburg
2191
For privacy-related questions, requests, or complaints, please contact our Information Officer using the contact details set out in Section 5 of this Privacy Policy.
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you agree to our privacy policy.
Websites store cookies to enhance functionality and personalise your experience. You can manage your preferences, but blocking some cookies may impact site performance and services.
Essential cookies enable basic functions and are necessary for the proper function of the website.
You can find more information in our Cookie Policy and Privacy Policy.