Privacy Policy



LEISURE PORTFOLIO MANAGEMENT ASSOCIATION PRIVACY & COOKIES POLICY



Registration number: 2006/010725/08
Last reviewed: August 2026
1. Introduction
Leisure Portfolio Management Association NPC (“LPA”, “we”, “us” or “our”) respects your privacy and is committed to processing Personal Information lawfully, reasonably and securely.

This Privacy and Cookies Policy explains:

what Personal Information we collect;
where we obtain it;
why and on what grounds we process it;
when and with whom we share it;
how we handle international transfers;
how long we retain it;
how we protect it;
how we use cookies and similar technologies; and
the rights available to you.

This Policy applies to Personal Information processed through our website and in connection with prospective, current and former membership, agreements, reservations, accommodation, exchanges, payments, enquiries, complaints and related services, whether collected online, telephonically, electronically, in writing, in person or through an authorised service provider.

Our website is available at:
[www.leisureportfolio.co.za](http://www.leisureportfolio.co.za)

This Policy must be read together with any specific collection notice, agreement, application form, marketing consent choice, website terms or service provider terms presented to you.

2. Applicable Law
We process Personal Information in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”), the Promotion of Access to Information Act 2 of 2000 (“PAIA”), the Consumer Protection Act 68 of 2008 and other applicable South African laws.

The terms “Personal Information”, “processing”, “responsible party”, “operator”, “data subject” and “special personal information” have the meanings assigned to them in POPIA.

3. Who this Policy Applies To
This Policy applies to Personal Information relating to:

prospective, current and former LPA Members, including joint Members;
authorised representatives and persons holding powers of attorney;
guests, occupants and travelling companions;
users of our website and digital services;
persons who contact or correspond with us;
service providers, contractors and business contacts; and
other identifiable natural or juristic persons whose information we lawfully process.

Where a Member provides Personal Information about a guest, travelling companion, joint Member or another person, the Member must be authorised to provide that information and must, where reasonably practicable, direct the person concerned to this Policy.

4. Personal Information We May Process
Depending on our relationship with you and the services you use, LPA may process Personal Information including:

identity and contact information, such as your name, identity or passport details, contact details, preferred language and information used to verify your identity;
membership and ownership information, including membership numbers, ownership or usage rights, resort, unit, week or points information, levy status, eligibility information and details of authorised representatives;
reservation, accommodation and exchange information, including the provider selected, booking and travel dates, accommodation details, exchanges or space-banking, guest and travelling-companion details, special accommodation requirements and the details of persons authorised to transact on your behalf;
financial and transactional information, including banking details, debit-order mandates and instructions, invoices, levies, fees, payments, refunds, account status and arrears;
communications and service information, including correspondence, enquiries, instructions, complaints, service requests, call recordings, security-verification records, feedback and marketing preferences; and
website and technical information, including IP address, device and browser information, login and account activity, cookies, security logs and information about the use of our website and electronic communications.

Where calls are recorded, callers will be notified before or at the commencement of the recording. Recordings will be used only for disclosed and lawful purposes such as verification, quality assurance, staff training, dispute management, fraud prevention and record keeping.

We will only collect and process Personal Information that is reasonably necessary for the relevant purpose.

Where payment processing is performed by an authorised payment provider, LPA does not ordinarily retain complete payment-card authentication data. The payment provider’s own privacy and security terms may apply to its processing.

4.1 Special Personal Information and Children’s Information
LPA may process special personal information or Personal Information relating to children where:

it is reasonably necessary to provide a requested reservation, accommodation, competition, promotion or related service;
a competent person has consented where consent is required; or
the processing is otherwise permitted by law.

This may include information concerning:

a child guest or travelling companion;
an accessibility, health or dietary requirement voluntarily provided for a requested service; or
a child’s participation in a competition, prize, promotional activity or family-related member benefit.

Where a child participates in a competition or promotion, we may process information reasonably necessary to administer the activity, verify eligibility, contact the competent person, award or deliver a prize and comply with legal or record keeping requirements.

5. How We Collect Personal Information
We may collect Personal Information:

directly from you;
through application forms, membership agreements and service requests;
when you use our website, Member portal or other digital services;
when you contact us by telephone, email, online form or other means;
during identity or Member verification;
when you make or amend a reservation;
when you check in at or use a resort or accommodation provider;
when you request registration with an exchange, reservation or travel provider;
when you make a payment or receive a refund;
from a joint Member or authorised representative;
from a resort, property manager or accommodation provider;
from an exchange or reservation provider;
from a payment, billing or collection provider;
from an affiliated service provider assisting with a requested service;
from fraud-prevention, identity-verification and information-security providers, where lawful and reasonably necessary;
from publicly available or regulatory sources where lawful; and
automatically through cookies, logs and similar technologies when you use our website.

Where Personal Information is obtained from another source, we will provide the notices required by law unless an applicable exception permits otherwise.

6. Grounds on Which We Process Personal Information
Depending on the circumstances, we process Personal Information where:

you have consented;
processing is necessary to conclude or perform an agreement with you;
processing is necessary to implement measures requested by you before entering into an agreement;
processing is required to comply with a legal obligation;
processing protects your legitimate interests;
processing is necessary to pursue the legitimate interests of LPA or a third party, unless your rights and interests require protection; or
processing is otherwise permitted by law.

We do not rely on consent where another lawful ground is more appropriate. Where we rely on consent, you may withdraw it, although withdrawal may affect a service where the relevant information cannot lawfully or practically be processed on another ground and is necessary to provide that service.

Withdrawal of consent does not affect processing that occurred lawfully before withdrawal.

7. Why We Process Personal Information
We process Personal Information where reasonably necessary to:

administer membership, ownership, accounts, payments and related agreements;
register Members with selected exchange or service providers and provide reservations, accommodation, exchange and related services;
communicate with Members, provide support, protect accounts, prevent fraud, facilitate exchanges and enhance membership benefits and comply with legal obligations; and
improve our services and send marketing where permitted by law and in accordance with your marketing choices.

8. Registration with RCI, 7Across and GoMelo
Where applicable, LPA may disclose Personal Information to the following providers for membership registration and administration. The Member acknowledges that access to exchange and booking networks, including RCI, 7Across and GoMelo, forms an integrated benefit of LPA membership, providing economic value and booking flexibility that outweighs purchasing standalone exchange subscriptions.

8.1 RCI
LPA discloses relevant Personal Information to Vacation Exchanges International (Proprietary) Limited, registration number 1990/005818/07, trading as RCI Africa (“RCI”), to:

register or enrol you as an RCI member;
establish and maintain your RCI membership;
provide and administer vacation exchange services;
process exchanges, bookings and space-banking transactions;
verify membership, ownership, levy and eligibility information;
update Member information;
report on bookings and exchange transactions; and
communicate with you about your RCI membership and requested services.

Personal Information disclosed may include your name, contact details, identity or passport information, month and year of birth, preferred language, LPA and RCI membership numbers, ownership or eligibility information, and relevant reservation, resort, unit, guest and transaction information.

RCI may process Personal Information as a separate responsible party for its own membership and service purposes. RCI’s processing is governed by its applicable privacy notice, available at:

https://www.rci.co.za/Account/PrivacyPolicy

8.2 7Across
Where you are eligible for or elect to use 7Across, LPA may disclose relevant Personal Information to 7Across and the applicable legal entity operating or administering that service to:

register or enrol you as a Member;
create and maintain your 7Across membership profile;
confirm eligibility;
process exchange, deposit and reservation activity;
communicate service and transactional information; and
administer the 7Across services selected by you.

The information disclosed will be limited to what is reasonably necessary for registration and the selected service. It may include identity, contact, membership, ownership, eligibility, reservation, guest and transaction information.

7Across’s privacy information is available at:

https://www.7across.com/legals/privacy

8.3 GoMelo
Where you are eligible for or elect to use GoMelo, LPA may disclose relevant Personal Information to GoMelo and the applicable legal entity operating or administering that service to:

register or enrol you as a Member;
create and maintain your GoMelo profile;
verify eligibility;
enable access to accommodation and reservation services;
process bookings, payments, guest information and service requests; and
administer the GoMelo services selected by you.

The information disclosed will be limited to what is reasonably necessary for registration and the selected service. It may include identity, contact, membership, eligibility, reservation, guest and transaction information.

You should review the privacy notice and terms presented by GoMelo during registration or use of its services.

8.4 Other Providers Selected by the Member
You may elect to use other exchange, reservation, accommodation, travel or benefit providers. Where you do so, LPA may share the Personal Information reasonably necessary to register you, arrange and administer the selected service, process payments and fulfil your instructions.

Before or when the relevant information is disclosed, you may be presented with the provider’s applicable terms and privacy notice. LPA encourages you to review those documents before using the service.

9. Other Parties With Whom We May Share Personal Information
LPA may also share Personal Information with payment and debit order providers, professional advisers, technology and administrative service providers, and authorities where reasonably necessary or required by law. We do not sell Personal Information and limit disclosures to what is reasonably necessary.

10. Service Providers’ Privacy Practices
Certain exchange, reservation, accommodation and travel providers independently determine how and why they process Personal Information. Those providers may therefore act as separate responsible parties.

Where a recipient acts independently:

its own terms and privacy notice will apply to its processing;
it is responsible for complying with applicable privacy law;
requests relating to its independent processing may need to be directed to that provider; and
LPA cannot amend or control that provider’s privacy policy.

LPA will provide available links or information concerning relevant provider privacy notices where reasonably practicable.

11. International and Cross-Border Transfers
RCI, 7Across, other exchange providers and some of our technology, cloud, reservation, support and fulfilment providers may operate internationally or use systems, personnel or servers situated outside South Africa.

Your Personal Information may therefore be accessed from, processed in, stored in or transferred to another country where reasonably necessary for a purpose described in this Policy.

LPA will only transfer Personal Information outside South Africa where permitted in accordance with section 72 of POPIA or other applicable law, including where the recipient is subject to law, binding corporate rules or agreements which provide protections substantially similar to the conditions for the lawful processing of Personal Information, the data subject has consented, the transfer is necessary to perform or conclude an agreement with or in the interest of the data subject, or the transfer benefits the data subject and obtaining consent is not reasonably practical. Where appropriate, we use contractual, organisational and technical measures designed to protect Personal Information transferred internationally.

Privacy and data-protection laws in a recipient country may differ from South African law. You may contact the appointed Information Officer for further information about the safeguards applicable to a material international transfer involving your Personal Information. LPA encourages Members to review the privacy policies of all providers before using their services.

12. Service Communications
LPA and relevant providers may send operational communications necessary to manage your membership or requested services, including account, payment, booking, resort, security, legal and support notices.

Because these communications are reasonably necessary to administer the applicable agreement, provide a requested service, protect an account or comply with law, they are not treated as optional direct marketing. You may request a different communication channel where reasonably practicable, but LPA may continue sending communications that are legally or operationally necessary.

13. Direct Marketing and Marketing Choices
13.1 LPA Marketing
Where permitted by law, LPA may send marketing about its own services, benefits and offers.

Where consent is required, we will obtain it in the prescribed or otherwise legally compliant manner. You may refuse or withdraw marketing consent without losing access to services that do not depend on that consent.

Every electronic marketing communication will provide an appropriate method to unsubscribe or object.

For the avoidance of doubt, any transactional communications relating to memberships, reservations, payments, legal notices and account administration are not regarded as direct marketing and cannot be opted out of where reasonably necessary to perform the agreement.

13.2 Marketing by RCI, 7Across, GoMelo and Other Providers
RCI, 7Across, GoMelo or another provider may market its own or similar services to you where permitted by law, including on the basis of your existing relationship with that provider. Registration or use does not constitute consent to unrelated or third-party marketing.

Where consent is required, you will be given a separate choice. Marketing is governed by the relevant provider’s privacy policy and must include an appropriate opt-out method. Requests to withdraw may need to be submitted directly to that provider, although LPA will provide reasonable assistance where appropriate.

13.3 Withdrawing or Changing Marketing Choices
You may withdraw marketing consent or object to LPA’s direct marketing at any time by using the unsubscribe facility, contacting LPA or using any preference facility made available by LPA. We may retain a limited suppression record to ensure that your opt-out continues to be honoured.

13.4 National Opt-Out Registry
LPA will comply with applicable requirements relating to the National Consumer Commission’s Opt-Out Registry.

Where the Registry is operational and applicable to a proposed marketing activity, LPA will take the required steps to screen or cleanse its marketing records against applicable pre-emptive blocks, and refrain from directing marketing communications to data subjects who have registered an applicable block, unless the communication is otherwise lawfully permitted.

14. Cookies and Similar Technologies
Our website uses cookies and similar technologies.

A cookie is a small data file placed on or associated with your device when you visit a website. Cookies may enable the website to function, maintain security, remember preferences, analyse usage or support advertising.

Depending on the functionality used on our website, we may use:

Strictly Necessary Cookies
These cookies are required for website security, network management, login, session continuity, forms, payments or other essential functions. The website may not operate correctly without them.

Preference Cookies
These cookies remember choices such as language, display settings or other preferences.

Analytics Cookies
These cookies help us understand how visitors use our website, identify technical problems and improve performance.

Advertising or Targeting Cookies
Where used, these cookies may help measure advertising, limit repeated advertisements or tailor content according to browsing activity.

14.1 Cookie Choices
Where required, non-essential cookies will be used according to your cookie choices.

Our cookie controls should allow you to:

accept cookies;
reject non-essential cookies;
select cookie categories; and
change your preferences later.

You may also control cookies through your browser settings. Blocking cookies may affect website functionality.

14.2 Third-Party Technologies
Some website functions may be provided by third parties, such as analytics, embedded content, payment, mapping, social media or security providers. Those providers may place or access their own cookies subject to their privacy and cookie notices.

Further details about the cookies currently used, their providers, purposes and duration should be provided in LPA’s cookie preference centre or cookie schedule.

15. Accuracy of Personal Information
We take reasonably practicable steps to maintain Personal Information that is complete, accurate, not misleading and updated where necessary.

You should provide accurate information and notify us when relevant information changes, particularly:

identity and contact information;
joint Member or representative information;
ownership or membership status;
guest information; and
information affecting a reservation or selected service.

We may share authorised updates with RCI, 7Across, GoMelo or another selected provider where necessary to keep the relevant membership or transaction record accurate.

Failure to keep Personal Information accurate may affect LPA's ability to provide certain services.

16. Security
We take reasonable and appropriate measures to protect Personal Information against loss, unauthorised access, disclosure, misuse and unlawful processing.

No system is completely secure. Members should safeguard their login details and promptly report suspected account misuse or fraud.

17. Security Incidents
Where LPA has reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, LPA will notify the Information Regulator and affected data subjects as soon as reasonably possible after discovery of the compromise, subject to any lawful delay or direction by a law-enforcement authority and the other requirements of POPIA.

Notices will contain the information required by law and will be communicated through an appropriate channel, considering the circumstances and the reasonably known risks.

18. Retention and Destruction
We retain Personal Information only for as long as reasonably necessary to fulfil the purpose for which it was collected or subsequently processed as described in this Policy. Retention periods are determined with reference to LPA’s documented retention schedule, the nature and sensitivity of the information, the relevant processing purpose and applicable legal limitation or record-keeping periods.

Once LPA is no longer authorised to retain Personal Information, the information will be securely destroyed, deleted or de-identified in a manner that prevents its reconstruction and in accordance with applicable law.

We may retain limited information needed to honour marketing objections or unsubscribe requests.

19. Automated Decision Making
We do not ordinarily make decisions based solely on automated processing that produce legal consequences or have a similarly significant effect on a person.

If we introduce such processing, we will do so only where permitted by law and will provide appropriate information and safeguards.

Automated security, fraud-detection or availability tools may flag an activity or request for human review without making a final legally significant decision.

20. Your Rights
You have the right, subject to applicable law, to request confirmation that LPA holds Personal Information about you, to request access to, correction or deletion of your Personal Information; object to certain processing or direct marketing; withdraw consent; and lodge a complaint with the Information Regulator.

We may require proof of identity and may refuse or limit a request where permitted or required by law. PAIA procedures may apply to formal access requests.

21. Complaints to the Information Regulator
You may lodge a complaint with the South African Information Regulator.

Current contact and complaint information is available at:
https://inforegulator.org.za

We encourage you to contact our Information Officer first so that we have an opportunity to investigate and respond, but this does not prevent you from approaching the Information Regulator directly.

22. External Links
Our website or communications may contain links to third-party websites or services. We do not control these services, which are governed by their own privacy policies and terms.

23. Contact Details
Questions, objections, requests or complaints relating to this Policy or LPA’s processing of Personal Information may be directed to:

Responsible Party:
Leisure Portfolio Management Association NPC (2006/010725/08)

Information Officer:
Charlene van den Berg

Deputy Information Officer:
Sharon Ferreira

Physical Address:
Mooikloof Office Park East
Corner Atterbury Road and Jollify Main Road
Mooikloof, Pretoria
0059

Postal Address:
PO Box 35580
Menlo Park
Pretoria
0102

General Email:
[enquiries@leisureportfolio.co.za](mailto:enquiries@leisureportfolio.co.za)

Privacy or Information Officer Email:
[charlenev@vrs-services.co.za](mailto:charlenev@vrs-services.co.za)

Telephone:
+27 (0)12 996 5106

Website:
[www.leisureportfolio.co.za](http://www.leisureportfolio.co.za)

PAIA Manual is available on our website.

24. Changes to this Policy
We may update this Policy to reflect changes in law, our services, technology, exchange or service providers, or our processing practices.

The current version will be published on our website with its effective date and version number.

Where a change is material, we will take reasonable steps to bring it to the attention of affected persons.

Previous versions may be obtained from us where reasonably required.

25. Interpretation and Governing Law
This Policy shall be interpreted in accordance with the laws of the Republic of South Africa.

Nothing in this Policy excludes, limits or waives any right or obligation under POPIA, PAIA or other applicable law.

If any provision conflicts with mandatory law, the mandatory law will apply, and the remaining provisions will continue to operate to the extent possible.