Data Protection · 13 Sections

Privacy Notice

How the Mgazi Family Funeral Fund collects, uses, protects, and retains your personal data — and the rights you hold over it.

Last updated May 2026

Section 1

Who We Are

The Mgazi Family Funeral Fund ("the Fund", "we", "us") is a private family mutual aid association. The Fund Committee acts as the data controller for personal data collected and processed in connection with Fund administration. All data processing is carried out in accordance with applicable data protection law, including UK GDPR where relevant.

Section 2

What Data We Collect

We apply the principle of data minimisation — we collect only the personal data necessary to operate the Fund effectively. This includes:

Member Registration Data

  • Full name and date of birth
  • Contact details (email address, phone number)
  • Country of residence
  • Proof of identity (ID document, selfie for KYC verification)
  • Family relationship information
  • Contribution tier and payment method preferences

Beneficiary Data

  • Beneficiary names and contact details
  • Relationship to the member
  • Payout destination details (bank account or mobile wallet)

Financial Data

  • Contribution payment records and transaction references
  • Claims submitted, approved, and paid
  • Payment gateway transaction references (we do not store full card numbers)

Claims Documentation

  • Death certificates
  • Funeral invoices and receipts
  • Executor letters and beneficiary proof documents

Section 3

Why We Process Your Data

We process personal data only for specific, justified purposes with a defined legal basis:

Purpose Legal Basis
Administering membership and contributions Consent / Contract
Processing and verifying claims Contract / Legitimate interest
Preventing fraud and verifying identity (KYC) Legitimate interest
Complying with legal or regulatory obligations Legal obligation
Communicating with members (reminders, updates) Consent / Legitimate interest
Generating financial reports and member statements Legitimate interest

Section 4

Who Has Access to Your Data

Access to personal data is strictly controlled on a need-to-know basis. Each Committee role has access only to what is necessary to fulfil their function:

  • Treasurer: Financial records, contribution ledger, and payout destination details
  • Secretary: Member register, contact details, and meeting records
  • Claims Officer: Claim-related documents and beneficiary details
  • Chair & Trustees: Summary reports and claim approval records only

No member data is shared with unauthorised third parties. Payment processing data is handled exclusively by our payment gateway partners (Stripe, PayNow, PayFast) under their own privacy policies and applicable data protection obligations.

Section 5

Data Sharing

We may share your personal data only with the following parties, and only to the extent necessary:

  • Payment processors (Stripe, PayNow, PayFast) — to process contributions and assistance payouts
  • Legal or regulatory authorities — only where required by applicable law or a valid legal obligation
  • Professional advisors — accountants or lawyers engaged by the Fund, subject to confidentiality obligations

We do not sell, rent, license, or trade member personal data to any third party — under any circumstances.

Section 6

International Transfers

As the Fund operates across multiple countries — including the United Kingdom, South Africa, Zimbabwe, and others — personal data may be transferred internationally as part of normal Fund administration. We ensure appropriate safeguards are in place, including:

  • Using payment processors that maintain adequate data protection standards
  • Implementing role-based access controls regardless of geographic location
  • Limiting cross-border data transfers strictly to what is necessary for Fund administration

Section 7

Data Retention

We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law:

Data Category Retention Period
Financial records (contributions, payouts) 7 years minimum
Member registration data Duration of membership + 3 years
Beneficiary records Duration of membership + 7 years
Claims documentation 7 years from claim closure
Meeting minutes and governance records Indefinite

Section 8

Your Rights

Depending on your country of residence, you may hold some or all of the following rights in relation to your personal data:

Access

Request a copy of the personal data we hold about you.

Rectification

Request correction of any inaccurate or incomplete personal data.

Erasure

Request deletion of your personal data, subject to applicable retention obligations.

Restriction

Request that we limit processing of your data in certain defined circumstances.

Portability

Request your data in a structured, commonly used, machine-readable format.

Objection

Object to processing carried out on the basis of legitimate interests.

Withdraw Consent

Where processing is based on your consent, you may withdraw it at any time — without affecting prior lawful processing.

To exercise any of these rights, contact the Fund Secretary via the member platform or at the contact details provided upon registration. We will respond within the timeframe required by applicable law.

Section 9

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure, including:

  • Encrypted data transmission via HTTPS/TLS for all communications
  • Role-based access controls limiting data access to authorised personnel only
  • Secure authentication with enforced strong password policies
  • Regular review and audit of access permissions
  • Secure storage of sensitive documents and records

Section 10

Data Breach Procedures

In the event of a personal data breach, the following protocol is to be followed:

  1. The breach must be reported to the Committee within 24 hours of discovery.
  2. Affected members will be notified without undue delay once the scope and impact are assessed.
  3. Where required by applicable law (e.g., UK GDPR), the relevant supervisory authority — such as the Information Commissioner's Office (ICO) in the United Kingdom — will be notified within 72 hours of discovery.
  4. The breach, its effects, and all remedial actions taken will be fully documented.

Section 11

Cookies & Platform

The Fund platform uses essential cookies only — for user authentication and secure session management. No tracking, advertising, or analytics cookies are used by us. Third-party payment processors (Stripe, PayNow, PayFast) may use their own cookies when processing transactions, as described in their respective privacy policies.

Section 12

Changes to This Notice

This Privacy Notice may be updated periodically to reflect changes in our practices, legal obligations, or the services we provide. Members will be notified of any material changes. The most current version of this Notice is always available on the Fund platform.

Section 13

Contact

For privacy-related enquiries, to exercise your data rights, or to raise a concern about how your personal data is handled, please contact the Fund Secretary via the member platform or at the contact details provided upon registration. All privacy requests will be handled with diligence and in accordance with applicable law.