Grindrod Terminals TLT
Privacy Notice
This notice explains how personal information is processed when authorised users access and use the TLT operational application.
Last updated: 23 July 2026
1. Who we are and the scope of this notice
Grindrod Limited and the relevant Grindrod group company operating TLT are committed to processing personal information lawfully, reasonably, transparently and securely. This notice applies to TLT user accounts, security and audit records, and personal information contained in operational records processed through TLT.
TLT supports terminal, rail, vessel, road, stock, maintenance, tyre and related administrative operations. It is not intended for advertising, competitions or consumer marketing.
2. Personal information processed by TLT
The information processed depends on your role and the workflow you use. It may include:
- Account and profile information: name, surname, username, email address, telephone number where supplied, profile picture, assigned roles, account status and company or terminal access.
- Security and technical information: login date and time, successful or unsuccessful login status, attempted username, IP address, browser/user-agent information, system name and security or role changes.
- Operational contact information: driver, operator, employee, supervisor, manager, customer, transporter, supplier or other business-contact details entered into authorised TLT workflows.
- User activity and operational records: records you create, approve, update or confirm, together with timestamps and audit information.
- Information received from connected systems: operational data obtained from authorised Grindrod or third-party systems, including Falcon and other terminal integrations, where required for TLT operations.
TLT should only be used to enter personal information that is necessary for an authorised business purpose. Users must not enter passwords, identity documents, medical information or other sensitive information into free-text fields unless the approved process expressly requires it.
3. How and why we use personal information
Personal information may be processed to:
- create and administer user accounts and confirm that users are authorised;
- provide, operate and support terminal and logistics workflows;
- apply role-based access and company or terminal restrictions;
- maintain audit trails, investigate incidents and protect systems and information;
- send operational, security and account-related notifications;
- produce operational reports, forecasts, statistics and performance dashboards;
- meet contractual, employment, safety, legal, regulatory and record-keeping duties; and
- establish, exercise or defend legal rights.
Processing is based on the applicable lawful justification, which may include performance of a contract, compliance with legal obligations, legitimate operational and security interests, or consent where consent is legally required. Accessing TLT does not turn consent into the legal basis for every processing activity.
4. Cookies and similar technologies
TLT uses cookies and browser storage that are necessary to provide and protect the service, including:
- authentication cookies that keep an authorised user signed in;
- session cookies used to maintain application state;
- security and anti-forgery cookies used to protect requests; and
- a remembered-login cookie when the user selects Remember me.
The login page uses Cloudflare Turnstile to help distinguish legitimate users from automated activity. Some pages may embed Tableau dashboards or load approved third-party web resources; those providers may process technical information or set their own cookies under their applicable notices.
5. Sharing and transfers
Access is limited according to business need and assigned permissions. Information may be shared with:
- authorised employees, contractors and Grindrod group companies;
- technology, hosting, email, security, dashboard and support service providers;
- customers, suppliers or operational partners where necessary for the relevant workflow;
- auditors, professional advisers, regulators, law-enforcement bodies or courts; and
- other recipients where disclosure is required or permitted by law.
Where personal information is processed outside South Africa, appropriate contractual, organisational and legal safeguards must be applied in accordance with applicable law and Grindrod policy.
6. Retention
Personal information is retained only for as long as required for the operational purpose, contractual or legal obligations, audit and security requirements, dispute management and approved retention schedules. Information may remain in protected backups until those backups are securely overwritten or expire.
7. Security and user responsibilities
Grindrod applies administrative, technical and physical safeguards designed to prevent loss, misuse, unauthorised access, alteration or disclosure. These include access controls, authentication, audit records, secure communications, monitoring and incident-management procedures.
Every TLT user must:
- keep login credentials confidential and use only their own account;
- access information only for an authorised business purpose;
- check that information entered is accurate and necessary;
- sign out or lock the workstation when unattended; and
- report suspected unauthorised access, disclosure or loss immediately through the approved incident channel.
8. Predictions and automated processing
TLT may generate forecasts or predicted completion information to support operational planning. These outputs are decision-support information and should be reviewed by an authorised user. TLT is not intended to make decisions that produce legal or similarly significant effects about a person solely through automated processing.
9. Your rights
Subject to POPIA and other applicable law, you may have the right to:
- ask whether Grindrod holds personal information about you and request access;
- request correction, updating or deletion of inaccurate or unlawfully retained information;
- object to processing in the circumstances provided by law;
- withdraw consent where processing is based on consent, without affecting prior lawful processing; and
- lodge a complaint with the Information Regulator (South Africa).
Grindrod may need to verify your identity and may retain information where retention is required or permitted by law. Requests relating to operational records may also require consultation with the relevant record owner.
10. Contact and complaints
For privacy enquiries, requests or concerns, use the approved Grindrod privacy or Information Officer channel, or contact Grindrod through: www.grindrod.com/contact-us .
You may also consult the full Grindrod Privacy Notice .
Complaints may be submitted to the Information Regulator (South Africa) using its current published complaint process and contact details.
11. Changes to this notice
This notice may be updated when TLT functionality, processing activities, service providers or legal requirements change. The latest version will be published on this page with its revision date.