Privacy Policy
1. Who we are
PopiGuard is a product of Celagenix Business Advisory (Pty) Ltd t/a Celagenix Agency (“Celagenix”, “we”, “us”, “our”), a South African company. Celagenix is the responsible party (as defined in the Protection of Personal Information Act 4 of 2013, “POPIA”) for the personal information described in Section 3(a) below, and acts as an operator on behalf of our Compliance Hub subscribers for the personal information described in Section 3(b).
Registered address: 4th Floor West Wing, Nelson Mandela Square, Sandton City, Sandton, Johannesburg, 2196. Phone: 012 755 5528. Contact for privacy queries: popi@celagenix.com.
Key terms used in this policy (as defined in POPIA s.1): a data subject is the person to whom personal information relates: for example, you, if you use PopiGuard directly, or a resident, client, employee or visitor whose information your organisation processes using the Compliance Hub. A responsible party determines the purpose and means of processing. An operator processes personal information for a responsible party, on that party's instruction, without determining the purpose or means itself.
2. Scope
This policy covers the free Snapshot quiz (quiz.popiguard.co.za), the paid Assessment (assessment.popiguard.co.za), the Compliance Hub platform (app.popiguard.co.za), and this website (popiguard.co.za). It does not cover websites we link to, including celagenix.com.
3. What personal information we collect, and in what capacity
(a) Information we hold as responsible party: about you, our customer
- Free Snapshot quiz: your name (optional), email address, your quiz answers, and the resulting compliance score.
- Paid Assessment: your name, email, phone number (if provided), your organisation's name and type, your assessment answers, and billing details processed through our third-party payment provider (we do not store your card number; the payment provider processes payment directly).
- Compliance Hub account: your name, email, role (for example trustee, practitioner, or Information Officer), organisation, and login credentials (passwords are stored in hashed form, never in plain text).
- Support and correspondence: anything you send us by email or through a contact or support form.
(b) Information we hold as an operator: on behalf of your organisation
If your organisation subscribes to the Compliance Hub, it will use the platform to record its own compliance activity, for example compliance task records, policy documents, data subject request (DSR) logs (which may include the name and email of a member of the public making a request to your organisation), and data breach incident records (which may describe categories of affected personal information, including special personal information such as biometric or health data, without necessarily identifying specific individuals). We process this information strictly on your organisation's instructions, as its operator. Your organisation remains the responsible party for this data and is responsible for having its own lawful basis to collect and process it, including under its own privacy notice to its residents, clients, employees or visitors.
4. Why we process your information
- To provide the product or service you've signed up for (performance of a contract).
- To process payment for a paid Assessment or a Compliance Hub subscription (performance of a contract).
- To send you service-related emails (for example your quiz results, onboarding, task reminders) and, where you've agreed, marketing communications (consent).
- To maintain the security, integrity and audit trail of the platform (legitimate interest).
- To comply with our own legal obligations, including tax and accounting record-keeping.
5. What happens if you don't provide your information
Some information is required for us to provide the product or service you've signed up for. For example, we cannot create a Compliance Hub account without an email address, or process a paid Assessment without payment details. Where information is required, we'll indicate this at the point of collection; if you choose not to provide it, we may not be able to provide that specific product or service. This never affects information your organisation is required to collect from its own residents, clients, employees or visitors under its own privacy notice. That is a separate matter between your organisation, as responsible party, and its own data subjects.
6. Direct marketing
Where you have not already provided your details to us in the course of a sale, we will only send you direct marketing communications with your consent, as required by POPIA s.69(1). If you are an existing customer, we may send you marketing about our own similar products or services on an opt-out basis, as permitted by s.69(3). Every such email includes a way to unsubscribe. You can withdraw consent or opt out at any time by using the unsubscribe link in any marketing email, or by emailing popi@celagenix.com. Withdrawing consent does not affect service-related emails (for example task reminders or billing notices), which are not marketing.
7. Who we share information with
We use a small number of third-party operators to run PopiGuard. Each processes personal information only on our instruction and only to the extent needed to provide their service to us. By category, these are:
- Cloud hosting, database, authentication and file-storage providers.
- Email delivery providers (for account, transactional and, where consented, marketing email).
- A payment provider that processes subscription and assessment payments. We do not store your card details.
We do not sell personal information to any third party.
Information processed outside South Africa. Some of these providers process information outside the Republic, including in the European Union and the United States. Where personal information is transferred outside South Africa, we rely on the safeguards required by POPIA section 72, including binding agreements that require protections substantially similar to POPIA's conditions for lawful processing, and that govern any onward transfer.
8. How long we keep information
We keep account and billing information for as long as your account is active, plus a further period required by South African tax and accounting law. Free Snapshot leads are retained until you unsubscribe or ask us to delete them. Compliance Hub data you enter as an operator is retained per your organisation's own retention decisions and is deleted or exported at your organisation's instruction on termination of your subscription.
9. Security
The Compliance Hub keeps each organisation's data logically isolated at the database level, so that one organisation's data is never visible to another; encrypts data in transit; and maintains an audit log of key account and data actions. No system is completely secure, and we cannot guarantee absolute security, but we take the reasonable technical and organisational measures required by POPIA section 19 to protect the personal information we hold.
10. Data breach notification
If we become aware of a security compromise affecting personal information for which we are the responsible party, we will notify the Information Regulator and affected individuals as required by POPIA section 22. Where we act as an operator for your organisation's own compliance data, we will notify your organisation promptly so it can meet its own notification duties.
11. Your rights
Under POPIA, you have the right to:
- Access the personal information we hold about you (s.23);
- Request correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading or unlawfully obtained personal information (s.24);
- Object to processing of your personal information on reasonable grounds (s.11(3));
- Withdraw consent, where processing is based on consent (s.11(2)(b));
- Lodge a complaint with the Information Regulator (details below).
To exercise any of these rights, contact popi@celagenix.com. If your request concerns data your own organisation holds about you (rather than your relationship with Celagenix directly), it should be directed to that organisation's own Information Officer. The Compliance Hub's DSR Register exists to help that organisation handle your request.
12. Automated decision-making
PopiGuard does not use any automated process to make a decision about you that produces legal or similarly significant effects without human review. If we introduce any such feature, we will update this policy first.
13. Cookies
The Compliance Hub uses a strictly necessary session cookie to keep you signed in. We do not currently use analytics or marketing cookies on any PopiGuard property. If this changes, we will update this policy and, where required, ask for your consent first.
14. Children's information
PopiGuard is a business-to-business governance tool intended for adult trustees, practitioners, Information Officers and managing agents. It is not directed at children, and we do not knowingly collect personal information from children.
15. Changes to this policy
We may update this policy from time to time. Material changes will be notified to Compliance Hub subscribers by email.
16. How to complain to the Information Regulator
Information Regulator (South Africa)
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Phone: 010 023 5200 · toll-free 0800 017 160
Current postal and physical addresses are published at www.inforegulator.org.za.