Privacy Policy
This Privacy Policy sets out the manner in which the Company collects, receives, records, organises, stores, updates, retrieves, uses, discloses, disseminates, merges, restricts, erases, or destroys personal information when Guardians, Subscribers, Minors, users, therapy practices, neurodiverse centres, visitors, or other authorised persons access or use the Company's websites, applications, products, services, support channels, and related platforms.
1. Responsible Party Details
For purposes of this Privacy Policy, the Company acts as the responsible party in respect of personal information processed under or in connection with the services, save where the Company processes personal information strictly on behalf of another responsible party. The Company determines the purpose of, and means for, processing personal information and undertakes to process such information lawfully, reasonably, and in a manner that does not unjustifiably infringe the privacy of data subjects, in accordance with the Protection of Personal Information Act, 4 of 2013, as amended from time to time.
The Company's designated Information Officer is Lizelle van der Walt. All notices, requests, objections, complaints, consent withdrawals, access requests, correction requests, deletion requests, and other privacy-related communications must be directed to the Company's designated privacy contact details as published or otherwise made available by the Company from time to time.
2. Personal Information We Collect
The Company may collect and process personal information that is adequate, relevant, and not excessive in relation to the purposes for which it is processed. Without limiting the generality of the aforegoing, the categories of personal information processed by the Company may include the following:
- Account and Subscriber information: name, surname, contact details, login details, organisation or practice details, subscription status, billing records, payment references, and support interactions.
- Guardian information: name, contact details, relationship to the Minor, consent records, parental control settings, and communications with the Company.
- Minor or user information: name or handle, age band, profile details, in-app activity, progress data, developmental metrics, usage history, learning or gameplay progress, and safety or support interactions.
- Technical and device information: device type, operating system, app version, IP address, browser information, crash logs, diagnostic data, cookies or similar technologies, and system performance information.
- Practice or centre information: information submitted by neurodiverse centres, therapy practices, professionals, administrators, or authorised staff when they use the Company's services.
Where the services involve therapy practices, neurodiverse centres, clinical observations, developmental assessments, health-related notes, professional observations, or similar information, such information may constitute special personal information as contemplated under POPIA. The Company will process special personal information only where authorised by law, including where appropriate consent has been obtained, where processing is necessary for the provision of services involving a professional subject to a duty of confidentiality, or where another lawful ground for processing is applicable.
3. Purposes for Processing Personal Information
The Company processes personal information for specific, explicitly defined, and lawful purposes, including, without limitation, to provide, operate, maintain, secure, administer, and improve the services; create, verify, and manage accounts; enable Guardian oversight and parental control functionality; provide progress dashboards, reports, and related functionality; process subscriptions, billing, and payments; respond to support requests; maintain service integrity and security; investigate suspected misuse, abuse, unlawful activity, or technical incidents; comply with applicable laws, regulatory obligations, contractual obligations, and lawful requests; communicate service, legal, security, or operational updates; and improve product performance, accessibility, reliability, and user experience.
4. Consent and Guardian Involvement
Where a Minor accesses or uses the services, the Company requires the involvement and consent of a competent Guardian before collecting or otherwise processing the Minor's personal information, unless otherwise permitted or required by applicable law. The Company may retain records of consent, account actions, changes to consent, consent withdrawals, notices, and related communications for compliance, evidentiary, safety, and service-administration purposes.
A Guardian may withdraw consent, object to processing, or request access to, correction of, deletion of, or restriction of processing of a Minor's personal information by contacting the Company using the designated privacy contact details. Withdrawal of consent will not affect the lawfulness of processing undertaken before such withdrawal and may limit or prevent the Company from providing all or part of the services where the relevant processing is necessary for service delivery, safety, compliance, or account administration.
5. Sharing Personal Information with Operators and Third Parties
The Company may disclose personal information to duly authorised operators and service providers that process personal information on behalf of, or in support of, the Company, including hosting providers, payment providers, analytics providers, support tools, communications providers, platform providers, software providers, security providers, and other service providers reasonably required to provide, secure, maintain, support, or improve the services. Such operators and service providers are required to process personal information only in accordance with the Company's instructions and to implement appropriate confidentiality, security, and data-protection safeguards.
The Company may further disclose personal information where required or permitted by law; where necessary to enforce its agreements, policies, or legal rights; where necessary to protect the rights, property, safety, or security of the Company, users, Minors, Guardians, Subscribers, service providers, or third parties; where necessary to investigate suspected misuse, fraud, abuse, unlawful conduct, or technical incidents; or in connection with a proposed or actual merger, acquisition, restructuring, sale of assets, financing transaction, or similar business transaction, subject to appropriate safeguards.
6. Cross-Border Transfers
Certain operators, service providers, systems, or infrastructure used by the Company may be located outside the Republic of South Africa or may result in personal information being transferred to, accessed from, or stored in another jurisdiction. Where the Company transfers personal information outside South Africa, it will take reasonable steps to ensure that the recipient is subject to a law, binding corporate rules, binding agreement, consent mechanism, contractual obligation, or other safeguards that provide an adequate level of protection as required by POPIA.
7. Retention of Personal Information
The Company will retain personal information only for as long as is reasonably necessary to fulfil the purposes for which such information was collected or subsequently processed, unless retention for a longer period is required or permitted by applicable law, contract, operational necessity, audit requirements, dispute-resolution purposes, security requirements, legitimate business interests, or compliance obligations.
The Company will not delete or destroy a Minor's personal information merely as a contractual penalty where continued retention is required by law, necessary for evidentiary purposes, necessary to resolve a dispute, necessary to protect a Minor or another person, or otherwise reasonably required in accordance with POPIA. Once personal information is no longer required, the Company will, where reasonably practicable, securely delete, destroy, de-identify, or restrict access to such information.
8. Data Subject and Guardian Rights
Data subjects, and Guardians acting on behalf of Minors where legally competent or authorised to do so, may exercise the rights afforded to them under POPIA, including the right to request access to personal information; request correction, destruction, or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained; object to certain processing; request restriction of processing where applicable; and request information regarding third parties to whom personal information has been disclosed.
All privacy-related requests must be submitted to the Company using the designated privacy contact details. The Company may require reasonable verification of identity, authority, Guardianship, or legal capacity before giving effect to any request. The Company will consider and respond to such requests within a reasonable period and may refuse, defer, or limit a request to the extent permitted or required by applicable law.
9. Security Safeguards
The Company will implement and maintain reasonable, appropriate technical and organisational measures designed to secure the integrity and confidentiality of personal information in its possession or under its control and to guard against the risk of loss, damage, unauthorised access, unauthorised processing, unlawful disclosure, alteration, destruction, or interference. Such safeguards may include access controls, authentication measures, encryption where appropriate, secure hosting practices, logging, monitoring, staff and contractor confidentiality obligations, vendor due diligence, operator controls, and incident-response procedures.
Notwithstanding the Company's security safeguards, no information system can be warranted to be entirely secure. If the Company has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the Company will assess the incident and, where required by law, notify the Information Regulator and affected data subjects or Guardians as soon as reasonably practicable.
10. Cookies, Analytics, and Product Improvement
The Company may use cookies, analytics technologies, diagnostic tools, software development kits, and similar technologies to operate the services, remember preferences, authenticate users, understand usage patterns, identify errors, improve functionality, support security, and enhance service performance. Where required by applicable law, the Company will provide appropriate notice and obtain consent before using non-essential technologies.
11. Direct Marketing and Communications
The Company may send service-related communications that are necessary or reasonably required for account administration, security, support, legal notices, operational updates, billing, or service functionality. The Company will send direct marketing communications only where permitted by applicable law, including where valid consent has been obtained or where another lawful basis exists. Recipients may opt out of direct marketing communications by using the unsubscribe, opt-out, or preference-management mechanism made available by the Company.
12. Complaints
If a data subject, Guardian, Subscriber, user, or other person has a privacy-related concern, complaint, objection, or request, that person is encouraged to contact the Company in the first instance so that the Company may investigate and attempt to resolve the matter. Nothing in this Privacy Policy limits any right to lodge a complaint with the Information Regulator of South Africa where a person believes that personal information has been processed unlawfully or that their rights under POPIA have not been respected.
Information Regulator contact details: Website: https://inforegulator.org.za; General enquiries: enquiries@inforegulator.org.za; POPIA complaints: POPIAComplaints@inforegulator.org.za; Telephone: 010 023 5200; Toll-free: 0800 017 160; Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191.
13. Changes to This Privacy Policy
The Company may amend, update, or replace this Privacy Policy from time to time to reflect changes in the services, applicable law, regulatory guidance, technical systems, third-party providers, business operations, or privacy practices. Where changes are material, the Company will take reasonable steps to notify affected users, Guardians, Subscribers, or other relevant persons by means of the services, email, notice, or another appropriate communication channel. The updated Privacy Policy will apply from the effective date indicated in the updated version or, if no effective date is indicated, from the date on which it is published or otherwise made available.