⚠ Draft pending attorney sign-off. This document still contains unresolved [PLACEHOLDER: …] items and must not be treated as final until they are completed and it is dated.
SparkED — Privacy Policy Effective date: [PLACEHOLDER: Effective Date] Last updated: [PLACEHOLDER: Last Updated Date]
1.1 This Privacy Policy explains how Incendio Digital Labs (Pty) Ltd ("Incendio", "we", "us", "our") collects, uses, stores, shares, and protects Personal Information in connection with SparkED (the "Service"), including for registered Users and for visitors to a published public Profile.
1.2 This Policy should be read together with our Terms of Service and our POPIA Notice.
2.1 Incendio Digital Labs (Pty) Ltd, registration number [PLACEHOLDER], is the "responsible party" (as defined in POPIA) for the Personal Information described in this Policy.
Registered address: [PLACEHOLDER] Contact: deon@incendiogroup.co.za
2.2 Our appointed Information Officer's details are set out in clause 16 below.
3.1 Account and Profile information, provided by you: name, email address, phone number, WhatsApp number, job title, company name, bio, profile photograph, company logo, and social media or website links.
3.2 Relationship Entries: where you choose to add them, the name and contact details of third parties you wish to feature on your Profile.
3.3 Billing information: your payments are processed by Paystack. We receive limited transaction metadata (such as a payment reference, status, and amount) but do not receive or store your card or bank account details.
3.4 Usage and analytics information: a hashed (one-way, non-reversible) version of your IP address, and your user-agent/device string, together with timestamps and records of feature use and Profile views. This is collected both for registered Users and for visitors who view a published public Profile.
3.5 Authentication and security information: your password, stored only in hashed form; your 2FA enrolment status; and one-time passwords ("OTPs") used to verify logins or actions, which are short-lived.
4.1 Most information is provided directly by you when you register, complete your Profile, or contact us.
4.2 Usage and analytics information is collected automatically when the Service, or a published Profile, is accessed — including by visitors who are not registered Users.
5.1 We process Personal Information for the following purposes, on the following legal bases:
| Purpose | Personal Information involved | Lawful basis |
|---|---|---|
| Creating and operating your account and Profile | Account/Profile information | Performance of a contract with you; your consent |
| Enabling sharing via Public Link, QR, vCard, NFC | Account/Profile information | Performance of a contract with you |
| Publishing a Relationship Entry you add | Relationship Entry data | Performance of our contract with you; the consent you warrant you have obtained from the third party (clause 7.2 of the Terms) |
| Processing payment for paid plans | Transaction metadata | Performance of a contract with you |
| Account security, fraud prevention, and abuse detection | Hashed IP, user-agent, login/security logs, OTPs | Our legitimate interest in securing the Service and our Users' accounts, together with performance of contract |
| Service analytics and improvement | Hashed IP, user-agent, usage data | Consent; our legitimate interest in understanding and improving the Service |
| Legal and regulatory compliance (e.g. tax, accounting records) | Billing metadata | Compliance with a legal obligation |
5.2 Where we rely on your consent, that consent is captured at registration by way of a checkbox, and is recorded together with the date, time, and version of this Policy and our Terms then in force.
6.1 We share Personal Information with the following service providers ("sub-processors"), each engaged under a written agreement, strictly to enable us to provide the Service:
| Sub-processor | Role | Location |
|---|---|---|
| Vercel | Application hosting | United States |
| Neon | Database hosting (PostgreSQL) | United States |
| Resend | Transactional email delivery | United States |
| Paystack | Payment processing | South Africa / Nigeria |
| Cloudflare | DNS, content delivery network, and security | Global network, including the United States |
6.2 We do not sell your Personal Information to any third party.
6.3 Other users or visitors who access your published public Profile will see the information you have chosen to include in it. This is not a "sharing" arrangement with a sub-processor; it is the intended function of a public Profile that you control.
7.1 As set out in clause 6 above, some of our sub-processors store or process Personal Information outside the Republic of South Africa, principally in the United States, and in the case of Paystack, potentially in Nigeria as well as South Africa.
7.2 South Africa's Information Regulator has not published a general finding that the United States or Nigeria provide a level of data protection adequate under POPIA section 72(1)(a). We therefore rely on the following grounds under section 72(1) for these transfers:
(a) your consent, given at registration and recorded as described in clause 5.2; and
(b) necessity for the performance of our contract with you — the transfer is required to provide the Service you have signed up for (for example, hosting your account data so the Service can operate, or sending you transactional emails).
7.3 [PLACEHOLDER / RISK FLAG FOR ATTORNEY: we recommend confirming that written data processing or cross-border transfer agreements are in place with Vercel, Neon, Resend, and Cloudflare that impose obligations on those providers substantially similar to POPIA's conditions for lawful processing, as an additional safeguard alongside consent and contractual necessity. See drafting notes at the end of this file.]
8.1 We retain Personal Information only for as long as necessary for the purposes described in this Policy, or as required by law. Our current retention approach is:
| Category | Retention period |
|---|---|
| Account and Profile data | Retained while your account is active. On a deletion request, retained for a 30-day grace period (during which the deletion can be cancelled or your data exported), then permanently deleted or irreversibly anonymised, save for information we must retain by law. |
| Relationship Entry data | Same as Account and Profile data above, or removed sooner on a valid takedown request. |
| Billing and transaction metadata | Retained for 5 years to meet record-keeping obligations under the Tax Administration Act 28 of 2011 and the Companies Act 71 of 2008. [PLACEHOLDER: confirm this 5-year period with your tax practitioner/accountant before final publish.] |
| Usage and analytics logs (hashed IP, user-agent) | Automatically purged by our retention process after 400 days (approximately 13 months). |
| Login/security logs | Automatically purged after 90 days. |
| One-time passwords (OTPs) | Retained only for the short validity window required to complete authentication — 10 minutes for email/SMS codes, approximately 30 seconds for authenticator-app (TOTP) codes — then deleted or invalidated. |
9.1 We apply technical and organisational measures appropriate to the risk, including: hashing of passwords; hashing of IP addresses before storage; optional 2FA; encryption in transit (TLS) and at rest (encrypted database storage; sensitive secrets such as authenticator-app (TOTP) seeds are separately encrypted); access controls limiting who within Incendio may access Personal Information; and due diligence on our sub-processors.
9.2 No method of transmission or storage is completely secure. See clause 14 for our commitment on security compromises.
10.1 Subject to POPIA, you have the right to:
(a) request confirmation of whether we hold Personal Information about you, and to access it;
(b) request correction or updating of inaccurate, incomplete, misleading, or outdated Personal Information;
(c) request deletion or destruction of Personal Information that we are no longer authorised to retain;
(d) object, on reasonable grounds, to our processing of your Personal Information; and
(e) lodge a complaint with the Information Regulator (contact details in clause 16).
10.2 You can exercise the access, export, correction, and deletion rights yourself at any time using the self-service tools in your account settings. Alternatively, you may contact us at deon@incendiogroup.co.za. We aim to respond within 20 business days.
11.1 When a person (whether or not they are a registered User) views a published public Profile, we record a hashed version of their IP address and their user-agent/device string, together with a timestamp, for security and analytics purposes (for example, to show you how many times your Profile has been viewed).
11.2 The Service does not set persistent tracking or advertising cookies for anonymous visitors to public Profiles. This analytics logging is performed server-side, not through a cookie.
11.3 [RISK FLAG FOR ATTORNEY: IP addresses are hashed using a keyed hash (HMAC-SHA256, with a server-side secret as the key) rather than a plain unsalted hash, and the raw IP address is never stored. We recommend confirming with counsel whether this keyed-hash implementation is sufficient to treat the resulting value as outside the scope of "Personal Information" under POPIA, or whether it should still be treated conservatively as Personal Information (as this draft currently does) before any public-facing text describes it as "anonymous."]
12.1 The Service is not intended for, and must not be used by, individuals under 18 years of age, consistent with the age of majority under the Children's Act 38 of 2005.
12.2 We do not knowingly collect Personal Information from children. There is currently no age-verification step beyond the self-declaration in clause 4.1 of our Terms of Service (no date-of-birth or similar check is performed at registration) — see drafting notes regarding POPIA sections 34–35. If we become aware that an account has been created by a person under 18, we will suspend and delete that account.
13.1 If you add a Relationship Entry, you are responsible for ensuring you have that person's consent, as set out in clause 7.2 of our Terms of Service.
13.2 A third party who believes their information has been published without consent may request its removal via deon@incendiogroup.co.za. See clause 7.3 of the Terms of Service for our commitment on response times.
14.1 If we become aware of reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible, in accordance with POPIA section 22.
14.2 That notification will, where possible, include: a description of the possible consequences of the compromise; the measures we have taken or intend to take in response; a recommendation on steps you can take to mitigate the possible adverse effects; and, if known, the identity of the unauthorised person who may have accessed the information.
14.3 Notification may be given by email, by notice on our website, or by any other method directed by the Information Regulator.
15.1 We may update this Policy from time to time. Material changes will be notified in the same manner described in clause 14.1 of the Terms of Service, and, where required by law, we will seek fresh consent.
16.1 Our Information Officer is:
[PLACEHOLDER: Information Officer full name] [PLACEHOLDER: Information Officer email] [PLACEHOLDER: Information Officer telephone number]
16.2 Our Information Officer is registered / in the process of being registered with the Information Regulator, as required by section 55(2) of POPIA. [PLACEHOLDER: confirm registration status and, once available, insert the Information Officer's registration reference.]
16.3 You may also lodge a complaint directly with the Information Regulator:
The Information Regulator (South Africa) Physical address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Telephone: 010 023 5200 (toll-free: 0800 017 160) General enquiries: enquiries@inforegulator.org.za POPIA complaints: POPIAComplaints@inforegulator.org.za Website: inforegulator.org.za [Verified against inforegulator.org.za/contact-us/ at the time of drafting — the Regulator has changed premises before, so please re-confirm this address before the final publish date.]
Incendio Digital Labs (Pty) Ltd [PLACEHOLDER: Registered Address] deon@incendiogroup.co.za