Saadjie POPIA Notice — version v1
Effective from: 2026-05-25
This POPIA Notice lists every obligation Saadjie holds under the South African Protection of Personal Information Act, 2013 ("POPIA"), together with the specific operational measure that satisfies each obligation on the live platform. It is the formal companion document to our plain-language Privacy Notice.
1. Responsible party
For the purposes of POPIA, Saadjie is the responsible party in respect of:
- Parent account information.
- Child page information (display name, date of birth, photos,
welcome message).
- Contributor information (name, email, message, amount) that
Contributors submit on the Saadjie contribution form.
- Visitor analytics hashes.
- The audit trail of Terms & Conditions acceptances.
Our payment partner Eclipse, operated by EFT Corp (Pty) Ltd, is a separate responsible party in respect of the full card-payment data captured on its hosted checkout page. Saadjie never sees or stores a full card number.
Information Officer / contact for any POPIA request: privacy@saadjie.com.
2. Lawful processing — POPIA s.11
Saadjie relies on the following lawful processing grounds:
- Consent (s.11(1)(a)) — recorded explicitly at sign-up
("I agree to the Terms & Conditions"), again at every add-child step, and per-milestone whenever the Parent opts in to fan a milestone out to past Contributors. Every acceptance writes a row to the tcs_acceptances table containing the version accepted, the timestamp, the IP address, and the User-Agent string.
- Performance of a contract (s.11(1)(b)) — the contribution
pipeline (the public page, the payment checkout, the receipt email) is necessary to perform the Terms & Conditions contract between Saadjie and the Parent.
- Legitimate interest (s.11(1)(f)) — Saadjie's fraud-prevention
and abuse-defence measures (rate limiting, CSP enforcement, audit logs of moderation actions) are processed on the legitimate- interest basis. The balancing-test record is retained internally.
3. Special personal information — s.26
A child is a data subject under POPIA, and information about a child under 18 is "special personal information" under s.26. Saadjie processes child information only on the basis of:
- The competent consent of the Parent or legal guardian (s.35), which
the Parent gives at the add-child step and re-confirms each time they upload a new photo or post a new milestone.
- The minimisation rule of s.10 — we collect only what is necessary
to render the page (a display name, an age, a photo, an optional welcome message).
The Parent may at any time remove a child, which triggers the soft- delete + 30-day grace window described in section 6 below.
4. Information quality and minimisation — s.10 & s.16
- Minimisation — Saadjie does not collect a date of birth unless
the Parent chooses to enter one; the public page renders a "first name + age in years" string with no birthday precision below the year. Contributor email addresses are required only when the Contributor wants a receipt; an anonymous contribution does not capture an email.
- Accuracy — the Parent dashboard lets the Parent edit every
field they entered. The right of correction is exercised in-app with immediate effect.
5. Disclosure to Contributors and recipients — s.18
At every collection point Saadjie tells the data subject:
- What we are collecting (the form labels are explicit).
- Why we are collecting it (the form copy explains the purpose).
- Who receives it (the receipt email and parent notification
flows are listed in the Terms & Conditions, section 6).
- How long we keep it (set out in this notice, section 6, and
in the Privacy Notice, section 4).
The Terms & Conditions checkbox at sign-up links to both this notice and the Privacy Notice so the parent can read them before consenting.
6. Right of access and right of erasure — s.23 & s.24
Right of access (s.23)
A Parent may at any time download a complete copy of every row tied to their account from the self-serve export page. The exported ZIP includes:
- The parent record (without the password hash).
- Every child page the parent has created, including soft-deleted
ones (retained for the audit trail).
- Every contribution made to those children's pages, including the
contributor email and the message-moderation state.
- Every thank-you and milestone the parent has posted.
- Every carousel photo (one file per photo) in their original
WebP form.
- The full Terms & Conditions acceptance audit trail.
- Every "report this page" submission about the parent's pages.
A Parent who cannot access the dashboard (for example because their account has been suspended) can request the same export by emailing privacy@saadjie.com.
Right of erasure (s.24)
A Parent triggers erasure by deleting a child from the dashboard, or by closing their account entirely. The cron-driven purge runs nightly and, after a 30-day grace window:
- Scrubs identity columns on the child row to the sentinel value
[deleted].
- Anonymises every contribution to that child (blanks the contributor
name, nulls the contributor email, sets the anonymous flag, wipes the message).
- Deletes every thank-you, milestone, and carousel-photo row attached
to that child.
- Removes the on-disk photo files referenced by those rows.
The financial-audit columns (contribution amount, status, timestamp, payment-processor reference) survive the scrub because POPIA s.24 allows retention to the extent legally required for tax and chargeback adjudication.
7. Cross-border transfer — s.72
Saadjie's primary infrastructure is hosted on AWS inside the eu-west-1 region. Operational metadata may be processed in the following secondary jurisdictions:
- Email delivery via Amazon SES (eu-west-1).
- Payment processing via Eclipse (EFT Corp), which is a South
African entity with its own POPIA compliance posture.
In each case the recipient is subject to a contractual or statutory regime that affords adequate protection within the meaning of s.72.
8. Security safeguards — s.19
- TLS 1.2+ on every public surface, with certificates renewed
automatically before expiry.
- Bcrypt password hashing at cost factor 14.
- Bcrypt rate-limited login + CSRF tokens on every mutating route.
- Strict Content-Security-Policy in enforce mode (with a separate
report-only header to surface drift); CSP violation reports are rate-limited at the endpoint and rotated out within 5 minutes.
- Daily off-site backup of the database, with quarterly restore
drills.
- Hard-coded reserved-word allowlist so a child slug cannot collide
with a system path.
- Multi-factor verification of every refund initiated from the
parent dashboard.
9. Breach notification — s.22
In the event of a security compromise that is reasonably likely to affect personal information, Saadjie will:
- Notify the Information Regulator within the time set out in
s.22(2), in the manner the Regulator's then-current guidance prescribes.
- Notify every affected data subject by email, sent to the address
on file, within the same window.
10. Information Officer and contact
The Saadjie Information Officer is the role to which the POPIA obligations described in this notice are operationally assigned. All POPIA-related correspondence — access requests, erasure requests, objections, withdrawals of consent, complaints — should be sent to privacy@saadjie.com.
Complaints about Saadjie's handling of personal information may also be lodged with the Information Regulator at inforegulator.org.za.