Legal

POPIA Privacy Policy

Last updated: 12 June 2026. This policy applies to Maths and Science Buddy (Pty) Ltd and all products operated under the mathscibuddy.co.za domain.

Published and reviewed by 's Information Officer (trading as Maths and Science Buddy)

Compliant with POPIA Act 4 of 2013

1. Who We Are

MG5 Pty Ltd (trading as Maths and Science Buddy) (“we”, “us”, “our”) is a South African educational technology company that operates the platform available at mathscibuddy.co.za. We are a Responsible Party as defined in the Protection of Personal Information Act 4 of 2013 (POPIA).

This Privacy Policy explains how we collect, use, store, and protect personal information in accordance with POPIA, the Electronic Communications and Transactions Act 25 of 2002 (ECT Act), and all applicable South African law.

2. Personal Information We Collect

We collect the following categories of personal information:

  • Identity data: First name, last name, username, or similar identifier.
  • Contact data: Email address.
  • Academic data: Grade level, selected subjects, term preference. We do not collect school names or student numbers unless voluntarily provided.
  • Payment data: Transaction reference numbers, subscription tier, and payment status. We do not store card numbers or bank account details — payments are processed by PayFast (Pty) Ltd, a PCI DSS-compliant payment gateway.
  • Usage data: Pages visited, features used, game session scores, and time on platform — collected in aggregate and linked to your account.
  • Technical data: IP address, browser type, device type, and operating system — collected automatically via server logs.
  • Communication data: Any message you send us via the contact form or email.

We do not collect race, religion, health, biometric, or criminal record information (special personal information under POPIA s. 26), except where a learner voluntarily discloses such information in a free-text support query.

3. How We Collect Information

  • Directly from you when you register, subscribe, contact us, or use our platform.
  • Automatically via cookies, server logs, and analytics tools when you browse our website.
  • From third parties — specifically our authentication provider (Clerk Inc.) and payment processor (PayFast) — who share only the minimum data necessary to create and manage your account.

4. Lawful Basis for Processing

We process your personal information only on the lawful grounds listed in POPIA s. 11(1). For each type of processing we rely on one or more of the following grounds:

  • Consent — s. 11(1)(a): Where you have given voluntary, specific, and informed consent (as defined in POPIA s. 1). We rely on consent for promotional email communications and optional analytics. You may withdraw consent at any time (s. 11(2)(b)); withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
  • Contract performance — s. 11(1)(b): Where processing is necessary to carry out actions for the conclusion or performance of a contract to which you are party. We rely on this ground to create your account, process payments, and deliver subscription services.
  • Legal obligation — s. 11(1)(c): Where processing is necessary to comply with an obligation imposed by law on us — including South African tax law (SARS record- keeping), the Companies Act, and the Consumer Protection Act.
  • Legitimate interests — s. 11(1)(f): Where processing is necessary for pursuing our legitimate interests, provided those interests are not overridden by your rights. We rely on this ground to detect fraud, maintain platform security, and improve our services.

5. How We Use Your Information

  • To register and maintain your account.
  • To process subscription payments and send receipts.
  • To personalise your learning experience (e.g., serving grade-appropriate content).
  • To send transactional emails (subscription confirmations, cancellation notices).
  • To send promotional communications — only where you have opted in.
  • To monitor platform performance, diagnose technical issues, and improve our products.
  • To detect, prevent, and respond to fraud or abuse.
  • To comply with legal and regulatory obligations.

We will never sell your personal information to any third party.

6. Who We Share Information With

We share your personal information only with trusted operators who process it solely on our behalf and under our instruction:

  • Clerk Inc. — Identity and authentication management (servers in the United States; Standard Contractual Clauses apply for cross-border transfers).
  • Supabase Inc. — Database hosting (servers in the European Union / AWS).
  • PayFast (Pty) Ltd — Payment processing (South African entity; PCI DSS compliant).
  • Resend Inc. — Transactional email delivery.
  • Sentry Inc. — Error monitoring (personal data is automatically scrubbed from error reports).

We may disclose personal information if required by law, court order, or competent South African authority. We will notify you where legally permissible.

7. How Long We Keep Information

  • Account data: Retained for the duration of your subscription plus 3 years, or as required by the Companies Act.
  • Payment records: Retained for 5 years in accordance with the South African Revenue Service (SARS) record- keeping requirements.
  • Server logs: Retained for 90 days and then deleted.
  • Support communications: Retained for 2 years from the date of the last communication.

After the applicable retention period, your personal information is securely deleted or anonymised.

8. How We Protect Information

In terms of POPIA s. 19(1), a responsible party must secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures to prevent loss, damage, unauthorised destruction or unlawful access. We implement the following measures to meet this obligation:

  • HTTPS/TLS encryption for all data in transit.
  • AES-256 encryption for sensitive data at rest.
  • Role-based access controls — staff access only the data necessary for their function.
  • Timing-safe signature verification for all payment webhooks.
  • Regular security audits and dependency vulnerability scanning.

Where we become aware of a security breach that affects your personal information, POPIA s. 22 requires us to notify the Information Regulator and you as soon as reasonably possible. That notification will be in writing and will include: a description of the possible consequences of the breach; the measures we have taken or propose to take to address it; our recommendations for steps you can take to mitigate the possible adverse effects; and, where known, the identity of the unauthorised person who accessed your information. Where notification to you would impede a criminal investigation, the Regulator may permit us to delay notifying you.

When personal information is no longer required, we destroy or delete it in a manner that prevents its reconstruction in an intelligible form, in accordance with POPIA s. 14(4)-(5).

9. Your Rights Under POPIA

POPIA s. 5 confers the following rights on data subjects. These rights are exercisable in accordance with the conditions set out in the Act:

  • Right to be notified (s. 18 & s. 22): To be informed when we collect your personal information and if a security breach occurs that affects you.
  • Right of access (s. 23): Request confirmation, free of charge (s. 23(1)(a)), of whether we hold personal information about you, and a description of that information. Further copies may be subject to a prescribed fee (s. 23(1)(b)).
  • Right to correction or deletion (s. 24): Request that we correct, destroy, or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully.
  • Right to object (s. 11(3)(a)): Object to the processing of your personal information at any time on grounds relating to your particular situation, unless we can demonstrate compelling legitimate grounds that override your interests.
  • Right to object to direct marketing (s. 11(3)(b) & s. 69): Object at any time to us using your personal information for direct marketing purposes. We will stop processing for that purpose as soon as reasonably practicable.
  • Right to withdraw consent (s. 11(2)(b)): Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
  • Right regarding automated decisions (s. 71): Not to be subject to a decision based solely on automated processing of your personal information that has legal consequences or substantially affects you (for example, automated account suspension). Where such processing is necessary, we will provide you with an opportunity to make representations.
  • Right to lodge a complaint (s. 74): Submit a written complaint to the Information Regulator at inforegulator.org.za if you believe we have interfered with the protection of your personal information.
  • Right to civil proceedings (s. 99): Institute civil proceedings in a court of competent jurisdiction for interference with the protection of your personal information.

To exercise any of these rights, submit a written request to our Information Officer at privacy@mathscibuddy.co.za. We will respond within 30 days.

10. Cross-Border Transfers of Personal Information

POPIA s. 72(1) restricts the transfer of personal information about a data subject to a third party in a foreign country. A transfer may only occur if one of the conditions in s. 72(1)(a)–(e) is met — for example, if the recipient is subject to a law or binding agreement that provides an adequate level of protection substantially similar to POPIA, or if the data subject consents to the transfer, or if the transfer is necessary for performance of a contract to which the data subject is party.

We transfer personal information outside South Africa to the following third-party processors, and the basis on which each transfer is justified:

  • Clerk Inc. (United States): Authentication and identity management. Transfer is necessary for performance of the contract between you and us (s. 72(1)(c)). Clerk adheres to Standard Contractual Clauses to provide adequate protection.
  • Supabase Inc. (European Union / AWS): Database hosting. The European Union is widely recognised as providing an adequate level of protection (s. 72(1)(a)).
  • Resend Inc. (United States): Transactional email delivery. Transfer is necessary for performance of the contract with you (sending subscription receipts and account notifications) (s. 72(1)(c)).
  • Sentry Inc. (United States): Error monitoring. Personal data is automatically scrubbed from error reports. The minimal residual transfer is within our legitimate interests in maintaining a secure and functional platform (s. 72(1)(c) read with s. 11(1)(f)).

11. Cookies & Tracking

We use cookies and similar tracking technologies to operate our platform and improve your experience. For full details see our Cookie Policy.

12. Children's Privacy

POPIA s. 1 defines a “child” as a natural person under the age of 18 years who is not legally competent, without the assistance of a competent person, to take any action or decision in respect of any matter concerning himself, herself or itself. Under POPIA s. 34 and s. 35, a responsible party may not process the personal information of a child without the consent of a competent person (a person who is legally competent to consent on behalf of that child).

Our platform is designed for Grade 8–12 learners, who are typically 13–18 years old. Because our learners fall within the POPIA definition of a child, we take the following steps:

  • We collect only the minimum personal information necessary to deliver the educational service (name, email, grade level).
  • We do not share children's personal information with any third party for commercial purposes.
  • We do not process special personal information (s. 26) about children, such as race, health, or biometric data.
  • We encourage parents or guardians to register accounts on behalf of learners under 18 and to be aware of the personal information collected.

A parent or guardian who believes we have collected personal information from a child without the required consent under s. 35 should contact our Information Officer immediately at privacy@mathscibuddy.co.za. We will promptly delete the information concerned.

13. Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will revise the “Last updated” date at the top of this page and, where the changes are material, notify you by email or via an in-app notice. Your continued use of our platform after the effective date of the updated policy constitutes acceptance of the revised terms.

14. Contact & Information Officer

For all privacy-related enquiries, access requests, or complaints:

Information Officer

MG5 Pty Ltd (trading as Maths and Science Buddy)

South Africa

Email: privacy@mathscibuddy.co.za

You may also contact the South African Information Regulator directly:

Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Website: inforegulator.org.za