1 Responsible party and contact
[LEGAL ENTITY NAME] is the responsible party for the processing described here. Information Officer: [NAME], [EMAIL], [ADDRESS]. Separate entities may be responsible parties or operators depending on the payment, screening, communication and service arrangement.
2 Information collected
- Account and identity information; contact and authentication data; customer addresses and access instructions; helper work eligibility, experience, references, qualifications and bank details.
- Booking, payment, payout, message, review, support and incident records; approximate or booking-time location; device, log and fraud-prevention data.
- Special personal information only where lawful and necessary, including criminal screening results, health or accessibility information, and limited child information. Do not store complete screening reports where a verified result and date are sufficient.
3 Purposes and lawful grounds
Information is processed to create accounts, verify eligibility and safety, match and perform bookings, process payments, communicate, prevent fraud, respond to incidents, comply with law, exercise or defend legal rights and improve services. Consent is used where required and must be specific, informed and withdrawable. Contract, legal obligation and legitimate interests are used only where appropriate under POPIA.
4 Children
A parent or competent person supplies only information necessary for a child care booking. Child information is restricted to approved personnel and the confirmed carer. Marketing profiling of children is prohibited. Consent and another lawful basis must be documented as required by POPIA.
5 Sharing and operators
Information may be shared on a need-to-know basis with the confirmed booking participant, payment providers, screening providers, cloud and communication operators, professional advisers, insurers and authorities where lawful. Written operator agreements must require confidentiality, security, breach support, deletion/return and sub-operator controls.
6 Cross border processing
Before transferring personal information outside South Africa, StudeeHelpers must confirm a lawful POPIA section 72 mechanism and document the receiving country, recipient protections and operational necessity.
7 Retention
Keep information only for an identified legal, contractual, safety or operational period. Publish a retention schedule covering unsuccessful applications, screening results, booking records, financial records, messages, incidents, access codes and deleted accounts. Access codes should expire promptly; sensitive documents should have shorter retention unless law requires otherwise.
8 Security and incidents
Use role-based access, multifactor authentication for admins, encryption in transit, private storage, signed URLs, logging, backups, vulnerability management and response procedures. Notify the Information Regulator and affected data subjects where required after a compromise, without unlawful delay.
9 Rights
Data subjects may request access, correction, deletion where applicable, objection, restriction, consent withdrawal and information about automated decisions. Requests go to [PRIVACY EMAIL]. Identity may be verified proportionately. Complaints may be submitted to the Information Regulator.
10 Marketing cookies and location choices
Service communications are separate from direct marketing. Marketing consent must be optional, granular and not preselected. Provide unsubscribe controls. Non-essential cookies require an appropriate consent mechanism. Location permission is optional until required for a chosen feature and must explain whether precise or approximate location is used.
