Privacy Policy
Privacy Policy (POPIA-Focused — TEMPLATE)
Note: POPIA (Protection of Personal Information Act) governs how personal information must be processed in South Africa. EduHub is committed to complying with POPIA obligations. Popia+1
2.1 Intro & Scope
This Privacy Policy explains how EduHub collects, uses, stores, discloses and protects personal information of Schools, Suppliers and visitors.
2.2 Responsible Party & Information Officer
Responsible party: EduHub ([insert legal entity name once registered]).
Information Officer: [Name, email, phone]. (POPIA requires an Information Officer and deputy for many organizations.) InfoTrust
2.3 What Personal Information We Collect
We may collect:
-
Identification: name, business name, position;
-
Contact: email, telephone, postal address;
-
Business details: supplier offerings, VAT number, bank account for payouts;
-
Transaction data: orders, invoices, payment confirmations;
-
Usage data: IP address, device, browsing and analytics;
-
Optional: logos, product images, references.
We do not collect sensitive personal information unless expressly required (and we will obtain consent then).
2.4 Purposes of Processing & Legal Basis
We process personal information for:
-
Facilitating discovery and contact between Schools and Suppliers (contract performance).
-
Managing accounts and payments (contractual necessity).
-
Improving the Platform and analytics (legitimate interest).
-
Marketing & communications (with consent or where permitted).
-
Complying with legal obligations (tax, anti-fraud, POPIA).
We will only process information where we have a lawful basis under POPIA (consent, contractual necessity, legal obligation or legitimate interest). Popia
2.5 Sharing & Disclosure
We share personal information with:
-
Suppliers (so Schools can be contacted);
-
Payment processors and courier/logistics partners;
-
Law enforcement or regulators where required by law;
-
Service providers under contract who process data on our behalf (with appropriate safeguards).
We will not sell personal information.
2.6 Security & Retention
-
We maintain appropriate technical and organisational measures to protect data (encryption, access controls, backups).
-
We retain data only as long as necessary (e.g., transactional records for tax: 5–7 years per South African tax rules) or as required by law.
2.7 Data Subject Rights
Under POPIA, you have rights to: access, correction, deletion (subject to legal retention obligations), object to processing, and lodge complaints with the Information Regulator. Contact our Information Officer to exercise rights.
2.8 Cross-border Transfers
If we transfer personal information outside South Africa (e.g., payment gateway servers), we will only do so with appropriate safeguards.
2.9 Updates & Contact
If you have privacy questions or wish to exercise rights, contact: info@myeduhub.co.za or the Information Officer. You may also lodge complaints with the Information Regulator (see popia.co.za).