Skip to main content

POPI Act Compliance

Last updated: 3 June 2026

1. Introduction

As a South African company, Spekboom Tree (Proprietary) Limited is committed to full compliance with the Protection of Personal Information Act 4 of 2013 ("POPI Act").

This page outlines how we comply with POPI Act requirements and your rights as a data subject under South African law.

2. Information Officer

As required by Section 56 of the POPI Act, we have designated an Information Officer responsible for ensuring POPI compliance:

Information Officer: Support Team

Email: support@spekboom.org

Company: Spekboom Tree (Proprietary) Limited

Registration Number: K2021143449

Registered in: South Africa

3. POPI Act Principles We Follow

We process personal information in accordance with all eight POPI Act conditions:

Condition 1: Accountability

We have appointed an Information Officer and implemented measures to ensure POPI compliance across our organization.

Condition 2: Processing Limitation

We only collect personal information lawfully and for specific, explicitly defined purposes related to our travel accommodation services.

Condition 3: Purpose Specification

We clearly communicate why we collect your information (bookings, payments, communication) and only use it for those stated purposes.

Condition 4: Further Processing Limitation

We do not use your information for purposes beyond what we originally disclosed, unless we obtain your consent or as required by law.

Condition 5: Information Quality

We take reasonable steps to ensure your personal information is complete, accurate, not misleading, and updated as necessary.

Condition 6: Openness

Our Privacy Policy provides clear information about our data practices, and we respond to requests for information.

Condition 7: Security Safeguards

We implement appropriate technical and organizational measures to secure your information against loss, damage, unauthorized access, and unlawful processing.

Condition 8: Data Subject Participation

You have the right to access, correct, and delete your personal information, and we provide mechanisms to exercise these rights.

4. Your Rights Under POPI

As a data subject, the POPI Act gives you these rights:

Right to Access

Request confirmation of what personal information we hold about you and obtain a copy.

Right to Correction

Request correction of inaccurate or incomplete personal information.

Right to Deletion

Request deletion of your personal information, subject to legal retention requirements.

Right to Object

Object to certain processing of your personal information, such as direct marketing.

Right to Complain

Lodge a complaint with the Information Regulator if you believe your rights have been violated.

Right to Information

Be informed about how your personal information is being processed.

How to Exercise Your Rights:

Contact our Information Officer at support@spekboom.org or use our automated data export/deletion tools in your account settings.

5. Cross-Border Data Transfers

We transfer personal information outside of South Africa to countries including:

  • European Union: Supabase (database hosting) - Adequacy recognized
  • United States: SendGrid, Twilio, Google, Sentry - Using Standard Contractual Clauses
  • Nigeria: Paystack (payment processing) - Regional proximity

As required by Section 72 of POPI, we ensure adequate protection through:

  • Adequacy decisions by the Information Regulator or EU Commission
  • Standard Contractual Clauses approved for international transfers
  • Processor commitments to equivalent protection standards

See our Data Processing Agreement for full details of all international processors.

6. Security Safeguards

To comply with Section 19 of POPI, we have implemented comprehensive security measures:

Technical Safeguards

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Regular security audits and penetration testing
  • Multi-factor authentication (2FA)
  • Automated security monitoring

Organizational Safeguards

  • Staff data protection training
  • Access controls and role-based permissions
  • Confidentiality agreements with employees
  • Incident response procedures
  • Regular policy reviews and updates

7. Data Breach Notification

In compliance with Section 22 of POPI, if a data breach occurs that compromises your personal information:

  • We will notify the Information Regulator as soon as reasonably possible
  • We will notify affected data subjects without undue delay
  • Notifications will include the nature of the breach and remedial measures
  • We will take immediate steps to mitigate risks and prevent further breaches

8. Data Retention

We retain personal information only as long as necessary for the purposes for which it was collected:

  • Active accounts: Duration of account + 6 months
  • Financial records: 7 years (as required by tax law)
  • Marketing consent: Until consent is withdrawn
  • Communication logs: 1 year for service quality

After retention periods expire, we securely delete or anonymize your information.

9. Children's Privacy

Our services are intended for users aged 18 and above. We do not knowingly collect personal information from children without parental consent as required by Section 35 of POPI.

If we become aware that we have collected information from a child under 18 without proper consent, we will delete that information promptly.

10. Filing a Complaint

If you believe we have not handled your personal information in accordance with POPI, you have the right to lodge a complaint:

First: Contact Our Information Officer

Email: support@spekboom.org

We will investigate and respond within 30 days.

If Unresolved: Contact the Information Regulator

Information Regulator (South Africa)

JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

P.O Box 31533, Braamfontein, Johannesburg, 2017

Email: inforeg@justice.gov.za

Website: www.justice.gov.za/inforeg

Complaints line: 010 023 5200

11. Updates to This Page

We may update this POPI compliance statement from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page shows when the most recent update occurred.

Related Documents

Questions or Concerns?

Contact our Information Officer at support@spekboom.org for any questions about our POPI compliance or to exercise your rights.