POPI Act Compliance
Last updated: 3 June 2026
1. Introduction
As a South African company, Spekboom Tree (Proprietary) Limited is committed to full compliance with the Protection of Personal Information Act 4 of 2013 ("POPI Act").
This page outlines how we comply with POPI Act requirements and your rights as a data subject under South African law.
2. Information Officer
As required by Section 56 of the POPI Act, we have designated an Information Officer responsible for ensuring POPI compliance:
Information Officer: Support Team
Email: support@spekboom.org
Company: Spekboom Tree (Proprietary) Limited
Registration Number: K2021143449
Registered in: South Africa
3. POPI Act Principles We Follow
We process personal information in accordance with all eight POPI Act conditions:
Condition 1: Accountability
We have appointed an Information Officer and implemented measures to ensure POPI compliance across our organization.
Condition 2: Processing Limitation
We only collect personal information lawfully and for specific, explicitly defined purposes related to our travel accommodation services.
Condition 3: Purpose Specification
We clearly communicate why we collect your information (bookings, payments, communication) and only use it for those stated purposes.
Condition 4: Further Processing Limitation
We do not use your information for purposes beyond what we originally disclosed, unless we obtain your consent or as required by law.
Condition 5: Information Quality
We take reasonable steps to ensure your personal information is complete, accurate, not misleading, and updated as necessary.
Condition 6: Openness
Our Privacy Policy provides clear information about our data practices, and we respond to requests for information.
Condition 7: Security Safeguards
We implement appropriate technical and organizational measures to secure your information against loss, damage, unauthorized access, and unlawful processing.
Condition 8: Data Subject Participation
You have the right to access, correct, and delete your personal information, and we provide mechanisms to exercise these rights.
4. Your Rights Under POPI
As a data subject, the POPI Act gives you these rights:
Right to Access
Request confirmation of what personal information we hold about you and obtain a copy.
Right to Correction
Request correction of inaccurate or incomplete personal information.
Right to Deletion
Request deletion of your personal information, subject to legal retention requirements.
Right to Object
Object to certain processing of your personal information, such as direct marketing.
Right to Complain
Lodge a complaint with the Information Regulator if you believe your rights have been violated.
Right to Information
Be informed about how your personal information is being processed.
How to Exercise Your Rights:
Contact our Information Officer at support@spekboom.org or use our automated data export/deletion tools in your account settings.
5. Cross-Border Data Transfers
We transfer personal information outside of South Africa to countries including:
- European Union: Supabase (database hosting) - Adequacy recognized
- United States: SendGrid, Twilio, Google, Sentry - Using Standard Contractual Clauses
- Nigeria: Paystack (payment processing) - Regional proximity
As required by Section 72 of POPI, we ensure adequate protection through:
- Adequacy decisions by the Information Regulator or EU Commission
- Standard Contractual Clauses approved for international transfers
- Processor commitments to equivalent protection standards
See our Data Processing Agreement for full details of all international processors.
6. Security Safeguards
To comply with Section 19 of POPI, we have implemented comprehensive security measures:
Technical Safeguards
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Regular security audits and penetration testing
- Multi-factor authentication (2FA)
- Automated security monitoring
Organizational Safeguards
- Staff data protection training
- Access controls and role-based permissions
- Confidentiality agreements with employees
- Incident response procedures
- Regular policy reviews and updates
7. Data Breach Notification
In compliance with Section 22 of POPI, if a data breach occurs that compromises your personal information:
- We will notify the Information Regulator as soon as reasonably possible
- We will notify affected data subjects without undue delay
- Notifications will include the nature of the breach and remedial measures
- We will take immediate steps to mitigate risks and prevent further breaches
8. Data Retention
We retain personal information only as long as necessary for the purposes for which it was collected:
- Active accounts: Duration of account + 6 months
- Financial records: 7 years (as required by tax law)
- Marketing consent: Until consent is withdrawn
- Communication logs: 1 year for service quality
After retention periods expire, we securely delete or anonymize your information.
9. Children's Privacy
Our services are intended for users aged 18 and above. We do not knowingly collect personal information from children without parental consent as required by Section 35 of POPI.
If we become aware that we have collected information from a child under 18 without proper consent, we will delete that information promptly.
10. Filing a Complaint
If you believe we have not handled your personal information in accordance with POPI, you have the right to lodge a complaint:
First: Contact Our Information Officer
Email: support@spekboom.org
We will investigate and respond within 30 days.
If Unresolved: Contact the Information Regulator
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O Box 31533, Braamfontein, Johannesburg, 2017
Email: inforeg@justice.gov.za
Website: www.justice.gov.za/inforeg
Complaints line: 010 023 5200
11. Updates to This Page
We may update this POPI compliance statement from time to time to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page shows when the most recent update occurred.
Related Documents
Questions or Concerns?
Contact our Information Officer at support@spekboom.org for any questions about our POPI compliance or to exercise your rights.