Document 4 of 7
Privacy Policy
POPIA-compliant privacy policy
Effective Date: 19 April 2026
Responsible Party:
K2026233999 (Pty) Ltd, trading as WhereZit
Registration Number: K2026233999
Address: Pretoria, Republic of South Africa
Privacy Contact: privacy@wherezit.co.za
Information Officer — Officially Registered
Name: Marius Mathys Marais
Title: Co-Founder, K2026233999 (Pty) Ltd trading as WhereZit
Appointment Date: 18 March 2026
Information Regulator Registration Number: 2026-008545
Registration Certificate Issued: 16 April 2026
Contact: privacy@wherezit.co.za
1. Introduction
K2026233999 (Pty) Ltd trading as WhereZit is committed to protecting the personal information of all individuals who use the WhereZit platform, in full compliance with the Protection of Personal Information Act 4 of 2013 (‘POPIA’).
This Privacy Policy explains what personal information we collect, the lawful basis on which we process it, how we use and protect it, how long we retain it, who we share it with, and your rights under POPIA.
2. Information Officer
Full Name: Marius Mathys Marais | Title: Co-Founder | Appointment Date: 18 March 2026 | Registration Number: 2026-008545 | Contact: privacy@wherezit.co.za
3. Personal Information We Collect
3.1 Registration Information — All Users
Full name, email address, mobile telephone number, date of birth (to verify 18+), city and province of residence.
3.2 Identity Verification — Winners Only
South African ID number or passport number, and a copy of identity document — collected only when identity verification is required for prize award.
3.3 Competition Entry Data
Entry coordinates (stored as a cryptographic hash during active competition), prize category entered, entry submission timestamp, and entry hash value.
3.4 Payment Information
Transaction reference numbers from PayFast or Yoco, transaction amounts and dates. Credit card numbers, CVV codes and bank account numbers are never stored by WhereZit — all card and banking data is processed exclusively by PayFast or Yoco.
3.5 NPO Client Information
Organisation name and registration number, administrator details, competition content, prize details and uploaded images. Banking details are held by the applicable payment processor, not WhereZit.
3.6 Technical and Usage Data
IP address, device type and browser information, pages visited, login and session timestamps, and cookie data as described in our Cookie Policy.
4. Lawful Basis for Processing
- Contractual necessity — processing required to provide the services you have requested
- Legal obligation — processing required to comply with South African legal requirements
- Legitimate interest — fraud prevention, security monitoring and platform improvement
- Consent — for any processing not covered by the above bases, explicit consent will be obtained
5. How We Use Personal Information
- Creating and managing your account
- Processing competition entry payments
- Calculating competition results
- Verifying winner identity and coordinating prize delivery
- Communicating results, winner notifications and platform updates
- Preventing fraud, account duplication and competition manipulation
- Maintaining audit records for legal compliance
- Improving the platform through anonymised analytics
- Complying with applicable legal obligations
6. Sharing of Personal Information
We do not sell personal information to any third party. We share it only with:
- PayFast or Yoco — payment processing data
- NPO client organisers — winner name and email only, for prize delivery
- Technology service providers — hosting and infrastructure under data processing agreements
- Legal and regulatory authorities — where required by law
- WhereZit’s legal advisors — where necessary for legal proceedings
7. Retention of Personal Information
- Player account information: active account + 1 year after closure
- Competition entry records: 3 years after competition close
- Payment transaction records: 5 years after transaction date
- Winner identity verification documents: 3 years after prize delivery
- NPO client records: active account + 3 years after closure
- Audit logs: 3 years after the relevant event
After applicable retention periods, personal information is securely and permanently deleted or irreversibly anonymised.
8. Security
- Cryptographic hashing of player entry coordinates during active competitions
- HTTPS/TLS encrypted transmission for all communications
- Access controls restricting personal data to authorised personnel only
- Regular security monitoring and audit logging
- Payment card data not stored by WhereZit
In the event of a data breach, we will notify you and the Information Regulator as required by POPIA.
9. Your Rights Under POPIA
As a data subject you have the right to:
- Request access to your personal information
- Request correction of inaccurate information
- Request deletion, subject to legal retention obligations
- Object to processing in certain circumstances
- Lodge a complaint with the Information Regulator
Contact privacy@wherezit.co.za. We will acknowledge within 3 business days and respond within 30 days.
10. Children’s Privacy
The platform is not directed at persons under 18. We do not knowingly collect personal information from minors. If we become aware of inadvertently collected minor data we will delete it promptly.
11. Cookies
Our use of cookies is described in our Cookie Policy.
12. Changes to This Policy
We may update this policy and will notify registered users of material changes by email. Continued use after publication constitutes acceptance. Contact: privacy@wherezit.co.za