← Back to Destiny Workshop
✦

POPIA Compliance Notice

Protection of Personal Information Act 4 of 2013

Effective date: 1 June 2026  ·  Last updated: 27 May 2026

About POPIA: The Protection of Personal Information Act (POPIA) is South Africa’s data-protection law, comparable to the EU’s GDPR. It gives you — the data subject — rights over your personal information and places obligations on organisations that process it. WarinHari Learn NPC is committed to full POPIA compliance.

1. Responsible Party

OrganisationWarinHari Learn NPC
RegistrationNon-profit company, South Africa
Information OfficerTo be registered with the Information Regulator
Contactprivacy@warinhari.online
PlatformDestiny Workshop (workshop.warinhari.online)

2. Lawful Basis for Processing

We process your personal information on the following lawful grounds:

  • Consent (s.11(1)(a)): You provide consent when you register and accept these policies. You may withdraw consent at any time by requesting account deletion.
  • Contractual necessity (s.11(1)(b)): Processing required to deliver the workshop experience you have subscribed to.
  • Legitimate interest (s.11(1)(f)): Fraud prevention, security monitoring and service improvement (where not overridden by your rights).
  • Legal obligation (s.11(1)(c)): Financial records retained as required by the South African Revenue Service (SARS).

3. Special Personal Information

POPIA affords special protection to certain categories of information. Destiny Workshop collects information about your personality, values, strengths and emotional intelligence. While these are not medical records, they are sensitive in nature. We treat all such data as special personal information and apply our highest level of protection:

  • AES-256-GCM encryption at rest (database level)
  • TLS 1.2+ in transit
  • Access limited to you and (where applicable) a facilitator you have explicitly enrolled under
  • No sale, sharing or use for advertising purposes

4. Your Rights as a Data Subject

Under POPIA, you have the following rights. To exercise any of them, email privacy@warinhari.online with the subject line matching the right you are exercising.

RightWhat it means
Right of Access (s.23)Request a copy of all personal information we hold about you
Right to Correction (s.24)Request that inaccurate or incomplete information be corrected or updated
Right to Deletion (s.24)Request deletion of your personal information (subject to legal retention obligations)
Right to Object (s.11(3))Object to processing based on legitimate interest — we will stop unless we have compelling grounds
Right to Restrict (s.22)Request that we restrict how we use your data while a correction request is being resolved
Right to Complain (s.74)Lodge a complaint directly with the Information Regulator of South Africa

We will respond to rights requests within 30 days. Complex requests may be extended by a further 30 days with notice.

5. Retention Periods

Data categoryRetention period
Workshop progress & AI contentFor the lifetime of your account; deleted within 30 days of account deletion request
Payment records & invoices5 years (SARS requirement)
Email correspondence3 years
Security logs12 months
Anonymised aggregated dataIndefinitely (cannot be linked back to you)

6. Cross-Border Transfers

Your data may be processed outside South Africa by the following third-party services, each of which provides an adequate level of protection:

  • Anthropic (USA): AI processing of your assessment responses under our enterprise API agreement. Data is not stored after processing and is not used to train Anthropic models.
  • Resend (USA): Transactional email delivery. Only your email address and message content are transmitted.
  • PayFast (South Africa): Payment processing — South African company, no cross-border transfer.

We ensure that cross-border transfers comply with POPIA s.72 by relying on recipient organisations that are bound by laws, binding corporate rules or contracts that uphold substantially similar principles to POPIA.

7. Security Measures

We implement the following technical and organisational measures to protect your information:

  • AES-256-GCM encryption for all sensitive fields stored in the database
  • bcrypt hashing (cost factor 12) for all passwords
  • TLS 1.2+ for all data in transit
  • JWT-based authentication with 30-day expiry and server-side validation
  • Database access restricted to internal API server only
  • Regular security reviews and dependency audits
  • Staff access to personal data limited to what is necessary for their role

8. Breach Notification

In the event of a personal information breach that poses a risk to you, we will notify you and the Information Regulator as required by POPIA s.22 — within 72 hours of becoming aware of the breach.

9. Complaints to the Information Regulator

If you are not satisfied with our response to a data-subject rights request, or believe we are not complying with POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa:

The Information Regulator (South Africa)
Website: inforegulator.org.za
Email: complaints.IR@justice.gov.za
Physical: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

10. Contact Our Information Officer

To exercise your rights or ask any question about how we handle your personal information:

Please include your full name, the email address linked to your account, and a clear description of your request. We may ask for proof of identity before processing requests that grant access to personal information.

Privacy PolicyTerms of ServiceHome