SS

Study Smart SA

Legal & Privacy Information

Privacy Policy

Effective date: May 2025  ·  Governed by the Protection of Personal Information Act 4 of 2013 (POPIA)

1. Who We Are

Study Smart SA (“we”, “us”, “our”) is an educational technology service providing AI-assisted study materials and examination practice papers aligned to the South African CAPS curriculum. By accessing Study Smart SA you confirm that you have read and understood this Privacy Policy.

Information Officer: As required by POPIA, our Information Officer can be contacted at hello@studysmartsa.co.za.

2. Personal Information We Collect

We collect only the minimum personal information required to provide and administer the service:

  • Full name — to personalise your experience within the app.
  • Email address — to identify your account and process subscription billing.
  • Child’s grade(s) — to display curriculum-appropriate content (up to three grades per account).
  • Subscription and billing data — your active plan (Monthly, Per Term, or Annual), billing cycle, subscription status, next billing date, and a PayFast payment reference. We do not store your card number or banking details; these are held exclusively by PayFast.

We do not collect your child’s name, school, or any other personal information about your child.

3. How We Use Your Information

Your personal information is used solely for the following purposes:

  • Creating and maintaining your account.
  • Processing your subscription payment via PayFast and confirming access after each successful debit.
  • Maintaining your authenticated session so you do not need to log in on every visit.
  • Displaying your name as a personalised greeting within the app.
  • Showing grade-appropriate CAPS content.
  • Managing subscription renewals, cancellations, and failed-payment events notified to us by PayFast.

We do not use your information for marketing to third parties, profiling, or automated decision-making beyond subscription status management.

4. Lawful Basis for Processing

We process your personal information on the basis of your explicit consent, given when you agree to these policies at registration, and as necessary to fulfil the subscription contract you enter into with us. You may withdraw consent at any time by contacting us to cancel your subscription and delete your account.

5. Data Storage and Security

Your name, email address, grade selection, and subscription data are stored in a secured cloud database (Supabase) hosted on servers with industry-standard encryption at rest and in transit. Access to this database is restricted to authorised personnel only.

Authentication tokens stored in cookies are signed using HMAC-SHA256 cryptographic signatures to prevent tampering. Session cookies expire after 30 days.

6. Third-Party Service Providers

We use the following third-party services to operate the platform. Each processes only the minimum data necessary:

  • Supabase— secure cloud database storing your name, email, grade selection, and subscription status. Subject to Supabase’s privacy and security policies.
  • PayFast — South African payment gateway that processes all subscription billing on our behalf. PayFast receives your name, email address, and the plan amount in order to process payment. Your card and banking details are held exclusively by PayFast and are never transmitted to or stored by Study Smart SA. PayFast is regulated and compliant with the Payment Card Industry Data Security Standard (PCI-DSS). See payfast.co.za/privacy-policy.
  • AI content providers — third-party AI services are used to generate study content. Your personal information is not sent to these services. Only the subject, grade, and curriculum topic you select are used to generate content.

We do not sell, rent, or share your personal information with any third party for commercial purposes.

7. Your Rights Under POPIA

As a data subject under POPIA, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request that inaccurate or incomplete information be corrected.
  • Deletion — request that your personal information be deleted from our systems.
  • Objection — object to the processing of your personal information.
  • Withdraw consent — withdraw your consent to processing at any time, which will result in your access being deactivated and your subscription being cancelled.
  • Complain — lodge a complaint with the Information Regulator of South Africa at www.inforegulator.org.za.

To exercise any of these rights, please contact our Information Officer at hello@studysmartsa.co.za. We will respond within 30 days.

8. Data Retention

We retain your personal information for as long as you hold an active subscription. Subscription and payment records may be retained for up to five years after account closure for financial and legal compliance purposes. If you request deletion, personal identifiers will be removed within 30 days, subject to any statutory retention obligations.

9. Children’s Privacy

Study Smart SA is designed for use by parents and guardians, not directly by children. We do not knowingly collect personal information from children under the age of 18. The account holder is always the parent or guardian.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you via the app. Continued use of the service after notification constitutes acceptance of the updated policy.

Last updated: May 2025  ·  Return to login