Privacy Policy

How we collect, use, and protect your personal information

Privacy Policy

Effective Date: 26 May 2026

THANDI AI (PTY) LTD (Registration No: 2025/939429/07) (hereinafter "Thandi," "we," "us," or "our") is committed to protecting your personal information in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

POPIA Registration Number: 2025-068149

1. INFORMATION OFFICER

Name: Seelan Govender

Email: hello@thandi.online | privacy@thandi.online

Phone: 0781298701

Physical Address: 170 Innes Road, Morningside, Durban, Kwa-Zulu Natal, 4001

2. PERSONAL INFORMATION WE COLLECT

From Learners:

  • Academic performance data (subjects, marks, grades)
  • Career interests and personality assessments
  • Grade level and educational institution type
  • Contact information (email for results delivery)
  • Device and browser information (technical logs)
  • From Schools:

  • Institutional contact details
  • Aggregated, anonymized learner analytics
  • Teacher/administrator email addresses
  • 3. HOW WE COLLECT DATA

  • Directly from learners via the assessment platform
  • Through school partnerships with explicit consent
  • Automated technical data (cookies, IP addresses)
  • 4. LEGAL BASIS FOR PROCESSING (POPIA)

    We process personal information based on:

  • Consent: Explicit opt-in for learners 18+ and from parents/guardians for minors under 18
  • Legitimate Interest: Providing educational guidance services
  • Legal Obligation: Compliance with South African education regulations
  • 5. PURPOSE OF PROCESSING

  • Generate personalized career and university recommendations
  • Match learners with relevant bursary opportunities
  • Provide educational institutions with aggregated insights
  • Improve our AI models and service delivery
  • 6. DATA RETENTION

  • Learner assessment data: Retained for duration of active account or maximum 3 years from last assessment, whichever is earlier
  • Account information: Until account deletion is requested
  • Anonymized analytics: Retained indefinitely for service improvement
  • 7. DATA SHARING & THIRD PARTIES

    We share data only with:

  • University partners: Anonymized trend data (no individual identifiers)
  • Bursary providers: Learner-initiated applications only
  • Service providers (sub-operators): Supabase (database), Vercel (hosting), Groq and Anthropic (AI processing), Resend (email), Upstash (session caching) — all governed by data processing agreements
  • Legal authorities: When required by South African law
  • WE DO NOT SELL PERSONAL INFORMATION TO THIRD PARTIES

    8. SECURITY MEASURES

  • End-to-end encryption for data in transit (TLS)
  • Encryption at rest via Supabase
  • Role-based access control and row-level security on learner data tables
  • API rate limiting on authenticated endpoints
  • Independent security review completed May 2026
  • POPIA-compliant data processing agreements with all sub-operators
  • 9. YOUR POPIA RIGHTS

    As a data subject, you have the right to:

  • Access your personal information (free of charge)
  • Correct inaccurate information
  • Delete your data ("right to be forgotten")
  • Object to processing
  • Data portability
  • Lodge a complaint with the Information Regulator
  • To exercise rights: Email privacy@thandi.online or hello@thandi.online with subject "POPIA Request"

    10. COOKIES & TRACKING

    See our [Cookie Policy](/legal/cookie-policy) for details. Thandi uses only essential cookies required for platform functionality. No analytics or marketing cookies are set.

    11. CROSS-BORDER DATA TRANSFERS

    We use sub-operators located in the EU and US (see POPIA Compliance Statement, Section 10). All transfers comply with POPIA Section 72 requirements through data processing agreements with each sub-operator.

    12. CHILDREN'S PRIVACY (Under 18)

  • Explicit parental/guardian consent required for learners under 18
  • Schools must act as intermediaries with documented consent
  • Age verification measures in place
  • Limited data collection for minors
  • 13. CHANGES TO THIS POLICY

    We will notify users of material changes via email and website notice. Continued use constitutes acceptance.

    14. CONTACT

    For privacy concerns: privacy@thandi.online

    For general inquiries: hello@thandi.online

    Information Regulator complaints: complaints.IR@justice.gov.za

    15. B-BBEE STATUS

    Thandi AI (PTY) LTD is a Level 1 B-BBEE Contributor with 100% black ownership.

    ---

    Version: 1.2

    Last Updated: 26 May 2026

    POPIA Registration: 2025-068149

    Document provided by THANDI AI (PTY) LTD

    POPIA Registration: 2025-068149