Privacy policy
How GroeiWys collects, uses, protects and shares personal information.
1. Responsible party
Riaan Burger, trading as GroeiWys, determines why and how customer information is processed. Physical address: Strydomstraat 11, Presidentia, Kroonstad, 9499, South Africa. Telephone: +27 79 873 6532. Privacy enquiries: info@groeiwys.co.za.
2. Information we process
- Registration information: name, email address, customer type, country, package and language.
- Account security: a strong one-way password hash, session status, recovery and access-link status, and the last successful login.
- Payment records: amount, currency, status, date, payment provider and a payment reference. GroeiWys does not receive or store the buyer’s complete card or bank details.
- Workspace data: profile, NFT tank readings, notes, historical records and settings entered by the user.
- Operational and security data: limited technical error, failed-login, email and payment warnings. Raw passwords and access tokens are not stored in these warnings.
3. Why we use it
To process registration and payment; activate the correct digital package; provide the service, support and account recovery; prevent fraud and unauthorised access; keep financial records; and comply with legal obligations.
4. Required fields and consequences
A name, valid email address, package choice and password are required to create an account and paid workspace. Without this information, GroeiWys cannot complete the order or provide secure access. Optional workspace content is processed only when the user enters it.
5. Service providers
GroeiWys currently uses PayFast for payments, Vercel for web hosting, Google Firebase for data storage and Resend for transactional email. They process only the information needed for their function and may use infrastructure outside South Africa. GroeiWys must maintain appropriate contractual and technical safeguards for such processing.
6. Retention
- Unpaid registrations are currently deleted automatically after 30 days.
- Active account and workspace data is kept while the service is provided and for a reasonable period afterwards for support, disputes and legal obligations.
- Financial records are kept for the period required by applicable tax, accounting and other laws.
- One-time tokens are stored as hashes and expire or are invalidated after use.
7. Security
GroeiWys uses HTTPS, separate customer workspaces, hashed passwords and tokens, limited sessions, rate limiting, secure server environment variables and PayFast server confirmation. No system is infallible; a confirmed security compromise will be handled in accordance with applicable notification requirements.
8. Your rights
Subject to applicable law, you may ask whether GroeiWys holds your personal information, request access or correction, object to certain processing, or request deletion where retention is no longer authorised or necessary. GroeiWys will first reasonably verify your identity.
9. Children and schools
School customers must ensure that they have the necessary authority before entering learners’ personal information. Current learner access is designed as read-only links; schools must not enter sensitive or unnecessary learner information in notes or profiles.
10. Enquiries and complaints
First email info@groeiwys.co.za with “POPIA request” in the subject. You may also lodge a complaint with the South African Information Regulator if the matter is not resolved.