Privacy Policy
Effective 12 August 2026. Last updated 18 August 2026.
1. Who we are
Funda ("Funda", "we", "us") is a gamified exam-preparation application for South African Grade 12 learners. The Responsible Party (as POPIA defines it), which is also the Controller (as the GDPR defines it), is Funda Go (Pty) Ltd, CIPC enterprise number K2026600708, of 2 Ferdinand Avenue, Eastleigh Ridge, Edenvale, Gauteng, 1609, South Africa.
This policy explains what personal information we collect, why we collect it, where we store it, how we protect it, who we share it with, and the rights you have.
Which laws apply. Funda is operated from South Africa and the service is directed at learners in South Africa, so POPIA governs everything we do with your personal information. Most of the infrastructure we run on sits in the European Union (section 7), and that processing is subject to the GDPR (Regulation (EU) 2016/679) in the hands of the providers concerned. We have chosen to hold ourselves to GDPR standards across the board: every user, wherever they live, gets the lawful-basis discipline set out in section 4, the rights set out in section 9, and the breach-notification commitments in section 11. Where the GDPR applies to you as a matter of law, nothing in this policy limits your rights under it.
2. Information Officer and representatives
In line with POPIA, the Information Officer of Funda Go (Pty) Ltd is the head of the company, and is reachable at support@fundafun.com. Direct any privacy question, access request, or complaint to that address and it will reach the Information Officer directly. Registration of the Information Officer with the Information Regulator is in progress; this section will name the officer and any deputy once the registration is confirmed.
- Data Protection Officer (GDPR Article 37): not appointed. We offer the service to learners in South Africa and do not offer it to, or monitor, people in the EU, so the GDPR does not apply to our processing and Article 37 is not engaged. The Information Officer performs the equivalent role. We will revisit this if we ever offer the service in the EU.
- EU representative (GDPR Article 27): not appointed, for the same reason. Hosting data in the EU does not by itself bring us within GDPR Article 3(2).
3. The personal information we collect
- Account information: email address, display name, and date of birth (used to determine whether guardian consent is required).
- Guardian information (for users under 18): the guardian's email address, and the date guardian consent was given.
- Payment information (only if a plan is bought): what was bought, the amount, the date, and PayFast's payment reference, together with the name and email address on the Funda account so that PayFast can issue its receipt. Card details are typed on PayFast's own secure page and go to PayFast, not to us. We never see or store a card number. PayFast gives us a token (a reference to the saved card) so that we can take the monthly renewal you agreed to on the 1st of each month.
- Learning data: your progress, question attempts and answers, experience points, in-app currency, streaks, and topic mastery.
- Technical and device data: device type, app version, and diagnostic error reports (which we scrub of identifying fields before storage).
- Usage data: how you interact with the app, to improve it.
We collect only what the service operationally requires. We do not collect special personal information (POPIA section 26) or special-category data (GDPR Article 9), such as health, biometric, religious, or political information, and we ask you not to submit any.
We do not sell your personal information, and we do not serve third-party advertising.
4. Why we process it, and our lawful basis
We process your information to create and secure your account, deliver and personalise the learning experience, track progress and rewards, diagnose faults, prevent abuse, and comply with our legal obligations. Our lawful bases, given as the POPIA justification first and its GDPR equivalent second:
- Performance of our agreement with you (POPIA section 11(1)(b); GDPR Article 6(1)(b)): creating and running your account, delivering lessons and questions, tracking progress, rewards, and streaks, and, if you buy a plan, taking that payment and the monthly renewals you agreed to.
- Consent (POPIA section 11(1)(a); GDPR Article 6(1)(a)): identified analytics and session recording, guardian-consented processing for under-18 users, and any optional communication. You may withdraw consent at any time (section 9), though some features will not function without it.
- Legitimate interests (POPIA section 11(1)(f); GDPR Article 6(1)(f)): keeping the service secure, preventing abuse, rate-limiting, and improving the product using anonymous or aggregated data.
- Legal obligation (POPIA section 11(1)(c); GDPR Article 6(1)(c)): retention and disclosure where the law requires it.
We do not make decisions about you that produce legal or similarly significant effects by automated means (POPIA section 71; GDPR Article 22). Question selection and difficulty are automated, but the only thing they change is what you are asked to practise next.
5. Children's information (users under 18)
We know many of our users are minors, and both POPIA and the GDPR give children's personal information special protection. If you indicate at sign-up that you are under 18, we require a parent or guardian's email address and send them a consent request. Your account remains inactive and we do not process your learning data until the guardian confirms consent. A guardian may withdraw consent at any time by contacting our Information Officer, after which we will deactivate the account and delete the associated data in line with section 8.
Our gate is stricter than either law requires. POPIA prohibits processing a child's personal information without the consent of a competent person (sections 34 and 35). The GDPR sets the consent age for online services at 16, and lets member states lower it to as young as 13 (Article 8). We require guardian consent for every user under 18, which sits above both thresholds.
We write this policy, and our consent requests, in language a learner can actually read (GDPR Article 12(1)).
Our community server. Funda runs an optional community and support server on Discord (section 6). It is not part of the app, no learning happens there, and nobody has to join it to use Funda. Discord sets its own minimum age of 13. Where a learner is under 18 we treat joining as part of the same processing the guardian consented to: we do not invite a learner before guardian consent is in place, and a guardian may ask us to remove the learner from the server at any time, which does not affect the Funda account.
6. Who we share it with (Operators and processors)
We use trusted service providers ("Operators" under POPIA, "processors" under the GDPR) who process data on our behalf under written contract:
- Supabase: database, authentication, and file storage.
- Vercel: application hosting and delivery.
- Amazon Web Services (Amazon SES, Cape Town, South Africa): transactional email (guardian-consent messages and account-related notices), sent from inside South Africa. We are moving this email from Resend (below) to Amazon SES; during the changeover either provider may deliver a message.
- Resend: transactional email (account, guardian-consent, and account-related notices), being retired in favour of Amazon SES.
- Upstash: rate-limiting and abuse prevention.
- PayFast (Payfast (Pty) Ltd, Cape Town, a subsidiary of Network International Holdings Plc): payment processing. When you buy a plan we send you to PayFast's secure payment page, where PayFast collects your card details. PayFast tells us whether the payment went through, the amount, its own payment reference, and the name and email address on your account, and gives us a card token so that we can charge the renewal you agreed to on the 1st of each month. We never receive your card number. PayFast is a PCI DSS Level 1 certified payment provider, and its handling of your card details is described in its own privacy policy at payfast.io/privacy-policy.
- Google Cloud (Vertex AI): the "Ask Fundi" study helper. When you ask Fundi a question, we send the words of your question and the matching material from our own past-paper collection to Google's AI service in the Netherlands, and it writes the explanation back. We do not send your name, your email address, your account, or anything that identifies you, and we remove email addresses, phone numbers and ID numbers from your question before it is sent. Google is contractually barred from using any of it to train its models. Ask Fundi is switched off unless you can see it in the app.
- PostHog: product analytics (PostHog EU Cloud, hosted in the European Union). By default we collect analytics anonymously: no cookies, no cross-session identifier, and no analytics profile is created. Identified analytics (linking usage to an account) and session recordings are switched on only for accounts where the required consent (including guardian consent for minors, section 4) has been given, and can be withdrawn at any time.
Each is bound to process personal information only on our instructions and to keep it secure, on terms meeting POPIA sections 20 and 21 and GDPR Article 28. Our record of these agreements, and of each provider's sub-processors and region, is kept in our processor register.
Discord is not one of our Operators. Funda runs an optional community and support server on Discord. Discord Inc. does not process your information on our instructions: it decides for itself what it collects from the people who use its service, so under POPIA it is a separate Responsible Party and under the GDPR a separate Controller. Three consequences are worth stating plainly:
- Discord's own privacy policy governs your Discord account, not this one. Read it before you join. Your Funda account and your Discord account stay separate, and we do not link them.
- Anything you post there is visible to other members and is held by Discord, on Discord's terms and for as long as Discord keeps it. Deleting your Funda account does not delete what you posted on Discord. Please do not post personal information about yourself or anyone else there, including full names, contact details, ID numbers, or screenshots that show them. The server rules say the same, and our moderators remove that content when they see it.
- We cannot confirm who you are on Discord, so we never act on account, payment, or privacy requests made there. Use the Help screen in the app or the Information Officer address in section 2. Funda staff will never send you a direct message first, and will never ask you for your password.
We prune messages from our own server after 90 days. What Discord itself keeps, and for how long, is governed by Discord's policy rather than ours.
7. Where your data is stored, and cross-border transfers
Most of your personal information is stored in the European Union:
- Database, authentication, and file storage (Supabase): European Union, Ireland.
- Product analytics (PostHog EU Cloud): stored in the European Union, Frankfurt, Germany. PostHog Inc. is a United States company and may carry out some processing (such as support and monitoring) from the United States under the standard contractual clauses in our data processing agreement.
- Application hosting and delivery (Vercel): global infrastructure operated from the United States and the EU.
- Transactional email (Amazon SES): South Africa, Cape Town (Amazon Web Services South Africa (Pty) Ltd). Guardian-consent email is sent from inside South Africa and does not leave the country on our behalf.
- Transactional email (Resend, being retired): global infrastructure operated from the United States and the EU.
- The "Ask Fundi" study helper (Google Cloud, Vertex AI): European Union, Netherlands. We call a Google data centre inside the EU, and Google guarantees the AI processing happens in that same region rather than wherever there is capacity. Nothing identifying you is sent (see section 6), so what crosses the border is a study question and our own past-paper text. Google does not keep your question unless its automated safety checks flag it, and anything flagged is held inside the EU for at most 90 days and is never used to train its models.
- Rate-limiting and abuse prevention (Upstash): European Union, Ireland. This service never receives your IP address: it is replaced with an irreversible pseudonym before it leaves our servers, so the only thing stored there is a short-lived counter that cannot be traced back to you.
- Payments (PayFast): South Africa. PayFast is a South African payment provider and processes your payment from Cape Town; its own privacy policy notes that it may also process data in the other countries where its group operates. Your card details stay with PayFast. The payment record and the card token we receive are stored with the rest of your account data in the European Union (Supabase, above).
- Community and support server (Discord): United States. This is the one transfer on this list that we do not make on your behalf. It happens because you chose to join a service that is not ours, and it is Discord, not Funda, that decides what is collected and where it is held (section 6).
Storing data in the EU means it is held to European data protection standards, which are among the strictest in the world. It also means two kinds of cross-border transfer happen, and both are covered:
- Out of South Africa. Because our infrastructure is EU-based, your information leaves South Africa. We rely on the conditions permitted by section 72 of POPIA, principally that the recipient is subject to laws or binding agreements that provide an adequate level of protection. EU data protection law meets that standard.
- Out of the European Economic Area. We administer the service from South Africa, and some providers operate from the United States. South Africa does not hold a European Commission adequacy decision, so those transfers rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and the technical measures described in section 10. For recipients in the United States we rely on the Standard Contractual Clauses, and on the EU-US Data Privacy Framework where the recipient is certified under it.
8. How long we keep it, and deletion
We keep your personal information while your account is active.
When you delete your account through the app, we deactivate it immediately: you can no longer sign in and we stop using your information to provide the service. The record is retained in a deactivated state so that the account can be restored if the deletion was a mistake, and so that we can meet our own legal and audit obligations.
To have your personal information erased permanently, contact our Information Officer. We will complete the erasure within 30 days of the request, and tell you when it is done. We will keep only what the law requires us to keep, and we will tell you what that is if it applies to you.
We may retain anonymised, non-identifying aggregates (for example, question-difficulty statistics) indefinitely for product analytics, as these no longer identify you.
Our retention periods, in summary (the full schedule is kept with our processor register and reviewed at least annually):
- Account and learning data: for as long as your account is active. If you ask us to delete your account, it is deactivated at once and permanently erased within 30 days. If an account is not used for 3 years, we disable it and keep the data for a further year in case you return, then erase it; we email you before each step.
- Guardian-consent and family-link tokens and codes: 30 days after they are used, or 60 days after they are issued if never used.
- In-app notifications: 90 days after you read them, or 180 days if unread.
- Diagnostic and error records: 90 days.
- Ask Fundi questions and answers: the text is removed after 90 days; the remaining usage statistics are deleted after 24 months.
- Push-notification subscriptions: removed when your device unsubscribes, or after 180 days without use.
- Purchase and billing records: 5 years, as South African company and tax law requires, in a form that no longer identifies your account once the account itself is deleted.
- Saved-card token (PayFast): used only for the renewals you agreed to and never charged after your plan is cancelled. Ask our Information Officer at any time to have the saved card removed from PayFast, and we will confirm when it is done.
- Administrator and security audit trail: 3 years.
9. Your rights
You have the right to:
- Access the personal information we hold about you (POPIA section 23; GDPR Article 15). We provide a downloadable export in-app.
- Correct or complete information that is inaccurate or out of date (POPIA section 24; GDPR Article 16).
- Delete your account and personal information (POPIA section 24; GDPR Article 17).
- Restrict our processing while a dispute about accuracy or lawfulness is being resolved (GDPR Article 18).
- Receive your data in a portable, machine-readable format, and have it sent to another service where that is technically feasible (GDPR Article 20). The in-app export is machine-readable.
- Object to processing based on legitimate interests, and to direct marketing at any time (POPIA sections 11(3) and 69; GDPR Article 21).
- Withdraw consent at any time, without affecting processing already carried out on that basis (POPIA section 11(2)(b); GDPR Article 7(3)).
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects (POPIA section 71; GDPR Article 22). We do not make such decisions.
- Complain to us, and to a supervisory authority (section 13).
We honour every right on this list for every user, whether or not the GDPR applies to them as a matter of law. To exercise any of them, contact our Information Officer (section 2). We respond within 30 days; if a request is complex we may extend that by up to two further months and will tell you why (GDPR Article 12(3)). Exercising these rights is free, unless a request is manifestly unfounded or excessive. POPIA prescribes forms for certain requests; we accept a plain email and will send you the prescribed form if one is needed.
10. Security
We protect your information with access controls, encryption in transit and at rest, row-level security on our database, rate-limiting, and scrubbing of identifying fields from diagnostic logs. Learner names are never shown on leaderboards; a system-generated alias is used instead. Parent and sponsor views never expose an individual learner's data beyond what that role is entitled to see. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data, including that of minors.
11. If something goes wrong (data breaches)
If personal information is accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected users as soon as reasonably possible after establishing the facts, as POPIA section 22 requires. Where the GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach (Article 33), and tell affected individuals directly and without undue delay where the breach is likely to result in a high risk to their rights (Article 34). A notice will describe what happened, which data was involved, what we are doing about it, and what you can do to protect yourself.
We keep an internal record of every breach, whether or not it is notifiable.
12. Changes to this policy
We may update this policy. Material changes will be communicated in-app, and the "Last updated" date above will change. Where a change materially alters processing that rests on your consent, we will ask for that consent again rather than assume it carries over.
13. Contact and complaints
Information Officer, Funda Go (Pty) Ltd: support@fundafun.com
Information Regulator (South Africa), to whom you may complain directly:
- General enquiries:
enquiries@inforegulator.org.za, telephone 010 023 5200 - POPIA complaints:
POPIAComplaints@inforegulator.org.za, or through the Regulator's eServices portal - Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- Website:
https://inforegulator.org.za
If you are in the EEA or the UK, you may instead lodge a complaint with your local data protection supervisory authority. The European Data Protection Board publishes the list of national authorities at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.