Privacy Policy
Last Updated: October 23, 2025
In Plain Language
We only collect your email address to send you wellness activities. We never sell your information, and you can unsubscribe anytime.
Quick Navigation
- 1. Who We Are
- 2. What Information We Collect
- 3. How We Use Your Information
- 4. Legal Basis for Processing
- 5. How We Protect Your Information
- 6. Sharing Your Information
- 7. Your Rights Under POPIA
- 8. Email Preferences
- 9. Children's Privacy
- 10. Data Retention
- 11. International Data Transfers
- 12. Cookies and Tracking
- 13. Changes to This Policy
- 14. Contact Us
Service Name: Gentle Wellness
Service Type: Free wellness newsletter for South African seniors
Location: South Africa
Contact: privacy@gentlewellness.co.za
Information You Provide
Email Address (Required)
- Collected when you subscribe to our newsletter
- Used only to send wellness activities
- Stored securely in our database
Feedback (Optional)
- Satisfaction ratings (1-5 stars)
- Activity preferences
- Testimonials (only with your explicit permission)
- Collected after 4 weeks of subscription
Information Automatically Collected
Email Engagement Data
- Whether you opened our emails (tracking pixel)
- Which activity links you clicked
- Used to improve content and measure engagement
- Not sold or shared with third parties
Technical Information
- IP address (for security and rate limiting)
- Browser type (for accessibility improvements)
- Device type (mobile vs desktop)
Information We DO NOT Collect
- Your name (unless you choose to provide it in feedback)
- Phone number
- Physical address
- Payment information (service is 100% free)
- Medical information
- ID numbers
Primary Use: Newsletter Delivery
- Send wellness activities 3 times per week (Monday, Wednesday, Friday)
- Send important service announcements (rare)
- Send feedback surveys after 4 weeks (optional)
Analytics Use
- Understand which activities are most popular
- Improve content quality
- Measure newsletter effectiveness
We do not use this data for advertising or sell it to anyone.
Legal Compliance
We may use your information to:
- Comply with South African law (POPIA, CPA)
- Respond to legal requests from authorities
- Protect our rights and prevent abuse
Under POPIA, we process your personal information based on:
Consent (Primary Basis)
- You explicitly consent when you subscribe
- You can withdraw consent by unsubscribing anytime
- Unsubscribe link in every email
Legitimate Interest
- Improving service quality
- Preventing fraud and abuse
- Analytics for content optimization
Technical Safeguards
- HTTPS encryption for all data transmission
- Passwords hashed with BCrypt (not stored in plain text)
- Database access restricted to authorized personnel only
- Regular security updates
Access Controls
- Only essential team members can access subscriber data
- Admin accounts require strong passwords
- All access is logged and monitored
Data Retention
- Active subscribers: Data retained while subscribed
- Unsubscribed users: Data anonymized after 30 days
- Legal requirement: Some data retained for 5 years (POPIA compliance)
What We Don't Do
- Sell your email address
- Share your information with marketers
- Send spam or unsolicited emails
- Use your data for purposes other than stated
We Do Not Sell or Rent Your Information
Your email address is never sold, rented, or shared for marketing purposes.
Limited Sharing with Service Providers
Brevo (Email Delivery)
- Location: European Union (GDPR compliant)
- Purpose: Send newsletters via their infrastructure
- Data shared: Email address, email content
- Privacy Policy: brevo.com/legal/privacypolicy
Microsoft SQL Server (Database)
- Location: South Africa (bb8.webetc.co.za)
- Purpose: Store subscriber data
- Data shared: All collected information
- Security: Encrypted with access controls
These providers are contractually obligated to protect your data and use it only for our stated purposes.
Legal Disclosures
We may disclose your information if:
- Required by South African law
- Responding to valid legal process (court order, subpoena)
- Protecting our rights or preventing fraud
- With your explicit consent
As a South African Resident, You Have the Right To:
Access
Request a copy of your personal information
- Email privacy@gentlewellness.co.za
- We will respond within 30 days (free of charge)
Rectification
Correct inaccurate information
- Update your email address by unsubscribing and resubscribing
- Or contact privacy@gentlewellness.co.za
Deletion
Request deletion of your information
- Unsubscribe via link in any email (automatic deletion within 30 days)
- Or email privacy@gentlewellness.co.za for immediate deletion
Objection
Object to processing
- Unsubscribe at any time
- No questions asked, no penalties
Data Portability
Receive your data in a portable format
- Request via privacy@gentlewellness.co.za
- We will provide JSON or CSV file within 30 days
Lodge a Complaint
If you believe we violated POPIA
Information Regulator (South Africa)
Website: inforegulator.org.za
Email: complaints.IR@justice.gov.za
You Are Always in Control
Easy Unsubscribe
- Click "Unsubscribe" link in any email
- Immediate removal from mailing list
- No questions asked, no delay
What Happens When You Unsubscribe
- You are immediately removed from mailing list
- No more newsletters sent
- Your email is anonymized within 30 days
- Engagement data is retained in aggregate (anonymized) for analytics
You will receive one confirmation email after unsubscribing. No further emails after that.
Gentle Wellness is designed for adults aged 60 and older. We do not knowingly collect information from anyone under 18 years of age.
If we discover we have inadvertently collected information from a minor, we will delete it immediately.
How Long We Keep Your Information
While You're Subscribed
- Email address and engagement data retained indefinitely
- Used to send newsletters and improve service
After You Unsubscribe
- Email address anonymized within 30 days
- Aggregate analytics data (anonymized) retained for 5 years
- Legal records retained as required by law (up to 5 years)
Inactive Accounts
If you don't open emails for 12 consecutive months, we may:
- Send a re-engagement email
- If no response within 30 days, automatically unsubscribe you
- This protects your privacy and maintains our email sender reputation
Data Location: All data stored in South Africa
We do not transfer your personal information outside South Africa except:
- Brevo email servers (EU - GDPR compliant, adequate protection)
- With your explicit consent
- In accordance with POPIA Chapter 9 (Transborder Information Flows)
Cookies We Use
Essential Cookies
- Session management for admin interface
- CSRF protection tokens
- No tracking cookies on public pages
Analytics
- We use server-side analytics (no Google Analytics)
- Email tracking pixel (1x1 transparent image)
- Used only to measure open rates
Your Control
- You can disable cookies in your browser
- This may affect admin functionality
- Newsletter delivery works without cookies
We may update this Privacy Policy occasionally. If we make material changes:
We will notify you by:
- Email to all subscribers
- Notice on our website (30 days before changes take effect)
- Continued use after notice = acceptance of new policy
Last Updated Date: Always shown at the top of this policy
We will respond within:
- 7 days for general inquiries
- 30 days for POPIA rights requests (access, deletion, etc.)
Information Regulator (POPIA Complaints)
If you believe we have violated POPIA:
Information Regulator (South Africa)
JD House, 27 Stiemens Street
Braamfontein, Johannesburg, 2001
Email: complaints.IR@justice.gov.za
Website: inforegulator.org.za
Summary (Plain Language)
Questions? Email privacy@gentlewellness.co.za
This Privacy Policy is effective as of October 23, 2025
© 2025 Gentle Wellness. All rights reserved.