Privacy Policy & POPIA Notice
Protection of Personal Information Act (Act No. 4 of 2013) • Promotion of Access to Information Act (Act No. 2 of 2000) • Electronic Communications and Transactions Act (Act No. 25 of 2002)
Statutory Responsible Party Particulars (Section 18 POPIA)
Official registered identity & communication channels under POPIA Act 4 of 2013
Organization & General Inquiries
Verified Contact Channels
Document Sections & Statutory Table of Contents
01.Legislative Framework & Definitions
This Privacy Policy and Compliance Manual constitutes the statutory disclosure of Healing Scar Oils (“HSO”, “the Responsible Party”, “we”, “us”, or “our”) pursuant to the provisions of:
- Section 14 of the Constitution of the Republic of South Africa, 1996 (the fundamental constitutional right to privacy);
- The Protection of Personal Information Act No. 4 of 2013 (“POPIA”);
- The Promotion of Access to Information Act No. 2 of 2000 (“PAIA”);
- The Electronic Communications and Transactions Act No. 25 of 2002 (“ECTA”);
- The Consumer Protection Act No. 68 of 2008 (“CPA”); and
- The Cybercrimes Act No. 19 of 2020.
“Data Subject” means the person or juristic entity to whom personal information relates, including private clients, holistic consultation clients, e-commerce purchasers, and ministry partners.
“Personal Information” means information relating to an identifiable, living natural person as defined in Section 1 of POPIA, including health-related skin conditions, booking notes, delivery addresses, and contact details.
“Special Personal Information” includes health or biometric information, religious or philosophical beliefs, and personal prayer concerns as contemplated in Sections 26 to 32 of POPIA.
“Processing” means any operation concerning personal information, including collection, recording, storage, updating, retrieval, consultation, use, transmission, and destruction.
“Operator” means an authorized third party who processes personal information on our mandate without coming under our direct authority, such as payment gateways, courier delivery services, and cloud hosting providers.
02.Lawful Grounds & Justification for Processing
In terms of Section 11(1) of POPIA, Healing Scar Oils strictly processes personal information only where one or more of the following lawful grounds apply:
- Performance of a Contract (Section 11(1)(b)): Processing is necessary to fulfill orders for our 82 handcrafted botanical formulations, process payment settlements, coordinate door-to-door courier deliveries across South Africa, or conduct scheduled online wellness consultations.
- Statutory & Legal Obligation (Section 11(1)(c)): Processing is mandatory to comply with obligations imposed by South African law, including the Tax Administration Act No. 28 of 2011 (issuing commercial invoices and maintaining accounting records for five years) and the Electronic Communications and Transactions Act No. 25 of 2002.
- Legitimate Interests of the Data Subject (Section 11(1)(d)): Processing protects the client's wellbeing, such as providing tailored botanical application ratios, safety dilutions, and individualized scar care guidance.
- Legitimate Interests of the Responsible Party (Section 11(1)(f)): Processing is necessary to maintain website cybersecurity, prevent fraudulent transactions, manage inventory, and resolve customer support queries.
- Voluntary & Explicit Consent (Section 11(1)(a)): Where explicit consent is provided, such as submitting voluntary prayer requests, product formulation suggestions, subscribing to botanical wellness newsletters, or donating to the ministry.
03.Categories of Personal Information Collected
In compliance with the Principle of Minimality (Section 10 of POPIA), we collect only the personal information strictly necessary to provide our natural restorative care products and consultation services:
A. Client Identification & Delivery Information
Full names, email address, WhatsApp/mobile telephone number, physical delivery street address, postal code, city, and province for nationwide door-to-door courier shipping.
B. Online Consultation & Health Assessment Notes
Health condition descriptions, scar history (e.g. surgical, burn, keloid, acne), skin sensitivity considerations, and preferred appointment time slots provided during consultation booking.
C. Spiritual Care & Prayer Ministry Submissions
Prayer requests and formulation suggestions submitted through our ministry portal. These are treated with strict confidentiality in accordance with pastoral trust.
D. Financial & Transactional Data
PayFast transaction reference IDs, order item manifests, amounts paid, and payment status tokens. We never capture, store, or process raw credit card numbers, debit card PINs, or CVV security codes on our servers.
E. Technical & Telemetric Data
IP addresses, browser type, device information, and interaction telemetry collected anonymously via Google Analytics (G-2SYX5QV0ZM) and Google reCAPTCHA v3 to ensure platform security.
04.Compliance with the 8 Conditions for Lawful Processing
Our internal protocols embed the eight statutory conditions of Chapter 3 of POPIA:
1. Accountability (Section 8): The Responsible Party ensures all measures giving effect to the conditions of POPIA are actively implemented, monitored, and audited.
2. Processing Limitation (Sections 9–12): Information is processed lawfully, minimally, and transparently, directly collected from the data subject wherever practicable.
3. Purpose Specification (Sections 13–14): Information is collected for explicit, defined, and lawful commercial or pastoral purposes related to restorative scar care.
4. Further Processing Limitation (Section 15): Any subsequent processing must be compatible with the initial purpose for which information was collected.
5. Information Quality (Section 16): We take reasonably practicable steps to ensure that personal records are complete, accurate, not misleading, and updated where necessary.
6. Openness (Sections 17–18): Transparent documentation of processing operations and direct Section 18 statutory disclosures provided to all clients at checkout and consultation booking.
7. Security Safeguards (Sections 19–22): Modern administrative, technical, and operational safeguards protecting personal data against loss, damage, or unauthorized access.
8. Data Subject Participation (Sections 23–25): Guaranteed statutory rights for data subjects to confirm, access, correct, or request deletion of their personal records.
05.Consultation Records, Confidentiality & Prayer Requests
Because Healing Scar Oils ministers to the physical, emotional, and spiritual wellbeing of our clients, we hold all consultation and prayer data to the highest standard of sacred confidentiality:
- Clinical Aromatherapy Assessment: Consultation notes taken by founder Tersia Herbst during 45-minute comprehensive or 25-minute follow-up sessions are utilized strictly for formulating custom essential oil dilutions and recommendations. They are never shared with commercial third parties.
- Special Personal Information (Section 26 POPIA): Insofar as scar details or health backgrounds constitute health data under Section 32 of POPIA, processing is carried out with explicit client consent for healthcare and botanical counseling purposes.
- Pastoral Prayer Trust: Submissions to `[email protected]` or via `/prayer` are received in faith and shared only with our internal prayer team. If a client selects the confidentiality toggle, their request is held in strict pastoral confidence.
06.Financial Transactions & PayFast Gateway Integrity
Every monetary transaction across our website is governed by strict financial security standards:
- Server-Side Price Calculation: All transaction amounts are calculated dynamically from our verified database prices. Zero client-side tampering is possible.
- PCI-DSS Level 1 Encrypted Settlement: Payments are processed via PayFast by Network (Merchant ID: 35505821). All debit/credit card, Capitec Pay, and Instant EFT data is handled directly on PayFast's encrypted 256-bit SSL banking infrastructure.
- Zero Local Financial Storage: We do not capture or store banking card credentials, CVV codes, or account passwords. We retain only the unique PayFast transaction signature token for accounting reconciliation.
- Official IP Whitelist & Verification: Webhook notifications (ITN) are accepted exclusively from verified PayFast IP address ranges (`197.97.145.144/28`, `41.74.179.192/27`, `102.216.36.0/28`, `102.216.36.128/28`, `144.126.193.139`) with MD5 signature validation.
07.Authorized Operators & Cross-Border Cloud Transfers (Section 72)
We do not sell, rent, or trade client data under any circumstances. We disclose personal information to authorized third-party Operators solely to fulfill our contractual obligations:
- Cloud Database (Supabase PostgreSQL): Product catalogues, booking references, and order manifests are stored on Supabase enterprise cloud databases with Row-Level Security (RLS) and strict multi-tenant isolation (`hso_*` prefix).
- Web Application Hosting (Google Firebase / GCP): Web application routing and static assets are delivered via Google Cloud Platform. Under Section 72(1)(a) of POPIA, transfers to these cloud regions are governed by binding corporate rules providing equivalent or superior data protection standards.
- Payment Gateway (PayFast by Network): Transaction settlement and instant payment clearing.
- Courier & Delivery Logistics Partners: Delivery names, physical addresses, and contact numbers are provided to reputable South African couriers strictly to complete door-to-door parcel delivery.
- Authenticated Email Services (Truehost cPanel SSL): Transactional receipts and appointment confirmations are dispatched through authenticated Truehost mail servers (`bhs105.truehost.cloud` on secure port 465).
08.Security Safeguards & Breach Protocol (Sections 19–22)
We implement comprehensive technical, administrative, and physical safeguards to prevent data compromise:
TLS 1.3 encryption for all data in transit (HTTPS), AES-256 encryption for database records at rest, salted password hashing, Google Cloud App Check bot defense, and least-privilege administrative access.
Strict access control for consultation files, multi-factor authentication on administrative dashboards, authenticated SMTP delivery, and continuous security audits.
Section 22 Breach Notification Protocol: In the event of a confirmed or reasonably suspected security compromise involving personal data, we will notify the South African Information Regulator and affected data subjects as soon as reasonably possible, detailing the nature of the breach, suspected consequences, and remediation measures taken.
09.Retention & Destruction of Records (Section 14)
Personal information is retained only for as long as necessary to fulfill the statutory or commercial purpose for which it was collected:
- Financial & Commercial Invoices: Retained for a mandatory statutory period of five (5) years in compliance with the Tax Administration Act No. 28 of 2011 and Companies Act 71 of 2008.
- Consultation Client History: Retained for the duration of the ongoing client-practitioner relationship to ensure consistent holistic care and safe botanical guidance.
- Order Courier Records: Archived after delivery completion, retaining only the transaction reference for warranty and return tracking.
- Destruction Protocol: Digital records scheduled for deletion are purged using cryptographic deletion routines; physical notes are securely shredded.
10.Data Subject Rights & Information Officer Contact
Under Sections 23, 24, and 25 of POPIA and the provisions of PAIA, you have the following enforceable statutory rights:
- Right of Access: Request confirmation whether we hold your personal information and obtain a formal copy thereof.
- Right to Rectification: Request correction or updating of inaccurate, outdated, or incomplete records.
- Right to Erasure / Deletion: Request destruction or deletion of personal information where we are no longer authorized to retain it.
- Right to Object: Object on reasonable grounds to the processing of your personal information (Form 1 of the POPIA Regulations).
- Right to Withdraw Consent: Withdraw consent for non-essential communications at any time without retroactive effect.
Designated Information Officer Contact Details
All requests for access (PAIA Form 02), correction, or objection must be directed in writing to our designated Information Officer:
11.Direct Marketing, Cookies & reCAPTCHA v3
Electronic Direct Marketing (Section 69 POPIA): We strictly adhere to Section 69 of POPIA. We only send marketing communications (seasonal formulation releases, botanical dilution advice) where you have given explicit opt-in consent or where you are an existing customer who ordered products with us previously. Every newsletter contains an immediate 1-click unsubscribe mechanism.
Essential Cookies & Local Storage: Our website uses minimal, strictly essential first-party cookies and local storage tokens:
- Shopping Cart Persistence (Zustand): Preserves your selected herbal formulations in your cart across page navigation.
- Session Navigation State: Anchors page transitions to the top of the main menu for optimal user experience.
- Google Analytics (G-2SYX5QV0ZM): Aggregates anonymized traffic insights to enhance site speed and usability without tracking personally identifying data.
- Google reCAPTCHA v3: Evaluates risk scores to defend against malicious spam and automated bot submissions on our consultation, prayer, and checkout forms.
12.Lodging a Complaint with the Information Regulator
While we encourage data subjects to resolve any concerns directly with our Information Officer, you have the statutory right under Section 74 of POPIA to lodge a formal complaint with the South African Information Regulator:
The Information Regulator (South Africa)
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal Address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
General Inquiries: [email protected]
POPIA Complaints Email: [email protected]
PAIA Complaints Email: [email protected]
Official Website: https://inforegulator.org.za/

