Privacy and POPIA notice
Effective 13 September 2026. This notice explains what personal information Demo Provider (Pty) Ltd ("we") collects when you use this site and the course, why, where it goes, and what your rights are under the Protection of Personal Information Act, 2013 (POPIA).
Responsible party: Demo Provider (Pty) Ltd, 1 Demo Street, Cape Town, 8001. Information Officer: Demo Information Officer, reachable at support@demo-provider.example.
What we collect
| Information | When | Why |
|---|---|---|
| First name, surname, email address | Sign-up | To create your account, verify your email, send you your receipt and certificate, and print your name on the certificate |
| Password (stored only as a one-way hash) | Sign-up | To secure your account |
| Profession (doctor or pharmacist) | Sign-up | To pre-select your pathway modules |
| Your acceptance of the terms | Sign-up | To record the agreement |
| Invoice number, PayFast reference, amount paid, date | Checkout | To activate your enrolment, issue your tax invoice, and reconcile payment. Card and bank details go to PayFast and never reach us |
| Pathway choice, lesson progress, assessment attempts and results | Learning | To gate lessons, save your place, and determine completion |
| Certificate code, holder name, completion date, and any revocation | Completion | To issue the certificate and answer verification requests |
| Security event log (sign-ins, failed sign-ins, password resets, payments, certificate actions) | While you use the account | To detect abuse and investigate faults. Unknown email addresses appear in it only as a fingerprint |
| Server logs (IP address, browser, pages requested) | Every visit | Security and fault-finding; kept no longer than 30 days |
We ask for nothing else: no ID number, cellphone, address, or professional registration number. We do not use advertising trackers or third-party analytics on this site. The only cookie we set is the session cookie that keeps you signed in.
Where it is held
Account, progress, payment, and certificate records are held on a server in South Africa. Encrypted backups of that database are held with Cloudflare; they are encrypted before they leave the server with a key that only we hold, and are kept for up to 12 months. The public pages of this site (everything you can read without signing in) are served through a global content-delivery network that holds no personal information about you.
Emails are sent for us by Resend from its European Union region (Ireland). Your email address and the content of each message pass through that service.
Who sees it
- PayFast, to process your payment and to let us reconcile it.
- Resend, to send verification, password-reset, receipt, and certificate emails.
- Cloudflare, which holds the encrypted backups and serves the public pages, and cannot read the backups.
- Anyone who enters your certificate code on the verification page sees the holder name, the completion date, and whether the certificate is valid or revoked. Nothing else about you is public.
- Nobody else, unless the law requires it or you ask us to.
We do not sell personal information or share it for marketing. We do not send marketing email.
How long we keep it
- Account, progress, and security log: until you close your account, then deleted within 30 days.
- Tax invoices and payment records: five years after the year of purchase, as the tax laws require.
- Certificate registry (code, holder name, completion date, revocation): retained indefinitely so that a certificate can always be verified. You may ask us to revoke a certificate; we cannot delete a registry entry while a certificate carrying its code may still be presented.
- Backups: a deleted record persists in encrypted backups for up to 12 months after deletion and is not restored except to recover from a failure.
Your rights
You may ask what we hold about you, ask us to correct it, or ask us to delete it, by emailing support@demo-provider.example from the address on your account. We answer within 30 days. You may object to processing, and you may complain to the Information Regulator (South Africa), complaints.IR@justice.gov.za, if you believe we have handled your information unlawfully.
Security
Passwords are stored as salted hashes and are never sent by email. Traffic is encrypted in transit. Sign-in is rate-limited and locked after repeated failures. Access to the server is restricted to named administrators over an authenticated private network. We will tell you and the Information Regulator if a breach affects your information, as POPIA requires.
Changes
We email account holders about material changes to this notice before they take effect.