Corrective draft and approval boundary
This version corrects omissions in the earlier notice. Qualified legal and privacy reviewers must confirm the applicable processing grounds, special personal information conditions, recipient arrangements, retention and market-specific disclosures before approval and publication. This draft does not itself establish those approvals or consent. ¶
Account deletion and other privacy-rights requests remain available while this draft is under review. Previously confirmed requests remain eligible for fulfilment; a notice update does not cancel them. The earlier version remains available for historical reference, not as evidence that these corrections have been approved. ¶
Who is responsible and who this policy covers
FLEXa is developed and provided by The Sovereign Series (Pty) Limited, the responsible party for the processing described in this policy unless an approved market annex identifies a different local responsible party. Privacy questions and rights requests can be sent to hello@sovereignseries.africa. ¶
This policy covers prospective and registered members, tenant and gym applicants, gym operators, authorised platform users, support contacts, and people whose information is included in a lawful access, payment, verification, security or audit record. Market-specific annexes may add mandatory local disclosures without reducing applicable rights. ¶
Where information comes from and whether it is required
Most information comes directly from you when you register, update a profile, upload a document, create a purchase, request access, contact support or request deletion. FLEXa also receives technical and security information from your browser or device; access and branch information from participating gyms; and status, reference or verification results from payment, identity-verification and communications providers. ¶
Fields marked as required are needed for the selected account or feature. Optional profile images, precise location, voice or video calls, HEALBE health submissions and health-sharing preferences can be declined. Contacts are entered by the member; FLEXa does not import the device address book. The current service does not require access to device call logs, SMS content, installed-app inventory or background location. Microphone access is requested for a member-initiated voice or video call, and camera access is requested for video calling or scanning. ¶
Why FLEXa processes information
FLEXa processes information to take steps you request and perform its service contract; comply with accounting, tax, consumer, identity, security and other legal obligations; protect the legitimate interests of members, gyms, FLEXa and the public; and obtain consent where the law or a device permission requires it. ¶
Operational purposes include account creation and security, eligibility and identity checks, gym discovery, quote calculation, purchase fulfilment, access-code issuance and validation, operator settlement, refunds, fraud and abuse prevention, support, service reliability, legal claims and attributable audit records. FLEXa does not sell personal or sensitive information and does not use it for third-party advertising. ¶
Location, camera, microphone, biometrics and notifications
Approximate location may be inferred from an internet address to show relevant markets or nearby gyms. Precise foreground location is requested only when you use a feature that needs it, such as distance, geofence or gym-entry validation. The current app does not request background location. ¶
Camera frames used to scan a gym QR code are processed for the scan and are not uploaded or retained as footage. A profile image or identity-document image that you deliberately capture or select is uploaded and handled as account or verification information. ¶
Configured member voice and video calling uses the microphone, and video also uses the camera, only after you join or accept a call and grant permission. Calls can use the portal or the foreground in-app call surface. The native app stops capture when you leave that surface or put the app in the background; it does not implement phone-equivalent background calling. Call participants receive the selected live audio or video, and connection setup processes call and network metadata. A member can decline a call or deny permission; camera permission for scanning is separate from consent to a call. ¶
A biometric sign-in prompt is performed by the device operating system. FLEXa receives the success or failure result and does not receive or store a fingerprint, face template or other biometric template. ¶
If the service is configured and you opt in, native message and call alerts use Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM). FLEXa binds a protected device delivery identifier to your authenticated session and notification choices. Providers receive that identifier and generic event references, not the chat body or sender name. Notification permission alone does not make delivery available or guaranteed, and a call alert does not automatically answer a call. This is ordinary notification delivery, not Apple VoIP push or a system background-call service. ¶
Pricing, eligibility and automated rules
FLEXa uses documented rules to derive the current gym demand band and quote, revalidate a purchase, assess account or market eligibility, detect security risk, and decide whether an access credential can be issued or redeemed. These rules can use branch, time, market, account, entitlement, device and foreground-location evidence. ¶
Material outcomes retain a status or reason code for audit and support. You may contact FLEXa to question an outcome or request human review where applicable. FLEXa does not use these rules to make credit, insurance or employment decisions. ¶
Cookies, app storage and internal analytics
The website uses essential authentication and antiforgery cookies, browser local storage for its installation identifier, and service-worker Cache Storage for the application shell. The mobile app keeps protected session material in operating-system secure storage, an installation identifier in Preferences and secure storage, and an application-private SQLite cache containing limited venue, visit, credential, purchase-reference and screen-state data. ¶
Logging out revokes the active server session and removes authenticated browser or app session material and user-scoped cached screen data. A non-secret installation identifier and the public application shell may remain so FLEXa can recognise an installation and start safely; uninstalling the app or clearing site or app storage removes that local copy. Server-side deletion cannot remotely erase a device that is offline. FLEXa creates internal service, security, purchase, access and audit events to operate the platform, investigate failures and measure service performance. The current app does not request the Android advertising identifier and does not use third-party advertising cookies or an advertising analytics SDK. ¶
International processing
Cloud, communications, verification, mapping or payment providers may process information in countries other than the country where it was collected. FLEXa must assess the destination, recipient and safeguard before enabling a provider or market flow. ¶
Where applicable law requires it, FLEXa relies on an approved adequacy basis, binding agreement, consent or another lawful transfer mechanism. Contact FLEXa for information about safeguards relevant to a specific transfer. ¶
How information is protected
FLEXa uses HTTPS in transit, role-based authorisation, multi-factor authentication, device-bound sessions, protected credentials, restricted administrative access, append-only audit controls, idempotency and session revocation. Member-chat messages are sent to BUA Speak as authenticated AES-256-GCM encrypted envelopes under the configured processor integration; selected linked documents and notification content are protected by the application. The mobile SQLite cache is application-private but is not represented as independently encrypted by FLEXa. ¶
No system can eliminate every risk. FLEXa investigates suspected incidents and will notify affected people and regulators when required by applicable law. Do not send passwords, raw payment credentials, one-time codes or identity-document images by ordinary support email. ¶
Your choices, rights and complaints
Subject to applicable law, you may request confirmation and access, correction or deletion; object to or ask for restriction of certain processing; withdraw consent without affecting earlier lawful processing; request portability where available; and complain about how information is handled. FLEXa may verify identity and may refuse or limit a request where the law requires or permits it. ¶
Send a rights request to hello@sovereignseries.africa. South African data subjects may also lodge a POPIA complaint with the Information Regulator. Details are available at https://inforegulator.org.za/contact-us/. ¶
Age and children's information
FLEXa member accounts are intended for adults aged 18 or older. Where enabled, verified date-of-birth evidence or an adult-eligibility decision is processed through the protected eligibility boundary and is not placed in ordinary session claims or public analytics. FLEXa does not knowingly offer a member account to a child. ¶
If you believe a child has supplied information contrary to this restriction, contact hello@sovereignseries.africa so FLEXa can investigate and take the action required by law. ¶
Account deletion
An authenticated member can request deletion after identity re-verification. The public web route is available to a low-privilege consumer account that cannot sign in and proves control of its registered email address; operator, administrator and multi-role accounts require authenticated handling or assisted review because their records can affect a gym tenant, staff or regulated evidence. ¶
Once a request is confirmed, FLEXa disables the account, revokes active sessions and queues manual privacy-operator fulfilment. For every affected member-chat binding, fulfilment first instructs BUA Speak to remove the participant copy and irreversibly anonymise that member's sender and encrypted-message processor copies. Only after BUA confirms the idempotent erasure does FLEXa pseudonymise the core identity profile, remove local member-chat participant and authored-message rows, remove authentication roles, claims, logins and tokens, and remove the current profile image. A failed or cancelled processor request leaves fulfilment incomplete and available for safe retry. Until every required processor and local step succeeds, disabling or pseudonymising the active profile does not yet constitute erasure of every associated record. Completed fulfilment does not erase lawfully retained records or every device-local copy. ¶
Successful fulfilment also removes the member's stored HEALBE samples, member-entered emergency contacts, health-notification preferences, health-delivery tracking rows, native push registrations and native push-delivery tracking. Disabling the account or withdrawing a notification preference alone is not deletion of those records. Health content may remain in inbox, protected notification-outbox and audit records under the existing restricted retained-record boundary. Messages already delivered to a recipient and offline device copies cannot be remotely recalled by account deletion; applicable retained-record and processor boundaries still apply. An alert already accepted by a push provider cannot be recalled by signing out or deleting the account; opening it still requires current authorization. ¶
Linked verification documents, agreement evidence, support and inbox records, referrals, protected notification content, adult-eligibility evidence, finance, access-control, security and audit records may retain an opaque user key or other identifying evidence. The retention register assigns each retained category a purpose, lawful basis, access restriction and disposal rule; records without a lawful retention need must be erased or irreversibly de-identified. ¶
Retention
Active profile information is kept while the account is active and for the limited period needed to complete closure, protect the service or resolve a request. One-time credentials, confirmation links and temporary security material expire on their configured short-lived schedules. Incomplete gym applications are deleted after the configured abandonment period, currently 10 days after the latest save; identity-capture links expire after 48 hours, but expiry of a link does not by itself prove erasure of its stored record or content. ¶
The controlled retention register records the trigger, period, lawful basis, access restriction, disposal method and backup treatment for financial, payment, contract, identity, eligibility, access, fraud, dispute, support, communications, device and audit records. No unspecified category is treated as retained indefinitely or erased automatically. Append-only evidence is preserved only while a lawful retention need applies and is deleted or irreversibly de-identified when that need ends. ¶
Changes to this policy
FLEXa retains versioned notices. This corrective version is a review draft; approval, any effective date, and communication of material changes through appropriate channels are separate publication steps. A draft date must not be treated as an approval or effective date. ¶
A market annex may identify additional local rights, responsible parties, providers or retention duties. The current public version and its available versions are exposed through the FLEXa privacy-notice endpoint. ¶
Optional HEALBE information, contacts and health alerts
When you submit HEALBE device or portal samples through the optional health integration, FLEXa stores the source sample reference, measurement and receipt times, and supplied heart rate, steps, calorie intake and expenditure, hydration, stress, sleep, wear duration and weight values. It derives member health summaries from those samples. Listing this integration does not mean every device or provider connection is enabled. ¶
You may enter emergency-contact names, relationship types, email addresses and telephone numbers. Obtain the person's permission to supply their details and tell them how you intend to use them. Daily summaries, urgent alerts and sharing with a doctor, trainer or active Global Administrators have separate member choices; sharing is not implied by an account or chat invitation. Changing a sharing preference stops future use of that choice but does not recall information already sent. ¶
Wearable values and automated extreme-heart-rate rules can be wrong. Summaries and alerts are not diagnosis, medical advice, continuous monitoring or an emergency-response service. Seek appropriate medical assistance instead of relying on an app alert. The lawful basis and applicable special-personal-information conditions for each health and third-party-contact flow, provider arrangements and category-specific retention schedule require qualified review; this draft does not claim those decisions have been made. ¶
Data categories and controls
The categories below describe the current web and mobile implementation. A feature that is not enabled in a user's market does not collect its feature-specific information merely because it is listed here. ¶
Identity, account and contact information
- Examples
- Name, username, email address, mobile number, member number, postal address, country, market, account role and communication preferences.
- Purpose
- Register and administer the account, contact you, route the correct market and provide role-appropriate services.
- Choice
- Core account fields are required; optional profile fields and preferences are identified in context.
Eligibility and verification information
- Examples
- Identification type and protected number, protected identity-document image or PDF, issuing country, verified date of birth where enabled, verification result, provider reference, adult-eligibility status and protected evidence reference.
- Purpose
- Verify identity, age or market eligibility; prevent duplicate or fraudulent accounts; satisfy approved onboarding and legal controls.
- Choice
- Required only when the selected market, role or regulated feature requires verification.
Device, authentication and security information
- Examples
- Installation-specific device identifier or hash, session identifier, login and OTP events, IP address, user agent, Google Play Integrity token and verdict when enabled, security alerts and revocation history.
- Purpose
- Authenticate users, bind sessions and access codes, prevent fraud, investigate abuse and keep the service reliable.
- Choice
- Required for protected account and access features; FLEXa does not collect the Android advertising identifier.
Location information
- Examples
- Approximate location derived from IP; optional precise foreground latitude and longitude; branch distance, geofence and access-event location evidence.
- Purpose
- Show relevant gyms, calculate distance and validate that access is attempted at the selected branch.
- Choice
- Precise location is permission-based and feature-specific. Declining it prevents features that require geofence evidence.
Images, documents, camera and biometric result
- Examples
- Optional profile image; identity or onboarding document you upload; QR scan result; local biometric success or failure result.
- Purpose
- Display an optional profile image, verify identity or an operator application, scan access codes and protect sign-in.
- Choice
- QR footage and biometric templates are not uploaded. Deliberately submitted images and documents are uploaded.
Purchase, payment and settlement information
- Examples
- Product, selected gym branch, captured quote, amount, currency, payment reference and status, refund, chargeback and operator-settlement records.
- Purpose
- Create and reconcile purchases, grant visits, settle gyms, issue eligible refunds, prevent fraud and meet accounting duties.
- Choice
- Required when using a paid feature. FLEXa does not store raw card, bank-login or one-time payment credentials.
Gym access and activity information
- Examples
- Visit entitlement, reservation, short-lived credential, branch, entry time, access outcome and reason code, redemption and training-history display.
- Purpose
- Issue and validate access, prevent duplicate redemption, provide visit history, support disputes and protect venue safety.
- Choice
- Required when requesting or using a FLEXa gym visit.
Communications and support information
- Examples
- Support category, subject, message and resolution; inbox or referral content; notification delivery and read state; agreement acceptance evidence; and privacy or deletion request.
- Purpose
- Answer requests, deliver security and transaction messages, investigate problems and evidence privacy outcomes.
- Choice
- Support content is optional; essential security or transaction messages may be necessary for the service.
Member-chat invitations, encrypted messages and safety controls
- Examples
- Chat title; invitation and final consent state; stable or pseudonymous FLEXa member identifiers; BUA conversation and case references; message identifier, authenticated AES-256-GCM ciphertext, sender reference, sent and delivery timestamps, retry state and erasure marker; and, when a member uses a safety control, the report category and optional details, encrypted evidence snapshot, reported or blocked member reference, leave state, safety-ticket reference and append-only action timestamps.
- Purpose
- Create a direct or group member chat only after the invited members have made final choices; provision the BUA conversation; store, deliver and safely retry encrypted messages; reject prohibited content; investigate safety, integrity or delivery reports; enforce member blocks and conversation leave; and prove an erasure outcome.
- Choice
- Optional. An invited member may decline before provisioning. Only active participants can send or read a provisioned chat, and members can report a received message, block its sender or leave the conversation.
Gym, tenant and authorised-user information
- Examples
- Business and branch details, directors, beneficial owners or authorised contacts, registration and onboarding documents, staff roles, approvals, pricing requests and operational audit evidence.
- Purpose
- Assess and administer participating gyms, enforce maker-checker controls, publish approved branches and settle operators.
- Choice
- Required for a tenant or operator applying for or administering FLEXa participation.
Service usage, diagnostics and audit information
- Examples
- Feature and business events, failure and timing data, configuration and policy versions, decisions, actor, timestamp and idempotency references.
- Purpose
- Operate, secure, troubleshoot and improve the service; reconcile changes; demonstrate accountability and investigate incidents.
- Choice
- Generated when the relevant service or governed action is used; not used for third-party advertising.
FLEXa Assist questions and responses
- Examples
- When the optional assistant is enabled: the question you intentionally submit, market, portal scope and role names; a one-way prompt hash, provider model and request reference; and the returned advisory answer.
- Purpose
- Provide role-bounded workflow guidance. The assistant cannot approve, publish, pay, unlock or change platform records.
- Choice
- Optional and disabled when no approved provider configuration is present. Do not enter passwords, OTPs, identity numbers, payment information or other personal or secret data.
Member-call media and connection information
- Examples
- Selected live microphone audio, camera video for video calls, participant and call references, invitation and call state, and network connection metadata.
- Purpose
- Set up and operate a joined or accepted member call through the portal or foreground in-app call surface.
- Choice
- Optional. Decline a call or deny microphone or camera permission. Native capture stops on leaving the call surface or backgrounding the app; system background calling is not implemented.
Native notification registration and delivery information
- Examples
- Protected APNs device token or Firebase installation identifier, hashed installation and authenticated-session bindings, platform and environment, notification choices, generic chat/call/event references, delivery state and timestamps.
- Purpose
- Deliver optional generic message and call alerts to the opted-in authenticated installation, suppress stale or unauthorized alerts, and open the relevant protected page after authorization.
- Choice
- Optional and disabled without approved provider configuration. Revoke the choice in the app or operating-system settings. Provider acceptance does not prove display or reading; no chat body or sender name is included in the provider payload.
HEALBE samples and derived health summaries
- Examples
- Source sample and connection type, timestamps, supplied heart rate, steps, calorie intake and expenditure, hydration, stress, sleep, wear duration, weight and derived health matrix summaries.
- Purpose
- Display submitted member health information and, when chosen, derive summaries and wearable-signal alerts. Not diagnosis or emergency monitoring.
- Choice
- Optional feature-specific submissions. Notification and recipient-sharing choices are separate. Legal approval of the processing and retention conditions is pending.
Member-entered emergency and professional contacts
- Examples
- Contact type, first name, surname, email address and telephone number for up to three member-entered contacts.
- Purpose
- Maintain the member's selected contacts and address optional urgent health alerts to doctor or trainer contacts when the matching sharing choice is enabled.
- Choice
- Optional, not imported from the device address book. The member should obtain permission from the contact; recipient qualification is not established by entering their details.
Health consent preferences and delivery tracking
- Examples
- Daily-summary and urgent-alert choices, separate doctor, trainer and Global Administrator sharing choices, consent and update timestamps, and delivery kind and idempotency references.
- Purpose
- Apply the selected health-message and recipient choices and avoid duplicate delivery.
- Choice
- Optional settings can be changed; changing them does not delete previously stored samples or recall already delivered messages.
Recipients and service providers
Provider availability and legal role can differ by market. FLEXa must approve the provider and relevant safeguards before enabling the integration. ¶
Participating gyms and operators
- Information
- The minimum member, credential, branch, access-outcome and dispute information needed for a selected visit.
- Purpose
- Validate entry, operate the venue, resolve an access issue and reconcile an eligible settlement.
PayFast and approved payment, refund and settlement providers
- Information
- Customer or member reference, purchase and branch details, amount, currency, payment reference, status, refund or settlement evidence.
- Purpose
- Process or confirm payment, refund and gym settlement; reconcile financial events and prevent fraud.
VerifyNow or another approved identity-verification provider
- Information
- When enabled: identity-document image or PDF, document type, issuing country, protected request fingerprint and provider reference.
- Purpose
- Authenticate the submitted document and return a match or review result.
Microsoft 365 and BulkSMS or approved replacement providers
- Information
- Registered email address or mobile number and the content of an authorised security, transaction, support or onboarding message.
- Purpose
- Deliver email and SMS communications. Passwords and raw payment credentials are not sent in these messages.
Google Maps and ipwho.is or approved replacement providers
- Information
- Map request, browser technical data, submitted address and coordinates for Google Maps; requesting IP address and returned approximate locality for ipwho.is.
- Purpose
- Render maps or geocode a submitted place and provide an approximate location when device location is not used.
CountriesNow or an approved replacement provider
- Information
- Selected country or region input and the returned country, state, city, currency or telephone-code reference data.
- Purpose
- Populate country and locality selectors used during registration and profile maintenance.
Google Play Integrity
- Information
- When enabled: integrity token, request hash, app or package and licensing signals, and device or account integrity verdicts returned by Google Play.
- Purpose
- Assess whether a protected Android request came from the expected app installation and apply the configured security policy.
Apple App Attest
- Information
- When enabled: an app-generated key identifier, attestation or assertion, request binding hash, bundle and operating-environment evidence returned through Apple services.
- Purpose
- Assess whether a protected iOS or Apple TV request came from the expected app installation and bind the result to the exact request and device session.
Approved FLEXa Assist model provider
- Information
- Only when the optional assistant is enabled: the submitted question together with the user's market, portal scope and role names. Passwords, OTPs, identity numbers, payment details and API keys are prohibited.
- Purpose
- Return advisory workflow guidance. The provider is not authorised to execute a FLEXa action or receive live balances, access decisions or identity documents.
BUA Speak member-chat processor
- Information
- For a consented chat: stable FLEXa chat identifier, BUA conversation and case references, stable or pseudonymous member identifiers and membership, message identifiers, authenticated encrypted message envelopes, timestamps and delivery metadata. The integration does not send a member email address, member number or chat title.
- Purpose
- Act only as FLEXa's processor to provision the consented conversation, validate and store the encrypted message copy, support idempotent delivery, and remove or irreversibly anonymise participant and member-authored processor copies when FLEXa fulfils account deletion.
Cloud hosting, database, security and operational providers
- Information
- Encrypted or access-controlled application data, logs, backups, network metadata and support diagnostics as necessary for the hosted service.
- Purpose
- Host and protect FLEXa, maintain availability, investigate incidents and recover the service.
Professional advisers, courts and public authorities
- Information
- Only the information relevant to an audit, legal claim, regulatory request, statutory report or lawful compulsory process.
- Purpose
- Obtain legal, accounting, insurance or security advice; establish or defend claims; and comply with law.
Accepted member-call participants
- Information
- The live audio and, for video calls, camera media selected for the call, plus call and connection information.
- Purpose
- Communicate in the member-initiated portal or foreground in-app call. Call acceptance does not grant access to a member's health records.
Apple, Google and the configured notification gateway operator
- Information
- Device delivery identifiers, platform and generic event references needed to route an opted-in alert. The provider payload excludes chat bodies, sender names and health content.
- Purpose
- Route generic native notifications under the approved service configuration. Applicable operator arrangements, international transfers and provider retention require privacy review; sharing infrastructure does not authorize another application's identities or credentials.
Member-selected health-alert recipients
- Information
- The member's display name, relevant wearable readings and alert text sent to the member and, only under the respective sharing choice, entered doctor or trainer email addresses or active Global Administrators.
- Purpose
- Deliver opted-in wearable-signal alerts. Entered contacts are not independently verified clinical providers, and these alerts are not an emergency-response service.
Records retained after deletion
Deleting an account removes the active profile and authentication material. It does not rewrite evidence that FLEXa must preserve for a lawful, security, accounting or dispute-resolution purpose. ¶
Financial and payment records
Retain gym-visit purchase and payment records with an opaque or pseudonymised subject key; remove direct profile fields from the active account.
Accounting, settlement, fraud prevention, refunds, tax, chargebacks and dispute resolution.Agreements and legal decisions
Retain immutable acceptance, evidence and decision records; restrict access to authorised roles.
Proof of contract, consent, regulatory decisions, claims and mandatory legal obligations.Access-control and security evidence
Retain append-only decisions and security events with the minimum subject reference.
Venue safety, credential integrity, incident investigation, abuse prevention and disputes.Member-chat processor, safety and delivery records
While needed to operate a consented chat, FLEXa holds invitation, participant, encrypted-message, delivery and member-safety state and BUA holds the scoped processor copy. On fulfilled account deletion, BUA removes the participant binding, replaces the member's sender reference with a keyed conversation-scoped pseudonym and overwrites that member's ciphertext with an erasure marker before FLEXa removes its local participant and authored-message rows. An append-only safety report, block or leave record may remain only for abuse prevention, an open support case, a legal claim or required audit integrity, with access restricted and the minimum pseudonymous subject and encrypted evidence references. Minimum non-identifying conversation, case, message, safety-action and erasure references may remain under that controlled rule and must be disposed of or irreversibly de-identified when the need ends.
Operate consensual member messaging, protect members, investigate abuse, prove delivery and deletion outcomes, and preserve only the minimum case and audit integrity required for security or disputes.Platform and deletion audit
Retain attributable, append-only audit events and the deletion outcome; never rewrite historical events.
Accountability, security monitoring, legal compliance and proof that the deletion request was fulfilled.Native push registrations and delivery tracking
Revoked or inactive registrations and completed or stale delivery tracking are subject to the implemented 30-day operational cleanup boundary, even when sending is disabled. Successful account-deletion fulfilment removes the member's registrations and associated delivery tracking. Inbox and audit records retain their separately disclosed boundaries, and provider-accepted alerts cannot be remotely recalled.
The operational cleanup period is a technical rule, not an assertion of legal approval. Qualified reviewers must confirm its justification, provider disposal terms and any applicable transfer requirements.Health and member-entered contact records
Stored HEALBE samples, emergency contacts, health-notification preferences and health-delivery tracking are removed during successful account-deletion fulfilment; they are not kept merely because the pseudonymous core user row remains. Health content in inbox, protected notification-outbox and audit records remains within the existing retained-record boundary. Already delivered messages and offline copies are outside a remote recall promise. Any genuinely required retained evidence remains subject to the disclosed restricted-access and lawful-retention boundary.
No health-specific retention duration or approval is asserted by this draft. Category-specific justification, disposal rules and any necessary retained evidence require qualified review.Governance registers and linked evidence
The effective policy is supported by controlled corporate, provider, transfer, retention and market records. Those records are maintained by accountable owners and are not silently inferred from application code. ¶
Responsible party and Information Officer records
The controller name and privacy mailbox are published in this policy. Registered-office, registration and Information Officer designations are maintained in the corporate and regulator records and can be requested through the privacy mailbox.
Roles, contracts and international transfers
The current provider categories, information and purposes are disclosed. Processor or independent-controller roles, contract status, processing countries and transfer safeguards are controlled in the provider register before an integration is enabled.
Record-by-record schedule and disposal
The retained categories are disclosed here. Their trigger, period, lawful basis, access restriction, disposal method and backup treatment are managed in the controlled retention register.
Local cache handling and market annexes
Current browser and app storage behavior is disclosed. An approved market annex identifies any additional local responsible party, right, provider or retention duty for that market.
Privacy, complaint and provider links
These links make the current controls, public authorities and external-provider notices directly reachable. A provider's public policy does not replace FLEXa's required contract, role assessment or transfer approval. ¶
Current privacy notice
The canonical human-readable notice you are viewing.
Machine-readable privacy notice
The versioned JSON contract used by FLEXa web and native clients.
Account deletion
Start or confirm an account-deletion request and review retained-record boundaries.
FLEXa terms and conditions
The effective service terms read together with this privacy notice and any approved market annex.
Payments and PayFast
The exact payment-authority, settlement-validation and credential-storage paragraphs.
Refunds and disputes
The cancellation, original-payment-rail, refund and transaction-dispute paragraphs.
Disclaimers and liability
The service-availability disclaimer, responsibility allocation and mandatory-rights boundary.
Privacy questions and rights requests
Contact FLEXa without sending passwords, OTPs, payment credentials or identity-document images.
POPIA resources
Official Information Regulator guidance and resources for the Protection of Personal Information Act.
Protection of Personal Information Act 4 of 2013
The official South African Government Act page and source document.
Consumer Protection Act 68 of 2008
The official South African Government Act page for consumer transactions and rights.
Electronic Communications and Transactions Act 25 of 2002
The official Act covering electronic transactions, records and consumer protections.
Information Regulator eServices
Official portal for regulated eServices, including Information Officer administration.
Information Regulator contact channels
Official contact details for POPIA and PAIA enquiries.
Information Regulator complaints
Official complaint guidance and forms.
Microsoft privacy statement
Privacy information for Microsoft cloud and communications services used by FLEXa.
Apple privacy policy
Privacy information relevant to Apple platform services, including app-distribution and attestation services.
Google privacy policy
Privacy information relevant to Google Maps and Play Integrity services.
BulkSMS data processing and privacy policy
Privacy information for the configured SMS-delivery provider.
PayFast privacy policy
Privacy information for PayFast when it processes member payment and transaction data.
VerifyNow privacy policy
Privacy information for optional identity-document verification when enabled.
IPWhoIs privacy policy
Privacy information for approximate IP-based location lookup.
CountriesNow service information
Public service documentation for country, locality, currency and telephone-code reference data.
Morph privacy policy
Privacy information for the configured FLEXa Assist model endpoint; no question is sent while the assistant is unconfigured or disabled.
Contact FLEXa about privacy
FLEXa may need to verify identity before providing account information or acting on a rights request. Do not email passwords, payment details, one-time codes or identity-document images. ¶
hello@sovereignseries.africaSouth African data subjects may also contact the independent Information Regulator or lodge a POPIA complaint. ¶
Information Regulator contact and complaint channels