← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — South Africa Country Annex

Effective date: 19 July 2026 Last updated: 19 July 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every South-African resident covered by this Annex; the Information Officer for the purposes of the Protection of Personal Information Act 4 of 2013 ("POPIA") Section 55 read with the Promotion of Access to Information Act 2 of 2000 ("PAIA"), with business contact (Information-Officer registration with the Information Regulator is an operational matter tracked in the internal registration checklist per the locked user decision); the designated contact point for the Information Regulator (South Africa), the National Consumer Commission ("NCC"), the Film and Publication Board ("FPB"), and the South African Police Service ("SAPS"), under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to POPIA (in force 1 July 2020; compliance deadline 1 July 2021) or its Regulations (2018); (b) any Information-Regulator Guidance Note, Code of Conduct, or enforcement action materially bearing on Sections 34-35 (children's personal information — processing prohibited unless a competent person consents or another Section 35 ground applies), Section 57 (prior authorisation — including Section 57(1)(d): processing involving the transfer of special personal information or the personal information of children to a third country that does not provide an adequate level of protection), or Section 72 (cross-border transfers); (c) any amendment to the Children's Act 38 of 2005 (age of majority — 18; competent person concept) or to the Films and Publications Act 65 of 1996 as amended by the 2019 Amendment Act (online-content regulation; CSAM offences); (d) any amendment to the Criminal Law (Sexual Offences and Related Matters) Amendment Act 32 of 2007 — in particular the Section 54 duty to report sexual offences against children; (e) any amendment to the Consumer Protection Act 68 of 2008 ("CPA-SA") or the Electronic Communications and Transactions Act 25 of 2002 ("ECTA"); (f) any amendment to the Cybercrimes Act 19 of 2020; (g) any decision of the Constitutional Court or the High Courts materially bearing on POPIA or the Constitution Section 14 privacy right; (h) any change in South Africa's adequacy postures (no EU adequacy at the Effective date); (i) any change to a sub-processor's South-Africa data-handling posture under our sub-processor register; (j) the bringing into force of any post-Effective-date South-African regulation governing automated processing or related techniques beyond POPIA Section 71 (covered by the deliberate-silence carve-out in § 2); (k) any Information-Regulator determination on the Section 57 prior-authorisation question for children's-data transfers that affects the § 8 analysis. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical South-African-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a South-African resident a right that the global Policy does not, this Annex governs; the converse also holds. The two are read together.

This Annex is drafted in English — one of South Africa's twelve official languages and the ordinary language of South-African commercial and legal drafting. No translation is statutorily required for POPIA notification purposes.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is South Africa. POPIA is a national statute; there is no provincial data-protection sub-layer.

We determine country of residence at install/sign-up time by (a) the country the parent self-declares in onboarding, (b) the IP-geolocation read at sign-up (discarded immediately after the residence decision — our internal data-flow map § 2.1), and (c) the Play Store account locale. Reviewable at Settings → Account → Region. Where any signal identifies South Africa, this Annex applies; the most-protective reading controls.

POPIA applies (Section 3(1)(b)) where the responsible party is not domiciled in South Africa but makes use of automated or non-automated means in the Republic (unless only for forwarding). Balance's processing engages South-African terminals (the parent's and kid's devices in the Republic) as part of the processing operation; Balance applies POPIA in full on the most-protective reading as the responsible party, with the parent and kid as data subjects.


2. Statutory framework — what applies

Instrument What it does Balance's posture
Constitution — Section 14 (privacy) + Section 28 (children — best interests paramount, Section 28(2)) The constitutional layer. Constitutional anchor. §§ 3, 5, 6 below.
POPIA — Act 4 of 2013 The principal statute. The eight conditions for lawful processing: (1) Accountability (s 8); (2) Processing limitation (ss 9-12 — lawfulness, minimality, consent/justification grounds in s 11); (3) Purpose specification (ss 13-14); (4) Further-processing limitation (s 15); (5) Information quality (s 16); (6) Openness (ss 17-18 — notification to the data subject); (7) Security safeguards (ss 19-22 — including s 22 breach notification); (8) Data-subject participation (ss 23-25 — access, correction, deletion). Sections 34-35 — processing of personal information of children prohibited unless a competent person consents (s 35(1)(a)) or another s 35 ground applies; Section 57(1)(d)prior authorisation for processing involving the transfer of special personal information or children's personal information to a third country without adequate protection (§ 8 below); Sections 60-68 codes of conduct; Section 69 direct-marketing opt-in; Section 71 automated decision-making; Section 72 cross-border transfers; Sections 73-99 complaints, enforcement, civil remedies (s 99); Sections 100-106 offences + administrative fines (up to R10 million). The principal statute. Applies. Treatment throughout.
Children's Act 38 of 2005 Age of majority 18 (s 17); the competent person holding parental responsibilities and rights; best-interests standard (s 7). Applies. §§ 5, 16 below.
Films and Publications Act 65 of 1996 (as amended 2019) Online-content regulation by the FPB; CSAM offences (ss 24B et seq.); industry reporting duties for in-scope providers. Applies. § 14 below.
Criminal Law (Sexual Offences) Amendment Act 32 of 2007 Sexual offences against children; the s 54 duty: any person with knowledge of a sexual offence against a child must report it to the SAPS. Applies — binds Balance personnel. § 14 below.
Cybercrimes Act 19 of 2020 Cybercrime offences + procedural powers (production orders, preservation). Applies. § 13 below.
CPA-SA 68 of 2008 + ECTA 25 of 2002 Consumer rights (fairness, disclosure, cancellation of fixed-term agreements s 14, unfair terms ss 48-51); ECTA Chapter 7 e-commerce consumer protections (s 43 disclosure; s 44 cooling-off — with the s 42(2) digital-content-scope limits). Applies. § 16 below.
PAIA 2 of 2000 Access-to-records regime; the PAIA manual and Information-Officer machinery shared with POPIA. Applies. § 6 below.
EU adequacy / Convention 108 / Budapest No EU adequacy. South Africa signed but has not ratified the Budapest Convention; not a party to Convention 108. MLAT and International Co-operation in Criminal Matters Act 75 of 1996 channels apply. Context-setting facts. § 13 below.

(Any prospective South-African regulation governing automated processing, algorithmic decisions, or related techniques beyond POPIA Section 71 — including any AI policy framework and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence is deliberate.)


3. Supervisory authorities

3.1 Information Regulator (South Africa)

Field Value
Name Information Regulator (South Africa)
Address JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001, South Africa
Website / complaint channel https://inforegulator.org.za/ — complaints to POPIAComplaints@inforegulator.org.za; enquiries enquiries@inforegulator.org.za
Breach-notification channel Section 22 security-compromise notification via the Regulator's eServices portal / prescribed form

A South-African resident may complain to the Regulator at any time (Section 74); prior contact with us is not a precondition, though we invite it at (named individual: , Information Officer). Civil remedies include Section 99 damages actions (strict-liability flavoured) in the High Court.

3.2 Other regulatory bodies

Body Subject matter Channel
National Consumer Commission (NCC) CPA-SA https://thencc.org.za/
Consumer Goods and Services Ombud CPA-SA ADR https://www.cgso.org.za/
Film and Publication Board (FPB) Online content; CSAM hotline https://www.fpb.org.za/ — FPB Hotline https://www.fpbhotline.org.za/
SAPS — Family Violence, Child Protection and Sexual Offences (FCS) Units Child-protection investigation; s 54 reports Emergency 10111; Crime Stop 08600 10111
Childline South Africa 24/7 children's helpline dial 116 (toll-free) — https://www.childlinesa.org.za/

3.3 The Information Officer

POPIA Section 55 + PAIA designate the head of the private body as Information Officer by default, with registration before the Regulator as the operational step. The Balance Information-Officer function is discharged by , Director, BabaYaga Program, TOO — , published here, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. The registration formality and any Section 57 filing decision are tracked in the internal registration checklist per the locked user decision — no local representative is engaged.


4. Lawful bases — POPIA Section 11 + Section 35


5. Children's rights overlay — POPIA ss 34-35

  1. The competent person always consents; the kid never self-registers. POPIA s 34 prohibits processing children's personal information unless a s 35 ground applies; Balance's ground is s 35(1)(a) — prior consent of a competent person: the parent (Children's Act parental responsibilities and rights) is the account holder, and the kid profile exists only inside the authenticated parent account. The pairing act is the parent's.
  2. Best interests paramount (Constitution s 28(2); Children's Act s 7): the DPIA records the analysis; the product exposes no content feed, no social surface, no contact-by-strangers surface, no advertising.
  3. The competent person exercises the kid's rights (§ 6) in-app or by email.
  4. Openness toward the child: kid-facing screens use age-appropriate plain language; the Children's Privacy Notice (H2) carries the child-readable summary.
  5. No commercial exploitation of children's data — ever (also the s 69 direct-marketing posture: none sent, and never to children).

Honoured at and in-app (the competent person exercises the kid's rights):

Timeline: we acknowledge within one business day and respond within a reasonable time as POPIA requires — and in any event within 30 days, Balance's self-imposed ceiling (mirroring the PAIA horizon). Requests may be in English or any official language (we translate on receipt), free of charge.



8. International data transfers from South Africa — POPIA s 72 (and the s 57 note)

Balance transfers South-African residents' personal information to the United States (hosting) with controller access from Kazakhstan, relying on s 72(1)(b) — the data subject's (competent person's) consent to the transfer, obtained at sign-up (the transfer-disclosure consent names the destinations), reinforced by contractual safeguards: every recipient is bound by a written agreement imposing security and confidentiality controls that give effect to POPIA-equivalent protection (our international-transfer pack § 6), with the E2EE proof-media measure on top. The s 72(1)(c)-(d) contract-necessity limbs supplement the consent basis for contract-necessary flows.

On s 57(1)(d) (prior authorisation for transfers of children's personal information to non-adequate countries): Balance relies on the s 72(1)(b) consent + contractual safeguards posture described above; the Information-Regulator filing decision on s 57 is assessed and tracked in the internal registration checklist, and § 18 re-opens this section on any Regulator determination or guidance affecting that analysis.


9. Data residency for South-African residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region (E2EE ciphertext only).
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any South-African resident's data held in South Africa? No. The s 72 mechanism in § 8 grounds the transfer.
Where is the controller (responsible party)? Kazakhstan (BabaYaga Program, TOO), with administrative access under written operator agreements (POPIA ss 20-21).
Is there a South-African establishment? No.

South Africa imposes no general data-localisation mandate on parental-control services.


10. Sub-processors (operators) touching South-African-resident data

Sub-processor Role Location South Africa transfer basis
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (US); relationship per our internal vendor-handling plan Hosts the FastAPI backend + MongoDB cluster United States POPIA s 72(1)(b) consent + written operator agreement (ss 20-21) with POPIA-equivalent safeguards; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) E2EE proof-media ciphertext + daily 30-day-rolling backups United States (us multi-region) s 72(1)(b) consent + Google Cloud DPA; ciphertext-only.
Google LLC — Firebase Cloud Messaging Push notifications United States s 72(1)(b) consent; push body free of sensitive content (M3).
Google LLC — Google Sign-In Parent Google authentication (when used) United States s 72(1)(b) consent + Google DPA.
Google LLC — Google Play Billing Subscription purchases United States / South Africa (Google Play) Google Play Developer Distribution Agreement + s 72(1)(b) consent.
Resend, Inc. (San Francisco, CA, USA) Transactional email United States s 72(1)(b) consent + DPA on file.

Full list: our sub-processor register.


11. Breach notification — POPIA s 22

Audience Trigger Deadline Channel
Information Regulator Reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person (a "security compromise"). As soon as reasonably possible after discovery (s 22(1)-(2)) — Balance's internal benchmark: within 72 hours. The Regulator's prescribed security-compromise form / eServices portal, filed by the Information Officer or South-African counsel on instruction.
Affected data subjects The same compromise. As soon as reasonably possible, unless identity cannot be established — in writing, with sufficient information to take protective measures (s 22(4)-(5)). Direct email to the affected parent; in-app banner; public incident page fallback.
CSAE-specific An incident with a CSAE component. Per § 14 + runbook M1. SAPS (s 54 duty) + FPB Hotline + (where applicable) NCMEC.

Internal SLA: our breach-notification runbook § 5.4 + § 9.


12. Cookies, spam, and electronic direct marketing

South Africa has no standalone cookies statute; identifiers are personal information under POPIA. The Balance app deploys strictly-necessary storage only (authentication tokens; device-pairing key wrap; earned-time cache), covered by the sign-up consent. The public site uses no analytics, advertising cookies, trackers, or fingerprinting. POPIA s 69 makes unsolicited electronic direct marketing opt-in (and ECTA s 45 adds unsubscribe duties) — Balance sends no electronic direct marketing to South-African residents; only transactional email. Advertising directed at children: never.


13. Lawful-access requests and the encryption posture

South-African authorities may seek data via Criminal Procedure Act 51 of 1977 s 205 subpoenas, Cybercrimes Act 19 of 2020 production/preservation orders, RICA-regulated interception directions (addressed to in-scope providers), and international channels (International Co-operation in Criminal Matters Act 75 of 1996; MLATs). Posture:

Full encryption posture: our encryption-posture record.


14. CSAE reporting routes — South Africa

Full routing table: Child Safety Standards § 8.5.


15. Complaint routes (summary)

Authority Subject matter Channel
Information Regulator POPIA + PAIA POPIAComplaints@inforegulator.org.za; https://inforegulator.org.za/
NCC / Consumer Goods and Services Ombud CPA-SA https://thencc.org.za/; https://www.cgso.org.za/
FPB Online-content complaints https://www.fpb.org.za/
SAPS Criminal (incl. s 54 reports) 10111
Courts POPIA s 99 damages; constitutional relief Per jurisdiction

A South-African resident may always first raise the matter at ; prior contact is not a precondition to any authority route.


16. Consumer rights — the CPA-SA + ECTA overlay


17. Cross-references


18. Versioning and review


End of South Africa Country Annex.

← Back to Privacy Policy · Children's Privacy Notice