Balance — South Africa Country Annex
Effective date: 19 July 2026 Last updated: 19 July 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every South-African resident covered by this Annex; the Information Officer for the purposes of the Protection of Personal Information Act 4 of 2013 ("POPIA") Section 55 read with the Promotion of Access to Information Act 2 of 2000 ("PAIA"), with business contact (Information-Officer registration with the Information Regulator is an operational matter tracked in the internal registration checklist per the locked user decision); the designated contact point for the Information Regulator (South Africa), the National Consumer Commission ("NCC"), the Film and Publication Board ("FPB"), and the South African Police Service ("SAPS"), under their respective intake protocols.
Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to POPIA (in force 1 July 2020; compliance deadline 1 July 2021) or its Regulations (2018); (b) any Information-Regulator Guidance Note, Code of Conduct, or enforcement action materially bearing on Sections 34-35 (children's personal information — processing prohibited unless a competent person consents or another Section 35 ground applies), Section 57 (prior authorisation — including Section 57(1)(d): processing involving the transfer of special personal information or the personal information of children to a third country that does not provide an adequate level of protection), or Section 72 (cross-border transfers); (c) any amendment to the Children's Act 38 of 2005 (age of majority — 18; competent person concept) or to the Films and Publications Act 65 of 1996 as amended by the 2019 Amendment Act (online-content regulation; CSAM offences); (d) any amendment to the Criminal Law (Sexual Offences and Related Matters) Amendment Act 32 of 2007 — in particular the Section 54 duty to report sexual offences against children; (e) any amendment to the Consumer Protection Act 68 of 2008 ("CPA-SA") or the Electronic Communications and Transactions Act 25 of 2002 ("ECTA"); (f) any amendment to the Cybercrimes Act 19 of 2020; (g) any decision of the Constitutional Court or the High Courts materially bearing on POPIA or the Constitution Section 14 privacy right; (h) any change in South Africa's adequacy postures (no EU adequacy at the Effective date); (i) any change to a sub-processor's South-Africa data-handling posture under our sub-processor register; (j) the bringing into force of any post-Effective-date South-African regulation governing automated processing or related techniques beyond POPIA Section 71 (covered by the deliberate-silence carve-out in § 2); (k) any Information-Regulator determination on the Section 57 prior-authorisation question for children's-data transfers that affects the § 8 analysis.
Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — South Africa row).
- Children's Privacy Notice § 14 (Country annexes — South Africa row).
- Child Safety Standards § 13 (Country annexes — South Africa row).
- Terms of Service § 17 (South Africa consumer-protection carve-out under the CPA 68 of 2008 + ECTA).
- Subscription Terms § 18 (South Africa consumer-rights overlay — CPA-SA + ECTA; Google Play refund policy as the operational floor).
- Data Retention & Deletion Policy § 13 (South Africa — Information Regulator complaint route).
- our breach-notification runbook § 9 (South Africa breach-notification route under POPIA Section 22 — as soon as reasonably possible).
- our international-transfer pack § 6 (POPIA Section 72(1)(b) consent + contractual-safeguards transfer mechanism).
This Annex is the canonical South-African-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a South-African resident a right that the global Policy does not, this Annex governs; the converse also holds. The two are read together.
This Annex is drafted in English — one of South Africa's twelve official languages and the ordinary language of South-African commercial and legal drafting. No translation is statutorily required for POPIA notification purposes.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose country of residence is South Africa. POPIA is a national statute; there is no provincial data-protection sub-layer.
We determine country of residence at install/sign-up time by (a) the country the parent self-declares in onboarding, (b) the IP-geolocation read at sign-up (discarded immediately after the residence decision — our internal data-flow map § 2.1), and (c) the Play Store account locale. Reviewable at Settings → Account → Region. Where any signal identifies South Africa, this Annex applies; the most-protective reading controls.
POPIA applies (Section 3(1)(b)) where the responsible party is not domiciled in South Africa but makes use of automated or non-automated means in the Republic (unless only for forwarding). Balance's processing engages South-African terminals (the parent's and kid's devices in the Republic) as part of the processing operation; Balance applies POPIA in full on the most-protective reading as the responsible party, with the parent and kid as data subjects.
2. Statutory framework — what applies
| Instrument | What it does | Balance's posture |
|---|---|---|
| Constitution — Section 14 (privacy) + Section 28 (children — best interests paramount, Section 28(2)) | The constitutional layer. | Constitutional anchor. §§ 3, 5, 6 below. |
| POPIA — Act 4 of 2013 | The principal statute. The eight conditions for lawful processing: (1) Accountability (s 8); (2) Processing limitation (ss 9-12 — lawfulness, minimality, consent/justification grounds in s 11); (3) Purpose specification (ss 13-14); (4) Further-processing limitation (s 15); (5) Information quality (s 16); (6) Openness (ss 17-18 — notification to the data subject); (7) Security safeguards (ss 19-22 — including s 22 breach notification); (8) Data-subject participation (ss 23-25 — access, correction, deletion). Sections 34-35 — processing of personal information of children prohibited unless a competent person consents (s 35(1)(a)) or another s 35 ground applies; Section 57(1)(d) — prior authorisation for processing involving the transfer of special personal information or children's personal information to a third country without adequate protection (§ 8 below); Sections 60-68 codes of conduct; Section 69 direct-marketing opt-in; Section 71 automated decision-making; Section 72 cross-border transfers; Sections 73-99 complaints, enforcement, civil remedies (s 99); Sections 100-106 offences + administrative fines (up to R10 million). | The principal statute. Applies. Treatment throughout. |
| Children's Act 38 of 2005 | Age of majority 18 (s 17); the competent person holding parental responsibilities and rights; best-interests standard (s 7). | Applies. §§ 5, 16 below. |
| Films and Publications Act 65 of 1996 (as amended 2019) | Online-content regulation by the FPB; CSAM offences (ss 24B et seq.); industry reporting duties for in-scope providers. | Applies. § 14 below. |
| Criminal Law (Sexual Offences) Amendment Act 32 of 2007 | Sexual offences against children; the s 54 duty: any person with knowledge of a sexual offence against a child must report it to the SAPS. | Applies — binds Balance personnel. § 14 below. |
| Cybercrimes Act 19 of 2020 | Cybercrime offences + procedural powers (production orders, preservation). | Applies. § 13 below. |
| CPA-SA 68 of 2008 + ECTA 25 of 2002 | Consumer rights (fairness, disclosure, cancellation of fixed-term agreements s 14, unfair terms ss 48-51); ECTA Chapter 7 e-commerce consumer protections (s 43 disclosure; s 44 cooling-off — with the s 42(2) digital-content-scope limits). | Applies. § 16 below. |
| PAIA 2 of 2000 | Access-to-records regime; the PAIA manual and Information-Officer machinery shared with POPIA. | Applies. § 6 below. |
| EU adequacy / Convention 108 / Budapest | No EU adequacy. South Africa signed but has not ratified the Budapest Convention; not a party to Convention 108. MLAT and International Co-operation in Criminal Matters Act 75 of 1996 channels apply. | Context-setting facts. § 13 below. |
(Any prospective South-African regulation governing automated processing, algorithmic decisions, or related techniques beyond POPIA Section 71 — including any AI policy framework and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence is deliberate.)
3. Supervisory authorities
3.1 Information Regulator (South Africa)
| Field | Value |
|---|---|
| Name | Information Regulator (South Africa) |
| Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001, South Africa |
| Website / complaint channel | https://inforegulator.org.za/ — complaints to POPIAComplaints@inforegulator.org.za; enquiries enquiries@inforegulator.org.za |
| Breach-notification channel | Section 22 security-compromise notification via the Regulator's eServices portal / prescribed form |
A South-African resident may complain to the Regulator at any time (Section 74); prior contact with us is not a precondition, though we invite it at (named individual: , Information Officer). Civil remedies include Section 99 damages actions (strict-liability flavoured) in the High Court.
3.2 Other regulatory bodies
| Body | Subject matter | Channel |
|---|---|---|
| National Consumer Commission (NCC) | CPA-SA | https://thencc.org.za/ |
| Consumer Goods and Services Ombud | CPA-SA ADR | https://www.cgso.org.za/ |
| Film and Publication Board (FPB) | Online content; CSAM hotline | https://www.fpb.org.za/ — FPB Hotline https://www.fpbhotline.org.za/ |
| SAPS — Family Violence, Child Protection and Sexual Offences (FCS) Units | Child-protection investigation; s 54 reports | Emergency 10111; Crime Stop 08600 10111 |
| Childline South Africa | 24/7 children's helpline | dial 116 (toll-free) — https://www.childlinesa.org.za/ |
3.3 The Information Officer
POPIA Section 55 + PAIA designate the head of the private body as Information Officer by default, with registration before the Regulator as the operational step. The Balance Information-Officer function is discharged by , Director, BabaYaga Program, TOO — , published here, in the global Privacy Policy § 1, and at balance.babayagaprogram.com. The registration formality and any Section 57 filing decision are tracked in the internal registration checklist per the locked user decision — no local representative is engaged.
4. Lawful bases — POPIA Section 11 + Section 35
- Parent account data: s 11(1)(b) contract necessity + s 11(1)(a) consent obtained at sign-up.
- Kid profile + device data: the competent person's consent under s 35(1)(a) — the parent holding parental responsibilities and rights consents by design through the parent-first onboarding (§ 5).
- Security, fraud-prevention, legal compliance: s 11(1)(c) legal obligation + s 11(1)(f) legitimate interests with the balancing recorded in our Data Protection Impact Assessment, never overriding the child's best interests (Constitution s 28(2)).
- No special personal information (POPIA ss 26-33) of South-African residents is processed in its own right; children's information is handled under the ss 34-35 regime with the § 8 transfer treatment. No advertising, profiling, or sale — monitoring/limits/tasks are performed at the parent's direction, strictly for the safety, well-being and parental supervision of the child, never for any commercial purpose.
5. Children's rights overlay — POPIA ss 34-35
- The competent person always consents; the kid never self-registers. POPIA s 34 prohibits processing children's personal information unless a s 35 ground applies; Balance's ground is s 35(1)(a) — prior consent of a competent person: the parent (Children's Act parental responsibilities and rights) is the account holder, and the kid profile exists only inside the authenticated parent account. The pairing act is the parent's.
- Best interests paramount (Constitution s 28(2); Children's Act s 7): the DPIA records the analysis; the product exposes no content feed, no social surface, no contact-by-strangers surface, no advertising.
- The competent person exercises the kid's rights (§ 6) in-app or by email.
- Openness toward the child: kid-facing screens use age-appropriate plain language; the Children's Privacy Notice (H2) carries the child-readable summary.
- No commercial exploitation of children's data — ever (also the s 69 direct-marketing posture: none sent, and never to children).
6. POPIA rights catalogue — ss 23-25 + related
Honoured at and in-app (the competent person exercises the kid's rights):
- s 23 — access: confirmation free of charge + the record itself — in-app JSON export at Settings → Family → [kid name] → "Export this kid's data" (no fee charged); PAIA-manual route also available.
- s 24 — correction and deletion: Settings → Account → Edit; deletion at Settings → "Delete my account" / "Delete this kid"; Delete-account page; cascade per Data Retention & Deletion Policy § 7.
- s 11(3) — objection to legitimate-interest processing; s 11(2) consent withdrawal — honoured at any time.
- s 69 — direct-marketing opt-in: moot — Balance sends none.
- s 71 — automated decision-making: Balance takes no decision with legal/substantial effect based solely on automated processing; the earned-time ledger is deterministic and parent-reviewable.
- s 74 complaint to the Information Regulator; s 99 civil action for damages.
Timeline: we acknowledge within one business day and respond within a reasonable time as POPIA requires — and in any event within 30 days, Balance's self-imposed ceiling (mirroring the PAIA horizon). Requests may be in English or any official language (we translate on receipt), free of charge.
7. Children's data — consent mechanics and minimisation
- Parent creates the account with a verified email (+ Google Play payment instrument where subscribed), then affirmatively creates the kid profile and pairs the kid's device — the s 35(1)(a) competent-person consent, evidenced and logged, via a consent screen itemising categories, purposes (safety and parental supervision only), recipients, retention, and rights.
- Data minimisation (s 10): only what the supervision service needs; proof media is E2EE to the parent's devices — Balance holds ciphertext only (§ 13).
- Kid data is never used for advertising, never profiled, never sold.
8. International data transfers from South Africa — POPIA s 72 (and the s 57 note)
Balance transfers South-African residents' personal information to the United States (hosting) with controller access from Kazakhstan, relying on s 72(1)(b) — the data subject's (competent person's) consent to the transfer, obtained at sign-up (the transfer-disclosure consent names the destinations), reinforced by contractual safeguards: every recipient is bound by a written agreement imposing security and confidentiality controls that give effect to POPIA-equivalent protection (our international-transfer pack § 6), with the E2EE proof-media measure on top. The s 72(1)(c)-(d) contract-necessity limbs supplement the consent basis for contract-necessary flows.
On s 57(1)(d) (prior authorisation for transfers of children's personal information to non-adequate countries): Balance relies on the s 72(1)(b) consent + contractual safeguards posture described above; the Information-Regulator filing decision on s 57 is assessed and tracked in the internal registration checklist, and § 18 re-opens this section on any Regulator determination or guidance affecting that analysis.
9. Data residency for South-African residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region (E2EE ciphertext only). |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any South-African resident's data held in South Africa? | No. The s 72 mechanism in § 8 grounds the transfer. |
| Where is the controller (responsible party)? | Kazakhstan (BabaYaga Program, TOO), with administrative access under written operator agreements (POPIA ss 20-21). |
| Is there a South-African establishment? | No. |
South Africa imposes no general data-localisation mandate on parental-control services.
10. Sub-processors (operators) touching South-African-resident data
| Sub-processor | Role | Location | South Africa transfer basis |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (US); relationship per our internal vendor-handling plan | Hosts the FastAPI backend + MongoDB cluster | United States | POPIA s 72(1)(b) consent + written operator agreement (ss 20-21) with POPIA-equivalent safeguards; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | E2EE proof-media ciphertext + daily 30-day-rolling backups | United States (us multi-region) |
s 72(1)(b) consent + Google Cloud DPA; ciphertext-only. |
| Google LLC — Firebase Cloud Messaging | Push notifications | United States | s 72(1)(b) consent; push body free of sensitive content (M3). |
| Google LLC — Google Sign-In | Parent Google authentication (when used) | United States | s 72(1)(b) consent + Google DPA. |
| Google LLC — Google Play Billing | Subscription purchases | United States / South Africa (Google Play) | Google Play Developer Distribution Agreement + s 72(1)(b) consent. |
| Resend, Inc. (San Francisco, CA, USA) | Transactional email | United States | s 72(1)(b) consent + DPA on file. |
Full list: our sub-processor register.
11. Breach notification — POPIA s 22
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| Information Regulator | Reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person (a "security compromise"). | As soon as reasonably possible after discovery (s 22(1)-(2)) — Balance's internal benchmark: within 72 hours. | The Regulator's prescribed security-compromise form / eServices portal, filed by the Information Officer or South-African counsel on instruction. |
| Affected data subjects | The same compromise. | As soon as reasonably possible, unless identity cannot be established — in writing, with sufficient information to take protective measures (s 22(4)-(5)). | Direct email to the affected parent; in-app banner; public incident page fallback. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 + runbook M1. | SAPS (s 54 duty) + FPB Hotline + (where applicable) NCMEC. |
Internal SLA: our breach-notification runbook § 5.4 + § 9.
12. Cookies, spam, and electronic direct marketing
South Africa has no standalone cookies statute; identifiers are personal information under POPIA. The Balance app deploys strictly-necessary storage only (authentication tokens; device-pairing key wrap; earned-time cache), covered by the sign-up consent. The public site uses no analytics, advertising cookies, trackers, or fingerprinting. POPIA s 69 makes unsolicited electronic direct marketing opt-in (and ECTA s 45 adds unsubscribe duties) — Balance sends no electronic direct marketing to South-African residents; only transactional email. Advertising directed at children: never.
13. Lawful-access requests and the encryption posture
South-African authorities may seek data via Criminal Procedure Act 51 of 1977 s 205 subpoenas, Cybercrimes Act 19 of 2020 production/preservation orders, RICA-regulated interception directions (addressed to in-scope providers), and international channels (International Co-operation in Criminal Matters Act 75 of 1996; MLATs). Posture:
- Proof media is end-to-end encrypted (fresh per-file key, XChaCha20-Poly1305, wrapped to parent-device X25519 keys; ciphertext-only upload). No master key, no backdoor.
- Response protocol: (1) acknowledge within one business day; (2) engage South-African counsel to assess validity; (3) preserve relevant ciphertext; (4) inform the authority plaintext is unavailable from us; (5) cooperate in identifying the lawful route to the key-holding parent.
- No bulk plaintext interception assistance; no server-side content scanning. CSAE cooperation runs via § 14 regardless, including the s 54 reporting duty.
Full encryption posture: our encryption-posture record.
14. CSAE reporting routes — South Africa
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day. - SAPS — emergency 10111; FCS Units; the s 54 duty requires any person with knowledge of a sexual offence against a child to report to SAPS.
- FPB Hotline —
https://www.fpbhotline.org.za/(CSAM category; FPB is the online-content regulator). - Childline South Africa — dial 116 (toll-free, 24/7);
https://www.childlinesa.org.za/. - Department of Social Development designated child-protection organisations (Children's Act s 110 reporting route for abuse/neglect).
- NCMEC CyberTipline (
https://report.cybertip.org/) — provider-side discoveries route to NCMEC, which relays to South-African law enforcement.
Full routing table: Child Safety Standards § 8.5.
15. Complaint routes (summary)
| Authority | Subject matter | Channel |
|---|---|---|
| Information Regulator | POPIA + PAIA | POPIAComplaints@inforegulator.org.za; https://inforegulator.org.za/ |
| NCC / Consumer Goods and Services Ombud | CPA-SA | https://thencc.org.za/; https://www.cgso.org.za/ |
| FPB | Online-content complaints | https://www.fpb.org.za/ |
| SAPS | Criminal (incl. s 54 reports) | 10111 |
| Courts | POPIA s 99 damages; constitutional relief | Per jurisdiction |
A South-African resident may always first raise the matter at ; prior contact is not a precondition to any authority route.
16. Consumer rights — the CPA-SA + ECTA overlay
- Disclosure (ECTA s 43): full supplier, price, and terms disclosure before purchase — implemented in Subscription Terms § 5.
- Cooling-off (ECTA s 44): 7-day cooling-off for e-transactions within its scope; where the digital-subscription supply falls outside s 44 (s 42(2) carve-outs), Balance honours the Google Play refund policy as the operational floor plus its voluntary refund posture (Subscription Terms § 8), which meets or exceeds the statutory position either way.
- Fixed-term agreements (CPA-SA s 14) + cancellation: the subscription cancels in-app / via Google Play at any time; no punitive cancellation charge.
- Unfair terms (CPA-SA ss 48-51): prohibited terms are absent from the Terms of Service; s 49 notice requirements for any limitation are met with plain, conspicuous language.
- Contracting capacity: age of majority 18 (Children's Act s 17); the subscribing parent must be an adult; the kid never contracts with Balance.
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — POPIA s 72(1)(b) consent + safeguards on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
- Every change to a substantive row in §§ 2-16 bumps the frontmatter and triggers re-publication.
- Any Information-Regulator guidance or determination on s 57(1)(d) children's-data transfer prior authorisation triggers an immediate re-open of § 8 and of the internal-checklist filing decision.
- A material POPIA / Regulations amendment triggers an off-cycle rewrite of §§ 2, 6, 8, 11.
- A material Children's Act / FPA / Sexual Offences Act change triggers an off-cycle update to §§ 5, 13, 14.
- A material CPA-SA / ECTA change triggers an off-cycle update to § 16 + Subscription Terms.
- A material change to a sub-processor's posture triggers an off-cycle update to §§ 8, 10.
- The annual review is by 9 June. The Privacy Officer signs off; the Designated Child Safety Officer co-signs any change to §§ 5, 7, 11, 13, 14.
End of South Africa Country Annex.