Privacy Policy
Last updated: March 2, 2026
1. Introduction
MeritFlow (“we,” “our,” or “us”) is committed to protecting the privacy of students, teachers, administrators, and all users of our student merit point management system. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, in compliance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and other applicable data protection laws.
2. Information We Collect
2.1 Personal Information
We may collect personal information that you provide directly to us, including:
- Name and contact information (email address, phone number)
- School affiliation and role (student, teacher, administrator)
- Student academic information (grade, class, teaching group)
- Merit and demerit point records and behavioral data
- Account credentials
2.2 Automatically Collected Information
When you access our service, we may automatically collect certain information, including your IP address, browser type, device type, operating system, access times, and pages viewed.
2.3 Cookies and Tracking
We use essential cookies to keep you logged in and maintain your session. We may also use analytics tools (such as Google Analytics) to understand how users interact with our service. You can control cookie preferences through your browser settings.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our merit point management service
- Process merit and demerit point transactions and maintain accurate records
- Send notifications about merit activities and achievements
- Generate analytics and reports for school administrators
- Respond to your comments, questions, and requests
- Ensure the security and integrity of our service
- Comply with legal obligations
4. Legal Basis for Processing (POPIA)
Under the Protection of Personal Information Act (POPIA), we process your personal information based on the following lawful grounds:
- Consent: Where you or your school has given explicit consent for data processing
- Contractual obligation: Processing necessary to fulfill our service agreement with your school
- Legal obligation: Processing required to comply with applicable laws
- Legitimate interest: Processing necessary for the proper functioning and improvement of the service
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information in the following circumstances:
- With school administrators who have authorized access
- With teachers who need access to manage their assigned students and classes
- With service providers who assist in operating our platform (e.g., cloud hosting, analytics)
- When required by law, regulation, or court order
- To protect the rights, property, or safety of MeritFlow, our users, or the public
6. Data Storage and International Transfers
Your data is stored securely on cloud infrastructure provided by Amazon Web Services (AWS). Data may be processed in regions outside of South Africa. Where data is transferred internationally, we ensure appropriate safeguards are in place as required by POPIA, including ensuring the recipient country has adequate data protection laws or that appropriate contractual protections are in place.
7. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption of data in transit and at rest, secure authentication mechanisms, role-based access controls, and regular security assessments.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law. When a school's subscription ends, we will retain data for a maximum of 90 days to allow for reactivation, after which it will be securely deleted. Schools may request earlier deletion of their data at any time.
9. Children's Privacy
Our service is designed for use in educational settings and processes information of learners who may be under the age of 18. In accordance with POPIA and the Children's Act of South Africa, we collect only the minimum information necessary to provide the service. Schools are responsible for obtaining appropriate parental or guardian consent before registering learners on the platform. Parents or guardians may contact us at any time to review, correct, or request deletion of their child's information.
10. Your Rights Under POPIA
As a data subject, you have the right to:
- Request access to your personal information we hold
- Request correction of inaccurate or incomplete information
- Request deletion or destruction of your personal information
- Object to the processing of your personal information
- Withdraw your consent at any time (where processing is based on consent)
- Lodge a complaint with the Information Regulator of South Africa
To exercise any of these rights, please contact our Information Officer using the details below. We will respond to your request within 30 days.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify affected parties of any material changes by posting the updated policy on this page, updating the “Last updated” date, and where appropriate, notifying schools directly via email.
12. Information Officer & Contact
If you have any questions about this Privacy Policy, wish to exercise your rights, or need to report a data breach, please contact our Information Officer:
Information Officer: MeritFlow Team
Email: support@meritflow.co.za
Website: www.meritflow.co.za
You may also lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.