Privacy Policy

Last updated: March 2, 2026

1. Introduction

MeritFlow (“we,” “our,” or “us”) is committed to protecting the privacy of students, teachers, administrators, and all users of our student merit point management system. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, in compliance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and other applicable data protection laws.

2. Information We Collect

2.1 Personal Information

We may collect personal information that you provide directly to us, including:

  • Name and contact information (email address, phone number)
  • School affiliation and role (student, teacher, administrator)
  • Student academic information (grade, class, teaching group)
  • Merit and demerit point records and behavioral data
  • Account credentials

2.2 Automatically Collected Information

When you access our service, we may automatically collect certain information, including your IP address, browser type, device type, operating system, access times, and pages viewed.

2.3 Cookies and Tracking

We use essential cookies to keep you logged in and maintain your session. We may also use analytics tools (such as Google Analytics) to understand how users interact with our service. You can control cookie preferences through your browser settings.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our merit point management service
  • Process merit and demerit point transactions and maintain accurate records
  • Send notifications about merit activities and achievements
  • Generate analytics and reports for school administrators
  • Respond to your comments, questions, and requests
  • Ensure the security and integrity of our service
  • Comply with legal obligations

4. Legal Basis for Processing (POPIA)

Under the Protection of Personal Information Act (POPIA), we process your personal information based on the following lawful grounds:

  • Consent: Where you or your school has given explicit consent for data processing
  • Contractual obligation: Processing necessary to fulfill our service agreement with your school
  • Legal obligation: Processing required to comply with applicable laws
  • Legitimate interest: Processing necessary for the proper functioning and improvement of the service

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information in the following circumstances:

  • With school administrators who have authorized access
  • With teachers who need access to manage their assigned students and classes
  • With service providers who assist in operating our platform (e.g., cloud hosting, analytics)
  • When required by law, regulation, or court order
  • To protect the rights, property, or safety of MeritFlow, our users, or the public

6. Data Storage and International Transfers

Your data is stored securely on cloud infrastructure provided by Amazon Web Services (AWS). Data may be processed in regions outside of South Africa. Where data is transferred internationally, we ensure appropriate safeguards are in place as required by POPIA, including ensuring the recipient country has adequate data protection laws or that appropriate contractual protections are in place.

7. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption of data in transit and at rest, secure authentication mechanisms, role-based access controls, and regular security assessments.

8. Data Retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law. When a school's subscription ends, we will retain data for a maximum of 90 days to allow for reactivation, after which it will be securely deleted. Schools may request earlier deletion of their data at any time.

9. Children's Privacy

Our service is designed for use in educational settings and processes information of learners who may be under the age of 18. In accordance with POPIA and the Children's Act of South Africa, we collect only the minimum information necessary to provide the service. Schools are responsible for obtaining appropriate parental or guardian consent before registering learners on the platform. Parents or guardians may contact us at any time to review, correct, or request deletion of their child's information.

10. Your Rights Under POPIA

As a data subject, you have the right to:

  • Request access to your personal information we hold
  • Request correction of inaccurate or incomplete information
  • Request deletion or destruction of your personal information
  • Object to the processing of your personal information
  • Withdraw your consent at any time (where processing is based on consent)
  • Lodge a complaint with the Information Regulator of South Africa

To exercise any of these rights, please contact our Information Officer using the details below. We will respond to your request within 30 days.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify affected parties of any material changes by posting the updated policy on this page, updating the “Last updated” date, and where appropriate, notifying schools directly via email.

12. Information Officer & Contact

If you have any questions about this Privacy Policy, wish to exercise your rights, or need to report a data breach, please contact our Information Officer:

Information Officer: MeritFlow Team

Email: support@meritflow.co.za

Website: www.meritflow.co.za

You may also lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.