Privacy Policy

Last updated: 9 June 2026

This is a starting template, not legal advice. Have a South African data-protection attorney review it (and the Operator Agreement) before relying on it commercially.

1. Who we are

Droop is a web-push notification service operated by PHPin24 (Pty) Ltd ("we", "us") at droop.co.za. Questions and data-subject requests: admin@droop.co.za (Information Officer).

2. Our role under POPIA

When we process the push subscriptions and messages of our account holders' end-users, we act as an Operator (processor) on behalf of the account holder, who is the Responsible Party (controller). For our own account holders' account data, we are the Responsible Party. Each account holder is bound by a written Operator Agreement (POPIA s21).

3. What we process

4. Lawful basis / consent

A push subscription is created only with the end-user's explicit browser permission ("Allow"), which is the consent gate. Account holders must additionally obtain consent that meets POPIA s69 (and, where relevant, GDPR/ePrivacy) before sending direct-marketing notifications, identify themselves in every message, and offer a free opt-out.

5. Security (POPIA s19)

Data is transmitted over TLS/HTTPS and access is restricted. The subscription endpoint is a secret capability and is protected accordingly.

6. Retention & deletion

Subscriptions are retained until the end-user unsubscribes or the push service reports the subscription as gone (HTTP 404/410), at which point we delete it. This deletion suppresses future messages โ€” re-contact requires a fresh opt-in.

7. Your rights

Under POPIA you may request access to, correction or deletion of your personal information, and may object to processing. Contact the Information Officer above.

8. Breach notification (POPIA s22)

If personal information is compromised, we will notify the affected parties and the Information Regulator as soon as reasonably possible.