Last updated: 9 June 2026
This is a starting template, not legal advice. Have a South African data-protection attorney review it (and the Operator Agreement) before relying on it commercially.
Droop is a web-push notification service operated by PHPin24 (Pty) Ltd ("we", "us") at droop.co.za. Questions and data-subject requests: admin@droop.co.za (Information Officer).
When we process the push subscriptions and messages of our account holders' end-users, we act as an Operator (processor) on behalf of the account holder, who is the Responsible Party (controller). For our own account holders' account data, we are the Responsible Party. Each account holder is bound by a written Operator Agreement (POPIA s21).
p256dh, auth), and user-agent string โ collected only after the end-user grants the browser notification permission.A push subscription is created only with the end-user's explicit browser permission ("Allow"), which is the consent gate. Account holders must additionally obtain consent that meets POPIA s69 (and, where relevant, GDPR/ePrivacy) before sending direct-marketing notifications, identify themselves in every message, and offer a free opt-out.
Data is transmitted over TLS/HTTPS and access is restricted. The subscription endpoint is a secret capability and is protected accordingly.
Subscriptions are retained until the end-user unsubscribes or the push service reports the subscription as gone (HTTP 404/410), at which point we delete it. This deletion suppresses future messages โ re-contact requires a fresh opt-in.
Under POPIA you may request access to, correction or deletion of your personal information, and may object to processing. Contact the Information Officer above.
If personal information is compromised, we will notify the affected parties and the Information Regulator as soon as reasonably possible.