ByteBuddies Academy
Privacy Statement
Last updated: July 2026
1. Introduction
This Privacy Statement explains how ByteBuddies Academy collects, receives, records, stores, uses, shares, protects and otherwise processes personal information in connection with the ByteBuddies Academy platform, curriculum hub, lesson tools, teacher planner, certificate studio, reports, Ask Byte features, administrative tools, websites and related services.
References to "ByteBuddies", "we", "us" or "our" include ByteBuddies Academy and Networks (Pty) Ltd where applicable. References to "you" or "your" include teachers, school administrators, parents, facilitators, learners where applicable, authorised account users, schools, organisations and visitors.
We intend to process personal information in a manner aligned with the Protection of Personal Information Act, 2013 ("POPIA") and other applicable data protection principles. This Privacy Statement must be read together with the applicable Terms and Conditions, school agreements, subscription arrangements, consent notices and any additional privacy notices that apply to a specific feature.
2. Responsible Party
Where ByteBuddies determines the purpose and means of processing personal information, it acts as the responsible party for purposes of POPIA. Where a school or organisation determines the purpose for which its users and learner information are entered into the platform, that school or organisation may act as the responsible party and ByteBuddies may process information as an operator or service provider, depending on the arrangement.
3. Meaning of Personal Information
In this Privacy Statement, "personal information" means information relating to an identifiable natural person or, where applicable under POPIA, an identifiable existing juristic person. This may include names, contact details, account details, school details, identifiers, login information, activity records, communication records, certificate records, technical information and other information that can reasonably identify a person or organisation.
"Processing" includes any operation concerning personal information, including collecting, receiving, recording, organising, storing, updating, retrieving, using, sharing, restricting, deleting or destroying such information.
4. Categories of Information We May Process
The categories of personal information processed through ByteBuddies Academy may include:
- account information, including name, surname, email address, password, role, access level, plan, school association and account status;
- school and organisation information, including school name, administrator details, teacher accounts, subscription or access records and related operational details;
- lesson and curriculum activity, including viewed lessons, favourites, completion status, notes, selected resources, pathway progress and classroom usage records;
- teacher planner information, including plan titles, dates, linked lessons, objectives, materials, class names, notes, activity plans and planning status;
- certificate information, including manually entered learner names, certificate titles, descriptions, dates, facilitator names, linked lessons, templates and verification codes;
- Ask Byte information, including prompts, internal responses, lesson context, conversation records, metadata and whether external AI was used;
- reports and administrative records, including usage summaries, access level information, upgrade requests, content submissions and approval records;
- communications, including support requests, messages, notices, feedback, consent records and administrative correspondence; and
- technical information, including IP address, browser type, device information, session data, cookies, log data, security records and diagnostic information.
5. Learner and Children's Information
ByteBuddies Academy is designed for educational use and may involve information relating to children or learners. The platform does not require full learner database management for its basic certificate functionality. Teachers may, however, manually enter learner names to create certificates or classroom records.
Schools, teachers and authorised adults are responsible for ensuring that learner information entered into the platform is lawful, appropriate, necessary and consistent with school policy, parental/guardian permissions and applicable data protection requirements.
We do not knowingly use children's personal information for commercial profiling, behavioural advertising or unrelated marketing resale. Where children's information is processed, it should be limited to educational support, certificate generation, lesson activity, progress support, classroom administration or related school-authorised purposes.
6. Purposes of Processing
We may process personal information for the following purposes:
- to create, maintain, authenticate, secure and administer user accounts;
- to provide access to lessons, curriculum content, resources, planner tools, certificate tools, Ask Byte features, reports and administrative functions;
- to apply role-based permissions, plan limits, premium access, download controls and subscription or access rules;
- to save user preferences, lesson progress, planner records, certificate records, notes and classroom activity;
- to generate certificates and maintain generated certificate records requested by authorised users;
- to provide school, teacher and administrator reporting where permitted by role and access level;
- to respond to support requests, communicate platform notices and provide operational assistance;
- to maintain security, prevent misuse, investigate suspicious activity and protect the platform;
- to improve, test, troubleshoot and maintain the platform and its educational content;
- to comply with legal, accounting, regulatory, contractual and administrative obligations; and
- for any other purpose that is compatible with the original purpose of collection or permitted by applicable law.
7. Lawful Basis for Processing
We process personal information only where there is a lawful basis to do so. Depending on the context, processing may be based on performance of a contract, consent, a legal obligation, legitimate interests, protection of a person or child, compliance with school or organisational arrangements, or another basis permitted by POPIA or applicable law.
Where consent is required, such consent should be voluntary, specific and informed. Where information relates to a child and consent is required by law, consent must be provided by a parent, guardian, competent person, school or authorised adult as applicable.
8. How Information Is Collected
Personal information may be collected directly from you when you register, log in, complete forms, submit content, create planner records, generate certificates, ask questions, communicate with us or use platform features.
Information may also be provided by schools, administrators, teachers, authorised organisations, implementation partners or service providers, or generated automatically when you use the platform, such as technical logs, session data and usage records.
9. Sharing of Personal Information
We do not sell personal information. We do not sell children's personal information. Personal information may be shared only where reasonably necessary, authorised or required for lawful platform, educational, operational, administrative, security or legal purposes.
Personal information may be shared with:
- authorised school administrators, teachers, facilitators or account administrators, according to role and access level;
- service providers who assist with hosting, storage, email, support, security, PDF generation, backups, analytics, maintenance or related technical services;
- professional advisers, auditors, insurers, legal representatives or consultants where necessary;
- regulators, courts, public bodies, law enforcement or other authorities where required or permitted by law;
- a successor, purchaser or other party in connection with a lawful business restructuring, transfer or sale, subject to appropriate safeguards; and
- any other person where you have consented or where disclosure is otherwise lawful and necessary.
Where service providers process personal information on our behalf, we require them to keep it confidential, use it only for authorised purposes and apply appropriate security measures.
10. International Transfers
Personal information may be stored or processed in South Africa or in other jurisdictions where our authorised service providers operate. Where personal information is transferred outside South Africa, we will take reasonable steps to ensure that the transfer complies with POPIA, including by using appropriate contractual, legal or organisational safeguards where required.
11. Security Safeguards
We take reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, unlawful disclosure, misuse, alteration and destruction. These measures may include access controls, authentication, role permissions, backups, system monitoring, secure hosting practices and administrative safeguards.
No electronic platform, internet transmission or storage system can be guaranteed to be completely secure. Users are responsible for keeping passwords confidential and for using accounts in a secure and authorised manner.
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will take reasonable steps required by applicable law, which may include notifying affected parties and/or the Information Regulator where required.
12. Retention of Personal Information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, or for a longer period where retention is required or authorised by law, contract, school arrangement, audit requirement, security requirement, dispute resolution process or legitimate operational need.
Account records, planner records, certificate records, support records, access records, financial records and administrative records may be retained for different periods depending on their purpose and legal requirements. When information is no longer required, we will take reasonable steps to delete, destroy, anonymise or de-identify it, where practical and lawful.
13. Cookies and Session Technologies
ByteBuddies Academy uses cookies, sessions and similar technologies for essential platform functions, including login, authentication, security, CSRF protection, user preferences, dark mode preference, navigation and normal Laravel application functionality.
We may also use limited technical or analytics information to understand platform performance, troubleshoot issues and improve user experience. You may configure your browser to refuse certain cookies, but some parts of the platform may not function correctly if essential cookies are disabled.
14. Direct Marketing
We may send administrative, security, account, service and platform notices where necessary. Marketing or promotional communication will be sent only where we have a lawful basis to do so, and you may opt out of marketing communications where required by law.
Children's personal information is not used for unrelated marketing or commercial profiling.
15. Third-Party Links and Services
The platform may contain links to third-party websites, resources or services. Independent third parties are responsible for their own privacy practices and terms. You should review the applicable third-party privacy policy before using external services.
16. Your Rights
Subject to applicable law, you may have the right to request confirmation of whether we hold personal information about you, request access to such information, request correction or deletion of inaccurate or unlawfully retained information, object to processing in certain circumstances, withdraw consent where processing is based on consent, and object to direct marketing.
Requests relating to learner or child information may need to be made or authorised by a parent, guardian, competent person, school administrator or other authorised adult, depending on the circumstances and applicable law.
We may require reasonable proof of identity and authority before acting on a request. We may refuse or limit a request where permitted or required by law.
17. Information Regulator
If you believe that your personal information has been processed unlawfully, you may lodge a complaint with the South African Information Regulator. Current publicly available contact details for the Information Regulator include:
Complaints email: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, South Africa
18. Changes to this Privacy Statement
We may update this Privacy Statement from time to time to reflect changes in the platform, law, technology, data practices, service providers or operational requirements. Where changes are material, we will take reasonable steps to notify users or administrators through appropriate channels.
Continued use of the platform after an updated Privacy Statement becomes effective indicates acknowledgement of the updated statement.
19. Contact
Privacy questions, access requests or data protection concerns may be directed to the ByteBuddies Academy platform owner or authorised school administrator. A formal privacy contact address and Information Officer details may be inserted here before final publication.