Privacy Policy
Last updated: 24 April 2026
1. Introduction
Taal Rooster is owned and operated by Responsive Design Agency (Pty) ("RDA", "we", "us", or "our"). We are committed to protecting the privacy and personal information of our users in accordance with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, and — for international schools or users with European connections — the EU General Data Protection Regulation (GDPR). This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Taal Rooster platform, and forms part of the Terms of Service.
2. Information Officer
For any privacy-related queries or requests regarding your personal information, please contact our Information Officer at contact@taalrooster.co.za. Our Information Officer is registered with the Information Regulator of South Africa in accordance with POPIA section 55 and is responsible for compliance, responding to data subject requests, and coordinating with the Regulator.
3. Personal Information We Collect
We collect the following categories of personal information:
- Identity information: Full name, email address, and role (teacher, student, school administrator, or moderator).
- Authentication data: Encrypted passwords (bcrypt hashed), OAuth tokens when using Google or Microsoft sign-in (AES-256-GCM encrypted at rest).
- School information: Email domain, school name, and school association.
- Educational records: Assignments, submissions, grades, rubric scores, and teacher feedback (text, timestamped comments, and audio notes).
- Video references: A reference (file ID and link) to each video submission stored in the teacher's or school's own Google Drive or Microsoft OneDrive. We do not store the video files themselves and do not access, stream, or view their content.
- Technical data: Browser type, device information, and service usage logs collected automatically. We deliberately do not store IP addresses in our application logs.
- Parental-consent metadata: For minor users, a boolean consent flag, the consent timestamp, and the version of the consent text shown to the parent. The parent's name and email are deleted immediately upon confirmation of consent.
4. Purpose of Processing
We process your personal information for the following purposes, as permitted under POPIA §§ 10–12:
- To create and manage your user account and authenticate your identity.
- To facilitate the creation, submission, and grading of video-based assignments.
- To associate users with their educational institution based on email domain.
- To send in-app and email notifications about assignment submissions, grades, and account events.
- To facilitate video-file transfer into the teacher's or school's own Google Drive or Microsoft OneDrive, and to store only a reference to those files.
- To operate parental-consent workflows for minor users as required by POPIA section 35.
- To process subscription payments via our payment provider (Paystack).
- To investigate abuse reports, enforce our Terms of Service and Acceptable Use Policy, and comply with legal obligations.
- To monitor platform security and generate audit logs for compliance purposes.
We do not use personal information or User Content for targeted advertising, behavioural profiling, or to train machine-learning or artificial-intelligence models. We do not perform automated decision-making or algorithmic grading — all assessments and grades are determined solely by human teachers. We may use aggregated, de-identified service-usage statistics for product improvement.
5. Legal Basis for Processing
We rely on your consent (POPIA §11(1)(a)) as the primary legal basis for processing your personal information, which you provide when creating an account and, for minors, through the parental-consent workflow. We may also process information where it is necessary for the performance of a contract with you (POPIA §11(1)(b)), where we have a legitimate interest (POPIA §11(1)(f) — for example, platform security and abuse investigation), or where processing is required by law.
6. Children's Information & Operator Relationship
Many users of Taal Rooster are children under 18 years of age. In accordance with POPIA §35, we require that a competent person (parent or legal guardian) provides consent for the processing of a child's personal information. We support two consent routes:
- Parent/guardian email consent (default). When a learner signs up and indicates they are under 18, our Parental Consent workflow delivers a time-limited, single-use confirmation link to the parent's email. Upon confirmation, the parent's name and email are permanently deleted and only a consent flag, timestamp, and consent-text version are retained for audit.
- School-managed consent attestation. A participating school may, through an authorised school administrator, formally attest that the school has obtained valid parent or guardian consent (or has another lawful basis under POPIA) for every enrolled learner to use Taal Rooster. The school must upload a signed copy of its consent agreement (or equivalent policy/notice) to our records. Where this mode is active, the school assumes full responsibility for obtaining, recording, maintaining, and honouring withdrawals of parent/guardian consent. Taal Rooster relies on the school's attestation and does not separately contact each parent.
Where a school is the Responsible Party under POPIA (i.e., the school has instructed the use of Taal Rooster with its students), Taal Rooster acts as an Operator for the school under POPIA sections 20–21. A written Operator Agreement between the school and Taal Rooster governs that relationship and is available on request. Schools and teachers are responsible for ensuring that appropriate parental consent has been obtained for their students, in accordance with that Operator Agreement and their own safeguarding policies.
7. Video Submissions & Special Personal Information
Where a student is identifiable from their face or voice in a video submission, that submission contains special personal information (biometric information) under POPIA section 26. Processing of such information is justified under POPIA section 27(1)(a) on the basis of the explicit consent of the data subject or, for minors, the parent/guardian via our Parental Consent workflow.
Video files are transferred from the student's browser into the teacher's or school's own Google Drive or Microsoft OneDrive account via a short-lived staging transfer. Only a reference (file ID and access link) is retained in our database. We do not access, stream, view, or otherwise process the content of video submissions beyond this transfer. Access to video content is governed entirely by the teacher's and school's Google Workspace or Microsoft 365 controls. Teachers and schools are responsible for managing, safeguarding, and deleting video files in their Drive or OneDrive accounts in accordance with their retention and safeguarding policies.
Because we do not view video content, we rely on reports from teachers, school administrators, students, and parents to identify abuse of the platform. Reports may be sent to contact@taalrooster.co.za. Our enforcement procedure is set out in our Terms of Service.
8. Third-Party Services & Cross-Border Transfers
Your personal information may be transferred to and processed in countries outside of South Africa through the following third-party services:
- Cloud infrastructure (Supabase on AWS): database, authentication, edge functions, and transactional email queueing. Data is encrypted in transit (TLS 1.2+) and at rest.
- Google Drive: Video files are stored on the teacher's or school's own Google Drive account, governed by Google LLC's privacy practices and the school's Google Workspace agreement.
- Microsoft OneDrive: Alternative to Google Drive, governed by Microsoft's privacy practices and the school's Microsoft 365 agreement.
- Google & Microsoft OAuth: When you sign in via Google or Microsoft, authentication data is processed by these providers under their respective privacy policies.
- Paystack: Subscription payment processing (PCI DSS Level 1).
- Sentry: Error monitoring. Configured to strip user-identifying information (email, username, IP) and to disable session replay; only technical data (stack traces, browser type) is transmitted.
These transfers are permitted under POPIA section 72 on the basis that (a) you (or, for minors, a parent/guardian) have consented to the transfer as part of your use of the Platform; (b) the transfer is necessary for the performance of our contract with you; and (c) we contract with providers bound by binding rules or laws that uphold principles of reasonable processing substantially similar to POPIA. For users subject to the GDPR, transfers rely on equivalent Article 49 grounds or the relevant Standard Contractual Clauses of each provider.
9. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes described in this policy, or as required by law (POPIA §14):
- Account data: retained while your account is active.
- Upon account deletion or termination: a 30-day grace period during which you may export your data; thereafter personal information is deleted or de-identified, subject to any legal retention obligations.
- Audit log entries: retained for up to seven (7) years to satisfy compliance and dispute-resolution needs. Audit entries do not contain email addresses or IP addresses.
- Parental-consent records: retained for the duration of the student's account plus seven (7) years after deletion (boolean flag, timestamp, and consent-text version only — no parent PII).
- Billing records: retained for five (5) years as required by South African tax and accounting law.
- Video files stored on teachers' Google Drive or OneDrive accounts are the responsibility of the respective teacher or school to manage and delete.
10. Your Rights Under POPIA
You have the following rights regarding your personal information:
- Right of access (§23): Request a copy of your personal information we hold.
- Right to correction (§24): Request correction of inaccurate personal information.
- Right to deletion (§24): Request deletion of your personal information, subject to legal obligations.
- Right to object (§11(3)): Object to the processing of your personal information on reasonable grounds.
- Right to data portability: Export your data in a machine-readable format.
- Right to withdraw consent: Withdraw your consent to processing at any time (this may affect your ability to use the platform).
- Right to complain: Lodge a complaint with the Information Regulator of South Africa (see §14 below).
To formally exercise your right to object to processing, you may use the POPIA Form 1 (Objection to Processing of Personal Information) issued by the Information Regulator. To request correction or deletion, you may use Form 2 (Request for Correction/Deletion of Personal Information). These forms are available at inforegulator.org.za. Completed forms should be submitted to our Information Officer at contact@taalrooster.co.za.
Most of these rights are self-serviceable from the Account Settings page. To exercise any other right, or if you are unable to use the self-service tools, contact our Information Officer at contact@taalrooster.co.za. We will respond within 30 days.
11. Security Measures
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, or damage (POPIA §19):
- Technical: TLS 1.2+ (HTTPS) for all data in transit; AES-256-GCM encryption of OAuth tokens at rest; bcrypt password hashing; SSL-encrypted database connections; row-level security policies on database tables; role-based application routing; JWT sessions with automatic expiry; cloud-storage tokens never exposed to browser clients.
- Organisational: access controls restricting employee data access to role-based necessity; employee confidentiality obligations; a documented incident-response plan; audit logging of significant actions; periodic review of security controls.
- Error monitoring: email, username, and IP address are stripped from all error reports; session replay is disabled; only technical data is transmitted to our error provider.
In the event of a security compromise that poses a risk to data subjects, we will notify affected users and the Information Regulator as required by POPIA section 22 as soon as reasonably possible and, in any event, without undue delay.
12. Cookies & Tracking
Taal Rooster uses essential cookies and browser local storage for authentication and session management only. We do not use third-party tracking cookies, advertising cookies, or analytics tools that track users across sessions or sites.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to account holders by email and through an in-app notice at least 20 business days before they take effect. Where a material change involves a new purpose of processing that requires fresh consent under POPIA, we will obtain that consent affirmatively rather than relying on continued use. Non-material changes (for example, clarification wording, typographical fixes) take effect when published.
14. Information Regulator
If you are unsatisfied with how we handle your personal information, you may lodge a complaint with the Information Regulator of South Africa:
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints.IR@justice.gov.za
Website: inforegulator.org.za
Contact
Business Name: Responsive Design Agency (Pty)
Address: 14 Sweet Home Way, Elfindale, Cape Town, 7945, South Africa
Information Officer: contact@taalrooster.co.za
General enquiries: contact@taalrooster.co.za
Abuse reports: contact@taalrooster.co.za
PAIA Manual: View our Promotion of Access to Information Act Manual