Skip to content
No results
  • Home
  • Courses
  • Journal
  • My Family
    • My Children
  • Cohorts
  • Progress
Budding Flowers
  • Home
  • Courses
  • Journal
  • My Family
    • My Children
  • Cohorts
  • Progress
Login
Budding Flowers

Privacy Notice

Last updated: 26 May 2026

Status: Draft for lawyer review. Not yet effective.


1. Who we are

This Privacy Notice describes how TechnoStars (“we”, “us”, “our”) collects, uses, and protects your personal information through the Budding Flower learning management system (the “Platform”). Budding Flower is operated by TechnoStars on behalf of partner institutions such as the Verenigde Gereformeerde Kerk Sarepta (URC Sarepta).

Responsible party (as defined in POPIA): TechnoStars Cape Town, 8000 Western Cape, South Africa

Information Officer: [Name and contact details to be inserted before publication] Email: privacy@buddingflower.co.za (placeholder — confirm before publication)

If you have any questions about this notice or your personal information, please contact our Information Officer using the details above.


2. What this notice covers

This notice applies to personal information collected through:

  • The Budding Flower website at buddingflower.co.za
  • Account registration as a learner or parent/guardian
  • Course participation, including lessons and quizzes
  • Any other interactions with the Platform

It does not cover personal information collected by the institutions themselves outside the Platform (for example, paper application forms held by your church), or by third-party services we link to (such as external course content providers).


3. The personal information we collect

We collect only the information we need to run the Platform. The specific information depends on whether you register as a learner, a parent/guardian, or an administrator.

Information we collect from all users

  • Username and email address — to create and access your account
  • First name and surname — to identify you on the Platform
  • Contact number — to reach you for account-related matters
  • Institution — the church, school, or organisation you belong to
  • Sub-unit (ward or class) — your group within the institution

Additional information from learners

  • Date of birth — used to identify which classes or groups apply to your age, and to help match family connections
  • School grade (when your institution requires this) — to organise learning material appropriately

Additional special category information from learners (when your institution requires this)

This information is “special personal information” under section 26 of POPIA and we only collect it with your explicit consent and only because it is necessary for the religious or educational programme you are enrolling in:

  • Whether you have been baptised and, if so, the date, location, and officiant
  • Your reasons for enrolling in the programme
  • Your worship attendance

These fields are only shown during registration if your institution has specifically chosen to collect them.

Information we collect from parents and guardians

  • Names and dates of birth of children you wish to link to your account — so that your child’s learner account can be matched to yours

Information collected automatically

When you use the Platform, our security and infrastructure systems may automatically log:

  • IP addresses — for security monitoring and brute-force protection
  • Login timestamps — for account security
  • Failed login attempts — for brute-force protection

Information we do not collect

We do not currently collect: identity numbers, banking details, biometric information, location data beyond IP address, or marketing preference data.


4. Why we collect this information (lawful basis)

Under section 11 of POPIA, we process your personal information on the following lawful grounds:

Performance of a contract (between you and us)

Most of your account data is processed because we need it to provide the service you signed up for: creating your account, enrolling you in courses, tracking your progress, and linking you to family members.

Your consent

Some information — particularly special category information about religious beliefs and practices — is processed only because you have given explicit consent during registration. You can withdraw this consent at any time (see Section 11 below).

Compliance with a legal obligation

We retain certain records (for example, basic account information) where the law requires us to do so.

Legitimate interest

We log security information (IP addresses, login attempts) to protect the Platform and other users from misuse.


5. Information about children (under 18)

Under sections 34 and 35 of POPIA, we may only process personal information of a child with prior consent from a competent person — usually a parent or legal guardian.

When a person under 18 registers as a learner, we require:

1. Confirmation during registration that parental or guardian consent has been obtained 2. Where possible, verification through the parent’s own registration on the Platform

If you are a parent or guardian and you believe your child has registered without your consent, please contact our Information Officer immediately and we will suspend the account and delete the data.

We design the Platform so that a child’s personal reflections (journal entries) are never visible to parents — only course progress and structured learning data is shared with linked parents.


6. Who we share your information with

We do not sell your personal information. We share it only with:

Your linked institution

Your registered institution (for example, URC Sarepta) has access to your account information and learning records so it can administer the programme you are enrolled in.

Linked parents/guardians (for learner accounts)

Parents you have confirmed as linked to your account can see your name, course enrolments, course progress, and recent learning activity. They cannot see your journal entries, login credentials, or any other private content.

Service providers (“operators” under POPIA)

We use the following service providers, each under a Data Processing Agreement that requires them to protect your information:

  • Hosting provider — to host the Platform and store its data
  • Brevo (formerly Sendinblue) — to send transactional emails such as password resets and registration confirmations
  • Wordfence — to provide security services such as two-factor authentication

Where any of these providers process data outside South Africa (Brevo is based in the EU), we ensure they offer protection at least equivalent to POPIA, in accordance with section 72 of the Act.

Where required by law

We may disclose personal information if compelled by a court order, regulator request, or other legal obligation. We will only do so to the extent strictly required.


7. How long we keep your information

We keep personal information only as long as we need it for the purposes set out in this notice, in accordance with section 14 of POPIA.

Category Retention period
Active account information Duration of active use + 12 months
Course progress records Duration of active use + 12 months
Special category data (religious info) Same as account, or until you withdraw consent
Journal entries Until you delete them, or until you delete your account
Family link records Until you remove the link
Security logs (IP addresses, login attempts) 30–90 days
Backups Per backup retention schedule (typically up to 12 months)

When data is no longer needed, we delete it or anonymise it so that you can no longer be identified from it.


8. How we protect your information

We take reasonable technical and organisational measures to protect your personal information, including:

  • HTTPS encryption of all data transmitted between you and the Platform
  • Two-factor authentication for administrator accounts
  • Role-based access control so that users only see data appropriate to their role
  • Brute-force login protection via Wordfence and Loginizer
  • Regular backups so we can recover from data loss
  • Restricted database access to a small number of authorised technical staff

Despite these measures, no system is completely secure. If we become aware of a security breach affecting your personal information, we will notify the Information Regulator and affected users as required by section 22 of POPIA.


9. Your rights as a data subject

Under POPIA, you have the following rights:

Right to access (section 23)

You can ask us what personal information we hold about you. We will respond within a reasonable time and free of charge for a first request.

Right to correction (section 24)

You can ask us to correct any inaccurate or outdated information. Most fields can be updated yourself in your account profile. For others, contact our Information Officer.

Right to deletion (section 24)

You can ask us to delete your personal information. We will do so unless we are required by law to keep it. Some data (such as security logs) will continue to be retained for the periods set out in Section 7.

Right to object to processing (section 11(3))

You can object to processing based on consent or legitimate interest. Where the processing was based on your consent, withdrawing consent stops the processing.

Right to lodge a complaint

If you believe we have not handled your personal information properly, you can complain to:

The Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Email: inforeg@justice.gov.za Website: www.justice.gov.za/inforeg

You may also escalate to the Information Officer of TechnoStars before lodging a formal complaint.


10. Cookies and similar technologies

The Platform uses session cookies to keep you logged in, and a small number of functional cookies to remember preferences. We do not use advertising cookies, tracking pixels, or third-party analytics.

You can disable cookies in your browser, but the Platform may not function correctly without them.


11. Withdrawing your consent

Where we process your personal information based on consent, you can withdraw it at any time:

  • For special category information (religious data): contact our Information Officer to have these fields removed from your account.
  • For family links: you can remove declared children via the My Children page.
  • For the entire account: contact our Information Officer to request account deletion.

Withdrawing consent does not affect processing that took place before the withdrawal, and we may continue to process your information on other lawful grounds (such as legal obligation).


12. Changes to this notice

We may update this notice from time to time. When we make significant changes, we will:

  • Update the “Last updated” date at the top
  • Notify active users by email
  • Post a notice on the Platform homepage

Your continued use of the Platform after changes means you accept the updated notice.


13. Contact us

For any questions, requests, or complaints about this notice or your personal information:

TechnoStars — Information Officer Cape Town, 8000, Western Cape, South Africa Email: privacy@buddingflower.co.za (confirm before publication)

For complaints to the Information Regulator, see Section 9.


This notice is provided in plain language to help you understand how we handle your personal information. If anything is unclear, please contact us.

  • Announcements
  • Privacy Notice
  • Terms of Use

Copyright © 2026 - WordPress Theme by TechnoStars