Need Help? Email: hello@petguru.co.za | Support Chat: Open Chat

POPIA Notice

POPIA Notice

Last updated: May 2026

This notice is issued by RealTeasy (Pty) Ltd ("PetGuru") in compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), which came into full effect on 1 July 2021. POPIA is South Africa's primary data protection legislation and regulates how organisations may collect, process, store, share, and destroy personal information about individuals (referred to as "data subjects").

PetGuru is committed to upholding the rights of all data subjects and to responsible, lawful processing of personal information. This notice should be read alongside our Privacy Policy for a complete understanding of how we handle your data.

1. What is POPIA?

The Protection of Personal Information Act 4 of 2013 is a comprehensive data protection law that gives effect to the constitutional right to privacy as enshrined in Section 14 of the Constitution of the Republic of South Africa, 1996. POPIA establishes conditions for the lawful processing of personal information and grants individuals meaningful rights over how their information is used.

POPIA establishes eight conditions for lawful processing of personal information:

  • Accountability: The responsible party must ensure compliance with all conditions for lawful processing.
  • Processing Limitation: Personal information may only be processed in a lawful, fair, and non-excessive manner.
  • Purpose Specification: Personal information must be collected for a specific, explicitly defined, and legitimate purpose.
  • Further Processing Limitation: Further processing must be compatible with the original purpose of collection.
  • Information Quality: Reasonable steps must be taken to ensure information is complete, accurate, and not misleading.
  • Openness: Data subjects must be notified of the collection and use of their personal information.
  • Security Safeguards: Reasonable technical and organisational measures must secure personal information against loss, damage, or unauthorised access.
  • Data Subject Participation: Data subjects have the right to access and correct their personal information.

2. Your Rights as a Data Subject

Under POPIA, you have the following rights in respect of your personal information held by PetGuru:

2.1 Right to be Notified

You have the right to be informed when PetGuru collects your personal information, the purpose for which it is being collected, and how it will be used.

2.2 Right of Access

In terms of Section 23 of POPIA, you have the right to request confirmation of whether PetGuru holds personal information about you, and to request a record of that information. Requests may be made to our Information Officer.

2.3 Right to Correction or Deletion

Under Section 24 of POPIA, you have the right to request the correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or that was obtained unlawfully. You also have the right to request the destruction or deletion of information that PetGuru is no longer authorised to retain.

2.4 Right to Object to Processing

In terms of Section 11(3) of POPIA, you have the right to object, on reasonable grounds, to the processing of your personal information. This includes the right to opt out of direct marketing at any time by using the unsubscribe link in any marketing communication or by contacting us directly.

2.5 Right to Withdraw Consent

Where PetGuru processes your personal information on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to the withdrawal.

2.6 Right to Lodge a Complaint

If you believe that PetGuru has violated your rights under POPIA, you have the right to lodge a complaint with the Information Regulator of South Africa:

  • Website: www.inforegulator.org.za
  • Email (Complaints): PAIAComplaints@inforegulator.org.za
  • Email (General): inforeg@justice.gov.za

3. Information We Process

PetGuru processes the following categories of personal information:

3.1 Identifying Information

  • Full name and profile photograph
  • Email address and contact number
  • Physical or postal address (for delivery purposes)
  • Identity document number (for Verified Breeder / professional applications only — stored only as an irreversible hash, never in plain text; see section 3.6)

3.2 Pet-Related Information

  • Pet names, species, breeds, ages, and photographs
  • Health records and vaccination information (where voluntarily provided)
  • Microchip or registration numbers

3.3 Financial Information

  • Transaction history for Marketplace purchases
  • Payment method details (processed and tokenised by our third-party payment gateway; PetGuru does not store full card details)

3.4 Technical and Usage Information

  • IP address and device identifiers
  • Browser and operating system information
  • Usage patterns, search queries, and Platform interactions
  • Cookie data (as described in our Cookie Policy)

3.5 Correspondence

  • Messages sent through the in-platform messaging system
  • Support tickets and email correspondence

3.6 Special Personal Information (Identity & Biometric Verification)

Where you apply for a Verified badge as a breeder or professional, we process certain special personal information as contemplated in Section 26 of POPIA — namely your South African ID number and, if you provide one, a facial image (selfie). In line with Section 27, this is done only with your explicit consent, obtained at the point of submission, and solely to confirm your identity and combat fraud on the Platform.

  • Your ID number is stored only as an irreversible cryptographic hash — never in plain text.
  • Your selfie is compared once against the photograph on your ID document (a one-to-one facial comparison). It is not used to build a facial database or to identify you in any other context, and the comparison provider does not retain it.
  • Identity and credential documents are read by automated systems to confirm authenticity and that the details match what you provided.
  • You may withdraw this consent at any time, after which we will stop processing and delete the associated information, subject to any legal retention obligations.

4. Lawful Basis for Processing

PetGuru processes personal information on the following lawful bases as set out in Section 11 of POPIA:

  • Consent: Where you have given us consent to process your information for a specific purpose (e.g., marketing communications).
  • Contractual Necessity: Where processing is necessary to perform a contract with you, such as fulfilling a Marketplace order or operating your account.
  • Legal Obligation: Where we are required to process your information to comply with a legal obligation imposed on us.
  • Legitimate Interest: Where processing is necessary for PetGuru's legitimate business interests, provided those interests are not overridden by your rights and freedoms (e.g., fraud prevention, platform security, and analytics).
  • Explicit Consent for Special Personal Information: Special personal information (your ID number and facial image) is processed only on the basis of your explicit consent under Section 27 of POPIA, for identity verification and fraud prevention.

5. How We Protect Your Information

In accordance with Section 19 of POPIA, PetGuru takes appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised destruction of personal information, and to prevent unlawful access to or processing of personal information.

Our security measures include:

  • SSL/TLS encryption for all data transmitted to and from the Platform
  • Bcrypt hashing for all stored passwords
  • Role-based access controls limiting employee access to personal information
  • Regular security assessments and penetration testing
  • Secure, access-controlled cloud infrastructure
  • Data breach response procedures aligned with Section 22 of POPIA

In the event of a security compromise that may affect your personal information, PetGuru will notify the Information Regulator and, where required, affected data subjects as soon as reasonably possible after becoming aware of the breach.

6. Accessing Your Information

To exercise any of your rights under POPIA, including requesting access to, correction of, or deletion of your personal information, please submit a written request to our Information Officer. We will acknowledge your request within 3 business days and respond substantively within 30 days, as required by POPIA.

Requests for access to personal information are governed by the provisions of the Promotion of Access to Information Act 2 of 2000 (PAIA). Please refer to our PAIA Manual for the full request procedure.

7. Information Officer

PetGuru has appointed an Information Officer as required by Section 55 of POPIA. The Information Officer is responsible for ensuring PetGuru's compliance with POPIA and for handling data subject requests and complaints.

  • Information Officer: PetGuru Information Officer
  • Organisation: RealTeasy (Pty) Ltd
  • Email: privacy@petguru.co.za
  • Country: Republic of South Africa

All POPIA-related enquiries, access requests, and complaints should be directed to the Information Officer. If you are dissatisfied with our response, you have the right to escalate your complaint to the Information Regulator of South Africa.