Privacy Policy

Privacy Policy

Effective Date: 17 August 2026 Version: v6 Document ID: hdcc-privacy-2026-08-17 Status: Active

What changed in v6 (Zelda, 17 August 2026): Addendum A is now part of this policy. It was a separate draft document sitting alongside the policy; on Zelda's instruction — "include the addendum to the acutal policy" — it has been folded in as section 21, so there is one policy to read and nothing left outside it. Section 21 discloses that some HDCC email correspondence, and the business signals derived from it, are processed on private infrastructure operated by Philip Simon in Cape Town under a POPIA section 21 operator relationship. It sets out what is processed, why, on what lawful basis, for how long, how it is secured, and how your rights reach it. It supersedes nothing. Sections 1 to 20 are unchanged, including the Photo and Media Release in section 20. This change collects no new information from you.

What changed in v4: the Photo and Media Release, which was a separate document you could accept or refuse on its own, is now section 20 of this policy.

What changed in v5 (12 August 2026): wording only — the courses are named Foundation Course 1 and Foundation Course 2, and PayFast is described as processing card payments, which is the only payment method HDCC accepts. No personal information, purpose, recipient, retention period or right of yours changed.


1. Introduction

Welcome to Helderberg Dog Coaching Centre (HDCC). We are a dog coaching business based in Annandale Drive, Somerset West, Western Cape, South Africa, on the Seventh Day Adventist School premises. We specialise in Agility, Hoopers, Canine Conditioning and Fitness Coaching (CFT), Foundation Course 1 and Foundation Course 2, field rentals, and event hosting.

When you bring your dog to us, you trust us with more than just a booking. You trust us with your dog's health, behaviour history, and your personal details. This Privacy Policy explains, in plain language as required by the Consumer Protection Act (CPA) section 49, how we collect, use, and protect your personal information.

This policy is written to comply with the Protection of Personal Information Act, 2013 (POPIA), the Electronic Communications and Transactions Act, 2002 (ECTA), and the Consumer Protection Act, 2008 (CPA).

This policy applies to our website (https://helderbergdogcoaching.co.za and helderbergdogcoaching.com), our booking systems, our communications via WhatsApp, email, and SMS, and any physical interactions at the Site.

2. Responsible Party and Information Officer

Under POPIA, the "Responsible Party" is the person who decides why and how your personal information is processed.

If you have any question about your data, contact the Information Officer at the operational email above.

3. Personal Information We Collect

We only collect information we need to run our coaching, ensure safety, and manage bookings. We classify what we collect under POPIA section 1 categories:

3.1 Account Details (Section 1: "personal information")

  • Full name, ID number, date of birth (with auto-calculated age), gender
  • Cell phone number, email address
  • Occupation, physical address, postal code
  • Emergency contact name and number
  • Physical disabilities or mobility limitations (collected to ensure we can adequately accommodate your needs — disclosure is optional)

3.2 Dog Information (Section 1: "personal information of the data subject" — your dog's info is YOUR personal information because it is tied to you)

  • Registered name, call name, microchip number
  • Vaccination acknowledgement
  • Date of birth (with auto-calculated age)
  • Breed (pure or cross + specifics)
  • Sex (intact male, intact female, neutered male, spayed female + approximate spay date)
  • Dog medical and behavioural information (special category — see Section 4):
    • Training history and level
    • Recall reliability
    • Behaviour with other dogs and people, on and off lead
    • General health
    • Freight-trained, stake-trained
    • Reactivity (human or dog)
    • Bite history (sensitive — required for safety)
    • Resource-guarding behaviour

3.3 Booking, Payment, and Attendance Data

  • Sessions booked, attendance records
  • Payment history (we do not store full card details — PayFast handles that)
  • Subscription option and renewal status
  • 5th-session bonus and make-up history

3.4 Technical Data

  • IP address, device type, browser information
  • Login timestamps and authentication events

3.5 Communications

  • WhatsApp, email, and SMS correspondence with you
  • Drawn-pad e-signature (captured at registration as a base64-encoded PNG)

3.6 Optional Google or Apple Sign-In

  • If you sign in using Google or Apple, we receive your name, email address, and profile picture from that provider. We do not receive your password.

3.7 Photographs, Video and Audio

  • Photographs, video and audio recordings made during sessions at the Site. See Section 20 (Photo and Media Release) for how they are used and how to withdraw.

4. Special Category: Dog Medical Information

Dog medical and behavioural information (bite history, reactivity, health conditions, spay status) is treated as personal information of the data subject under POPIA section 1 because it is tied to you as the dog's owner.

We process this category of information under the lawful basis of:

  • Consent (POPIA section 11(1)(a)): you give explicit consent at registration.
  • Legitimate Interest (POPIA section 11(1)(f)): safety of you, your dog, our Coaches, and other clients and their dogs at the Site.
  • Performance of a Contract (POPIA section 11(1)(b)): we cannot safely deliver coaching without it.

Purpose limitation (POPIA section 13): we use dog medical information only to:

  1. Assess training suitability and risk before accepting a booking.
  2. Inform safety decisions during sessions (e.g. group-class composition).
  3. Provide tailored coaching and conditioning recommendations.
  4. Maintain incident records (bite history, accident reports) for the statutory limitation period (7 years).

We do not use dog medical information for marketing, third-party sharing, or any purpose unrelated to coaching.

Retention (POPIA section 14): dog medical information is kept for the active relationship plus 7 years (the prescription period for common-law personal-injury claims). After that, records are securely deleted or anonymised.

5. Lawful Bases for Processing (POPIA section 11)

We rely on:

  • Consent (s11(1)(a)) — you opt in at registration.
  • Performance of a contract (s11(1)(b)) — we need your details to book your session, process payment, and deliver coaching.
  • Legitimate interest (s11(1)(f)) — safety, fraud prevention, business operations.
  • Legal obligation (s11(1)(c)) — tax records (SARS), incident logs.

6. How We Use Your Personal Information

  • To manage your bookings, subscriptions, and payments.
  • To communicate with you about your sessions, schedule changes, and safety alerts.
  • To maintain health and behaviour records for the safety of everyone at the Site.
  • To send transactional emails (receipts, confirmations, reminders, cancellation notices, policy-change notifications).
  • To send marketing communications only if you have explicitly opted in (separate from your account creation).

7. The Drawn-Pad Signature

When you register, you sign these documents using a drawn-pad on screen. Your signature is captured as a base64-encoded PNG image.

Storage and use (POPIA section 14 — Security Safeguards):

  • The signature image is encrypted at rest in our database.
  • It is stored only to evidence your acknowledgement of the legal documents you signed.
  • We do not use it for biometric matching, authentication, or any other purpose.
  • It is not shared with any third party except where legally required.
  • It is deleted when you close your account, except where retention is required to defend a legal claim under the 3-year general prescription period.

8. Who We Share Information With (Operators)

We do not sell your personal information. We do not share it for advertising purposes. We share data only with third-party Operators that help us run the business. Each is bound by a Data Processing Agreement.

Operator Purpose Location Cross-Border Safeguard
Resend Transactional and policy-change email delivery Ireland (EU) Standard Contractual Clauses; equivalent protection under POPIA s72
DigitalOcean Website hosting and database storage Amsterdam (NL, EU) Standard Contractual Clauses; equivalent protection under POPIA s72
Google Optional Google Sign-In (OAuth) Global Your consent; Google's Privacy Policy
Apple Optional Apple Sign-In (OAuth) Global Your consent; Apple's Privacy Policy
PayFast Card payment processing South Africa PCI-DSS compliance; PayFast's privacy terms

9. Cross-Border Transfers (POPIA section 72)

Some Operators (Resend, DigitalOcean) are located in the European Union. Under POPIA section 72, we ensure your data is protected even when transferred across borders by relying on:

  • The recipient's contractual undertaking equivalent to POPIA.
  • The European Union's General Data Protection Regulation (GDPR) — which the South African Information Regulator has accepted as providing adequate protection.

10. Retention Periods (POPIA section 14)

  • Active client data: Active relationship + 5 years (SARS tax record requirement).
  • Prospect data: 24 months from last contact.
  • Marketing opt-in lists: Until you opt out.
  • Incident records and bite history: 7 years (common-law prescription period).
  • Drawn-pad signature: Active account + 3 years (general prescription).
  • Communications (WhatsApp, email): 24 months from last interaction.
  • Web access logs: 90 days.

After these periods, your data is securely deleted or fully anonymised.

11. Your Rights as a Data Subject (POPIA sections 23, 24, 25)

You have the right to:

  • Access — ask what data we hold about you.
  • Correction — fix incorrect or incomplete data.
  • Deletion — ask us to delete your data, subject to legal retention requirements.
  • Object — object to processing, including for direct marketing.
  • Restriction — limit how we use your data while a dispute is resolved.
  • Lodge a complaint with the Information Regulator if you believe we have violated your rights.

How to exercise these rights: email helderbergdogcoachingcentre@gmail.com. We will respond within 30 days.

12. Cookies and Tracking

  • Essential cookies: required for the site to function (e.g., keeping you logged in).
  • Functional cookies: used to remember your preferences.
  • No advertising cookies. We do not track you across other websites. We do not run third-party advertising pixels.

You can manage or block cookies through your browser settings.

13. Children (POPIA sections 34, 35)

Our services are not directed at persons under 18 years of age.

If a minor (a child under 18) participates in our coaching, a parent or legal guardian must register on their behalf and provide explicit consent. The personal information of children is treated with special care.

14. Security Safeguards (POPIA section 19)

  • Encryption in transit: TLS 1.3 on all website connections.
  • Encryption at rest: all sensitive fields (including drawn-pad signatures) are encrypted in the database.
  • Passwords: hashed using bcrypt with industry-standard cost factor.
  • Access control: only Zelda Simon and a small number of authorised technical administrators have access to your data.
  • Audit logs: we log who accesses sensitive records and when.
  • Annual review: we review our security safeguards each year.

15. Data Breach Notification (POPIA section 22)

If we become aware of a data breach that compromises your personal information, we will notify you and the Information Regulator as soon as reasonably possible, in accordance with POPIA section 22. We will inform you of the nature of the breach and the steps we are taking to mitigate harm.

16. Direct Marketing (POPIA section 69, ECTA section 45)

We respect your inbox.

  • Marketing messages (newsletters, class promotions) are sent only if you have given separate, explicit opt-in.
  • Every marketing message has a clear, easy unsubscribe link.
  • You can opt out at any time. Transactional messages (booking confirmations, policy changes) continue regardless.

17. Changes to This Policy

When we change this Privacy Policy we will:

  1. Send you an email from legal-notices@helderbergdogcoaching.co.za (a no-reply address used only for legal notices) with a link to the updated policy and a summary of what changed.
  2. Update the "Effective Date" and "Document ID" at the top.
  3. Give you a 30-day grace period during which you can object, opt out, or close your account without penalty.

Add legal-notices@helderbergdogcoaching.co.za and helderbergdogcoachingcentre@gmail.com to your safe-sender list so notifications reach your inbox.

18. Information Regulator Complaint

If you are not satisfied with our handling of your data, you may lodge a complaint with:

Information Regulator of South Africa JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Email: POPIAComplaints@inforegulator.org.za Website: https://inforegulator.org.za

19. Contact

Helderberg Dog Coaching Centre Information Officer: Zelda Simon Operational Email: helderbergdogcoachingcentre@gmail.com Legal Notices: legal-notices@helderbergdogcoaching.co.za (no-reply) Address: Annandale Drive, Somerset West, Western Cape, South Africa

20. Photo and Media Release

Until 9 August 2026 this was a separate document that you could accept or refuse on its own. It is now part of this Privacy Policy, and accepting this policy at registration includes accepting this section.

Lawful basis, stated plainly. Because you cannot register without accepting this policy, we do not rely on your consent alone (POPIA section 11(1)(a)) for the website, social-media and marketing uses in section 20.2. We rely on our legitimate interest in showing what the centre does (section 11(1)(f)), balanced against your unconditional right to withdraw in section 20.5. Internal coaching use — the first bullet of section 20.2 — is necessary to perform our contract with you (section 11(1)(b)).

20.1 What we capture

At Helderberg Dog Coaching Centre (HDCC) we record sessions to help your dog learn and to show what we do. This includes:

  • Photographs
  • Video recordings
  • Audio recordings (including commands and conversation during sessions)

These recordings may be made by Zelda Simon, Elzabi van Wyk, Sarah Davies (in her photographer and social-media collaborator capacity), or by HDCC-authorised guest contractors.

20.2 How we use it

  • Internal coaching and progress. Reviewing your dog's behaviour, giving you feedback (including marked-up screenshots from video), and internal coaching reference material. Visible only to HDCC staff (Zelda, Elzabi, Sarah) and to you. Not shared publicly.
  • HDCC website and social media. The HDCC website (helderbergdogcoaching.co.za) and the social channels HDCC uses at any given time — currently Facebook (@HelderbergDogCoaching) and Instagram (@helderbergdogcoaching), and any further channels (for example TikTok or YouTube) HDCC may adopt. Publicly visible on the internet.
  • External marketing. Paid adverts, printed flyers, brochures, and third-party press articles or interviews. Publicly visible in advertising channels and print media.

We do not specifically tag you on a photograph or video. Normal social-media profile tagging may occur if you re-post HDCC content under your own profile.

20.3 Identifying information

We are careful about what we identify in published content:

  • We use your dog's call name in posts. We do not publish your full name without your separate written consent.
  • Your face may appear in group footage where capture is unavoidable. We use reasonable effort to avoid close-up identification.
  • We never publish your home address, phone number, email address, or ID number.

20.4 Annotated coaching feedback

For conditioning clients in particular, your dog's video footage may be screenshot, marked up with annotations (arrows, circles, notes) and returned to you as coaching feedback.

Those annotated screenshots are shared only with you, kept in your account's feedback section, and are subject to the same retention rules as other dog and handler personal information (sections 4 and 10 above).

20.5 Your right to withdraw — no conditions attached

You must accept this policy to register with HDCC, and this section forms part of it. Your right to withdraw is what keeps that fair, so we state it plainly:

  • You may withdraw your agreement to the website, social-media and marketing uses described in section 20.2 at any time, free of charge, by emailing the Information Officer at helderbergdogcoachingcentre@gmail.com. You do not have to give a reason.
  • Withdrawing does not affect your access to coaching, your bookings, your subscription, or your standing at HDCC in any way. We will not treat you differently for it.
  • We will remove your content from HDCC-controlled channels (website, social media) as soon as reasonably possible, and within 30 days.
  • What we cannot guarantee: if third parties have already re-shared, downloaded or printed our content, we cannot always retrieve it. We will make a reasonable effort to ask them to remove it. Once flyers or brochures are printed, they cannot be recalled.
  • Internal coaching use (the first bullet of section 20.2) continues after withdrawal, because it is necessary for safety and for the service we are contracted to provide.

20.6 Children under 18

If a person under 18 appears in HDCC footage — whether as the handler or as a household member visible at the Site — the parent or legal guardian who registered on their behalf accepts this section for them, and may withdraw it on their behalf on the same terms. This complies with POPIA sections 34 and 35 (special treatment of children's data).

20.7 Copyright and licence

  • Ownership: HDCC retains the copyright in all photographs, video and audio created by our staff and collaborators (including Zelda Simon, Elzabi van Wyk and Sarah Davies). Where Sarah Davies is the principal photographer or videographer, photo credit is given as "Sarah Davies at HDCC" alongside the HDCC brand.
  • Your licence to HDCC: you grant HDCC a non-exclusive, royalty-free licence to use, reproduce, edit and display the content for the purposes set out in section 20.2, for as long as you have not withdrawn under section 20.5.
  • Your own use: you may freely share photos and videos HDCC takes of your own dog (for example re-posting them to your personal social media), provided you credit HDCC where reasonable and do not use the content commercially.

20.8 No payment

This is a free licence. You will not receive any payment, royalty or fee for the use of your image, and you do not retain commercial rights to footage created by HDCC.

20.9 HDCC content standard

HDCC operates on the premises of the Seventh Day Adventist School. We commit that all content shared on our channels will be:

  • Family-rated.
  • Apolitical.
  • Free from religious or political recruitment.
  • Free from sexualised content.
  • Free from content that would be embarrassing or harmful to any handler or dog.

20.10 Electronic acceptance

This section is accepted electronically as part of HDCC registration. Under Electronic Communications and Transactions Act (ECTA) section 13, your drawn-pad signature combined with your account email confirmation is a valid electronic signature for it.


21. Empire-Side Processing (Athena's Empire as Operator)

This section was Addendum A. It is now part of this policy rather than a document alongside it. It supersedes nothing. Sections 1 to 20 continue to apply in full; this section only adds the disclosure of a second-line processor.

21.1 Purpose of this section

This section discloses and authorises a further category of processing: empire-side processing of personal information by Athena's Empire, a private AI infrastructure used by Helderberg Dog Coaching Centre (HDCC) to assist with operations, financial signal detection, and business intelligence.

Sections 1 to 20 describe processing performed directly by HDCC (the Responsible Party). They do not disclose any processing performed by Athena's Empire as a contracted processor. This section closes that gap and satisfies POPIA section 11 (lawful processing) and section 21 (operator contracts) requirements for that processing flow.

This section does not change the categories of information collected, the primary purposes for which it is collected, your rights as a data subject, or the lawful basis on which HDCC processes your information. Those remain as stated elsewhere in this policy — in particular sections 3 and 4 (what we collect), section 5 (lawful bases), section 6 (how we use it), section 10 (retention) and section 11 (your rights).

This section only adds the second-line processing relationship between HDCC and Athena's Empire.

21.2 Who is Athena's Empire?

Athena's Empire is a privately-owned AI infrastructure operated by Philip Simon, Zelda Simon's son, on equipment that he owns and controls. It is not a public service, not a third-party SaaS provider, and not accessible to anyone other than Philip Simon and authorised members of the Simon family.

Athena's Empire is contracted to HDCC under an operator agreement between Zelda Simon and Philip Simon, governed by section 21 of POPIA.

The infrastructure runs on hardware physically located in Cape Town, South Africa. None of the personal information processed under this section leaves South African soil unless explicitly authorised by Zelda Simon for a specific purpose with a recorded lawful basis.

21.3 What Athena's Empire processes on HDCC's behalf

Athena's Empire processes the following categories of HDCC personal information:

  1. Email content received at helderbergdogcoachingcentre@gmail.com, including sender, recipients, subject, body text, and any attachments metadata. Stored encrypted at rest in HDCC's primary email mailbox (Google Workspace, HDCC's existing data controller relationship) and additionally in Athena's Empire's local database for processing purposes.

  2. Derived summaries and categories generated by Athena's Empire from the email content — for example, "this email is a vendor invoice from a garden maintenance supplier," or "this email is a customer enquiry about Sunday lessons." These derivations are stored alongside the original email.

  3. Structured financial signals extracted from emails — for example, "the card payment for a specific booking failed." These structured signals are written to FinanceHOD's working memory, a per-principal database that segregates HDCC's information from any other business handled by Athena's Empire.

  4. Vector embeddings of email summaries used for semantic search within Athena's Empire. Embeddings are derived numerical representations and cannot be reversed to recover the original email content.

Athena's Empire does not process: dog medical or behavioural information, identification numbers (ID, passport, microchip), payment-card data, or biometric data (signatures). Those categories remain solely with HDCC's primary systems as described in sections 3 and 4 of this policy.

21.4 Purpose of empire-side processing

Empire-side processing exists for the following specific, defined purposes, each consistent with POPIA section 13 (purpose specification):

Purpose Example outcome
Operations optimisation Surface a vendor invoice to Zelda within minutes instead of missing it in the inbox.
Cash-flow visibility Detect payment failures and surface them to the FinanceHOD agent for follow-up.
Vendor relationship management Track open accounts-payable items by sender domain.
Pattern detection Identify trends in customer enquiries (e.g. peak booking windows) that inform HDCC's marketing decisions.
Internal audit Maintain a chronologically-ordered record of HDCC business correspondence for the Responsible Party's review.

Empire-side processing is not used for: profiling individual customers, automated decision-making with legal effect, behavioural advertising, or disclosure to any third party. Athena's Empire is a fully closed, non-commercial environment.

21.5 Lawful basis

Empire-side processing is performed under POPIA section 11(1) on the following lawful bases:

  • Legitimate interest of HDCC (section 11(1)(f)) in managing its own business correspondence, detecting payment failures and vendor invoices, and improving operational responsiveness. A POPIA section 11(2) balancing test has been completed; the conclusion is that the processing is proportionate to the legitimate interest, the information processed is minimised to what is necessary, and the processing does not unreasonably override the data subject's rights or interests.

  • Contractual necessity (section 11(1)(b)) where the empire-side processing supports performance of HDCC's contract with the data subject (e.g. responding promptly to customer enquiries, processing booking confirmations).

This section does not rely on customer consent for empire-side processing. Consent is reserved for processing that genuinely requires it (e.g. marketing communications), as described in section 5 of this policy.

A data subject who objects to empire-side processing on legitimate-interest grounds may exercise the right to object in section 11 of this policy. HDCC will then exclude that data subject's correspondence from empire-side processing within 30 days, subject to the operational realities of inbox-level email infrastructure (specifically: emails from objecting customers will still arrive in the HDCC mailbox but will be flagged in the empire-side ingestion pipeline as excluded, and kept out of any derivation, categorisation, or downstream agent visibility).

21.6 Retention

Empire-side processed information is retained for the same period as the primary information from which it is derived, as set out in section 10 of this policy (Retention Periods):

  • Financial signals (cash-flow signals, open watches, risk events and observations derived from vendor or payment emails): 7 years from the date of the underlying email, in line with section 1(1)(c) of the Tax Administration Act, 2011 and SARS practice.
  • Operational and marketing-derived signals (booking confirmations, classroom comments, vendor offers, business-profile signals): 3 years from the date of the underlying email.
  • Vector embeddings: deleted at the same time as the underlying derived record (cascading delete).
  • Raw email storage in Athena's Empire's local database: 3 years from receipt, after which raw bodies are pruned but derived signals are retained per the periods above.

These periods are aligned with section 10 of this policy. They do not extend the periods stated there. If section 10 is amended to shorten retention, the empire-side retention shortens automatically to match.

21.7 Security safeguards (POPIA section 19)

Empire-side processing satisfies POPIA section 19 through the following technical and operational measures:

  1. Network isolation. Athena's Empire runs on a private network not reachable from the public internet. Access from Philip Simon's personal devices is via VPN with per-device cryptographic identity.
  2. Loopback-only services. All empire-side services listen on localhost only. Inter-service communication crosses a restricted overlay network with per-service authentication tokens.
  3. At-rest encryption. Personal information is stored in PostgreSQL with filesystem-level encryption. Especially-sensitive fields use application-level AES-256-GCM encryption with keys rotated quarterly.
  4. In-transit encryption. All cross-service traffic within Athena's Empire is over TLS 1.3.
  5. Access control. Database credentials are held in a secrets manager and rotated. No human can read raw HDCC personal information from Athena's Empire without first authenticating as Philip Simon to multiple distinct services.
  6. Audit logging. Every read or write of HDCC personal information by Athena's Empire is logged to an append-only audit log with hash-chained integrity. Audit log review is available to Zelda Simon as the Responsible Party upon request.
  7. No external disclosure. Athena's Empire does not send HDCC personal information to any third party. Specifically: no foreign cloud, no SaaS analytics, no marketing platforms, no advertising networks.

21.8 Sub-processors

Empire-side processing relies on the following components operating exclusively on Philip Simon's hardware in South Africa:

Component Purpose Location
PostgreSQL Primary structured storage Cape Town, ZA
Qdrant Vector embedding storage Cape Town, ZA
Locally-hosted language models Email summarisation, categorisation Cape Town, ZA

These are not independent third parties; they are open-source software components running on Philip Simon's owned hardware. Athena's Empire does not engage external SaaS sub-processors.

If Athena's Empire ever needs to engage an external sub-processor (for example, to use a cloud-hosted language model for a specific task), the Responsible Party will be notified in advance and this section will be revised.

21.9 Data subject rights and deletion cascade

The data subject rights set out in section 11 of this policy (access, correction, deletion, objection, restriction, and complaint) extend to empire-side processed information.

Specifically: when a data subject exercises the right to deletion against HDCC, the deletion cascades to empire-side derivatives within 30 days:

  1. The raw email records matching the data subject's email address are deleted.
  2. The corresponding derived digest records are deleted.
  3. The corresponding observation, cash-flow signal, open-watch and risk-event records for that data subject are deleted.
  4. The corresponding vector embedding points are deleted.
  5. Any internal channel messages containing identifiable information about the data subject are deleted from Athena's Empire channels.

The audit log retains the fact of deletion (date, request reference) but not the deleted information itself.

The Responsible Party may request the Information Officer to provide written confirmation that the cascade has completed.

Right of access: a data subject who exercises the right of access under section 11 receives both the primary-system information and the empire-side derived signals about them.

21.10 Information Officer responsibility

Zelda Simon remains the Information Officer with responsibility for all HDCC personal information, including the portion processed by Athena's Empire. Philip Simon, as the operator of Athena's Empire, is accountable to Zelda Simon for the operator obligations in POPIA section 21 (security safeguards, breach notification, return-or-destroy on termination).

If Zelda Simon terminates the operator relationship with Athena's Empire, Philip Simon will, within 30 days:

  1. Return all HDCC personal information to HDCC in a portable format, or securely destroy it per Zelda Simon's instruction.
  2. Provide written confirmation of return or destruction.
  3. Confirm that no backups or copies of HDCC personal information remain on Athena's Empire infrastructure.

21.11 Breach notification

In the event of a security breach affecting HDCC personal information processed by Athena's Empire, Philip Simon will notify Zelda Simon within 24 hours of detection. Zelda Simon, as Information Officer, will then discharge HDCC's POPIA section 22 notification obligations to the Information Regulator and affected data subjects.

21.12 Changes to this section

This section may be amended only with Zelda Simon's written sign-off. The amendment process is the one in section 17 of this policy (Changes to This Policy). Material amendments will be notified to existing customers through the section 17 notification mechanism.


Document ID: hdcc-privacy-2026-08-17 | Version: v6 | Effective: 17 August 2026

Helderberg Dog Coaching Centre · helderbergdogcoachingcentre@gmail.com · +27 72 602 3318