Legal
Privacy policy
How Amatle Institute handles personal information under the Protection of Personal Information Act 4 of 2013 (POPIA) and what your rights are. Last updated 21 September 2026.
1. Who is responsible
Amatle Makhoakhoa (Pty) Ltd (registration number 2021/439126/07), trading as Amatle Institute, of Unit A23, Northview Shopping Centre, Malibongwe Drive, Northriding, 2188, is the responsible party for personal information processed through this website and our courses. Our Information Officer is registered with the Information Regulator. You can reach the Information Officer through the contact form by choosing "Privacy and personal information", or at info@amatleinstitute.co.za with "Privacy" in the subject line.
2. What we collect
- Account details: your name and email address, and the sign-in records needed to keep your account secure.
- Orders and payments: the email address you bought with, what you bought, the amount, the payment method and the reference. For organisations we also keep the billing name, address and any purchase order number. Card details are collected and held by our payment provider, iKhokha. We never see or store your full card number.
- Learning records: which lessons you have played, how far you got and when, lessons completed and certificates issued.
- Security records: the devices signed in to your account and a log of access to course content. IP addresses and browser details in these records are stored in hashed form, not as readable values.
- Messages: what you send us through the contact form or by email, including your name, email address, organisation and order reference.
- Marketing preferences: your email address and the date you agreed, if you ask to hear from us.
- Website use: the pages viewed, the page you came from and a random session code held in your browser for that visit only. This is not linked to your name or account.
We collect this information from you, except payment confirmations, which come from iKhokha, and records our platform creates as you use it.
3. Why we use it
- To create and run your account, give you the courses you bought, record your progress and issue certificates, because this is necessary to perform our agreement with you.
- To issue invoices and keep financial records, because the law requires it.
- To decide refund requests, including whether a course has been started, because this is necessary to perform our agreement and to protect our legitimate interests.
- To keep accounts and content secure, enforce the personal licence and detect misuse, because of our legitimate interest in protecting the service.
- To answer your messages, because you asked us to.
- To understand how the website is used, in a form not linked to you, because of our legitimate interest in improving it.
- To send marketing email, only with your consent, which you can withdraw at any time.
Giving us your details is voluntary, but without account and order details we cannot sell you a course or give you access to it.
We do not sell personal information. We do not make automated decisions about you that have legal consequences. Member information is never given to the systems we use to write course content.
4. Who we share it with
We use the following providers, who process personal information only on our instructions and must keep it secure and confidential:
- Supabase, for our database, sign-in and file storage, hosted in Ireland.
- Vercel, for hosting this website, including standard web server logs, on servers in several countries.
- iKhokha, for card and instant EFT payments, in South Africa.
- Resend, for sending and receiving email, in the United States.
We may also disclose personal information where the law requires it, to our professional advisers under a duty of confidentiality or to a buyer of the business, who would be bound by this policy.
5. Information sent outside South Africa
Some of these providers store or process information outside South Africa, in Ireland and the United States. We transfer personal information outside South Africa only where section 72 of POPIA allows it. We rely on the recipient being subject to a law, binding corporate rules or a binding agreement that gives protection substantially similar to POPIA, or on the transfer being necessary to perform our agreement with you.
6. How long we keep it
- Invoices, orders and payment records: five years from the end of the tax year in which the transaction took place, as tax law requires.
- Account, access and learning records: while you hold access and for 24 months after it ends.
- Certificate verification records: indefinitely, reduced to the serial number, the course, the date and your initials, so a certificate you hold can always be verified.
- Device and session records: 90 days after last use.
- Content access logs: 12 months.
- Messages and support correspondence: 36 months after the matter is closed.
- Marketing preferences: until you withdraw consent, and reviewed after 24 months without engagement. If you unsubscribe we keep a coded record of your address so that we do not email you again.
- Website use records: 14 months, after which only totals are kept.
When a period ends, the information is deleted or de-identified.
7. How we protect it
Member records sit behind database rules that refuse access unless a specific permission allows it. Information is encrypted in transit. Card details never reach us. IP addresses and browser details in our security logs are stored only in hashed form. If personal information is accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible, as section 22 of POPIA requires.
8. Your rights
- To ask whether we hold personal information about you and for a copy of it (section 23).
- To ask us to correct or delete information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully (section 24).
- To object to processing that relies on our legitimate interests (section 11(3)).
- To withdraw consent to marketing at any time, using the unsubscribe link in any marketing email.
- To complain to the Information Regulator (section 13 below).
We acknowledge a request within two business days, answer a request for access or correction within 15 business days, act on an objection within five business days and stop marketing to you within one business day. We may ask you to confirm your identity first. We do not charge for a straightforward request.
9. Marketing
We send marketing email only to people who have asked for it. Every marketing email has an unsubscribe link and unsubscribing takes effect within one business day. Service emails about something you bought, such as invoices and access notices, are not marketing.
10. Cookies and browser storage
We do not use advertising or tracking cookies. To count page views without identifying you, this website keeps a random session code in your browser that is cleared when you close the tab. When you sign in, your browser stores a sign-in token so that you stay signed in. Our payment provider may set its own cookies on its payment page.
11. Children
Our courses are for adults. We do not knowingly collect personal information from anyone under 18 without the consent of a parent or guardian.
12. Changes to this policy
We publish any change on this page with a new date. If a change materially affects how we use information we already hold about you, we will email you before it takes effect.
13. The Information Regulator
If you are not satisfied with how we handle your personal information, you may complain to the Information Regulator (South Africa):
- JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- PO Box 31533, Braamfontein, Johannesburg, 2017
- Complaints: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Website: inforegulator.org.za