Legal • paleopower.co.za
Privacy Policy
How Paleo Power (Online Synergy CC) collects, uses, stores, and protects your personal information — and how to exercise your rights under South African law.
Privacy at a Glance
Data We Collect
Name, email, IP address, browsing data via cookies. No sensitive health data.
Why We Collect It
Newsletter delivery, site analytics, spam prevention, service improvement.
Who We Share With
MailChimp, Google Analytics, Akismet, ClickBank. We do not sell your data.
Retention Period
Up to 2 years, or as required by law. Newsletter data until you unsubscribe.
Your Rights
Access, correct, delete, or object to your data at any time.
Governing Law
POPIA (SA). GDPR rights honoured for EEA/UK. CCPA for California residents.
01 Who We Are
This Privacy Policy is issued by Online Synergy CC, a close corporation registered in South Africa and trading as PaleoPower. We operate paleopower.co.za and are the "responsible party" for your personal information as defined under the Protection of Personal Information Act 4 of 2013 (POPIA).
Online Synergy CC (trading as PaleoPower)PO Box 838, Sea Point, Cape Town, Western Cape 8060, South Africa
Website: paleopower.co.za • Contact: paleopower.co.za/contact
POPIA — Information Officer
Under POPIA, Online Synergy CC has designated a responsible member as Information Officer. Requests relating to your personal information should be directed via our Paleo Power contact page. We aim to respond to all data subject requests within 30 days as required by POPIA.
02 What Information We Collect
Information you provide to us
- Name and email address — when you subscribe to our newsletter via MailChimp
- Name, email, and comment content — when you submit a comment on an article
- Name, email, and message content — when you contact us via our contact form
We do not collect sensitive personal information as defined by POPIA (including health data, biometric data, religious beliefs, political opinions, or financial information).
Information collected automatically
| Data Type | Examples | Collected |
|---|---|---|
| IP address & device identifiers | IP, browser fingerprint, device type | Yes |
| Log & usage data | Pages viewed, timestamps, referring URLs | Yes |
| Location data | Country/city inferred from IP | Approximate |
| Cookie & tracking data | Session IDs, analytics cookies | Yes |
| Sensitive personal information | Health data, biometrics, financial info | No |
| Payment information | Credit card or banking details | No |
| Precise GPS location | Device GPS coordinates | No |
03 How We Use Your Information
- Newsletter delivery: To send the PaleoPower newsletter you subscribed to
- Site operation: To maintain technical functioning, including spam prevention via Akismet
- Analytics: To understand how visitors use the site via Google Analytics (anonymised aggregate data)
- Comment moderation: To manage and moderate user-submitted comments
- Communication: To respond to contact form submissions
- Legal compliance: To comply with applicable South African law
- Fraud prevention: To detect and prevent spam, abuse, and security incidents
We do not use your personal information for automated decision-making or profiling that produces legal or significant effects on you.
04 Legal Bases for Processing
POPIA — Primary Governing Law (South Africa)
As a South African operator, our primary legal basis framework is POPIA. We process personal information only where at least one of the following conditions is met: consent (newsletter subscriptions), legitimate interest (analytics and security), legal obligation (compliance with SA law), or contractual necessity (delivering a service you requested).
GDPR / UK GDPR — EEA & UK Visitors
If you are located in the EEA or United Kingdom, we also recognise the legal bases under GDPR. Our processing for newsletter subscribers is based on your express consent; analytics is based on legitimate interests. You may withdraw consent at any time without affecting prior lawful processing.
06 Third-Party Processors
The following third-party services process personal data on our behalf or in connection with the site:
- MailChimp (Intuit)Email newsletter delivery and subscriber managementPrivacy Policy
- Google AnalyticsAnonymised site traffic and user behaviour analyticsPrivacy Policy
- Akismet (Automattic)Comment spam detection and filteringPrivacy Policy
- ClickBankAffiliate programme transaction processingPrivacy Policy
- CloudflareCDN, DDoS protection, bot managementPrivacy Policy
- TermlyCookie consent banner managementPrivacy Policy
Where these processors are located outside South Africa, we ensure they provide adequate protection for personal information as required by POPIA Section 72.
08 How Long We Keep Your Data
- Newsletter subscriber data: Until you unsubscribe
- Comment data: For as long as the associated article remains published, unless you request deletion
- Contact form submissions: Up to 2 years
- Analytics data: Anonymised after 26 months (Google Analytics default)
- Server logs: Typically 90 days for security purposes
09 How We Protect Your Data
We implement appropriate technical and organisational security measures including HTTPS encryption, Cloudflare DDoS protection, WordPress security hardening, and limited access controls. No internet transmission is 100% secure — while we take all reasonable steps to protect your information, we cannot warrant absolute security.
10 Children & Minors
This site is not directed at children under the age of 18. We do not knowingly collect personal information from minors. Under POPIA, processing a child's personal information requires prior consent from a competent person. If you believe your child has provided us with personal information without consent, contact us immediately and we will promptly delete that information.
11 Your Privacy Rights — Overview
Right to Access
Request a copy of the personal information we hold about you.
Right to Correct
Request correction of inaccurate or incomplete personal information.
Right to Delete
Request deletion of your personal information, subject to legal retention obligations.
Right to Object
Object to processing based on legitimate interests, including direct marketing.
Right to Portability
Receive your data in a structured, machine-readable format.
Withdraw Consent
Withdraw consent for consent-based processing at any time without penalty.
To exercise these rights, contact us via our contact page. We will respond within 30 days. For newsletter preferences: update your MailChimp subscriber preferences.
12 POPIA Rights — South African Residents
Protection of Personal Information Act 4 of 2013 (POPIA)
POPIA is the primary law governing our processing of your personal information. As a data subject under POPIA, you have the right to be notified (Section 18), access your information (Section 23), request correction or deletion (Section 24), and object to processing (Section 11(3)).
Information Regulator of South Africa
If you have a complaint we cannot resolve directly, you may contact the Information Regulator:
Website: inforegulator.org.za
General: [email protected]
POPIA complaints: [email protected]
13 GDPR Rights — EEA & UK Visitors
GDPR / UK GDPR
If you are located in the EEA or UK, the GDPR or UK GDPR applies. You may lodge a complaint with your national supervisory authority. UK residents may contact the Information Commissioner's Office (ICO). Our lawful bases for processing are consent (newsletter), legitimate interests (analytics, security), and legal obligation.
14 CCPA Rights — California Residents
California residents have rights under the CCPA and CPRA. Categories of personal information collected in the past 12 months:
| Category | Collected |
|---|---|
| A. Identifiers (name, email, IP) | Yes |
| B. Customer records (name, contact info) | Yes |
| C–K. All other categories | No |
We do not sell personal information. California residents may request access, deletion, or opt-out of sale (not applicable) via our contact page.
15 Do Not Track
Because no universal technical standard for Do-Not-Track (DNT) signals has been adopted, we do not currently alter our data collection practices in response to DNT signals. If a standard is adopted that we are required to comply with, we will update this policy accordingly.
16 Data Breach Notification
POPIA Chapter 6 — Security Compromise Notification
In the event of a security compromise affecting your personal information, Online Synergy CC will notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering the compromise, as required by Section 22 of POPIA. Notification will be provided via the contact details we hold for you and will include the nature of the compromise, categories affected, steps taken, and our Information Officer's contact details.
17 Policy Updates
We review and update this Privacy Policy periodically to reflect changes in law, technology, or our data practices. The "Last updated" date at the top of this page indicates the most recent revision. Your continued use of the site after any revision constitutes acceptance of the updated policy.
Summary of Key Points
- We are Online Synergy CC, the responsible party for your data under POPIA
- We collect name, email, and technical/usage data only — no sensitive personal information
- Your data is used for newsletter delivery, analytics, comment moderation, and site security
- We do not sell your personal information to any third party
- Third-party processors (MailChimp, Google Analytics, Akismet, ClickBank) operate under their own policies
- South African residents have full rights under POPIA including the right to complain to the Information Regulator
- In the event of a data breach, we will notify you and the Information Regulator under POPIA Chapter 6
- You may withdraw consent or unsubscribe at any time with no penalty
18 Contact Us & Complaints
Online Synergy CC (trading as PaleoPower)
Privacy & data subject requests: paleopower.co.za/contact
Registered address:Online Synergy CC
PO Box 838, Sea Point
Cape Town, Western Cape 8060
Republic of South Africa
We aim to respond to all privacy requests within 30 days as required under POPIA. If unsatisfied, escalate to the Information Regulator (see Section 12).