Privacy Policy
This policy covers solfalabs.com — this website and nothing else. Any software Solfa Labs releases will carry its own privacy policy, published before anyone can install it. The only personal information this site collects is an email address you type in yourself.
Most privacy policies are long because the service behind them is complicated. This one is long because it is specific: rather than say "we may collect certain information", it names every field, every recipient, every retention period and every legal basis. There is far less to describe than the length suggests, and that is the point.
1Who we are
This site is operated by Solfa Labs, a software company incorporated in the Republic of South Africa and based in Bloemfontein, Free State. Throughout this document "we", "us" and "our" mean Solfa Labs; "you" means the person reading the site or joining the waitlist.
In the language of the Protection of Personal Information Act 4 of 2013 — POPIA — we are the responsible party. We decide what personal information is collected here and why, and we answer for it.
| Item | Detail |
|---|---|
| Operator | Solfa Labs |
| Location | Bloemfontein, Free State, South Africa |
| Privacy contactdata requests, complaints, regulator correspondence | privacy@solfalabs.com |
| General contact | hello@solfalabs.com |
| Support | support@solfalabs.com · Support page |
| Information OfficerPOPIA s 55 | Reachable at privacy@solfalabs.com. Under POPIA the head of a private body is its Information Officer by operation of law; correspondence to that address reaches the person holding the role. |
| Postal address | Provided in writing on request to any data subject or to the Information Regulator. We publish our city rather than a private address; this does not limit your ability to contact us, to serve us, or to complain about us. |
2What this policy covers
The pages you can read on solfalabs.com, the waitlist form, and any email you send us about either.
It does not cover anything you reach by leaving this site. If you follow a link away from solfalabs.com, whatever you find there is governed by that operator's policy, not ours. We have no ability to see what you do once you leave, and no interest in trying.
The site is a set of static pages. It is not an account system, a shop, a forum, or a service you log in to. There is nothing here to sign into and no password to lose.
3The eight conditions we work to
POPIA sets out eight conditions for lawful processing. They are not a checklist we file away; each one has a concrete meaning here, and this is what each one means.
| Condition | What the Act requires | How it applies here |
|---|---|---|
| Accountabilitys 8 | The responsible party must ensure the conditions are met. | One accountable person, named by role in §1 and reachable at a monitored address. There is no queue to be passed along. |
| Processing limitationss 9–12 | Lawful, minimal, and with a proper justification. Collected from the data subject directly. | One field, typed by you, with a tick-box you have to tick. We collect an email address because a mailing list cannot function without one. |
| Purpose specificationss 13–14 | Collected for a specific, explicitly defined, lawful purpose, and not kept longer than necessary. | The purpose is stated on the form itself, repeated in §5, and is the only thing we do with it. Retention periods are in §9. |
| Further processing limitations 15 | Later uses must be compatible with the original purpose. | There are no later uses. We will not repurpose the list for anything you did not agree to, and if we ever wanted to, we would ask rather than reinterpret. |
| Information qualitys 16 | Complete, accurate, not misleading, updated where necessary. | You typed it, so it is as accurate as you made it, and you can correct or remove it at any time — see §12. |
| Opennessss 17–18 | Maintain documentation, and tell the data subject the prescribed things at the point of collection. | This document. §1 gives our identity, §5 the purpose and whether supply is voluntary, §8 the cross-border position, §12 the right to object, §18 the Regulator's details. |
| Security safeguardsss 19–22 | Appropriate, reasonable technical and organisational measures; and notification if they fail. | §10 lists the measures. §11 states what we do if they are breached, and the commitment there is stricter than the Act requires. |
| Data subject participationss 23–25 | The right to know what is held, and to have it corrected or deleted. | §12 and §13. Free, no forms, no fee, and answered within 30 days. |
4Everything we collect
This is the complete inventory. There is no second list.
| What | Exactly which fields | Why | Legal basis | Where it goes |
|---|---|---|---|---|
| Waitlist entry | The email address you type. The date and time you submitted it. A record that you ticked the consent box. Whether you have confirmed by clicking the link we email you. | So we can tell you when the beta opens and when the product is released. | Consent — POPIA s 11(1)(a). Voluntary in the full sense: nothing on this site is withheld if you do not join, and withdrawing is one click. | Kit, our email provider. See §7. |
| Email you send us | Your address, what you wrote, and anything you attach. | To answer you. | Legitimate interests — s 11(1)(f). Answering a message someone chose to send is the least intrusive processing there is. | Our mailbox. |
| Server logs | IP address, timestamp, the path requested, the HTTP status, and the browser's user-agent string. Generated automatically by the web server, as they are by every web server. | Keeping the site up and diagnosing faults and abuse. | Legitimate interests — s 11(1)(f). A server that cannot log cannot be defended or debugged. Balanced against your interests, and available on request. | Our hosting provider. |
That is all of it. We do not ask for or receive your name, your telephone number, your postal address, your date of birth, your employer, your payment details, your location, or anything about your device beyond what your browser announces to every site it visits.
4.1 Special personal information
POPIA s 26 defines special personal information as religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour. We collect none of it and have no field capable of holding it. No processing on this site engages ss 27 to 33, and no authorisation under s 57 is required.
5The waitlist, in detail
The waitlist is the only thing on this site that collects anything, so it deserves its own section rather than a line in a table.
5.1 What happens when you submit the form
- Your browser sends your address and your consent to Kit, our email provider, directly. It does not pass through a Solfa Labs server on the way, because there is no server between you and Kit.
- Kit sends you a single email containing a confirmation link.
- Until you click that link you are not on the list. Your address sits unconfirmed, we do not email you again, and it is deleted automatically if you never confirm.
- If you do click it, you are subscribed, and you will receive occasional email about the product's progress and its release.
This is double opt-in. It is slower than the alternative and it loses us some signups, and we use it anyway: it is the only method that makes it impossible to add someone who did not ask, whether by malice or by typo.
5.2 What we will send you
Infrequent email about this product — progress, an invitation to the beta when it opens, and notice of release. We will not send you unrelated offers, we will not email you about a different product, and we will not pass your address to anyone who will.
5.3 Leaving
Every message has an unsubscribe link. One click, effective immediately, no confirmation step and no attempt to talk you out of it. Unsubscribing removes you from the list rather than silencing you on it. You can also write to privacy@solfalabs.com and ask, and we will do it for you.
5.4 What the consent box means
It has to be ticked, it is never pre-ticked, and the form will not submit without it. Ticking it means you agree to receive the email described in §5.2 and that you accept this policy and the Terms of Use. It means nothing else. It is not a licence to contact you about anything we later find interesting, and it does not survive your withdrawal of it.
6What this website does not do
Stating an absence precisely is more useful than stating a presence vaguely, so:
- No cookies. Not one — not necessary, functional, analytical or otherwise. This is why you were not shown a cookie banner. A banner asking permission for nothing is theatre, and we would rather have nothing to ask about.
- No analytics. No Google Analytics, no Plausible, no Fathom, no self-hosted equivalent. We do not know how many people visit this site beyond what the server log shows, and we have decided we can live with that.
- No tracking pixels, tag managers or advertising scripts of any kind, from anyone.
- No session recording or heatmaps. Nothing watches your cursor.
- No third-party fonts, scripts, frames or embeds. Every asset is served from our own domain, so loading a page does not announce your visit to anyone else.
- No social media buttons. Those are tracking beacons that happen to look like logos.
- No fingerprinting — no canvas, font-enumeration or timing techniques used to identify a browser without storing anything on it.
- No accounts, no passwords, no logins.
- No selling, renting, trading or sharing of anything about you, to anyone, for money or for anything else of value. There is no circumstance in which this changes without this policy changing first.
A "Do Not Track" header or a Global Privacy Control signal has nothing to act on here. We honour both by having nothing for them to switch off.
7Who else sees your address
Two organisations, both acting on our instructions under written terms, both named.
| Recipient | Role | What they receive | Where |
|---|---|---|---|
| KitConvertKit LLC | Operator — processes on our instructions and for no purpose of its own. | Your email address, the date you subscribed, your consent record, and whether you confirmed. Kit also records whether a message was delivered and opened, which is how any mail provider works. | United States |
| Our hosting provider | Operator — serves the files. | Server logs only, as described in §4. No form data reaches the host; the waitlist form posts to Kit directly. | Named on request. We do not publish it, because naming your infrastructure publicly is an invitation. |
Beyond those two, personal information leaves us only if we are legally compelled — a valid court order or a lawful demand from a competent authority. We would tell you before complying unless we were legally barred from doing so. We have never received such a demand.
If Solfa Labs is ever sold or merges with another company, the waitlist may transfer to the acquirer. You would be told before it happened and given the chance to leave first, and the acquirer would be bound by this policy until you had that chance.
8Sending information out of South Africa
Kit is in the United States, so your address leaves the Republic. POPIA s 72 prohibits that unless one of five grounds applies, and we rely on two of them together.
- Section 72(1)(b) — a binding written agreement with Kit that imposes conditions substantially similar to POPIA's, including a term restricting onward transfers. This is the primary ground.
- Section 72(1)(a) — you consent to the transfer. The form tells you before you submit, and this section tells you in full.
Because no special personal information and no child's information is involved, the prior authorisation the Regulator requires under s 57(1)(d) for certain transfers does not arise.
We are honest about the residual point: an email address held in the United States is subject to United States law, including lawful access by its authorities. That is true of every mailing list run on an American provider, which is most of them. The mitigation available to us is to hold as little as possible for as short a time as possible, which is what §4 and §9 describe.
9How long we keep it
POPIA s 14 forbids keeping personal information longer than necessary for the purpose. Concretely:
| Record | Retention | Why that period, and not longer |
|---|---|---|
| Confirmed waitlist entry | Until you unsubscribe, or 24 months after the product's public release, whichever comes first. | A waitlist for something already released is just a mailing list nobody agreed to. It should expire, so it does. |
| Unconfirmed waitlist entry | 30 days, then deleted. | Somebody who never confirmed either changed their mind or never asked in the first place. Either way, keeping the address serves no one. |
| Unsubscribe recordyour address, and the fact that you left | Kept after you leave. | This is the one thing we deliberately do not delete on unsubscribe, because it is what guarantees you are never re-added by a later import. If you would rather it went too, say so and we will erase it — you would then need to unsubscribe again if you were ever re-added. |
| Email you send us | 24 months from the last message in the thread. | Long enough that a follow-up next year has context; short enough that old correspondence does not accumulate for ever. |
| Server logs | 30 days. | Long enough to investigate an outage or an attack. Short enough to be useless for building any picture of a person. |
10Security
POPIA s 19 requires appropriate, reasonable technical and organisational measures against loss, damage and unauthorised access. What we actually do:
- Transport. Every network request this site makes uses HTTPS with TLS 1.2 or better. There is no cleartext endpoint.
- Storage at rest. Files are served from an encrypted store, and Kit encrypts subscriber data at rest.
- The form posts directly to Kit over HTTPS. Your address is never written to a Solfa Labs server, so there is no database of ours to breach.
- There is no database, no admin panel and no login anywhere on this site. Most website breaches are a compromised administrative account or an injection into a data store. Neither exists here.
- Administrative access is restricted to named, authorised personnel and protected by multi-factor authentication.
- The site is static. No server-side code runs when you visit, so there is no application logic to exploit.
- Minimisation is the main control. The strongest security measure on this site is how little it collects. Information we never hold cannot be stolen from us.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If you find a vulnerability, write to privacy@solfalabs.com. We will acknowledge within 72 hours, we will not threaten you, and we will credit you if you would like the credit.
11If something goes wrong
POPIA s 22 requires notification to the Information Regulator and to every affected person as soon as reasonably possible after we become aware of a security compromise. South Africa sets no materiality threshold — every compromise is reportable, however small, and there is no level at which we get to decide it does not matter.
Our commitment, which is stricter than the Act:
- We notify the Information Regulator within 72 hours of becoming aware, on the Regulator's prescribed section 22 form.
- We notify everyone affected within 72 hours, by email, in plain language: what happened, what information was involved, what we have done, and what you should do.
- We do not wait for certainty before telling you. "We are still investigating" is more useful to you than silence.
- We publish a public account within 30 days, unless doing so would help an attacker still at work — in which case we publish as soon as it would not.
12Your rights
Under POPIA you have the following rights in relation to what this site holds. We extend all of them to everyone, wherever you live.
| Right | Source | What it means here |
|---|---|---|
| Be told whether we hold anything about you | s 23(1)(a) | Ask, and we confirm within 30 days whether your address is on the list. |
| Receive a copy | s 23(1)(b) | We send you every field we hold about you. Given §4, this is a short email. |
| Correct it | s 24(1)(a) | A misspelled address is fixed or replaced on request. |
| Have it deleted | s 24(1)(b) | Complete erasure from the list and from Kit. Nothing on this site is subject to a statutory retention period that would override this. |
| Object to processing | s 11(3) | Object to anything we do on legitimate interests — the server logs — and we stop unless we can show compelling lawful grounds. |
| Withdraw consent | s 11(2)(b) | As easy to withdraw as it was to give: the unsubscribe link. Withdrawal does not make what happened before it unlawful. |
| Not be subjected to unsolicited marketing | s 69 | We only email people who asked, and only about the thing they asked about. |
| Not be subject to an automated decision | s 71 | Nothing here makes any decision about you. There is no scoring, ranking, segmenting or profiling of any kind — everyone on the list receives the same message. |
| Complain to the Regulator | s 74 | Details in §18. You do not have to come to us first, though we would like the chance. |
| Civil proceedings | s 99 | Available to you independently of anything the Regulator does or does not do. |
13How to exercise them
Email privacy@solfalabs.com and say what you want. That is the entire procedure.
| Point | Detail |
|---|---|
| Proving who you are | Write from the address in question. That is sufficient — it is the only identifier we hold, so it is the only one we could check against. We will never ask you for a copy of your identity document, which would mean collecting far more sensitive information than the request itself concerns. |
| How long we take | 30 days. POPIA says "a reasonable time"; we have committed to a number so that you can hold us to it. |
| Cost | Free. POPIA permits a prescribed fee for access requests. We waive it. |
| Forms | None required. You may use POPIA Form 2 if you prefer the formal route, and we will treat a plain email exactly the same way. |
| If we refuse | We tell you in writing, give the specific ground, and tell you how to complain. We do not simply stop replying. |
| Fastest route for deletion | The unsubscribe link at the foot of any message we have sent you. It is immediate and needs nothing from us. |
14Email we send you
POPIA s 69 permits electronic direct marketing only with consent, or to an existing customer about similar products, and it allows a company to approach someone who has not consented once only to ask for that consent. We do not make even that single approach: if you have not asked to hear from us, you will not.
Section 45 of the Electronic Communications and Transactions Act 25 of 2002 additionally requires that any unsolicited commercial communication identify its sender and offer a way to opt out. Ours identifies us and carries an unsubscribe link in every message, although nothing we send is unsolicited in the first place.
The Consumer Protection Act 68 of 2008 gives you the right to refuse direct marketing and to register a pre-emptive block. We honour any such block.
15Age
The waitlist is for people aged 18 or over.
POPIA treats anyone under 18 as a child, and s 34 prohibits processing a child's personal information unless a narrow exception in s 35 applies — which for a marketing mailing list would require the verified prior consent of a competent person. We have set the floor at 18 rather than build a consent-verification process around a mailing list, which is the proportionate answer for a service that collects one email address.
If you are under 18, please do not join the waitlist. If we learn that an address belongs to someone under 18, we delete it and tell the person why. If you are a parent or guardian and believe your child has subscribed, write to privacy@solfalabs.com and we will remove it within 7 days.
16If you are not in South Africa
This policy is written to South African law, because that is where we are and that is the law that governs us.
The internet does not respect that boundary. If you live elsewhere, your own country's data protection law may give you rights in addition to the ones described here — the General Data Protection Regulation in the European Union, the UK GDPR, state privacy statutes in the United States, and others. We have not written a separate section for each, because a policy that lists statutes it does not actually operate to is worse than one that says plainly what it will do.
What we commit to, and do:
- We honour the rights in §12 — access, a copy, correction, deletion, objection and withdrawal of consent — for every person who asks, regardless of where they live and regardless of whether any law requires it of us.
- We apply one standard rather than sorting people by residence. Doing otherwise would mean determining where you live in order to decide how much privacy to give you, which is a worse intrusion than the one it would be solving.
- If you believe a right under your own law has not been met, write to privacy@solfalabs.com and say which right and which law. We will engage with it properly rather than sending you a form letter.
17Changes to this policy
- Material changes — a new category of information, a new recipient, a new purpose, or the removal of anything promised in §6 — are announced by email to everyone on the list at least 30 days before they take effect. That is time to read them and to leave if you disagree.
- Corrections and clarifications take effect when published.
- Superseded versions are archived and provided on request, so you can always establish what you actually agreed to and when.
- Staying subscribed after a change takes effect means the new version applies to you. Silence is never treated as agreement to a material change you were not told about.
18Complaints
Please write to privacy@solfalabs.com first. Most complaints are a misunderstanding that can be fixed the same day, and we would rather fix it than read about it from a regulator.
You are not obliged to. You may complain directly to the Information Regulator at any time.
| Authority | How to reach them |
|---|---|
| Information RegulatorSouth Africa | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 POPIAComplaints@inforegulator.org.za 010 023 5200 · toll free 0800 017 160 inforegulator.org.za — complaints are lodged on Form 5. |
| Elsewhere | If you are outside South Africa you may also be able to complain to your own national data protection authority. See §16 for our position on this. |
AAnnex A · Definitions
- Personal information
- Information relating to an identifiable living person — and, uniquely under POPIA, to an identifiable existing juristic person such as a company. Broader than "sensitive": an email address is personal information, and so is an IP address in most circumstances.
- Special personal information
- The categories listed in POPIA s 26, which attract stricter rules. Enumerated in §4.1. We hold none of it.
- Responsible party
- The person or body that determines the purpose and means of processing. Solfa Labs, for this site.
- Operator
- Someone who processes personal information on behalf of a responsible party, under its authority and for no purpose of their own. Kit and our hosting provider.
- Data subject
- The person the information is about. You.
- Processing
- Anything at all done with personal information — collecting, storing, using, transmitting, altering, erasing. Merely holding something and doing nothing with it is still processing.
- Consent
- A voluntary, specific and informed expression of will. A pre-ticked box is not consent. Nor is permission buried in a document nobody was shown.
- Double opt-in
- Requiring a person to confirm by clicking a link in an email before they are added to a list, proving that the address was submitted by the person who controls it. What §5 describes.
- Security compromise
- POPIA's term for what is elsewhere called a data breach: unauthorised access to, or acquisition of, personal information. §11 sets out what we do about one.
- Information Officer
- The person accountable under POPIA for a body's compliance. Under s 55 the head of a private body holds the role automatically. Ours is contactable at the address in §1.
BAnnex B · Where each duty is met
For anyone checking this document against the Act rather than reading it.
| Provision | Requires | Addressed in |
|---|---|---|
| POPIA ss 9–12 | Processing limitation, consent, direct collection | §3, §4, §5 |
| POPIA ss 13–15 | Purpose specification, retention, further processing | §3, §5, §9 |
| POPIA s 16 | Information quality | §3, §12 |
| POPIA s 17 | Documentation | This document |
| POPIA s 18 | Notification to the data subject at collection | §1, §4, §5, §8, §12, §18 |
| POPIA s 19 | Security safeguards | §10 |
| POPIA ss 20–21 | Operator obligations and written contracts | §7 |
| POPIA s 22 | Notification of a security compromise | §11 |
| POPIA ss 23–25 | Access, correction, deletion | §12, §13 |
| POPIA s 26 | Special personal information | §4.1 |
| POPIA ss 34–35 | Children's personal information | §15 |
| POPIA s 55 | Information Officer | §1 |
| POPIA s 69 | Direct marketing by electronic communication | §5, §14 |
| POPIA s 71 | Automated decision making | §12 |
| POPIA s 72 | Transfers outside the Republic | §8 |
| POPIA ss 74, 99 | Complaints and civil remedies | §18 |
| ECTA s 45 | Unsolicited commercial communications | §14 |
| CPA s 11 | Right to refuse direct marketing | §14 |
Contact
Privacy questions, requests and complaints: privacy@solfalabs.com. Anything else: Support.
This policy is a statement of how Solfa Labs handles personal information on this website. It is not legal advice, and nothing in it limits a right you hold under any law that applies to you.