Legal

Privacy Policy

Last updated: 29 June 2026  ·  The Brothers Prim (Pty) Ltd (Reg. 2020/775091/07)

We take your privacy seriously. We do not sell your personal information to third parties. This policy explains exactly what we collect, why, and how you can control it. We comply with the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Who We Are

The Brothers Prim (Pty) Ltd (Registration No. 2020/775091/07), incorporated in the Republic of South Africa, operates the Prismé personality profiling platform. We are the Responsible Party as defined under POPIA.

Information Officer contact: Please use our contact form for all privacy enquiries.

2. What Personal Information We Collect

CategoryWhat We CollectWhy
Account dataEmail address, name, password (hashed)Account creation and authentication
Quiz responsesYour answers to the 5-question personality quizTo generate your personality profile
Subscription dataPlan type, payment status, subscription datesTo manage your subscription
Payment dataProcessed by PayFast — we receive only confirmation, not card detailsTo process subscription payments
Usage dataPages visited, features used, session durationTo improve the Platform
Device dataBrowser type, operating system, IP addressSecurity and fraud prevention

We do not collect sensitive personal information such as racial or ethnic origin, health data, biometric data, criminal records or financial account details beyond what is necessary for payment processing.

Note: While Prismé content references haplogroup and ancestral heritage as a personality framework, we do not collect, process or store actual genetic data. The haplogroup references are used as a cultural and historical categorisation framework only.

3. How We Use Your Information

We process your personal information only for the following lawful purposes:

  • •  To create and manage your account
  • •  To generate and display your personality profile
  • •  To process subscription payments and manage billing
  • •  To send transactional emails (account confirmation, payment receipts)
  • •  To respond to your support requests
  • •  To improve Platform functionality and user experience
  • •  To detect, prevent and investigate security incidents and fraud
  • •  To comply with applicable legal obligations

We will only send marketing communications with your explicit consent and you may unsubscribe at any time.

4. How We Share Your Information

We do not sell, rent or trade your personal information. We share data only with:

Third PartyPurposeTheir Privacy Policy
SupabaseDatabase storage and authenticationsupabase.com/privacy
PayFastPayment processingpayfast.co.za/privacy
VercelPlatform hostingvercel.com/legal/privacy-policy

We may disclose your information to law enforcement or regulatory authorities where required by law, court order or to protect the rights, property or safety of Prismé, its users or the public.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. If you close your account we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, accounting or regulatory compliance purposes (typically up to 5 years for financial records).

6. Security

We implement industry-standard security measures to protect your personal information, including:

  • •  Encryption in transit (HTTPS/TLS) and at rest
  • •  Hashed password storage — we never store your password in plain text
  • •  Role-based access controls on our database
  • •  Row-level security policies in Supabase
  • •  Regular security assessments
  • •  Rate limiting to prevent brute-force attacks

No system is completely secure. In the event of a data breach that is likely to affect your rights and freedoms, we will notify you and the Information Regulator as required by POPIA.

7. International Data Transfers

Your data is stored on Supabase servers in the European Union (Frankfurt region) and served via Vercel's global network. By using Prismé you consent to this transfer. We ensure that appropriate safeguards are in place to protect your data in accordance with POPIA.

8. Your Rights Under POPIA

As a data subject under POPIA, you have the right to:

  • •  Access: Request a copy of the personal information we hold about you
  • •  Correction: Request that we correct inaccurate or incomplete information
  • •  Deletion: Request deletion of your personal information (subject to legal retention requirements)
  • •  Objection: Object to the processing of your personal information
  • •  Restriction: Request that we restrict processing of your information
  • •  Portability: Request your data in a structured, commonly used format
  • •  Complaint: Lodge a complaint with the Information Regulator of South Africa

To exercise any of these rights, please submit your request via our contact form. We will respond within 30 days.

Information Regulator of South Africa: inforegulator.org.za · complaints.IR@justice.gov.za

9. Cookies and Tracking

Prismé uses only essential cookies and local browser storage necessary for authentication and session management. We do not use advertising cookies or third-party tracking technologies. We do not participate in cross-site tracking or behavioural advertising.

10. Children's Privacy

Prismé is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately. If you are between 13 and 18, you must have verifiable parental consent to use the Platform.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or platform notification at least 14 days before the changes take effect. The date at the top of this page indicates when the Policy was last revised.

Information Officer: The Brothers Prim (Pty) Ltd

Contact: Please use our contact form for all privacy-related queries and complaints.

Registration: 2020/775091/07

Jurisdiction: Republic of South Africa