LegalPrivacy Policy (POPIA)
This policy explains how Hitman Academy collects, uses, protects, and retains personal information under South Africa's Protection of Personal Information Act (POPIA).
This page is written so you can understand exactly what to do when you want access, correction, deletion, objection, or another privacy action.
Last updated: 14 April 2026
1. Information We Collect
We collect only what we need to operate the site and respond to you:
- Contact form data: name, email, phone, training goal, message, and optional attachment.
- Review data: first and last name (or anonymous), optional program/role, rating, and review message.
- Technical diagnostics: page route, viewport size, connection type, and web-vitals timing metrics.
- Security events for admin access protection (for example, failed/successful login events).
2. Cookies and Local Storage
- Session and CSRF cookies are used for secure form and admin operations.
- Local storage keeps your theme preference and privacy-banner acknowledgment.
- We do not use third-party ad tracking cookies on this site.
3. Why We Process It and Legal Basis
- To respond to class and contact enquiries.
- To review and publish testimonials where approved.
- To keep the website secure, stable, and performant.
- To meet legal and regulatory obligations where applicable.
We rely on consent where required and legitimate interests for security and core operations.
4. Sharing and Cross-Border Processing
We do not sell personal information. We may share data only with service providers needed for hosting, infrastructure, security, and communication under confidentiality and security controls.
Some providers may process data outside South Africa. Where that applies, we use reasonable contractual and security safeguards aligned with POPIA requirements.
5. Retention
- Contact submissions are retained only as long as needed to manage the enquiry.
- Security and performance logs are retained according to operational settings (currently 7 days by default).
- You can request deletion where retention is no longer legally or operationally required.
6. Security Measures
- Session controls, CSRF protection, and rate limiting are used to reduce abuse.
- Input validation, file-type controls, and server-side checks are applied on submissions.
- Access to sensitive admin functions is restricted and logged.
7. Children and Youth Data
If a learner is a minor, a parent or legal guardian should submit enquiries and requests on their behalf. We may request guardian confirmation before processing certain actions.
8. Your Rights Under POPIA
- Request access to your personal information.
- Request correction or deletion of inaccurate or unnecessary information.
- Object to certain processing.
- Lodge a complaint with the Information Regulator South Africa.
9. How to Submit a Privacy Request
- Go to our Contact page and select "Privacy request (POPIA)" as your goal.
- Include your full name, the email or phone used with us, and an approximate date of interaction.
- State your request clearly: access, correction, deletion, objection, or complaint escalation.
- We may ask for reasonable verification before releasing, changing, or deleting records.
We respond within applicable legal timelines and may extend where permitted by law (for example where the request is complex or we need additional verification).
10. Contact and Regulator
For privacy requests, use our Contact page. If you are unhappy with the outcome, you can lodge a complaint with the Information Regulator (South Africa).
You can also email admin@hitmanacademy.co.za with the subject line "Privacy request (POPIA)".
Information Regulator website: inforegulator.org.za
11. Policy Updates
We may update this policy to reflect legal, operational, or security changes. The latest version is always published on this page with an updated date.