PRIVACY POLICY

How we protect your privacy

Last updated: 3 September 2026 Applies to: dufp.org

This policy explains, in plain terms, what Development United For Progress does with personal information collected through dufp.org. It is written to satisfy the Protection of Personal Information Act 4 of 2013 (POPIA). If anything here is unclear, ask us and we will explain it.

This document has been prepared carefully but it is not legal advice. Please have it reviewed by a qualified adviser in South Africa before publication, and check that the retention periods and the list of processors match what DUFP actually does.

1. Introduction

Development United For Progress (“DUFP”, “we”, “us”) is the organisation responsible for the personal information described in this policy. We work in youth development, digital skills, entrepreneurship and creative problem solving.

Who we are
Development United For Progress
18 Culm Road
Plumstead
Cape Town 7800
South Africa
How to reach us about privacy
z@dufp.org  ·  +27 21 482 3956
Information Officer
Our Information Officer, as required by POPIA, can be reached at the address and email above.

What this policy covers. This policy explains what personal information we collect through the dufp.org website, why we collect it, how long we keep it, who we share it with, and what you can require us to do about it. It applies to this website only. Where we link out to another organisation, that organisation's own policy applies.

Our commitment. We ask for the minimum we need, we tell you why we are asking, and we do not sell personal information. We treat the Protection of Personal Information Act 4 of 2013 (POPIA) as the floor rather than the ceiling.

2. Information We Collect

Information you give us

Contact form
Your name, email address, organisation or business name, telephone number (optional), the area of interest you select, and the content of your message. Your organisation and telephone number are optional and the form works without them.
Newsletter
Your email address, and only if you actively tick the newsletter box. That box is never ticked for you, and leaving it alone has no effect on your enquiry.
Applications and correspondence
If you apply for a programme, a partnership or a role, we process what you choose to send us for that purpose.

Information collected automatically

Our website is served through Cloudflare. For every visitor, Cloudflare processes a limited technical record in order to deliver the site and keep it available: your IP address, the type of request, your browser's user agent string and approximate location derived from the network. This is necessary to serve a page at all and to block attacks. It is not used to build a profile of you.

We do not run analytics or advertising scripts unless you have chosen to allow that category of cookie. Until you do, no analytics or advertising cookie is written and no such script is loaded. See our Cookie Policy for the detail.

What we do not collect We do not ask for payment card details on this website, we do not collect special category or sensitive information through the contact form, and we ask that you do not send it to us that way.

3. How We Use Your Information

  • To read and reply to an enquiry you send us.
  • To provide information, materials or services you have asked for.
  • To assess and process a partnership, membership or programme application.
  • To send newsletters and updates, only where you have opted in, and only until you opt out.
  • To understand which pages are useful and to improve the site, in aggregate, and only where you have allowed analytics cookies.
  • To keep the website secure and available, and to investigate misuse.
  • To meet obligations placed on us by law, including under POPIA.

We do not use your information to make automated decisions that have a legal or similarly significant effect on you, and we do not carry out profiling for marketing purposes.

4. Lawful Basis for Processing

POPIA permits processing only where one of the grounds in section 11 applies. We rely on the following.

Consent (section 11(1)(a))
For newsletters and other direct marketing by electronic means, which section 69 of POPIA requires us to obtain before we write to you. Consent is a positive act, it is recorded with a date and time, and you may withdraw it at any point.
Necessary to conclude or perform a contract (section 11(1)(b))
Where you are enrolling on a programme or entering an agreement with us.
Legal obligation (section 11(1)(c))
Where a statute or a regulator requires us to keep or produce a record.
Legitimate interests (section 11(1)(f))
To reply to an enquiry you have chosen to send us, and to keep the website secure. We have weighed this against your interests and consider a reply to your own message to be what you expect.

Because we also receive enquiries from people in the United Kingdom and the European Economic Area, we apply the equivalent GDPR bases to those visitors: consent for marketing, contract where relevant, and legitimate interests for correspondence and security.

5. Data Storage and Retention

We keep personal information only as long as it is doing the job it was collected for.

Retention periods
WhatHow long we keep it Then what
Contact form enquiry and our reply 24 months from the last message in the thread Deleted from the mailbox and any ticketing record
Newsletter subscription Until you unsubscribe, and reviewed if you have not opened an email from us for 24 months Removed from the list; we keep only a suppression record of the fact that you unsubscribed
Programme, partnership or role application 12 months from the decision, unless you ask us to keep it for future opportunities Deleted
Records we must keep by law The period the relevant law requires Deleted at the end of that period
Consent records for cookies and marketing Retained while the consent is live and for 24 months afterwards, so that we can show what you agreed to Deleted

Where it is stored

Enquiries arrive in our organisational email and are held on our email provider's servers. The website itself is static and stores nothing about you: it is delivered by Cloudflare's content network, and the form submission is processed by a Cloudflare serverless function which passes the message to our email provider and does not retain a copy.

How it is protected

  • The whole site is served over HTTPS with a valid TLS certificate, so anything you type in the form is encrypted in transit.
  • Access to the mailbox is limited to staff who need it, and is protected by multi factor authentication.
  • API credentials for the form are held as encrypted environment secrets and are never present in the website code.
  • We review who has access, and remove access when someone leaves.
  • The form is rate limited and screened for automated abuse.

6. Your Rights

POPIA gives you the following rights over your personal information. You can exercise any of them by writing to us at the address above, at no cost.

Right to be told what we hold, sections 23 and 24
You may ask us to confirm whether we hold information about you and to give you a copy of it. Section 23 requires us to tell you free of charge whether we hold it. A request for the record itself is made under the Promotion of Access to Information Act, and we will send you the form and explain any prescribed fee before anything is charged.
Right to correction or deletion, section 24
You may require us to correct information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained, or to delete it.
Right to object, section 11(3)
Where we rely on legitimate interests, you may object to the processing on reasonable grounds and we will stop unless the law requires otherwise.
Right to withdraw consent, section 11(2)
Where we rely on your consent, you may withdraw it at any time. Withdrawing consent does not affect anything done lawfully before you withdrew it.
Right to stop direct marketing, section 69
You may tell us at any time to stop sending you marketing, and we will.
Right not to be subject to automated decision making, section 71
We do not make decisions about you by automated means.
Right to complain
You may complain to us first, and we would like the chance to put things right. You also have the right to complain directly to the Information Regulator (South Africa) at inforegulator.org.za or complaints.IR@justice.gov.za, and to institute civil proceedings under section 99.

We will respond as soon as reasonably practicable and in any event within 30 days. We may need to confirm who you are before we act, so that we do not disclose your information to someone else.

7. Cookies

A cookie is a small text file that a website asks your browser to store and send back on later visits. Similar technologies, such as local storage and pixels, do the same job and we treat them the same way.

We ask for your agreement before setting any non essential cookie, in line with POPIA and the Electronic Communications and Transactions Act. When you first arrive you are asked to choose, with “Reject all” given the same prominence as “Accept all”. Until you choose, only strictly necessary cookies exist, and no analytics or advertising script is loaded at all.

You can change or withdraw your choice at any time using the control, which also sits in the footer of every page.

The full list of cookies, what each one does and how long it lasts, is in our Cookie Policy.

8. Third Party Services

We keep the number of third parties as small as we can. These are the ones involved in running dufp.org today.

Processors and service providers
ServiceWhat it does for us Their privacy information
Cloudflare, Inc. Hosts and delivers the website, provides the TLS certificate, filters malicious traffic, and runs the serverless function that processes the contact form cloudflare.com/privacypolicy
Resend, operated by Plus Five Five, Inc. Delivers the message from the contact form to our mailbox privacy policy at resend.com
Our mailbox provider Holds the correspondence once it has arrived Named on request. Change this row to name the provider you actually use.
Not currently in use We do not presently run Google Analytics, Google AdSense or any other advertising network on this site. If we add one, we will update this policy and the Cookie Policy before it goes live, and it will be placed behind the consent choice described above rather than switched on silently.

International transfers

Cloudflare and our email provider process data on servers outside South Africa. Section 72 of POPIA permits this where the recipient is subject to a law or binding agreement that provides an adequate level of protection, and our agreements with these providers include the required contractual protections.

9. Data Security

No website can promise perfect security, and we will not pretend otherwise. What we can tell you is exactly what we do.

  • Encryption in transit. The entire site is served over HTTPS using TLS. Requests over plain HTTP are redirected. Strict Transport Security is enabled so that your browser refuses to downgrade.
  • No database on the website. The site is static. There is no login, no user account and no visitor database to breach.
  • Secrets kept out of the code. The credential used to send your message is stored as an encrypted environment secret in Cloudflare and is never present in anything sent to your browser.
  • Access control. Mailbox and hosting access is limited to the people who need it, protected by multi factor authentication, and reviewed periodically.
  • Abuse controls. The contact form is rate limited, carries a hidden field that automated submissions tend to fill in, and rejects submissions that fail validation.
  • Input handling. Everything you submit is treated as untrusted text. It is validated, length limited and escaped before it is placed in an email, so that a submission cannot be used to forge mail headers or inject content.

If something goes wrong

If a breach compromises your personal information we will notify the Information Regulator and you as soon as reasonably possible after discovering it, as section 22 of POPIA requires, unless a public body directs us to delay in order to protect a criminal investigation.

10. Children's Privacy

Under POPIA a child is a person under 18 who is not legally competent to act without assistance. We do not knowingly collect personal information from a child without the consent of a competent person.

Our programmes may be aimed at young people, but this website is written for the adults who support them: parents, guardians, teachers, mentors and partner organisations. Where a programme involves anyone under 18, enrolment is handled offline through a parent, guardian or school rather than through this website, and consent is obtained in that process.

If you believe a child has given us personal information through this website, please contact us at z@dufp.org and we will delete it.

11. Changes to This Policy

We review this policy at least once a year, and whenever we change what we collect or add a new service provider.

  • The date at the top of this page always shows when it was last changed.
  • If a change materially affects your rights or what we do with your information, we will say so prominently on the website, and we will email anyone who has opted in to hear from us.
  • If a change means we need consent we did not previously have, we will ask again rather than assume. Adding a new cookie category resets the consent banner for everyone.
  • We keep previous versions and will send you an earlier one on request, so that you can see what changed.

12. Contact Us

For anything in this policy, or to exercise any of your rights, contact us and we will help.

Post
Development United For Progress
18 Culm Road
Plumstead
Cape Town 7800
South Africa
Email
z@dufp.org
Telephone
+27 21 482 3956
Supervisory authority
the Information Regulator (South Africa)  ·  inforegulator.org.za

You are also welcome to use our contact form, though please do not put sensitive information in it.