1. Who We Are
Prepped Exams Pty (Ltd) is a South African private company with registration number 2026/158241/07. We operate the Prepped Exams platform, including preppedexams.co.za, tenant subdomains, and related product pages that link to this policy.
This policy is intended to support compliance with the Protection of Personal Information Act, 2013 (POPIA), read together with other applicable South African laws.
2. Scope
This policy applies to personal information processed through the Prepped Exams platform, including the website you are currently visiting at hs.preppedexams.co.za, our account registration and login flows, subscription purchasing flows, exam and practice features, analytics features, teacher, tutor, or trainer linking features, creator workflows, and communications with us.
It applies to students, parents or sponsors, teachers, tutors, trainers, creators, applicants, and other individuals who interact with our services.
3. Personal Information We Collect
Account and profile information
- First name, last name, email address, password hash, tenant or site association, and account status information.
- Optional profile details such as institution name, phone number, and current academic level where provided.
- Role and permission data, such as student, teacher, sponsor, creator, or content-review permissions.
Subscription and payment information
- Subscription package, subjects purchased, duration, start and expiry dates, and whether access is active.
- Payment reference numbers, payment amount, payment method, fee amounts, discount code usage, sponsor purchase data, and related transaction status information.
- Basic purchaser details used in the payment process, such as name and email address.
Learning, exam, and analytics information
- Exam sessions, answers, progress, timing, question order snapshots, scores, completion data, and related academic performance records.
- Derived analytics such as strengths, weak areas, topic progress, average time spent, and other learning insights.
- Teacher, tutor, trainer, sponsor, and linked-user relationship data where those features are used.
Creator and business relationship information
- Creator application information, creator tier or revenue-share information, referral information, and where relevant, bank or payout details supplied by creators.
- Content moderation, review, and audit trail information relating to creator-submitted material.
Technical and security information
- Session identifiers, CSRF tokens, browser and device-related signals, and hashed device identifiers used for account and session security.
- Login, security, and operational logs, including failed access attempts and similar security events.
- Limited browser-side storage or session storage entries used for convenience features or workflow state in parts of the platform.
Communications
- Emails, support requests, complaints, feedback, and records of communications with us.
We do not intentionally ask users to provide special personal information unless it becomes genuinely necessary for a lawful purpose and we are permitted to process it. Please do not send unnecessary sensitive information to us.
4. How We Use Personal Information
- To create and manage accounts, authenticate users, secure access, and operate tenant-specific platform experiences.
- To provide purchased subscriptions, exam practice, results, analytics, teacher, tutor, or trainer links, and creator features.
- To process and reconcile payments, sponsorships, discount codes, and subscription entitlement changes.
- To keep exam progress resilient across refreshes, disconnections, and load-shedding-related interruptions.
- To measure learning progress, generate feedback, and improve content quality and user experience.
- To detect misuse, fraud, account sharing, suspicious activity, abuse of refunds, or other harmful conduct.
- To communicate about the service, account actions, billing, security, support, or operational updates.
- To meet legal, regulatory, contractual, tax, audit, and governance obligations.
5. Our POPIA Grounds for Processing
Depending on the circumstances, we may process personal information because:
- it is necessary to conclude or perform a contract with you, such as providing platform access after you sign up or pay;
- it is necessary to comply with legal obligations, including accounting, tax, consumer, audit, and access-to-information obligations;
- it is necessary for our legitimate interests or those of users, provided those interests are not overridden by your rights, such as fraud prevention, platform security, product administration, and analytics;
- you have given consent, where consent is the appropriate lawful basis; and
- another lawful justification under POPIA applies.
6. Cookies and Similar Technologies
The platform uses cookies and similar technologies that are needed for core site and security functions. These include session cookies, CSRF protection cookies, authentication-related cookies, and similar mechanisms used to keep you logged in securely and protect forms from abuse.
We may also use limited browser storage features for workflow preferences or session continuity in certain parts of the platform. At launch, we do not intend to rely on advertising cookies, and if we later introduce non-essential analytics or marketing technologies we may update this policy and any consent flows as needed.
7. When We Share Personal Information
We may share personal information only where reasonably necessary and lawful, including with:
- our payment processor, including PayFast, to process and verify payments and related transaction events;
- hosting, infrastructure, cloud storage, email delivery, observability, security, and support service providers acting on our instructions;
- teachers, tutors, trainers, sponsors, or linked accounts where the platform feature you use is designed to share relevant learning or relationship information;
- professional advisers such as accountants, auditors, legal advisers, or insurers where required;
- regulators, courts, law-enforcement bodies, or other authorities where we are legally required or lawfully permitted to do so;
- successors, buyers, or restructuring parties in connection with a merger, sale, financing, or business reorganisation, subject to lawful safeguards.
We do not sell personal information as a business model.
8. Cross-Border Processing
While Prepped Exams is based in South Africa, some of our technology operators may use infrastructure or support arrangements that involve processing or storing personal information outside South Africa. Where this happens, we will take reasonable steps to ensure that the transfer is lawful under POPIA and that appropriate safeguards are in place.
9. Retention
We keep personal information for as long as it is reasonably necessary for the purpose for which it was collected, including to provide the service, preserve account and learning history, administer subscriptions, maintain audit trails, handle disputes, enforce terms, and comply with law.
Some categories of information, such as purchase records, platform usage history, and academic progress records, may be retained for extended periods where operationally justified or legally required. When information is no longer reasonably needed, we may delete it, de-identify it, or archive it securely.
10. Security
We use reasonable technical and organisational measures designed to protect personal information. These may include secure transport over HTTPS, access controls, password hashing, tenant scoping, session protections, fraud and abuse controls, logging, rate limiting, and monitoring of application errors and security events.
No system can promise absolute security. You are responsible for keeping your login credentials confidential and for contacting us promptly if you believe your account or information has been compromised.
11. Children and School-Age Users
Our platform is designed to support learners, including Grade 12 students, and may also be used in adult education or professional contexts through different tenants. Where a user is a child under applicable law, use of the platform should happen with the involvement, authority, or consent of a parent, guardian, school, or other competent person where required by law.
If you believe a child has provided information to us in a way that is not authorised, please contact us at legal@preppedexams.co.za.
12. Your Rights
Subject to POPIA, PAIA, and other applicable law, you may have rights to:
- request access to personal information we hold about you;
- request correction, updating, or deletion of inaccurate or unlawfully processed information;
- object to certain processing or request restriction where the law allows;
- withdraw consent where processing depends on consent, without affecting earlier lawful processing; and
- lodge a complaint with the Information Regulator.
Requests can be sent to legal@preppedexams.co.za. We may need to verify your identity before acting on a request.
13. Direct Marketing
We may use contact details to send service-related communications that are necessary to operate your account or subscription. We may also send limited product or launch communications where permitted by law. Where marketing consent is required, we will seek it, and you can opt out of non-essential marketing messages.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the platform, the law, or our processing practices. The updated version will be published on the website with a revised effective date. Continued use of the platform after an update will be subject to the updated policy to the extent permitted by law.
15. Contact and Complaints
If you have a privacy question, access request, correction request, or complaint, contact us at legal@preppedexams.co.za.
If you are not satisfied, you may also approach the Information Regulator (South Africa) using the contact details and complaint channels published on its official website.