South Dune

Simplified Member Management & Billing

Privacy Policy

Effective date: 1 September 2026

Policy version: 1.0

1. Who this policy covers

This policy explains how South Dune (“South Dune”, “we”, “us” or “the Platform”), a software platform developed, owned and operated by Pitonix Digital Pty Ltd, a company incorporated in South Africa, collects and uses personal information when you use the South Dune software as a staff user, administrator or owner of an organization (such as a gym, studio, school or club) that uses our platform.

This policy does not cover the members (participants) that organizations manage inside the Platform — including any minors. Each organization using South Dune is the Responsible Party (data controller) for the personal information of its own members, and is required to provide its members' guardians with its own privacy notice. We provide a template for this — see the Guardian Privacy Notice Template — but the organization is responsible for adapting, publishing, and honouring it. South Dune acts as an Operator (data processor) on the organization's behalf for that data: we host it, secure it, and act on the organization's instructions, but we are not the party a parent should contact about their child's record — the organization is.

2. Information we collect about you

When you create a staff/owner account, we collect: name, email address, phone number (optional), password (hashed, never stored in plain text), and your role within your organization. If you use passkey or two-factor authentication, we store the associated credential metadata, not biometric data itself. We also process technical data automatically — IP address, browser type, and session/authentication cookies (see our Cookie Policy).

3. Why we process this information

  • To create and secure your account, and authenticate you (contract necessity).
  • To operate the scheduling, membership, and billing features you use (contract necessity).
  • To send you service emails — email confirmation, password reset, two-factor codes, organization invitations (contract necessity / legitimate interest).
  • To maintain security logs and prevent abuse (legitimate interest).

We do not sell your personal information, and we do not use it for third-party advertising.

4. Who we share it with

  • Sub-processors such as our email delivery provider and our hosting/database provider, who process personal information on our behalf. We require appropriate contractual and security safeguards from our service providers.
  • Other authorized users within your organization, according to the role-based access controls built into the Platform (Owner/Admin/Instructor/Accountant).
  • Law enforcement or regulators, where disclosure is required or permitted by law.

We do not otherwise disclose your personal information to third parties except where necessary to provide, secure, maintain, or improve the Platform, or where required or permitted by law.

5. Where your data is stored

Data is primarily stored with our hosting and database providers in South Africa. Some of our service providers or sub-processors may process personal information outside South Africa.

Where personal information is transferred outside South Africa, we will ensure that the transfer is made in accordance with applicable data protection laws, including POPIA. This may include relying on an applicable law or binding agreement that provides an adequate level of protection, obtaining consent where appropriate, or relying on another lawful basis permitted by applicable law.

We take reasonable steps to ensure that any third party processing personal information on our behalf maintains appropriate safeguards for the security and confidentiality of that information.

6. How long we keep it

Staff and administrator account information is retained for as long as the account remains active or as reasonably necessary to provide and secure the Platform.

For organizations that manage members and account holders through the Platform, member and account-holder records may be marked as inactive when they are no longer actively using the relevant services. If a member or account holder remains inactive for 24 months, we will remove their personal profile information from the Platform.

Information contained in financial records, including billing and ledger records, may be retained after a member or account holder is removed where reasonably necessary for accounting, reconciliation, audit, dispute resolution, fraud prevention, legal, or regulatory purposes. Where appropriate, personal information in these financial records will be anonymized so that the financial record can be retained without unnecessarily retaining identifiable personal information.

Security and audit logs may be retained for up to 12 months, unless a longer period is reasonably necessary for security investigations, fraud prevention, legal compliance, or the establishment, exercise, or defence of legal claims.

Where an organization's account is no longer active, we may retain certain information for as long as reasonably necessary to comply with legal, accounting, tax, regulatory, fraud-prevention, dispute-resolution, or other lawful obligations. We will delete or anonymize information when it is no longer reasonably required for these purposes.

7. Your rights

Subject to applicable law, including the Protection of Personal Information Act (POPIA) where applicable, you may have the right to:

  • request access to the personal information we hold about you;
  • request correction or updating of inaccurate or incomplete personal information;
  • request deletion or removal of your personal information where we are legally permitted to do so;
  • object to certain processing of your personal information where applicable;
  • request a copy of your personal information in a reasonably usable or portable format, where applicable; and
  • withdraw consent where processing is based on your consent, subject to any legal or contractual consequences of doing so.

Some requests may be subject to legal, regulatory, security, financial, or other lawful limitations. For example, we may need to retain certain information to comply with legal obligations, maintain financial records, prevent fraud, resolve disputes, or establish, exercise, or defend legal claims.

To exercise your rights or make a privacy-related request, contact support@southdune.com. We may need to verify your identity before processing your request.

We will respond to requests within the period required by applicable law and will provide an explanation where we are unable to fulfil a request, in whole or in part.

You also have the right to lodge a complaint with the Information Regulator of South Africa or, where applicable, another relevant supervisory or regulatory authority.

8. Security

We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure.

These measures include encrypted transport (HTTPS), hashed credentials, role-based access controls, tenant-level data isolation, secure session and cookie handling, and encryption of sensitive fields within the Platform where appropriate.

The Platform is designed as a multi-tenant system. Personal information is associated with the relevant organization, and access to organization data is restricted through organization-level authorization and data-access controls.

We also maintain audit records for certain administrative and financial activities to help detect and investigate unauthorized changes, misuse, or other security incidents.

No system is completely secure. If we become aware of a security compromise involving personal information, we will take appropriate steps to contain and investigate the incident and provide notifications where required by applicable law.

9. Children

This policy is written for adult staff/administrator account holders. South Dune's staff accounts are not intended for use by anyone under 18. If your organization manages information about minors as members (participants), that processing is governed by your organization's own guardian-facing privacy notice, not this document.

10. Changes to this policy

We will post the updated policy here with a new effective date and version number, and notify account holders of material changes by email.

11. Contact us

© 2026 Pitonix Digital. All rights reserved.

Connection Interrupted

Your current session is still open. We'll keep trying to restore it.

Rejoining the server...

Rejoin failed. Trying again in s.

Failed to rejoin. Retry now or reload the page.

The session has been paused by the server.

Failed to resume the session. Retry now or reload the page.