Privacy Policy
Metabolomics South Africa (MSA)
Website: https://metabolomics-sa.co.za
Last updated: 24 February 2026
Metabolomics South Africa (MSA) is committed to protecting your personal information and ensuring that it is processed lawfully, reasonably, and transparently in accordance with the Protection of Personal Information Act, Act 4 of 2013 (POPIA). POPIA sets minimum conditions for lawful processing, requires openness, regulates direct marketing, and outlines rights of data subjects.
Depending on your interactions with our website, we may collect:
1.1 Information you provide directly
- Name, surname, affiliation, institution
- Email address and contact details
- Event registration details, abstract submissions, dietary or accessibility preferences
- Membership details
- Newsletter subscription information (managed via Zoho Campaigns)
1.2 Automatically collected information
- Device and browser information
- General location based on anonymised analytics
- Cookies or similar technologies
- Security information collected by Cloudflare Turnstile or Google reCAPTCHA (used to prevent automated abuse)
Cookies and similar identifiers are personal information when linked to an identifiable individual under POPIA.
1.3 Information processed during payments
If you purchase membership or event tickets, PayFast processes your payment. We do not store your full card details.
PayFast acts as an operator under POPIA and must apply appropriate security safeguards.
- Through forms on our website (events, memberships, abstracts, contact)
- Through Zoho Campaigns when you subscribe or interact with emails
- Automatically through cookies and analytics, with explicit consent for any non‑essential cookies
- Through anti‑spam tools (Turnstile and reCAPTCHA) for security purposes
During payment processing via PayFast
POPIA requires that collection be direct and transparent, with clear notification to the data subject.
We process information for:
- Membership administration
- Event registrations, programme preparation, and communication
- Newsletter and community communications (via Zoho Campaigns)
- Website operation, security, performance, and monitoring
- Analytics (Google Analytics) to understand website performance
- Compliance with legal and record‑keeping requirements
POPIA requires that information be collected for specific, explicitly defined, lawful purposes.
We send emails to subscribers and members through Zoho Campaigns.
- You will only receive marketing emails if you opt in.
- You may unsubscribe at any time.
POPIA regulates electronic direct marketing and requires opt‑in consent for unsolicited marketing.
5.1 Essential Cookies (Always Active)
Required for security and proper website functioning, including:
- Cloudflare Turnstile
- Google reCAPTCHA
These are necessary to prevent automated abuse and maintain system integrity.
5.2 Non‑Essential Cookies (Only with Consent)
Our site uses Google Analytics (GA4) for aggregated analytics and performance insights.
POPIA requires websites to obtain consent before using non‑essential cookies.
GA4 Privacy Details
GA4:
- Does not log or store full IP addresses
- Applies EU‑focused data handling and anonymisation for global privacy alignment
- Allows disabling granular device/location data
You can change your cookie preferences at any time using our site’s cookie settings.
Processing is done on the following POPIA‑aligned bases:
- Consent: analytics cookies, newsletters
- Requested services: membership, event registrations
- Legitimate interests: site security, performance, Turnstile/reCAPTCHA
- Legal obligation: accounting, reporting, and regulatory compliance
These align with POPIA’s processing limitation and purpose specification requirements.
We may share personal information with:
- Passantbyte (hosting provider): website infrastructure
- Zoho (Zoho Campaigns): email communications
- PayFast: payment processing
- Cloudflare Turnstile and Google reCAPTCHA: anti‑spam and security
- Website service providers such as developers or security vendors (acting as operators)
All operators must apply appropriate safeguards under POPIA.
We do not sell your personal information.
Some service providers may process information outside South Africa.
POPIA requires cross‑border transfers to be protected by adequate legal or organisational safeguards.
Note on EU users:
If we intentionally offer services to, or monitor behaviour of, individuals in the EU, GDPR may apply extraterritorially.
We implement reasonable technical and organisational measures, including:
- SSL encryption
- Access controls
- Malware and firewall protection
- Anti‑spam measures
- Server‑level security via Passantbyte
- POPIA‑compliant operator agreements
POPIA requires responsible parties and operators to implement adequate security safeguards.
We only retain personal information for as long as:
- It is required to deliver services
- It is required by law
- There is a legitimate purpose for retaining it
Retention must not exceed what is necessary under POPIA.
You have the right to:
- Request access to your personal information
- Request correction of inaccurate or outdated information
- Request deletion where legally applicable
- Object to processing
- Withdraw consent
- Opt out of direct marketing
- Lodge a complaint
These rights are provided under POPIA’s data subject participation provisions.
Our site is not intended for use by individuals under 18.
POPIA restricts processing of children’s personal information and may require authorisation.
Our website may link to external websites.
Those websites are governed by their own privacy policies. POPIA’s openness requirement mandates such disclosure.
If you have questions or wish to exercise your rights, contact:
Information Officer (Interim):
Email: info(at)metabolomics-sa.co.za
Information Regulator (South Africa):
Website: https://inforegulator.org.za
MSA may update this Privacy Policy from time to time. The latest version will always appear on this page with an updated date.
