Privacy Notice · POPIA, Act 4 of 2013

How we protect your information.

Opulence is a Responsible Party under the Protection of Personal Information Act, 2013. This notice maps every category of processing we perform to the Act's eight conditions for lawful processing.

At a glance

If you'd rather skim than read fifteen pages.

1 · Who is the Responsible Party?

Opulence (Pty) Ltd ("Opulence", "we", "us") operates this platform and acts as the Responsible Party for the personal information you provide. Opulence Private Client services are delivered as juristic representative of Nisela Fund Managers, an authorised FSP — Nisela operates as a separate Responsible Party for regulated advisory records and you will receive a distinct disclosure from Nisela where applicable.

Information Officer (POPIA §55): Richard Ngwenya · privacy@opulence.luxe.
Deputy Information Officer: Refiloe Celeste Khumalo · dpo@opulence.luxe.

2 · What personal information we process

CategoryExamplesSource
Identity & contactFull name, email, phone, city, member referenceYou · application form
AuthenticationPassword (stored as scrypt hash with per-account salt)You
MembershipTier, billing cadence, next billing date, paid-until dateService operation
Service recordsConcierge requests, travel/event briefs, Petals deliveriesYou · Relationship Manager
MobilityPickup/drop-off, distance, fare, chauffeur, ratings, scheduled timeService operation
StaysReservations, host listings, photographs you upload, guest reviewsYou · hosts
MessagesGuest ↔ host messages (contact details never shared)You · host
FinancialPayment provider reference, amount, status, description, currency — no card numbersPayment provider
BehaviouralTime of requests, frequency, cadence — only if you opt in to profilingService operation
TechnicalIP address, user agent, session token, audit timestampsYour device

We do not collect special personal information (POPIA §26) — health, religion, biometric, race, political opinion — unless you explicitly volunteer it for a specific request (e.g. dietary restrictions for an event) under §27 grounds, and only for that single purpose.

3 · The eight POPIA conditions — how we comply

Condition 1 · Accountability (§8)

A designated Information Officer (§55) sets, reviews and enforces this notice. Material changes are versioned (current version ) and every consent is stamped with the policy version under which it was given.

Condition 2 · Processing limitation (§§9–12)

We only collect personal information that is adequate, relevant and not excessive. Our lawful bases (§11):

Direct collection (§12) — we collect from you. The only exceptions: payment status from your bank/card processor, and ride/stay activity reported by hosts/chauffeurs delivering the service.

Condition 3 · Purpose specification (§§13–14)

Each category in §2 is collected for an explicitly stated purpose. We retain records for as long as the lawful basis applies:

Condition 4 · Further processing limitation (§15)

We will not re-use your information for a new purpose without first re-establishing a lawful basis — typically by asking you to opt in.

Condition 5 · Information quality (§16)

You can review and correct your profile at any time via the Privacy Rights Portal. We act on corrections within 7 business days; access requests within 30 days (POPIA §23).

Condition 6 · Openness (§§17–18)

This notice is our §18 disclosure. A formal Manual under the Promotion of Access to Information Act, 2000 (PAIA), is available from the Information Officer on request.

Condition 7 · Security safeguards (§§19–22)

Our technical and organisational measures (§19):

Condition 8 · Data subject participation (§§23–25)

Your rights, exercisable from the Privacy Rights Portal:

4 · Automated decisions & profiling (§71)

Some service personalisation (recommended trips, room upgrades, cellar suggestions) uses algorithmic models trained on your prior activity — only if you opt in to profiling. Material decisions (whether to accept a booking, grant credit, refund a fare) are never fully automated: a human staff member reviews and decides. This meets POPIA §71 and aligns with GDPR Article 22.

5 · Sharing with third parties

CategoryRecipientPurposeBasis
PaymentStripe / YocoCard processing§11(1)(b) contract
Hosting & storageCloud infrastructure providerApplication hosting§11(1)(b) contract · §21 operator
Regulated FSNisela Fund ManagersWhere you transact under their FSP§11(1)(c) legal obligation
Marketing analyticsNone unless you opt in§11(1)(a) consent only
Curation partnersEstates / galleries / hostsTo fulfil your specific request§11(1)(b) or §11(1)(a)

We never sell your personal information.

6 · Cross-border transfers (§72)

Our diaspora servicing layer (London, Dubai pop-ups; concierge requests routed to overseas partners) may require transferring your information outside South Africa. Where we do, we use one of the §72 grounds:

7 · Children

Opulence services are not offered to children under 18. If a child's information reaches us in error we will delete it on the first business day after we become aware (POPIA §35).

8 · Lodging a complaint

Please first email privacy@opulence.luxe and we will respond within 7 business days. You may also lodge a complaint with the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg · POPIAComplaints@inforegulator.org.za.

9 · Changes to this notice

We will notify you in-app and by email of material changes. The current policy version is , dated June 2026. Prior versions are archived against every member's consent timestamp.