18+

Age Verification

You must be 18 years or older to access this website. Please confirm your age to continue.

Privacy Policy & GDPR

How we collect, use, and protect your personal information when you visit the Helderberg Hospice Draw website.

Last Updated: 27 March 2026

1. Introduction

Welcome to the Helderberg Hospice June Mega 2026 Draw informational website ("the Website"). We are committed to protecting your privacy and ensuring your personal data is handled securely and transparently, in accordance with all applicable data protection legislation.

This Privacy Policy & Data Protection Policy explains what personal information we collect when you visit our Website, how we use it, the legal bases for processing, and your rights. This policy is aligned with the requirements of the following legislation:

  • Protection of Personal Information Act (POPIA) — South Africa
  • Promotion of Access to Information Act (PAIA) — South Africa
  • Electronic Communications and Transactions Act (ECT Act) — South Africa
  • Cybercrimes Act — South Africa
  • General Data Protection Regulation (GDPR) — European Union

By using this Website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of the Website immediately.

2. Responsible Party / Data Controller

The responsible party (as defined under POPIA) and data controller (as defined under GDPR) for the processing of your personal data through this Website is:

  • Website: Helderberg Hospice Draw Info
  • Email: [email protected]
  • Location: Helderberg, Western Cape, South Africa

This Website is an independent informational resource. The official Helderberg Hospice is a separate entity. For questions about data processed directly by Helderberg Hospice (e.g., draw entries, donations), please contact them at [email protected].

3. Important Disclaimer

This Website does not process draw entries, collect payment information, or handle donations. All draw entries and financial transactions are conducted exclusively through the official Helderberg Hospice website, which processes credit card transactions in South African Rand (ZAR) through PCI DSS Level 1 certified payment processors.

Any personal information you provide when entering the draw or making a donation is governed by Helderberg Hospice's own privacy and data protection policies, not this policy.

4. Personal Information We Collect

"Personal information" means any information that identifies or can be used to identify a living, identifiable natural person (as defined under POPIA Section 1 and GDPR Article 4). We collect the minimum amount of data necessary to operate and improve this Website:

Data Category Specific Data Purpose Retention
Technical Data IP address, browser type and version, operating system, device type, screen resolution, referring URL Website functionality, security monitoring, analytics 26 months
Usage Data Pages visited, time on page, click interactions, scroll depth, navigation paths Website improvement, content optimisation, user experience analysis 26 months
Cookie Data Cookie consent preference, age verification status, session identifiers Remembering your preferences, maintaining session state, legal compliance 12 months
Communication Data Email address, name, message content (only if you contact us directly) Responding to enquiries, providing support 24 months after last contact
Analytics Data Anonymised and aggregated browsing statistics via Google Analytics Understanding audience demographics, measuring Website performance 26 months

We do not collect: financial or banking details, identity documents, medical information, donor records, or any sensitive personal information as defined under POPIA Section 26.

5. Consent

In accordance with POPIA Section 11 and GDPR Article 6(1)(a), we obtain your consent before processing personal information where required. Our consent practices include:

  • Positive opt-in: No pre-ticked boxes. You must actively consent to non-essential cookies via our cookie banner.
  • Specific and granular: Consent requests are separate from terms and conditions. Different types of processing require separate consent.
  • Easy withdrawal: You may withdraw consent at any time by clearing your browser cookies, using our cookie banner, or contacting us directly. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Evidence retention: We retain records of who consented, when, how, and what was communicated at the time of consent.
  • Regular review: We periodically review and refresh consent where appropriate.

6. Legal Basis for Processing

6.1 Under POPIA

We process personal information in accordance with the conditions for lawful processing set out in POPIA Chapter 3, including:

  • Consent (Section 11(1)(a)): For non-essential cookies and voluntary communications
  • Legitimate interest (Section 11(1)(f)): For essential Website functionality, security, and age verification
  • Legal obligation (Section 11(1)(c)): To comply with applicable laws, including age restriction requirements

6.2 Under GDPR

For visitors from the EEA and UK, we rely on:

  • Consent (Article 6(1)(a)): For analytics cookies and voluntary data submissions
  • Legitimate interest (Article 6(1)(f)): For essential technical data, security, and Website improvement

We have conducted a legitimate interest assessment and determined that these processing activities are proportionate and do not override your fundamental rights and freedoms.

7. How We Use Your Data

We use the data we collect for the following lawful purposes:

  • Website Operation: To deliver and maintain the Website, ensure it displays correctly, and provide a functional user experience
  • Analytics and Improvement: To analyse how visitors use the Website, identify popular content, detect errors, and improve layout, performance, and content
  • Security: To detect and prevent fraudulent activity, abuse, or security threats
  • Legal Compliance: To comply with applicable laws, including age verification requirements
  • Communication: To respond to enquiries if you contact us directly

We will never sell your personal data to third parties. We do not use your data for automated decision-making or profiling.

8. Data Sharing and Third Parties

We may share your data with the following categories of third-party service providers, solely for the purposes described in this policy:

8.1 Hosting Provider

Our Website is hosted by a third-party hosting provider. This provider processes technical data (such as IP addresses and server logs) as part of delivering the Website to your browser. The hosting provider acts as an operator/data processor under our instructions and is bound by appropriate data processing agreements.

8.2 Google Analytics

We use Google Analytics to understand how visitors interact with our Website. Google Analytics collects anonymised usage data using cookies. You can opt out by:

We do not share your personal data with any other third parties for marketing or commercial purposes.

9. Data Storage and Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:

  • Encryption: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) / HTTPS
  • Access Controls: Access to personal data is restricted to authorised personnel only, on a need-to-know basis with strong password protocols
  • Security Headers: We implement HTTP security headers (X-Content-Type-Options, X-Frame-Options, referrer policies) to mitigate common web vulnerabilities
  • Firewalls and Antivirus: Servers and systems are protected with approved security software and firewalls
  • Backups: Regular automated backups are performed with tested recovery procedures
  • Data Minimisation: We collect only the minimum personal data necessary for the stated purposes
  • Secure Deletion: Personal data that is no longer needed is securely deleted or anonymised

While we take every reasonable precaution, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our specific retention periods are:

  • Technical and usage data: 26 months from the date of collection
  • Cookie preferences: 12 months from the date of consent or last update
  • Communication data: 24 months from the date of your last communication with us
  • Analytics data: 26 months (as configured in Google Analytics)
  • Server logs: 90 days

After the applicable retention period expires, personal data is securely deleted or anonymised so that it can no longer be linked to you.

11. Your Rights

Depending on your location, you have the following rights regarding your personal data:

11.1 Under POPIA (South Africa)

  • Right to be notified (Section 18): You have the right to be informed about what personal information we collect and why
  • Right of access (Section 23): You may request a copy of your personal information we hold
  • Right to correction (Section 24): You may request correction of inaccurate or incomplete information
  • Right to deletion (Section 24): You may request deletion of your personal information in certain circumstances
  • Right to object (Section 11(3)): You may object to the processing of your personal information for direct marketing or on reasonable grounds
  • Right to lodge a complaint: You may lodge a complaint with the Information Regulator

11.2 Under GDPR (EEA/UK)

  • Right of Access (Article 15)
  • Right to Rectification (Article 16)
  • Right to Erasure / Right to be Forgotten (Article 17)
  • Right to Restriction of Processing (Article 18)
  • Right to Data Portability (Article 20)
  • Right to Object (Article 21)
  • Right to Withdraw Consent
  • Right to Lodge a Complaint with a supervisory authority

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. We may ask you to verify your identity before processing your request.

12. Children's Privacy (18+)

This Website and the Helderberg Hospice June Mega 2026 Draw are strictly intended for individuals aged 18 years and older. We do not knowingly collect personal data from anyone under 18.

We implement an age verification gate that requires all visitors to confirm they are 18 or older before accessing content. If we become aware that we have collected personal data from a person under 18, we will take immediate steps to delete that data.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected].

13. International Data Transfers

Our Website primarily operates from South Africa. Some third-party service providers (such as Google Analytics) may process your data in countries outside South Africa or the EEA. Where personal data is transferred internationally, we ensure appropriate safeguards are in place:

  • Transfers to countries with an adequate level of data protection as recognised by the European Commission
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Compliance with POPIA Section 72 conditions for cross-border transfers from South Africa

14. Non-Compliance and Penalties

We take our obligations under POPIA and GDPR seriously. Under South African law, offences under POPIA — such as hindering the Information Regulator, failing to protect personal information, or unlawful processing — can result in fines or imprisonment of up to 10 years. Under GDPR, organisations face fines of up to 4% of annual global turnover or €20 million.

We maintain strict internal policies to ensure compliance and prevent data breaches.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • The "Last Updated" date at the top of this page will be revised
  • Material changes will be communicated through a notice on the Website
  • Where required by law, we will seek your consent before applying changes

16. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

For complaints regarding data protection, you may also contact:

For questions about data processed by Helderberg Hospice directly (draw entries, donations, patient information), please contact Helderberg Hospice at [email protected].

Responsible Participation

Participation in draws and lotteries should be enjoyable and responsible. Only enter with money you can afford. If you or someone you know has a gambling problem, please seek help. You must be 18 years or older to enter.