RootCalm logo
    Back to Home

    Data Processing Information

    Last updated: September 20, 2026

    1. About This Document

    RootCalm ("we," "us," or "the Responsible Party") processes personal information on behalf of our users in accordance with applicable data protection laws, including:

    • POPIA - Protection of Personal Information Act 4 of 2013 (South Africa)
    • GDPR - General Data Protection Regulation (European Union)
    • CCPA - California Consumer Privacy Act (United States)

    2. Our Role as Responsible Party

    Under POPIA, RootCalm acts as the Responsible Party (equivalent to "Data Controller" under GDPR) for all personal information collected through our Service. We determine the purposes and means of processing personal information.

    Information Officer:

    Dr. Elizma van der Smit

    Email: support@root-calm.com

    Physical Address: South Africa

    3. Sub-Processors (Third-Party Operators)

    We engage the following third-party service providers ("Operators" under POPIA / "Processors" under GDPR) to process personal information on our behalf. Each sub-processor is bound by data processing agreements requiring them to protect your information.

    Supabase Inc.

    United States (AWS infrastructure)

    Service: Database Hosting & Authentication

    Data Processed: User accounts, assessment data, application data

    Safeguards: SOC 2 Type II certified, GDPR compliant, data encrypted at rest and in transit

    PayFast (Pty) Ltd

    South Africa

    Service: Payment Processing

    Data Processed: Payment information, transaction records, billing details

    Safeguards: PCI-DSS Level 1 certified, POPIA compliant

    Resend Inc.

    United States

    Service: Email Delivery

    Data Processed: Email addresses, email content, delivery metadata

    Safeguards: SOC 2 Type II certified, TLS encryption

    YouTube (Google LLC)

    United States / Global

    Service: Embedded Guided Meditation Videos

    Data Processed: Video playback data (no personal user data sent)

    Safeguards: Google enterprise security standards, privacy-enhanced embed mode

    Sumsub (Sum and Substance Ltd)

    United Kingdom / European Union

    Service: Identity Document & Facial-Liveness Verification (court-mandated programmes only)

    Data Processed: Identity document images, selfie/liveness images, biometric templates derived from them, verification result and audit trail

    Safeguards: ISO 27001 certified, SOC 2 Type II, GDPR compliant, UK/EU data residency, explicit consent required before capture; see Privacy Policy section 6A

    Google LLC (via Lovable AI)

    United States / Global

    Service: AI Analysis Features

    Data Processed: Journal entries, assessment responses (for AI analysis only)

    Safeguards: Enterprise AI data protection, no training on user data

    4. Data Processing Purposes

    We process personal information for the following purposes:

    Service Delivery

    Providing anger assessment, tracking, and management features

    Account Management

    Authentication, user preferences, and subscription management

    Payment Processing

    Processing subscription payments and maintaining billing records

    Communication

    Sending transactional emails, reminders, and progress reports

    AI-Powered Features

    Providing personalized insights, thought reframing, and prevention plans

    Court Compliance

    Tracking program completion and generating compliance certificates

    5. Your Rights

    Under POPIA and GDPR, you have the right to:

    • Access your personal information
    • Correct inaccurate or incomplete information
    • Request deletion of your information
    • Object to certain processing activities
    • Request restriction of processing
    • Data portability (receive your data in a structured format)
    • Withdraw consent at any time
    • Lodge a complaint with the Information Regulator

    To exercise these rights, contact our Information Officer at support@root-calm.com

    6. Security Measures

    We implement appropriate technical and organizational measures to protect personal information:

    Technical Measures

    • TLS/SSL encryption in transit
    • AES-256 encryption at rest
    • Row Level Security (RLS)
    • Regular security audits

    Organizational Measures

    • Access controls and authentication
    • Staff confidentiality agreements
    • Sub-processor vetting
    • Incident response procedures

    7. Changes to Sub-Processors

    We may update our list of sub-processors from time to time. Material changes will be reflected on this page with an updated "Last updated" date. We encourage you to review this page periodically. If you have concerns about a new sub-processor, please contact us.

    8. Contact Information

    For questions about data processing or to exercise your rights:

    Information Officer: Dr. Elizma van der Smit

    Email: support@root-calm.com

    For complaints, you may also contact the Information Regulator of South Africa at inforegulator.org.za

    This Data Processing Information page was last updated on September 20, 2026.