Last updated: September 2026
1. INTRODUCTION
This Privacy Policy and POPIA Notice explains how Jacques de Villiers, trading as Mostly Responsible(ish) (“Mostly Responsible(ish)”, “we”, “us” or “our”), collects, uses, stores, shares and protects personal information.
We are committed to processing personal information lawfully, reasonably and securely in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and other applicable South African law.
This Policy applies to personal information processed through our website, communications, forms, comments, community features and related Mostly Responsible(ish) services.
This includes Mostly SOS(ish) / A Mostly Ear (“SOS”) and information received through its forms, messages, email correspondence and any follow-up communications. SOS is a listening, informal support and signposting feature, not a healthcare, counselling, crisis or emergency service.
2. RESPONSIBLE PARTY
For purposes of POPIA, the responsible party is:
Jacques de Villiers trading as Mostly Responsible(ish)
Gordon’s Bay, Western Cape, South Africa
Website: responsible-ish.co.za
Privacy and legal enquiries: admin@responsible-ish.co.za
These details will be updated if the legal structure of Mostly Responsible(ish) changes.
3. PERSONAL INFORMATION WE MAY COLLECT
Depending on how you interact with Mostly Responsible(ish), we may collect:
- your name and email address;
- information submitted through contact forms;
- comments and information you choose to publish or submit through community features;
- communication, subscription and email preferences;
- information voluntarily submitted through Confessions or similar features;
- correspondence between you and Mostly Responsible(ish);
- technical information relating to your use of our website, which may include your IP address, browser, device and website activity information;
- information reasonably necessary to administer a Mostly Responsible(ish) account or community membership where applicable; and
- other personal information that you voluntarily provide to us.
SOS information may include your chosen name, contact details, message, our replies, referral preferences and any health or mental-health information you voluntarily disclose, such as symptoms, diagnoses, treatment, distress or thoughts of self-harm. Health information is special personal information under section 26 of POPIA and is subject to the additional protections described in section 6A. Other special personal information volunteered in a message receives the applicable additional protection too.
We will not intentionally collect personal information that is unnecessary or excessive for the purpose for which it is requested.
4. HOW WE COLLECT PERSONAL INFORMATION
We generally collect personal information directly from you when you:
- contact or communicate with us;
- complete a form;
- submit a comment, story or Confession;
- join or participate in the Mostly Responsible(ish) community;
- subscribe to communications;
- manage your communication preferences; or
- otherwise provide information to us.
This includes contacting SOS and responding to an SOS follow-up. We do not routinely obtain medical records or contact your healthcare professional to collect information about you.
Certain technical information may also be collected automatically when you use our website.
Where permitted by law, we may receive information from service providers acting on our behalf or from information that you have deliberately made public.
5. VOLUNTARY AND REQUIRED INFORMATION
Providing personal information to Mostly Responsible(ish) is generally voluntary.
However, certain information may be required where it is necessary to provide a service or feature that you request. For example, we need a usable email address if you ask us to send information to you or if an email address is necessary to administer a particular account or service.
If you choose not to provide information that is reasonably necessary for a requested service or feature, we may be unable to provide that service or feature.
Where the provision of information is required by law, we will process that information as permitted or required by applicable law.
6. INFORMATION YOU VOLUNTARILY SHARE
Some Mostly Responsible(ish) features may allow you to share personal experiences, stories, comments or other information.
Please consider carefully what personal information you provide, particularly where the information is sensitive or relates to another person.
Information submitted privately will not be made public merely because it was submitted to Mostly Responsible(ish).
Where a feature is intended to publish information publicly, we will take reasonable steps to make that clear before submission.
6A. SOS SUBMISSIONS AND SPECIAL PERSONAL INFORMATION
Purpose and minimum information
We use SOS information only as reasonably necessary to receive and read your request, provide informal support or general signposting, correspond with you, arrange a referral you request, manage any lawful safety response, and keep limited records needed for those purposes or legal obligations. We do not use SOS health information for advertising, marketing profiles or unrelated commercial purposes.
Sharing health or mental-health details is voluntary. You may ask for general signposting without providing a diagnosis, medical records or a detailed personal history. Please share only what is needed for your request and avoid identifying other people unnecessarily. A message sent privately to SOS is not information deliberately made public by you.
Lawful processing and consent
POPIA generally prohibits processing special personal information unless an authorisation under sections 27 to 33 applies. For ordinary SOS support involving your health or mental-health information, we rely on your voluntary, specific and informed consent under section 27(1)(a), together with compliance with POPIA’s general processing conditions. We will request and record a clear affirmative indication of that consent for the stated SOS purposes. Reading this Policy, accepting the Terms, remaining silent or simply using the website does not itself give that consent.
Where sensitive information arrives without sufficiently clear consent, we will limit handling to what is lawfully necessary to address receipt, seek consent or securely remove the information. We will not continue ordinary support processing of that information without a valid basis. Any processing without consent must have a separate applicable authorisation, such as processing necessary to establish, exercise or defend a right or obligation in law under section 27(1)(b). A general legitimate interest alone does not override the prohibition on processing special personal information. We do not assume that the authorisation for medical professionals or healthcare institutions applies to SOS.
Consent is specific to the purpose explained to you. Consent to an SOS conversation is separate from consent to marketing, publication or disclosure to an independent professional for a referral. We will obtain any additional consent or other lawful authority needed for a new purpose.
You may decline consent or withdraw it at any time by emailing admin@responsible-ish.co.za. Withdrawal does not make earlier lawful processing unlawful. It may mean that we cannot continue the part of SOS support that depends on that information. We will stop consent-based processing and delete or restrict the information unless a separate lawful basis permits or requires continued processing or retention, which we will explain where applicable.
Privacy and disclosure boundaries
SOS messages are private correspondence and are not submitted for public posting. We will not publish your SOS message, use it as a testimonial or identify you for publicity without separate, specific permission. We do not sell SOS information or share it with referral partners for their own marketing.
Access is limited to Jacques de Villiers and other specifically authorised people who need it to handle your SOS request or fulfil a lawful operational, security or legal duty. Hosting, form, email, backup and technical providers may process information only as needed for their authorised functions. People and operators handling it must be subject to appropriate confidentiality duties and security safeguards. General community participation or moderation does not by itself entitle someone to access SOS correspondence.
We will obtain your specific consent before forwarding your message or health information to an independent professional for an ordinary referral. You can instead contact the professional directly. Any commercial or referral arrangement does not itself authorise disclosure of your information. An independent professional who receives information for their own services is responsible for their own processing and privacy notice.
We may also disclose the minimum necessary information to comply with a legal obligation or valid legal process, or to emergency services, an appropriate authority or another person able to assist where disclosure is necessary and legally permitted to address a serious threat to your or another person’s life or safety. We must identify a lawful basis for the disclosure and, for special personal information, an applicable authorisation under POPIA; a safety concern alone does not dispense with those requirements. We will limit the recipients, information and purpose, record the basis for disclosure, and seek consent or inform you beforehand where safe, lawful and reasonably practicable. Urgency or a legal restriction may prevent advance notice.
SOS cannot promise absolute confidentiality, legal privilege, continuous monitoring, an emergency response or successful intervention. Do not wait for an SOS reply in an emergency. In South Africa, call 112 from a mobile phone or seek help at the nearest hospital emergency department; elsewhere, contact local emergency services. The Website Terms of Use & Disclaimer explain SOS’s service boundaries.
7. WHY WE PROCESS PERSONAL INFORMATION
We may process personal information where reasonably necessary to:
- provide and operate our website and services;
- respond to enquiries and communications;
- administer comments, submissions and community participation;
- provide information or communications that you have requested;
- manage subscriptions and communication preferences;
- send newsletters, article notifications or direct marketing where permitted by law;
- administer accounts or memberships;
- moderate the community and enforce applicable terms;
- maintain the security and integrity of our website, accounts and systems;
- prevent or investigate misuse, fraud, unlawful activity or security threats;
- maintain records where reasonably or legally necessary;
- comply with legal and regulatory obligations;
- establish, exercise or defend legal rights; and
- maintain and improve the operation and functionality of Mostly Responsible(ish).
We will not intentionally process personal information for a purpose that is incompatible with the purpose for which it was collected unless the further processing is permitted by law.
For ordinary personal information, the lawful basis depends on the purpose and may be your consent, steps to enter into or perform a contract you request, compliance with a legal obligation, or the lawful protection of your, our or a third party’s legitimate interests under section 11 of POPIA. Special personal information also requires the additional authorisation explained in section 6A; the general purposes listed here do not remove that requirement.
8. EMAIL COMMUNICATIONS AND DIRECT MARKETING
Where consent is required by law, we will obtain the necessary consent before sending electronic direct marketing.
Submitting an enquiry, comment, Confession or other communication does not, by itself, mean that you have agreed to receive marketing communications.
Contacting SOS, sharing health information, receiving a reply or accepting a referral does not opt you into marketing. SOS consent and marketing consent are separate, and support is not conditional on agreeing to marketing. A service reply to your SOS request is not permission to add you to a marketing list.
Where subscription preferences are available, you may choose the categories of communication you wish to receive.
Marketing and subscription emails will provide a reasonable and accessible method to unsubscribe or manage your communication preferences.
Unsubscribing from emails does not automatically terminate your Mostly Responsible(ish) membership or account.
You may remain a member of the community while choosing not to receive marketing or subscription emails.
Membership termination, account deletion and email subscription preferences are treated as separate actions.
Where you withdraw consent or unsubscribe from applicable communications, we will honour that request subject to communications that we may still lawfully or necessarily send, such as essential account, security, legal or service-related communications.
9. WE DO NOT SELL PERSONAL INFORMATION
Mostly Responsible(ish) does not sell, rent or trade personal information.
We will not provide your personal information to another business for that business to independently market its products or services to you without an appropriate lawful basis or your consent where required.
We may use trusted service providers or operators that process personal information on our behalf where reasonably necessary to provide hosting, email, website functionality, forms, security, backups, technical support or other legitimate operational services.
Where required by law, appropriate confidentiality and security obligations will apply to service providers processing personal information on our behalf.
Where a provider acts as our operator, we will put in place a written contract requiring the security measures prescribed by section 19 of POPIA, confidentiality and processing only within our authorisation. The operator must notify us immediately if it has reasonable grounds to believe that information has been accessed or acquired by an unauthorised person. The more specific disclosure limits in section 6A apply to SOS information.
We may also disclose personal information:
- where you have consented to the disclosure;
- where required or permitted by law;
- in response to a lawful request, court order or legal process;
- to establish, exercise or defend legal rights; or
- where reasonably necessary and lawful to protect our users, systems, rights, property or security.
10. SECURITY OF PERSONAL INFORMATION
We take reasonable and appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised destruction, unlawful access and unlawful processing.
These measures may include, where appropriate:
- restricting access to personal information;
- password and account security;
- appropriate website and hosting security;
- maintaining and updating software and systems;
- using reputable service providers;
- backup and recovery measures; and
- reviewing access and security measures where reasonably necessary.
No internet-connected system can be guaranteed to be completely secure. We therefore cannot promise absolute security, but we will take reasonable measures required by applicable law to protect personal information in our possession or under our control.
For SOS information, safeguards must reflect the sensitivity of health and mental-health disclosures. We restrict access to those who need it, use appropriate account and device protection, protect transmission and storage according to assessed risks, and keep sensitive correspondence out of public community areas and marketing lists. We identify foreseeable risks, regularly check safeguards and update them when risks or deficiencies change. Confidentiality duties, appropriate operator contracts, secure disposal and access reviews form part of these measures. No statement here promises an absolute level of security.
11. SECURITY COMPROMISES
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate the incident, take reasonable steps to contain and address it, and comply with the notification and reporting requirements imposed by POPIA.
Where required by law, we will notify the Information Regulator and affected data subjects.
Notifications required by section 22 will be made as soon as reasonably possible after discovery, subject only to the qualifications and permitted delays in that section. SOS information is covered by these obligations too.
12. RETENTION OF PERSONAL INFORMATION
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected or subsequently lawfully processed, or for longer where retention is required or permitted by law.
Information may also be retained where reasonably necessary for lawful recordkeeping, contractual purposes, security, dispute resolution or the establishment, exercise or defence of legal rights.
When personal information is no longer required and there is no lawful reason to retain it, we will delete, destroy or de-identify it as required by applicable law.
We review the need to retain SOS messages, attachments, replies and referral records when the correspondence ends and periodically thereafter. Relevant factors include whether your request or an agreed follow-up remains open, whether a complaint, safety matter or legal claim requires a record, and any applicable legal retention duty. We retain only what is needed, restrict any record held solely for a legal purpose, and securely delete, destroy or de-identify information as soon as reasonably practicable when its lawful retention period ends. We do not retain health details indefinitely merely because you contacted SOS. Protected backups may retain residual copies until their normal secure deletion or overwrite cycle; those copies remain access-restricted, are not reused for ordinary purposes and are subject to deletion controls if restored.
13. COOKIES AND TECHNICAL INFORMATION
Our website may use cookies and similar technologies for purposes such as website functionality, security, user preferences, performance and analytics.
These technologies may process technical information such as browser type, device information, IP address and website usage information.
Where consent is legally required for a particular technology or processing activity, we will implement an appropriate consent mechanism.
Our use of cookies and similar technologies may change as the website develops, and this Policy will be updated where necessary.
SOS message contents and health disclosures are not to be sent to advertising tools or used to build marketing profiles. Any technical collection associated with SOS remains subject to data minimisation, purpose limitation and the safeguards in this Policy.
14. THIRD-PARTY SERVICES AND LINKS
Our website may contain links to websites or services operated independently by third parties.
We are not responsible for the privacy practices, security, availability or content of independent third-party websites or services. You should review their privacy information before providing personal information to them.
Where a service provider processes personal information on our behalf, we will take reasonable steps required by POPIA in relation to that processing.
15. CROSS-BORDER PROCESSING
Some hosting, email, cloud, technical or other service providers may process or store personal information outside South Africa.
Where personal information is transferred outside South Africa, we will take reasonable steps to ensure that the transfer is permitted under POPIA and that the requirements applicable to cross-border transfers are satisfied.
This includes SOS information held by overseas email, hosting or cloud providers. A transfer must meet section 72 of POPIA, for example through adequate protection under applicable law or a binding agreement, or another applicable statutory ground. We will not transfer special personal information or children’s personal information to a third party in a country lacking adequate protection without first obtaining the prior authorisation required by sections 57 and 58, unless a lawful exception applies. A referral relationship is not itself a cross-border transfer authorisation.
16. CHILDREN’S PERSONAL INFORMATION
Mostly Responsible(ish) is not primarily directed at children.
We do not intentionally seek to collect or process children’s personal information without the consent of a competent person or another lawful basis permitted by POPIA.
If we become aware that children’s personal information has been collected or processed without the required lawful basis, we will take appropriate steps to address the matter.
These protections also apply if a child contacts SOS. Where a child’s health or other special personal information is involved, both the requirements for children’s information under sections 34 and 35 and the additional authorisation for special personal information must be met. Ordinary SOS consent does not override those requirements. We will limit handling to what is lawful and necessary, including obtaining a competent person’s consent where applicable or addressing a legal safeguarding obligation.
17. YOUR RIGHTS
Subject to POPIA and other applicable law, you may have the right to:
- ask whether we hold personal information about you;
- request access to personal information that we hold about you;
- request correction or updating of inaccurate, incomplete, misleading or outdated personal information;
- request deletion or destruction of personal information where legally applicable;
- object to certain processing of your personal information;
- withdraw consent where processing is based on consent, subject to applicable legal limitations and consequences;
- object to or opt out of direct marketing;
- request information concerning certain third parties or categories of third parties that have had access to your information where applicable; and
- lodge a complaint with the Information Regulator.
These rights may be subject to procedures, exceptions and limitations imposed by POPIA, PAIA or other applicable law.
18. REQUESTS CONCERNING YOUR PERSONAL INFORMATION
Requests relating to your personal information may be sent to:
admin@responsible-ish.co.za
We may require reasonable proof of identity before providing access to, correcting or deleting personal information in order to protect information against unauthorised disclosure or alteration.
We will process valid requests in accordance with applicable law.
19. INFORMATION REGULATOR
You have the right to lodge a complaint with the Information Regulator (South Africa) if you believe that your personal information has been processed in violation of POPIA.
At the date of this Policy, the Information Regulator’s contact details include:
Information Regulator (South Africa) Woodmead North Office Park 54 Maxwell Drive Woodmead, Johannesburg
South Africa
Telephone: 010 023 5200
Email: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Website and current complaint procedures: https://inforegulator.org.za/contact-us/
The Regulator’s current contact and complaint procedures are available from its official website.
20. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy when our services, technology, business structure, processing activities or legal obligations change.
The current version will be published on our website and the Last updated date will be changed accordingly.
Where a material change requires additional notification or consent under applicable law, we will take the appropriate steps.
21. CONTACT
Questions, requests or concerns relating to privacy or personal information may be directed to:
Mostly Responsible(ish)
Jacques de Villiers trading as Mostly Responsible(ish)
Gordon’s Bay, Western Cape, South Africa
Email: admin@responsible-ish.co.za
Website: responsible-ish.co.za
