Legal

Privacy Policy

How PEN Play collects, uses, and protects personal information - with special care for the children in your care - in line with South Africa's Protection of Personal Information Act (POPIA).

Version: 1.0Last updated: 17 August 2026Effective: 17 August 2026

1. Introduction

PEN Play (“PEN Play”, “we”, “us”, “our”) is committed to protecting your privacy and the privacy of the children in your care. PEN Play is a product of BigBrave, and comprises the Whartels game (“the Game”) and the PEN Play web portal (“the Portal”), together “the Services”. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have.

This Policy is issued in accordance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) and read together with the Promotion of Access to Information Act 2 of 2000 (“PAIA”) and, where applicable, other data-protection laws. Capitalised terms such as “personal information”, “processing”, “responsible party”, “operator”, “data subject” and “competent person” carry the meanings given to them in POPIA.

PEN Play is designed for the benefit of children but is used by adults. Children do not create their own accounts. A parent, legal guardian or authorised professional (a “competent person”) sets up and controls access on a child's behalf.

By using the Services, or by permitting a child in your care to use the Services, you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the Services.

2. Who is responsible for your information

The responsible party (data controller) for personal information processed through the Services is the legal entity operating PEN Play, trading as PEN Play. Its full registered details are set out below.

Responsible party & contact details

  • Entity: BigBrave (Pty) Ltd, trading as PEN Play
  • Company registration number: [to be confirmed]
  • Registered address: [to be confirmed]
  • General enquiries: info@penplay.com
  • Data-protection / privacy enquiries: info@penplay.com
  • Telephone: +27 (0) 82 853 2320

Information Officer

As required by POPIA, we have designated an Information Officer who is responsible for encouraging and ensuring compliance with POPIA, dealing with data-subject requests, and liaising with the Information Regulator. You can contact our Information Officer at info@penplay.com (marked “for the attention of the Information Officer”).

3. Personal information we collect

We collect only the personal information we need to provide and improve the Services. The categories below describe what we may collect, depending on how you use the Services and the role you hold.

Information about account holders (adults)

  • Identity and contact details: name, surname, email address, and (where provided) telephone number.
  • Role and relationship: whether you are a parent, teacher, therapist, institution administrator or other user, and your relationship to the children linked to your account.
  • Professional and organisation details: for teachers, therapists and institutions - practice or school name, registration number (where you provide it), and role within the organisation.
  • Authentication and security information: password (stored only in hashed form by our authentication provider), one-time passcodes (OTPs) used to verify sign-in, and “trusted device” indicators.
  • Billing information: subscription plan, billing status, and transaction references. Card and payment details are processed by our payment provider and are not stored by us (see “Payments” below).

Information about children (learners)

  • Profile details entered by the competent person: the child's name or nickname, age or date of birth, grade or school year, and (optionally) relevant learning or developmental context provided to personalise the experience.
  • Gameplay and progress data: question templates attempted, responses, scores, progress, and derived recommendations.
  • Wellbeing and mood indicators: emotion, mood and related inputs the child records during play, which help generate psycho-educational feedback for the competent person.

Information collected automatically

  • Device and technical data: device type, operating system, app version, and identifiers needed for push notifications (messaging tokens).
  • Sign-in and security logs: IP address, approximate location (city / country) derived from your connection, and device information, recorded to detect and alert you to suspicious sign-in activity and to protect your account.
  • Usage data: pages and features used, and interaction events, used to operate and improve the Services.
  • Cookies and similar technologies: see “Cookies” below.

We do not knowingly collect more information about a child than is necessary to deliver the Services. We do not require children to provide unnecessary personal details as a condition of play.

4. Special personal information & children's information

POPIA gives extra protection to “special personal information” (which can include information about a person's health or wellbeing) and to the personal information of children. Because PEN Play supports learning, cognition and emotional wellbeing, some of the information we process - for example mood, emotion and developmental context - may be sensitive in nature.

Children's information (POPIA ss 34–35)

We process a child's personal information only where a competent person (a parent, legal guardian, or a professional lawfully authorised to act for the child) has consented, or where processing is otherwise permitted by law - for example, where it is necessary for the proper performance of a public-law duty, or to protect a legitimate interest of the child. By adding a child to your account, you warrant that you are a competent person entitled to provide that consent, or that you are authorised by a competent person to do so.

Special personal information (POPIA ss 26–27)

Where the information we process qualifies as special personal information, we rely on your explicit consent and on the exemptions that permit processing for the child's education, guidance and wellbeing. We use this information only to generate feedback, recommendations and reports for the competent person, and never to make decisions that produce legal or similarly significant effects about the child without human involvement.

You may withdraw consent at any time (see “Your rights”). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, but may mean we can no longer provide some or all of the Services for that child.

5. How and why we use your information

We process personal information only for lawful purposes and in a way that is adequate, relevant and not excessive. Our purposes include:

  • Providing the Services - creating and managing accounts, delivering gameplay, generating recommendations, and giving competent persons and professionals reports on a child's progress and wellbeing.
  • Authentication and account security - verifying identity, sending OTPs, recognising trusted devices, and alerting you to suspicious sign-in activity.
  • Billing and administration - managing subscriptions, processing payments through our payment provider, and keeping accounting records.
  • Communication - sending service messages, security alerts, and responding to your support requests and enquiries.
  • Improvement and research - understanding how the Services are used so we can improve them; where we use information for research or analytics, we de-identify or aggregate it wherever practicable.
  • Legal and compliance - meeting our legal obligations, exercising or defending legal claims, and preventing fraud or misuse.

Legal grounds for processing

Depending on the purpose, we rely on one or more of the justifications recognised by POPIA: your consent (or a competent person's consent for a child); the performance of a contract with you; compliance with a legal obligation; the protection of a legitimate interest of the data subject; or the pursuit of our legitimate interests (or those of a third party) in a way that is balanced against your rights.

6. Direct marketing

We will only send you electronic marketing (such as newsletters or product updates) where you have opted in, or where the law otherwise permits us to contact an existing customer about similar products and services. You can opt out of marketing at any time - every marketing email contains an unsubscribe link, and you can also update your preferences in the Portal or by contacting us. Opting out of marketing does not stop essential service and security messages, which we must send to operate your account.

7. When we share your information

We do not sell your personal information. We share it only in the following circumstances:

  • With operators (processors): trusted service providers who process personal information on our behalf and under our instructions, subject to written agreements requiring appropriate security. These include our cloud, database and authentication providers, our payment provider, our email/SMS providers, our hosting and analytics providers, and providers of push-notification services.
  • Within a learning relationship: information about a child may be visible to the competent persons and authorised professionals (for example a linked parent, teacher, therapist or institution administrator) connected to that child's account, so they can support the child.
  • For legal reasons: where we are required or permitted by law, court order, or a competent authority, or to protect our rights, users, or the public.
  • In a business transfer: if PEN Play or its business is reorganised, merged or acquired, personal information may be transferred as part of that transaction, subject to this Policy.

Our current key operators include Google Firebase (authentication, database and messaging), our website hosting provider, our email/SMS delivery providers, and Paystack (payment processing). We update this list as our providers change.

8. Cross-border transfers

Some of our operators store or process personal information on servers located outside the Republic of South Africa. Where we transfer personal information across borders, we do so in accordance with section 72 of POPIA - that is, where the recipient is subject to a law, binding rules or agreement that provides an adequate level of protection substantially similar to POPIA; where you (or the competent person) have consented; or where the transfer is necessary to perform our contract with you. We take reasonable steps to ensure that your information continues to be protected wherever it is processed.

9. How we protect your information

We take the security of personal information seriously and maintain appropriate, reasonable technical and organisational measures to safeguard it against loss, damage, and unauthorised or unlawful access, in line with POPIA's security-safeguards condition. These measures include:

  • Encryption of data in transit, and access controls that limit who can view personal information.
  • Passwords stored only in hashed form, one-time-passcode verification, trusted-device recognition, and alerts for suspicious sign-in activity.
  • Role-based access so that users only see the information appropriate to their role and relationship.
  • Written agreements with our operators requiring them to maintain adequate security and to process information only on our instructions.

Data breaches

If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering the compromise, as required by section 22 of POPIA, unless a public body or the Regulator directs otherwise.

10. How long we keep your information

We keep personal information only for as long as necessary to fulfil the purposes described in this Policy, to provide the Services, and to comply with our legal, accounting and reporting obligations. When information is no longer needed, we securely delete it or de-identify it so that it can no longer be linked to you or a child.

When an account or a child profile is deleted, we redact or remove personal information in line with our internal data-retention and deletion procedures. Some records (for example transaction and tax records) may be retained for the periods required by law, and de-identified or aggregated data may be retained for research and statistical purposes.

11. Your rights

As a data subject (or a competent person acting for a child), POPIA gives you the following rights in relation to personal information we hold:

  • To be notified that we are collecting your information, and if it has been accessed by an unauthorised person.
  • To ask us to confirm, free of charge, whether we hold personal information about you, and to request access to that information.
  • To request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully.
  • To object, on reasonable grounds, to the processing of your personal information.
  • To object at any time to the processing of your personal information for direct marketing.
  • Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, without human involvement.
  • To withdraw consent where we rely on it (this does not affect processing carried out before withdrawal).
  • To submit a complaint to the Information Regulator, and to institute civil proceedings regarding an alleged breach of POPIA.

To exercise any of these rights, contact us at info@penplay.com. You can also request deletion of your data through our data-deletion request form. We may need to verify your identity, and (where a request concerns a child) your authority as a competent person, before we act. We will respond within the timeframes required by law.

12. Cookies & similar technologies

The Portal uses cookies and similar technologies (such as local storage) that are necessary for it to work - for example to keep you signed in, remember your language preference, and recognise trusted devices for security. We may also use analytics technologies to understand how the Services are used so we can improve them.

You can control cookies through your browser settings, but disabling necessary cookies may affect how the Services function. Where the law requires consent for non-essential cookies, we will ask for it.

13. Third-party links & services

The Services may link to, or rely on, third-party websites and services (for example app stores, payment providers, or educational content). This Policy does not cover those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy notices of any third-party service you use.

14. Changes to this Policy

We may update this Policy from time to time to reflect changes in the Services, our practices, or the law. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Services or by email. Your continued use of the Services after an update means you accept the revised Policy.

15. How to contact us & the Information Regulator

If you have any questions, requests or concerns about this Policy or how we handle personal information, please contact us first so we can help:

  • Email: info@penplay.com (for the attention of the Information Officer)
  • Telephone: +27 (0) 82 853 2320

You also have the right to lodge a complaint with the Information Regulator of South Africa:

  • The Information Regulator (South Africa)
  • Email (complaints): complaints.IR@inforegulator.org.za
  • Email (POPIA enquiries): POPIAComplaints@inforegulator.org.za
  • Website: https://inforegulator.org.za