POPIA Privacy Policy
Last updated: 02 October 2025
Responsible Party (Controller):
Stagi Pty Ltd (“Stagi”, “we”, “us”).
Registered address: Walmer, Gqebehra, Eastern Cape, South Africa, 6070.
Email: imagine@stagi.co.za (privacy & queries).
Information Officer: Appointed by Stagi (contact via imagine@stagi.co.za).
1) Scope
This policy explains how we process personal information under the Protection of Personal Information Act 4 of 2013 (“POPIA”). It applies to stagi.co.za, our apps and related services in South Africa.
2) What we collect
- Account & contact: name, email, phone, agency/role.
- Usage: device info, IP address, logs, cookie IDs, analytics.
- Content: property photos uploaded and prompts you enter.
- Billing: references from our payment provider (no card PANs stored by Stagi).
3) Purposes (POPIA s11)
- Provide, secure and improve Stagi (image enhancement, style packs, before/after previews).
- Account administration, support, fraud/abuse prevention.
- Service communications; marketing only with consent (opt-out anytime).
- Legal compliance (tax, security incident reporting).
4) Lawful bases
- Performance of a contract (service delivery).
- Consent (marketing/certain cookies).
- Legitimate interests (analytics, abuse prevention) balanced with your rights.
5) Operators (Processors)
We use vetted providers (hosting/CDN, analytics, email, payments) under written contracts requiring security, confidentiality, and processing only on our instructions.
6) Cross-border transfers
If data is transferred outside South Africa, we ensure adequate protection (adequate jurisdictions, contractual safeguards or consent) as contemplated in POPIA s72.
7) Security
- Encryption in transit; least-privilege access; audit logging.
- Backups and monitoring; vulnerability management.
- Operator due-diligence and confidentiality obligations.
8) Your rights
You may request access, correction, deletion (where applicable), object to processing, and complain to the Information Regulator. Contact us at imagine@stagi.co.za. Information Regulator: inforegulator.org.za.
9) Retention
We retain personal information only as needed for the purposes above and legal requirements. You can delete uploads in your account; backups roll off per schedule.
10) Cookies & analytics
Essential cookies support login and preferences; optional analytics help improve features. Manage preferences via your browser and our banner.
11) Direct marketing
Electronic marketing is sent only with consent to customers/opt-in contacts and always includes an unsubscribe option.
12) Security compromises (breach)
On reasonable grounds of a compromise, we will notify affected persons and, where required, the Information Regulator, describing the incident, risks and mitigation steps.
13) PAIA
Our PAIA manual is available on request at imagine@stagi.co.za.