Privacy Policy
Privacy Policy
This policy explains how personal information is handled through this website, related communications and business relationships.
- Responsible party
- BrilliantMathsTutors
- Website
- https://brilliantmathstutors.co.za/
- Jurisdiction
- Republic of South Africa
- Last updated
- 2026-07-20
Website legal document
1 Scope and responsible party
Who this notice covers and who decides how personal information is processed.
This Privacy Policy explains how BrilliantMathsTutors (the “responsible party”, “we”, “us” or “our”) processes personal information through https://brilliantmathstutors.co.za/, related digital services, enquiries and client or supplier relationships.
Current business and contact details, including the channel for privacy enquiries, are available Here.
Website legal document
2 Information we may collect
The categories depend on how a person uses the website or engages with the business.
We may process identifying and contact information, enquiry and correspondence records, account or transaction details where relevant, service-delivery records, billing information that is not retained by a payment processor, technical and security logs, device or browser information, consent choices, and website interaction information.
We aim to collect only information that is adequate, relevant and reasonably necessary for the stated purpose.
Website legal document
3 Sources of personal information
Information may be obtained directly or from lawful operational sources.
We generally collect personal information directly from the person concerned through forms, email, telephone, messaging, account registration, orders, support requests or contractual dealings. We may also receive information from authorised representatives, referral partners, public business records, payment providers, hosting and security operators, or other lawful sources where direct collection is not reasonably practicable.
Website legal document
4 Purposes and justification
Why information is processed and the grounds relied upon.
We process personal information to respond to enquiries; prepare quotes; conclude and perform agreements; provide, support and improve services; administer accounts and payments; secure and operate the website; maintain business and legal records; comply with legal duties; prevent misuse or fraud; communicate service information; and conduct direct marketing where permitted.
Depending on the circumstances, processing may be based on consent, contractual necessity, a legal obligation, protection of a legitimate interest, or the legitimate interests of the responsible party or a third party. Consent is not treated as the only possible ground for every processing activity.
Website legal document
5 Website forms and communications
What happens when a person contacts us.
Information submitted through contact forms, email, telephone or messaging is used to respond, keep an appropriate record, provide requested information, prepare a proposal, deliver services, and protect against abuse. Fields marked as required are necessary to process the request; failing to provide them may prevent us from responding or delivering the requested service.
Website legal document
6 Cookies, analytics and similar technologies
Optional storage and measurement follow the visitor’s Bloom Consent choices.
We use essential technologies for security, consent storage and core website operation. Optional functional, analytics, marketing and external-media technologies are controlled through Bloom Consent. Google services may remain technically available in a limited, cookieless measurement state where Google Consent Mode supports that behaviour, while optional storage remains denied.
The current technical service and storage disclosures are listed in the disclosure schedule below.
Technical disclosure snapshot. This schedule was generated when this legal version was published. It records declared services, identifiers, consent categories, cookie name patterns and remote hosts; it does not store cookie values or request URLs.
| Service | Provider | Category | Identifier | Declared technologies | Consent behaviour |
|---|---|---|---|---|---|
| Bloom Consent | Bloom Way Digital | Necessary | bloom_consent_v1 | Cookies: bloom_consent_v1 | Required for core operation and not disabled through optional consent controls. |
| WordPress operational cookies | WordPress | Necessary | wordpress-core | Cookies: wordpress_, wordpress_sec_, wp-settings-, wp-settings-time-, comment_author_ | Required for core operation and not disabled through optional consent controls. |
| Google Tag Manager | Service container | GTM-5GJPB7K6 | Hosts: www.googletagmanager.com, googletagmanager.com | Container remains operational under Limited; optional Google storage follows the visitor’s category choices. | |
| Google Analytics 4 | Analytics | G-CKQV9K76PG | Cookies: _ga, _ga_, _gid, _gat | Hosts: google-analytics.com, analytics.google.com, www.googletagmanager.com | Analytics storage is denied under Limited and granted only with Analytics consent; supported cookieless measurement may continue. | |
| Google tag | Service container | GT-KFNPTKZ | Hosts: www.googletagmanager.com, googletagmanager.com | Container remains operational under Limited; optional Google storage follows the visitor’s category choices. | |
| Google Ads conversion tracking | Marketing | AW-11029236820 | Cookies: _gcl_au, _gcl_, _gac_ | Hosts: googleadservices.com, doubleclick.net, googlesyndication.com, www.googletagmanager.com | Advertising storage and advertising-personalisation signals are denied under Limited and granted only with Marketing consent. |
Snapshot date: 2026-07-20. Consent-policy version: 1.0. Bloom consent preference lifetime: 180 days.
Observation boundary: same-origin JavaScript cannot see HttpOnly cookies; remote GTM container internals and server-side tags cannot be proven from the browser registry alone. Provider contracts and current provider notices should be reviewed where processing location, recipients or retention periods are material.
Website legal document
7 Operators and recipients
The categories of parties that may process information for us.
We may share personal information with contracted operators and recipients that support hosting, security, communications, analytics, advertising, payment processing, accounting, professional advice, service delivery, backups and business administration. They receive only the information reasonably required for their function and are expected to protect it under applicable law and contractual duties.
We do not sell personal information as a business model.
Website legal document
8 Cross-border processing
Some operators may process information outside South Africa.
Where personal information is transferred outside the Republic of South Africa, we take reasonable steps to ensure that the recipient is subject to a law, binding corporate rules, agreement or other protection that provides an adequate level of protection, or that another lawful basis for the transfer applies. The locations and safeguards depend on the operators actually used.
Website legal document
9 Retention and deletion
Records are kept only for as long as justified.
We retain personal information for the period reasonably needed for the purpose collected, contractual and support requirements, legitimate operational needs, dispute management, legal or regulatory obligations, and applicable prescription or record-keeping periods. Information is deleted, destroyed or de-identified when retention is no longer authorised, subject to lawful exceptions and backup rotation.
Website legal document
10 Security safeguards
Reasonable technical and organisational safeguards are used.
We use safeguards appropriate to the nature of the information and reasonably foreseeable risks. These may include access control, secure transport, software maintenance, malware and intrusion controls, backups, logging, confidentiality duties, vendor review and incident procedures. No internet transmission or storage system can be represented as absolutely secure.
Website legal document
11 Your rights
Requests are handled subject to identity verification and lawful exceptions.
A data subject may ask whether we hold personal information about them; request access; ask for correction, deletion or destruction where permitted; object to certain processing; withdraw consent where processing depends on consent; object to direct marketing; and lodge a complaint with us or the Information Regulator.
Requests may be submitted Here. We may request information reasonably necessary to verify identity and authority before acting.
Website legal document
12 Direct marketing
Electronic marketing is managed separately from ordinary service communications.
We may send direct marketing where the recipient has consented or another permission recognised by law applies. Every qualifying electronic marketing message should identify the sender and provide a practical way to opt out. Service, security, billing and contractual communications are not treated as marketing merely because they relate to an existing relationship.
Website legal document
13 Children and special personal information
Additional care applies to higher-risk information.
Our general website is not directed at children. We do not intentionally process the personal information of a child without a competent person’s authorisation or another lawful basis. We also avoid collecting special personal information unless it is necessary, authorised and accompanied by suitable safeguards.
Website legal document
14 Automated decisions and profiling
Material decisions should not be based solely on automation without lawful safeguards.
Unless specifically disclosed for a service, we do not make decisions that have legal or similarly significant effects solely through automated processing. Routine security, spam, fraud, analytics and website-personalisation tools may use automated signals but remain subject to appropriate human oversight where required.
Website legal document
15 Security compromises
How affected people may be notified.
If we have reasonable grounds to believe that unauthorised access to or acquisition of personal information has occurred, we will assess the incident and notify the Information Regulator and affected data subjects when required, subject to lawful delay or instruction.
Website legal document
16 Complaints and regulator
How to raise a privacy concern.
Please first contact us Here so that we can investigate and respond. A person may also lodge a complaint with the Information Regulator of South Africa using the Regulator’s current official complaint channels.
Website legal document
17 Third-party websites
External services have their own privacy practices.
Links or embedded services operated by third parties are provided for convenience or functionality. We do not control their independent processing practices. Users should review the relevant provider’s privacy information before supplying personal information to that provider.
Website legal document
18 Changes and contact details
How this policy is maintained.
We may amend this policy to reflect changes in law, services, technology or processing practices. The current version will be published on https://brilliantmathstutors.co.za/ with its effective date.
Privacy and general enquiries may be submitted Here.
Document responsibilitySite owner review responsibility
The organisation operating this website remains responsible for the document it publishes.
The site owner is responsible for reviewing this document against the organisation’s actual services, information-processing practices and legal obligations. Details that do not apply should be removed, business-specific information should be kept current, and qualified legal advice should be obtained where appropriate. Bloom Platform provides document tooling and does not certify legal compliance.