Reachby Zavon
Legal

Privacy Policy

This Policy describes how Zavon Holdings Group (Pty) Ltd, the operator of Reach by Zavon, collects, processes, stores and discloses personal information. It applies to every organisation that uses Reach and to every person whose address is held in it.

Effective 7 September 2026

1.Who is responsible for what

The Protection of Personal Information Act, 2013 (POPIA) distinguishes the party who decides why personal information is processed (the Responsible Party) from the party who processes it on their instructions (the Operator). Reach sits on both sides of that line, depending on whose information is in question.

  • For the people who operate Reach — the administrators at a subscribing organisation — we are the Responsible Party. We decide why their account information is processed.
  • For an organisation's audience — the recipients whose addresses, names and attributes the organisation holds in Reach — the organisation is the Responsible Party and we are the Operator. We process those details only on that organisation's instructions.

If you received an email sent through Reach, your first point of contact is the organisation that sent it. They decided to hold your details and to mail you, and they are accountable for that under POPIA. We will help them answer you, but we will not act on their data without their authority — except to stop mailing you, which you can do yourself with the unsubscribe link in any message, and which we honour centrally and immediately.

2.What we hold

About administrators: name and work email address; the organisation they belong to and their permissions within it; sign-in records; and diagnostic information about how they use the console, for fixing faults and improving the product.

About an organisation's audience, on that organisation's behalf:

  • the email address, and a name where the organisation has one;
  • the attributes the organisation records against a person for segmenting a mailing — a role, a campus, a year group — which are whatever the organisation chooses to keep;
  • the record of what was sent to that address and when, whether it was delivered or bounced, and whether it was opened or a link in it was clicked;
  • subscription and unsubscribe state, per publication, so that leaving one mailing does not leave others.

We do not build a profile of any recipient across organisations, and we do not mail anybody on our own behalf.

3.Lawful basis

For administrators, we process on the basis of the contract with their organisation and our legitimate interest in operating and securing the service. For an audience, the lawful basis is the sending organisation's to establish and to be able to demonstrate; our processing rests on our contract with them, as their Operator.

4.Who else sees it

Reach does not deliver mail itself. Messages are passed to our central mail service, which uses Postmark (Wildbit, LLC, United States) as its delivery provider. Delivering an email necessarily discloses the recipient's address and the content of the message to that provider and to the recipient's own mail provider. Beyond that:

  • our hosting and database providers, which store the data at rest under contract;
  • a professional adviser or authority where the law requires disclosure — and we will tell the affected organisation unless we are prohibited from doing so;
  • a successor, if the business is sold, on the same terms as this Policy.

We do not sell personal information, and we do not share it for anybody else's marketing.

5.Sending outside South Africa

Our delivery provider and some of our infrastructure are outside the Republic. Section 72 of POPIA permits such a transfer where the recipient is bound by rules affording adequate protection; our providers are bound by contractual data-protection terms to that effect. An email addressed to somebody abroad also, by its nature, travels there.

6.How long we keep it

Audience records and sending history are kept while the organisation's subscription is active, because the record of what was sent to whom is what makes an unsubscribe or a complaint answerable. Message bodies are kept for a shorter period — 180 days by default — after which the record of the message survives without its contents.

A suppression is kept indefinitely, deliberately. If somebody unsubscribes or an address hard bounces, forgetting that fact would mean mailing them again. Deleting an audience does not delete the record that a person asked not to be mailed.

After a subscription ends we keep the organisation's data long enough for a one-time export and for any legal retention period, then delete it.

7.Security

Access to the console is through Accounts using short-lived tokens; sign-in links and session tokens are stored only as hashes, so a leaked backup contains nothing anybody can sign in with. Every route decides against the caller's permissions for the organisation in question, so one organisation cannot read another's audiences, mail or figures. Data is encrypted in transit, and at rest by our infrastructure providers.

No system is perfectly secure. If a breach affects personal information we hold, we will notify the Information Regulator and the affected organisations as section 22 of POPIA requires.

8.Opens, clicks and what they are worth

Reach records whether a message was opened and whether a link was clicked. Open tracking uses a small image; many mail clients now load images automatically or block them entirely, so the figures under-count some recipients and over-count others. We report them as indicative, and no decision that affects a person should rest on them alone.

9.Your rights

Under POPIA you may ask to see the personal information held about you, to correct or delete it, to object to its processing, and to complain to the Information Regulator.

  • If you are an administrator, write to us at [SENSITIVE] and we will answer within 30 days.
  • If you received a mailing, the unsubscribe link in it stops the mail immediately and needs nothing from anyone. For access, correction or deletion, ask the organisation that mailed you — they hold the record and the responsibility. Tell us if they do not respond and we will follow it up with them.

The Information Regulator (South Africa) can be reached at complaints.IR@justice.gov.za.

10.Children

Reach is not intended for children, and an organisation must not use it to mail a child without the consent of a competent person as POPIA requires. Where an organisation's audience includes minors — a school, a youth group — that consent is theirs to obtain and to hold.

11.Changes

We may update this Policy. We will give at least 30 days' notice of a material change, in the product and to administrators' addresses, and the effective date above will change.

Contact

Zavon Holdings Group (Pty) Ltd
[SENSITIVE]

See also the Terms and Conditions, which set out who is responsible for the mail sent through Reach.