loader image

Website Privacy & Cookies Policy

Last updated: 19 August 2025
Responsible Party: SUMMERHILL PRIVATE SCHOOL (Pty) Ltd
Address: Cnr 8th & 10th Road, Erand, Gauteng, South Africa • Postal: PO Box 2465, Halfway House, 1685
Information Officer: Chantelle JacobsEmail: chantelle@summerhill-school.co.za
General enquiries: info@summerhill-school.co.za

1) Scope

This notice explains how we collect, use, share, store, and protect personal information collected via our website (including online forms). It complements our internal school privacy practices and our PAIA Manual.

2) What we collect (website & forms)

  • Contact form: name, surname, email, message.

  • Book-a-Tour form: same as above (and, where applicable, preferred date/time).

  • Online application: learner and parent/guardian details; schooling history; medical/health information necessary for schooling; emergency contacts; copies/photos of IDs; financial information relevant to admissions; proof of payment for application fees; and the learner’s photo (where requested).
    We do not display this information publicly.

3) Why we collect it (lawful grounds under POPIA)

  • Consent — when you submit forms, book a tour, or provide optional information.

  • Contract / steps to contract — to process admissions and enrolment.

  • Legal obligation — to meet statutory record-keeping and reporting duties.

  • Legitimate interests — to respond to enquiries, ensure website security, and improve our services.
    We do not sell personal information or use it for automated decision-making.

4) How we use and share information

We use information to respond to enquiries, arrange school tours, process applications, manage admissions, communicate with parents/guardians, and operate the website securely. We do not share personal information with third parties except with our operators (processors) who provide IT/website services under instruction and confidentiality:

  • Hosting: Xneelo (South Africa, JHB).

  • Email (SMTP relay): for sending form notifications.

  • Forms & storage: Gravity Forms; application data and selected fields stored in the School’s Google Drive/Sheets for internal processing (access limited to authorised staff).

  • Analytics: Google Analytics (traffic measurement).

  • Embedded services: Google Maps (location), YouTube (video), Instagram feed (via Smash Balloon).

  • Payments: currently EFT; if/when we add PayFast, card details are processed on the gateway, not on our website.

All operators act on our documented instructions and may not use the data for their own purposes.

5) Children’s information & consent

We collect children’s personal information from parents/guardians for admissions and school purposes with consent given when completing the online application. Where required, we may ask for proof of guardianship. We only publish learner images with appropriate consent (if applicable).

6) Retention

We keep personal information only as long as necessary for the stated purposes and legal duties, then securely delete/anonymise it. Typical periods:

  • Contact / Book-a-Tour submissions: kept for the enquiry and administrative follow-up, then deleted within 12 months.

  • Unsuccessful applications: retained for up to 24 months (audit/follow-up), then deleted.

  • Successful applications: information becomes part of the learner record and is retained according to the School’s retention schedule and applicable laws (e.g., financial records retained for statutory periods).

7) Security

We use administrative, technical, and physical safeguards including HTTPS encryption, role-based access, least-privilege, restricted staff access for admissions, regular updates and backups, and (for administrators) multi-factor authentication. Incidents are handled under our breach procedure led by the Information Officer.

8) Your rights (POPIA)

You may request access, correction, deletion, or objection to processing, and you may withdraw consent where processing is based on consent. Please contact the Information Officer (details above). Formal access requests may be made under PAIA (see our PAIA Manual).

9) Cross-border processing

Our hosting is in South Africa. Some operators (e.g., Google services and, if enabled, PayFast) may process or store information in other countries. Where this occurs, we implement section 72 POPIA safeguards (contractual and technical protections) to ensure an adequate level of protection.

10) Cookies & similar technologies

We use cookies to run the site and understand usage. We will display a cookie banner/manager (Complianz) to obtain consent for non-essential cookies. You can change your choices at any time via the banner.

Categories we use

  • Essential (always on): site security/session, load balancing, and preferences required for the site to function.

  • Analytics (consent-based): Google Analytics (e.g., _ga, _ga_*) to measure traffic and improve content.

  • Embeds/Functionality (consent-based): YouTube player, Google Maps, Instagram (Smash Balloon) may set their own cookies.

Managing cookies
Use the banner to accept/decline categories. You can also clear or block cookies in your browser settings. For Google Analytics, you may use Google’s opt-out tools as an additional measure.

11) Contact & complaints

If we cannot resolve your concern, you may contact the Information Regulator (South Africa):

12) Changes to this notice

We may update this notice from time to time. Material changes will be posted on this page with a new “Last updated” date.