PRIVACY AND DATA PROTECTION POLICY
4ZL (PTY) LTD
Last updated: October 5, 2026
1. INTRODUCTION 4ZL (PTY) LTD, the Republic of South Africa (country code 710), registration number: 2025 / 550843 / 07, 47 ASH ROAD, KYALAMI AH, GAUTENG, 1649, is committed to protecting and respecting your privacy.
This Privacy Policy sets out the basis on which any personal information we collect from you, or that you provide to us, will be collected, used, stored and processed by us. We collect, use, and disclose your information as described in this Privacy Policy and, where required by applicable law, only where We have a valid legal basis to do so, including your consent (where consent is required).
This Privacy Policy is governed by the laws of the Republic of South Africa (Protection of Personal Information Act, POPIA) and General Data Protection Regulation (GDPR).
This Privacy Policy applies to all processing of personal data carried out by the Company, as well as to all information that the Company may obtain about the Data subject, and applies to all websites (social media accounts, messenger channels and chats, and websites containing links to this Privacy Policy, regardless of how they are used or accessed, including access via mobile devices).
2. INTERPRETATION. KEY TERMS AND DEFINITIONS 2.1.
Interpretation. The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
2.2.
Definitions. For the purposes of this Privacy Policy:
(1)
Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to 4ZL (PTY) LTD, the Republic of South Africa (country code 710), registration number: 2025 / 550843 / 07, 47 ASH ROAD, KYALAMI AH, GAUTENG, 1649.
(2)
Cookies are small files that are placed on your computer, mobile device or any other device by a website, containing the details of your browsing history on that Website, among its many uses.
(3)
Country refers to: The Republic of South Africa.
(4)
Data Controller (Responsible Party) – is a legal or natural person, an agency, a public authority, or any other body who, alone or when joined with others, determines the purposes of any Personal Data and the means of processing it.
For the purposes of this Privacy Policy, a Data Controller is Company.
(5)
Data Processor (Operator) – is a legal or a natural person, agency or any other body who processes personal data on behalf of a Data Controller. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
(6)
Data subject – person to whom personal information relates.
(7)
Personal Data (or "Personal Information") is information relating to an individual, living, natural person, and where it is applicable, an identifiable, existing juristic person, including. Personal Data can extend to any information where you can be identified directly or indirectly, in particular by reference to an identifier. Information that does not identify a particular person, such as statistical information, is not personal information and is not covered by this Privacy Policy.
We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.
(8)
Privacy Policy refers to the 4ZL (PTY) LTD Privacy and Data Protection Policy.
(9)
Processing – any operation or activity or any set of operations, whether or not by automatic means, concerning personal information, including: (a) the collections, receipt, recording, organization, collation, storage, updating or modification, retrieval, alteration, consultation, or use; (b) dissemination by means of transmission, distribution, or making available in any other form; or (c) merging, linking, as well as restricting, degrading, erasing, or destroying of information.
(10)
Service refers to the Website.
(11)
Website refers to https://onlineschooldental.com/.
All other terms appearing in the text of this Privacy Policy shall be interpreted by the Parties in accordance with applicable law and the customary rules of interpretation of such terms established on the Internet.
3. PROCESSING OF PERSONAL DATA Providing Personal Data is voluntary. However, if you do not provide Personal Data that is necessary to perform the contract or comply with a legal obligation, we may not be able to provide the relevant service or fulfill the obligation.
Below, you can find detailed information on the specific purposes for which we process Personal Data, the exact types of Personal Data we process, and to whom and where we transfer it, where required.
3.1.
Legal ground. We only process your Personal Data when we believe it is necessary and we have a valid legal ground (a lawful basis) for doing so in accordance with the applicable law.
For example:
1) You have given your consent to the processing.
We can process your personal data where you have given clear consent for us to process such personal data for a specific purpose.2) The processing is needed for a contract with you.
We can process your personal data where the processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into such a contract. This means that we can carry out the actions needed to conclude or execute our contract with you.3) The processing is needed for Our legitimate interests.
We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. 4) The processing is needed for a public task.
We can process your personal data where the processing is necessary for us to perform a task in the public interest or an official function, and the task or function has a clear basis in law.3.2.
How We use Personal Data. To achieve the purposes listed below, we will collect, receive, record, organize, store, update or amend, retrieve, alter, view or use, combine, match, block, delete and destroy Personal Data.
3.3.
Purposes, legal bases and time limits for the processing of Personal Data: № | Purpose of processing Personal Data | |
1 | For the conclusion, performance, amendment and termination of a contract | Data subjects: Website visitor / customer / counterparty / representative of customer or counterparty. |
List of Personal Data: Natural persons: surname, first name; date of birth; email address; telephone number; information related to providing products and services; billing details; banking details; tax information and payment records. Juristic persons: the name of the legal entity; registration number; physical and postal address and contact details (email address, telephone number); names of contact persons; tax-related information; billing details; banking details; payment records. |
Retention period: until the contract is terminated or until consent to the processing of Personal Data is withdrawn. |
Legal ground: the processing is needed for a contract with you and/or your consent. |
2 | Providing access to the Service, simplifying account creation and account management, to protect our Services | Data subjects: Service user. |
List of Personal Data: surname, first name; email address; device and browser information (including the device identification number and type); network and connection information (including the Internet Service Provider (ISP) and the Internet Protocol (IP) addresses); device and browser identifiers and information; advertising identifiers; cookie identifiers and information. |
Retention period: until the contract is terminated or until consent to the processing of Personal Data is withdrawn. |
Legal ground: the processing is needed for a contract with you and/or your consent. |
3 | Company marketing (including to marketing and promotional communications) | Data subjects: Website visitor / customer / counterparty / representative of customer or counterparty. |
List of Personal Data: Natural persons: surname, first name; email address, telephone number, device and browser information (including the device identification number and type); network and connection information (including the Internet Service Provider (ISP) and the Internet Protocol (IP) addresses); device and browser identifiers and information; advertising identifiers; cookie identifiers and information. Juristic persons: the name of the legal entity; contact details (email address, telephone number); device and browser information (including the device identification number and type); network and connection information (including the Internet Service Provider (ISP) and the Internet Protocol (IP) addresses); device and browser identifiers and information; advertising identifiers; cookie identifiers and information. |
Retention period: until consent to the processing of Personal Data is withdrawn. |
Legal ground: your consent. |
4 | Publishing reviews on the Website with the aim of increasing customer loyalty and fostering a positive attitude amongst customers towards goods, works and services | Data subjects: customer / counterparty / representative of customer or counterparty. |
List of Personal Data: surname, first name; email address; still and video images of you. |
Retention period: until consent to the processing of Personal Data is withdrawn. |
Legal ground: your consent. |
5 | To respond to user inquiries/offer support to users, to request feedback | Data subjects: Website visitor / customer / counterparty / representative of customer or counterparty. |
List of Personal Data: surname, first name; email address; telephone number, data collected through metrics programs, log and usage data, device data. |
Retention period: until consent to the processing of Personal Data is withdrawn. |
Legal ground: your consent and/or the processing is needed for our legitimate interests. |
6 | To send administrative information to you | Data subjects: Service user / customer / counterparty / representative of customer or counterparty. |
List of Personal Data: Natural persons: surname, first name; email address; telephone number. Juristic persons: the name of the legal entity; contact details (email address, telephone number). |
Retention period: until the contract is terminated or until consent to the processing of Personal Data is withdrawn. |
Legal ground: your consent and/or the processing is needed for our legitimate interests. |
7 | Call recording | Data subjects: Website visitor / customer / counterparty / representative of customer or counterparty. |
List of Personal Data: human voice data. |
Retention period: until consent to the processing of Personal Data is withdrawn. |
Legal ground: your consent and/or the processing is needed for our legitimate interests. |
We process your Personal Data to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your Personal Data for other purposes.
3.4.
Limits on the Processing of Personal Data. Your Personal Data will not be stored for longer than is necessary for the purposes described in this Privacy Policy unless further retention is required by law or contractual obligation or otherwise reasonably required by us.
The processing of Personal Data is limited to the fulfilment of specific, pre-defined and legitimate purposes. The processing of Personal Data that is incompatible with the purposes for which it was collected is not permitted. Only Personal Data that is relevant to the purposes of its processing may be processed.
3.5.
Personal Data of minors. The Company does not intentionally process the Personal Data of minors. The Company recommends that only persons aged 18 or over use the Website. Responsibility for the actions of minors on the Website lies with their legal guardians. All visitors under the age of 18 must obtain permission from their legal guardians before providing any Personal Data about themselves.
If the Company becomes aware that it has received personal information about a minor without the consent of their legal guardians, such information will be deleted as soon as possible.
3.6. We do not process Personal Data about health, race or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, biometrics or criminal record.
3.7.
Information automatically collected.The Company processes Personal Data both with and without automated means. In doing so, the Company complies with the requirements for automated and non-automated Personal Data processing established by current legislation.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
3.8. All Personal Data that you provide to Us must be true, complete, and accurate, and you must notify us of any changes to such Personal Data.
As a general rule, the Company does not verify the accuracy of the Personal Data provided by Data subjects. The risk of providing inaccurate personal data, including providing third parties’ data as one’s own, is borne by the Data subject.
The Company assumes that:
(a) Data subject provides reliable and sufficient Personal Data in an up-to-date manner.
(b) Data subject is familiar with this Policy Privacy and expresses his informed and informed consent to it.
3.8.
How we collect your Personal Data? We collect most of your Personal Data directly from you when you fill out forms on Our Website or in your personal account, or interact with Us. We may also collect Personal Data from and about you using cookies and other similar tracking technologies (for more information, see Section 7 of Our Privacy Policy).
4. PRINCIPLES AND CONDITIONS FOR PROESSING PERSONAL DATA 4.1. Personal Data is processed for each processing purpose by:
- obtaining Personal Data orally and/or in writing directly from the Data subject of the Personal Data;
- maintaining Personal Data in the Company's logs, registers, and system data;
- using other methods of processing Personal Data.
4.2. When processing Personal Data, its accuracy, sufficiency, and relevance in relation to the purposes for which it is processed are ensured. The Company's processing of Personal Data is limited to achieving specific, predetermined, and legitimate purposes. Processing of Personal Data incompatible with the purposes for which it was collected is prohibited. Combining databases containing Personal Data processed for incompatible purposes is prohibited. The Company takes the necessary measures to delete or rectify incomplete or inaccurate data.
4.3. The Company has implemented, maintains, and regularly reviews the following technical and organisational measures to safeguard personal information against loss, destruction, unauthorised access, alteration, or disclosure:
4.3.1.
Technical Measures: Encryption –
Personal Data is encrypted both in transit and at rest using industry-standard cryptographic protocols.Access Control –
access to personal information is granted on a strictly need-to-know basis following the principle of least privilege. Each user is assigned a unique account with role-based permissions.Endpoint Protection –
all devices processing Personal Data are equipped with up-to-date antivirus and anti-malware software. Security patches and updates are applied in a timely manner.Backups –
regular backups of Personal Data n are performed, and restoration procedures are periodically tested. Backup copies are stored securely and separately from the primary infrastructure.Logging and Audit Trails –
comprehensive logs of access and operations involving Personal Data are maintained and regularly reviewed to detect anomalous or unauthorised activity.Secure Disposal –
when data storage media are decommissioned, disposal methods that prevent reconstruction of data are applied, including physical destruction and cryptographic erasure.Authentication.
Network Security.
4.3.2.
Organizational Measures:Information Officer (Data Protection Officer (DPO)) –
the Company has appointed a person responsible for the processing of Personal Data.Internal Policies –
written internal policies governing the handling, storage, and processing of Personal Data have been adopted and are binding on all employees.Staff Training –
all personnel, ensuring access to personal data, regular training on mandatory information security requirements.Confidentiality Agreements –
employees and third parties with access to Personal Data are required to sign written confidentiality agreements.Role-Based Access Restriction –
access to Personal Data is limited to those employees whose duties strictly require it, and access rights are reviewed periodically.Incident Response Plan –
a incident response plan is in place, covering identification, assessment, containment, notification, and recovery from security incidents.Breach Notification –
where there are reasonable grounds to believe that Personal Data has been accessed or acquired by an unauthorized person, the Company notifies the Information Regulator or other regulatory bodies and the affected Data subjects as soon as reasonably practicable, in accordance with the requirements of applicable law..Regular Audits –
the Company conducts periodic internal audits and assessments of the effectiveness of its security measures and updates them as necessary.4.3.3.
Operator Management:Written Contracts with Operators –
the Company enters into a written contract with every operator that processes Personal Data on its behalf. Each contract requires the operator to: process personal information solely on the documented instructions of the Company; maintain the confidentiality of all Personal Data; implement and maintain technical and organizational security measures; immediately notify The Company of any actual or suspected compromise of Personal Data.Non-Delegation of Accountability –
the Company retains full accountability for the security of Personal Data, even where processing is carried out by an operator on its behalf.
4.4.
Conditions for terminating the processing of Personal Data:
a) achievement of the purposes of processing Personal Data and the maximum retention periods for Personal Data;
b) loss of need to achieve the purposes of processing Personal Data;
c) provision by the Personal Data subject or their legal representative of information confirming that the Personal Data was obtained illegally or is not necessary for the stated purpose of processing;
d) impossibility of ensuring the lawfulness of the processing of Personal Data;
d) withdrawal of consent to the processing of Personal Data by the Data subject if the retention of Personal Data is no longer required for the purposes of processing Personal Data;
e) request by the Personal Data subject to the Company to cease processing Personal Data, except in cases stipulated by law;
g) expiration of the limitation periods for legal relations within the framework of which the processing of Personal Data is or was carried out;
h) liquidation or reorganization of the Company.
We will only keep your Personal Data for as long as it is necessary for the purposes set out in this Privacy Police, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).
When we have no ongoing legitimate business need to process your Personal Data, We will either delete or anonymise such information, or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then We will securely store your Personal Data and isolate it from any further processing until deletion is possible.
5. SHARING OF PERSONAL DATA 5.1.
Categories of recipients. We may share your data with third-party who perform services for us or on our behalf and require access to such information to do that work.
The Company may share Personal Data with the following categories of recipients:
(1) Operators – third parties engaged to process personal information on behalf of the Company, including but not limited to cloud hosting providers, payment processors, IT support providers, and marketing platforms. Sharing with operators is governed by written contracts, which require the operator to: process Personal Data solely on the documented instructions of the Company; maintain the confidentiality and security of personal information; immediately notify the Company of any actual or suspected compromise of Personal Data.
(2) Public or Regulatory Authorities – where disclosure is required by law, court order, or lawful request from a competent authority, including the Information Regulator, South African Police Service, or other regulatory bodies.
(3) Professional Advisors – legal counsel, auditors, and consultants in the course of providing professional services to the Company, subject to confidentiality obligations.
(4) Successors or Assignees – in the event of a merger, acquisition, restructuring, or sale of assets, personal information may be transferred to the successor entity, subject to the same protections afforded under this Privacy Policy.
5.2. The third parties we may share Personal Data with are as follows:
- Advertising, Direct Marketing, and Lead Generation:
Google Ads.
- Providing a platform for the provision of services:
GetCourse.io.
5.3.
Conditions for sharing. The Company ensures that:
(1) Personal Data is shared only for purposes compatible with the original purpose of collection, unless the Data subject has consented to a new purpose or sharing is otherwise permitted by law;
(2) recipients are informed of the confidential nature of the Personal Data and are required to protect it accordingly;
(3) the Company remains accountable for the personal information even when it is shared with operators, and does not delegate its accountability to any third party.
5.4.
Direct Marketing and Sharing for Marketing Purposes. The Company does not share personal information with third parties for their direct marketing purposes without the prior consent of the Data subject. Where Personal Data is used for the Company's own direct marketing, the Data subject has the right to opt out at any time.
5.5.
Breach Notification in case of shared Personal Data. Where there are reasonable grounds to believe that personal information shared with or held by an operator has been compromised, the Company notifies:
- the Information Regulator or other regulatory bodies as soon as reasonably practicable;
- the affected Data subjects as soon as reasonably practicable.
6. RIGHTS OF THE DATA SUBJECT 6.1. You have
certain rights under applicable data protection laws. These may include the right:
(1) to request access and obtain a copy of Your Personal Data,
(2) to request rectification or erasure;
(3) to restrict the processing of your Personal Data;
(4) if applicable, to data portability;
(5) not to be subject to automated decision-making.
In certain circumstances, нyou may also have the right to object to the processing of your Personal Data.
6.2. To request review, update or deletion of your personal data, as well as other requests related to the processing of personal data,
please contact Us by email: academy.zublab@gmail.com.
You will not be required to pay any fees to access your Personal Data or to exercise any of your other rights. To process your request, we must verify your identity. After you exercise any of these rights, we will take all reasonable steps to respond to your request within thirty (30) days of its receipt, notifying you either that we have complied with it or that there are objective reasons preventing us from doing so.
6.3.
Withdrawal of consent. If we process your personal data based on your consent, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting Us via email: academy.zublab@gmail.com.
However, please note that this will not affect the lawfulness of the data processing prior to your withdrawal, nor will it affect the processing of your Personal Data carried out on lawful grounds other than consent.
6.4.
Opting out of marketing and promotional communications (direct marketing). You can unsubscribe from our marketing and promotional communications (direct marketing) at any time by replying "STOP" or "UNSUBSCRIBE" to the SMS messages we send you or by contacting Us via email: academy.zublab@gmail.com. You will then be removed from our marketing lists. However, we may continue to communicate with you (for example, by sending you service messages necessary for the administration and use of your account, responding to support requests, or for other non-marketing purposes).
7. COOKIES AND SIMILAR TRACKING TECHNOLOGIES 7.1. We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.
We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising, including to help manage and display advertisements or to tailor advertisements to your interests. The third parties and service providers use their technology to provide advertising about products and services tailored to your interests which may appear either on our Services or on other websites.
Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.
8. OTHER CONDITIONS 8.1.
Cross-border transfers. In the event of cross‑border transfers of personal information beyond the Republic of South Africa, the Company applies the safeguards authorized under section 72 of POPIA и GDPR. As a standard measure, this includes concluding a Data Processing Agreement that ensures protections equivalent to those required by POPIA and GDPR. Where necessary, the client’s consent to such international transfers is secured at the stage of entering into the service agreement.
8.2.
Privacy Policy update. We may update this Privacy Policy from time to time. The updated version will be indicated by an updated 'Revised' date at the top of this Privacy Policy. If we make material changes to this Privacy Policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how we are protecting your information.
8.3.
Invalidity of individual provisions. The invalidity of individual provisions of this Privacy Policy, if such is recognized by a decision of a court or other authorized state body, does not entail its invalidity as a whole.
8.4.
Our contacts. If you have questions or comments about this notice, you may contact our Information Officer (Data Protection Officer (DPO)) by email at academy.zublab@gmail.com, or contact Us by post at:
4ZL (PTY) LTD
47 ASH ROAD, KYALAMI AH, GAUTENG, 1649.
8.5. If you are unsatisfied with the manner in which we address any complaint with regard to our processing of personal information, you can contact the office of the regulator, the details of which are:
The Information Regulator (South Africa)
General enquiries: enquiries@inforegulator.org.za
Complaints (complete POPIA/PAIA form 5): PAIAComplaints@inforegulator.org.za & POPIA Complaints@inforegulat or.org.za
4ZL (PTY) LTD
Registration number: 2025 / 550843 / 07
Address: 47 ASH ROAD, KYALAMI AH, GAUTENG, 1649
Email: academy.zublab@gmail.com