Privacy Policy
Last updated: 6 September 2026
Responsible Party / Information Officer
When I Am Gone (Pty) Ltd, Office 8, PineworX, Lonsdale Way, Pinelands, Cape Town, 7405, South Africa.
Privacy contact (for the Information Officer): Natalie Macdonald Spence, support@wheniamgone.co.za
Regulator: Information Regulator (South Africa) - inforegulator.org.za
1. Introduction
When I Am Gone (Pty) Ltd ("we", "our", "us") looks after your privacy. We handle your personal information under the Protection of Personal Information Act 4 of 2013 (POPIA) and any other data protection laws that apply.
This policy covers the personal vault, will preparation, practitioner portal, legal notice services, consultations, support and optional communications. WIAG is the responsible party for its own account, billing and service administration. Where a practitioner determines why client information is processed, that practitioner may be a separate responsible party and WIAG may act as its operator under written instructions. The parties remain responsible for their respective legal duties.
2. Information We Collect
Account Information
When you create an account, we collect:
- Email address (for authentication and communication);
- Name (optional, for personalisation);
- Phone number (optional, for account recovery); and
- For practitioners: firm name, regulatory body, practice number and any verification evidence you submit.
Vault Data
Private vault content is encrypted in your browser using a key derived from your passphrase. Account records, file names, categories, dates and other metadata can remain readable by the service. Will preparation, contacts, practitioner matters and support may also involve information processed in readable form. If you choose a supported document-sharing workflow, the document may be decrypted for server scanning and then encrypted for authorised access. Browser encryption does not apply to every record on the platform.
Legal Notice and Practitioner Matter Data
When you use the practitioner portal, we process the matter details you enter, such as the deceased's name, identity number, dates and notice text. We need these to draft and publish the notice. Unlike vault data, this information is processed in plain text on our servers because it has to be sent to the Government Printing Works or newspapers for publication.
Payment Information
Payments are processed by Paystack. We receive a transaction reference and status but do not receive or store your full card number.
Usage Information
We automatically collect:
- Log data (IP address, browser type, access times);
- Device information (device type, operating system); and
- Usage patterns (features used, pages visited).
3. How We Use Your Information
We use your information to:
- Provide and maintain our services;
- Authenticate your identity and secure your account;
- Send important service notifications and transactional email;
- Prepare exports you request and, where separately enabled, process explicit practitioner sharing; public LifeKey executor and trusted-contact requests are paused;
- Verify practitioner credentials and lodge legal notices on your instructions;
- Improve our service and develop new features; and
- Comply with legal obligations.
3A. Grounds for processing
Account administration and requested services may require processing to perform our contract with you. Legal record-keeping and lawful reporting may require processing to comply with legislation. Security, fraud prevention and the defence of legal claims may rely on a lawful and proportionate legitimate interest. Optional electronic marketing requires consent or the limited existing-customer exception allowed by POPIA section 69. We must identify an appropriate ground for each purpose, and further use must be compatible with the original purpose or independently authorised.
3B. Sensitive information and information about others
Health, religious, biometric and other special personal information, and children’s information, require the additional authorisations in POPIA. Where GDPR applies, an Article 9 condition may also be required. Include another person’s information only where you have a lawful basis to do so, and provide the relevant privacy notice where required. A person’s inclusion as a beneficiary or contact does not authorise marketing to them. An adult account holder cannot give consent on behalf of every other adult. Encryption does not remove these requirements.
4. Data Security
Encryption protects private vault content, but does not make every record anonymous or remove our data protection duties. Your vault passphrase is not stored on our servers. The service also uses the following safeguards:
- Encrypted connections between your browser and our servers;
- Encrypted storage of our database and uploaded files, managed by our hosting providers;
- Hashing of one-time verification codes and session tokens before storage;
- Regular security reviews, dependency audits and monitoring; and
- Strict role-based access controls for our staff.
5. Sub-processors and Data Sharing
We do not sell personal information. Service providers process the information needed for their assigned functions. Some act as operators on our instructions; payment providers, publishers and independent professionals may also have their own legal responsibilities. The relevant services include:
- Replit and its infrastructure providers supply application hosting, the managed database and storage infrastructure. Their processing can include account records, readable service records, metadata and encrypted vault content.
- Google Cloud Storage stores uploaded objects through the hosting arrangement. Encryption and access rules depend on the upload or sharing workflow.
- Paystack processes payments. WIAG receives transaction references and payment status, but not your full card number.
- Resend and, where enabled, Twilio deliver email and SMS. Recipient details and message content are processed for delivery.
- Sentry and Plausible, where enabled support error diagnostics and optional public-page analytics respectively. Optional analytics requires your separate choice.
- AI service providers, where an AI feature is enabled may process the prompt and information you submit to that feature. Do not include vault passphrases or unnecessary identity, health or children’s information in prompts or support messages.
- Government Printing Works, newspapers and authorised practitioners receive information required for a publication or professional service you request. Publication can make the notice publicly accessible.
We may also share personal information with a practitioner you explicitly authorise through any separately enabled sharing feature, and with law enforcement or regulators where legally required. Public LifeKey access-request sharing is paused during private review.
6. Cross-border Transfers and International Data Processing
Our service uses international providers, including Replit, Google Cloud, Resend and Paystack. Information may be processed outside South Africa. A provider’s country of incorporation does not establish the actual location of every server, backup or support team. Contact the Information Officer for the providers, locations and transfer safeguards relevant to your information.
Each transfer needs an applicable ground under POPIA section 72. These grounds include adequate protection under a law, binding corporate rules or a binding agreement under section 72(1)(a); consent under section 72(1)(b); or the specific contractual necessity grounds under sections 72(1)(c) and (d). A general acceptance of this policy, encryption or a payment provider’s security certification does not by itself establish a lawful transfer. Where GDPR applies, its separate international-transfer requirements must also be met.
Categories of data transferred
- Account information (email address, name, phone number);
- Vault metadata (record counts, dates, activity logs);
- Transactional data (payment references, subscription status); and
- Any personal information you store in the plain-text sections of your vault (such as executor, beneficiary, and guardian details submitted via the will generator or contact manager).
Your rights
You may ask what information is transferred, to whom and on what legal basis. Where we rely on consent, you may withdraw it prospectively. We will explain any service consequence and whether another lawful ground applies. Withdrawing optional analytics or marketing consent does not cancel your vault account.
Cross-border transfer enquiries
For enquiries specifically about cross-border data transfers, contact our Information Officer at support@wheniamgone.co.za.
7. Your data protection rights
Subject to the applicable legal requirements, you may:
- Ask whether we hold your personal information and request access to it;
- Ask us to correct inaccurate information or delete information we are no longer entitled to retain;
- Object to processing on the grounds provided by law and object to direct marketing;
- Withdraw consent for future processing that depends on consent;
- Ask for reasons if a request is refused, including the legal basis for any retention or restriction; and
- Complain to the Information Regulator without first completing our internal complaints process.
To make a request, use our data rights form or email support@wheniamgone.co.za. You do not need an active account. We may ask for proportionate identity or authority verification. We aim to respond within 21 calendar days, subject to the applicable legal deadline and any lawful extension. We will explain a refusal or delay and your complaint options.
7A. Where GDPR applies
GDPR can apply where processing falls within its territorial scope, including relevant activities of an EU establishment, offering goods or services to people in the EU, or monitoring their behaviour there. It is not determined by nationality alone. Where it applies, you also have the applicable rights of access, rectification, erasure, restriction, objection and, where its conditions are met, data portability. You may complain to a competent supervisory authority. We must respond without undue delay and ordinarily within one month; a permitted extension requires reasons and notice within the first month. POPIA access rights are distinct from GDPR portability. An account export may omit records and is not a substitute for a complete rights response.
8. Data Retention
We keep personal information only for a stated purpose and for as long as a lawful retention ground applies. Account closure starts a deletion process; it is not proof that every record, object or backup has been erased. The service applies a 30-day account-deletion waiting period, but unresolved records or storage failures can require manual completion. Contact us for confirmation of the scope and status of deletion. Necessary tax, transaction, dispute and regulatory records may be retained separately, with restricted use, for the applicable period. FICA retention applies to the records and activities covered by that Act, not automatically to every vault file.
Backup copies may remain until they expire under the relevant retention arrangements. They must not be used for ordinary processing after a valid deletion request. Any disaster recovery must account for earlier deletion requests before restored information returns to ordinary use. We must confirm deletion coverage before describing a request as fully completed.
9. Contact Us
For privacy-related inquiries or to exercise your rights, contact us at:
Email: support@wheniamgone.co.za
Address: When I Am Gone (Pty) Ltd, Office 8, PineworX, Lonsdale Way, Pinelands, Cape Town, 7405, South Africa.
You may also lodge a complaint directly with the Information Regulator at inforegulator.org.za.
9A. Self-drafting acknowledgement log
We record the date, time and source IP address when you confirm that you are drafting your own will. This supports fraud prevention and the investigation of a genuine dispute. Retention must be justified for those purposes or a specific legal obligation; this acknowledgement does not permit indefinite retention of all your information.
9B. Analytics and conversion measurement
Optional Plausible analytics helps us measure visits to approved public pages. It loads only after you select Allow analytics. We exclude account, vault, payment and token routes, remove URL query strings and fragments, and do not send contact details or free-form record content.
Meta Pixel and Google Ads tags are disabled. Allowing optional analytics does not authorise advertising or identity matching. You can stop future optional analytics on this browser through Privacy choices on our Cookie Policy page by selecting Essential only.
External server-side conversion measurement is paused. Registration, will and payment conversions are not sent to advertising platforms. Hashing an email address or phone number with SHA-256 does not make it anonymous. Operational audit and lifecycle records remain subject to the purposes and retention rules described in this policy.
9C. Security compromises
Where POPIA section 22 applies, we must notify the Information Regulator and affected data subjects as soon as reasonably possible, subject to its specific exceptions and permitted delays. POPIA does not provide a general 72-hour waiting period. Where GDPR applies, a notifiable breach must be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness; communication to affected people is separately required without undue delay where the applicable high-risk threshold is met. We must assess both regimes independently.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service, and update the "Last updated" date at the top of this page.