Privacy Policy
How Map My Future (a trading name of GAMCO Investments (Pty) Ltd, registration number 2018/096618/07) collects, uses, safeguards and, where required, discloses your personal information.
GAMCO Investments (Pty) Ltd, a company duly incorporated under the laws of the Republic of South Africa with registration number 2018/096618/07, trading as Map My Future (“Map My Future”, “we”, “us”, “our”), is the Responsible Party in respect of the personal information described in this Privacy Policy, as that term is defined in the Protection of Personal Information Act, 2013 (Act 4 of 2013) (“POPIA”). This Privacy Policy explains what personal information we collect, why we collect it, how we use and safeguard it, with whom we share it, and the rights you have in relation to it. It should be read together with our POPIA Notice and Terms & Conditions.
1. Personal Information We Collect
We collect the following categories of personal information directly from you when you create an account, complete the assessment, or upgrade to the Pro tier:
1.1 Contact details
- Full name
- Email address
- School name
1.2 Academic information
- Current grade level (Grade 10, 11 or 12)
- Subjects taken and most recent marks (NSC or IEB)
- Intended faculty, course or career direction
1.3 Psychometric information
- Responses to the RIASEC vocational interests battery
- Responses to the Big Five personality dimensions
- Responses framed on Super’s Career Development Theory
- Career maturity and decisional-readiness responses
1.4 Demographic information
- Age
- Grade and home language
- Province or region (where provided)
1.5 Payment information
If you upgrade to the Pro tier, payment is processed by PayFast, a registered South African payment service provider. PayFast collects and processes your card and billing details directly. Map My Future does not receive, see, or store your card number, CVV, expiry date or bank account details. We retain only a record of the transaction (reference number, amount, date, status) for accounting and audit purposes.
1.6 Technical information
- IP address
- Browser type and version
- Device type and operating system
- Usage analytics (pages visited, time on site, interactions with the assessment)
2. How We Use Your Personal Information
We use the personal information described above for the following purposes:
- Generating personalised course matches and a strength profile based on your academic and psychometric inputs
- Surfacing bursary opportunities relevant to your profile, faculty interests and chosen universities
- Providing AI-generated course insights and a personalised report on the Pro tier
- Processing Pro tier payments through PayFast and issuing receipts
- Improving the platform, the matching logic and the question set over time
- Complying with legal, regulatory, tax and audit obligations
- Sending operational communications (account confirmation, payment receipts, service notices)
- Sending optional communications (product updates, tips) only where you have expressly opted in
3. Lawful Basis for Processing (POPIA §11)
We process your personal information on one or more of the following lawful bases:
- Consent — for example, when you submit your assessment responses or opt in to receive product communications.
- Performance of a contract — where processing is necessary to deliver the Pro tier services you have paid for.
- Legitimate interest — for example, to improve our service, prevent fraud and abuse, and maintain security.
- Compliance with a legal obligation — for example, tax record retention under the Income Tax Act and the Companies Act.
4. Processing of Children’s Information (POPIA §35)
Map My Future’s services are designed for students aged 15 to 18. POPIA classifies persons under 18 as children. By accepting these terms and submitting personal information through Map My Future, the user warrants that they have obtained the necessary consent from a parent or legal guardian to do so. Where a parent or guardian becomes aware that their child has used Map My Future without their consent, they may contact our Information Officer to request access to, correction of, or deletion of the child’s personal information.
5. Data Retention
We retain your personal information only for as long as necessary for the purposes set out in this Privacy Policy, subject to the following category-specific periods:
- Free tier accounts: 24 months from your last login, after which the account is deleted or the data is de-identified.
- Pro tier accounts: 36 months from the date of purchase, after which the account is deleted or the data is de-identified.
- Payment records: 5 years, in line with the South African Revenue Service record-retention requirements and the Companies Act, 2008.
- Anonymised analytics: retained indefinitely for product improvement; this data cannot be linked back to you.
You may request earlier deletion at any time by contacting our Information Officer. We will action the request within 30 days, subject to any overriding legal obligation to retain the data.
6. Security Safeguards (POPIA §19)
We take reasonable technical and organisational measures to protect your personal information against loss, unauthorised access, alteration or disclosure, including:
- Encrypted storage on Supabase (AES-256 at rest) with TLS encryption in transit
- HTTPS enforced across the entire site and application
- Access controls limiting backend data access to authorised personnel only
- Operator agreements with all third-party processors requiring equivalent safeguards
- Periodic review of access logs and security configurations
No internet-based service can guarantee absolute security. While we take the safeguards above seriously, you acknowledge that transmission of information over the internet carries inherent risk. If we become aware of a security compromise that affects your personal information, we will notify you and the Information Regulator as required by section 22 of POPIA.
7. Sharing Your Information
We share your personal information only with the following categories of recipients, and only to the extent necessary:
7.1 Operators (POPIA §1)
- Supabase — cloud database and authentication, hosted on Amazon Web Services
- n8n on Railway — workflow automation for the matching engine
- Anthropic — AI processing of anonymised matching prompts for course insights
- PayFast — payment processing for Pro tier upgrades
- Email service provider — transactional email delivery
Each operator is bound by a written agreement requiring them to process your information only on our instructions and to maintain appropriate security safeguards.
7.2 No sale to third parties
We do not sell, rent or otherwise make your personal information available to universities, schools, bursary providers, advertisers or any other third-party marketers.
7.3 Legal authorities
We may disclose your personal information to a law enforcement, regulatory or court authority where required by law or court order.
8. Cross-Border Transfers (POPIA §72)
Some of our operators (including Supabase, Anthropic and Railway) process data on servers located outside the Republic of South Africa. Where personal information is transferred outside South Africa, we rely on one or more of the transfer grounds permitted by section 72 of POPIA, namely:
- Transfer to a jurisdiction that provides an adequate level of data protection, or
- Binding contractual undertakings with the recipient that uphold POPIA-equivalent standards, or
- The consent of the data subject, where applicable.
9. Cookies and Similar Technologies
Map My Future uses a small number of cookies and similar technologies, limited to:
- Strictly necessary cookies — session cookies used to keep you logged in and to remember your progress through the assessment.
- Analytics cookies — where applicable, used in aggregate form only to understand how the platform is used.
We do not use third-party advertising cookies, cross-site tracking pixels, or behavioural advertising technologies. You may disable cookies in your browser settings, but some parts of the service may not function correctly if you do.
10. Your Rights as a Data Subject
Under section 5 of POPIA, you have the right to:
- Be notified that your personal information is being collected and, where applicable, that it has been accessed or acquired by an unauthorised person
- Request access to the personal information we hold about you
- Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully
- Object, on reasonable grounds, to the processing of your personal information
- Object to processing for the purposes of direct marketing
- Not be subject to a decision based solely on automated processing where that decision results in legal consequences for you
- Submit a complaint to the Information Regulator (South Africa)
- Institute civil proceedings regarding alleged interference with the protection of your personal information
To exercise any of these rights, contact our Information Officer (details below). We will respond within 30 days.
11. Third-Party Links
Our platform may link to external websites, including university application portals and bursary providers. We are not responsible for the privacy practices or content of those websites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or by a prominent notice on the platform. The “Last reviewed” date at the top of this page indicates when the policy was last updated. Continued use of Map My Future after a change takes effect constitutes acceptance of the revised policy.
13. Contact Us
Email: support@mapmyfuture.co.za
Phone: +27 83 274 8678
GAMCO Investments (Pty) Ltd · Registration 2018/096618/07
36 Woodlands Ave, Hurlingham Manor, Johannesburg, 2195
If you are not satisfied with our response to a request or complaint, you may lodge a complaint with the Information Regulator (South Africa) — see our POPIA Notice for contact details.