/legal/popia

Privacy and POPIA

Vulos publishes an operating system and open-source apps that you run on your own machine. We operate no service that holds your data, so the only personal information in scope here is what this website unavoidably involves — request logs, and email you choose to send us. This page sets out that scope, your rights under the Protection of Personal Information Act 4 of 2013 (POPIA), and how to exercise them.

POPIA Act 4 of 2013Information Regulator (SA)No accounts, no trackingLast reviewed 2026-07-24

Section 1

What personal information exists

This is a static website: a folder of files served by a web server. It has no database, no API, no accounts and no login. In full, here is everything that touches personal information:

  • Web-server request logs

    Our host records the ordinary details of each request — IP address, the page asked for, the time, and the browser user-agent string. This is how a web server works; it is the technical minimum for serving a page and keeping the site available. Legal basis: legitimate interest under POPIA s11(1)(f).

  • Email you send us

    If you write to privacy@vulos.org or any other address of ours, we hold your message and address for as long as it takes to deal with what you asked, and then for as long as we might reasonably need to refer back to it. Legal basis: consent (s11(1)(a)) — you chose to write — and legitimate interest in answering you.

  • Nothing else

    No analytics, no tracking pixels, no advertising tags, no third-party fonts, no embedded widgets, no newsletter list. The site sets no cookies; your light-or-dark theme choice is stored in your own browser and never leaves it. There is no account to create and no form to fill in.

  • And nothing at all from the software

    Your files, mail, calendar, contacts, keys and AI context live on your own machine. They are not sent to us and we have no way to reach them. Where the software needs somewhere to store or route something, you choose that provider — see how the software handles data.

For the website, Vulos is the Responsible Party under POPIA. For anything on your own box, you are — see data processing.


Section 2

Your rights under POPIA

POPIA confers the following rights. All of them are exercised the same way here: email privacy@vulos.org. There is no dashboard, because there is no account behind which to put one.

POPIA s23

Right of Access

You may ask whether we hold personal information about you and receive a copy of it. Given the scope above, the honest answer is usually “only a server log line, and only if you tell us roughly when and from which address”. Ask at privacy@vulos.org and we will reply within 30 days.

POPIA s24

Right to Correction or Deletion

You may ask us to correct, destroy or delete personal information that is inaccurate, irrelevant, excessive or unlawfully obtained. A South African quirk: POPIA s24 couples correction and deletion in one right, where the GDPR splits them across Art.16 and Art.17. We honour both.

POPIA s25

Right to Object

Where we rely on legitimate interest — in practice, only web-server logs — you may object on grounds relating to your particular situation. We stop unless there are compelling legitimate grounds that override the objection, or the information is needed for legal claims.

POPIA s11(3)

Withdrawal of Consent

Where we rely on consent — in practice, only a message you sent us — you may withdraw it at any time and ask us to delete the correspondence. Withdrawal does not undo processing that was lawful before it.

POPIA s69

Complaint to the Regulator

You may complain to the Information Regulator (South Africa) if you believe your POPIA rights have been infringed: inforegulator.org.za. We would rather you gave us a chance to fix it first at privacy@vulos.org, but that is your call, not a precondition.

POPIA s18

Notification of Collection

When personal information is collected, s18 requires you to be told who is collecting it, why, and whether it is voluntary. This page is that notice. Section 1 above lists everything collected and why; none of it is mandatory, and you can read the whole site without sending us anything but a request log line.

Email privacy@vulos.org with the subject POPIA request. We reply within 30 days, and usually much sooner — there is very little to look through. We may ask you for enough detail to find the records you mean, and to be reasonably satisfied you are who you say you are before handing anything over.


Section 3

Information Officer

POPIA makes the head of a private body its Information Officer, responsible for compliance with the Act and for dealing with requests. Reach ours at privacy@vulos.org — the address is monitored by the person who holds that role, and a message sent there is a message to the Information Officer.


Section 4

Cross-Border Transfers

Under POPIA s72, personal information may leave South Africa only in defined circumstances. Our position is short, because there is almost nothing to move:

  • This website is served from Johannesburg

    The site runs as a static container in the jnb region. Its host, Fly.io, Inc., is a United States company, so request logs are handled by a company outside South Africa as part of providing the hosting. This is the only ordinary transfer we make, and s72(1)(b) — necessity for performance of the contract that gets the page to you — is what it rests on.

  • Your data goes nowhere, because we never have it

    There is no customer bucket, no managed instance and no region to choose, because we store nothing for you. Where your box keeps its data — and therefore which country it sits in — is your decision and your provider’s jurisdiction, not ours.


Section 5

Security Compromise

POPIA s22 requires a Responsible Party to notify the Information Regulator and the affected people as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person. If that ever happens to the small set of information described in Section 1 — our request logs or our mailbox — we will do exactly that, and say plainly what was involved and what we did about it.

A compromise of your box is not something we can detect or notify you about; we have no visibility into it. That duty travels with the data, and the data is with you. To report a vulnerability in the software itself, write to security@vulos.org.

Information Regulator (SA): inforegulator.org.za · inforeg@justice.gov.za


Section 6

POPIA-Specific Definitions

Key POPIA terms, and where Vulos sits in relation to each:

POPIA TermDefinition & Vulos context
Personal informationInformation relating to an identifiable, living, natural person or an identifiable, existing juristic person (s1). Broader than the GDPR, which covers natural persons only — in South Africa, information about a company can be personal information too.
Responsible PartyWhoever determines the purpose and means of processing — the GDPR’s “controller”. Vulos is the Responsible Party for this website’s request logs and its mailbox. For everything on your own box, you are.
OperatorSomeone who processes personal information for a Responsible Party under a mandate — the GDPR’s “processor”. Vulos is nobody’s Operator. We hold no mandate and receive no data, so the written-mandate requirements of s20 and s21 have nothing to attach to.
ProcessingAny operation on personal information — collection, receipt, recording, storage, updating, retrieval, use, dissemination, merging, erasure or destruction (s1). Far broader than the colloquial sense: simply storing a log line is processing.
Special personal information (s26)Information about religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health, sex life, biometrics or criminal behaviour. We neither collect nor process any. If you keep such information on your own box, s26 and s27 apply to you as the Responsible Party.
Children’s information (s34)Personal information about a person under 18, which s34 protects with a general prohibition subject to limited exceptions. This website is not directed at children and collects nothing beyond what Section 1 describes.
De-identificationAltering information so that it cannot be linked to a person without separately kept information (s1). Relevant to how you handle records on your own box; we hold no records to de-identify.

Exercise your rights

Access, correction, deletion, objection or withdrawal — one address, answered by the Information Officer.

Email privacy@vulos.org →

Data processing

Why there is no data-processing agreement, who is responsible for what, and what the licence grants and disclaims.

Read data processing →

How the software handles data

Where your data sits, who holds the keys, and what you can verify for yourself in the source.

Software and data →