Holla Africa

Privacy Policy

Elephant · operated on the Holla Africa platform · Version 2026-09-07

This policy explains how we handle your personal information under South Africa's Protection of Personal Information Act, 2013 (POPIA). It forms part of our Terms & Conditions. The responsible party is the operator of this club on the Holla Africa platform; contact us via in-app Live Support.

1. What we collect

  • Identity: name and surname, South African ID number (or passport), date of birth, and the documents you upload for verification (ID, proof of address, proof of bank account).
  • Contact: mobile number and email address.
  • Financial: deposits, withdrawals, your own-name bank account details for payouts, and payment-provider references. We never see or store full card numbers — cards are processed by the payment provider.
  • Play: your game rounds, bets, wins, bonuses and balances.
  • Technical: device/IP information and session logs used for security and fraud prevention.
  • Support: your Live Support conversations.

2. Why we process it (and the lawful basis)

  • To run your account and pay you — performance of our contract with you.
  • Age and identity verification, AML monitoring and reporting — legal obligations under FICA and gambling legislation.
  • Fraud prevention, duplicate-account and security checks — our legitimate interest in a safe platform, and your protection.
  • Responsible-gambling tools (limits, self-exclusion) — legal obligation and your protection.
  • Marketing messages — ONLY with your consent (opt-in at registration, withdrawable at any time in your account or by replying STOP). We never make marketing a condition of playing.

3. Who we share it with

  • Payment providers — to process your deposits and payouts.
  • Identity-verification and fraud-prevention partners — to meet FICA duties.
  • Game suppliers/aggregator — receive a pseudonymous player code and play data needed to run the games, not your identity documents.
  • Messaging providers — to send you the SMS/WhatsApp messages you have asked for (OTPs, alerts, opted-in marketing).
  • Authorities — the Financial Intelligence Centre, regulators, SAPS or courts, where the law requires.

We never sell your personal information. Every processor working for us is bound by contract to protect it.

4. Where it is processed

Your information is stored on our servers and may be processed by service providers (e.g. payment, verification or messaging providers) whose infrastructure is outside South Africa. Where that happens, POPIA's cross-border rules apply: we transfer only to providers subject to equivalent protection or bound by contract to POPIA-level safeguards.

5. How long we keep it

  • Account, identity and transaction records: at least 5 years after the business relationship ends — FICA requires this even if you ask for deletion earlier.
  • Self-exclusion records: for the exclusion period and as long as needed to enforce it.
  • Support conversations and security logs: up to 5 years.
  • Marketing preferences: until you withdraw consent or close your account.

When a retention period ends, records are deleted or anonymised.

6. How we protect it

Encrypted connections (HTTPS) throughout; passwords stored only as strong one-way hashes; identity documents on private storage with staff access logged; role-based staff permissions with audit trails; and payment-card processing fully delegated to the payment provider so card numbers never touch our servers. No system is perfectly secure — if a breach ever affects your data we will notify you and the Information Regulator as POPIA requires.

7. Your rights (POPIA)

  • Access: ask what personal information we hold about you (a PAIA request — we respond within the statutory period).
  • Correction: ask us to fix inaccurate details (identity fields are corrected by staff with supporting documents).
  • Deletion: ask us to delete information we are not legally required to keep (see clause 5 for FICA retention we cannot waive).
  • Objection: object to processing based on legitimate interest.
  • Marketing opt-out: withdraw marketing consent at any time — in your account settings, by replying STOP, or via support.
  • Complaint: you may complain to the Information Regulator (South Africa) — JD House, 27 Stiemens Street, Braamfontein, Johannesburg; [email protected].

Exercise any of these via in-app Live Support. We verify identity before releasing data.

8. Cookies & local storage

We use strictly necessary cookies/local storage only: your login session, security (CSRF) protection, and remembering in-app preferences. We do not run third-party advertising trackers on the platform.

9. Children

The platform is strictly 18+. We do not knowingly process children's information; any account found to belong to a minor is closed and its data handled per clause 5's legal-retention rules.

10. Changes

Material changes to this policy are announced in the app and the version date above updates. Continued use after a change means acceptance.