Legal

Security & Data Breach Notice

Last updated: 1 October 2026 · Applies to the DeeMusiq app, website and backend services.

1. Purpose and scope

This notice describes the safeguards DeeMusiq ("we", "us") applies to personal information, what happens if a security compromise occurs, and the extent to which liability is limited under the laws of the Republic of South Africa. It forms part of, and must be read together with, our Privacy Policy and Terms of Service. Where this notice conflicts with the Protection of Personal Information Act 4 of 2013 ("POPIA") or any other applicable law, the law prevails.

2. Safeguards we maintain

In terms of section 19 of POPIA, we maintain generally accepted information-security practices and procedures appropriate to the nature of the information we process, including, without limitation:

  • encryption of traffic between the app and our services, and encryption of sensitive fields at rest;
  • pseudonymisation of direct identifiers (for example, phone numbers are stored as keyed hashes, never in plaintext);
  • role-based access controls, separate administrative credentials, and audit logging of access to personal information;
  • rate limiting, automated abuse detection and network-level protection of our infrastructure;
  • retention limits and scheduled deletion of operational data; and
  • self-service export and deletion of your personal information within the app.

3. No absolute security

No method of transmission over the internet or method of electronic storage is completely secure. While we implement and continuously improve the safeguards described above, we cannot and do not guarantee absolute security, and you provide information to us with an understanding of this inherent risk. This acknowledgment does not relieve us of any duty imposed by law, including the duty to maintain reasonable safeguards under section 19 of POPIA.

4. Breach notification commitment

If we become aware of a security compromise in which personal information was accessed or acquired by an unauthorised person, we will, as required by section 22 of POPIA:

  • notify the Information Regulator (South Africa) as soon as reasonably possible;
  • notify affected data subjects by email (if registered) and in-app notification, unless the identity of the data subjects cannot be established or a lawful exemption applies; and
  • include in that notification the information contemplated by section 22(5) of POPIA, to the extent known: what happened, what information is affected, what we are doing about it, and what you can do to protect yourself.

We commit to issuing user-facing notifications within 72 hours of confirming a notifiable breach where reasonably feasible.

5. Limitation of liability

To the maximum extent permitted by applicable law, and without excluding, limiting or waiving any right or remedy that cannot lawfully be excluded, limited or waived:

  • DeeMusiq, its members, officers, employees, contractors and operators shall not be liable for any indirect, incidental, special, consequential or punitive damages, or any loss of profits, data, goodwill or opportunity, arising out of or in connection with a security compromise, unauthorised access, or loss or alteration of data, howsoever caused;
  • our aggregate liability arising from or in connection with any security incident shall, to the extent such limitation is lawful, be limited to the amounts (if any) paid by you to DeeMusiq in the three (3) months preceding the event giving rise to the claim;
  • nothing in this notice excludes or limits liability for gross negligence or wilful misconduct, any liability under section 99 of POPIA or other statutory liability that cannot be excluded by agreement, or any right you hold under the Consumer Protection Act 68 of 2008 that cannot lawfully be waived.

Any exclusion or limitation in this notice applies only to the extent permitted by law; where a court or the Regulator finds a provision unenforceable, the remainder continues in full force.

6. Prospective application

This notice takes effect from the date of its publication and applies prospectively. It does not, and cannot, alter, extinguish or limit any right, remedy or obligation in respect of any incident that occurred before that date; such matters remain governed by the law and the terms in force at the relevant time.

7. Your responsibilities

  • Keep your device and the DeeMusiq app up to date; only install the app from our official download page and verify the published SHA-256 checksum where offered.
  • Do not share your account credentials or device signing keys.
  • Report suspected vulnerabilities or breaches promptly (see section 8).

8. Responsible disclosure

Security researchers may report vulnerabilities to [email protected]. Our disclosure contacts are published in machine-readable form at /.well-known/security.txt. We will not pursue legal action against good-faith research that respects user privacy, does not degrade the service, and gives us reasonable time to remediate before publication.

9. Governing law

This notice is governed by the laws of the Republic of South Africa. Nothing in it limits your right to approach the Information Regulator (South Africa) — complaints: inforeg.org.za — or any competent court.