← Back to Astrea
Astrea Legal

Privacy Notice

How Astrea processes and protects personal and sensitive information.

1. RECORDAL

1.1. Astrea operates an online platform designed to assist persons with the preparation, compilation and administration of applications for the appointment of an administrator in terms of section 60 of the Mental Health Care Act, 17 of 2002.

1.2. In providing the Services, Astrea necessarily Processes Personal Information relating to Users, Applicants, Patients, Proposed Administrators and other persons whose information may be relevant to an Application.

1.3. The nature of an Application may require Astrea to Process highly sensitive information, including identity documents, medical information, mental-health information, financial information, asset information and information concerning family relationships.

1.4. Astrea recognises the constitutional right to privacy and is committed to Processing Personal Information lawfully, reasonably and in a manner which does not unjustifiably infringe the privacy of Data Subjects.

1.5. This Privacy Notice records the categories of information Processed, purposes of Processing, lawful bases, recipients, safeguards, rights of Data Subjects and procedures for exercising those rights.

2. INTERPRETATION

2.1. "Applicant" means the person making the section 60 Application.

2.2. "Application" means an application for appointment of an administrator prepared using the Platform.

2.3. "Astrea" means Astrea Holdings Proprietary Limited.

2.4. "Data Subject", "Personal Information", "Processing", "Responsible Party", "Operator" and "Special Personal Information" bear the meanings assigned to them in POPIA.

2.5. "Patient" means the person in respect of whose property the appointment of an administrator is sought.

2.6. "Platform" means Astrea's website, applicant portal, administrative systems and related technology.

2.7. "POPIA" means the Protection of Personal Information Act, 4 of 2013, as amended.

2.8. "Proposed Administrator" means the person proposed for appointment as administrator.

3. RESPONSIBLE PARTY

3.1. Astrea acts as Responsible Party where it determines the purpose and means of Processing.

3.2. Astrea's final registered company details and Information Officer contact particulars shall be published prior to public launch.

4. APPLICATION OF THIS POLICY

4.1. This Policy applies to Personal Information Processed through the Website, registration, Applications, uploaded documents, email, telephone communications, payment administration, Courier administration, support interactions, security logs and other legitimate means.

4.2. It applies whether Personal Information is collected directly from a Data Subject or lawfully supplied by another person.

5. APPLICANT INFORMATION

Astrea may Process the Applicant's names, surname, identity number, date of birth, contact details, physical address, occupation, relationship to the Patient, identity documentation, login credentials, correspondence and instructions.

6. PATIENT INFORMATION

Astrea may Process the Patient's names, identity number, date of birth, age, gender, residential information, family information, occupation, identity documentation, care information, medical and mental-health information, information concerning decision-making capacity, assets, liabilities, income, expenditure, bank accounts, pensions, investments, property, vehicles and supporting documentation.

7. PROPOSED ADMINISTRATOR INFORMATION

Astrea may Process the Proposed Administrator's name, identity number, contact details, occupation, relationship to the Patient, residential and business addresses, identity documents and suitability-related information required for the Application.

8. THIRD-PARTY INFORMATION

Astrea may Process limited information concerning spouses, children, next of kin, carers, medical practitioners, service providers, witnesses, investigators, officials of the Master's Office and other persons legitimately relevant to the Application.

9. TECHNICAL INFORMATION

Astrea may Process IP addresses, browser information, device information, login dates and times, session information, security events, audit trails and other technical information reasonably required to operate and secure the Platform.

10. PAYMENT INFORMATION

Astrea may Process payment references, proofs of payment, account-holder information appearing on payment records, payment dates, amounts and invoice information.

Astrea presently uses EFT as its primary payment method and does not require Users to provide payment-card credentials directly to Astrea.

11. SPECIAL PERSONAL INFORMATION

11.1. Astrea expressly acknowledges that Applications may contain Special Personal Information, particularly medical and mental-health information.

11.2. Astrea shall not Process Special Personal Information merely because such information may be commercially useful or interesting.

11.3. Such information shall be Processed only where reasonably necessary and where a lawful basis under POPIA or other applicable law exists.

12. PURPOSES OF PROCESSING

Astrea may Process Personal Information to:

12.1. create and administer User accounts;

12.2. verify identity;

12.3. receive Application information;

12.4. prepare prescribed forms;

12.5. generate Application Packs;

12.6. identify supporting documentation;

12.7. communicate with Users;

12.8. verify payment;

12.9. arrange Courier collection;

12.10. record Application status;

12.11. provide support;

12.12. maintain security and audit records;

12.13. prevent fraud;

12.14. comply with legal obligations;

12.15. defend or enforce legal rights;

12.16. maintain accounting records; and

12.17. improve Platform reliability and security using appropriately minimised information.

13. LAWFUL BASIS FOR PROCESSING

13.1. Astrea shall not rely indiscriminately on consent for every Processing activity.

13.2. Depending on the circumstances, Processing may occur because:

13.2.1. the Data Subject has consented;

13.2.2. Processing is necessary for conclusion or performance of a contract;

13.2.3. Processing complies with an obligation imposed by law;

13.2.4. Processing protects a legitimate interest of the Data Subject;

13.2.5. Processing is necessary for a legitimate interest of Astrea or a third party, subject to applicable rights; or

13.2.6. another lawful basis applies.

14. MANDATORY AND VOLUNTARY INFORMATION

14.1. Certain information is mandatory because Astrea cannot generate a usable Application Pack without it.

14.2. Other supporting information may be voluntary.

14.3. Failure to provide mandatory information may result in Astrea being unable to proceed.

15. INFORMATION OBTAINED INDIRECTLY

15.1. Due to the nature of section 60 Applications, Applicants may provide Personal Information relating to Patients and other persons.

15.2. Astrea may therefore receive information indirectly.

15.3. Astrea shall Process such information only to the extent reasonably necessary and lawful.

16. USER RESPONSIBILITY FOR THIRD-PARTY INFORMATION

16.1. A User submitting information about another person warrants that it is supplied for a lawful purpose connected with the Application.

16.2. The User shall not submit unlawfully obtained records, irrelevant private information, information for harassment or surveillance, or information known to be false.

17. INFORMATION QUALITY

17.1. Astrea shall take reasonably practicable steps to ensure Personal Information within its control is complete, accurate and not misleading having regard to the purpose of Processing.

17.2. Astrea nevertheless relies substantially on information supplied by Users.

18. DATA MINIMISATION

18.1. Astrea shall endeavour to collect only information which is adequate, relevant and not excessive having regard to the purpose for which it is Processed.

18.2. Astrea shall not intentionally design the Platform to collect sensitive information unrelated to the section 60 process.

19. DISCLOSURE OF PERSONAL INFORMATION

19.1. Astrea does not sell Personal Information.

19.2. Astrea may disclose information where reasonably necessary to the Master, a court, an appointed investigator, an appointed Courier, hosting and infrastructure providers, email providers, professional advisers, auditors, accountants, regulators, law-enforcement authorities or persons authorised by the Data Subject.

19.3. Disclosure shall be limited to information reasonably necessary for the relevant purpose.

20. COURIER INFORMATION

20.1. For collection purposes, Astrea may disclose the Applicant's name, contact details, collection address, reference number and reasonable collection instructions to a Courier.

20.2. Astrea shall not disclose the full substantive contents of an Application merely because a Courier is providing transport services, unless reasonably necessary and lawful.

21. OPERATORS AND SERVICE PROVIDERS

21.1. Astrea may appoint Operators to perform hosting, cloud storage, email delivery, cybersecurity, backup, maintenance, document processing or other support functions.

21.2. Where required by POPIA, Astrea shall ensure appropriate written arrangements requiring Operators to preserve confidentiality and implement reasonable security safeguards.

22. INFORMATION SECURITY

22.1. Astrea shall implement appropriate and reasonable technical and organisational measures designed to preserve confidentiality and integrity of Personal Information.

22.2. Safeguards may include authentication controls, password hashing, role-based access, restricted administration access, encrypted transport, controlled document access, secure hosting, system logging, backup procedures, vulnerability management, confidentiality controls and incident-response procedures.

23. NO ABSOLUTE SECURITY WARRANTY

23.1. Astrea takes information security seriously but does not warrant that any electronic system is incapable of compromise.

23.2. Nothing in this clause diminishes Astrea's obligation to maintain appropriate safeguards.

24. SECURITY COMPROMISES

24.1. Where there are reasonable grounds to believe that Personal Information has been accessed or acquired by an unauthorised person, Astrea shall investigate the circumstances.

24.2. Where required by law, Astrea shall notify the Information Regulator and affected Data Subjects.

24.3. Astrea shall take reasonable steps to contain, investigate and remediate a security compromise.

25. RECORD RETENTION

25.1. Astrea shall not retain Personal Information longer than necessary to achieve the purpose for which it was collected or subsequently Processed, subject to lawful retention requirements.

25.2. Astrea may retain records where required by law, for evidentiary purposes, for establishment or defence of legal rights, for financial or tax purposes or to resolve complaints.

25.3. Upon expiry of the applicable period, Astrea shall securely delete, destroy or de-identify Personal Information where reasonably practicable.

26. BACKUPS

26.1. Personal Information may temporarily remain in secure backups following deletion from active systems.

26.2. Backup copies shall ordinarily be restored only for disaster recovery, business continuity or legitimate security purposes.

27. CROSS-BORDER PROCESSING

27.1. Astrea may use technology providers whose infrastructure is located outside South Africa.

27.2. Where information is transferred outside South Africa, Astrea shall take reasonable steps to ensure that the transfer complies with section 72 of POPIA or another lawful mechanism.

28. DIRECT MARKETING

28.1. Astrea distinguishes transactional communications from direct marketing.

28.2. Transactional communications may include verification, payment, document-generation, Application, Courier and security messages.

28.3. Electronic direct marketing shall be undertaken only as permitted by applicable law.

29. COOKIES AND SIMILAR TECHNOLOGIES

29.1. The Website may use cookies and comparable technologies for authentication, session management, security, essential functionality, preferences and lawful analytics.

29.2. Astrea shall not knowingly deploy unnecessary non-essential tracking without appropriate notice and, where required, consent.

30. AUTOMATED PROCESSING

30.1. Astrea uses software to populate and generate documents using information supplied by Users.

30.2. Such automation does not determine whether an administrator will be appointed and does not substitute the Master's statutory decision.

31. DATA SUBJECT RIGHTS

Subject to applicable law, a Data Subject may have the right to inquire whether Astrea holds Personal Information, request access, request correction, request deletion where justified, object to Processing, withdraw consent where consent is the lawful basis, object to direct marketing and lodge a complaint with the Information Regulator.

32. ACCESS TO PERSONAL INFORMATION

32.1. Requests for access may be directed to Astrea's Information Officer.

32.2. Astrea may require adequate proof of identity and information reasonably necessary to locate the relevant record.

32.3. Access may be subject to PAIA where applicable.

33. CORRECTION AND DELETION

33.1. A Data Subject may request correction or deletion where permitted by law.

33.2. Astrea may decline deletion where continued retention is required by law, required as evidence, necessary for legal rights or otherwise lawfully justified.

34. PERSONS WITH IMPAIRED CAPACITY

34.1. Astrea acknowledges that the very nature of a section 60 Application may concern a Patient whose capacity to manage property or affairs is in issue.

34.2. Astrea shall approach such information with enhanced sensitivity and shall not treat the creation of an Application as permission for indiscriminate disclosure.

35. CHILDREN'S INFORMATION

35.1. Astrea does not provide its standard Applicant Services to persons under 18 acting in their own capacity as Applicants.

35.2. An Application may nevertheless contain limited information concerning children who are family members of the Patient.

36. MASTER OF THE HIGH COURT

36.1. Submission of an Application necessarily entails disclosure of relevant information to the Master.

36.2. Once information has lawfully been submitted, the Master's subsequent Processing is governed by the Master's statutory responsibilities and applicable law.

36.3. Astrea does not control the Master's internal systems or information practices.

37. INVESTIGATORS

37.1. Where the Master appoints an investigator, relevant information may be disclosed pursuant to the lawful mandate.

37.2. Astrea does not determine whether an investigator is appointed, the identity of the investigator or what information the investigator lawfully requires.

37.3. Where Themis is appointed, information shall be Processed pursuant to that lawful mandate and applicable privacy obligations.

38. ASTREA AND THEMIS

38.1. Astrea and Themis are separate juristic persons.

38.2. Their separate ownership or commercial relationship does not permit unrestricted sharing of Personal Information.

38.3. Any disclosure between them must have an appropriate lawful basis.

39. CHANGE OF OWNERSHIP OR RESTRUCTURING

39.1. If Astrea undergoes a lawful merger, restructuring or sale of business, Personal Information may form part of transferred business records subject to applicable Data Protection Laws.

40. LEGAL DISCLOSURES

Astrea may Process or disclose information where reasonably necessary to comply with legislation, court process, lawful regulatory requirements, investigation of fraud, establishment or defence of rights or protection of legitimate safety interests, subject to applicable law.

41. PERSONAL INFORMATION IMPACT ASSESSMENTS

Astrea shall conduct and maintain appropriate privacy impact assessments for material Processing activities, particularly those involving medical records, identity documents, estate information, administrator access, cloud infrastructure, email transmission, backups and third-party integrations.

42. ACCESS CONTROLS AND INTERNAL CONFIDENTIALITY

42.1. Access to sensitive Application information shall be limited according to legitimate operational need.

42.2. Persons granted access shall be subject to appropriate confidentiality obligations.

42.3. Personal Information shall not be accessed out of curiosity or for private purposes.

43. COMPLAINTS

43.1. Privacy complaints may be directed to Astrea's Information Officer.

43.2. Nothing in this Policy prevents a person from lodging a complaint with the Information Regulator.

44. CHANGES TO THIS POLICY

44.1. Astrea may amend this Policy to reflect changes in law, regulation, technology, the Platform or its Processing activities.

44.2. Historical legal acceptance records shall continue to record the version applicable when an Application was submitted.

Version: 1.1
Effective date: 22 August 2026