Last updated: 19.08.2026
Calabash.courses is operated by The Calabash of Knowledge (Pty) Ltd, a company registered in South Africa under registration number 2016/055019/07, with its address at 133 George Avenue, Fairfield, Johannesburg, 2196, South Africa.
In this policy, "we", "us" and "our" mean The Calabash of Knowledge (Pty) Ltd. "You" means anyone who visits our website or holds a Calabash account.
We are the responsible party for your personal information under South Africa's Protection of Personal Information Act (POPIA), and the data controller under the UK GDPR where that law applies to you.
This policy covers calabash.courses and all of its regional and application subdomains.
How to contact us about your information
Information Officer: Kyla Edinburg, Chief Executive Officer Email: privacy [at] calabash.courses Post: The Information Officer, The Calabash of Knowledge (Pty) Ltd, 133 George Avenue, Fairfield, Johannesburg, 2196, South Africa
Our Information Officer is registered with the Information Regulator of South Africa.
Information you give us when you register: your first name, last name, email address, password, professional registration number, and country.
Your professional registration number is the number issued to you by your professional regulator, for example the HPCSA in South Africa or the PsyBA in Australia. We collect it because continuing professional development records are only useful to you if they are tied to the registration they support.
Information about your learning: the courses and talks you access, your progress through them, your quiz answers and scores, the time you spend on course material, and the certificates we issue to you.
Information about your payments: a record of what you bought, when, in which currency, and the invoice we issued. Payments are processed by Stripe. Your card number never reaches our systems.
Information you send to support: the content of any support request you submit through the platform, and our replies.
Information collected automatically: your IP address, browser type and version, operating system, device type, the pages you visit, and how you move through them. Some of this is collected by the analytics and advertising tools described under "Cookies and tracking" below.
We do not ask you for your identity number, passport number or date of birth. We do not ask you for, and we ask that you do not send us, any information about your own health, or any clinical or case material about the people you work with.
Under POPIA and the UK GDPR we have to have a lawful ground for every use of your information. Ours are set out below.
To give you the service you signed up for - creating and running your account, giving you access to the courses and talks you have paid for, tracking your progress, issuing your certificates, taking payment, and sending you service messages such as receipts and password resets. Ground: performance of our contract with you.
To keep records of the professional development you have completed - so that you can produce evidence to your regulator, and so we can reissue a certificate years later if you need one. Ground: performance of our contract with you, and our legitimate interest in maintaining reliable records of what we certified.
To run and improve the platform - diagnosing faults, understanding which courses are used and where people get stuck, and planning what to build next. Ground: our legitimate interests in operating and improving a service you find useful.
To recommend content to you - we suggest talks and CPD plan content based on what you have watched and completed, and we adapt the content of some of our emails to reflect your activity and your professional field. Ground: our legitimate interests in making the service relevant to you. See "Automated recommendations" below.
To send you our newsletter and marketing emails - about new courses, talks and features. Ground: your consent. If you are already a customer, we may also rely on the exception in section 69(3) of POPIA, and the equivalent rule in the UK, which lets us tell existing customers about services similar to ones they have already bought. Either way you can stop it at any time, and every marketing email contains an unsubscribe link.
To advertise on Facebook and Instagram - see "Advertising" below. Ground: your consent.
To meet our legal obligations - keeping tax and accounting records, and responding to lawful requests from regulators, courts and law enforcement. Ground: compliance with a legal obligation.
To establish, exercise or defend legal claims. Ground: our legitimate interests in protecting our position, and in some cases a legal obligation.
We do not sell your personal information. We share it with the service providers below. Each of them is bound by a written agreement that permits them to use your information only to provide their service to us. Locations are as published by each provider and can change.
| Provider | What they do | Where your data sits |
| xneelo | Hosting for our website, application and database | Germany |
| Stripe | Payment processing | Ireland, the United States and other locations Stripe operates from |
| Mailjet | Sending our service emails and our newsletter | European Union |
| Vimeo | Hosting and delivering course video | United States |
| Website analytics (Google Analytics) | United States and other locations Google operates from | |
| Hotjar | Website analytics and session recording | European Union |
| Meta | Advertising on Facebook and Instagram | United States and other locations Meta operates from |
We may also disclose your information where we are required to by law, where we need to in order to establish or defend a legal claim, or where we reasonably believe disclosure is necessary to prevent fraud or harm.
If our business is sold or merged, your information may transfer to the new owner. We will tell you before that happens and explain what it means for you.
We use cookies and similar technologies for three purposes:
Necessary cookies keep you signed in, remember your preferences, and keep the site secure. The site does not work without them, so we do not ask for consent to set them.
Analytics cookies and tools tell us how the site is used. We use Google Analytics, and we use Hotjar, which records how visitors move through the site and produces heat maps showing where people click and scroll. We configure Hotjar to mask information typed into form fields, so it does not capture what you enter. This helps us find parts of the site that confuse people.
Advertising cookies let us measure and target our advertising. We use the Meta pixel, which reports back to Meta when you visit our site or take an action such as starting a subscription.
We ask for your consent before setting analytics and advertising cookies, and you can change or withdraw that choice at any time through the cookie settings link in our website footer. Withdrawing consent does not affect anything we did before you withdrew it.
We advertise on Facebook and Instagram. To do that, we do two things you should know about.
We use the Meta pixel on our website, which tells Meta when a visitor has been to our site and what they did there.
We also upload customer lists to Meta to build what Meta calls Custom Audiences. The list contains your name, email address and country. It is hashed before it is sent, meaning it is converted into an unreadable string that Meta matches against its own hashed records. Meta then shows our adverts to people who are already our customers, and builds "Lookalike Audiences" of other people with similar characteristics so we can advertise to them. We do this for customers in South Africa, Australia and the United Kingdom.
For this activity, we and Meta are joint controllers under the UK GDPR, meaning we are both responsible for it. Meta's own terms describe how it handles the information, and you can control how Meta uses your information for advertising through your Facebook or Instagram ad settings.
We rely on your consent for this, which you give or refuse through our cookie settings. You can also email privacy [at] calabash.courses at any time and we will remove you from the lists we upload, whatever your cookie settings say.
We use your activity on the platform to recommend talks and CPD content to you, and to decide which content goes into some of the emails we send you. This is automated, but it only affects what we show you. It has no effect on your access to the service, what you pay, whether you pass an assessment, or any certificate we issue. There is no automated decision-making that produces legal effects for you or similarly significantly affects you.
You can object to this profiling at any time by emailing privacy [at] calabash.courses. You have an absolute right to object to profiling for direct marketing purposes, and we will stop if you ask.
Our servers are in Germany, and several of the providers listed above are outside South Africa, the United Kingdom and Australia.
For transfers out of South Africa, we rely on section 72 of POPIA. Germany and the European Union have data protection law that provides a level of protection substantially similar to POPIA. Where a provider is in a country without comparable law, we rely on our contract with that provider, which binds it to standards equivalent to POPIA, or on the transfer being necessary to perform our contract with you.
For transfers out of the United Kingdom, we rely on the UK's adequacy regulations where they cover the destination, and on the UK International Data Transfer Agreement or the UK Addendum to the European Commission's Standard Contractual Clauses where they do not.
| What | How long |
| Accounts that are never confirmed |
Deleted |
| Your account and profile | For as long as your account exists. If you stop using Calabash we disable the account and keep the records below |
| CPD and course completion records, and certificates issued | Indefinitely, unless you ask us to delete them |
| Payment and invoice records | Seven years, to meet our obligations under the Companies Act and tax law |
| Support requests | Three years from the date the request is closed |
| Marketing preferences and the record of your consent | Until you withdraw, and then a minimal record that you withdrew |
| Website analytics data | As set by our Google Analytics and Hotjar retention settings |
| Database backups | 24 hours |
We keep completion records and certificates indefinitely on purpose. Professional regulators audit CPD activity years after the fact, and practitioners regularly come back to us for evidence of courses they completed long ago. If you would prefer we did not, you can ask us to delete them, but you should download your certificates first, because we will not be able to reissue them.
If you want your information deleted rather than retained, email privacy [at] calabash.courses and tell us. Some information will survive deletion where we are legally required to keep it, principally financial records.
Whether you are in South Africa, the United Kingdom, Australia or elsewhere, you can ask us to:
tell you what we hold about you and give you a copy;
correct anything that is wrong or incomplete;
delete your information, subject to the records we are required to keep;
stop or restrict a particular use of your information;
give you a copy of the information you gave us in a common, machine-readable format;
stop using it for direct marketing, which we will always do, no questions asked; and
object to a use we have justified by our legitimate interests, including profiling.
Email privacy [at] calabash.courses. We will respond within 30 days. We do not charge for this, unless a request is clearly excessive or repetitive, in which case we will tell you what it costs before we do anything.
You can also ask for access to records under the Promotion of Access to Information Act. Our PAIA manual explains how, and is available on our website.
If you are unhappy with how we have handled your information, tell us first at privacy [at] calabash.courses. We will acknowledge your complaint within 30 days and respond as quickly as we can. If we do not resolve it, you can complain to:
South Africa: the Information Regulator, JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. Email: enquiries@inforegulator.org.za. Toll free: 0800 017 160. Web: inforegulator.org.za
United Kingdom: the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Web: ico.org.uk/make-a-complaint
Australia: the Office of the Australian Information Commissioner, GPO Box 5288, Sydney NSW 2001. Web: oaic.gov.au/privacy/privacy-complaints
We take reasonable steps to protect your information. Traffic between your browser and our site is encrypted in transit, and requests over an unencrypted connection are redirected to an encrypted one. Your password is stored using a strong one-way hashing algorithm, which means we cannot see it and cannot recover it for you. If you would rather not use a password at all, you can sign in with a single-use link sent to your email address. Our servers are hosted in Germany and the database is backed up daily, with backups retained for 24 hours. Access to the database and the administrative interface is restricted to a small number of named people, and sign-ins to those systems are logged. Card details are handled entirely by Stripe and are never stored on our systems.
No system is completely secure. If a security compromise affects your personal information, we will notify the Information Regulator and, where the law requires it, you, as soon as reasonably possible after we establish what happened.
Please choose a password you do not use anywhere else.
Calabash is a professional development service for registered practitioners and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, email privacy [at] calabash.courses and we will delete it.
Our site links to other websites, and our courses are delivered through video hosted by Vimeo. When you follow a link away from Calabash, this policy stops applying and the other site's policy takes over. We are not responsible for how other sites handle your information.
We update this policy from time to time. The date at the top tells you when we last did. If we make a change that materially affects how we use your information, we will tell you by email or through the platform before it takes effect, rather than relying on you to notice.
ACT (Acceptance and Commitment Therapy/Theory): Fusion vs Defusion and Avoidance vs Acceptance