Privacy Policy

How Enzi handles personal information

This Privacy Policy explains how Enzi Family Tree ("Enzi", "we", "us", or "our") collects, uses, stores, shares, and protects personal information when you use our websites, apps, and related services.

Last updated: 23 July 2026

Scope

This policy applies to personal information processed in connection with Enzi's mobile apps, web experiences, invitations, support processes, and family collaboration features.

Applicable frameworks

We aim to process personal information in a manner consistent with the principles of the EU General Data Protection Regulation (GDPR) and the South African Protection of Personal Information Act, 2013 (POPIA), to the extent those laws apply to a specific user or processing activity.

1. Responsible party / controller

Enzi Family Tree is responsible for deciding why and how personal information is processed for the core operation of the service. Questions about this policy may be sent to support@enziapp.com.

2. Information we collect

  • Account details such as your name, email address, and login credentials.
  • Profile and family-tree information that you submit or manage.
  • Stories, photos, biographies, and relationship details you choose to add.
  • Invitation, approval, and family-linking metadata.
  • Support communications and bug reports you send us.
  • Technical logs needed for security, diagnostics, and service reliability.

3. Special personal information and children's data

Because family-tree services may involve ancestry, relationships, dates, and other sensitive context, users should only upload personal information they are authorised to share. Where required by law, you must obtain consent or have another valid legal basis before sharing information about another person.

4. How we use information

  • To create and maintain user accounts and family trees.
  • To authenticate users and secure the platform.
  • To enable invitations, relationship management, and collaboration features.
  • To provide support, fix issues, and improve the service.
  • To comply with legal obligations and enforce our terms.

5. Legal bases for processing

Depending on the context, we rely on one or more of the following: contract necessity, legitimate interests, consent, compliance with legal obligations, or another lawful basis recognised under GDPR and POPIA.

6. Account verification and security

We may require email verification before a new account can access Enzi. This helps us reduce fraudulent sign-ups, secure family data, and confirm that account-recovery messages are delivered to the right inbox.

7. Sharing and disclosure

We may share personal information with service providers, infrastructure providers, analytics or security vendors, professional advisers, or competent authorities where necessary to operate the service, meet legal obligations, protect rights, or investigate abuse. We do not sell personal information.

8. Service providers and subprocessors

We may use third-party providers for authentication, database hosting, file storage, crash diagnostics, email delivery, payments, and customer support. Those providers may process personal information only on our documented instructions and subject to appropriate confidentiality and security obligations.

9. International transfers

Your information may be processed in countries other than your own. When cross-border transfers are required, we take reasonable steps to ensure adequate protection, including appropriate contractual, technical, or organisational safeguards where required.

10. Security safeguards

We implement reasonable technical and organisational measures designed to protect confidentiality, integrity, and availability, including access controls, email verification, role-based access, encrypted transport, logging, and least-privilege access where practical. Media files and internal administration tools are restricted to authenticated access.

11. Security incidents

If we become aware of a personal-information breach that is likely to create material risk, we will investigate, contain the issue, and notify affected parties or regulators where required by applicable law.

12. Retention

We retain personal information only for as long as necessary for the purpose for which it was collected, to provide the service, meet legal obligations, resolve disputes, prevent fraud, or enforce agreements.

13. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, withdrawal of consent, or data portability. POPIA users may also lodge a complaint with the Information Regulator, and GDPR users may lodge a complaint with their competent supervisory authority.

14. Deletion and account closure

You may request deletion of your account or personal information by contacting support@enziapp.com. We may retain limited records where necessary to satisfy legal, fraud, security, backup, or dispute-resolution requirements.

15. Cookies and local storage

Our web experiences may use cookies or similar technologies necessary for authentication, security, session continuity, performance, and product improvement. You can manage these through your browser settings where available.

16. Changes to this policy

We may update this policy from time to time. We will post the revised version here with a new effective date, and where required we will take additional steps to notify users.

17. Contact us

For privacy requests or concerns, contact support@enziapp.com.

Important: This policy is intended to reflect the operational controls and privacy principles used by Enzi. If your organisation uses Enzi in a regulated or enterprise context, you may need additional disclosures, contractual terms, or jurisdiction-specific notices.