Compliance 01
Universal Privacy & Data Sovereignty Policy
At Braai, privacy is not a transactional setting—it is a non-negotiable sovereign digital right. We operate under strict cryptographic data minimization and zero-surveillance architecture.
Last Updated: 25 August 2026
1. Statutory Scope & Data Controller Classifications
This Universal Privacy and Data Sovereignty Policy governs the collection, processing, and protection of personal data across the global Braai ecosystem.
- South African Domicile (POPIA Act 4 of 2013): Braai (Pty) Ltd operates as the statutory Responsible Party. Cross-border transfers of personal data to international infrastructure partners are governed strictly under POPIA Section 72 Standard Contractual Clauses (SCC) ensuring equivalent statutory data protection.
- European Union & United Kingdom (GDPR / UK GDPR): Braai operates as the Data Controller under Regulation (EU) 2016/679 and the UK Data Protection Act 2018.
- California (CCPA / CPRA): Braai certifies that it does NOT sell, rent, or share personal information with third-party data brokers or advertising networks.
2. Non-Custodial Identity & Local-First Architecture
Braai is architected around self-sovereign cryptographic primitives:
- Decentralized Identifiers (W3C DIDs): Users own and control their cryptographic key pairs. Braai maintains zero custodial possession of user private keys.
- Flames Physical Credentials (AS-015): Encrypted NFC/RFID cards adhering to ISO/IEC 18013-5 standards for offline biometric identity attestation.
- Local-First Encryption: Sensitive preferences and message drafts reside on your device in an encrypted Drift SQLite vault. Synchronized state replicates via secure PowerSync encrypted streams.
3. Algorithmic Constitution & Non-Addictive Design
The Algorithmic Invariant: The Braai Network shall not intentionally optimise user engagement through the amplification of harmful, addictive, or deceptive content.
- Zero Infinite Scroll: Feeds feature natural breaks and time-well-spent limits to respect human attention.
- Zero Surveillance Advertising: We do not deploy cross-site tracking cookies, behavioral tracking pixels, or third-party advertising SDKs.
- On-Device Safety Scanners: Content moderation tools (such as the Flame Filter and Predatory Language Scanner) execute on-device and at the private edge strictly for CSAM detection, abuse prevention, and physical threat mitigation. Safety telemetry is never monetized.
4. Information We Process & Purpose Limitation
| Data Category | Purpose & Processing Basis | Retention Perimeter |
|---|---|---|
| Cryptographic Identity (DIDs, Public Keys) | Network authentication and verifiable credential verification. | Active lifecycle until account termination. |
| Date of Birth (Zero-Knowledge Age Tier) | Structural age classification (Child, Teen, Adult) to gate minor safety. | Converted to cryptographic capability attestation. |
| Fulfillment Delivery Data (Marketplace) | Physical artisan order delivery via independent merchants. | Merchant must permanently purge within 30 days of delivery. |
| Financial KYC / Card Details | Regulated banking acquiring and fiat settlement behind Perimeter Gateways. | Retained exclusively by licensed banking partners; Braai never stores raw PANs. |
5. Universal Data Subject Rights (POPIA / GDPR / CCPA)
All users worldwide possess enforceable statutory rights:
- Right of Access & Portability (POPIA s23 / GDPR Art 15 & 20): Export complete account attestations, order history, and ledger journals in open JSON/CSV format at any time.
- Right to Rectification & Erasure (POPIA s24 / GDPR Art 16 & 17): Correct inaccurate personal records or request complete deletion of identity profiles and non-financial data.
- Right to Human Explainability: Receive a plain-language human explanation for any automated trust score or moderation action with direct appeal to the Technical Architecture Council.
6. Statutory Information Officer & Supervisory Authority Contact
For data rights requests or formal inquiries, contact our designated Data Protection Officer:
- Information Officer: Braai (Pty) Ltd Privacy & Compliance Office
- Email:
[email protected] - Supervisory Recourse: You have the statutory right to lodge a complaint directly with the South African Information Regulator (
[email protected]) or your national Data Protection Authority (DPA).
© 2026 Braai (Pty) LTD. All rights reserved.
Proprietary compliance architecture. Do not reproduce.
Proprietary compliance architecture. Do not reproduce.