Legal
Privacy Policy
How Creating Health collects, uses, and protects your personal information in accordance with POPIA.
Version: 1.2 · 20 August 2026.
1. Who we are
Creating Health is the digital home of Dr Bernard Brom’s writing, protocols and teaching. We take the privacy of your personal information seriously, and we handle it in line with South Africa’s Protection of Personal Information Act 4 of 2013 (‘POPIA’).
For the purposes of POPIA, the responsible party — the person who decides why and how your information is processed — is Dr Bernard Brom, trading as Creating Health (a sole proprietorship). Our Information Officer can be reached at hello@creatinghealth.co.za. You can always reach a human; we read every message.
2. What information we collect, and why
We try to collect as little as we can, and only what the platform genuinely needs.
- Your email address — when you sign up for the newsletter, create an account, or make a purchase. We use it to send you what you asked for and to manage your membership.
- Your name (optional) — to address you personally and manage your account.
- Payment information — to take payment and manage your subscription. We never see or store your full card number (see below).
- Your membership tier and status — so we can unlock the content your tier includes.
- Health information you choose to share — only if you volunteer it, for example when asking Bernard a question. This is sensitive, and we treat it specially (see section 3).
- Messages you send us — so we can read and reply.
- Reflections and conversations you post — what you write in the community rooms, or as a reflection under a piece of writing, together with your first name. We use it to carry the conversation you joined. Where you write it decides who can see it: see ‘What you write, and who sees it’ below.
- Basic, privacy-friendly usage data — to keep the site fast and understand what’s useful. We do not build an advertising profile of you.
- Your ‘stillness’ preference — if you set a reduced-motion preference, it is stored in your own browser so we can respect it on your return.
About your card details. We never see or store your full card number. Card payments are handled entirely by our payment processor, PayFast — a South African PCI-DSS Level 1 Service Provider gateway. For recurring memberships, PayFast securely stores (‘tokenises’) your card on its own systems and gives us only a reference, never the card number itself.
Watermarked downloads. When you download a members’ PDF (for example a Mind Map), we stamp it with your email address and member ID. This makes each copy traceable to the member who downloaded it and discourages sharing of paid material. Embedding your email and member ID in the file is itself a processing of your personal information, and we tell you so here.
3. Special information — your health
Some of what people share on a health platform is, by its nature, sensitive. Under POPIA, information about your health is ‘special personal information’, and the law sets a higher bar for handling it.
We do not ask you for health information as a condition of joining, and most of the platform never touches it. The one place it can arise is if you choose to describe your own situation — for example, when asking Bernard a question. In that case we ask for your explicit consent separately, at the moment you submit, with a dedicated tick-box — never bundled into our general terms. We use it only to let Bernard read and answer your question. If Bernard shares an answer with the wider membership, we strip your name and anything else that could identify you first. This promise covers questions you send us privately. It does not cover things you choose to publish yourself — a reflection under an article, or a post in one of the community rooms, carries your first name because that is what makes it a conversation. Please do not put anything about your own health into a reflection that you would not want a stranger to read. If you have something private to ask Bernard, send it to us directly instead, and the paragraph above applies to it in full. You can withdraw your consent and ask us to delete your question at any time. Please do not share details of a medical emergency through the platform — contact your local emergency services.
4. What you write, and who sees it
Not everything you write on Creating Health is equally visible, and we would rather you knew exactly which is which.
- The community rooms (The Circle, The Lounge) are for members only. They are closed to search engines, and only members whose membership opens that room can read them.
- Reflections under a piece of writing sit on the page itself, under your first name. If the writing is open to everyone, the reflection is too — visible to any visitor, and to search engines and AI assistants that read the page. If the writing is behind the membership, so is the reflection.
- Questions you send us directly are private between you and Bernard, and are covered by the health paragraph above.
You can take down anything you wrote yourself, at any time, using the ‘retract’ control beneath it: a reflection, a reply, or something you said in one of the rooms. Closing your account works differently, and it is worth knowing before you post: we take your name off what you wrote, and the words themselves stay where they are. A conversation other members answered is not yours alone, and deleting it would take their replies with it. Section 8 sets out exactly what comes off and what remains. What we cannot reach are copies that search engines or AI systems have already made, which is the honest reason we ask you to think before you post something personal.
5. Who processes your information for us
We use a small number of trusted specialist services to run the platform. Each one only handles the data it needs, under contract, and none may use your information for their own purposes:
- PayFast (South Africa) — payments and subscriptions.
- Supabase (European Union — Frankfurt) — secure sign-in, your account, and the community conversations you take part in.
- Beehiiv — the newsletter.
- Sanity (European Union) — the content library.
- Resend — account and receipt emails.
- Vercel (European Union — Frankfurt) — hosting and privacy-friendly analytics.
We keep this list current. If we add or change a material service, we will update this policy.
6. Your information leaves South Africa
We want to be straight with you about this. Our website runs on servers in Frankfurt, in the European Union, and several of the services above are based in the European Union or the United States. That means your personal information is processed outside South Africa. POPIA allows this (section 72), and we rely on the following:
- For services in the European Union, the EU’s data-protection regime (the GDPR) provides a level of protection broadly comparable to POPIA.
- For services in the United States, we rely on the data-processing contracts we have in place with each provider, which require them to protect your information to comparable standards, and on the fact that the transfer is necessary to provide the service you asked for.
- Where we rely on your consent (for example the newsletter), that consent also covers the cross-border element, which we disclose to you here.
If you would like more detail about the protections in place for any specific service, please ask us.
7. Cookies and analytics
We have deliberately kept this light. We do not use advertising cookies, and we do not track you across other websites. Our analytics are privacy-friendly and are about how the site performs, not about profiling you. Strictly necessary cookies keep the site working and, once you sign in, keep you securely signed in — these are essential to a service you asked for. Your motion preference is stored in your own browser, not sent to us. Because we do not set advertising or third-party tracking cookies, you won’t be met with an intrusive cookie wall. If that ever changes, we will ask for your consent first.
8. Your rights
POPIA gives you real control over your information. You may:
- ask what we hold about you, and why;
- correct or update anything that is wrong;
- ask us to delete information we no longer have a reason to keep, or to close your account entirely — write to us and we’ll confirm within 30 days. Your name and address come off everything we hold. Anything you wrote in a conversation other members took part in stays where it is, without your name on it, and payment records the law requires us to keep are kept but no longer point to you;
- object to a particular use, where we rely on legitimate interest;
- withdraw consent at any time — for example, unsubscribe from the newsletter (every issue has a one-click unsubscribe);
- complain — first to us, and if we don’t resolve it, to the Information Regulator (see section 11).
To exercise any of these, write to us at hello@creatinghealth.co.za. We may need to confirm your identity first, to protect your information.
9. How long we keep it
We keep your information only as long as we have a reason to: account and membership data for as long as you have an account and a reasonable period afterwards for our legal, tax and accounting duties; your newsletter subscription until you unsubscribe; any health information you shared only as long as needed to answer you, or until you ask us to delete it; and payment records for as long as the law requires.
What you write in the community rooms, including the live room in The Circle, is kept as part of the record of those conversations, for as long as we run them. A live room can feel as though it passes. It does not: nothing said there is deleted on a timer, and we would rather you knew that before you write in one. If you close your account, your name comes off what you wrote and the words themselves stay, because a conversation other members answered would stop making sense with pieces taken out of it. Section 8 sets out what comes off and what remains, and you can take down anything you wrote yourself at any time.
10. How we keep it safe
We take reasonable, appropriate steps to protect your information, including encrypted connections across the site, card data handled only by PayFast (a PCI-DSS Level 1 Service Provider) and never stored by us, access limited to those who need it, and verification of incoming payment notifications before we act on them. No online service can promise perfect security, but if a breach ever affected your personal information, we would act on it and notify you and the Information Regulator as POPIA requires.
11. Complaints — the Information Regulator
If you believe we have mishandled your information and we haven’t put it right, you can complain to South Africa’s data-protection authority:
The Information Regulator (South Africa)
General enquiries: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Telephone: 010 023 5200
Website: inforegulator.org.za
12. Changes to this policy
We may update this policy from time to time — for example if we add a service or the law changes. When we do, we’ll change the version date at the top, and for significant changes we’ll tell you. The current version always lives at creatinghealth.co.za/privacy.
Version 1.1 (31 July 2026) — we added ‘What you write, and who sees it’ (section 4), because the platform now lets you post reflections and take part in community rooms, and you should know before you write which of those a stranger can read. We also narrowed the promise in section 3: stripping your name applies to questions you send us privately, and cannot apply to something you choose to publish under your own first name. Nothing about how we handle a private question to Bernard has changed.
Prepared for Creating Health by Auto Alpha Advisory.