Privacy Policy
Last updated: 26 August 2026 · Version: 1.0
In plain terms
- Two sets of law protect your personal information here, not one. South Africa’s Protection of Personal Information Act — and, because the company behind Hippool is registered in France, European data protection law (the GDPR) as well.
- We collect what we need to sell you a pool and deliver it. Not more.
- Marketing messages only if you said yes. That’s the law here, and we follow it.
- You have a named person to talk to — our Information Officer — and two regulators you can escalate to. All of it here →
- Your information goes to France and to our providers abroad. Section 6 explains exactly how that’s allowed and what protects you.
1. Who processes your information
- Responsible party / data controller BME Consulting, trading as Hippool
- Legal form — Société à responsabilité limitée (SARL) — a French private limited company
- Registered office — 113 rue Marietton, 69009 Lyon, France
- Company number (SIREN) — 754 058 410 · Lyon Trade and Companies Register (RCS Lyon)
- Information Officer — Steven Robert
- Information Officer contact — contact@hippool.com · BME Consulting, 113 rue Marietton, 69009 Lyon, France
- Privacy contact (EU) — contact@hippool.com · BME Consulting, 113 rue Marietton, 69009 Lyon, France
We’re a French company selling to customers in South Africa. We say it plainly — and it means your information is covered twice over.
- South African law. We apply the Protection of Personal Information Act 4 of 2013 (POPIA) to everything we do with the personal information of our South African customers, and this policy is written to it.
- European law. Because BME Consulting is established in France, the General Data Protection Regulation applies to our processing — the Regulation follows the company, not the customer (GDPR Art. 3(1)). That gives you a second, independent set of rights and a second regulator.
2. What we collect, and where it comes from
We collect your information directly from you, when you place an order, contact us, or subscribe to our emails. Where we collect it from anywhere else — a delivery carrier confirming an address, a payment provider confirming a payment — we say so here.
- Ordering: name, delivery and billing address, email address, phone number, what you ordered and what you paid.
- Contacting us: your name, your contact details, and what you tell us — including photos you send with a claim.
- Subscribing: your email address and the date you consented.
- Browsing: device and browser information, approximate location from your IP address, pages viewed, how you arrived. From cookies — see Cookie Policy.
We do not collect special personal information — nothing about your health, your beliefs, your race, your politics or your biometrics. Both South African and European law hold that kind of information to a much higher standard; the simplest way to meet it is not to collect it. We have no reason to, and we don’t want it.
We never see or store your full card number. That stays with our payment provider.
3. Why we’re allowed to process it
Both POPIA and European law require us to have a justification for everything we do with your information. Ours, side by side:
- Process and deliver your order; contact you about it — POPIA justification: Necessary to perform our contract with you · GDPR legal basis: Art. 6(1)(b) — contract
- Handle warranty claims, faults and returns — POPIA justification: Necessary to perform the contract, and to comply with the Consumer Protection Act · GDPR legal basis: Art. 6(1)(b) and 6(1)(c)
- Keep accounting and tax records — POPIA justification: Compliance with a legal obligation · GDPR legal basis: Art. 6(1)(c) — French commercial and tax law (§8)
- Prevent fraud and secure the shop — POPIA justification: Our legitimate interests, and yours · GDPR legal basis: Art. 6(1)(f)
- Send you marketing emails — POPIA justification: Your consent (§7) · GDPR legal basis: Art. 6(1)(a)
- Analytics and advertising cookies — POPIA justification: Your consent (Cookies) · GDPR legal basis: Art. 6(1)(a)
You can object. Where we rely on our legitimate interests, you have the right to object to the processing. Tell our Information Officer (§11) and we’ll deal with it.
4. What we use it for, and what we don’t
We use your information for the purposes set out in §3, and we don’t use it for anything else without coming back to you first.
We do not sell your personal information. We do not trade it or rent it.
And we don’t make automated decisions about you — no profiling that decides your price, no automated decision with a legal or similarly significant effect. Both POPIA and European law give you a right against that kind of decision. There isn’t one here.
5. Who else touches your information
- Shopify — What they do for us: Hosts and runs the shop, stores orders and customer records · Where they are: Canada, United States and other locations
- Payment providers — What they do for us: Take your payment — card through Shopify Payments, PayPal, or bank transfer
- Delivery carriers — What they do for us: Deliver your order — name, address, phone number · Where they are: South Africa
- Email platform — What they do for us: Sends order emails and, with your consent, marketing
- Analytics — What they do for us: Aggregate site usage, with your consent
Each of them is bound to us by a written agreement, must process your information only as we instruct, and must keep it secure — as required both by POPIA (operator agreements) and by European law (GDPR Art. 28).
6. Where your information goes
Your information is processed outside South Africa — principally in France, where we are, and on our providers’ infrastructure. Two sets of rules govern that, and we meet both.
- Because it’s necessary to perform our contract with you. We can’t deliver a pool, take a payment or handle a warranty claim without your information reaching us in France and reaching our providers. POPIA expressly permits a transfer that is necessary to perform a contract between you and us.
- Because our providers are bound by written agreements requiring a level of protection consistent with South African law, including on any onward transfer.
- For anything that isn’t necessary for your order — marketing, analytics — we rely on your consent, and you can withdraw it.
- Once your information is with us in France, sending it on to anyone outside the European Union is a restricted transfer. South Africa does not have a European adequacy decision, and neither does Australia — so when we pass your details to a South African delivery carrier, that transfer is covered by Standard Contractual Clauses approved by the European Commission (GDPR Art. 46), together with an assessment of the risks.
- Transfers to Shopify are covered by Canada’s adequacy decision and, for the United States, by the EU-U.S. Data Privacy Framework or Standard Contractual Clauses.
You can ask us for a copy of the safeguards we use. Contact our Information Officer or our privacy contact (§14).
7. Marketing messages
We only send you marketing if you said yes. In South Africa that’s not a courtesy, it’s the law: electronic direct marketing requires your consent unless you’re already our customer and we’re telling you about our own similar products — and even then, you get a clear way to say no, every time. European law requires the same thing, and adds that we must be able to prove you consented.
- The subscription box is never pre-ticked.
- Every marketing message has a working unsubscribe, and identifies us.
- We ask once. If you say no, or don’t answer, we don’t ask again.
8. How long we keep it
We keep your information only as long as we need it for the purpose we collected it for, or as long as the law requires — then we delete it, de-identify it, or move it into restricted archive storage.
- Your customer account and order history, in active use — How long: While you’re a customer, and 3 years after our last contact with you · Why: Reference period applied by the French data protection authority
- Invoices, order records and supporting accounting documents, in restricted archive — How long: 10 years from the close of the financial year · Why: French commercial law — Code de commerce, art. L123-22 (tax law requires at least 6 years).
- Warranty and claim records — How long: For the length of the warranty and a reasonable period afterwards
- Marketing subscription — How long: Until you withdraw consent, plus a short suppression record · Why: Consent — and proof of it
- Enquiries with no order — How long: 3 years from our last contact with you
9. Keeping it safe, and telling you if it goes wrong
- The shop runs on Shopify, which maintains its own security infrastructure and certifications.
- Access inside our team is limited to those who need it.
- Every account that can reach your information is protected by two-factor authentication — a password is not enough on its own. Signing in also requires a code sent to the account holder’s mobile phone.
If your information is compromised, POPIA requires us to notify both the Information Regulator and you, as soon as reasonably possible after we find out — and to tell you enough for you to protect yourself. European law adds a hard deadline: we must report it to the French authority within 72 hours, and tell you directly if the risk to you is high. We will do both.
10. Children
Hippool is sold to adults. We don’t market to children and we don’t knowingly collect the personal information of anyone under 18. If you believe we hold a child’s information, tell our Information Officer and we’ll delete it.
11. Your rights, and how to use them
You have rights under POPIA, and rights under European law. They overlap, and where they don’t, you get the benefit of both.
You can:
- Ask us what we hold about you, and get a copy (POPIA s. 23 · GDPR Art. 15);
- Ask us to correct or delete information that’s wrong, misleading, out of date, incomplete or that we no longer have grounds to keep (POPIA s. 24 · GDPR Art. 16 and 17);
- Ask us to restrict what we do with it while a dispute about it is sorted out (GDPR Art. 18);
- Ask for a machine-readable copy of the information you gave us, to take elsewhere — a right European law gives you (GDPR Art. 20);
- Object to processing based on our legitimate interests (POPIA s. 11(3) · GDPR Art. 21);
- Withdraw your consent to marketing or to non-essential cookies, at any time;
- Not be subject to an automated decision that significantly affects you (POPIA s. 71 · GDPR Art. 22) — we don’t make any;
- Complain — to us, and then to either regulator (§12).
Start here: contact our Information Officer, Steven Robert, at contact@hippool.com, or write to us at BME Consulting, 113 rue Marietton, 69009 Lyon, France.
How long we take: one month, extendable by two more for a complex request, in which case we tell you inside the first month and explain why (GDPR Art. 12(3)). It costs you nothing.
12. Complaining to a regulator
- Address Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- Telephone — 010 023 5200 · Toll free 0800 017 160
- Enquiries — enquiries@inforegulator.org.za
- Website — inforegulator.org.za
CNIL (France) — the French data protection authority, which supervises us because we’re established in France.
- Address — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Website — cnil.fr
13. Changes to this policy
If we change this policy, we publish the new version here with a new date. If the change is significant, we’ll tell you.
14. Contact
Information Officer: Steven Robert
Email: contact@hippool.com — we answer general enquiries within 48 hours (Monday to Friday). A formal request about your rights has its own deadline: one month (§11).
Post: BME Consulting, 113 rue Marietton, 69009 Lyon, France.
Related pages: Cookie Policy · Terms of Sale · Legal Notice