Privacy Policy

It also explains your rights under applicable data protection laws, including the Protection of Personal Information Act (POPIA), the UK General Data Protection Regulation (UK GDPR), and the EU General Data Protection Regulation (EU GDPR). We collect limited personal data and only process it where we have a lawful basis to do so. We may update this Privacy Policy from time to time. The latest version will always be published on this page. If we make material changes, we will update the “Last updated” date. If you have questions about this Policy or how we handle personal data, contact: weare@mensch.club

1. Who we are

This website is operated by:

K2019049395 Pty Ltd trading as MENSCH
Registered address: 3 Vesperdene Road, Greenpoint, Cape Town, Western Cape, 8005, South Africa
Email: weare@mensch.club

For the purposes of data protection law, we act as a data controller unless otherwise stated.

2. Personal data we collect

2.1 Contact form data. When you contact us via our website, we may collect:

We use this data to respond to your enquiry and assess potential business relationships.

2.2 Analytics and technical data. We use Google Analytics and PostHog (product analytics, hosted in the European Union) to collect:

This information is used to understand website performance and improve user experience. Analytics and session replay only run after you accept Statistics cookies via our cookie banner; without that consent nothing is recorded. Private pages we share with clients are never recorded.

2.3 Business-to-business outreach. We may collect professional contact details such as:

We do this where we identify a legitimate professional alignment with our services. This processing is based on legitimate interest. You may object at any time (see Section 9).

2.4 Client and project data (not collected via website). In the course of delivering brand services, we may process:

We do not process payments or billing data via our website. Client and project data may be stored in secure cloud-based systems, including platforms such as Google Drive, Notion, or equivalent tools used in our operations.

Depending on the engagement, we may act as a data controller (where we determine how and why personal data is processed); or a data processor (where we process data on a client’s documented instructions).

2.5 Free tools and downloads. When you request a free tool from our Lab (for example the Content Pack kit), we collect:

We use this data to send you the tool and, occasionally, the research we make with it. Every such email carries an unsubscribe link, and you can ask us to delete your details at any time (see Section 9). The download form is protected against automated abuse by Cloudflare Turnstile, which processes your IP address and browser information to tell a person from a bot; Cloudflare's privacy policy applies to that check. The tool itself, once downloaded, runs on your own computer and sends nothing to us.

3. Lawful basis for processing

We process personal data on the following lawful bases:

Where we rely on legitimate interest, we ensure that such processing does not override your rights and freedoms.

4. Cookies

We use cookies to ensure core website functionality, analyse traffic and usage, and improve performance and user experience. Analytics cookies (Google Analytics, PostHog) are set only after you accept Statistics cookies. You can manage or withdraw consent to non-essential cookies at any time through our cookie banner.

5. Sharing of personal data

We may share personal data with trusted service providers, including:

We do not sell personal data. We may disclose personal data where required by law or regulatory authorities.

6. International transfers

Because we operate globally and use international service providers, personal data may be transferred outside South Africa, the UK or the European Economic Area. Where this occurs, we implement appropriate safeguards, including standard contractual clauses, contractual data protection commitments, and transfers to jurisdictions with recognised adequacy decisions. All international transfers are conducted in compliance with POPIA and applicable GDPR requirements.

7. Data retention

We retain personal data indefinitely unless you request deletion; we determine the data is no longer necessary; or we are legally required to retain or delete it for a specific period. Where legally permissible, we will delete personal data upon verified request.

8. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration and unlawful disclosure. However, no internet-based system can be guaranteed to be completely secure.

9. Your rights

Depending on your location, you may have the right to:

If you are located in South Africa, you may contact the Information Regulator. In the United Kingdom, you may contact the Information Commissioner’s Office (ICO). In the European Union, you may contact your local Data Protection Authority.

To exercise your rights, contact: weare@mensch.club

10. Updates to this policy

We may update this Privacy Policy from time to time. The most current version will always be published on this page with the updated date. This Privacy Policy was last updated on 24 September 2026.