Effective date: 26 January 2025
Last updated: 13 April 2026
1. Who We Are
This website is operated by Simas Corporation (Pty) Ltd, trading as Femagraphy (“Femagraphy”, “we”, “us”, or “our”).
Femagraphy is a Johannesburg-based creative platform involved in fine-art editorial photography, cinematic visual projects, creative collaborations, related communications, and, where applicable, digital products, memberships, gallery access, or online sales.
Responsible Party: Simas Corporation (Pty) Ltd
Registration number: 2019/162925/07
Trading name: Femagraphy
Physical address: 74 George Ave, Sandringham, 2192, Gauteng, South Africa
Email address: info@femagraphy.co.za
Privacy / Information Officer contact: The Manager
2. Scope of This Policy
This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you:
- visit or use this website;
- contact us through forms, email, or other channels;
- apply to collaborate with Femagraphy;
- submit photographs, portfolio material, identity or age-confirmation information, or other content to us;
- purchase products or services from us, where applicable;
- subscribe to newsletters, updates, or promotional communications; or
- otherwise interact with us online or offline.
This policy applies to personal information processed by or on behalf of Femagraphy in connection with our website, communications, creative collaboration process, and related business activities.
3. Age Restriction
Femagraphy is intended for adults aged 18 and older only.
By using this website, contacting us, applying to collaborate, or submitting any information or media to us, you confirm that you are 18 years of age or older.
We do not knowingly collect personal information from children. If we become aware that personal information relating to a person under 18 has been submitted to us without lawful basis, we will take appropriate steps to delete, restrict, or otherwise deal with that information in accordance with applicable law. POPIA places additional restrictions on the processing of children’s information.
4. Personal Information We May Collect
Depending on how you interact with us, we may collect and process the following categories of personal information:
4.1 Information you provide directly
- full name;
- email address;
- telephone or WhatsApp number;
- city, province, and country;
- date of birth or age confirmation;
- social media handles or portfolio links;
- communication preferences;
- any information you include in contact forms, emails, messages, or applications.
4.2 Application and collaboration information
If you apply to collaborate with Femagraphy, we may collect:
- recent photographs or portfolio images;
- height, measurements, experience level, availability, and location;
- project interests;
- boundaries, wardrobe preferences, and related collaboration information you choose to share;
- identity or age-verification information where necessary;
- correspondence about project suitability, scheduling, concepts, releases, and approvals.
4.3 Website and technical information
When you use our website, we may collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- referring website;
- pages viewed;
- date and time of access;
- on-site activity, navigation, and interaction data;
- cookie and similar technology data.
4.4 Transaction and account information
Where applicable, we may collect:
- billing details;
- delivery details;
- order information;
- payment status;
- customer account details;
- support history;
- purchase and subscription records.
We do not intentionally store full card details unless we expressly say so and lawfully do so through appropriate systems. Payments may be processed by third-party payment providers.
4.5 Media and content you submit
We may collect and store:
- photographs;
- videos;
- application media;
- email attachments;
- submitted forms;
- creative references;
- correspondence records;
- consent records, release records, and related documentation.
Some submissions may contain personal or sensitive content. Please only send information that is reasonably necessary for your enquiry, application, or transaction.
5. How We Collect Personal Information
We may collect personal information:
- directly from you;
- when you fill in forms on our website;
- when you email, message, or call us;
- when you apply to collaborate with Femagraphy;
- when you make a purchase or use account features, where applicable;
- through cookies, analytics, server logs, and similar technologies;
- from social media platforms or third-party links you voluntarily provide to us;
- from service providers acting on our behalf; and
- where lawful, from publicly available sources or professional/creative references relevant to your enquiry or application.
Where reasonably practicable, we collect personal information directly from you.
6. Why We Process Personal Information
We process personal information only for legitimate, specific, and lawful purposes related to Femagraphy’s activities. These purposes may include:
- responding to enquiries and communications;
- reviewing, managing, and administering collaboration applications;
- verifying age and maintaining an adult-only environment;
- assessing project fit, availability, location, and suitability;
- communicating about concepts, logistics, boundaries, releases, and scheduling;
- providing customer support;
- processing purchases, subscriptions, memberships, or gallery access, where applicable;
- maintaining internal business records;
- operating, securing, troubleshooting, and improving our website and systems;
- preventing fraud, abuse, spam, unlawful conduct, or misuse of our services;
- sending service-related communications;
- sending marketing or promotional communications where permitted by law or where you have consented;
- complying with legal, tax, accounting, regulatory, contractual, and record-keeping obligations; and
- protecting our rights, property, safety, personnel, collaborators, users, and business operations.
POPIA requires personal information to be collected for a specific, explicitly defined, and lawful purpose, retained only as authorised, processed with adequate security safeguards, and handled in a way that supports data-subject participation rights.
7. Lawful Basis / Justification for Processing
Depending on the circumstances, we may process personal information where:
- you have consented;
- processing is necessary to take steps at your request or to perform a contract;
- processing is necessary to comply with a legal obligation;
- processing protects a legitimate interest of yours;
- processing is necessary for pursuing our legitimate interests or those of a third party, where permitted by law; or
- processing is otherwise authorised or required by applicable law.
Where consent is the basis for processing, you may withdraw that consent, subject to lawful and contractual limitations.
8. Special or Sensitive Content
Because Femagraphy operates in an adult artistic context, some communications or submissions may include content that is private, intimate, or sensitive in nature.
We ask that you only provide such information where it is genuinely necessary for your application, enquiry, or collaboration. Where we receive special or sensitive personal information, we will limit its use to the relevant purpose, apply heightened care where reasonably required, and process it only where permitted by law.
Submission of photographs, application materials, and collaboration information does not automatically mean publication, approval, acceptance, or ongoing engagement.
9. Cookies and Similar Technologies
We may use cookies, pixels, analytics tools, and similar technologies to:
- keep the website functioning properly;
- remember user preferences;
- improve performance and usability;
- understand how visitors use the site;
- measure audience activity and traffic patterns; and
- support security and fraud-prevention measures.
Some cookies may be essential for website operation, while others may be used for analytics, functionality, or marketing, depending on how the site is configured.
You can usually manage cookies through your browser settings and, where applicable, through cookie-consent tools presented on the site. Disabling cookies may affect certain website features.
10. Direct Marketing
Where permitted by law, we may send you updates, newsletters, announcements, or promotional content. You may opt out of direct marketing at any time by using the unsubscribe mechanism provided or by contacting us.
We will not knowingly send unsolicited electronic direct marketing in a manner that is not permitted by applicable law. POPIA gives data subjects the right to object to direct marketing and limits unsolicited electronic direct marketing except as allowed by law.
11. When We Share Personal Information
We do not sell personal information.
We may share personal information where reasonably necessary with:
- website hosting providers;
- domain, email, and communication providers;
- website developers, plugin providers, and technical support providers;
- analytics and security service providers;
- payment processors and financial service providers;
- cloud storage and document management providers;
- accounting, legal, compliance, and professional advisers;
- logistics or fulfilment providers, where applicable;
- contractors or operators processing information on our behalf; and
- regulators, law-enforcement agencies, courts, or other parties where disclosure is required or permitted by law.
Where third parties process personal information on our behalf, we expect them to apply appropriate confidentiality and security safeguards.
POPIA requires operators processing information on behalf of a responsible party to act with authorisation/confidentiality, and it requires contractual security measures between the responsible party and the operator.
12. International Transfers
Some of our service providers or systems may store or process personal information outside South Africa.
Where personal information is transferred outside the Republic, we will take reasonable steps to ensure that such transfer is made in a manner consistent with applicable law, including where the recipient is subject to laws, binding rules, or agreements that provide an adequate level of protection, or where another lawful basis for transfer applies.
POPIA restricts transfers of personal information outside South Africa unless certain conditions are met.
13. Retention of Personal Information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, or for longer where required or permitted by law, contract, dispute resolution, accounting, tax, audit, backup, fraud-prevention, or enforcement needs.
By way of example, we may retain:
- contact and enquiry records for a reasonable administrative period;
- application and collaboration records for as long as necessary to manage the application process, future opportunities, dispute resolution, record-keeping, or compliance;
- customer and transaction records for legally required or operational retention periods;
- technical logs and backups for security, continuity, and troubleshooting purposes; and
- consent, release, and contractual records for as long as necessary to evidence permissions, rights, obligations, and lawful processing.
When we no longer need personal information, we will delete, destroy, de-identify, or restrict it as appropriate and as required by law.
POPIA requires purpose-based retention and provides data subjects with rights to request correction, deletion, or destruction in certain circumstances.
14. Security
We take reasonable technical and organisational steps to protect personal information against loss, misuse, unauthorised access, disclosure, alteration, and destruction.
These measures may include access controls, password protection, secure hosting practices, limited internal access, service-provider controls, and administrative safeguards appropriate to the nature of the information we hold.
No system is completely secure, and we cannot guarantee absolute security.
If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, POPIA requires notification to the Regulator and, subject to the Act, the affected data subject as soon as reasonably possible.
15. Your Rights
Subject to applicable law and appropriate proof of identity, you may have the right to:
- ask whether we hold personal information about you;
- request access to your personal information;
- request correction of inaccurate, irrelevant, excessive, out-of-date, incomplete, misleading, or unlawfully obtained information;
- request deletion or destruction of personal information where lawful grounds exist;
- object to certain forms of processing;
- object to direct marketing at any time;
- withdraw consent where processing is based on consent; and
- lodge a complaint with the Information Regulator.
We may need to verify your identity before giving effect to a request.
POPIA expressly provides rights of access, correction/deletion, objection, notice of security compromise, and complaint. The Information Regulator also publishes complaint, objection, and correction/deletion forms.
16. How to Exercise Your Rights
To exercise any privacy right, please contact us using the details below and provide enough information for us to identify you and understand your request.
Please include:
- your full name;
- your contact details;
- sufficient information to identify the relevant interaction or record; and
- proof of identity where reasonably required.
We may decline, limit, or defer a request where applicable law allows us to do so.
17. Third-Party Links and Platforms
Our website may contain links to third-party websites, social media platforms, payment services, or external tools. We are not responsible for the privacy practices of third parties, and you should review their privacy policies separately.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect operational, legal, technical, or regulatory changes. The latest version will be published on this page with an updated “Last updated” date.
19. Contact Us
For privacy-related questions, requests, or complaints, please contact:
Femagraphy / [Insert legal entity name]
Attention: Information Officer / Privacy Contact
Email: [Insert email]
Phone: [Insert phone]
Address: [Insert physical address]
20. Complaints to the Information Regulator
If you believe that your personal information has been processed unlawfully or that your privacy rights have been interfered with, you may lodge a complaint with the Information Regulator (South Africa).
The Information Regulator publishes complaint guidance and prescribed forms for objections, correction/deletion requests, complaints, security compromises, and Information Officer registration.
