We collect personal information that you provide directly or that is generated through your use of our website and services. The types of personal information we may collect include:

  • Identification and Contact Information: Name, email address, phone number, postal address, and other similar details provided when you create an account, place an order, subscribe to newsletters, or contact us.
  • Payment and Transaction Information: Billing details, payment method information (e.g., credit card details processed via secure third-party providers), and order history.
  • Health and Wellness-Related Information: If relevant to your purchases (e.g., for wellness items), we may collect information about your preferences or needs, but only with your explicit consent where required.
  • Technical and Usage Data: IP address, browser type, device information, pages visited, time spent on the site, and other analytics data collected automatically via cookies and similar technologies.
  • Marketing Preferences: Information about your consent to receive promotional communications.

We collect this information from:

  • Forms you submit on our website (e.g., registration, checkout, inquiries).
  • Automated technologies (e.g., cookies, web beacons).
  • Third-party sources (e.g., payment processors, shipping partners) where necessary for service delivery.
Providing personal information is voluntary in some cases (e.g., newsletters), but required for others (e.g., completing a purchase). If you do not provide required information, we may not be able to fulfill your request.
We process your personal information for specific, legitimate purposes and only to the extent necessary. Under POPIA and PDPL, we rely on bases such as consent, contract performance, legal obligations, or legitimate interests. Uses include:

  • Fulfilling Orders and Services: Processing purchases, shipping products, handling payments, and providing customer support.
  • Improving Our Services: Analyzing usage patterns to enhance website functionality and user experience.
  • Marketing and Communications: Sending promotional emails, newsletters, or updates about our products (only with your consent, which you can withdraw at any time).
  • Compliance and Legal Purposes: Complying with laws, preventing fraud, resolving disputes, or responding to regulatory requests.
  • Security: Detecting and preventing unauthorized access or misuse.
We do not process your information for incompatible purposes without notifying you and obtaining consent where required.
We may share your personal information with:

  • Service Providers: Third-party vendors (e.g., payment gateways, shipping companies, IT providers) who assist in operating our business. These parties are contractually obligated to protect your data and process it only for specified purposes.
  • Legal and Regulatory Authorities: As required by law, such as for tax reporting, customs clearance, or in response to court orders.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.

We do not sell your personal information to third parties. Sharing is limited to what is necessary and compliant with POPIA and PDPL.
As we operate in South Africa and the UAE, your personal information may be transferred between these countries or to third countries (e.g., for cloud storage). We ensure such transfers comply with legal requirements:

  • Under POPIA: Transfers are made only with adequate safeguards, such as binding corporate rules or standard contractual clauses.
  • Under PDPL: Transfers outside the UAE require approval from the UAE Data Office or equivalent protections to ensure a level of protection no less than that provided by PDPL.
We implement appropriate technical and organizational measures to protect your personal information from unauthorized access, loss, alteration, or disclosure. These include encryption, firewalls, access controls, and regular security audits. In the event of a data breach that poses a high risk to your rights, we will notify you and the relevant authorities (e.g., Information Regulator in South Africa or UAE Data Office) without undue delay, as required by POPIA and PDPL.
You have rights regarding your personal information. To exercise them, contact us using the details below. We will respond within reasonable timeframes (typically 30 days).

Under POPIA (South Africa):

  • Right to be informed about processing.
  • Right to access your information.
  • Right to correct inaccurate or incomplete information.
  • Right to object to processing (e.g., for direct marketing).
  • Right to request deletion of unnecessary or unlawfully obtained information.
  • Right to withdraw consent.
  • Right to complain to the Information Regulator.

Under PDPL (UAE):

  • Right to access your data.
  • Right to rectification of inaccurate data.
  • Right to erasure ("right to be forgotten").
  • Right to restrict processing.
  • Right to data portability.
  • Right to object to processing, including automated decision-making and profiling.
  • Right to withdraw consent.
  • Right to complain to the UAE Data Office.

We may require proof of identity before fulfilling requests. Some rights may be limited where processing is necessary for legal reasons.
Our website uses cookies and similar technologies to enhance functionality, analyze traffic, and personalize content. Essential cookies are necessary for site operation, while others (e.g., analytics, marketing) require your consent.

You can manage cookie preferences through your browser settings or our cookie banner. For more details, see our Cookie Policy.

We retain your personal information only as long as necessary for the purposes outlined, or as required by law (e.g., for tax or accounting purposes). After that, it is securely deleted or anonymized.
Our services are not intended for individuals under 18. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it promptly.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The updated policy will be posted on our website with the effective date. We encourage you to review it periodically.
If you have questions, requests, or complaints about this Privacy Policy or our data practices, please contact our Data Protection Officer:

  • Email: privacy@behindthescenes.com (placeholder; update with actual email)
  • Address: Behind the Scenes, [Company Address in UAE/South Africa]
  • For South Africa: You can also contact the Information Regulator at inforeg@justice.gov.za.
  • For UAE: Contact the UAE Data Office via their official channels.

By continuing to use our website and services, you acknowledge that you have read and understood this Privacy Policy.