Privacy / 8 October 2026

Your information deserves care.

This notice covers the Kamva website account and its current free web tools.

Who to contact

Kamva is operated by Emmanuel Vilakazi; the registered company/legal applicant and registration number remain TBC. Contact info@kamva-app.co.za for access, correction, deletion, guardian withdrawal, complaints or security concerns. This notice does not claim POPIA certification.

What the account stores

Your email address, age band (16–17 or 18+), email-verification status, account creation and sign-in times, and the version/time of the notice acknowledged. For ages 16–17 we also record a parent/legal guardian email and their approval choice. We do not ask for ID numbers, exact birth dates, school reports or bank credentials.

Why it is used

To verify control of an inbox, grant free member access, protect the service, record applicable consent and respond to account requests. Account messages are service emails, not marketing opt-ins. Marketing requires a separate choice; none is collected here.

What stays in your page

APS marks, CV text, cash-plan inputs and directory searches are processed in your current browser page. They are not submitted to the account database, sent to an AI provider or automatically saved in browser storage. Refreshing or leaving the page loses them. Downloaded or printed files remain on your device and should be protected, especially on shared computers.

Ages 16–17

Learner email verification is followed by a parent/legal guardian approval request. Member access remains locked until both steps are complete. The guardian sees the learner email and the limited data-processing request, not the learner’s CV, marks or financial entries. Email control and a guardianship attestation do not independently prove a legal relationship. Disputed relationships require human review. Account approval does not activate the planned parent dashboard.

Security and recipients

The website uses encrypted HTTPS connections, secure session cookies, one-use expiring codes, request limits and server-side access checks. Account storage is outside the public website directory. Hosting and email delivery providers process necessary service data; the hosting provider may retain its own access logs and backups. No system is risk-free, and a broader independent review is required before large-scale rollout.

Retention

Sign-in codes expire after 10 minutes; expired code records are removed after about one day. Abuse-limit records are removed after two days. Unverified or unapproved learner registrations expire after seven days. An account you disable loses access immediately and is scheduled for personal-data removal after 30 days; cleanup runs during account-service use. Operational hosting backups may remain for their provider retention period. Active accounts retain the minimal account record until disabled or a deletion request is resolved.

Your controls

Use My account to export the account information or disable access. Contact us from the registered email for corrections or recovery. A guardian can withdraw approval by contacting us from the approval email; ownership and the request will be checked. Sign out on shared devices. Never share an emailed sign-in code.

Cookies and external links

A necessary session cookie keeps account forms and sign-in secure. It is not an advertising tracker. This site does not add behavioural analytics or marketing cookies. External universities, funders and job websites have their own privacy notices, terms and requirements.

Limits of the tools

Admissions requirements change, and minimums do not guarantee selection. The APS estimate is not a universal university calculation. CV examples are prompts, not facts about you. Financial outputs are planning estimates, not advice, audited reports or tax returns. Confirm important decisions with the relevant institution or qualified professional.