SPORADIC LEGAL

PRIVACY POLICY

Last updated: 13 July 2026

1. Introduction

Sporadic Adaptoceuticals, referred to in this Privacy Policy as “Sporadic,” “we,” “us,” or “our,” respects the privacy of every customer, website visitor, prospective customer, supplier, business partner, and person who communicates with us.

We understand that customers may share private information with us when:

Visiting our website;

Placing an order;

Communicating with us through WhatsApp;

Sending a direct message on social media;

Completing an online form;

Requesting product information;

Asking questions about wellness products;

Making a payment;

Arranging delivery;

Submitting a review, complaint, return, or refund request; or

Participating in a promotion or customer programme.

We recognise that some customer enquiries may involve personal and sensitive matters. We therefore handle personal information with care, discretion, and respect.

This Privacy Policy explains:

What personal information we collect;

Why we collect it;

How we use it;

When it may be shared;

How we protect it;

How long it may be retained;

The rights available to customers; and

How customers may contact us about their information.

2. Our Privacy Commitment

Sporadic is committed to protecting the confidentiality and privacy of customer information.

We will not sell, rent, trade, or commercially distribute customer personal information to unrelated third parties.

We will not publicly disclose that a person is a Sporadic customer without that person’s permission, unless disclosure is required by law.

We do not publish customer names, order histories, product choices, contact details, health-related questions, private messages, testimonials, photographs, or personal experiences without appropriate permission.

Personal information is used only for legitimate purposes connected to our business, such as:

Processing orders;

Communicating with customers;

Delivering products;

Providing customer support;

Maintaining business and financial records;

Preventing fraud;

Complying with legal obligations; and

Sending marketing communications where permitted.

We limit access to personal information to people and service providers who reasonably require it to perform an authorised function.

3. Applicable Law

This Privacy Policy is intended to operate in accordance with the laws of the Republic of South Africa, including where applicable:

The Protection of Personal Information Act 4 of 2013, commonly known as POPIA;

The Promotion of Access to Information Act 2 of 2000, commonly known as PAIA;

The Electronic Communications and Transactions Act 25 of 2002;

The Consumer Protection Act 68 of 2008; and

Other applicable privacy, consumer, electronic-communications, recordkeeping, and business laws.

Where this Privacy Policy conflicts with a mandatory legal requirement, the applicable law will take precedence.

4. Responsible Party

For purposes of POPIA, Sporadic is generally the “responsible party” when we determine why and how personal information is processed.

This means Sporadic is responsible for taking reasonable steps to ensure that personal information under our control is:

Processed lawfully;

Collected for a specific and legitimate purpose;

Relevant to that purpose;

Accurate where reasonably possible;

Kept only for as long as necessary;

Protected against unauthorised access or loss; and

Handled in a transparent manner.

Some external service providers may process information on our behalf. These providers are generally referred to as “operators” under POPIA.

5. What Is Personal Information?

Personal information is information relating to an identifiable individual or, where applicable, an identifiable legal entity.

Depending on how a customer interacts with Sporadic, personal information may include:

Full name;

Telephone or WhatsApp number;

Email address;

Delivery or billing address;

Province, city, suburb, or postal code;

Order number;

Products ordered;

Purchase history;

Payment confirmation;

Transaction reference;

Delivery instructions;

Courier tracking information;

Social-media username;

Website account details;

Communications with Sporadic;

Product enquiries;

Reviews and testimonials;

Photographs or videos submitted by a customer;

Refund, return, or complaint information;

Device and browser information;

Internet Protocol address;

Cookie or website-usage information;

Marketing preferences; and

Any other information voluntarily supplied to us.

6. Information We Generally Do Not Need

Customers should not send Sporadic more personal information than is reasonably necessary for their enquiry or transaction.

Unless specifically required for a lawful reason, customers should not send us:

Online banking passwords;

Bank card PINs;

One-time passwords;

Complete payment-card security codes;

Copies of identity documents;

Detailed medical records;

Medical aid records;

Unrelated legal documents;

Passwords for social-media accounts; or

Information belonging to another person without permission.

Sporadic will never ask a customer to disclose their banking password, card PIN, or one-time password.

7. Information Provided Directly by Customers

We may collect information directly when a customer:

Places an order through the website;

Orders through WhatsApp;

Contacts us by telephone;

Sends an email;

Communicates through Instagram, Facebook, Threads, or another platform;

Completes an online enquiry or contact form;

Subscribes to a mailing or marketing list;

Enters a promotion;

Requests customer support;

Reports an adverse product experience;

Requests a return, refund, or exchange;

Submits a review or testimonial;

Provides delivery information; or

Makes a payment.

Customers are responsible for ensuring that the information they supply is reasonably accurate, current, and complete.

8. Information Collected Automatically

When a person visits the Sporadic website, certain technical information may be collected automatically by our website, hosting provider, analytics tools, security tools, or cookie technologies.

This information may include:

Internet Protocol address;

Device type;

Browser type;

Operating system;

Approximate geographic region;

Date and time of access;

Pages viewed;

Links selected;

Referring website;

Time spent on pages;

Website errors;

Shopping-cart activity;

Session information; and

General website-interaction data.

This information may be used to:

Keep the website functioning;

Protect the website against fraud or attacks;

Understand how visitors use the website;

Improve website navigation;

Diagnose technical problems;

Measure marketing performance; and

Improve products, content, and customer service.

Where this information can reasonably identify a person, it will be treated as personal information.

9. Information Obtained From Third Parties

We may receive personal information from third parties where necessary to complete a transaction or provide a service.

These parties may include:

Payment processors;

Banks or payment platforms;

Courier and delivery companies;

Website-hosting providers;

E-commerce providers;

Social-media platforms;

Advertising platforms;

Authorised Sporadic stockists or agents;

Fraud-prevention services; and

Professional advisers.

For example, a courier may provide Sporadic with delivery-status information, or a payment processor may confirm that a payment was successful.

We will use information obtained from third parties only where there is a lawful and legitimate basis for doing so.

10. Information About Product Use and Wellbeing

Customers sometimes voluntarily share information about:

Their reasons for considering a product;

Their personal wellbeing;

Sleep patterns;

Stress;

Mood;

appetite;

Pain;

Medication;

Allergies;

Sensitivities;

Previous product experiences;

Mental or physical health concerns; or

Adverse reactions.

Some of this information may qualify as special personal information, including health-related information.

Customers are not required to provide detailed health information merely to browse the website or purchase an ordinary product, unless particular information is reasonably necessary for safety, legal compliance, or the handling of a customer enquiry.

Where a customer voluntarily shares sensitive information with Sporadic, we will treat it as confidential and use it only for relevant purposes, such as:

Responding to the customer’s enquiry;

Recording a safety complaint;

Investigating a product concern;

Handling a return or refund;

Meeting a legal reporting obligation; or

Protecting the customer or another person from a serious risk.

Sporadic is not a medical practice, and customers should not use our communication channels as a replacement for professional medical care.

11. Purposes for Processing Personal Information

We may process personal information for the following purposes:

11.1 Processing orders

This may include:

Confirming an order;

Verifying product selection;

Calculating amounts payable;

Recording payment;

Preparing and packaging an order;

Issuing an invoice or receipt;

Arranging delivery;

Providing tracking information; and

Maintaining transaction records.

11.2 Customer communication

We may use contact details to:

Answer enquiries;

Confirm availability;

Provide order updates;

Resolve delivery issues;

Respond to complaints;

Explain product information;

Process returns;

Investigate damaged or incorrect orders; and

Provide general customer service.

11.3 Website operation

Information may be processed to:

Maintain the website;

Improve website functionality;

Operate shopping-cart features;

Prevent technical errors;

Protect accounts;

Analyse website performance; and

Detect suspicious activity.

11.4 Legal and regulatory compliance

We may process information to:

Maintain accounting and tax records;

Respond to lawful requests;

Comply with court orders;

Manage consumer complaints;

Investigate suspected fraud;

Protect legal rights;

Assist law-enforcement authorities where legally required;

Manage product recalls; and

Meet other lawful obligations.

11.5 Business administration

Information may be used for:

Internal recordkeeping;

Stock management;

Sales reporting;

Customer-service improvement;

Financial administration;

Risk management;

Quality control;

Supplier management; and

Business planning.

11.6 Marketing

Where permitted by law, information may be used to:

Send product announcements;

Share promotions;

Send educational or wellness content;

Inform customers about availability;

Invite customers to participate in promotions; and

Communicate with existing customers about similar Sporadic products.

Customers may opt out of direct marketing as explained below.

12. Lawful Grounds for Processing

Depending on the circumstances, Sporadic may process personal information because:

The customer has given consent;

The information is required to complete or prepare for a transaction;

Processing is necessary to comply with a legal obligation;

Processing protects a legitimate interest of the customer;

Processing is necessary to pursue a legitimate interest of Sporadic or a third party, provided the customer’s privacy rights are appropriately considered;

Processing is required for the proper performance of a public-law duty; or

Another lawful basis applies.

We will not rely on consent where another lawful basis is more appropriate.

Where processing is based specifically on consent, the customer may withdraw that consent, subject to any lawful consequences or information that must still be retained.

13. Order Confidentiality

Sporadic treats customer orders as private.

We do not intentionally disclose a customer’s product choices or order history to family members, employers, friends, neighbours, or other unauthorised persons.

However, limited order information may necessarily appear on:

Payment confirmations;

Invoices;

Courier records;

Shipping labels;

Order notifications;

Bank statements;

Website accounts; or

Communications sent to contact details supplied by the customer.

Customers should provide a secure telephone number, email address, and delivery address to which they have authorised access.

Sporadic cannot be responsible where another person gains access because the customer:

Uses a shared telephone;

Uses a shared email account;

Provides an address accessible to other people;

Leaves messages or order records visible;

Shares an account password;

Forwards private communications; or

Supplies incorrect contact information.

14. Discreet Handling

Where reasonably possible, Sporadic handles orders and customer communications discreetly.

However, we cannot guarantee complete anonymity because information may be required by:

Payment providers;

Couriers;

Website systems;

Accounting records;

Legal authorities; or

Other service providers required to complete the transaction.

Discretion does not mean that Sporadic may conceal information where disclosure is required by law.

15. Payments

Payments may be processed through banks, payment gateways, electronic-transfer systems, or other payment service providers.

Sporadic may receive or retain information such as:

Customer name;

Amount paid;

Payment date;

Bank reference;

Transaction reference;

Payment status; and

Limited account-identification information.

We do not intentionally store customers’ online banking passwords, card PINs, or one-time passwords.

Where a third-party payment provider processes a transaction, that provider may independently collect and process payment information under its own privacy policy and security procedures.

Customers should review the privacy and security terms of the payment service they choose to use.

16. Courier and Delivery Information

To deliver an order, Sporadic may share the minimum reasonably necessary information with a courier or delivery provider.

This may include:

Customer name;

Delivery address;

Telephone number;

Email address;

Parcel details;

Delivery instructions; and

Order or tracking reference.

Courier companies may process this information under their own privacy policies and legal obligations.

Sporadic does not authorise couriers to use customer information for unrelated marketing.

17. Service Providers

Sporadic may use external service providers to assist with business operations.

These may include providers of:

Website hosting;

E-commerce systems;

Website maintenance;

Cloud storage;

Email services;

Payment processing;

Courier services;

Accounting;

Customer communication;

Cybersecurity;

Analytics;

Advertising;

Legal services; and

Technical support.

We aim to provide service providers only with the information reasonably necessary for their function.

Where appropriate, service providers are expected to:

Process information only for authorised purposes;

Maintain confidentiality;

Use reasonable safeguards;

Restrict access;

Notify us of relevant security incidents; and

Comply with applicable privacy obligations.

Some providers may act as independent responsible parties and may have their own privacy policies.

18. Social-Media and Messaging Platforms

Sporadic may communicate with customers through services such as:

WhatsApp;

Instagram;

Facebook;

Threads; and

Other social-media or messaging platforms.

When a customer uses one of these platforms, the platform provider may independently collect information under its own terms and privacy policy.

Sporadic does not control how an external platform processes:

Account information;

Device information;

Usage information;

Contact lists;

Cookies;

Advertising identifiers; or

Other information collected by the platform.

Customers should avoid sharing highly sensitive information through public comments or group discussions.

A private message sent through a platform is more discreet than a public comment, but the information is still processed through that third-party platform.

19. Public Comments, Reviews and Testimonials

Information posted publicly on social media, public review pages, or public website areas may be visible to other people.

Customers should not post information publicly that they wish to keep confidential.

Sporadic may request permission to share a customer review, testimonial, photograph, message, or personal experience in marketing material.

We will not intentionally publish private customer communication as a testimonial without appropriate permission.

Where permission is granted, the customer may specify whether:

Their full name may be used;

Only a first name may be used;

Their social-media username may be used;

Their photograph may be used; or

The testimonial must remain anonymous.

Permission to use future material may generally be withdrawn, although withdrawal may not always affect material already lawfully printed, distributed, or published.

20. Direct Marketing

Sporadic may send marketing messages only where there is an appropriate lawful basis.

Marketing may include:

Product announcements;

Promotions;

Discount offers;

Educational content;

Reorder reminders;

New-product information; and

Sporadic news.

Customers may object to direct marketing or unsubscribe at any time.

An opt-out request may be made by:

Replying “STOP” or “UNSUBSCRIBE” where appropriate;

Using an unsubscribe facility;

Sending Sporadic a WhatsApp message;

Contacting us through the website; or

Requesting removal through the channel from which the communication was received.

After opting out, a customer may still receive non-marketing communications that are reasonably necessary, including:

Order confirmations;

Payment communications;

Delivery updates;

Safety notices;

Product-recall information;

Responses to enquiries;

Policy notices affecting an active transaction; and

Legally required communications.

Sporadic will not charge a customer for requesting removal from a marketing list, although normal network or data charges may apply.

21. WhatsApp Broadcasts and Groups

Where Sporadic uses a WhatsApp broadcast list, recipients generally receive the message privately rather than seeing the other recipients.

Where a customer voluntarily joins a WhatsApp group, their:

Telephone number;

Profile name;

Profile photograph; and

Group activity

may be visible to other group members, depending on WhatsApp’s settings.

Customers should consider this before joining a group.

Sporadic cannot guarantee the conduct of other group members and is not responsible if another member independently records, forwards, screenshots, or misuses information shared in a group.

Private customer matters should be discussed with Sporadic through a direct message rather than in a public or group environment.

22. Cookies and Similar Technologies

The Sporadic website may use cookies and similar technologies.

Cookies are small files or identifiers stored on a visitor’s device or browser.

They may be used for:

Essential website functionality;

Maintaining a shopping session;

Remembering preferences;

Website security;

Fraud prevention;

Measuring website traffic;

Understanding visitor behaviour;

Improving website content;

Remembering shopping-cart selections; and

Supporting advertising or analytics.

22.1 Essential cookies

These cookies may be necessary for the website to work correctly. Blocking them may prevent certain website functions from operating.

22.2 Analytics cookies

These may help us understand how visitors use the website, which pages are popular, and where technical improvements are needed.

22.3 Advertising cookies

Where used, advertising technologies may help measure campaign performance or display relevant content.

Customers may manage cookies through their browser or any cookie-consent tool available on the website.

Disabling cookies may affect website performance or functionality.

23. Information Security

Sporadic takes reasonable technical and organisational measures to protect personal information against:

Loss;

Damage;

Unauthorised destruction;

Unlawful access;

Unauthorised disclosure;

Alteration;

Misuse; and

Unlawful processing.

Depending on the systems used and the sensitivity of the information, measures may include:

Password-protected accounts;

Restricted access;

Device security;

Secure website connections;

Access controls;

Software updates;

Anti-malware protections;

Secure backups;

Confidentiality requirements;

Verification procedures;

Secure storage;

Careful disposal of records; and

Monitoring for suspicious activity.

We regularly consider the foreseeable risks to information in our possession and aim to improve safeguards where reasonably necessary.

24. No Absolute Security Guarantee

Sporadic takes customer privacy seriously, but no website, messaging platform, electronic transmission, cloud service, or storage method can be guaranteed to be completely secure in every circumstance.

We therefore cannot promise that a security incident will never occur.

What we can promise is that we will:

Treat customer information as confidential;

Avoid unnecessary collection;

Restrict access;

Use reasonable safeguards;

Investigate suspected incidents;

Take reasonable steps to limit harm; and

Make legally required notifications where a security compromise occurs.

Customers should also protect their own information by using secure devices, passwords, contact details, and internet connections.

25. Security Compromises

Where Sporadic has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will assess the incident and act in accordance with applicable law.

Depending on the circumstances, this may include:

Securing affected accounts or systems;

Changing passwords or access credentials;

Investigating the cause;

Preserving evidence;

Contacting relevant service providers;

Limiting further unauthorised access;

Notifying the Information Regulator;

Notifying affected individuals; and

Providing reasonable guidance on protective steps.

Notifications may be delayed where legally permitted or required, including where a law-enforcement authority determines that notification would interfere with an investigation.

26. Access to Personal Information

A customer may ask Sporadic to confirm whether we hold personal information about them.

Subject to applicable law, the customer may also request access to that information.

Before providing access, we may need to verify the identity of the person making the request.

We may request information such as:

Full name;

Telephone number;

Email address;

Order reference;

Proof of purchase; or

Other reasonable verification details.

We will not provide personal information to a person who cannot reasonably establish that they are the customer or an authorised representative.

A request may be refused or limited where permitted by law, including where disclosure would unreasonably reveal information about another person, interfere with legal privilege, compromise security, or violate another lawful restriction.

27. Correction of Personal Information

Customers may request that inaccurate, incomplete, outdated, excessive, or misleading personal information be corrected or updated.

Where information is necessary for an active order, customers should notify us promptly of any change to:

Delivery address;

Contact number;

Email address;

Customer name; or

Delivery instructions.

Sporadic cannot guarantee correction of an address after an order has already been dispatched.

28. Deletion and Destruction Requests

A customer may request deletion or destruction of personal information where Sporadic is no longer authorised to retain it.

However, information may need to be retained where reasonably necessary for:

Tax and accounting obligations;

Transaction records;

Consumer-protection requirements;

Product-safety records;

Recall management;

Fraud prevention;

Legal disputes;

Complaint resolution;

Enforcement of agreements;

Compliance with a court order; or

Another lawful purpose.

Where complete deletion is not legally or practically appropriate, we may restrict the information’s use, securely archive it, or retain only what is necessary.

29. Objection to Processing

Customers may object to certain processing of their personal information where POPIA gives them that right.

An objection should explain:

The information concerned;

The processing being objected to;

The reason for the objection; and

The outcome requested.

Sporadic will consider the objection and stop or adjust the processing where legally required.

An objection will not necessarily prevent processing that remains necessary to:

Complete an existing transaction;

Meet a legal obligation;

Establish or defend a legal claim;

Prevent fraud;

Protect a person’s legitimate interests; or

Perform another lawful function.

Where Sporadic relies specifically on consent, the customer may withdraw that consent.

Withdrawal will generally apply to future processing and will not automatically invalidate processing that occurred lawfully before consent was withdrawn.

Withdrawal may also affect our ability to provide a service where the information is necessary for that service.

For example, Sporadic cannot deliver an online order without receiving and sharing the necessary delivery information.

31. Automated Decisions

Sporadic does not ordinarily make decisions that produce significant legal consequences for customers solely through automated processing.

Website or payment systems may automatically:

Detect possible fraud;

Reject invalid information;

Calculate prices;

Apply availability rules;

Generate communications; or

Flag suspicious transactions.

Where an automated process materially affects a customer, the customer may contact Sporadic and request that the matter be reviewed where appropriate.

32. Children’s Personal Information

Sporadic’s adult-use products and services are not intended for children.

We do not knowingly invite children to purchase adult-use products or submit personal information for that purpose.

Where parental or guardian consent is legally required, information relating to a child will not knowingly be processed without appropriate authority or another lawful basis.

If a parent or guardian believes that a child has provided personal information to Sporadic without appropriate permission, they should contact us so that the matter can be investigated.

We may retain limited information where necessary to prevent unlawful transactions, protect the child, document an incident, or comply with law.

33. Information Relating to Other People

A customer should not provide Sporadic with another person’s personal information unless:

The other person has authorised it;

The customer is legally permitted to provide it;

It is reasonably necessary to fulfil a lawful purpose; or

Another lawful basis applies.

For example, where a customer sends a gift to another person, the customer must ensure that they are permitted to provide the recipient’s name, address, and contact details.

The information should be limited to what is necessary for delivery.

34. Cross-Border Processing

Some of Sporadic’s service providers, hosting systems, social-media platforms, cloud services, analytics systems, or technical providers may process or store information outside South Africa.

Where personal information is transferred across borders, Sporadic will take reasonable steps to ensure that the transfer is permitted under applicable law.

This may involve considering whether:

The recipient is subject to adequate privacy protections;

An appropriate agreement exists;

The customer has consented;

The transfer is necessary for a contract;

The transfer benefits the customer; or

Another lawful basis applies.

Customers who use global services such as WhatsApp, Instagram, Facebook, cloud platforms, or international payment systems acknowledge that those providers may process information in multiple countries under their own privacy frameworks.

35. Retention of Personal Information

Sporadic retains personal information only for as long as reasonably necessary or legally permitted.

Retention periods may depend on:

The reason the information was collected;

Whether an order remains active;

Tax and accounting requirements;

Product-safety obligations;

Complaint or warranty periods;

Possible legal claims;

Fraud-prevention needs;

Consent;

Contractual obligations; and

Applicable law.

Examples include:

Order records may be retained for financial, consumer, and legal purposes;

Delivery records may be retained to resolve delivery disputes;

Complaint records may be retained for quality and legal purposes;

Product-safety records may be retained to investigate incidents or recalls;

Marketing information may be retained until consent is withdrawn or the information is no longer required; and

Technical security records may be retained for a limited period to prevent fraud and investigate attacks.

When information is no longer reasonably required, we will aim to delete, destroy, anonymise, or securely archive it as appropriate.

36. Anonymised and Aggregated Information

Sporadic may use information that has been anonymised or combined so that it no longer reasonably identifies a particular customer.

This information may be used for:

Business analysis;

Product planning;

Website improvement;

Sales reporting;

Marketing analysis;

Customer-service improvement; and

Statistical purposes.

Properly anonymised information is not treated as personal information where it can no longer reasonably be linked to an identifiable person.

Sporadic may disclose personal information where reasonably necessary to:

Comply with a law;

Respond to a lawful court order, subpoena, warrant, or regulatory request;

Cooperate with an authorised investigation;

Enforce an agreement;

Protect Sporadic’s legal rights;

Prevent fraud or unlawful activity;

Protect the safety of a customer or another person;

Manage a product recall;

Respond to a serious product-safety concern; or

Defend a legal claim.

We will not voluntarily disclose more information than is reasonably necessary for the lawful purpose.

38. Sale or Restructuring of the Business

If Sporadic is sold, merged, reorganised, transferred, or incorporated into another business, relevant personal information may form part of the business records transferred to the new owner or entity.

Any such transfer must remain subject to applicable privacy law.

Where reasonably required, affected individuals will be informed of a material change in responsibility for their information.

A transfer of business records does not mean that Sporadic sells customer information as a separate commercial product.

39. Third-Party Websites

The Sporadic website may contain links to third-party websites, payment pages, courier websites, research resources, retailers, or social-media services.

Sporadic does not control the privacy practices or security of independent third-party websites.

Customers should review the privacy policy of any third party before:

Providing personal information;

Creating an account;

Making a payment;

Accepting cookies; or

Using its services.

This Privacy Policy applies to information controlled by Sporadic and does not automatically govern an independent third party.

40. Customer Responsibilities

Customers can help protect their privacy by:

Providing accurate contact details;

Using a secure telephone and email account;

Protecting passwords;

Not sharing payment passwords or one-time passwords;

Avoiding public disclosure of private order details;

Checking whether a communication is genuinely from Sporadic;

Reporting suspicious messages;

Reviewing third-party privacy policies;

Keeping delivery information current; and

Contacting us promptly if their account or communication channel is compromised.

Customers should be cautious of anyone falsely claiming to represent Sporadic.

41. Identity Verification

To protect customer information, Sporadic may verify identity before:

Releasing personal information;

Changing delivery details;

Processing a refund;

Changing account information;

Discussing an order with another person;

Providing transaction records; or

Acting on a privacy request.

Verification measures will be proportionate to the sensitivity of the request.

We will not disclose a customer’s information merely because another person knows the customer’s name or telephone number.

42. Authorised Representatives

A customer may authorise another person to act on their behalf.

Sporadic may request:

Written authority;

Identification of the customer;

Identification of the representative;

Details of the request; and

Confirmation that the authority remains valid.

We may refuse to disclose information where the authority cannot reasonably be verified.

43. Privacy Requests

A customer may contact Sporadic to request:

Confirmation that we hold their information;

Access to their information;

Correction of information;

Deletion where legally appropriate;

Restriction of processing;

Withdrawal of consent;

Objection to direct marketing;

An explanation of how information is used; or

Investigation of a privacy concern.

Requests should include enough information for us to identify the customer and understand the request.

We may ask for reasonable proof of identity before acting.

We will respond within a reasonable period and in accordance with any applicable statutory timeframe.

44. Fees for Requests

Sporadic will not ordinarily charge a fee merely to receive a privacy enquiry or correction request.

A lawful fee may apply in limited circumstances, including where permitted under PAIA or another applicable law for access to particular records.

Where a fee applies, the customer will be informed before the request is processed.

45. Complaints to Sporadic

Customers are encouraged to contact Sporadic first if they believe their information has been:

Used without authority;

Shared improperly;

Collected unfairly;

Stored inaccurately;

Used for unwanted marketing;

Lost;

Accessed by an unauthorised person; or

Otherwise handled contrary to this Privacy Policy.

We will make reasonable efforts to investigate the concern and provide an appropriate response.

46. Complaints to the Information Regulator

A person who believes that their personal information has been processed in violation of POPIA may lodge a complaint with South Africa’s Information Regulator.

Current complaint procedures and contact information should be obtained directly from the Information Regulator’s official website.

At the date of this Policy, the Information Regulator may be contacted through its official complaints process and at:

Information Regulator South Africa

POPIA complaints: POPIAComplaints@inforegulator.org.za

Telephone: 010 023 5200

Customers should verify current contact information before submitting a complaint.

47. Changes to This Privacy Policy

Sporadic may update this Privacy Policy to reflect changes in:

Our products;

Website functions;

Payment systems;

Delivery services;

Marketing practices;

Technology;

Service providers;

Business operations; or

Applicable law.

The current version will be published on the Sporadic website with a revised “Last updated” date.

Where a change materially affects how existing personal information is used, we will take reasonable steps to notify affected individuals where required.

48. Contact Information

Questions, objections, correction requests, access requests, marketing opt-outs, or complaints concerning personal information may be directed to:

Business: Sporadic Adaptoceuticals

Website: www.sporadic.co.za

WhatsApp: 061 905 9813

Facebook: @SporadicLT

Instagram: @sporadic_lemon_tek

Privacy requests should clearly state that the enquiry relates to privacy or personal information.

49. Final Privacy Assurance

Sporadic values the trust customers place in us.

We understand that purchasing wellness products and discussing personal wellbeing can be private. Customer information will therefore be treated respectfully, discreetly, and confidentially.

We do not sell customer personal information.

We do not intentionally disclose private customer enquiries, order details, health-related discussions, testimonials, or contact information to unauthorised persons.

Information will be collected only where reasonably necessary, used for legitimate purposes, protected through reasonable safeguards, and retained only for as long as legally or operationally required.

Nothing in this Privacy Policy limits any privacy right that a person has under POPIA or another applicable South African law.