Privacy Policy
Last updated: 18 September 2026
This Privacy Policy explains how we collect, use, share and protect your personal information, in line with South Africa's Protection of Personal Information Act, 2013 ("POPIA"). GreenLine is a family internet-safety service, so we take particular care with the personal information of children — please read section 3 carefully.
1. Who we are (Responsible Party & Information Officer)
The Responsible Party for your personal information is XTIAN (PTY) Ltd, a company registered in South Africa (trading as "GreenLine"; registration number and registered address available on request from the address below).
Our Information Officer, registered with the Information Regulator as required by POPIA, can be contacted at privacy@mygreenline.co.za, on WhatsApp at 071 387 5199, or by post at our registered address (available on request).
2. The personal information we collect
- Account details — name, email address, and (for hardware orders) delivery address and phone number
- Billing information — processed by our payment provider; we do not store full card numbers
- Network activity — the domains your devices look up (DNS queries), source IP address, timestamps and connection metadata, used to deliver and enforce filtering
- Technical information — device type, browser, operating system, and app version
- Mobile app keyword matches — only where the feature is switched on with consent (see sections 3 and 6)
- Support communications — messages you send us by email or WhatsApp
We do not collect passwords, the contents of your encrypted (HTTPS) traffic, financial credentials, or screenshots. Please note that DNS query logs do reveal which websites and services your devices connect to — see section 5.
3. Children's personal information
GreenLine is designed to protect families, and by its nature it processes the network activity (and, where enabled, keyword matches) of children in your household. Under POPIA a child is anyone under 18, and children's personal information is "special personal information" that may only be processed with the consent of a competent person (a parent or legal guardian).
When you create an account and add or protect devices used by children, you confirm that you are the parent or legal guardian of those children (or are otherwise authorised to consent on their behalf), and you consent, as their competent person, to GreenLine processing their personal information for the purpose of providing the filtering and family-safety service.
You may withdraw this consent at any time by contacting us or removing the relevant devices; doing so will end the protection for those devices. You may also exercise the rights in section 11 on a child's behalf.
4. Why we process it, and our justification
We process personal information only where POPIA (section 11) allows, namely:
- To perform our contract with you — creating your account, delivering DNS/VPN filtering, processing payments and hardware orders, and providing support
- With consent — for optional features such as mobile keyword monitoring and accountability-partner reporting, and for processing children's information (section 3)
- For our legitimate interests — keeping the service secure and reliable, and improving it, in a way that is balanced against your rights
- To comply with the law — for example keeping tax records
We never sell your personal information, and we do not use it for third-party advertising.
5. What our filtering VPN and DNS see
GreenLine is a filtering service, not a "no-logs" privacy VPN. To block harmful sites we route your devices' traffic through a secure WireGuard tunnel and resolve their DNS look-ups. In doing so our systems necessarily see, and log for a limited period, the domains your devices request, the source IP address, timestamps, and connection metadata (such as VPN handshake times). "Connection logs" means this network metadata — it does not include the contents of your encrypted traffic, which stays private between your device and the website you visit. We keep this data only as long as set out in section 8, to run the filter, show your family dashboard, and keep the service secure.
6. Who we share it with
We share personal information only with the operators and parties below, under agreements that require them to protect it:
- Paystack — to process payments
- Brevo — to send transactional emails (e.g. verification, receipts)
- PostHog — product analytics, to understand and improve how the service is used
- Google and Apple — if you choose to sign in with them
- Google Firebase — for app notifications
- Our cloud hosting and infrastructure providers — to run the service
- Accountability partners — only where you switch this feature on: the keyword matches or activity summaries you choose to share are sent to the person you nominate. We will only enable this where the person being monitored is you, a child for whom you are the competent person, or another adult who has consented and been informed. You can turn it off at any time.
We may also disclose information where the law requires it, or to protect our rights or someone's safety.
7. Sending information outside South Africa
Some of the providers above process personal information outside South Africa. Where that happens, POPIA (section 72) requires appropriate protection. We rely on the recipient being subject to laws or binding agreements that protect your information to a standard comparable to POPIA, or on your consent or the need to perform our contract with you. You can contact us for more detail about a specific provider.
8. How long we keep it
- Account information — for the life of your account and up to 12 months after closure (to handle billing and support queries)
- DNS query metadata — a rolling 14-day window
- Connection logs — up to 90 days
- Mobile keyword-monitoring and accountability data — while the feature is enabled, and deleted shortly after it is switched off
- Billing records — 7 years (SARS tax requirement)
9. How we keep it safe
We take appropriate, reasonable technical and organisational measures to protect your information (POPIA section 19). Data is encrypted in transit (TLS) and at rest, passwords are hashed using Argon2id, access is restricted, and any operator that processes data on our behalf is required by written agreement to keep it secure.
10. Data breaches
If personal information under our control is accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as soon as reasonably possible after becoming aware of it, as required by POPIA (section 22).
11. Your rights
Under POPIA you have the right to:
- Ask what personal information we hold about you, and request access to it
- Ask us to correct or delete information that is inaccurate, irrelevant, or no longer needed
- Object to processing on reasonable grounds
- Withdraw consent you have given (this does not affect processing before withdrawal)
To exercise these rights, contact privacy@mygreenline.co.za. We aim to respond within a reasonable time. Formal access requests may follow the procedure under the Promotion of Access to Information Act (PAIA).
You also have the right to complain to the Information Regulator: POPIAComplaints@inforegulator.org.za (see inforegulator.org.za).
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "last updated" date, and where changes are significant we will let account holders know.
13. Contact us
For any privacy question, email privacy@mygreenline.co.za or message us on WhatsApp at 071 387 5199.