Legal
Privacy Policy
Last updated: 23 August 2026
This policy explains how Themyscira (Pty) Ltd, trading as cmd+post ("cmd+post", "we", "us", "our"), collects, uses, discloses, and protects personal information in connection with the cmd+post platform (the "Service"). It is written to comply with South Africa's Protection of Personal Information Act 4 of 2013 ("POPIA") and to reflect internationally recognised data protection standards, including the EU/UK General Data Protection Regulation ("GDPR"), for users accessing the Service from other jurisdictions.
1. Who we are & how to contact us
The "responsible party" (under POPIA) and "data controller" (under GDPR) for personal information processed through the Service is:
Themyscira (Pty) Ltd, trading as cmd+post
South Africa
Information Officer: privacy@cmdplus.tech
Our Information Officer, appointed in terms of POPIA, is responsible for ensuring compliance with this policy and applicable data protection law, and for responding to requests and complaints described below.
2. Scope of this policy
This policy applies to personal information we process when:
- you visit cmdplus.tech or sign up for early access;
- you use the cmd+post application (facility scheduling, project management, talent booking, billing, live review, remote editing, and QC tools);
- you apply for or hold a cmd+post Pro membership; or
- you otherwise communicate with us, including support requests.
Where an organisation ("Customer") uses cmd+post to manage its own clients, talent, or crew, that Customer is generally the responsible party / controller for the personal information it uploads to the Service (for example, talent contact details or client billing information), and cmd+post acts as an operator (POPIA) / processor (GDPR) on the Customer's behalf. This policy covers cmd+post's own processing as an operator/processor, as well as our processing as a responsible party for account, billing, and platform usage data. Questions about a specific organisation's use of your personal information should first be directed to that organisation.
3. Information we collect
We collect the following categories of personal information:
- Account & profile information: name, email address, phone number, job title, company name, and password (stored in hashed form).
- Pro membership applications: first name, last name, email address, and area of work, submitted through our membership request form.
- Project, talent, and billing data: information entered into the Service by Customers, such as booking schedules, task assignments, talent availability and skills, invoices, and quotes. This may include personal information about a Customer's own clients, freelancers, or crew.
- Media and content: video, audio, images, review notes, and QC results uploaded to or generated within the Service.
- Usage & device data: log data, IP address, browser type, device identifiers, pages viewed, and actions taken within the Service, collected automatically.
- Payment information: billing address and payment details, processed by our third-party payment processors. cmd+post does not store full card numbers.
- Communications: correspondence with our support or sales team.
4. How we use personal information
We use personal information to:
- provide, operate, secure, and maintain the Service;
- create and manage accounts and Pro memberships;
- process bookings, invoices, quotes, and payments;
- enable facility scheduling, project tracking, live review, remote editing, and QC workflows;
- respond to support requests and membership applications;
- send service-related communications and, where you have agreed, marketing communications;
- monitor, analyse, and improve the Service, including troubleshooting and security monitoring;
- comply with legal, regulatory, and contractual obligations; and
- detect, prevent, and investigate fraud, abuse, or security incidents.
5. Lawful basis / justification for processing
In line with POPIA's processing limitation and purpose specification conditions, and GDPR's lawfulness requirement, we process personal information only where we have a valid basis to do so, including:
- Performance of a contract — to provide the Service you or your organisation has signed up for;
- Consent — for example, when you submit a Pro membership request or opt in to marketing communications, which you may withdraw at any time;
- Legitimate interests — such as securing the Service, preventing fraud, and improving our product, balanced against your rights and reasonable expectations; and
- Legal obligation — where processing is required to comply with South African or other applicable law.
7. Cross-border transfers
Some of our service providers may process personal information outside South Africa, including in the European Union, United Kingdom, or United States. Where we transfer personal information across borders, we do so in accordance with POPIA section 72 (for example, relying on the recipient being subject to laws, binding corporate rules, or contractual arrangements that provide an adequate level of protection substantially similar to POPIA) and, where applicable, GDPR Chapter V (such as standard contractual clauses). We take reasonable steps to ensure such recipients apply data protection standards consistent with this policy.
8. Data retention
We retain personal information for as long as reasonably necessary to fulfil the purposes described in this policy, including for as long as an account remains active, plus a reasonable period afterwards to comply with legal, accounting, tax, or dispute-resolution requirements. Pro membership applications that are not progressed are retained for a limited period to allow us to follow up, after which they are deleted or anonymised. Media and project data uploaded by a Customer is retained according to that Customer's account settings and instructions, and is deleted or returned on reasonable request following account termination, subject to any applicable legal retention obligations.
9. Security safeguards
Consistent with POPIA's security safeguards condition and GDPR's integrity and confidentiality principle, we implement appropriate technical and organisational measures to protect personal information against loss, unauthorised access, interference, modification, or disclosure, including encryption in transit, access controls, and staff confidentiality obligations. No system is completely secure, and we cannot guarantee absolute security, but we take security seriously and will notify affected individuals and the Information Regulator of any qualifying security compromise as required by POPIA section 22.
11. Your rights
Subject to applicable law, you have the right to:
- be notified that personal information about you is being collected or has been accessed or acquired by an unauthorised person;
- request access to the personal information we hold about you;
- request correction or updating of inaccurate, outdated, incomplete, or misleading personal information;
- request deletion or destruction of personal information we no longer have authority to retain;
- object, on reasonable grounds, to the processing of your personal information;
- object to processing for purposes of direct marketing, and withdraw consent at any time;
- where applicable under GDPR, request restriction of processing or data portability; and
- lodge a complaint with the relevant supervisory authority (see section 15).
To exercise any of these rights, contact us at privacy@cmdplus.tech. We may need to verify your identity before actioning a request, and will respond within the timeframes required by applicable law.
12. Children's information
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from children as defined by POPIA or GDPR without the consent of a competent person (such as a parent or guardian) required by law. If you believe a child has provided us with personal information, please contact us so we can delete it.
13. Automated decision-making
We do not use personal information to make decisions about individuals based solely on automated processing, including profiling, that would produce legal or similarly significant effects, without appropriate human involvement.
14. Third-party links and services
The Service may link to or integrate with third-party websites or tools that we do not control. This policy does not apply to those third parties, and we encourage you to review their own privacy policies.
15. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or applicable law. We will post the updated version on this page with a revised "Last updated" date, and where changes are material, we will provide additional notice as required by law.
16. Complaints & supervisory authorities
If you have concerns about how we process your personal information, please contact our Information Officer first at privacy@cmdplus.tech, so that we can try to resolve the matter. You also have the right to lodge a complaint with:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints.IR@justice.gov.za ·
inforeg@justice.gov.za
Website: inforegulator.org.za
If you are located in the European Economic Area or United Kingdom, you may also lodge a complaint with your local data protection supervisory authority.
17. Contact us
For any questions about this policy or our privacy practices, contact our Information Officer at privacy@cmdplus.tech.
This document is a general template intended to reflect POPIA and internationally recognised privacy standards for a SaaS product of this kind. It is provided for informational purposes and does not constitute legal advice; we recommend having it reviewed by a qualified attorney before relying on it for your specific circumstances.
