Privacy Policy.
Last Modified: 1 January 2026
Effective Date: 1 January 2026
1. Introduction and Scope
Department Six (Pty) Ltd (“Company,” “we,” “us,” or “Agency”) respects your privacy and is committed to protecting it through this Privacy Policy.
This Policy governs your access to and use of:
- Our Website: www.departmentsix.co (including any content, functionality, and services offered on it).
- Our Applications: Any mobile applications, software, or digital products (“Apps”) we develop, publish, or manage on platforms including the Apple App Store, Google Play Store, and Garmin Connect Developer Programme.
We act as a Responsible Party under South Africa’s Protection of Personal Information Act (POPIA) and as a Data Controller under the General Data Protection Regulation (GDPR).
Please read this Privacy Policy carefully. By using our Website or Apps, you accept and agree to be bound by it. If you do not agree, you must not access or use our services.
2. Information We Collect
We collect information in three ways: (1) Information you voluntarily provide, (2) Information collected automatically, and (3) Information processed via third-party integrations (App APIs).
A. Information You Provide to Us
The Website and our Apps provide various places for users to provide information. We collect information that you provide by:
- Filling out forms on the Website (e.g., “Contact Us” or project briefs).
- Registering for an account within our Apps.
- Subscribing to our newsletter or downloading resources.
- Responding to surveys or providing feedback.
- Ordering products or services via the Website.
This information may include:
- Identity Data: Name, username, or similar identifiers.
- Contact Data: Email address, telephone number, billing address, and physical address.
- Financial Data: Payment card details (processed via secure third-party gateways; we do not store raw card data).
B. Information Collected Automatically (Web & App)
As you navigate our Website or use our Apps, we use automatic data collection technologies (including Google Analytics, Cookies, and Server Logs) to collect:
- Device Information: Type of computer/mobile device, OS version, unique device identifiers (IMEI, MAC address), and mobile network information.
- Log Data: IP address, browser type, pages visited, time spent on pages, and crash reports.
- Location Data:
- Website: General location based on IP address.
- Apps: Precise location (GPS) only if you explicitly grant permission for features like mapping or fitness tracking.
C. Specific Health & Fitness Data (App Integrations)
For Apps that integrate with Garmin Connect, Apple HealthKit, or Google Health Connect, we may collect the following only with your explicit consent:
- Activity Data: Steps, heart rate, sleep analysis, calories burned, and activity routes.
- Physiological Data: Weight, BMI, or other metrics synced from your wearable device.
Crucial Restriction: This health data is used solely to provide the functional features of the App (e.g., displaying your run history). It is never sold to advertising platforms or data brokers.
3. Use of Cookies and Pixels
We use standard technology called “cookies” and server logs.
Cookies:
A cookie is a small text file that includes an anonymous unique identifier. You can modify your browser settings to decline cookies, though this may disable some Website features.
- Strictly Necessary Cookies: Required for the Website to operate.
- Analytical/Performance Cookies: Allow us to recognise and count visitors (e.g., Google Analytics).
Social Media Pixels:
We reserve the right to use social media pixels (e.g., Meta/Facebook Pixel). These allow social media platforms to track visitors to external websites to tailor advertising messages users see while visiting that social media platform.
Third-Party Tracking:
Some content (including advertisements) on the Website may be served by third parties. These third parties may use cookies/pixels to collect information about your online activities over time and across different websites. We do not control these third parties’ tracking technologies.
4. How We Use Your Information
We use your personal information for the following purposes:
- Service Delivery: To design, build, and grow the digital products you requested.
- App Functionality: To display your health stats, map your location, or sync your wearable device data (as applicable).
- Communication: To notify you about changes to our Website, products, or services.
- Customer Support: To respond to your enquiries and resolve technical issues.
- Marketing: To provide you with offers, promotions, and newsletters (subject to your consent preferences).
- Contractual Obligations: To carry out any contract between you and the Company.
5. Developer & Partner Specific Declarations
To strictly comply with the requirements of our technology partners, we make the following declarations regarding our Apps:
A. Garmin Developer Programme
- We adhere to the Garmin Connect Developer Programme Agreement.
- We do not use Garmin user data for any purpose other than providing the user with the App’s specific functionality.
- No Sale of Data: We do not sell, rent, or transfer Garmin user data to advertising networks, data brokers, or any unauthorized third parties.
- We do not store Garmin user data longer than is necessary to provide the service.
B. Google Play Store (Data Safety)
- We transparently disclose all data access in our Google Play Data Safety section.
- Runtime Permissions: We request sensitive permissions (e.g.,
ACCESS_FINE_LOCATION,BODY_SENSORS) only when the feature is in use. - Advertising IDs: If Advertising IDs are used, strictly for analytics or non-personalised advertising, respecting the user's system-level opt-out settings.
C. Apple App Store (Privacy Nutrition Labels)
- We practice Data Minimisation, requesting only data essential for the App’s core functionality.
- HealthKit: We do not write data to HealthKit without explicit user permission, and we do not use HealthKit data for advertising or data mining.
6. Disclosure of Your Information
As a general rule, we do not sell, rent, or lease your information. We may disclose your personal information to:
- Service Providers: Subsidiaries, affiliates, and contractors who support our business (e.g., cloud hosting, payment processors, email automation tools). They are bound by confidentiality agreements.
- Legal Compliance: When required by law, court order, or government entity (including South African and International authorities).
- Business Transfers: To a successor in the event of a merger, divestiture, restructuring, or sale of Company assets.
7. International Data Transfers
Department Six operates globally.
- From South Africa: We may transfer data to countries outside South Africa. We ensure these countries have adequate data protection laws, or we engage in binding agreements (such as Operator Agreements) to ensure POPIA compliance.
- From the UK/EU: Data transferred outside the UK/EU is protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).
8. Email and Newsletter Policy
We are committed to keeping your email address confidential.
- Opt-In: If you are in the UK/EU, we only add you to our newsletter list if you affirmatively consent. If you are outside the UK/EU and download a free resource/purchase a product, we may auto-enrol you with an easy option to unsubscribe.
- Opt-Out: All marketing emails contain a clear "Unsubscribe" link. You may also contact us at
hello@departmentsix.coto be removed. - No Spam: We do not sell our subscription lists to third parties.
9. Data Retention
We retain your information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law (e.g., tax records).
- Client Data: Retained for the duration of the relationship plus 5 years (statutory requirement).
- App User Data: Retained while the account is active. Upon account deletion, data is anonymised or erased within 30 days.
10. Security
We employ commercially reasonable methods to ensure the security of your data, including SSL (Secure Sockets Layer) encryption for data in transit and robust access controls for data at rest. However, please note that email is not a secure medium; strictly sensitive information should not be sent via unencrypted email.
11. Children’s Privacy
- General: Our Website is not intended for children under 13 years of age (US/UK) or 18 years of age (South Africa). We do not knowingly collect personal information from children.
- Compliance: If you believe we have collected information from a child under the relevant age without parental consent, please contact us immediately at
hello@departmentsix.co, and we will delete such information.
12. Your Rights (POPIA & GDPR)
Under the GDPR (UK/EU) and POPIA (South Africa), you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request we correct inaccurate or incomplete data.
- Erasure (Right to be Forgotten): Request we delete your data where there is no legal reason for us to keep it.
- Objection: Object to the processing of your data for direct marketing.
- Withdraw Consent: Withdraw consent at any time where we rely on consent to process data.
- Lodge a Complaint:
- South Africa: The Information Regulator (https://inforegulator.org.za/).
- UK: The Information Commissioner's Office (ICO).
13. Contact Information
Department Six (Pty) Ltd welcomes your questions or comments regarding this Privacy Policy.
Physical Address:
Department Six (Pty) Ltd
Second Floor, The Harrington
50 Harrington Street
Zonnebloem, 7925
Cape Town, South Africa
Email: hello@departmentsix.co
Website: www.departmentsix.co
Information Officer: Keagan Mc Goldrick
Changes to This Policy
We will post any changes to this Privacy Policy on this page. If we make material changes to how we treat users’ personal information, we will notify you by email or a notice on the Website home page. You are responsible for ensuring we have an up-to-date email address for you.