Privacy
What AtChoir holds, what it deliberately never asks for, and what you can ask us to do with it.
Last updated 10 August 2026
The short version
AtChoir is choir operations software, made by SJL Consulting (Pty) Ltd. This page explains what personal information the app holds, who is responsible for it, and what you can ask us to do with it.
It is written to be read by a choir director, not a lawyer. If anything here is unclear, write to info@sjl-consulting.co.za and ask.
- We hold a display name, an email address, an optional voice part, a role, and the records a choir creates: attendance, tasks, events and chat messages.
- We never ask for a date of birth or an age.
- Each choir owns its own members' information. We hold it on the choir's behalf.
- Production data is stored under EU jurisdiction.
- You can ask to see your information, correct it, or have it deleted.
What we collect, and why
Only what the app needs to run a choir. Each item below is there for a reason, and the reason is the only thing it is used for.
- Display name — so members can recognise each other in attendance, in chat and on tasks.
- Email address — to sign in, to send account mail, and for a director to invite a member.
- Password — stored only as a one-way hash (PBKDF2), never as the password itself. We cannot read it, and we cannot tell you what it is.
- Voice part (optional) — to group and sort members. A member can leave it blank.
- Role — whether someone is a member or a director. This decides what they can see and do.
- Attendance records — present, late, absent, excused, and the time a QR self-check-in was scanned at a rehearsal.
- Tasks and projects — who is doing what, by when, for concerts, tours and fundraisers.
- Chat messages — what members write to each other, either to the whole choir or to a smaller group they are part of.
- Calendar entries — rehearsals and events, and who they are for.
What we never collect
The app stores no date of birth, no age, and no flag marking anyone as a minor. There is nowhere to enter one.
This is deliberate. Rather than ask who is a child and treat those members differently, AtChoir is built to the standard a child deserves, for everyone. That way it never needs to ask. It also means that if the data were ever exposed, there is no age or birth date in it to expose.
We do not sell personal information, we do not use it for advertising, and we do not use choir data to train machine learning models. There is no advertising in the app.
Who is responsible for what
POPIA splits this into two roles, and the split matters because it decides who you should approach with a question.
Your choir is the responsible party. The choir decides who its members are, what is recorded about them, and how long it is kept. In practice that decision sits with the director and the choir's committee.
SJL Consulting is the operator. We run the software and hold the data on the choir's instructions. We do not decide what your choir records, and we do not use your choir's data for our own purposes.
SJL Consulting is the responsible party for two things only: billing information for the choir that is invoiced, and our own technical telemetry about how the software performs.
So: a member's question about their own record goes to their choir first. The choir can escalate anything technical to us, and we will act on the choir's instruction.
Members under 18
Because the app holds no age, it cannot tell whether a member is an adult or a child, and it does not try to.
Consent for minors is handled at choir level. When a choir is set up, the director attests that the choir has the necessary permission from the parents or guardians of any members who are children, in the form the choir's own rules and the law require. That is one attestation by the choir, not forty separate in-app consents from individual members.
POPIA treats the personal information of children as a special case: section 34 prohibits processing it, and section 35 sets out the narrow circumstances where processing is allowed, including with the consent of a competent person such as a parent or guardian. The choir-level attestation exists so that a choir can record, once, that it has that consent.
Keeping the attestations themselves — the signed forms, the emails from parents — is the choir's responsibility. We do not hold them.
Where the data is kept
Production data is stored in a database whose jurisdiction is locked to the European Union at the moment it is created. It cannot be moved afterwards.
There is no African region available for this datastore, so the EU was a deliberate choice rather than a default. It is the strongest available regime for a cross-border transfer under POPIA section 72, which permits a transfer where the receiving country's law provides a level of protection substantially similar to POPIA's.
The website you are reading and the app's servers are operated on infrastructure provided by Cloudflare. Apple and Google distribute the app itself through their app stores; they do not receive your choir's records.
Signing in, and how sessions are protected
When you sign in, your device stores a session token in the operating system's own secure store — the keychain on iOS, the keystore on Android. It is not kept in ordinary app storage.
On our side we never store the token itself, only a hash of it. A hash can confirm that the token you present is the right one, but it cannot be turned back into a working token. If our records were read by someone who should not have them, they could not sign in as you with what they found.
What we measure about the app itself
We record basic technical telemetry so we can tell whether the software is working: the request method, and a normalised route such as the shape of the address being called.
Telemetry never contains names, email addresses, message content, or any free text a member has typed. It tells us that a page was slow. It does not tell us who was on it or what they wrote.
How long we keep things
The choir decides how long its own records are kept, because the choir is the responsible party. Attendance history, tasks and events remain available for as long as the choir wants them, and a director can delete them at any time.
When a member is removed from a choir, their access ends immediately.
When a choir stops using AtChoir, we keep its data for 30 days so that it can be restored if the choir changes its mind or the account was closed in error, and then we delete it from production. Backups fall away on their own backup cycle after that. If a choir wants its data deleted sooner, or wants an export before deletion, ask us and we will do it.
Billing records are kept for as long as South African tax and company law requires us to keep them. Those are SJL Consulting's own records, not the choir's.
Your rights
Under POPIA you may ask what personal information is held about you, ask for it to be corrected if it is wrong, and ask for it to be deleted where there is no longer a reason to keep it. You may also object to how it is being used.
Start with your choir. Once the web console is built, your director will be able to see, correct and delete member records directly there — a misspelled name or a wrong voice part will take a moment to fix. Until then, ask your director to raise it with us at info@sjl-consulting.co.za.
If your choir cannot resolve it, write to info@sjl-consulting.co.za and say which choir you belong to and what you are asking for. We will confirm receipt and respond within a reasonable time. Where we hold the data as an operator, we will act on the choir's instruction rather than on our own judgement, and we will tell you that is what we are doing.
We may need to confirm who you are before acting on a request, so that nobody else can obtain or change your information by pretending to be you.
You may also complain to the Information Regulator (South Africa). Their contact details are published at inforegulator.org.za.
Deleting an account
A member can ask their director to remove them from the choir. Removal ends access at once and removes the member from the choir's lists.
To have your personal information deleted rather than simply leaving a choir, use Delete account in the app's Account tab. If you can no longer sign in, write to info@sjl-consulting.co.za instead. We delete the display name, email address, voice part and role.
Some things survive that deletion, and it is fair to say so plainly. Attendance records, to-dos and chat messages you were part of may remain, with your name taken off them — a choir's own record of its rehearsals, its work and its conversations belongs to the choir, not to any one person in it. If a choir wants a specific record removed as well, write to us at the address above.
Buying AtChoir
The app is free to download on both app stores. There is nothing to buy inside it, and no individual can subscribe.
Choirs are invoiced directly by SJL Consulting, by EFT. A choir gets in touch, we set the organisation up, and the director then provisions the members, who simply sign in. That means the only personal information involved in payment is the choir's own billing contact — not its members'.
To set up a choir, write to info@sjl-consulting.co.za.
Changes to this page
If we change how personal information is handled, we will change this page and note the date. Where a change is significant, we will tell the choirs directly rather than rely on anyone re-reading the site.
Contact
SJL Consulting (Pty) Ltd, registration number 2019/210092/07, trading as AtChoir.
14 Leonor, Dundas Street, Strand, 7140, South Africa.
POPIA notice
This section sets out, in one place, the information required by the Protection of Personal Information Act, 4 of 2013. It repeats what is above rather than adding to it.
POPIA notice: responsible party and operator
Each choir using AtChoir is the responsible party for its members' personal information. The choir determines the purpose of the processing and the means by which it happens.
SJL Consulting (Pty) Ltd, registration number 2019/210092/07, of 14 Leonor, Dundas Street, Strand, 7140, is the operator. It processes that personal information on behalf of the choir, on the choir's instruction, and for no other purpose.
SJL Consulting is itself the responsible party in respect of its own billing records and its own technical telemetry.
POPIA notice: Information Officer
The Information Officer of SJL Consulting (Pty) Ltd can be contacted at info@sjl-consulting.co.za, or by post at 14 Leonor, Dundas Street, Strand, 7140, South Africa.
Requests for access, correction or deletion, and any complaint about how personal information has been handled, may be sent to that address.
POPIA notice: information processed and purpose
The categories of personal information processed are: display name; email address; voice part (optional); role within the choir; attendance records including QR self-check-in events; calendar entries; tasks and project assignments; and chat messages.
The purpose of the processing is the administration of a choir, orchestra, band or ensemble: keeping attendance records, scheduling rehearsals and events, allocating work, and allowing members to communicate with one another.
No date of birth, age, or minor status is collected or stored. No special personal information within the meaning of POPIA is required by the app, and none is requested by it. Choirs are asked not to enter such information into free-text fields.
Supplying a display name and an email address is necessary in order to use the app. Supplying a voice part is optional.
- Sign-in credentials, held only as a one-way hash.
POPIA notice: children
Section 34 of POPIA prohibits the processing of the personal information of a child, and section 35 sets out the circumstances in which that prohibition does not apply, including where a competent person such as a parent or guardian has consented.
AtChoir does not identify which of a choir's members are children, because it holds no age. Instead, the choir attests at set-up that it has obtained the consent required by section 35 for any member who is a child, and undertakes to keep the record of that consent. The choir, as responsible party, remains accountable for that consent.
POPIA notice: cross-border transfer
Production data is stored under the jurisdiction of the European Union. The jurisdiction is fixed when the datastore is created and cannot be changed afterwards. No African region is offered for this datastore.
The transfer is made in reliance on section 72 of POPIA, on the basis that the law of the receiving jurisdiction upholds principles for the lawful processing of personal information that are substantially similar to the conditions in POPIA, and includes provisions substantially similar to section 72 governing onward transfer.
The transfer is also given effect by the contract between SJL Consulting and its infrastructure provider, and by the contract between SJL Consulting and each choir.
POPIA notice: security safeguards
Session tokens are stored on the member's device in the platform keychain or keystore. Only hashes of session tokens are stored on the server, so a stored value cannot be replayed as a valid session.
Access to a choir's data is limited by role. Telemetry excludes names, email addresses, message content and all free text.
POPIA notice: data subject rights
A data subject may request confirmation of whether personal information about them is held, and a record or description of that information; request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully; object to the processing; and complain to the Information Regulator.
Requests should be directed to the choir in the first instance, as responsible party, and may be directed to the Information Officer at info@sjl-consulting.co.za. Identity may need to be verified before a request is acted on.
The Information Regulator (South Africa) publishes its contact details and complaint forms at inforegulator.org.za.