AtChoir

Privacy

What AtChoir holds, what it never asks for, and what you can ask us to do with it.

Last updated 1 October 2026

The short version

AtChoir is choir operations software, made by SJL Consulting (Pty) Ltd. This page explains what personal information the app holds, who is responsible for it, and what you can ask us to do with it.

It is written for someone in a choir's management to read. If anything here is unclear, write to info@sjl-consulting.co.za and ask.

What we collect, and why

Only what the app needs to run a choir. Each item below is used only for the purpose given next to it.

What we never collect

The app stores no age and no flag marking anyone as a minor. A birthday is held only where a member has added their own, and only that member and their choir's management can see it.

AtChoir does not treat children differently from adults: every member's information gets the same protection. Where a member has given a birthday that makes them under 18, the choir's management sees "Under 18" beside their name. That is worked out when the page is shown and is not stored. One rule depends on it, and it is set out under "Members under 18" below.

We do not sell personal information, we do not use it for advertising, and we do not use choir data to train machine learning models. There is no advertising in the app.

Who is responsible for what

POPIA splits this into two roles, and the split matters because it decides who you should approach with a question.

Your choir is the responsible party. The choir decides who its members are, what is recorded about them, and how long it is kept. In practice that decision sits with the choir's management and its committee.

SJL Consulting is the operator. We run the software and hold the data on the choir's instructions. We do not decide what your choir records, and we do not use your choir's data for our own purposes.

SJL Consulting is the responsible party for two things only: billing information for the choir that is invoiced, and our own technical telemetry about how the software performs.

So: a member's question about their own record goes to their choir first. The choir can escalate anything technical to us, and we will act on the choir's instruction.

Members under 18

The app can tell that a member is under 18 only if that member has added their own birthday. A member who has not may still be a child, so the app does not rely on it.

Consent for minors is handled at choir level. When a choir is set up, its management attests that the choir has the necessary permission from the parents or guardians of any members who are children, in the form the choir's own rules and the law require. It is one attestation by the choir, and individual members are not asked to consent in the app. Its wording names the information held about each member, including the details a member may add.

One rule in the app depends on a birthday. Where a member's own birthday shows they are under 18, their dietary requirements are saved only if the choir has made that attestation in its current wording.

POPIA treats the personal information of children as a special case: section 34 prohibits processing it, and section 35 sets out the narrow circumstances where processing is allowed, including with the consent of a competent person such as a parent or guardian. The choir-level attestation exists so that a choir can record, once, that it has that consent.

Keeping the evidence behind that attestation, such as signed forms and emails from parents, is the choir's responsibility. We do not hold it.

Where the data is kept

Production data, including uploaded documents, is stored in a database and a file store whose jurisdiction is locked to the European Union at the moment each is created. It cannot be moved afterwards.

There is no African region available for either datastore, so we chose the EU. We rely on POPIA section 72, which permits a transfer where the receiving country's law provides a level of protection substantially similar to POPIA's.

The website you are reading and the app's servers are operated on infrastructure provided by Cloudflare. Apple and Google distribute the app itself through their app stores, and otherwise do not receive your choir's records.

Push notifications are delivered through Expo, a United States company. To tell management that a member has cancelled, the event's name and the phone token of the person being told pass through Expo on the way to Apple or Google. The member's name and the reason they gave never do.

Signing in, and how sessions are protected

When you sign in, your device stores a session token in the operating system's own secure store: the keychain on iOS, the keystore on Android. It is not kept in ordinary app storage.

On our side we never store the token itself, only a hash of it. A hash can confirm that the token you present is the right one, but it cannot be turned back into a working token. If our records were read by someone who should not have them, they could not sign in as you with what they found.

What we measure about the app itself

Our hosting provider, Cloudflare, keeps a short-lived technical log of requests to our servers and of any errors, so that we can find and fix faults. It records things such as the time, the web address requested and whether it worked. Nothing is measured about how members use the app.

Our own log lines carry technical details only. Each one is a message we wrote in advance, filled in only with details we check before they are written: the kind of error, the part of the system and the database table and columns involved, an error code from the database's or the email service's published list, a standard description of the fault, the place in our program where it happened, and how long the withheld error text was.

A few lines add other checked technical values: the reference numbers our system generated for records our staff created, a seat count, the status code another service answered with, and, if our staff sign-in cannot fetch its security keys, the address of that key service and how many keys are still held.

Apart from the technical values listed above, no log line includes the content of anything a member typed or anything that was being saved, and none copies the wording of an error, so none holds names, email addresses, message content, or any free text a member has typed.

How long we keep things

The choir decides how long its own records are kept, because the choir is the responsible party. Attendance history, tasks and events remain available for as long as the choir wants them. The choir's management can delete a task or an event at any time, and can correct an attendance mark at any time, but there is no way to delete an attendance record outright.

When a member is removed from a choir, their access ends immediately. The choir keeps a record that they were a member, so that it has a history of its members: their name, voice part and role, the dates they joined and left, and their attendance history. Only the choir's management can see it, and their email address is no longer shown to the choir.

Their passport number and dietary requirements are deleted when they leave, and their agreement to the choir holding dietary requirements ends with them. Their phone number and birthday are deleted too, unless they chose to let the choir keep their contact details after leaving.

Their sign-in is deleted unless they chose that, or they belong to another choir that still needs it. If it is kept only because they chose to stay in touch, the email address stays, the choir's management can see it, and the password is deleted. This applies to members who leave from 1 October 2026. Someone who left a choir before then can ask us to delete their sign-in, at info@sjl-consulting.co.za.

When a choir asks us to close its account, we keep its data for 30 days so that it can be restored if the choir changes its mind or the account was closed in error, and then we delete it from production. When a choir's licence lapses without being renewed, we keep its data for 12 months, as the terms of service set out, and warn the choir's management in writing before deleting it.

In both cases the deletion is carried out by us, by hand, not by an automatic process. Backups fall away on their own backup cycle after that. If a choir wants its data deleted sooner, or wants an export before deletion, ask us and we will do it.

Billing records are kept for as long as South African tax and company law requires us to keep them. Those are SJL Consulting's own records, not the choir's.

Your rights

Under POPIA you may ask what personal information is held about you, ask for it to be corrected if it is wrong, and ask for it to be deleted where there is no longer a reason to keep it. You may also object to how it is being used.

Start with your choir. Your choir's management can see, correct and remove members directly in the web console at portal.atchoir.com, including a misspelled name or a wrong voice part. If that does not resolve it, write to us at info@sjl-consulting.co.za.

If your choir cannot resolve it, write to info@sjl-consulting.co.za and say which choir you belong to and what you are asking for. We will confirm receipt and respond within a reasonable time. Where we hold the data as an operator, we will act on the choir's instruction rather than on our own judgement, and we will tell you that is what we are doing.

We may need to confirm who you are before acting on a request, so that nobody else can obtain or change your information by pretending to be you.

You may also complain to the Information Regulator (South Africa). Their contact details are published at inforegulator.org.za.

Deleting an account

A member can ask their choir's management to remove them from the choir. Removal ends access at once and takes the member off the choir's current list. The choir keeps them on its list of former members (name, voice part, role, the dates they joined and left, and attendance history), which only management can see, and their email address is no longer shown to the choir.

The yes-or-no replies they gave for events stay as part of that history; any reason they typed is deleted. What happens to their personal details and sign-in when they leave is set out under "How long we keep things" above.

To have your personal information deleted, and not only to leave a choir, use Delete account on the app's Account screen (tap your initials at the top right of any screen). If you can no longer sign in, write to info@sjl-consulting.co.za instead. We delete the display name, email address, voice part, phone notification token, any personal details you added (phone number, birthday, passport number and dietary requirements), and any reply and reason you gave for an event, in every choir you belong to.

Some things survive that deletion. Attendance records, to-dos, chat messages and documents you uploaded may remain, with your name taken off them, because a choir's own record of its rehearsals, its work and its files belongs to the choir.

The record of your place in each choir also remains without your name: your role there and the dates you joined, rested and left, because those decide how the choir's attendance totals count. So does the record of which version of the member terms you accepted and of your answers about your own information, each with its date.

When you delete your account, your event replies do not survive in any form. Unlike attendance, the yes-or-no answer and any reason you gave are deleted outright. If a choir wants a specific record removed as well, write to us at the address above.

Buying AtChoir

The app is free to download on both app stores. There is nothing to buy inside it, and no individual can subscribe.

Choirs are invoiced directly by SJL Consulting, by EFT. A choir gets in touch, we set the organisation up, and the choir's management then adds the members, who are each emailed a link to set up their account. The only personal information involved in payment is the choir's own billing contact.

To set up a choir, write to info@sjl-consulting.co.za.

Changes to this page

If we change how personal information is handled, we will change this page and note the date. Where a change is significant, we will tell the choirs directly rather than rely on anyone re-reading the site.

Contact

SJL Consulting (Pty) Ltd, registration number 2019/210092/07, trading as AtChoir.

14 Leonor, Dundas Street, Strand, 7140, South Africa.

info@sjl-consulting.co.za

POPIA notice

This section sets out, in one place, the information required by the Protection of Personal Information Act, 4 of 2013. It repeats what is above rather than adding to it.

POPIA notice: responsible party and operator

Each choir using AtChoir is the responsible party for its members' personal information. The choir determines the purpose of the processing and the means by which it happens.

SJL Consulting (Pty) Ltd, registration number 2019/210092/07, of 14 Leonor, Dundas Street, Strand, 7140, is the operator. It processes that personal information on behalf of the choir, on the choir's instruction, and for no other purpose.

SJL Consulting is itself the responsible party in respect of its own billing records and its own technical telemetry.

POPIA notice: Information Officer

The Information Officer of SJL Consulting (Pty) Ltd can be contacted at info@sjl-consulting.co.za, or by post at 14 Leonor, Dundas Street, Strand, 7140, South Africa.

Requests for access, correction or deletion, and any complaint about how personal information has been handled, may be sent to that address.

POPIA notice: information processed and purpose

The categories of personal information processed are: display name; email address; voice part (optional); role within the choir; the dates a member joined, rested and left the choir; attendance records including QR self-check-in events; apologies for events; calendar entries, including notes for members and repertoire; tasks and project assignments; chat messages; documents uploaded by management, together with who uploaded them; event replies, including the reason given when a reply changes from yes to no; which version of a choir's member terms a member accepted on joining, and when; where a member has chosen to add them, a phone number, date of birth, passport number and dietary requirements; a member's answers on whether the choir may keep their details after they leave and may hold their dietary requirements; and a phone's push notification token.

The purpose of the processing is the administration of a choir, orchestra, band or ensemble: keeping attendance records, scheduling rehearsals and events, allocating work, and allowing members to communicate with one another.

No age and no minor status is stored. A date of birth is stored only where a member adds their own.

The app does ask for one piece of free text: a short reason, of up to 280 characters, when a member changes a reply from yes to no on an event that asks for one. Members are told, at the point of typing, not to include medical details, and the reason is shown only to the choir's management.

Dietary requirements, which a member may add, can reveal health or religious belief and are special personal information within the meaning of POPIA. They are saved only with the member's own consent (and, for a member whose birthday shows they are under 18, only where the choir has attested that it holds a parent's or guardian's consent), stored encrypted, shown only to the choir's management, and deleted when the member withdraws that consent or leaves the choir. Beyond those two fields, no special personal information is requested by the app.

Supplying a display name and an email address is necessary in order to use the app. Supplying a voice part, a phone number, a birthday, a passport number or dietary requirements is optional.

POPIA notice: children

Section 34 of POPIA prohibits the processing of the personal information of a child, and section 35 sets out the circumstances in which that prohibition does not apply, including where a competent person such as a parent or guardian has consented.

AtChoir does not decide which of a choir's members are children. It shows the choir's management "Under 18" beside a member who has added a birthday that makes them so, and relies on nothing else, because a member who has given no birthday may still be a child.

The choir attests that it has obtained the consent required by section 35 for every member who is a child, covering the information the attestation lists, and undertakes to keep the record of that consent. Where a member's own birthday shows they are under 18, their dietary requirements are stored only if the choir has made that attestation in its current wording. The choir, as responsible party, remains accountable for that consent.

POPIA notice: cross-border transfer

Production data, including uploaded documents, is stored under the jurisdiction of the European Union. The jurisdiction is fixed when each datastore is created and cannot be changed afterwards. No African region is offered for either datastore.

The transfer is made in reliance on section 72 of POPIA, on the basis that the law of the receiving jurisdiction upholds principles for the lawful processing of personal information that are substantially similar to the conditions in POPIA, and includes provisions substantially similar to section 72 governing onward transfer.

The transfer is also given effect by the contract between SJL Consulting and its infrastructure provider, and by the contract between SJL Consulting and each choir.

POPIA notice: security safeguards

Session tokens are stored on the member's device in the platform keychain or keystore. Only hashes of session tokens are stored on the server, so a stored value cannot be replayed as a valid session.

Access to a choir's data is limited by role. A member's personal details can be seen only by that member and by the choir's management, and changed only by that member. Technical and error logs exclude names, email addresses, message content and all free text.

A member's passport number and dietary requirements are encrypted before they are stored, with a key that is kept apart from the database. If that key is not available, those two fields are refused rather than stored unencrypted.

POPIA notice: data subject rights

A data subject may request confirmation of whether personal information about them is held, and a record or description of that information; request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully; object to the processing; and complain to the Information Regulator.

Requests should be directed to the choir in the first instance, as responsible party, and may be directed to the Information Officer at info@sjl-consulting.co.za. Identity may need to be verified before a request is acted on.

The Information Regulator (South Africa) publishes its contact details and complaint forms at inforegulator.org.za.