Privacy Policy for Wezi Financial Advisor (Pty) Ltd

UPDATED PRIVACY POLICY (AS AT 13 MAY 2023)

1. Introduction

1.1. This Privacy Policy forms part of our standard Terms & Conditions of Service and applies to

all users of our services (registered or non-registered), including visitors to our website (User,

you, your). All references herein to us, our, or we are to Wezi Financial Advisor (Pty) Ltd.

1.2. Your privacy is important to us. The purpose of this Privacy Policy is to help you understand

how we collect, use, store, and share personal data about you. Personal data means any

information about an individual from which that person can be identified and does not include

anonymous data.

1.3. If you do not agree with this Policy, you may not use our website or our services and are

required to cease doing so immediately.

1.4. PLEASE NOTE: Where you use our services to communicate messages to third parties

such as your customers, we act as the data processor, and you act as the data controller. This

means that you determine the purpose and means of processing information about message

recipients. It is your responsibility to ensure that the data uploaded to our platform conforms to

all applicable local and international data protection laws and regulations, including but not

limited to the General Data Protection Regulation (GDPR) and South Africa’s Protection of

Personal Information Act (POPIA).

2. The Personal Data We Collect About You and Where We Get It From

2.1. We collect relevant and minimal personal data about you for the purpose of managing your

affairs with us.

2.2. We collect information about you when you register for an account, create or modify your

profile on our website, purchase services from us, raise a query with our support team, contact

us by phone, email, or live chat, sign up to any of our mailing lists, request marketing to be sent

to you, take part in surveys, or provide feedback.2.3. We may collect, use, store, and transfer different kinds of personal data about you,

grouped as follows:

Note: All credit card and electronic funds transfer payment processes are managed directly by

third-party payment service providers. We do not hold your credit card details.

3. How We Process Your Personal Data

3.1. We will process your personal data in a manner that is adequate, relevant, and not

excessive, compatible with the purpose for which it was collected unless you have consented to

an alternative purpose in writing, or we are authorized by POPIA or national legislation.

3.2. We commonly use your personal data in the following circumstances:

3.3. Marketing communications will only be sent if you have requested them, purchased

services from us, or provided explicit consent. You can opt-out at any time.

3.4. All processing of your data will adhere to applicable laws and will be conducted to the

minimum extent necessary.

4. Cookies

4.1. We use temporary or session cookies to remember details about your interaction with our

website.

4.2. We utilize first and third-party cookies to enhance the user experience, track usage, and

display relevant advertising. Tools such as Google Analytics and Google Analytics Remarketing

help us achieve this.

4.3. Cookies help us track usage patterns and compile de-identified data.

4.4. Classes of information collected via cookies include:

4.5. You can manage your cookie preferences in your browser settings. Opting out may disable

certain features on our website.

4.6. You can opt-out of third-party cookie by emailing info@wezifin.co.za replying

Stop/Unsubscribe to any correspondence you receive.

5. Keeping Your Personal Data Secure

5.1. We utilize data center service providers in the United Kingdom and South Africa to host and

store information on our private cloud infrastructure.

5.2. Adequate technical, organizational, and security measures are in place to protect your

personal data. Access is restricted to authorized personnel, and all third parties are bound by

confidentiality agreements.

5.3. We take measures to prevent:

5.4. We continuously update security measures against new risks or deficiencies.

5.5. Although we implement robust security, the inherent nature of the Internet means we

cannot guarantee absolute data security. Transmitting personal data is done at your own risk.

5.6. Procedures are in place to handle suspected data breaches, and we will notify you and

relevant regulators when required.

6. How We Share the Personal Data We Hold About You

6.1. We do not sell your personal data to third parties.

6.2. Your data may be shared with third-party hosting, backup, storage, and virtual infrastructure

service providers necessary for our operations. These third-party providers comply with similar

data protection standards.

6.3. Third-party providers only process your data per our instructions.

6.4. Exceptional circumstances for data sharing include:

6.5. We may share data only with your explicit consent.

6.6. Information may be transferred in case of company mergers, sale of assets, or acquisitions.

6.7. Our website may contain links to third-party websites. We’re not responsible for their

privacy practices; please review their policies before sharing your data.

6.8. Communications may be monitored for system health and forensic reasons per the

Regulation of Interception of Communications Act 70 of 2002 (RIC Act).

7. How Long Do We Keep Your Personal Data?

7.1. We retain personal data only as long as necessary to fulfill the purpose for which it was

collected.

7.2. Account information is kept active for the duration you are using our services and for a

reasonable period afterward.

7.3. We keep some information to comply with legal and regulatory obligations, resolve

disputes, and enforce agreements.

7.4. Written requests for data deletion will be honored unless we're legally obliged to retain it.7.5. Anonymized personal data may be used for research or statistical purposes indefinitely.

8. Accessing and Controlling Your Personal Data

8.1. You have the right to:

8.2. For exercising your rights or complaints, please contact us. We aim to respond within one

month and may charge a reasonable fee for unfounded or repetitive requests.

8.3. You can access and update your information through account settings or contact us directly

for assistance.

8.4. Deactivating your account does not delete your information; you may opt out of promotional

communications but will still receive transactional messages.

9. Transfer of Personal Data

9.1. Our website operates from South Africa, and by using it, you consent to transferring,

processing, and storing your information in South Africa.

9.2. If you are an EU resident, we control your personal data per EU data protection laws.

9.3. We require third-party service providers to match South African data protection standards.

9.4. Hosting or cloud services located outside South Africa ensure similar data protection

through binding contracts or countries with equal privacy laws.

10. Children

10.1. Our website is not intended for children under 18. Processing data for individuals under

18 requires explicit parental or guardian consent.

11. Consent

11.1. By using our services, you consent to this Privacy Policy.

11.2. Consent is given voluntarily after understanding the policy’s provisions.

11.3. To withdraw previously given consent, contact our information officer.

12. Changes to this Privacy Policy

12.1. We may update this Privacy Policy periodically. Significant changes will be prominently

communicated.

12.2. Continued use of our website or services indicates acceptance of the updated Privacy Policy.

13. Contact Us

For any concerns or to exercise your legal rights, please contact us at:

Appendix 1 – How We Use Your Personal Data

How? What? Why?
To register you as a new customer and manage your account

Name and contact details,

Profile information

To perform our contract with you.
To enable you to log into our website and interact with customer service Name and contact details We have a legitimate interest in making it easy for you to use our website and services.
To sell you services Name and contact details, Purchase history To perform our contract with you.
To take payments and give refunds Payment information To perform our contract with you.
To send you service messages Name and contact details To perform our contract with you.
To provide customer support and training Purchase history, Customer service history To perform our contract with you. We have a legitimate interest in improving customer service.
To send you information about new services Name and contact details, Marketing preferences We have a legitimate interest in developing our services.
To ask you to leave reviews or take surveys Name and contact details, Profile information, Marketing preferences, Survey responses We have a legitimate interest in understanding customer needs and improving services.
To administer and protect our business and this website Name and contact details, Payment information We have a legitimate interest in running our business, network security, and legal ramifications.
To use data analytics Name and contact details, Purchase history, Profile information We have a legitimate interest in optimizing our service and understanding customer needs.