Legal
Privacy Policy
AfricaPay
1. Introduction and Purpose
AfricaPay and its associated services (collectively referred to as "AfricaPay", "we", "us", or "our"), provides payment infrastructure, merchant acquiring, digital wallets, payment gateways, and digital asset services.
We are dedicated to safeguarding the privacy of our clients, merchants, consumers, authorized representatives, and ultimate beneficial owners. This Privacy Policy governs the collection, use, processing, disclosure, storage, and protection of Personal Information in compliance with the Protection of Personal Information Act, No. 4 of 2013 ("POPIA"), while fulfilling our statutory compliance and reporting obligations under the Financial Intelligence Centre Act, No. 38 of 2001, as amended ("FICA"), the Protection of Constitutional Democracy Against Terrorist and Related Activities Act, No. 33 of 2004 ("POCDATARA"), and other applicable South African financial regulations.
2. Responsible Party and Information Officer Details
AfricaPay is the Responsible Party in respect of all Personal Information processed under this Policy:
- Entity Name: AfricaPay
- Registration Number: 2021/963668/07
- Registered Address: 16 14th Street, Menlo Park, Pretoria, Gauteng, 0081
- Website: https://africapay.co.za/
- Compliance & Information Officer Email: privacy@africapay.co.za / compliance@africapay.co.za
3. Categories of Personal Information Collected
To establish business relationships, process financial and digital asset transactions, and satisfy mandatory statutory Customer Due Diligence (CDD) obligations, we collect the following categories of information:
3.1. Natural Persons (Consumers, Sole Proprietors, Directors, Trustees, Partners, and Ultimate Beneficial Owners)
- Identity Data: Full legal name, date of birth, nationality, South African Identity Number, or foreign passport details.
- Verification Documents: Certified copies of Identity Documents/Passports, photographs, or biometric records.
- Contact Data: Physical residential address, postal address, email address, and mobile contact numbers.
- Financial & Tax Data: Bank account verification details (less than 3 months old), South African Revenue Service (SARS) income tax number, and tax residency status.
- Source of Funds & Wealth: Occupation, employer name, nature of business activities, documented proof of source of funds, and broader source of wealth.
- Prominence Classification: Disclosures regarding Domestic Prominent Influential Person (DPIP) or Foreign Prominent Public Official (FPPO) status, including immediate family and close associate relations.
3.2. Legal Entities (Companies, Close Corporations, Partnerships, Trusts)
- Corporate & Registration Data: Registered legal name, trading name, CIPC registration certificate (COR14.3 / CM1 / CK1 / CK2), Memorandum of Incorporation (MOI), trust deeds, and partnership agreements.
- Operational Data: Proof of registered office and business operating address (less than 3 months old), utility bills, and contact details.
- Tax & Fiscal Data: Official SARS documentation confirming Income Tax and VAT registration numbers.
- Governance & Ownership: Stamped shareholding register, organograms, resolutions appointing authorized signatories/representatives, and certified identification/proof of address for all directors, trustees, partners, and Ultimate Beneficial Owners holding 25% or more effective control or voting rights.
3.3. Transactional, Technical, and Digital Asset Data
- Transaction Records: Transaction values, currency/cryptocurrency pairings, transaction timestamps, payment channels, settlement records, sender/beneficiary details, and counterparties.
- Technical Telemetry: IP address, device fingerprints, operating system, geolocation identifiers, browser type, and system event logs.
- Blockchain & Digital Asset Data: Public cryptographic wallet addresses, transaction hashes, and on/off-ramp activity logs.
4. Legal Grounds and Purposes for Processing
We process your Personal Information only where a valid legal basis exists under POPIA, categorized as follows:
| Legal Ground | Purpose and Context |
|---|---|
| Legal & Statutory Obligation | Undertaking mandatory FICA Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD); screening against UN Security Council and Targeted Financial Sanctions (TFS) lists; reporting Cash Thresholds (CTR/CTRA) exceeding R24,999.00; submitting Suspicious and Unusual Transaction/Activity Reports (STR/SAR); reporting Terrorist Property (TPR/TFTR/TFAR); verifying credentials with CIPC, SARS, and the Department of Home Affairs. |
| Contractual Performance | Onboarding merchants, executing payment gateway routing, provisioning Point of Sale (AfriPOS) and digital wallet services (AfriWallet, AfriX), processing card/EFT/mobile money transactions, facilitating crypto-fiat on/off-ramps, and settling funds. |
| Legitimate Interests | Preventing fraud, detecting transactional anomalies via AI and risk-scoring mechanisms, maintaining ledger integrity, ensuring platform cybersecurity, and defending against legal claims. |
| Consent | Direct communications, opting in to specialized product trials, or specific processing scenarios where required by law. |
5. Mandatory Disclosure and Failure to Provide Information
In accordance with Section 20A and Section 21 of FICA, AfricaPay is strictly prohibited from establishing or maintaining a business relationship, or executing transactions with anonymous clients, clients using false/fictitious names, or parties whose identities cannot be verified.
Providing accurate, authenticated identification and source of funds documentation is a statutory requirement. Failure or refusal to provide mandatory information will result in:
- Immediate refusal or termination of the business relationship or single transaction.
- Potential filing of regulatory reports with the Financial Intelligence Centre (FIC) where circumstances appear suspicious or irregular.
6. Information Sharing and Third-Party Disclosures
We do not sell personal data. We disclose information strictly in accordance with legislative requirements or to authorized service providers under formal data-processing agreements:
- Regulatory & Statutory Authorities: We share data directly with the Financial Intelligence Centre (FIC), the South African Reserve Bank (SARB), the South African Revenue Service (SARS), and law enforcement agencies pursuant to statutory duties (e.g., FICA Sections 28, 28A, 29, 35).
- Verification & Screening Partners: Identity verification providers, credit bureaus, CIPC lookup nodes, and third-party AML/Sanctions compliance platforms (e.g., DocFox).
- Payment Infrastructure & Liquidity Partners: Registered acquiring banks, payment card networks (Visa/Mastercard), payment switches, and certified digital asset infrastructure partners (e.g., liquidity and on/off-ramp providers) to facilitate settlements and conversions.
- Legal Privilege & Secrecy Limitations: In terms of Section 37 of FICA, statutory reporting obligations override common law and contractual duties of secrecy and confidentiality, excluding communications protected by legal professional privilege.
- Anti-Tipping Off Obligations: In terms of Section 29 of FICA, AfricaPay and its employees are legally prohibited from informing any client or third party that a regulatory report or inquiry has been filed with the FIC.
7. Cross-Border Data Transfers
AfricaPay operates across African and international financial corridors. Personal information and transaction telemetry may be transferred, processed, and hosted on secure cloud infrastructure located outside of South Africa.
Cross-border transfers occur strictly under Section 72 of POPIA, ensuring that:
- The recipient country maintains data protection laws providing a level of protection substantially similar to POPIA; or
- The transfer is governed by binding contractual agreements (Standard Contractual Clauses) imposing rigorous data protection, confidentiality, and security standards; or
- The transfer is directly necessary for the performance of a cross-border contract or remittance transaction initiated by the client.
8. Record Retention
In alignment with Section 8 of our Risk Management and Compliance Programme and statutory directives under FICA, all Personal Information, identity verification files, client communications, transaction ledgers, declined/terminated client records, and regulatory filings are retained for a minimum period of 5 (five) years.
The 5-year retention period begins from the latest of:
- The date of the client’s final transaction;
- The formal termination date of the business relationship; or
- The date on which a formal report was submitted to the Financial Intelligence Centre (FIC).
Upon the lapse of statutory retention mandates, data will be safely destroyed, de-identified, or irreversibly anonymized in terms of POPIA.
9. Information Security Safeguards
AfricaPay maintains comprehensive physical, technical, and operational security measures to prevent loss, unauthorized access, destruction, or unlawful alteration of Personal Information:
- Encryption Standards: Data at rest is encrypted using AES-256 standards, and all data in transit across networks is protected via Transport Layer Security (TLS 1.3).
- Access Governance: Role-based access control (RBAC), multi-factor authentication (MFA), and detailed immutable audit trails for all system operations.
- Infrastructure Security: Enterprise-grade cloud environments, real-time threat detection, automated AML/fraud monitoring, regular vulnerability scanning, and independent security assessments.
10. Data Subject Rights Under POPIA
Subject to statutory limitations imposed by FICA, POCDATARA, and the Prevention of Organised Crime Act (POCA), data subjects have the right to:
- Access: Request confirmation of whether we hold Personal Information about you and receive a copy of that record.
- Correction & Rectification: Request correction, completion, or updating of inaccurate, irrelevant, out-of-date, or misleading information.
- Deletion / Destruction: Request erasure of Personal Information, provided the data is no longer necessary for contractual purposes and the statutory retention period under FICA (5 years) has elapsed.
- Objection: Object to processing based on reasonable grounds relating to your particular situation (unless processing is mandated by law).
- Complaints: Lodge a complaint with our Information Officer at privacy@africapay.co.za or escalate to the South African Information Regulator.
Contact Details for the Information Regulator (South Africa)
- Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- Postal Address: P.O Box 31533, Braamfontein, Johannesburg, 2017
- Complaints Email: complaints.IR@inforegulator.org.za
- General Inquiries: enquiries@inforegulator.org.za
11. Amendments and Policy Reviews
This Privacy Policy is subject to an annual review alongside our internal Risk Management and Compliance Programme (RMCP). Any changes necessitated by legislative developments, operational adjustments, or supervisory notices will be updated on this page with a revised "Last Updated" date.