Legal centre · POPIA

Your information,
and what you can ask us to do.

Access, correction, deletion and objection under the Protection of Personal Information Act, set out as a procedure you can actually follow. Also, plainly, what happens when a regulator or the police ask us for information about you.

Version 1.0 · Effective 18 August 2026 · Next review 18 February 2027

You do not need a form to start

Email support@conexus-crypto.com with "data request" in the subject line, or message the desk on WhatsApp or Telegram. We accept a substantially similar request in any written form. The prescribed forms exist if you prefer them, and we will send you a blank copy of any of them.

The four rights

Access, correction, deletion, objection.

Each right comes from a named section of POPIA, and each has a limit worth knowing before you use it. The detail, including the limits, is in the document below.

Access

Section 23: be told free of charge whether we hold personal information about you, and be given a record or a description of it, including who has had access to it.

Correction

Section 24(1)(a): have information corrected where it is inaccurate, out of date, misleading, excessive or obtained unlawfully. Where a record must be kept as it stands, we correct forward and date it.

Deletion

Section 24(1)(b): have a record destroyed where we are no longer authorised to keep it. Sections 22 and 23 of the FIC Act require five years, and where they apply, the statutory duty prevails and we say so in writing.

Objection

Section 11(3): object to processing that rests on legitimate interests. Direct marketing is governed separately by section 69, and an objection to marketing is absolute and needs no reason.

One thing we cannot do

A section 29 report cannot be disclosed to you.

Section 29 of the Financial Intelligence Centre Act requires a suspicious or unusual transaction report, with no monetary threshold, within 15 days excluding weekends and public holidays. The Act makes it an offence to disclose that such a report has been made. We are therefore not able to confirm or deny one, to you or to anyone else. Any desk that tells you it would warn you first is describing a crime.

The short version

You have the right to know what personal information we hold about you, to have it corrected if it is wrong, to have it deleted where we are not required to keep it, and to object to us using it for certain purposes. You do not have to explain why you want to exercise those rights, and exercising them costs nothing.

Write to support@conexus-crypto.com with the words "data request" in the subject line, say which of the four things you want, and give us enough detail to find you. We will acknowledge it, verify that you are who you say you are, and answer in writing.

The rest of this page explains the formal machinery behind that, because you are entitled to use the formal machinery if you prefer it, and because a desk that holds identity documents and bank statements should be able to describe the process precisely rather than vaguely.

That machinery is South African. The desk deals with clients in more than one country, but the company holding your information is registered in the Republic, so the Protection of Personal Information Act and the Promotion of Access to Information Act are the statutes that govern what it holds and what you can require of it — wherever you happen to bank, and whatever currency you settled in.

Who handles these requests

Information OfficerInformation Officer — to be confirmed
Deputy Information OfficerInformation Officer — to be confirmed
Responsible partyregistered company name — to be confirmed, registration number CIPC registration number — to be confirmed
Emailsupport@conexus-crypto.com
Telephone and WhatsApp+27 76 560 1228
AddressTiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925

In a private body the head of the body is the Information Officer by operation of law, under section 1 of PAIA and section 1 of POPIA. The duties of the role are set out in section 55 of POPIA: to encourage compliance with the conditions for lawful processing, to deal with requests made to the body, to work with the Information Regulator in relation to investigations, and otherwise to ensure that the body complies with the Act. Regulation 4 of the POPIA Regulations requires the Information Officer to be registered with the Information Regulator before performing those duties, and our Information Officer is registered accordingly. Deputy Information Officers are designated under section 17 of PAIA so that there is always somebody available to receive a request.

The formal manual describing every category of record this body holds is the PAIA section 51 manual. What we collect and why is in the privacy policy.

The four rights, and what each one actually gets you

Access

Section 23 of POPIA gives you the right to be told, free of charge, whether we hold personal information about you, and to be given a record or a description of that information, including the identity of any third party who has had access to it. The mechanics of an access request run through PAIA, which is why the two Acts are stitched together on this site.

In practice, for a client of the desk, an access request returns the onboarding file we hold on you, the trade records associated with you, and the correspondence on file. If what you actually want is a copy of a specific settlement confirmation or a rate applied on a specific date, ask your trader. That is not a legal request, it is a normal one, and it takes minutes.

Correction

Section 24(1)(a) of POPIA gives you the right to request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. Corrections are usually simple: a changed address, a corrected spelling, a bank account that has been closed. Where a correction affects a record we are obliged to retain in its original form, we correct forward — the original record stays, and the correction is recorded against it with the date. Section 24(3) requires us to notify any third party to whom the information was supplied of the correction, where that is reasonably practicable.

Deletion

Section 24(1)(b) gives you the right to request destruction or deletion of a record of personal information that we are no longer authorised to retain. This is the right that most often meets a limit, and we would rather set out the limit here than surprise you with it later. Sections 22 and 23 of the Financial Intelligence Centre Act require customer due diligence records and transaction records to be kept for five years after the business relationship ends or the single transaction concludes. Tax legislation imposes its own retention period on the records supporting a return. Where a deletion request collides with either, the statutory retention duty prevails, we will tell you which provision we are relying on, and we will delete the record when the period expires. What we can and will do in the meantime is stop using the information for anything other than the purpose the law requires.

Objection

Section 11(3) of POPIA lets you object, on reasonable grounds, to processing that relies on legitimate interests or on the pursuit of our own or a third party's legitimate interests. If you object and the objection is upheld, we must stop that processing. Direct marketing by electronic communication is governed separately by section 69: we may only send it with your consent, or to an existing customer in relation to similar products, and every message must offer a way to opt out. An objection to marketing is absolute and takes effect immediately — you do not need a reason for that one.

The prescribed POPIA forms

The Regulations made under POPIA prescribe three forms that matter here. All of them are published by the Information Regulator and we will email a blank copy of any of them on request.

Form 1 Objection to the processing of personal information, in terms of section 11(3) of POPIA
Form 2 Request for correction or deletion of personal information, in terms of section 24(1) of POPIA
Form 4 Application for consent to process personal information for the purpose of direct marketing by electronic communication, in terms of section 69(2) of POPIA

A request for access to a record is made on Form 2 of the PAIA Regulations, which is a different Form 2 to the POPIA one. The two Acts each have their own numbered forms and the numbering is unhelpfully similar. If you tell us in plain words what you want, we will tell you which form applies, or handle it without one.

We accept a substantially similar request in any written form

The forms exist to make sure a request contains the information needed to act on it. They are not a gate.

We will accept any request that contains substantially the same information as the prescribed form, in whatever written form it reaches us. An email is fine. A WhatsApp message to the desk number is fine. A Telegram message on our published handle is fine. A letter delivered to the Cape Town office is fine. A scanned page in your own handwriting is fine. We will not refuse a request because it arrived on the wrong stationery, and we will not send you away to fill in a PDF when you have already told us what you need.

What a request does need to contain, however it arrives:

  • your full name, and any other name you have dealt with us under;
  • enough detail to identify you in our records — the mobile number or email address on file is usually the fastest;
  • which right you are exercising: access, correction, deletion, or objection;
  • for a correction, what is wrong and what it should say;
  • for a deletion, which information you want removed;
  • for an objection, what processing you are objecting to and, where the ground requires it, why;
  • an address, email or number where we can send the answer.

We verify identity before we act, and we do it proportionately. For an existing client we will usually verify through the channel and credentials already on file. Where a request would result in personal information being disclosed or destroyed and the identity of the requester is not established to our satisfaction, we will ask for more before we act — and we will explain what we are asking for and why, rather than simply going quiet. A request to send a client file to a new email address will always be checked by a call to the number on file.

If you are acting for somebody else — as an executor, a curator, a parent or guardian of a child, or under a power of attorney — send proof of that capacity with the request.

Timelines

AcknowledgementWithin 2 business days of receipt, with a reference
Access request under PAIADecision within 30 days of receipt, extendable once by up to 30 days under section 57, with written reasons
Correction or deletionAs soon as reasonably practicable; our target is 30 days, and we will tell you if a statutory retention period prevents deletion
Objection to processingConsidered and answered in writing within 30 days
Objection to direct marketingEffective on receipt; suppression applied within 2 business days
FeeNo fee for a request about your own personal information. Fees for other records are as set out in the PAIA manual

Where a request is complex, or where a record contains information about a third party who has to be consulted under sections 71 and 72 of PAIA, we will tell you before the original period runs out, say how much longer we need, and give the reason.

If you are not satisfied: the Information Regulator

Take it up with the Information Officer first. Most disagreements are about scope or about identity verification and are resolved in a single exchange. If that does not work, you have two independent routes and you do not need our permission to use either.

Under POPIA, section 74 allows a data subject to submit a complaint to the Information Regulator about alleged interference with the protection of personal information, or about a determination by an adjudicator. Under PAIA, section 77A allows a requester to complain to the Regulator about a decision of a private body, including a refusal of access, a deemed refusal, a fee, or an extension. A PAIA complaint must be lodged within 180 days of the decision unless the Regulator condones a late complaint. Beyond that, section 78 of PAIA allows an application to court, and POPIA allows civil proceedings under section 99.

BodyInformation Regulator (South Africa)
Physical addressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal addressP.O. Box 31533, Braamfontein, Johannesburg, 2017
Telephone010 023 5200
General enquiriesenquiries@inforegulator.org.za
PAIA complaintsPAIAComplaints@inforegulator.org.za
POPIA complaintsPOPIAComplaints@inforegulator.org.za
Websiteinforegulator.org.za

Complaints under POPIA go to POPIAComplaints@inforegulator.org.za and complaints under PAIA to PAIAComplaints@inforegulator.org.za. If your complaint is about the service you received rather than about your information rights, the complaints procedure sets out the route to the FAIS Ombud instead.

Requests for your information from police and regulators

The other half of this subject is what happens when somebody who is not you asks for your information. Clients rarely ask about it up front, and it is one of the more important things to understand about dealing with a regulated desk, so it is set out here in full.

South African law obliges an accountable institution to produce information in defined circumstances. The requests we can lawfully receive include:

  • a request from the Financial Intelligence Centre under the Financial Intelligence Centre Act 38 of 2001, including a request for information under section 27 and a direction under section 32;
  • a subpoena under section 205 of the Criminal Procedure Act 51 of 1977, issued by a magistrate on application by the prosecuting authority;
  • a search warrant issued by a court, executed by the South African Police Service or the Directorate for Priority Crime Investigation;
  • a request from the South African Revenue Service under Chapter 5 of the Tax Administration Act 28 of 2011, including a notice under section 46;
  • a supervisory or investigative request from the Financial Sector Conduct Authority under the FAIS Act or under Chapter 9 of the Financial Sector Regulation Act 9 of 2017;
  • a court order, including a preservation or restraint order under the Prevention of Organised Crime Act 121 of 1998;
  • an obligation arising under a sanctions measure binding on South Africa.

How we handle one

  1. Verify that the request is real

    Impersonation of law enforcement is a known technique for extracting client data. We verify the identity of the requester and the authenticity of the instrument through the issuing body’s own published channels, not through the contact details printed on the document.

  2. Check the authority and the scope

    We establish which provision is being relied on, whether it in fact empowers the request, and exactly what it covers. A request for one client’s file is not authority to hand over a list of clients, and a warrant is limited to what it names.

  3. Take legal advice where the position is not clear

    Where the instrument is ambiguous, overbroad or of doubtful validity, we take advice before producing anything, and we will challenge a request that exceeds its authority.

  4. Produce the minimum that the law requires

    We disclose what is lawfully demanded and no more. Records are produced in a form that can be traced, and we keep a copy of exactly what was handed over.

  5. Log it

    Every request, the authority relied on, the decision taken, the date, and the records produced are recorded. Section 23 of POPIA entitles you to be told the identity of third parties who have had access to your information, and that log is how we answer.

  6. Tell you, unless we are prohibited from telling you

    Our default is to notify the client that their information has been requested. Where the law prohibits notification, we do not notify, and we will not pretend otherwise on this page.

That last point deserves to be stated without softening. Section 29 of the FIC Act requires an accountable institution to report a suspicious or unusual transaction to the Financial Intelligence Centre, with no monetary threshold, and within 15 days excluding weekends and public holidays. The Act makes it an offence for a person who knows or suspects that such a report has been made to disclose that fact. We are therefore not able to confirm or deny whether a report has been made about any transaction, to you or to anyone else. Any desk that tells you it would warn you first is describing a crime.

Equally, this is what we do not do. We do not sell personal information. We do not share client information with marketing partners or data brokers. We do not give information to another client, to a counterparty, or to a person who telephones claiming to be from your bank. And we do not respond to an informal request from a person asserting authority without an instrument behind it. The rules we apply to onboarding and monitoring are set out in full in the AML and KYC policy.

Security incidents affecting your information

Section 22 of POPIA requires a responsible party that has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, subject only to a determination by a public body or the Regulator that notification would impede a criminal investigation.

The notification must be in writing and must give sufficient information to allow you to take protective measures, including a description of the possible consequences, the measures we intend to take, a recommendation of what you can do to mitigate the effect, and, if we know it, the identity of the person who accessed the information.

We hold to that. If information about you is compromised, you will be told what happened, what was affected, and what to do about it — by name, not by press release.

Read next

Send the request, get a reference.

Every data request is acknowledged in writing within two business days with a reference number, and answered by a person who can explain the outcome rather than quote a policy at you.

Investing in crypto assets may result in the loss of capital, as the value is variable and can go up as well as down. A crypto asset is not legal tender and is not a regulated deposit. Conexus Crypto provides an exchange service only and does not provide financial, investment, legal or tax advice.
WhatsApp Request a quote
ДизайнНовыйПрежний