POPIA and PAIA requests
Which form to use to get a copy, a correction or a deletion, and what it costs.
This notice is the section 18 notification that the Protection of Personal Information Act 4 of 2013 requires a responsible party to give you. Its headings are the subsections of section 18(1), in order, so that you can check the notice against the statute rather than against a template written for another country.
Version 1.0 · Effective 18 August 2026
Most of what the desk collects is collected because the FIC Act requires it, not because it is convenient: without it the desk may not lawfully trade with you. None of it is sold, none of it builds a marketing profile, and it is kept for five years after the relationship ends because sections 22 and 23 of the FIC Act require that.
The responsible party is registered company name — to be confirmed, registration number CIPC registration number — to be confirmed, trading as Conexus Crypto, of Tiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925, South Africa.
The registered Information Officer is Information Officer — to be confirmed, reachable at support@conexus-crypto.com or on +27 76 560 1228. Section 55 of POPIA makes the Information Officer responsible for compliance, for dealing with requests made to the desk, and for working with the Regulator. Where the name above is marked as awaiting confirmation, that appointment has not yet been published on this site; requests sent to the address above still reach the person holding the role.
The desk is a responsible party in its own right for client and website data. It is not an operator for anyone else, and it does not process personal information on instruction from a third party.
The desk is established in South Africa, so POPIA is the law that governs how it handles your information — wherever you live, and whatever currency you settle in. Where the law of your own country gives you further rights over your information, this notice does not displace them: write to the Information Officer and you will be told how a request of that kind is handled.
Collected directly from you, during onboarding and afterwards: full names and any former names; date of birth; identity number or passport number and the document image; nationality and country of tax residence; residential and postal address, with a document evidencing it; contact telephone number and email address; the instant messaging handle you choose to deal on; occupation or the nature of your business; bank account details and the name in which the account is held; SARS income tax reference number where you have one; source of funds and, where enhanced due diligence applies, source of wealth; blockchain addresses you nominate and the networks they sit on; and, for a legal person, its registration documents, its authorised representative and its beneficial owners down to natural persons.
Generated by us about you: the record of every quote requested, issued, accepted or lapsed; trade confirmations; settlement records; the risk rating applied to you under our Risk Management and Compliance Programme; notes of calls and meetings held for compliance purposes; correspondence with you; and the record of any report the desk was obliged to file.
Collected from sources other than you, which section 18(1)(a) requires us to identify: sanctions, terrorist financing and watch-list data from the United Nations Security Council consolidated list and the Targeted Financial Sanctions list maintained under the FIC Act, together with equivalent screening data supplied by our banking and liquidity counterparties; politically exposed person and adverse media data from commercial screening databases; identity verification results from the providers our RMCP names; blockchain analytics on the addresses you use, drawn from public ledger data and from a commercial analytics provider; company, director and beneficial ownership data from the CIPC; and, where you were introduced by an existing client, the fact of that introduction.
Collected automatically when you use this website: the two browser storage keys described in the cookie notice, and standard server log data held by our hosting provider — IP address, user agent, requested URL, timestamp and response status. The website sets no analytics or advertising cookie.
registered company name — to be confirmed, registration number CIPC registration number — to be confirmed, Tiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925, South Africa. Postal address as above. Telephone +27 76 560 1228. Email support@conexus-crypto.com. Information Officer: Information Officer — to be confirmed.
The desk's Johannesburg location operates by appointment and holds no separate record system; every record described in this notice is held under the Cape Town entity.
Your information is not sold, rented, exchanged or used to build a marketing profile, and it is not used for any purpose incompatible with those listed above.
Mandatory, because a statute requires it. Your full names, date of birth, identity or passport number and its image, residential address and its proof, nationality and tax residence, the nature and purpose of the business relationship, the source of funds and, in a higher-risk case, the source of wealth, beneficial ownership for a legal person, your bank account details, and the originator and beneficiary information that Directive 9 requires to accompany a transfer. The desk cannot lawfully trade with you without these. Note that Directive 9 of 2024 applies with no minimum threshold; below R5 000 a reduced information set applies and the ordering institution need not verify it, which is verification relief and not anonymity.
Mandatory, because the desk's own Risk Management and Compliance Programme requires it. Your SARS income tax reference number where one has been issued to you, your occupation or line of business, and confirmation of which blockchain addresses you control. These are our requirements rather than express statutory fields, and they exist because a section 42 RMCP has to set out how the desk decides what it needs.
Voluntary. The instant messaging channel you prefer to deal on, an alternative contact number, your preferred language, any commentary you give about a trade beyond what due diligence requires, and your consent to receive non-operational messages. Nothing here affects whether the desk can trade with you.
If you do not provide the mandatory statutory information, the desk cannot onboard you and cannot execute a trade. This is not a commercial preference: section 21 of the FIC Act prohibits an accountable institution from establishing a business relationship or concluding a single transaction with a client whose identity it has not established.
If you provide the information at onboarding but then decline to update it, or decline to answer a question raised by ongoing due diligence under section 21C, the desk may suspend trading until the position is resolved, and in some circumstances must terminate the relationship.
If you decline to provide information the desk asks for under its own RMCP, the desk may still be able to proceed, usually at a higher risk rating and sometimes with a lower limit. A trader will tell you which category a request falls into if you ask.
Declining to provide voluntary information has no consequence beyond the obvious one: we will contact you on the channel we do have.
Some of your information leaves South Africa. Section 72 of POPIA permits this only in defined circumstances, and the desk relies on the following.
Website hosting and edge delivery. This website and its form endpoints run on Cloudflare's global network. A request you make may be served from, and logged at, a data centre outside South Africa. Cloudflare, Inc. is bound by contractual terms that impose obligations substantially similar to the conditions for lawful processing in POPIA, which is the basis in section 72(1)(a).
Bot mitigation on forms. Cloudflare Turnstile is loaded only on pages that carry a form. It receives the technical signals needed to distinguish a person from a script.
Screening and analytics providers. Sanctions, politically exposed person, adverse media and blockchain analytics providers may hold or process data outside South Africa. Each is engaged under a written operator agreement that requires POPIA-equivalent safeguards and prohibits use of the data for the provider's own purposes.
Counterparty institutions under the Travel Rule. Where you send crypto assets to, or receive them from, an institution in another country, Directive 9 of 2024 requires originator and beneficiary information to travel with the transfer. That transfer is necessary for the performance of your contract with the desk, which is the basis in section 72(1)(b), and the receiving institution is itself subject to Travel Rule obligations in its own jurisdiction.
Where a recipient country's law does not provide an adequate level of protection, the desk relies on contractual safeguards, and it will tell you which basis applies to a specific transfer if you ask.
Recipients and categories of recipients. The Financial Intelligence Centre, where a report or a request for information requires it. The FSCA and other regulators, on lawful request. SARS, under the Tax Administration Act and the Crypto-Asset Reporting Framework. Law enforcement and the courts, under a warrant, subpoena or court order. The desk's banking partners and liquidity venues, to the extent needed to settle your trade and to satisfy their own compliance duties. Counterparty institutions under the Travel Rule. Operators engaged in writing: hosting and edge infrastructure, email, identity verification, sanctions and PEP screening, and blockchain analytics. The desk's professional advisers — auditors, attorneys, the external compliance function — under professional duties of confidentiality. A successor in title, if the business is transferred, on notice to you.
Nature of the information. Identity and contact data, financial and transactional data, compliance and risk data, and technical website data. Some of it is special personal information within the meaning of section 26 of POPIA only in narrow cases — for example where a document you supply reveals biometric data. The desk does not collect information about your religion, philosophical beliefs, race, trade union membership, political persuasion, health, sex life or criminal behaviour, except where a sanctions or adverse media screening result unavoidably discloses the last of these; section 27(1)(b) permits that processing where it is necessary to comply with an obligation of international public law or to establish or defend a right.
The right of access and the right to rectify. You may ask what personal information the desk holds about you and ask for a copy, and you may ask for information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained to be corrected or deleted. The section below on your rights explains the mechanism for each.
The right to object. You may object to processing on reasonable grounds under section 11(3)(a), except where the processing is required by law — which covers most of what appears in this notice.
The right to complain to the Regulator. Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · PO Box 31533, Braamfontein, 2017 · telephone 010 023 5200 · general enquiries enquiries@inforegulator.org.za · POPIA complaints POPIAComplaints@inforegulator.org.za · PAIA complaints PAIAComplaints@inforegulator.org.za · inforegulator.org.za
Compliance with an obligation imposed by law — section 11(1)(c). This is the basis for identity verification, due diligence, screening, record keeping, Travel Rule messaging, and all reporting to the Financial Intelligence Centre and SARS. Your consent is not required for these and withdrawing it would not stop them.
Necessary for the performance of a contract — section 11(1)(b). This is the basis for quoting, executing and settling trades and for the operational messages that go with them.
Legitimate interests — section 11(1)(f). This is the basis for fraud prevention, securing this website, keeping a record of correspondence, and defending a claim. The desk has balanced those interests against your privacy and applies the narrowest processing that achieves the purpose.
Consent — section 11(1)(a). This is the basis only for optional analytics cookies, if the site ever loads any, and for any non-operational message you have asked to receive. Consent given here can be withdrawn at any time, and withdrawing it does not affect processing that already happened lawfully.
Section 14 of POPIA prohibits keeping records identifying a data subject for longer than necessary, unless a law requires or authorises retention. Several do.
At the end of a retention period, records are destroyed or de-identified in a way that prevents reconstruction, as section 14(4) requires.
Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. In practice that means: transport encryption on every page and every form on this site; encryption at rest for client documents; access to client files limited to the traders and compliance staff who need them, with individual accounts and multi-factor authentication; separation between the public website and the systems that hold client records; logging of access to compliance records; a written incident response procedure; and confidentiality undertakings from every person with access.
Section 20 requires an operator to process only with the responsible party's knowledge, and section 21 requires a written contract with each operator obliging it to maintain the same security safeguards. Every operator engaged by the desk is under such a contract. If you want to know which operators handle a specific category of your information, ask the Information Officer and you will be told.
No safeguard is absolute, and this notice does not claim otherwise. The largest realistic risk to your information is not a breach of the desk's systems but somebody impersonating the desk to you, which is why the verify our channels page exists and why the desk will never ask you for a private key, a seed phrase or a one-time password.
Section 5 of POPIA gives a data subject the following rights. For each one, this is the actual mechanism.
The desk does not charge for a correction, an objection or the first copy of your own record. Where PAIA prescribes a fee for reproduction of a large record, the fee and the calculation are given to you before any work starts.
Section 69 prohibits processing personal information for direct marketing by unsolicited electronic communication unless the data subject has consented, or is an existing customer contacted about the desk's own similar products with an opportunity to opt out on every message.
The desk sends operational messages — a quote, a confirmation, a settlement advice, a change to a document in this legal centre — because those are necessary to perform the contract, not marketing. Anything else is sent only if you asked for it, and every such message carries an unsubscribe instruction that works on the first attempt.
The desk does not buy contact lists, does not send unsolicited messages to people who have not dealt with it, and does not pass your contact details to anyone for their own marketing. To opt out of everything except operational messages, reply "stop" to any message or write to support@conexus-crypto.com.
Screening tools produce automated alerts — a possible sanctions match, an address flagged by blockchain analytics, an unusual pattern. Those alerts do not decide anything on their own. Every decision to decline a client, decline a trade or end a relationship is taken by a person in the compliance function, who records the reason.
You have the right under section 71 not to be subject to a decision with legal consequences based solely on automated processing. Because the desk does not take such decisions automatically, that right is not engaged in practice; if it ever becomes engaged, you will be told at the time and given the opportunity to make representations.
Section 22 requires a responsible party that has reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person to notify the Information Regulator and the affected data subject as soon as reasonably possible after discovering it, subject only to a delay requested by law enforcement to protect an investigation.
The desk undertakes to do exactly that. A notification to you will describe what happened, the categories of information involved, what the desk has done and is doing about it, what you should do to protect yourself, and the identity of the person who accessed the information if the desk knows it. It will be sent in writing to the email address on your record and, where the compromise is serious, by telephone as well. The desk will not soften the description or delay the notification to manage its own reputation.
If you believe your information held by the desk has been compromised, tell the Information Officer immediately at support@conexus-crypto.com.
The two browser storage keys this site writes, the one cookie Cloudflare may set, and how to withdraw consent are described in full in the cookie and local storage notice. No analytics or marketing script loads before consent is recorded.
Section 34 of POPIA prohibits processing the personal information of a child except in the circumstances section 35 allows. The desk does not knowingly onboard anyone under 18 and does not direct this website at children. If you believe a child's information has reached us, tell the Information Officer and it will be deleted unless a law requires it to be kept.
Complain to the desk first, in writing, to support@conexus-crypto.com, marked for the attention of the Information Officer. You will get an acknowledgement within two business days and a substantive answer within 30 days, in writing, with reasons.
You may complain to the Information Regulator at any time, whether or not you have complained to the desk first, using the Regulator's prescribed complaint form. Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · PO Box 31533, Braamfontein, 2017 · telephone 010 023 5200 · general enquiries enquiries@inforegulator.org.za · POPIA complaints POPIAComplaints@inforegulator.org.za · PAIA complaints PAIAComplaints@inforegulator.org.za · inforegulator.org.za
Where your complaint is about a financial service rather than about your information, the complaints procedure sets out the route to the FAIS Ombud instead.
Version 1.0. Effective 18 August 2026. Last reviewed 18 August 2026. Next scheduled review 18 August 2027, or sooner if the law or the desk's processing changes.
A material change to this notice — a new purpose, a new category of recipient, a new cross-border transfer or a change to retention — is notified to active clients by email before it takes effect, and the superseded version is kept and available on request. A change that only corrects a reference or improves clarity takes effect on publication.
Which form to use to get a copy, a correction or a deletion, and what it costs.
Everything this site writes to your browser, and how to withdraw consent.
Why this particular set of information is collected, and how client risk is rated.
A request for a copy, a correction or a deletion goes to the Information Officer at support@conexus-crypto.com and is answered within 30 days, in writing, with the statutory reference for anything that cannot be deleted.