POPIA Privacy Notice

1. Our commitment to privacy

Cape Mutual is committed to protecting your privacy and processing personal information in accordance with POPIA. This Notice explains how we collect, use, store, share and protect your personal information, and your rights in relation to it. In this Notice, Cape Mutual is the responsible party.

2. Information we collect

We may collect: name and surname; identity or passport number; contact details; business information; banking information; financial records; transaction history; device information; IP address; location information; credit history; affordability information; communication records; and information obtained from third parties.

3. Lawful basis for processing

We process personal information on one or more of the lawful bases recognised by POPIA, namely: your consent; the conclusion or performance of a contract with you; compliance with a legal obligation (including under the NCA and FICA); the protection of a legitimate interest of yours; the proper performance of a public-law duty; or the pursuit of our or a third party’s legitimate interests.

4. Purposes of processing

We process personal information to verify identity; assess funding applications; conduct affordability assessments; create and maintain credit profiles; detect and prevent fraud; meet legal obligations (including NCA and FICA obligations); provide and improve our products and services; develop credit scoring and risk models; communicate with customers; and conduct analytics and reporting.

5. Credit profiling and automated decision-making

You consent to Cape Mutual using your personal, financial, transactional and behavioural information to create and maintain internal credit profiles and risk assessments, and to support credit and risk decisions using automated systems, algorithms and statistical models. Your rights where a decision is based solely on automated processing are set out in section 71 of POPIA and in clause 6 of Document C.

6. Sharing of information

We may share personal information with credit bureaux; banks and financial institutions; funders and lending partners; collection agents; fraud prevention agencies; technology service providers (operators); professional advisers; and regulators and government authorities. Such sharing occurs only where lawfully permitted or required, and operators process personal information on our behalf under written contracts that impose POPIA-compliant security and confidentiality obligations.

7. Cross-border transfers of information (section 72 of POPIA)

Some processing supporting the Platform is performed outside the Republic of South Africa. In particular, Cape Mutual uses a technology and credit-intelligence service provider located in the Republic of Rwanda (its “operator”) to provide platform, scoring and lending-support services.

7.1 What is transferred: The category of information transferred outside South Africa for routine processing is your transactional information (for example, transaction and repayment records and related platform-usage data used for credit intelligence, scoring and product operation). Your personal identifying information and business information are not transferred outside South Africa as a matter of routine. Where, in a particular case, it becomes necessary to transfer personal identifying information or business information cross-border (for example, to perform your agreement, to provide support, or to meet a legal obligation), we will do so only on the section 72 bases set out below.

 

Category

Transferred cross-border?

Primary section 72 basis

Transactional information

Yes — routine (to operator in Rwanda)

72(1)(a) binding agreement + 72(1)(b) consent + 72(1)(c) performance of contract

Personal identifying information

Not routine — only where necessary

72(1)(a) and (b); and (c)/(d) where transfer is necessary for your contract

Business information

Not routine — only where necessary

72(1)(a) and (b); and (c)/(d) where transfer is necessary for your contract

7.2 The lawful bases we rely on: We transfer personal information outside South Africa only where one or more of the following conditions in section 72(1) of POPIA is met:

  • Adequate protection by binding agreement (s72(1)(a)). The recipient is subject to a binding written agreement that provides an adequate level of protection, upholding principles for reasonable processing substantially similar to POPIA’s conditions and including provisions, substantially similar to section 72, governing onward transfer of personal information to third parties in a foreign country. Our operator agreement with the Rwanda service provider contains these safeguards.
  • Consent (s72(1)(b)). You consent to the transfer (see clause 4 of Document C).
  • Necessary for your contract (s72(1)(c)). The transfer is necessary for the performance of a contract between you and Cape Mutual, or to take steps at your request before entering into such a contract.
  • Necessary for a contract in your interest (s72(1)(d)). The transfer is necessary for the conclusion or performance of a contract concluded in your interest between Cape Mutual and a third party (for example, with the operator that provides scoring and lending-support services).
  • For your benefit (s72(1)(e)). The transfer is for your benefit, it is not reasonably practicable to obtain your consent, and if it were, you would be likely to give it.

7.3 Safeguards: Our operator agreement requires the recipient to: process personal information only on our documented instructions and for the agreed purposes; apply security safeguards substantially similar to those required by POPIA; maintain confidentiality; notify us of any security compromise; assist us in meeting data-subject requests and regulatory obligations; restrict onward transfers on terms substantially similar to section 72; and return or delete personal information on termination.

8. De-identified data

Cape Mutual may use anonymised and aggregated information for statistical analysis, product development, credit model development, market research and business intelligence. Such information does not identify you personally, and de-identified information may be retained indefinitely.

9. Data security

Cape Mutual implements encryption, access controls, monitoring and other reasonable technical and organisational measures to secure personal information against loss, damage and unauthorised access or processing.

10. Security compromises (data breaches)

Where a security compromise occurs in respect of which there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, Cape Mutual will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, in accordance with section 22 of POPIA.

11. Retention of information

We retain information for as long as required by law (including NCA and FICA record-keeping periods), to fulfil contractual obligations, or to protect legitimate business interests. De-identified information may be retained indefinitely.

12. Your rights

You have the right to access your personal information; correct inaccurate information; object to certain processing; withdraw consent where applicable; request deletion where legally permissible; and lodge a complaint with the Information Regulator. You also have the rights in respect of automated decision-making set out in section 71 of POPIA and clause 6 of Document C.

13. Information Officer and PAIA

Cape Mutual has appointed and registered an Information Officer with the Information Regulator, and has compiled and published a PAIA manual. Contact details and the manual location are set out in Annexure 1.

14. Information Regulator

Information Regulator (South Africa). Website: www.justice.gov.za/inforeg. Email: complaints.IR@justice.gov.za.