PROTECTION OF PERSONAL INFORMATION ACT (“POPIA”)
Privacy Policy
Issued in terms of the Protection of Personal Information Act 4 of 2013 (POPIA)
This Privacy Policy explains how Finsmart Asset Management (Pty) Ltd collects, uses, stores, shares and protects your personal information. We are committed to processing your personal information lawfully, fairly and transparently in compliance with POPIA and all other applicable legislation. Please read this policy carefully.
1. Who we are
Finsmart Asset Management (Pty) Ltd ("Finsmart", "we", "us" or "our") is an authorised financial services provider licensed by the Financial Sector Conduct Authority (FSCA) under FSP number 44557. We provide financial planning, investment advice and intermediary services to individuals and entities throughout South Africa.
For the purposes of POPIA, Finsmart is the responsible party in respect of personal information collected and processed in connection with our financial services.
Information Officer: Christel du Toit
Email: christel@finsmart.co.za
Telephone: 082 852 7610
Physical address: 60 Mostert Road, Melkbosstrand, Western Cape, 7441
2. Scope of this policy
This policy applies to all personal information we collect and process about:
- Current, prospective and former clients and customers;
- Authorised users and representatives acting on behalf of customers;
- Visitors to our website (www.finsmart.co.za);
- Employees, contractors and job applicants (where a separate HR privacy notice has not been issued);
- Beneficiaries nominated on financial products; and
- Any other natural person whose personal information we process in the course of our business.
This policy does not apply to the personal information practices of third-party product providers, investment platforms or other organisations whose products or services we may recommend. We encourage you to read their privacy policies independently.
3. Personal information we collect
We collect only the personal information that is adequate, relevant and not excessive for the purposes described in this policy. The categories of personal information we typically collect are set out below:
| Category | Examples | Purpose |
|---|---|---|
| Identity information | Full name, ID/passport number, date of birth, gender, nationality, marital status | FICA verification, FAIS compliance, advice suitability |
| Contact details | Residential and postal address, email address, telephone numbers | Communication, correspondence, service delivery |
| Financial information | Income, assets, liabilities, net worth, tax number, banking details, investment values | Financial needs analysis, suitability assessment, fee deduction |
| Employment information | Employer name, occupation, employment status | Financial needs analysis, risk profiling |
| Risk and investment profile | Investment objectives, risk tolerance, investment term, knowledge and experience | Suitability of advice and products |
| Special personal information | Health or medical information (where relevant to risk products), disability status | Underwriting, product suitability (only where necessary and with consent) |
| Beneficiary information | Names and contact details of nominated beneficiaries | Administration of investment and life products |
| Transaction and product data | Investment history, policy details, contribution and withdrawal records | Ongoing advice, record-keeping, regulatory reporting |
| Communication records | Emails, WhatsApp messages, call recordings, correspondence | Service delivery, dispute resolution, regulatory compliance |
| Website usage data | IP address, browser type, pages visited, cookies | Website functionality, analytics, security |
We do not collect or process special personal information (such as health data, religious beliefs or criminal records) unless it is strictly necessary for the services you have requested, and only with your explicit consent or as permitted by law.
4. How we collect personal information
4.1 Directly from you
- When you complete financial planning questionnaires, fact-finds or needs analysis forms;
- When you apply for or take out a financial product through us;
- When you correspond with us by email, telephone, WhatsApp or in person;
- When you visit our website and interact with online forms or tools; and
- When you provide documents for FICA verification purposes.
4.2 From third parties
- Product providers and investment platforms (e.g., investment values, policy details, transaction history);
- Credit bureaus and identity verification services (for FICA and fraud-prevention purposes);
- The South African Revenue Service (SARS) and other government bodies (where required by law);
- The Financial Intelligence Centre (FIC) and sanctions screening databases; and
- Other financial advisers or intermediaries involved in managing your affairs, where you have authorised the sharing of information.
4.3 Automatically
- Through cookies and similar tracking technologies when you visit our website (see Section 12 below).
5. Purposes for which we use your personal information
5.1 Provision of financial services
- Conducting financial needs analyses and risk profiling;
- Providing financial advice and making product recommendations;
- Preparing records of advice, fee disclosure statements and proposal documents;
- Facilitating the implementation of advice, including product applications, switches, withdrawals and contributions;
- Administering your investment portfolio on an ongoing basis; and
- Communicating investment updates, portfolio schedules and market commentary.
5.2 Legal and regulatory compliance
- Establishing and verifying your identity under FICA;
- Screening against targeted financial sanctions lists (terrorist financing and proliferation financing);
- Reporting suspicious or unusual transactions to the Financial Intelligence Centre;
- Complying with FAIS record-keeping, advice and disclosure obligations;
- Fulfilling tax-reporting obligations to SARS; and
- Responding to requests from the FSCA, FIC or other regulatory authorities.
5.3 Business operations
- Maintaining accurate customer records;
- Managing and resolving complaints;
- Fraud prevention and detection;
- Training and quality assurance (including call and correspondence review); and
- Internal reporting and business analytics.
5.4 Communication and marketing
- Sending service-related communications (e.g., review reminders, fee notices, portfolio updates);
- Sending newsletters, market commentary or financial education content — where you have consented or where permitted by applicable law; and
- Notifying you of changes to our services, products, fees or policies.
You may opt out of marketing communications at any time by contacting us at christel@finsmart.co.za or by using the unsubscribe link in any marketing email. Opting out will not affect service communications required for the management of your account.
6. Legal basis for processing
We process your personal information on the following grounds under POPIA:
- Contract: processing is necessary to perform the financial services agreement between us, or to take steps at your request before entering into such an agreement.
- Legal obligation: processing is necessary to comply with a statutory obligation (e.g., FICA, FAIS, SARS reporting, POCDATARA).
- Legitimate interest: processing is necessary for our legitimate business interests (e.g., fraud prevention, business analytics, improving our services), provided those interests are not overridden by your rights and interests.
- Consent: where we rely on your consent, we will ask for it explicitly and separately. You may withdraw your consent at any time, subject to applicable legal requirements.
- Vital interest: in exceptional circumstances where processing is necessary to protect your vital interests or those of another person.
7. Sharing your personal information
We do not sell your personal information. We share your personal information only in the following circumstances:
7.1 Product providers and investment platforms
We share the personal information necessary to implement your financial plan with the product providers and investment platforms through whom your products are held (e.g., Allan Gray, Sanlam, Old Mutual, Discovery). These parties are responsible parties or operators in their own right and are subject to their own privacy policies.
7.2 Our compliance and service providers
We may share your personal information with our compliance practice (Moonstone Compliance), professional advisers (legal, audit and tax), IT service providers, cloud hosting providers and document management systems. These parties process personal information on our behalf as operators and are contractually required to maintain appropriate confidentiality and security measures.
7.3 Regulatory and law enforcement authorities
We are required by law to disclose personal information to:
- The Financial Intelligence Centre (FIC) — suspicious transaction and cash threshold reports;
- The FSCA — in response to supervisory requests or investigations;
- SARS — for tax-reporting purposes; and
- Law enforcement agencies — where required by a court order or applicable law.
7.4 Successors and business transfers
In the event that Finsmart's business or a part thereof is acquired, merged or transferred to another entity, your personal information may be disclosed to the prospective purchaser or successor, subject to equivalent privacy and confidentiality undertakings.
7.5 With your consent
We may share your personal information with other parties where you have given your explicit consent.
8. Cross-border transfers of personal information
Where your investments include offshore components, or where we use cloud-based service providers whose servers are located outside South Africa, your personal information may be transferred to a country other than South Africa.
We will only transfer personal information to a foreign country if:
- The recipient country provides an adequate level of protection for personal information as determined by the Information Regulator; or
- The recipient has agreed in writing to process the personal information in accordance with standards substantially similar to those required by POPIA; or
- You have consented to the transfer; or
- The transfer is necessary for the performance of a contract between you and us, or for your benefit.
Where we transfer personal information to offshore investment platforms or product providers on your instruction, such transfers are necessary for the implementation of your chosen offshore investment strategy.
9. Retention of personal information
We retain your personal information only for as long as is necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:
| Category | Retention period | Basis |
|---|---|---|
| Records of advice and client files | FAIS Act: minimum 5 years from date of advice or end of relationship | Regulatory requirement |
| FICA customer due diligence records | FICA: minimum 5 years from end of business relationship | Regulatory requirement |
| Financial product and transaction records | Life of product + 5 years after termination | Regulatory and contractual |
| Complaint records | 5 years from resolution | Regulatory and operational |
| Tax-related records | As required by SARS (generally 5 years) | Regulatory requirement |
| Marketing and communication records | Until withdrawal of consent or 3 years from last interaction | Legitimate interest / consent |
| Website usage data | 12 months | Operational |
Where personal information is no longer required, we will securely destroy, delete or de-identify it in a manner that prevents unauthorised reconstruction.
10. Security of your personal information
We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it against loss, theft, misuse, unauthorised access, disclosure, alteration or destruction.
Our security measures include:
- Password-protected and encrypted storage systems for customer data;
- Access controls limiting personal information to authorised staff only;
- Secure email and communication channels for transmitting sensitive information;
- Regular review of access rights and system security;
- Confidentiality obligations for all staff and service providers with access to personal information; and
- Incident response procedures for managing personal information breaches.
In the event of a personal information breach that is likely to result in serious harm to you, we will notify the Information Regulator and, where required, notify you as soon as reasonably possible, in accordance with Section 22 of POPIA.
While we take all reasonable precautions, no method of electronic storage or transmission is completely secure. You transmit personal information to us at your own risk. Please ensure that your own devices and communications are secure.
11. Your rights under POPIA
As a data subject under POPIA, you have the following rights in respect of your personal information held by us:
11.1 Right of access
You may request confirmation of whether we hold personal information about you and, if so, request a description and copy of that information. We will respond within a reasonable time and in accordance with the prescribed fees (if any).
11.2 Right to correction
You may request that we correct or update personal information that is inaccurate, misleading, out of date or incomplete. We will correct or delete such information as soon as reasonably practicable.
11.3 Right to deletion
You may request that we delete or destroy your personal information where it is no longer necessary for the original purpose, you have withdrawn your consent, or you have successfully objected to the processing. This right is subject to our legal retention obligations under FAIS, FICA and other applicable legislation.
11.4 Right to object
You may object to the processing of your personal information on reasonable grounds relating to your particular situation. We will consider your objection and either comply or provide written reasons for our refusal.
11.5 Right to withdraw consent
Where we process your personal information on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
11.6 Right not to be subject to automated decision-making
You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects concerning you or similarly significantly affects you, without human review, unless you have consented or this is authorised by law.
11.7 How to exercise your rights
To exercise any of the above rights, please submit a written request to our Information Officer:
Name: Christel du Toit
Email: christel@finsmart.co.za
Telephone: 082 852 7610
Address: 60 Mostert Road, Melkbosstrand, Western Cape, 7441
We may require you to verify your identity before processing your request. We will respond within 30 business days of receiving a complete request. Where we are unable to comply, we will provide written reasons.
12. Cookies and website usage
Our website (www.finsmart.co.za) may use cookies and similar tracking technologies to improve your browsing experience and to collect usage analytics. Cookies are small text files stored on your device.
We may use the following types of cookies:
- Strictly necessary cookies: required for the website to function and cannot be disabled.
- Analytics cookies: help us understand how visitors use our website (e.g., Google Analytics). These are anonymised where possible.
- Functional cookies: remember your preferences and settings.
You can control or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. Where required by law, we will request your consent before placing non-essential cookies.
13. Children's personal information
Our financial services are directed at adults (persons aged 18 years and over). We do not knowingly collect personal information from children under the age of 18 without the consent of a competent person (as defined in POPIA) — typically a parent or legal guardian.
Where a beneficiary named on a financial product is a minor, we will process only the minimum personal information required for that purpose, and will take additional care to protect such information. If you believe we have inadvertently collected personal information about a child without appropriate consent, please contact our Information Officer immediately.
14. Complaints
If you believe that we have processed your personal information in a manner that is inconsistent with POPIA or this Privacy Policy, you may:
14.1 Contact us directly
In the first instance, please contact our Information Officer to allow us to address your concern:
Email: christel@finsmart.co.za
Telephone: 082 852 7610
We will acknowledge your complaint within 5 business days and will endeavour to resolve it within 30 business days. See also our Complaints page.
14.2 Lodge a complaint with the Information Regulator
If your complaint is not resolved to your satisfaction, you may lodge a complaint with the Information Regulator of South Africa:
Information Regulator
Website: www.inforegulator.org.za
Email: inforeg@justice.gov.za
Telephone: 010 023 5207
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal obligations or the requirements of the Information Regulator. The current version of this policy, with its effective date, will always be available on request and on our website at www.finsmart.co.za.
Where changes are material, we will notify you directly (by email or in writing) before the changes take effect, where reasonably practicable. Your continued use of our services after the effective date of any update constitutes your acknowledgement of the revised policy.
16. Applicable legislation and regulatory framework
This Privacy Policy is issued in compliance with and subject to the following principal legislation and regulatory requirements:
- Protection of Personal Information Act 4 of 2013 (POPIA)
- Financial Advisory and Intermediary Services Act 37 of 2002 (FAIS Act)
- Financial Intelligence Centre Act 38 of 2001 (FICA)
- Protection of Constitutional Democracy against Terrorist and Related Activities Act 33 of 2004 (POCDATARA)
- Income Tax Act 58 of 1962 (as amended)
- Electronic Communications and Transactions Act 25 of 2002 (ECTA)
- Consumer Protection Act 68 of 2008 (CPA)
- Conduct of Financial Institutions Bill (COFI Bill) — COFI-aligned pending enactment
17. Contact us
Finsmart Asset Management (Pty) Ltd
FSP 44557 | Reg. 2012/116595/07
60 Mostert Road, Melkbosstrand, Western Cape, 7441
christel@finsmart.co.za | jacques@finsmart.co.za | emil@finsmart.co.za
Tel: 082 852 7610
Regulatory note: This Privacy Policy has been prepared to comply with the Protection of Personal Information Act 4 of 2013 (POPIA), which became fully effective on 1 July 2021. It is also aligned with the applicable requirements of the FAIS Act, FICA, POCDATARA, and the market conduct principles of the Conduct of Financial Institutions Bill (COFI Bill), introduced in Parliament in 2026. This policy should be reviewed annually and updated to reflect any legislative amendments, changes to our business practices, or guidance issued by the Information Regulator or FSCA.