Legal · Privacy policy
Privacy policy
How payDNA (Pty) Ltd collects, uses, and protects personal information, in line with POPIA.
This Privacy Policy applies to:
- Customers
- Employees
- Job applicants; and
- Third-party service providers
Definitions
- 1.1 "Authorised Third Parties" means all third parties who process the Personal Information of Data Subjects on behalf of payDNA or as part of any functions or duties they carry out for payDNA;
- 1.2 "Customer" means a customer of payDNA that makes use of the Services in accordance with the accepted terms and conditions;
- 1.3 "Customer Data" means data inputted and supporting documents provided by the Customer for the purpose of using the Services, which may include Personal Information;
- 1.4 "Data Subjects" means Customers, Employees, job applicants (successful or unsuccessful), and third-party service providers;
- 1.5 "Electronic Communication" means any message sent over an electronic communications network;
- 1.6 "Employees" means former and current employees of payDNA, including interns;
- 1.7 "Operator" means a person who processes Personal Information on behalf of payDNA;
- 1.8 "Personal Information" means information relating to an identifiable person, including but not limited to identity, financial, contact, biometric, and demographic data;
- 1.9 "POPIA" means the Protection of Personal Information Act, 4 of 2013;
- 1.10 "Processing" means any operation performed on Personal Information, including collection, storage, use, dissemination, or deletion;
- 1.11 "Regulator" means the Information Regulator;
- 1.12 "Responsible Party" means the entity determining the purpose and means of processing Personal Information;
- 1.13 "Services" means financial and payment services provided by payDNA, including digital cash card and money transfer services.
Introduction
2.1 This policy governs how payDNA processes Personal Information.
2.2 Where payDNA processes Personal Information on behalf of a Customer, the Customer remains the Responsible Party.
2.3 For Employees, job applicants, and third parties, payDNA acts as the Responsible Party.
2.4 payDNA complies with POPIA in the collection, use, and retention of Personal Information.
Personal information of data subjects
3.1 payDNA collects Personal Information directly from Data Subjects when voluntarily provided.
3.2 By providing information, Data Subjects consent to its processing.
3.3 Information collected may include:
- Customers: Name, ID/passport, date of birth, address, financial info, and identification documents
- Employees: Personal details, employment history, banking, tax, and performance data
- Third Parties: Company registration, contact and financial details
- Job Applicants: Personal details, CVs, qualifications, and screening data
3.4 Additional information provided voluntarily is deemed consented for processing.
Lawful processing
4.1 payDNA processes Personal Information only for legitimate purposes:
- Customers: To provide financial/payment services
- Employees: HR, payroll, compliance, and operational needs
- Third Parties: Vetting and onboarding
- Job Applicants: Recruitment and screening
4.2 Information will not be used for unrelated purposes without consent.
4.3 payDNA takes reasonable steps to ensure data accuracy.
4.4 Where necessary, additional consent will be obtained.
4.5 Authorised Third Parties must comply with this policy.
Rights of data subjects
Data Subjects have the right to:
- Access their Personal Information
- Request correction or deletion
- Understand how their data is used
- Lodge complaints with the Information Regulator
Requests must be accompanied by proof of identity.
Security
payDNA implements appropriate safeguards, including:
- Secure cloud storage
- Encryption and firewalls
- Multi-factor authentication
- Restricted access controls
Data breach notification
In case of a breach, payDNA will:
- Notify affected parties as soon as possible (within 5 days where feasible)
- Mitigate risks
- Provide updates
- Notify authorities where required
Disclosure required by law
Where required by law, payDNA may disclose Personal Information and will:
- Notify Data Subjects where possible
- Limit disclosure to what is necessary
- Comply with legal obligations
This may include compliance with financial regulations and reporting obligations.
Cross-border transfers
Personal Information may only be transferred outside South Africa if:
- Consent is obtained
- Equivalent protection exists
- It is necessary for service delivery
Retention and destruction
Personal Information will be:
- Retained only as long as necessary
- Deleted securely when no longer required
- Kept longer only where legally required or consented to
Direct marketing
11.1 Data Subjects may object to direct marketing at any time.
11.2 Marketing is only allowed if:
- Consent is given; or
- The Data Subject is an existing customer
11.3 Consent requests are limited to one initial request unless withdrawn.