Access
Section 23: be told free of charge whether we hold personal information about you, and be given a record or a description of it, including who has had access to it.
Access, correction, deletion and objection under the Protection of Personal Information Act, set out as a procedure you can actually follow. Also, plainly, what happens when a regulator or the police ask us for information about you.
Version 1.0 · Effective 18 August 2026 · Next review 18 February 2027
Email support@conexus-crypto.com with "data request" in the subject line, or message the desk on WhatsApp or Telegram. We accept a substantially similar request in any written form. The prescribed forms exist if you prefer them, and we will send you a blank copy of any of them.
Each right comes from a named section of POPIA, and each has a limit worth knowing before you use it. The detail, including the limits, is in the document below.
Section 23: be told free of charge whether we hold personal information about you, and be given a record or a description of it, including who has had access to it.
Section 24(1)(a): have information corrected where it is inaccurate, out of date, misleading, excessive or obtained unlawfully. Where a record must be kept as it stands, we correct forward and date it.
Section 24(1)(b): have a record destroyed where we are no longer authorised to keep it. Sections 22 and 23 of the FIC Act require five years, and where they apply, the statutory duty prevails and we say so in writing.
Section 11(3): object to processing that rests on legitimate interests. Direct marketing is governed separately by section 69, and an objection to marketing is absolute and needs no reason.
Section 29 of the Financial Intelligence Centre Act requires a suspicious or unusual transaction report, with no monetary threshold, within 15 days excluding weekends and public holidays. The Act makes it an offence to disclose that such a report has been made. We are therefore not able to confirm or deny one, to you or to anyone else. Any desk that tells you it would warn you first is describing a crime.
You have the right to know what personal information we hold about you, to have it corrected if it is wrong, to have it deleted where we are not required to keep it, and to object to us using it for certain purposes. You do not have to explain why you want to exercise those rights, and exercising them costs nothing.
Write to support@conexus-crypto.com with the words "data request" in the subject line, say which of the four things you want, and give us enough detail to find you. We will acknowledge it, verify that you are who you say you are, and answer in writing.
The rest of this page explains the formal machinery behind that, because you are entitled to use the formal machinery if you prefer it, and because a desk that holds identity documents and bank statements should be able to describe the process precisely rather than vaguely.
That machinery is South African. The desk deals with clients in more than one country, but the company holding your information is registered in the Republic, so the Protection of Personal Information Act and the Promotion of Access to Information Act are the statutes that govern what it holds and what you can require of it — wherever you happen to bank, and whatever currency you settled in.
| Information Officer | Information Officer — to be confirmed |
|---|---|
| Deputy Information Officer | Information Officer — to be confirmed |
| Responsible party | registered company name — to be confirmed, registration number CIPC registration number — to be confirmed |
| support@conexus-crypto.com | |
| Telephone and WhatsApp | +27 76 560 1228 |
| Address | Tiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925 |
In a private body the head of the body is the Information Officer by operation of law, under section 1 of PAIA and section 1 of POPIA. The duties of the role are set out in section 55 of POPIA: to encourage compliance with the conditions for lawful processing, to deal with requests made to the body, to work with the Information Regulator in relation to investigations, and otherwise to ensure that the body complies with the Act. Regulation 4 of the POPIA Regulations requires the Information Officer to be registered with the Information Regulator before performing those duties, and our Information Officer is registered accordingly. Deputy Information Officers are designated under section 17 of PAIA so that there is always somebody available to receive a request.
The formal manual describing every category of record this body holds is the PAIA section 51 manual. What we collect and why is in the privacy policy.
Section 23 of POPIA gives you the right to be told, free of charge, whether we hold personal information about you, and to be given a record or a description of that information, including the identity of any third party who has had access to it. The mechanics of an access request run through PAIA, which is why the two Acts are stitched together on this site.
In practice, for a client of the desk, an access request returns the onboarding file we hold on you, the trade records associated with you, and the correspondence on file. If what you actually want is a copy of a specific settlement confirmation or a rate applied on a specific date, ask your dealer. That is not a legal request, it is a normal one, and it takes minutes.
Section 24(1)(a) of POPIA gives you the right to request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. Corrections are usually simple: a changed address, a corrected spelling, a bank account that has been closed. Where a correction affects a record we are obliged to retain in its original form, we correct forward — the original record stays, and the correction is recorded against it with the date. Section 24(3) requires us to notify any third party to whom the information was supplied of the correction, where that is reasonably practicable.
Section 24(1)(b) gives you the right to request destruction or deletion of a record of personal information that we are no longer authorised to retain. This is the right that most often meets a limit, and we would rather set out the limit here than surprise you with it later. Sections 22 and 23 of the Financial Intelligence Centre Act require customer due diligence records and transaction records to be kept for five years after the business relationship ends or the single transaction concludes. Tax legislation imposes its own retention period on the records supporting a return. Where a deletion request collides with either, the statutory retention duty prevails, we will tell you which provision we are relying on, and we will delete the record when the period expires. What we can and will do in the meantime is stop using the information for anything other than the purpose the law requires.
Section 11(3) of POPIA lets you object, on reasonable grounds, to processing that relies on legitimate interests or on the pursuit of our own or a third party's legitimate interests. If you object and the objection is upheld, we must stop that processing. Direct marketing by electronic communication is governed separately by section 69: we may only send it with your consent, or to an existing customer in relation to similar products, and every message must offer a way to opt out. An objection to marketing is absolute and takes effect immediately — you do not need a reason for that one.
The Regulations made under POPIA prescribe three forms that matter here. All of them are published by the Information Regulator and we will email a blank copy of any of them on request.
| Form 1 | Objection to the processing of personal information, in terms of section 11(3) of POPIA |
|---|---|
| Form 2 | Request for correction or deletion of personal information, in terms of section 24(1) of POPIA |
| Form 4 | Application for consent to process personal information for the purpose of direct marketing by electronic communication, in terms of section 69(2) of POPIA |
A request for access to a record is made on Form 2 of the PAIA Regulations, which is a different Form 2 to the POPIA one. The two Acts each have their own numbered forms and the numbering is unhelpfully similar. If you tell us in plain words what you want, we will tell you which form applies, or handle it without one.
The forms exist to make sure a request contains the information needed to act on it. They are not a gate.
We will accept any request that contains substantially the same information as the prescribed form, in whatever written form it reaches us. An email is fine. A WhatsApp message to the desk number is fine. A Telegram message on our published handle is fine. A letter delivered to the Cape Town office is fine. A scanned page in your own handwriting is fine. We will not refuse a request because it arrived on the wrong stationery, and we will not send you away to fill in a PDF when you have already told us what you need.
What a request does need to contain, however it arrives:
We verify identity before we act, and we do it proportionately. For an existing client we will usually verify through the channel and credentials already on file. Where a request would result in personal information being disclosed or destroyed and the identity of the requester is not established to our satisfaction, we will ask for more before we act — and we will explain what we are asking for and why, rather than simply going quiet. A request to send a client file to a new email address will always be checked by a call to the number on file.
If you are acting for somebody else — as an executor, a curator, a parent or guardian of a child, or under a power of attorney — send proof of that capacity with the request.
| Acknowledgement | Within 2 business days of receipt, with a reference |
|---|---|
| Access request under PAIA | Decision within 30 days of receipt, extendable once by up to 30 days under section 57, with written reasons |
| Correction or deletion | As soon as reasonably practicable; our target is 30 days, and we will tell you if a statutory retention period prevents deletion |
| Objection to processing | Considered and answered in writing within 30 days |
| Objection to direct marketing | Effective on receipt; suppression applied within 2 business days |
| Fee | No fee for a request about your own personal information. Fees for other records are as set out in the PAIA manual |
Where a request is complex, or where a record contains information about a third party who has to be consulted under sections 71 and 72 of PAIA, we will tell you before the original period runs out, say how much longer we need, and give the reason.
Take it up with the Information Officer first. Most disagreements are about scope or about identity verification and are resolved in a single exchange. If that does not work, you have two independent routes and you do not need our permission to use either.
Under POPIA, section 74 allows a data subject to submit a complaint to the Information Regulator about alleged interference with the protection of personal information, or about a determination by an adjudicator. Under PAIA, section 77A allows a requester to complain to the Regulator about a decision of a private body, including a refusal of access, a deemed refusal, a fee, or an extension. A PAIA complaint must be lodged within 180 days of the decision unless the Regulator condones a late complaint. Beyond that, section 78 of PAIA allows an application to court, and POPIA allows civil proceedings under section 99.
| Body | Information Regulator (South Africa) |
|---|---|
| Physical address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
| Postal address | P.O. Box 31533, Braamfontein, Johannesburg, 2017 |
| Telephone | 010 023 5200 |
| General enquiries | enquiries@inforegulator.org.za |
| PAIA complaints | PAIAComplaints@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| Website | inforegulator.org.za |
Complaints under POPIA go to POPIAComplaints@inforegulator.org.za and complaints under PAIA to PAIAComplaints@inforegulator.org.za. If your complaint is about the service you received rather than about your information rights, the complaints procedure sets out the route to the FAIS Ombud instead.
The other half of this subject is what happens when somebody who is not you asks for your information. Clients rarely ask about it up front, and it is one of the more important things to understand about dealing with a regulated desk, so it is set out here in full.
South African law obliges an accountable institution to produce information in defined circumstances. The requests we can lawfully receive include:
Impersonation of law enforcement is a known technique for extracting client data. We verify the identity of the requester and the authenticity of the instrument through the issuing body’s own published channels, not through the contact details printed on the document.
We establish which provision is being relied on, whether it in fact empowers the request, and exactly what it covers. A request for one client’s file is not authority to hand over a list of clients, and a warrant is limited to what it names.
Where the instrument is ambiguous, overbroad or of doubtful validity, we take advice before producing anything, and we will challenge a request that exceeds its authority.
We disclose what is lawfully demanded and no more. Records are produced in a form that can be traced, and we keep a copy of exactly what was handed over.
Every request, the authority relied on, the decision taken, the date, and the records produced are recorded. Section 23 of POPIA entitles you to be told the identity of third parties who have had access to your information, and that log is how we answer.
Our default is to notify the client that their information has been requested. Where the law prohibits notification, we do not notify, and we will not pretend otherwise on this page.
That last point deserves to be stated without softening. Section 29 of the FIC Act requires an accountable institution to report a suspicious or unusual transaction to the Financial Intelligence Centre, with no monetary threshold, and within 15 days excluding weekends and public holidays. The Act makes it an offence for a person who knows or suspects that such a report has been made to disclose that fact. We are therefore not able to confirm or deny whether a report has been made about any transaction, to you or to anyone else. Any desk that tells you it would warn you first is describing a crime.
Equally, this is what we do not do. We do not sell personal information. We do not share client information with marketing partners or data brokers. We do not give information to another client, to a counterparty, or to a person who telephones claiming to be from your bank. And we do not respond to an informal request from a person asserting authority without an instrument behind it. The rules we apply to onboarding and monitoring are set out in full in the AML and KYC policy.
Section 22 of POPIA requires a responsible party that has reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, subject only to a determination by a public body or the Regulator that notification would impede a criminal investigation.
The notification must be in writing and must give sufficient information to allow you to take protective measures, including a description of the possible consequences, the measures we intend to take, a recommendation of what you can do to mitigate the effect, and, if we know it, the identity of the person who accessed the information.
We hold to that. If information about you is compromised, you will be told what happened, what was affected, and what to do about it — by name, not by press release.
The full account of what we collect, the lawful basis for it, and who it goes to.
The formal section 51 manual: categories of records, fees, timelines and remedies.
Which documents the FIC Act requires, why each one, and what happens to them afterwards.
Every data request is acknowledged in writing within two business days with a reference number, and answered by a person who can explain the outcome rather than quote a policy at you.