Privacy notice

Privacy notice under POPIA.

This notice is the section 18 notification that the Protection of Personal Information Act 4 of 2013 requires a responsible party to give you. Its headings are the subsections of section 18(1), in order, so that you can check the notice against the statute rather than against a template written for another country.

Version 1.0 · Effective 18 August 2026

The short version

Most of what the desk collects is collected because the FIC Act requires it, not because it is convenient: without it the desk may not lawfully trade with you. None of it is sold, none of it builds a marketing profile, and it is kept for five years after the relationship ends because sections 22 and 23 of the FIC Act require that.

The responsible party

The responsible party is registered company name — to be confirmed, registration number CIPC registration number — to be confirmed, trading as Conexus Crypto, of Tiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925, South Africa.

The registered Information Officer is Information Officer — to be confirmed, reachable at support@conexus-crypto.com or on +27 76 560 1228. Section 55 of POPIA makes the Information Officer responsible for compliance, for dealing with requests made to the desk, and for working with the Regulator. Where the name above is marked as awaiting confirmation, that appointment has not yet been published on this site; requests sent to the address above still reach the person holding the role.

The desk is a responsible party in its own right for client and website data. It is not an operator for anyone else, and it does not process personal information on instruction from a third party.

The desk is established in South Africa, so POPIA is the law that governs how it handles your information — wherever you live, and whatever currency you settle in. Where the law of your own country gives you further rights over your information, this notice does not displace them: write to the Information Officer and you will be told how a request of that kind is handled.

s18(1)(a) — the information collected, and its source where it is not collected from you

Collected directly from you, during onboarding and afterwards: full names and any former names; date of birth; identity number or passport number and the document image; nationality and country of tax residence; residential and postal address, with a document evidencing it; contact telephone number and email address; the instant messaging handle you choose to deal on; occupation or the nature of your business; bank account details and the name in which the account is held; SARS income tax reference number where you have one; source of funds and, where enhanced due diligence applies, source of wealth; blockchain addresses you nominate and the networks they sit on; and, for a legal person, its registration documents, its authorised representative and its beneficial owners down to natural persons.

Generated by us about you: the record of every quote requested, issued, accepted or lapsed; trade confirmations; settlement records; the risk rating applied to you under our Risk Management and Compliance Programme; notes of calls and meetings held for compliance purposes; correspondence with you; and the record of any report the desk was obliged to file.

Collected from sources other than you, which section 18(1)(a) requires us to identify: sanctions, terrorist financing and watch-list data from the United Nations Security Council consolidated list and the Targeted Financial Sanctions list maintained under the FIC Act, together with equivalent screening data supplied by our banking and liquidity counterparties; politically exposed person and adverse media data from commercial screening databases; identity verification results from the providers our RMCP names; blockchain analytics on the addresses you use, drawn from public ledger data and from a commercial analytics provider; company, director and beneficial ownership data from the CIPC; and, where you were introduced by an existing client, the fact of that introduction.

Collected automatically when you use this website: the two browser storage keys described in the cookie notice, and standard server log data held by our hosting provider — IP address, user agent, requested URL, timestamp and response status. The website sets no analytics or advertising cookie.

s18(1)(b) — the name and address of the responsible party

registered company name — to be confirmed, registration number CIPC registration number — to be confirmed, Tiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925, South Africa. Postal address as above. Telephone +27 76 560 1228. Email support@conexus-crypto.com. Information Officer: Information Officer — to be confirmed.

The desk's Johannesburg location operates by appointment and holds no separate record system; every record described in this notice is held under the Cape Town entity.

s18(1)(c) — the purpose for which the information is collected

  • To identify and verify you, and to keep that verification current, as sections 21 and 21A of the FIC Act require of an accountable institution.
  • To decide whether to enter into or continue a business relationship with you, and at what risk rating.
  • To quote, execute and settle trades, including sending the settlement currency to your bank account and crypto assets to your nominated address.
  • To comply with the Travel Rule under FIC Directive 9 of 2024, which requires originator and beneficiary information to accompany a transfer between institutions.
  • To detect, prevent and report money laundering, terrorist financing, sanctions evasion and fraud, including filing cash threshold reports above R49 999.99 under section 28 and suspicious and unusual transaction reports under section 29 of the FIC Act.
  • To meet tax reporting obligations, including the OECD Crypto-Asset Reporting Framework adopted by South Africa from 1 March 2026.
  • To keep the records that sections 22 and 23 of the FIC Act, the Tax Administration Act and the Companies Act require.
  • To handle complaints, disputes and regulatory enquiries, and to establish, exercise or defend a legal claim.
  • To operate and secure this website, including bot mitigation on the forms.
  • To send you operational messages about a trade, an account change or a change to a document in the legal centre.

Your information is not sold, rented, exchanged or used to build a marketing profile, and it is not used for any purpose incompatible with those listed above.

s18(1)(d) — whether supplying the information is voluntary or mandatory

Mandatory, because a statute requires it. Your full names, date of birth, identity or passport number and its image, residential address and its proof, nationality and tax residence, the nature and purpose of the business relationship, the source of funds and, in a higher-risk case, the source of wealth, beneficial ownership for a legal person, your bank account details, and the originator and beneficiary information that Directive 9 requires to accompany a transfer. The desk cannot lawfully trade with you without these. Note that Directive 9 of 2024 applies with no minimum threshold; below R5 000 a reduced information set applies and the ordering institution need not verify it, which is verification relief and not anonymity.

Mandatory, because the desk's own Risk Management and Compliance Programme requires it. Your SARS income tax reference number where one has been issued to you, your occupation or line of business, and confirmation of which blockchain addresses you control. These are our requirements rather than express statutory fields, and they exist because a section 42 RMCP has to set out how the desk decides what it needs.

Voluntary. The instant messaging channel you prefer to deal on, an alternative contact number, your preferred language, any commentary you give about a trade beyond what due diligence requires, and your consent to receive non-operational messages. Nothing here affects whether the desk can trade with you.

s18(1)(e) — the consequences of not providing the information

If you do not provide the mandatory statutory information, the desk cannot onboard you and cannot execute a trade. This is not a commercial preference: section 21 of the FIC Act prohibits an accountable institution from establishing a business relationship or concluding a single transaction with a client whose identity it has not established.

If you provide the information at onboarding but then decline to update it, or decline to answer a question raised by ongoing due diligence under section 21C, the desk may suspend trading until the position is resolved, and in some circumstances must terminate the relationship.

If you decline to provide information the desk asks for under its own RMCP, the desk may still be able to proceed, usually at a higher risk rating and sometimes with a lower limit. A dealer will tell you which category a request falls into if you ask.

Declining to provide voluntary information has no consequence beyond the obvious one: we will contact you on the channel we do have.

s18(1)(f) — the law authorising or requiring the collection

  • Financial Intelligence Centre Act 38 of 2001 — Item 22 of Schedule 1 (crypto asset service providers as accountable institutions, effective 19 December 2022); section 21 and section 21A (customer due diligence and enhanced due diligence); section 21C (ongoing due diligence); sections 22 and 23 (record keeping); section 28 (cash threshold reports above R49 999.99); section 29 (suspicious and unusual transaction reports); sections 26A to 26C (targeted financial sanctions); section 42 (Risk Management and Compliance Programme).
  • FIC Directive 9 of 2024, in force since 30 April 2025, implementing the FATF Travel Rule with no minimum threshold.
  • Financial Advisory and Intermediary Services Act 37 of 2002, and the General Code of Conduct made under it, following the declaration of crypto assets as a financial product by General Notice 1350 in Government Gazette 47334 of 19 October 2022.
  • Tax Administration Act 28 of 2011, and the OECD Crypto-Asset Reporting Framework adopted in South Africa from 1 March 2026, with the first return due to SARS by 31 May 2027.
  • Companies Act 71 of 2008, including the record-keeping and disclosure duties in sections 24 and 32.
  • Electronic Communications and Transactions Act 25 of 2002, sections 43 and 51.
  • Protection of Personal Information Act 4 of 2013 itself, which authorises processing necessary to comply with an obligation imposed by law.

s18(1)(g) — transfers to a third country, and the protection there

Some of your information leaves South Africa. Section 72 of POPIA permits this only in defined circumstances, and the desk relies on the following.

Website hosting and edge delivery. This website and its form endpoints run on Cloudflare's global network. A request you make may be served from, and logged at, a data centre outside South Africa. Cloudflare, Inc. is bound by contractual terms that impose obligations substantially similar to the conditions for lawful processing in POPIA, which is the basis in section 72(1)(a).

Bot mitigation on forms. Cloudflare Turnstile is loaded only on pages that carry a form. It receives the technical signals needed to distinguish a person from a script.

Screening and analytics providers. Sanctions, politically exposed person, adverse media and blockchain analytics providers may hold or process data outside South Africa. Each is engaged under a written operator agreement that requires POPIA-equivalent safeguards and prohibits use of the data for the provider's own purposes.

Counterparty institutions under the Travel Rule. Where you send crypto assets to, or receive them from, an institution in another country, Directive 9 of 2024 requires originator and beneficiary information to travel with the transfer. That transfer is necessary for the performance of your contract with the desk, which is the basis in section 72(1)(b), and the receiving institution is itself subject to Travel Rule obligations in its own jurisdiction.

Where a recipient country's law does not provide an adequate level of protection, the desk relies on contractual safeguards, and it will tell you which basis applies to a specific transfer if you ask.

s18(1)(h) — recipients, the nature of the information, and your rights

Recipients and categories of recipients. The Financial Intelligence Centre, where a report or a request for information requires it. The FSCA and other regulators, on lawful request. SARS, under the Tax Administration Act and the Crypto-Asset Reporting Framework. Law enforcement and the courts, under a warrant, subpoena or court order. The desk's banking partners and liquidity venues, to the extent needed to settle your trade and to satisfy their own compliance duties. Counterparty institutions under the Travel Rule. Operators engaged in writing: hosting and edge infrastructure, email, identity verification, sanctions and PEP screening, and blockchain analytics. The desk's professional advisers — auditors, attorneys, the external compliance function — under professional duties of confidentiality. A successor in title, if the business is transferred, on notice to you.

Nature of the information. Identity and contact data, financial and transactional data, compliance and risk data, and technical website data. Some of it is special personal information within the meaning of section 26 of POPIA only in narrow cases — for example where a document you supply reveals biometric data. The desk does not collect information about your religion, philosophical beliefs, race, trade union membership, political persuasion, health, sex life or criminal behaviour, except where a sanctions or adverse media screening result unavoidably discloses the last of these; section 27(1)(b) permits that processing where it is necessary to comply with an obligation of international public law or to establish or defend a right.

The right of access and the right to rectify. You may ask what personal information the desk holds about you and ask for a copy, and you may ask for information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained to be corrected or deleted. The section below on your rights explains the mechanism for each.

The right to object. You may object to processing on reasonable grounds under section 11(3)(a), except where the processing is required by law — which covers most of what appears in this notice.

The right to complain to the Regulator. Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · PO Box 31533, Braamfontein, 2017 · telephone 010 023 5200 · general enquiries enquiries@inforegulator.org.za · POPIA complaints POPIAComplaints@inforegulator.org.za · PAIA complaints PAIAComplaints@inforegulator.org.za · inforegulator.org.za

The lawful basis for each activity, under section 11

Compliance with an obligation imposed by law — section 11(1)(c). This is the basis for identity verification, due diligence, screening, record keeping, Travel Rule messaging, and all reporting to the Financial Intelligence Centre and SARS. Your consent is not required for these and withdrawing it would not stop them.

Necessary for the performance of a contract — section 11(1)(b). This is the basis for quoting, executing and settling trades and for the operational messages that go with them.

Legitimate interests — section 11(1)(f). This is the basis for fraud prevention, securing this website, keeping a record of correspondence, and defending a claim. The desk has balanced those interests against your privacy and applies the narrowest processing that achieves the purpose.

Consent — section 11(1)(a). This is the basis only for optional analytics cookies, if the site ever loads any, and for any non-operational message you have asked to receive. Consent given here can be withdrawn at any time, and withdrawing it does not affect processing that already happened lawfully.

How long the information is kept

Section 14 of POPIA prohibits keeping records identifying a data subject for longer than necessary, unless a law requires or authorises retention. Several do.

  • Five years under the FIC Act. Sections 22 and 23 require an accountable institution to keep client identification and transaction records for at least five years from the date the business relationship ends, or from the date a single transaction was concluded. Where a report was filed under section 29, the five years run from the date of the report.
  • Five years under the Tax Administration Act. Section 29 requires records supporting a return to be kept for five years from submission, and longer where an audit or an objection is running.
  • Seven years under the Companies Act for accounting records and certain company records.
  • For the duration of a dispute, and for three years after it ends, where a claim has been made or threatened.
  • Website server logs are kept by the hosting provider for a short operational period and are not linked to a client record.
  • The cx-consent record stays in your own browser until you clear it; the desk holds no server-side copy.

At the end of a retention period, records are destroyed or de-identified in a way that prevents reconstruction, as section 14(4) requires.

Security safeguards, and the operators we use

Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. In practice that means: transport encryption on every page and every form on this site; encryption at rest for client documents; access to client files limited to the dealers and compliance staff who need them, with individual accounts and multi-factor authentication; separation between the public website and the systems that hold client records; logging of access to compliance records; a written incident response procedure; and confidentiality undertakings from every person with access.

Section 20 requires an operator to process only with the responsible party's knowledge, and section 21 requires a written contract with each operator obliging it to maintain the same security safeguards. Every operator engaged by the desk is under such a contract. If you want to know which operators handle a specific category of your information, ask the Information Officer and you will be told.

No safeguard is absolute, and this notice does not claim otherwise. The largest realistic risk to your information is not a breach of the desk's systems but somebody impersonating the desk to you, which is why the verify our channels page exists and why the desk will never ask you for a private key, a seed phrase or a one-time password.

Your rights under section 5, and how to exercise each one

Section 5 of POPIA gives a data subject the following rights. For each one, this is the actual mechanism.

  • To be notified that information is being collected (section 18) — this notice is that notification, and a dealer will confirm any additional collection at the time.
  • To be notified that your information has been accessed by an unauthorised person (section 22) — see the breach section below.
  • To establish whether the desk holds your information, and to request access to it (section 23) — send a request to support@conexus-crypto.com. Access requests are made on the prescribed PAIA request form for a private body, and the process, fees and deadlines are set out in the POPIA and PAIA requests page and in the PAIA manual. The desk must respond within 30 days, extendable once by a further 30 days with reasons.
  • To request correction or deletion (section 24) — use Form 2 of the POPIA Regulations, sent to the Information Officer. Where a record is required by the FIC Act, the desk will correct an inaccuracy but cannot delete the record before its retention period ends; it will say so in writing and give the statutory reference.
  • To object to processing on reasonable grounds (section 11(3)(a)) — use Form 1 of the POPIA Regulations. An objection cannot stop processing the law requires, and the desk will tell you which parts it can and cannot stop.
  • Not to have your information processed for direct marketing by unsolicited electronic communication (section 69) — see the direct marketing section below.
  • Not to be subject to a decision based solely on automated processing (section 71) — see the automated decisions section below.
  • To complain to the Information Regulator (section 74) — using the Regulator's complaint form, with the contact details given below.
  • To institute civil proceedings (section 99) for alleged interference with the protection of your personal information.

The desk does not charge for a correction, an objection or the first copy of your own record. Where PAIA prescribes a fee for reproduction of a large record, the fee and the calculation are given to you before any work starts.

Direct marketing under section 69

Section 69 prohibits processing personal information for direct marketing by unsolicited electronic communication unless the data subject has consented, or is an existing customer contacted about the desk's own similar products with an opportunity to opt out on every message.

The desk sends operational messages — a quote, a confirmation, a settlement advice, a change to a document in this legal centre — because those are necessary to perform the contract, not marketing. Anything else is sent only if you asked for it, and every such message carries an unsubscribe instruction that works on the first attempt.

The desk does not buy contact lists, does not send unsolicited messages to people who have not dealt with it, and does not pass your contact details to anyone for their own marketing. To opt out of everything except operational messages, reply "stop" to any message or write to support@conexus-crypto.com.

Automated decision-making under section 71

Screening tools produce automated alerts — a possible sanctions match, an address flagged by blockchain analytics, an unusual pattern. Those alerts do not decide anything on their own. Every decision to decline a client, decline a trade or end a relationship is taken by a person in the compliance function, who records the reason.

You have the right under section 71 not to be subject to a decision with legal consequences based solely on automated processing. Because the desk does not take such decisions automatically, that right is not engaged in practice; if it ever becomes engaged, you will be told at the time and given the opportunity to make representations.

Security compromises, and what we will tell you — section 22

Section 22 requires a responsible party that has reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person to notify the Information Regulator and the affected data subject as soon as reasonably possible after discovering it, subject only to a delay requested by law enforcement to protect an investigation.

The desk undertakes to do exactly that. A notification to you will describe what happened, the categories of information involved, what the desk has done and is doing about it, what you should do to protect yourself, and the identity of the person who accessed the information if the desk knows it. It will be sent in writing to the email address on your record and, where the compromise is serious, by telephone as well. The desk will not soften the description or delay the notification to manage its own reputation.

If you believe your information held by the desk has been compromised, tell the Information Officer immediately at support@conexus-crypto.com.

This website, cookies and children

The two browser storage keys this site writes, the one cookie Cloudflare may set, and how to withdraw consent are described in full in the cookie and local storage notice. No analytics or marketing script loads before consent is recorded.

Section 34 of POPIA prohibits processing the personal information of a child except in the circumstances section 35 allows. The desk does not knowingly onboard anyone under 18 and does not direct this website at children. If you believe a child's information has reached us, tell the Information Officer and it will be deleted unless a law requires it to be kept.

Complaining about how your information is handled

Complain to the desk first, in writing, to support@conexus-crypto.com, marked for the attention of the Information Officer. You will get an acknowledgement within two business days and a substantive answer within 30 days, in writing, with reasons.

You may complain to the Information Regulator at any time, whether or not you have complained to the desk first, using the Regulator's prescribed complaint form. Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · PO Box 31533, Braamfontein, 2017 · telephone 010 023 5200 · general enquiries enquiries@inforegulator.org.za · POPIA complaints POPIAComplaints@inforegulator.org.za · PAIA complaints PAIAComplaints@inforegulator.org.za · inforegulator.org.za

Where your complaint is about a financial service rather than about your information, the complaints procedure sets out the route to the FAIS Ombud instead.

Version, changes and review

Version 1.0. Effective 18 August 2026. Last reviewed 18 August 2026. Next scheduled review 18 August 2027, or sooner if the law or the desk's processing changes.

A material change to this notice — a new purpose, a new category of recipient, a new cross-border transfer or a change to retention — is notified to active clients by email before it takes effect, and the superseded version is kept and available on request. A change that only corrects a reference or improves clarity takes effect on publication.

Related documents.

Ask what the desk holds about you.

A request for a copy, a correction or a deletion goes to the Information Officer at support@conexus-crypto.com and is answered within 30 days, in writing, with the statutory reference for anything that cannot be deleted.

Investing in crypto assets may result in the loss of capital, as the value is variable and can go up as well as down. A crypto asset is not legal tender and does not fall within the National Payment System Act. Conexus Crypto provides an exchange service only and does not provide financial, investment, legal or tax advice.
WhatsApp Request a quote