This Privacy Policy explains how FicMe (Pty) Ltd (hereinafter referred to as "FicMe", "we", "us" or "the Organisation") collects, verifies, stores, uses, discloses and otherwise processes personal information through the FicMe platform.
FicMe operates a secure electronic platform designed to facilitate the collection, verification, secure storage and controlled disclosure of personal information and supporting documentation required by accountable institutions to comply with the provisions of the Financial Intelligence Centre Act, 38 of 2001 ("FICA"), the Protection of Personal Information Act, 4 of 2013 ("POPIA"), and other applicable legislation.
In operating the FicMe platform, FicMe determines the purposes for which, and the means by which, personal information is processed in relation to the services provided through the platform and, accordingly, acts as a responsible party, as contemplated in POPIA, in respect of such processing. This applies irrespective of whether the personal information is submitted directly by an individual, or is submitted on behalf of a company, trust, partnership, other juristic person or legal arrangement by an authorised representative.
Nothing in this Privacy Policy limits the responsibilities of any accountable institution, company, trust or other organisation that collects, submits, accesses or otherwise processes personal information through the FicMe platform. Such entities may, in relation to their own processing activities and legal obligations, also constitute responsible parties in terms of POPIA and remain responsible for ensuring that their collection, disclosure an
1. Responsible Party
FicMe (Pty) Ltd (Registration number: [Registration number])
Information Officer Details:
Information Officer: ………………………………………….
Deputy Information Officer: ……………………………………
Physical Address: ………………………………………..
Postal Address: ………………………………………….
Telephone Number: +27 …………………………………….
Email address: privacy@ficme.app
2. Personal information we collect
Personal information is collected solely for the purpose of facilitating the identification and verification of natural and juristic persons in accordance with FICA and may include identity documents, registration documents, proof of address, tax information, ownership and control information, and any other information reasonably required to enable an accountable institution to fulfil its statutory customer due diligence obligations.
Account information: name, email, mobile number, password hash.
Identity information: South African ID number, passport number, date of birth.
Verification documents: ID document, proof of address, bank confirmation, SARS tax certificate, Organisation registration (CIPC) and beneficial ownership documents.
Contact and address details for you and, for business accounts, the entities you manage.
Consent, sharing and audit metadata: when documents were shared, with whom, and how consent (usually OTP) was captured.
Technical data: IP address, device and browser information, log data.
Billing information processed by our payment providers on our behalf.
3. Why we process your personal information (purpose and lawful basis)
To create and operate your compliance passport (performance of the contract with you).
To let you share documents with accountable institutions on your instruction (your consent).
To send expiry reminders and service notifications (legitimate interest / performance of contract).
To meet our own record-keeping and reporting obligations (compliance with a legal obligation).
To secure the platform, prevent fraud and abuse (legitimate interest).
To bill you and collect payment (performance of contract).
FICA Vault processes such personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), and only for lawful purposes consistent with the purpose for which the information was obtained.
4. Who we share it with
Personal information and supporting documentation will only be made available to an accountable institution that has subscribed to the Organisation's platform and solely for the purpose of enabling that accountable institution to comply with its obligations under FICA and any applicable anti-money laundering, counter-terrorist financing or related legislation.
Accountable institutions and other recipients that you specifically approve — always with an audit trail.
Operators / sub-processors that host, secure and support the platform (cloud hosting, email delivery, analytics, payment processing, customer support).
Regulators, courts or law-enforcement where we are legally compelled to do so.
Personal information will not be sold, marketed or disclosed to third parties for commercial purposes.
The disclosure of personal information to a subscribing accountable institution shall only occur after the data subject, or where applicable the duly authorised representative of a juristic person, has expressly authorised such disclosure through the Organisation's authentication process, including, where applicable, verification by means of a One-Time Password (OTP) or any other secure multi-factor authentication process implemented by the Organisation. No personal information shall be released without such authorisation, unless the Organisation is required to do so by law or pursuant to a lawful order of a competent authority.
5. Cross-border transfers
Some of our sub-processors process data outside South Africa. Where this happens, we rely on POPIA-compliant safeguards, including adequacy findings, binding corporate rules or contractual protections that require a comparable standard of protection.
6. Retention
We keep personal information only as long as necessary for the purposes above or as required by law (for example FIC Act record-keeping). When you close your account, we allow a 30-day export window and then delete or anonymise your content, except where a legal retention obligation requires us to keep it longer.
7. Security
FicMe maintains appropriate, reasonable and industry-accepted technical and organisational safeguards designed to protect personal information against loss, unauthorised access, misuse, disclosure, alteration or destruction. Such safeguards include encryption of data in transit and at rest where appropriate, secure authentication procedures, OTP-based consent for sharing, signed and time-limited share links, and continuous monitoring access controls based on authorised user permissions, activity logging and monitoring, and other security measures designed to preserve the confidentiality, integrity and availability of personal information.
No system is perfectly secure, but we work hard to protect your information and will notify you and the Information Regulator of any material personal-information breach as required by POPIA.
8. Cookies
See our Cookie Policy for details of the cookies and similar technologies we use.
9. Children
FicMe is not directed at children under 18. We do not knowingly collect personal information of children without appropriate parental consent.
Where you submit or upload the personal information of a child (as defined in POPIA) through the FicMe platform, you represent and warrant that you are duly authorised to do so and that the processing of such personal information is undertaken with the consent of a competent person, as contemplated in section 35(1)(a) of the Protection of Personal Information Act, 4 of 2013 ("POPIA"), or is otherwise lawfully permitted in terms of POPIA.
By submitting such information, you further confirm and declare that all consents, permissions and authorities required by applicable law have been obtained prior to the submission of the child's personal information and that you shall, upon request, be able to demonstrate or provide evidence of such authority or consent. You indemnify FicMe against any loss, claim, liability, damage, penalty or expense arising from any breach of the warranties and confirmations contained in this clause.
10. Your rights
Under POPIA you may:
ask what personal information we hold about you and request a copy;
ask us to correct or delete inaccurate or out-of-date information;
object to processing that relies on legitimate interest;
withdraw consent for future processing that relies on consent;
complain to the Information Regulator (South Africa) — inforegulator.org.za.
To exercise these rights, contact privacy@ficme.app.
11. Consent and Authorisation
Subscribing accountable institutions receiving personal information through FIC Vault's platform acknowledge and agree that such information may only be processed for the specific purpose for which it was disclosed, namely compliance with FICA and related legal obligations. The information may not be further processed, retained, disclosed or used for any unrelated purpose except where permitted or required by law or with the further consent of the relevant data subject.
The Organisation does not independently verify or supplement personal information from unauthorised third-party data sources obtained without the knowledge or consent of the relevant data subject. Personal information is collected directly from the data subject or from a duly authorised representative and is disclosed only in accordance with the data subject's express authorisation and applicable law.
All subscribers and/or users of the platform / application expressly:
warrants that all information supplied is true and correct;
consents to the storage of the information on the platform;
authorises the Organisation to disclose the information to specifically authorised subscribing accountable institutions for FICA purposes;
acknowledge that each disclosure requires a fresh authorisation (OTP) unless the user has expressly selected an ongoing authorisation;
acknowledge that consent may be withdrawn at any time, subject to statutory record-retention obligations under FICA; and
acknowledges that FicMe merely facilitates the secure transfer of information and does not determine whether an accountable institution has satisfied its own FICA obligations.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email or in-app at least 14 days before they take effect.
13. General Privacy Statement
This Privacy Policy addresses the collection, processing, storage, use and disclosure of personal information obtained by the Organisation specifically for purposes of facilitating compliance with the Financial Intelligence Centre Act, 38 of 2001 ("FICA"), and related legal and regulatory requirements.
The Organisation also collects and processes other categories of personal information in the ordinary course of conducting its business, including information collected through its website, applications, communications, customer support services, subscription services, marketing activities and other interactions with users.
FICA Vault's general practices relating to the collection, processing, retention, security, sharing and protection of personal information, together with the rights of data subjects under the Protection of Personal Information Act, 4 of 2013 ("POPIA"), are set out in the Organisation's General Privacy Statement, which is available under the Legal Notices section of the Organisation's website.
This Privacy Policy forms part of, and must be read together with, the Organisation's General Privacy Statement. Unless expressly stated otherwise, all definitions, data subject rights, security measures, retention practices, procedures for exercising rights, complaints procedures, contact details of the Information Officer, and other provisions contained in the General Privacy Statement are incorporated into this Privacy Policy by reference as if specifically set out herein.
All users, subscribers, data subjects and authorised representatives are encouraged to read the General Privacy Statement together with this Privacy Policy. The General Privacy Statement supplements this Privacy Policy and applies to all processing of personal information by the Organisation except to the extent that this Privacy Policy contains specific provisions applicable to information collected and processed for FICA compliance purposes. In the event of any inconsistency relating to the processing of FICA-related information, the provisions of this Privacy Policy shall prevail to the extent of that inconsistency.
14. Authority to Submit and Disclose Personal Information
Where you submit, upload, provide or otherwise make available personal information to FicMe, whether relating to yourself or to any other natural or juristic person, you represent, warrant and undertake that:
you are duly authorised to submit, upload and disclose such personal information to FicMe for the purposes contemplated by the FicMe platform;
the collection, disclosure and submission of such personal information to FicMe complies with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), the Financial Intelligence Centre Act, 38 of 2001 ("FICA"), and all other applicable laws;
where required by law, you have obtained all necessary consents, permissions, authorisations and approvals from the relevant data subject or from any person lawfully authorised to act on behalf of such data subject, prior to submitting the personal information to FicMe;
where you submit personal information in your capacity as a director, trustee, member, partner, shareholder, beneficial owner, authorised representative, employee, administrator, agent or any other authorised person acting on behalf of a company, trust, partnership, association, legal arrangement or other organisation, you have the necessary authority to do so and to disclose the personal information of the relevant data subjects to FicMe;
all personal information submitted to FicMe is, to the best of your knowledge, complete, accurate and up to date at the time of submission, and you undertake to update such information where it becomes inaccurate or incomplete; and
you shall, upon reasonable request by FicMe, provide such documentary proof of your authority, consent or other lawful basis for the disclosure and processing of the personal information as FicMe may reasonably require in order to comply with its legal and regulatory obligations.
You acknowledge and agree that FicMe is entitled to rely upon the warranties, representations and undertakings contained in this clause and shall not be obliged to verify your authority or the existence of any consent or other lawful basis before processing the personal information submitted through the FicMe platform.
You indemnify and hold harmless FicMe, its directors, officers, employees and agents against any loss, damage, liability, claim, administrative fine, penalty, cost or expense (including reasonable legal costs) arising from or relating to any breach of the warranties, representations or undertakings contained in this clause, or from any unauthorised or unlawful submission or disclosure of personal information by you.

