POPIA & Data Protection Policy
Contents
1. Purpose & scope 2. Definitions 3. Lawful basis for processing 4. Special personal information & child data 5. Information we process & sources 6. Purposes of processing & further-processing limitation 7. Consent — how we obtain, record & honour it 8. Data-subject rights (request, access, correct, delete, object) 9. Power of attorney & acting on behalf of others 10. Information sharing & processors 11. Cross-border transfers 12. Retention & deletion 13. Information security measures 14. AI and automated decision-making 15. Direct marketing 16. Cookies & client-side state 17. Incident response & breach notification 18. Complaints & the Information Regulator 19. Changes to this policy1. Purpose & scope
This policy explains how Wynk Credit (Pty) Ltd ("Wynk", "we", "us") processes personal information as a responsible party under the Protection of Personal Information Act, 2013 (Act 4 of 2013) ("POPIA"). It applies to every person whose personal information we process — including data subjects whose information is provided to us by partner banks, insurers, medical schemes, debt-collection agencies and other accountable institutions ("Partners") — and to staff, clients and visitors of our website and portals.
Where we process personal information on instruction of a Partner who themselves act as the responsible party, we do so as an operator. In those cases the Partner's policy and operator agreement govern the relationship in addition to this policy.
2. Definitions
- POPIA — the Protection of Personal Information Act, 4 of 2013.
- Personal information — information relating to an identifiable living natural person, and where applicable, an identifiable existing juristic person.
- Special personal information — religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, or criminal behaviour (POPIA s.26).
- Data subject — the person to whom personal information relates.
- Responsible party — the party that determines the purpose and means of processing.
- Operator — a party that processes personal information on behalf of a responsible party.
- Processing — any operation on personal information (collection, recording, storage, use, dissemination, deletion).
- Information Officer — the person designated by Wynk under POPIA s.55 to oversee compliance (privacy@wynk.credit).
3. Lawful basis for processing
We process personal information only where one of POPIA s.11(1) lawful grounds applies:
- Consent — explicit, voluntary, informed and specific consent from the data subject (or a competent person for child data).
- Necessary to perform a contract — where the data subject is party to a contract or steps preceding one.
- Compliance with a legal obligation — particularly the Financial Intelligence Centre Act 38 of 2001 ("FICA") for customer due diligence, the National Credit Act 34 of 2005 ("NCA") for credit-related processing, and the Companies Act for beneficial-ownership look-through.
- Protection of a legitimate interest — including fraud prevention and information security, subject to a balancing test against the data subject's rights.
- Pursuit of legitimate interests of the responsible party or a third party — including the proper pricing of risk in an inclusive credit-intelligence layer.
The lawful basis applicable to each processing activity is recorded in our Processing Register, available on request.
4. Special personal information & child data
We process two categories of special personal information:
- Biometric information — only with explicit consent and only via the Department of Home Affairs (DHA) Digital Gateway / ABIS. We verify against the state's population register; we do not hold a copy of the state's biometric database. Where we enrol a biometric template, it is stored in irreversible, encrypted form under a segregated key class. Raw biometric imagery is never retained.
- Health information — processed only with explicit consent, exclusively for health-intelligence purposes lawfully delegated by a scheme or insurer, under a segregated key class and with purpose limitation enforced in code.
We do not knowingly process personal information of children under 18 without the consent of a competent person. Where we receive such data without proof of competent-person consent, we either obtain it or delete the data.
5. Information we process & sources
| Category | Examples | Source |
|---|---|---|
| Identity | Name, ID number, date of birth, MSISDN, email, registration number | Data subject, Partner, CIPC, DHA Digital Gateway |
| Financial behaviour | Bank statements, POS settlements, mobile-money flows, payroll, repayment outcomes | Partner banks, fintechs, lenders, debt collectors |
| Credit signal | Scores, features, model reason codes | Computed by Wynk on the data above |
| Verification | Liveness result, DHA/ABIS match result, offline-credential metadata | DHA Digital Gateway via our adapter |
| Compliance | PEP/sanctions screening hits, CIPC beneficial-owner look-through, FICA outcome | Public registries & third-party screening lists |
| Health (special) | Engagement (steps, gym, screenings, Rx adherence), clinical claims metadata | Wearables, partner schemes & insurers under explicit consent |
| Account & security | Email, password hash, IP, user-agent, session metadata | The data subject when they create a client account |
6. Purposes of processing & further-processing limitation
We process personal information only for the specific purposes listed below. Personal information collected for one purpose is not used for another unless POPIA s.15(3) permits it (compatible purpose, further consent, statistical/research with appropriate safeguards, or a legal obligation).
- credit_scoring — calculating and serving Wynk Scores and related decisions.
- identity_verification — matching against DHA/ABIS; issuing reusable offline credentials.
- fica_cdd — turnkey customer due diligence on behalf of accountable institutions.
- health_intelligence — explicitly-consented behavioural engagement and morbidity analytics.
- marketing — only with explicit consent, and only where the data subject has not opted out.
7. Consent — how we obtain, record & honour it
Where consent is the lawful basis, we obtain it through clear, specific, informed and voluntary opt-in, separately per purpose. Consent is recorded on a hash-chained consent ledger with the prior-block hash bound into each new entry, making the record tamper-evident. The Engine refuses to score, verify, run FICA or run health intelligence on a subject unless an active consent for that purpose exists; the refusal itself is logged on the audit ledger.
You may grant, change or revoke consent at any time in the client portal → My consents. Revocation takes effect immediately; downstream processing for that purpose ceases. Revocation does not affect the lawfulness of processing carried out before revocation, nor does it remove our right to retain records required by law (FICA s.22–24: five-year retention).
8. Data-subject rights
Under POPIA you have the following rights, each of which we honour through the client portal or, where you prefer, on written request to privacy@wynk.credit:
- Right to be notified (s.18) — what data we hold, the purpose, and the source.
- Right of access (s.23) — a complete export ("DSAR") of every record, processing event and consent entry, replayable in order, including live hash-chain integrity proof. Available in the client portal under Download my data.
- Right to correction or deletion (s.24) — to correct, complete, update or delete personal information that is inaccurate, irrelevant, excessive, out of date, misleading or unlawfully obtained.
- Right to object (s.11(3)) — to processing based on legitimate interest, and to direct marketing.
- Right to data portability — the DSAR export is provided in machine-readable JSON.
- Right not to be subject to a decision based solely on automated processing (s.71) — see section 14.
- Right to complain (s.74) — to us or to the Information Regulator.
We respond within 30 days. Where the request engages information about another person, we balance the rights involved before responding.
9. Power of attorney & acting on behalf of others
A data subject may delegate management of their data to another natural person ("the attorney") under a recorded mandate. The mandate specifies a scope (view only / consent management / full data management) and may be time-limited. Each grant and revocation is written to a hash-chained mandate ledger; the client portal exposes both ledgers to the principal.
An attorney may not in turn delegate the mandate; PoA cannot be granted via PoA. Every action taken under a mandate is recorded on the audit ledger with both the attorney's identity and the principal subject, so an action taken under PoA is always distinguishable from a self-action.
Where a court or competent authority appoints a curator, executor or other legal representative, we accept appropriate evidence and register the mandate on the same ledger.
10. Information sharing & processors
We do not sell personal information. We share it only with:
- Partners who are accountable institutions or contracted operators acting on their own data subjects' instructions, under written operator agreements that meet POPIA s.20–21 standards.
- Service providers strictly necessary for operation — cloud hosting (af-south-1), key-management (HSM/KMS), email delivery, error monitoring — each bound by data-processing terms.
- Regulators and law enforcement where compelled by law (FIC, Information Regulator, NCR, SARB, courts).
An up-to-date list of sub-processors is available on request from privacy@wynk.credit.
11. Cross-border transfers
Personal information is primarily stored in South Africa (AWS af-south-1, Cape Town). Where any cross-border transfer is required (for example, for a partner's regional deployment), it occurs only under POPIA s.72 conditions — to a country with substantially similar protection, under a binding agreement with appropriate safeguards, or with the data subject's consent.
12. Retention & deletion
| Category | Retention period | Reason |
|---|---|---|
| FICA records | 5 years from end of relationship | FIC Act s.22–24 |
| Credit decisions & reason codes | 5 years | NCA & explainability for the data subject |
| Consent ledger entries | Lifetime of the responsible party | Tamper-evident record of authority |
| Audit log | 7 years | Regulatory replay |
| Health intelligence records | 3 years or per scheme contract | POPIA s.14: not longer than necessary |
| Marketing preferences | Until withdrawn | Honour opt-out |
| Server logs (security) | 13 months | Incident investigation |
At the end of retention, records are securely destroyed or de-identified beyond reasonable re-identification.
13. Information security measures
Protection of data is the product. Our measures include — and we test annually — at least the following:
- Envelope encryption (AES-256-GCM) with a unique data-encryption key per record, bound to the record by additional authenticated data, wrapped under domain-segregated master keys.
- Segregated key classes for biometric and health information (POPIA s.26), HSM-backed in production.
- Hash-chained consent & audit ledgers — every entry binds the prior hash, so any retroactive alteration is detectable.
- Salted pseudonyms on the identity graph — raw identifiers do not index any record.
- Role-based access control with least privilege; PII unseal requires the compliance or owner role and is itself audited.
- Strong authentication — scrypt-hashed passwords, hardened session cookies (HttpOnly, SameSite=Strict, Secure in production), idle-timeout, login rate limits, IP & account lockouts with exponential backoff, and CSRF protection on every mutating endpoint via a double-submit token bound to the session.
- Hardened HTTP — strict Content-Security-Policy, X-Content-Type-Options nosniff, X-Frame-Options DENY, Strict-Transport-Security, Referrer-Policy, Permissions-Policy.
- Input validation & output escaping end-to-end.
- Parameterized queries — no string-concatenated SQL.
- API keys — Ed25519/HMAC-strong tokens, only hashes are stored, shown once at issuance, scope-limited, revocable.
- Webhook signing for outbound deliveries.
- Penetration testing — continuous internal stress tests (see the trust centre) and an external annual penetration test.
- Backups — encrypted at rest, geographically separated, tested for restore quarterly.
14. AI and automated decision-making
Credit scores, fraud probabilities and morbidity indices are calculated by AI models. Under POPIA s.71 you have the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effect.
To honour this:
- Every score is returned with explainable, signed reason codes — the data subject and the institution can read them in plain language.
- A lending decision based on a Wynk Score must be reviewable by a natural person at the institution's request — we surface the reason codes and the underlying features.
- You may, at any time, request human review of any decision an institution made about you using a Wynk product. Send a request to privacy@wynk.credit; we will route it to the relevant institution and supply them with the decision evidence.
- Our AI copilot for staff and the scoped AI for clients operate under purpose-limitation and read-only constraints. The scoped client AI sees only the principal's own snapshot — never other subjects — and is audit-logged.
- Models are governed under a champion/challenger discipline with documented performance and population scope.
15. Direct marketing
We send direct marketing only with explicit, separate opt-in consent (POPIA s.69), and only by the channels you have agreed. Each communication includes a one-click unsubscribe. Existing customers may receive marketing about similar products on the basis of POPIA s.69(3), unless they object.
16. Cookies & client-side state
We use only the cookies strictly necessary to operate the site and portals: a session cookie (HttpOnly, SameSite=Strict, Secure in production) and a CSRF token. We do not run third-party advertising or behavioural-tracking cookies on our properties.
17. Incident response & breach notification
We maintain a documented incident-response runbook. In the event of a personal-information compromise that creates a real risk of significant harm:
- Containment within hours; rotation of any compromised keys.
- Forensic assessment and replay against the hash-chained audit log.
- Notification to the Information Regulator as soon as reasonably possible, in compliance with POPIA s.22.
- Direct notification to affected data subjects with: what happened, what data was involved, what we did, and what they should do.
- Post-incident review and policy update.
18. Complaints & the Information Regulator
If you believe we have processed your personal information unlawfully, please contact the Information Officer first (privacy@wynk.credit) — we aim to resolve complaints within 30 days. You also have the right to lodge a complaint directly with the South African Information Regulator:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: inforeg@justice.gov.za · PAIA: PAIAComplaints@inforegulator.org.za
POPIA: POPIAComplaints@inforegulator.org.za
19. Changes to this policy
We may update this policy from time to time. The "Effective" date at the top reflects the current version. Material changes will be communicated through the client portal and, where appropriate, by email.