Privacy Policy
Your numbers are yours. Here’s exactly how FinFex handles your information, in line with POPIA.
We respect your privacy and are committed to protecting your personal data. One promise sits above everything: your data works for you, never against you. We never sell it, and we never share your liquidity signal with anyone who could use it to harm you.
Version 1.0 · Effective 16 July 2026 · Responsible party: FinFex Pty Ltd · Information Officer registered with the Information Regulator (South Africa) · Registration 2026-0611586 (FINFEX PTY LTD · THE PULSE)
1. Who We Are & Our Promise
FinFex Pty Ltd (“FinFex”, “we”, “us”) is a South African company that builds The Pulse — the predictive liquidity engine that turns your daily trade records into a 14-day Safe-to-Spend signal, delivered over WhatsApp and our app. We respect your privacy and we are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, store and protect your information when you use our website, products or services.
One promise sits above everything in this policy, because our whole business is built on it: your data works for you, never against you. We never sell your information, and we never share your liquidity signal with anyone who could use it to harm you — not a lender chasing you, not a landlord, not a supplier negotiating against you. Verification and data sharing exist to unlock benefits for you (like supplier stock guarantees), and only ever with your consent.
FinFex is the “responsible party” under South Africa’s Protection of Personal Information Act, 2013 (POPIA). Our Information Officer is registered with the Information Regulator and is your first contact for anything in this policy (see Section 15).
2. Scope — What This Policy Covers
This policy covers personal information we process about: merchants and business owners who use The Pulse (free or paid); aspiring entrepreneurs on Advisory-Only Mode; consultants, bookkeepers and advisors using Portfolio Triage; contact people at our wholesaler and other partners; and visitors to our website and WhatsApp channels.
It covers our website, the WhatsApp bot, our progressive web app, and our sales and support interactions. It does not cover third-party services you use alongside ours (for example Yoco, Sage, or WhatsApp itself) — their own privacy policies govern what they do. Our employees’ personal information is covered by our internal People & HR Policy Playbook, not this document.
3. Information We Collect
We collect only what the product genuinely needs — every extra field is treated internally as a defect, not a feature. What we collect depends on how you use The Pulse:
- Identity and contact information: your name, phone number, business name, language preference, and business type (for example spaza, salon, transport), collected when you sign up.
- Trade and ledger data you give us: photos of paper tallies, voice notes, text entries and till slips that you send us to record your trade — parsed into revenue, expense and liability entries. This may include supplier names, amounts, and (only if you choose to enter them, always in your private channel) informal loan details.
- Connected account data, with your explicit consent: if you link a payment or accounting service (such as Yoco or Sage) through the two-tap authorisation, we receive the transaction history you approve. You can disconnect at any time.
- Verification data: where you seek Verified status, corroborating information from wholesalers you actually buy from — limited to what confirms your trading pattern, never your full ledger handed to them (see Section 5).
- Usage and technical data: how you interact with the bot and app (keywords used, alerts received and read, device type, approximate network conditions) so we can keep the product fast on low-bandwidth connections, plus standard server logs.
- Communications: your messages with our support and onboarding team, corrections you send us when a forecast is wrong, and referral connections when you share The Pulse with another trader.
- Special personal information: we do not ask for it. If it appears incidentally (for example in a voice note), we do not use it for any decision, and it is protected under POPIA’s stricter rules.
4. How We Use Your Information
Under POPIA we may only process your information lawfully, minimally, and for specific purposes we have told you about. Here is the full list — and the lawful basis for each:
- To provide The Pulse: parsing your entries, computing your Safe-to-Spend signal, your ring status, and your alerts — performance of our contract with you (POPIA s 11(1)(b)).
- To improve forecast accuracy for you: when you correct a forecast, your correction retrains the model that serves you — legitimate interest pursued with your knowledge (s 11(1)(f)), and the improvement is shown back to you.
- To verify your business when you request Verified status and its benefits — performance of contract and your consent.
- To send you service messages: alerts, ring changes and onboarding check-ins, in your language, respecting quiet hours (21:00–06:00). Marketing messages, where any, are separate, and you can opt out of them at any time without affecting your service (s 69 direct-marketing rules; ECTA s 45).
- To keep the service safe: fraud and anomaly detection, security monitoring, and abuse prevention — legitimate interest and legal obligation.
- To comply with law: tax, financial-sector and regulatory obligations, and responses to lawful requests by public authorities — legal obligation (s 11(1)(c)).
- To understand usage in aggregate: statistical and product analytics performed on de-identified data that no longer identifies you — POPIA does not restrict properly de-identified data, and we hold ourselves to re-identification being prohibited internally.
- We never use your data to: sell or rent it to anyone; profile you for lending you did not ask about; share your liquidity distress with any third party; or train models for anyone else’s benefit using your identifiable data.
5. Sharing of Information
We share personal information only in the narrow circumstances below, and every recipient is bound by contract to protect it. We run an incentive-alignment check on every partner before signing: any partner who could gain from misusing your data is redesigned around, or not signed at all.
- Service providers (“operators” under POPIA s 20–21): cloud infrastructure (hosted in the AWS Africa (Cape Town) region), the WhatsApp Business API, and payment processors — each processes your data only on our written instructions, under confidentiality and security obligations.
- Wholesalers, for verification only and with your consent: when you request Verified status, the wholesalers you buy from confirm your purchasing pattern. They see aggregates sufficient to corroborate — never your full ledger, never your Safe-to-Spend signal, and they are contractually barred from using verification data for their own credit decisions about you without your separate, explicit consent (for example when you apply for a stock guarantee).
- Your consultant or bookkeeper, only if you consent: if your advisor uses Portfolio Triage, you receive a consent request naming the advisor and exactly what they will see (liquidity risk states — not your raw ledger). No consent, no visibility, and you can revoke at any time.
- Vetted financial partners, only at your request: if you ask to be introduced for working capital or a stock guarantee, we share only what you approve, with partners who have passed our non-predatory vetting. We never “pre-sell” your data to lenders.
- Legal and safety disclosures: where a law, court order or regulator lawfully requires it, or where disclosure is necessary to prevent serious and imminent harm — limited to what is required, documented, and challenged where the request is overbroad.
- Business changes: if FinFex is ever merged, acquired or restructured, your information may transfer to the successor — bound by this policy, with notice to you, and your rights intact.
6. Data Security
POPIA s 19 requires appropriate, reasonable technical and organisational measures — we treat that as a floor, because our verification-grade dataset deserves bank-grade care. Our measures include: encryption of data in transit and at rest; strict least-privilege access on multi-tenant grants (your advisor, if any, sees only what you consented to; our own staff see only what their role requires); network isolation; continuous security monitoring with fraud and anomaly detection; an immutable, tamper-evident consent ledger; scheduled resilience and failover testing (we rehearse failures monthly rather than assuming reliability); and independent security review as part of our investor and partner diligence.
No system on earth is perfectly secure. If a breach ever occurs that affects your personal information, we will contain it, assess it within 24 hours, and notify the Information Regulator and you as required by POPIA s 22 — in plain language, in your language, telling you what happened, what data was involved, and what we are doing about it.
7. Data Retention
We keep personal information only as long as the purpose it was collected for requires, or as law requires — whichever is longer — and then we delete or de-identify it. Our schedule in summary:
- Your ledger and forecast history: retained while your account is active, because your history is what makes your forecast accurate. If you close your account, it is deleted or fully de-identified within 90 days, except where law requires longer.
- Consent records: kept on the immutable ledger for 7 years, because proving what you consented to — and what you revoked — protects you.
- Financial and tax records: 5 years (or as tax law requires).
- Verification and corroboration records: for the life of your Verified status plus the period our financial-sector obligations require.
- Support conversations and corrections: 24 months, after which they are de-identified into training data that no longer identifies you.
- Technical logs: rolling short-term windows (typically 90 days) unless preserved for an active security investigation.
8. Your Rights
POPIA gives you real, enforceable rights over your information, and we have built the mechanics to honour them fast — in your language, over the channel you already use:
- Access: ask what we hold about you and get a copy, in plain language (also supported by PAIA — our PAIA manual is available on request).
- Correction: fix anything inaccurate — including a wrong forecast input; correcting us is built into the product and we thank you for it.
- Deletion: ask us to delete personal information we no longer need or process unlawfully; account closure triggers the Section 7 schedule.
- Objection: object to processing based on legitimate interests, and to direct marketing at any time — marketing stops immediately on opt-out.
- Consent withdrawal: revoke any consent (a connected account, an advisor’s visibility, verification sharing) at any time; we honour revocations within 48 hours and they are recorded on the same immutable ledger as the original consent.
- Not to be subject to automated decisions with legal or similar significant effect without recourse: your Safe-to-Spend signal is advisory to you — it is never used to automatically deny you anything; verification decisions include human review and you can always ask for the reasons and challenge them.
- Complaint: complain to us first if you wish (Section 15) — or directly to the Information Regulator (South Africa): inforegulator.org.za, JD House, 27 Stiemens Street, Braamfontein, Johannesburg. You never need our permission to go to the Regulator.
To exercise any right: message the keyword PRIVACY on the bot, or contact the Information Officer (Section 15). We verify your identity (OTP on your registered number), act within the statutory windows, and never charge for a first request.
9. Our Commitment — The Non-Predatory Line
Most privacy policies stop at compliance. Ours cannot, because trust is our entire product. So we commit, in writing, to the following — and we invite you to hold us to them:
- We never sell your personal information. Not to advertisers, not to data brokers, not to lenders. Revenue comes from services you choose, never from your data changing hands.
- Your distress is private. A RED status — especially anything involving informal loans — travels only on your private channel, is never visible to advisors, wholesalers or anyone else, and is never used to market anything to you. We do not monetise hard times.
- We show you only numbers we can stand behind. When our system lacks confidence, it says so honestly (a GREY ring) rather than guessing — the same honesty applies to what we tell you about your data.
- Corrections belong to you. When you tell us a forecast was wrong, your correction improves your own forecast, and we close the loop by telling you so.
- The free warning stays free. Your Safe-to-Spend warning is never paywalled, and leaving The Pulse is always free: ask, and we help you export your ledger history in a usable format.
10. Cookies & Tracking Technologies
Our product lives mostly in WhatsApp, which uses no FinFex cookies at all. Our website and progressive web app use a deliberately small set:
- Strictly necessary storage: session tokens, language preference, and the offline-first sync queue that keeps your data safe when connectivity drops. These are essential and cannot be switched off; they store nothing used to track you across other sites.
- Analytics: privacy-respecting, aggregate usage measurement to see what is slow or confusing — configured without cross-site tracking identifiers. Where consent is required for analytics in your jurisdiction, we ask first.
- What we do not use: third-party advertising cookies, social-media trackers, cross-site behavioural profiling, or fingerprinting. Our growth engine is traders recommending us to traders — not surveillance.
- You can clear or block storage in your browser settings; the app will tell you plainly if a function (like offline sync) cannot work without it.
11. Children’s Privacy
The Pulse is a business tool for adults. We do not offer services to, or knowingly collect personal information from, anyone under 18 (a “child” under POPIA, which permits processing a child’s information only in narrow circumstances with a competent person’s consent). Our sign-up flow requires confirmation of age and business ownership.
If you believe a child’s information has reached us, contact the Information Officer (Section 15) and we will investigate and delete it promptly. If we expand into youth entrepreneurship programmes in future, we will do so under a specific, consent-based framework published in advance — with guardians’ consent obtained verifiably, and never with tracking or behavioural profiling of minors.
12. Transfers of Data Across Borders
Your data lives in South Africa: our production systems run in the AWS Africa (Cape Town) region, and data residency in-country is an architectural commitment, not an accident. Some service providers (for example the WhatsApp Business API) may process limited data outside South Africa as part of delivering messages to you.
Whenever personal information leaves South Africa, POPIA s 72 applies: we transfer only to recipients bound by law, binding corporate rules or contract to a substantially similar standard of protection as POPIA, or with your consent, or where the transfer is necessary to perform our contract with you. Our operator agreements carry these protections explicitly, and the transfer register is reviewed in our quarterly privacy audit.
13. Other Jurisdictions — GDPR, DPDP & African Data-Protection Laws
FinFex is built in South Africa under POPIA. As we grow across borders — SADC corridors, diaspora users, embedded partnerships — we hold ourselves to the strictest applicable standard and this section explains how the policy adapts:
- European Union / EEA (GDPR): if we offer services to people in the EU/EEA, GDPR applies to that processing. Our POPIA foundations map closely: our lawful bases (Article 6), your rights (Articles 15–22, including portability — which our ledger-export commitment already delivers), breach notification (Articles 33–34), and international transfers via adequacy decisions or Standard Contractual Clauses (Chapter V). Where GDPR grants a stronger right than POPIA, EU/EEA users receive the stronger right, and we will appoint an EU representative (Article 27) before actively serving that market.
- India (Digital Personal Data Protection Act, 2023 and its Rules; Information Technology Act, 2000): if we offer services to Data Principals in India, the DPDP Act applies. We will process digital personal data only with consent or for legitimate uses as defined in the Act, honour Data Principals’ rights (access, correction and erasure, grievance redressal, and nomination), provide notices in the languages the Act requires, apply verifiable parental consent for anyone under 18 with no tracking or targeted advertising to children, and observe the security and breach-notification duties of a Data Fiduciary, including reporting to the Data Protection Board of India. Reasonable security practices under the IT Act, s 43A framework, are already met by our Section 6 measures.
- SADC and wider Africa: as corridors open beyond South Africa, we will comply with each country’s data-protection law before launch — for example Botswana’s Data Protection Act, Namibia’s emerging framework, Zimbabwe’s Data Protection Act, Mozambique’s constitutional and sectoral rules, and Kenya’s Data Protection Act if East African corridors open. Country launches are stage-gated: privacy compliance is a launch precondition, funded as pre-revenue infrastructure — never retrofitted after growth.
- One standard everywhere: wherever the law is silent or weaker, the commitments in this policy — especially Section 9 — still apply in full. The floor travels with us.
14. Changes to This Policy
When we change this policy, we change it in the open. We will notify you of material changes through the channel you already use (WhatsApp or the app), in your language, at least 14 days before they take effect — with a plain-language summary of what changed and why, not just a new wall of text. The current version and its effective date always appear at the top of this policy, and previous versions are available on request.
We will never use a policy change to take rights away from you retroactively, and we will never introduce data selling by amendment — Section 9’s commitments are permanent.
15. Contact Us
For anything in this policy — questions, rights requests, or complaints — your first contact is our Information Officer:
- Information Officer, FinFex Pty Ltd — responsible party under POPIA. Information Regulator registration: 2026-0611586 (FINFEX PTY LTD · THE PULSE).
- WhatsApp: message the keyword PRIVACY to +27 67 682 0384 — the same channel you already use for The Pulse. We confirm receipt within 2 business days and act within POPIA’s statutory windows.
If you prefer — or if you are not satisfied with our response — you can contact the Information Regulator (South Africa) directly at any time: inforegulator.org.za · JD House, 27 Stiemens Street, Braamfontein, Johannesburg. You never need our permission to do so.