Privacy

Privacy Policy

How SwapEazi collects, uses, stores, and shares your personal information — and the rights you have in relation to it.

Effective: 7 August 2026Version 1.1

1. Introduction

SwapEazi (Pty) Ltd ("SwapEazi", "we", "us", or "our") operates the platform available at swapeazi.io. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our services, and your rights in relation to that information.

By using SwapEazi, you agree to the collection and use of information in accordance with this policy.

2. Who We Are

SwapEazi (Pty) Ltd is a private company incorporated under the laws of South Africa (CIPC registration), and South Africa is our place of business. For questions about this policy, contact us at hello@swapeazi.io.

SwapEazi is the responsible party for the personal information described in this policy, in the sense given to that term by the Protection of Personal Information Act 4 of 2013 (POPIA), and the data controller for the purposes of the UK and EU General Data Protection Regulation where that applies.

Our Information Officer is Msingathi Majola, director, at hello@swapeazi.io. Section 56 of POPIA makes the head of a private body its Information Officer by default, and that is the basis of this appointment.

3. Information We Collect

3.1 Information You Provide

  • Business information: company name, registration number, business address, beneficial ownership
  • Contact information: name, email address, phone number of the people we deal with
  • Payment information: your supplier's invoices, the accounts you pay from and pay to, and your payment history
  • Verification documents: identity documents for directors and owners, and proof of business address

3.2 Information Collected Automatically

  • IP address and device information
  • Browser type and operating system
  • Usage data: pages visited, features used, session duration

3.3 Information from Third Parties

  • Identity and business verification providers
  • Sanctions and watchlist screening providers
  • Licensed and regulated collection and payout partners

4. How We Use Your Information

We use your personal information to:

  • Provide, operate, and improve our services
  • Verify your identity and comply with KYC/AML obligations
  • Process transactions and send confirmations
  • Detect and prevent fraud, money laundering, and other illegal activity
  • Comply with applicable laws, regulations, and regulatory requests
  • Communicate with you about your account and service updates
  • Conduct sanctions screening against applicable sanctions lists (OFAC, EU, UN)

5. Legal Basis for Processing (POPIA and GDPR)

5.1 South Africa: POPIA

Most of the personal information we process is processed under South African law. Our grounds for processing under section 11 of POPIA are:

  • Performance of a contract to which the data subject is a party, meaning arranging and reconciling the payments you ask us to arrange
  • Compliance with an obligation imposed by law, including the Financial Intelligence Centre Act, sanctions law and tax law
  • Pursuit of our legitimate interests, or those of a third party to whom the information is supplied, including fraud prevention, security and reconciliation
  • Consent, where we have asked for it and you have given it

We do not process special personal information or the personal information of children for any purpose connected with this service.

5.2 European Economic Area and United Kingdom: GDPR

Where a data subject is in the EEA or the United Kingdom, our legal bases under the GDPR are:

  • Contract performance: processing necessary to provide our services
  • Legal obligation: compliance with AML, KYC, sanctions, and tax laws
  • Legitimate interests: fraud prevention, security, and service improvement
  • Consent: where you have explicitly consented to processing

Where both POPIA and the GDPR apply to the same processing, we meet the higher standard.

6. Data Sharing

We may share your information with:

  • KYC/AML and identity verification providers
  • Payment and financial infrastructure partners
  • Regulatory authorities and law enforcement where required by law
  • Legal and professional advisors

We do not sell your personal data to third parties.

7. International Data Transfers

SwapEazi operates across Southern Africa and South Africa, and works with licensed partners in each market. Your data may be transferred to and processed in countries other than your own for the purpose of completing a payment, and we require appropriate safeguards from every partner that handles it.

8. Data Retention

We retain personal data for as long as necessary to provide our services and comply with legal obligations. KYC and transaction records are retained for a minimum of 5 years as required by applicable AML laws, and up to 10 years where required by local regulations.

9. Your Rights

9.1 If you are in South Africa

POPIA gives you the following rights in respect of the personal information we hold about you:

  • To be told that we hold personal information about you, and to be given a record or description of it, under section 23
  • To ask us to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, under section 24
  • To ask us to destroy or delete a record we are no longer authorised to retain, under section 24
  • To object, on reasonable grounds, to processing carried out on the basis of legitimate interests, under section 11(3)
  • To object at any time to processing for direct marketing, under section 11(3) and section 69
  • Not to be subject to a decision based solely on automated processing that has legal consequences for you, under section 71
  • To complain to the Information Regulator, and to institute civil proceedings, under section 74 and section 99

A request under section 23 or 24 is made on Form 2 prescribed under the Promotion of Access to Information Act, sent to our Information Officer. Send it to hello@swapeazi.io and we will acknowledge it and tell you what happens next.

9.2 Complaining to the Information Regulator

If you are not satisfied with how we have handled your personal information, you may complain to the Information Regulator of South Africa. You do not have to complain to us first, although we would rather you did so that we can put it right.

  • Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
  • Complaints: complaints.IR@justice.gov.za
  • General enquiries: inforeg@justice.gov.za
  • Website: inforegulator.org.za

9.3 If you are in the EEA or the United Kingdom

The GDPR gives you the rights of access, rectification, erasure, restriction of processing, objection and data portability, and the right to lodge a complaint with your local supervisory authority.

9.4 Exercising your rights

Contact us at hello@swapeazi.io. We will verify who you are before acting on a request, because acting on an unverified request is itself a breach. Some rights are limited by our legal retention obligations: we cannot delete a verification or payment record that anti-money-laundering law requires us to keep, and we will tell you when that is the reason.

10. Security

We implement technical and organisational measures to protect your personal information, including encryption in transit and at rest, restricted access to production data, and separation of public and privileged database credentials.

Our security page sets out where data is hosted and stored, how access is controlled, the sub-processors that handle data on our behalf, and how to report a vulnerability to us. It is published at swapeazi.io/security.

No method of transmission over the internet is completely secure, and we do not claim otherwise.

11. Data Breach Notification

A compromise of personal information is treated as an incident from the moment it is suspected, not from the moment it is confirmed. We contain it first, then establish what happened, then notify.

Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise. We will do so, and we will not delay notification to complete an investigation.

Our internal target is to notify the Information Regulator within 72 hours of establishing that a compromise has occurred, and to notify affected data subjects at the same time unless a public body with jurisdiction tells us that doing so would impede a criminal investigation. Where the GDPR applies, the 72-hour obligation under Article 33 applies in any event.

A notification to you will say what happened, what information was involved, what we have done about it, and what you should do. It will be sent in writing to the address we hold for you, and published on this website where we cannot reach you individually.

Where a compromise occurs at a sub-processor or a licensed partner, we require them to tell us without undue delay, and our obligation to notify you is unchanged by the fact that the incident happened elsewhere.

12. Cookies

This website uses cookies and local browser storage only where they are necessary for it to work. That means remembering your light or dark theme preference, and holding a signed session for a signed-in area. We do not use advertising cookies, and we do not sell or share browsing data.

You can clear or block cookies through your browser. Blocking them will not stop you reading this site, but a signed-in area will not keep you signed in.

If we later add analytics or any non-essential cookie, we will ask for your consent before setting it and update this section to say what it does.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on our website with an updated effective date. Continued use of our services after changes constitutes acceptance of the updated policy.

Contact

Questions or requests under this policy: hello@swapeazi.io