How SwapEazi collects, uses, stores, and shares your personal information — and the rights you have in relation to it.
SwapEazi (Pty) Ltd ("SwapEazi", "we", "us", or "our") operates the platform available at swapeazi.io. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our services, and your rights in relation to that information.
By using SwapEazi, you agree to the collection and use of information in accordance with this policy.
SwapEazi (Pty) Ltd is a private company incorporated under the laws of South Africa (CIPC registration), and South Africa is our place of business. For questions about this policy, contact us at hello@swapeazi.io.
SwapEazi is the responsible party for the personal information described in this policy, in the sense given to that term by the Protection of Personal Information Act 4 of 2013 (POPIA), and the data controller for the purposes of the UK and EU General Data Protection Regulation where that applies.
Our Information Officer is Msingathi Majola, director, at hello@swapeazi.io. Section 56 of POPIA makes the head of a private body its Information Officer by default, and that is the basis of this appointment.
We use your personal information to:
Most of the personal information we process is processed under South African law. Our grounds for processing under section 11 of POPIA are:
We do not process special personal information or the personal information of children for any purpose connected with this service.
Where a data subject is in the EEA or the United Kingdom, our legal bases under the GDPR are:
Where both POPIA and the GDPR apply to the same processing, we meet the higher standard.
We may share your information with:
We do not sell your personal data to third parties.
SwapEazi operates across Southern Africa and South Africa, and works with licensed partners in each market. Your data may be transferred to and processed in countries other than your own for the purpose of completing a payment, and we require appropriate safeguards from every partner that handles it.
We retain personal data for as long as necessary to provide our services and comply with legal obligations. KYC and transaction records are retained for a minimum of 5 years as required by applicable AML laws, and up to 10 years where required by local regulations.
POPIA gives you the following rights in respect of the personal information we hold about you:
A request under section 23 or 24 is made on Form 2 prescribed under the Promotion of Access to Information Act, sent to our Information Officer. Send it to hello@swapeazi.io and we will acknowledge it and tell you what happens next.
If you are not satisfied with how we have handled your personal information, you may complain to the Information Regulator of South Africa. You do not have to complain to us first, although we would rather you did so that we can put it right.
The GDPR gives you the rights of access, rectification, erasure, restriction of processing, objection and data portability, and the right to lodge a complaint with your local supervisory authority.
Contact us at hello@swapeazi.io. We will verify who you are before acting on a request, because acting on an unverified request is itself a breach. Some rights are limited by our legal retention obligations: we cannot delete a verification or payment record that anti-money-laundering law requires us to keep, and we will tell you when that is the reason.
We implement technical and organisational measures to protect your personal information, including encryption in transit and at rest, restricted access to production data, and separation of public and privileged database credentials.
Our security page sets out where data is hosted and stored, how access is controlled, the sub-processors that handle data on our behalf, and how to report a vulnerability to us. It is published at swapeazi.io/security.
No method of transmission over the internet is completely secure, and we do not claim otherwise.
A compromise of personal information is treated as an incident from the moment it is suspected, not from the moment it is confirmed. We contain it first, then establish what happened, then notify.
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise. We will do so, and we will not delay notification to complete an investigation.
Our internal target is to notify the Information Regulator within 72 hours of establishing that a compromise has occurred, and to notify affected data subjects at the same time unless a public body with jurisdiction tells us that doing so would impede a criminal investigation. Where the GDPR applies, the 72-hour obligation under Article 33 applies in any event.
A notification to you will say what happened, what information was involved, what we have done about it, and what you should do. It will be sent in writing to the address we hold for you, and published on this website where we cannot reach you individually.
Where a compromise occurs at a sub-processor or a licensed partner, we require them to tell us without undue delay, and our obligation to notify you is unchanged by the fact that the incident happened elsewhere.
This website uses cookies and local browser storage only where they are necessary for it to work. That means remembering your light or dark theme preference, and holding a signed session for a signed-in area. We do not use advertising cookies, and we do not sell or share browsing data.
You can clear or block cookies through your browser. Blocking them will not stop you reading this site, but a signed-in area will not keep you signed in.
If we later add analytics or any non-essential cookie, we will ask for your consent before setting it and update this section to say what it does.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on our website with an updated effective date. Continued use of our services after changes constitutes acceptance of the updated policy.
Questions or requests under this policy: hello@swapeazi.io