C Cofi Compliance coficompliance.com
Services What's new Regulatory Brief Fit & Proper Vacancies Contact

Legal hygiene

Privacy Notice

Cofi Compliance - Compliance, Implemented.

Publication placeholder: Final legal/entity details are still required where bracketed placeholders appear, including legal entity name, registration number, addresses, telephone number, Information Officer details, and any approved FSCA compliance-practice wording.

Issuer: Cofi Compliance [insert legal entity name, e.g. (Pty) Ltd] ("Cofi Compliance", "we", "us", "our")

Website: https://coficompliance.com/

Effective date: [insert date]

Version: 1.0

1. Purpose of this Privacy Notice

This Privacy Notice explains how Cofi Compliance collects, uses, stores, shares, protects, and destroys personal information when people visit our website, contact us, request services, subscribe to updates, apply for a role, or otherwise interact with us.

We process personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), the Promotion of Access to Information Act, 2 of 2000 ("PAIA"), and other applicable South African laws.

2. Responsible party and contact details

Cofi Compliance is the responsible party for personal information that it determines the purpose and means of processing.

Information Officer: [insert name]

Deputy Information Officer: [insert name, if applicable]

Email: hello@coficompliance.com

Physical address: [insert physical address]

Company registration number: [insert registration number]

FSCA-approved compliance practice status: [insert status if applicable]

3. Personal information we may collect

We may collect and process:

  • Identity and contact information, including names, job titles, email addresses, telephone numbers, company names and FSP numbers.
  • Client and prospective-client information, including licence categories, compliance questions, regulatory correspondence, representative/KI information, service requirements, website URLs, and business records voluntarily supplied to us.
  • Website and technical information, including IP address, device information, browser type, pages visited, timestamps, referral source, and cookie or analytics identifiers where applicable.
  • Recruitment information, including CVs, qualifications, employment history, references, interview notes, and suitability information.
  • Billing and administration information, including invoices, payment status, tax information, engagement letters, and supplier information.
  • Communication records, including emails, consultation requests, meeting notes, support queries, complaints, and consent records.

4. Sources of personal information

We may collect personal information directly from you, from your employer or representative, from public regulatory sources, from public company or FSP records, from our website forms, from email and meeting interactions, and from service providers who support our website, hosting, email, CRM, document storage, analytics, or business operations.

5. Purposes for processing

We process personal information to:

  • Respond to enquiries and consultation requests.
  • Provide compliance, licensing, fit and proper, COFI readiness, website review, regulatory monitoring, training, and related services.
  • Prepare proposals, engagement letters, reports, evidence files, regulatory submissions, and implementation plans.
  • Maintain client records, compliance calendars, training records, billing records, and internal quality controls.
  • Manage recruitment and supplier relationships.
  • Improve website functionality, security, content relevance, and user experience.
  • Send regulatory updates, service communications, or marketing communications where permitted by law.
  • Comply with legal, regulatory, tax, accounting, recordkeeping, and dispute-resolution obligations.
  • Detect, prevent, and respond to fraud, unlawful activity, security incidents, or unauthorised access.

6. Legal bases and lawful processing

Depending on the circumstances, we process personal information because:

  • You have consented to the processing.
  • Processing is necessary to perform or enter into a contract.
  • Processing is necessary to comply with a legal obligation.
  • Processing protects a legitimate interest of Cofi Compliance, a client, a data subject, or another person, where such interest is not overridden by the data subject's rights.
  • Processing is necessary for the proper performance of a public law duty, where applicable.

7. Special personal information and children's information

We do not intentionally collect special personal information or children's personal information through the website unless it is necessary for a specific lawful purpose and appropriate safeguards apply. If such information is provided to us as part of a client matter or recruitment process, we will process it only where permitted by POPIA and applicable law.

8. Direct marketing and regulatory updates

We may send regulatory updates or service communications to existing clients or subscribers where permitted. You may opt out of marketing communications at any time by using the unsubscribe option or contacting us at hello@coficompliance.com.

We will not sell your personal information to third-party advertisers.

9. Sharing personal information

We may share personal information with:

  • Employees, consultants, contractors, and authorised representatives who need access to perform their duties.
  • Hosting, email, analytics, CRM, document management, cybersecurity, accounting, and professional-service providers.
  • Regulators, public bodies, ombuds, courts, law enforcement, or other authorities where required or permitted by law.
  • Clients, counterparties, or advisers where necessary to deliver services or protect legal rights.

Where a service provider acts as an operator under POPIA, we require appropriate confidentiality and security undertakings.

10. Cross-border transfers

Some technology providers may store or access information outside South Africa. Where personal information is transferred cross-border, we will take reasonable steps to ensure that the transfer is lawful and that appropriate safeguards apply.

11. Security safeguards

We take reasonable and appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, unlawful processing, disclosure, alteration, or destruction. Measures may include access controls, password controls, secure storage, role-based permissions, backups, confidentiality undertakings, security reviews, and incident-response procedures.

No website, email system, or electronic storage platform can be guaranteed to be completely secure. Users should avoid sending unnecessary sensitive information through website forms or unsecured email.

12. Retention and destruction

We retain personal information only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law, contract, regulatory expectation, dispute-resolution need, or legitimate business purpose. When information is no longer required, we will delete, destroy, de-identify, or restrict it in a manner that prevents unauthorised use or reconstruction, where reasonably practicable.

13. Data subject rights

Subject to applicable law, you may request to:

  • Confirm whether we hold your personal information.
  • Access your personal information.
  • Correct or update inaccurate, irrelevant, excessive, outdated, incomplete, misleading, or unlawfully obtained information.
  • Delete or destroy information that we are no longer authorised to retain.
  • Object to certain processing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the Information Regulator.

Requests may be sent to hello@coficompliance.com. We may require proof of identity before acting on a request.

14. PAIA and access requests

Requests for access to records under PAIA must be submitted using the prescribed process described in our PAIA Manual. POPIA access and correction requests may be handled through the same contact point to ensure consistent processing.

15. Complaints

Complaints may be sent to hello@coficompliance.com. You may also contact the Information Regulator (South Africa) through the contact details published on its website.

16. Third-party websites and videos

Our website may link to third-party websites, regulatory sources, FSCA pages, YouTube videos, and other external content. We do not control those websites or their privacy practices. Users should review the applicable third-party privacy notices and cookie notices before interacting with external content.

17. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. The latest version will be published on our website with its effective date.

Privacy Notice PAIA Manual Data Subject Requests
Cofi Compliance Compliance, Implemented. hello@coficompliance.com
Privacy Notice PAIA Manual Terms of Use Website Disclaimer Cookie Notice Data Subject Requests Email Disclaimer