Crypto.com – Africa Privacy Notice

Last Updated: 20 June 2022

Welcome to Crypto.com – Africa Privacy Notice (“Privacy Notice”). The practices described below only apply to the processing of your personal information subject to the applicable local laws, with emphasis on the South African Protection of Personal Information Act, 2013 (Act 4 of 2013) (POPIA) which gives effect to the constitutional right to data privacy in terms of Section 14 of the Bill of Rights of the Constitution and / or the respective applicable regulations. Please spend a few minutes to read it carefully before providing us with any information about you or any other person.

Contents

1.Introduction

2. Purpose

3. Who we are

4. What information we collect about you

5. How we collect your personal information

6. How we use your information

7. Disclosures of your information

8. International transfers

9. Information security

10. Information retention

11. Your legal rights

1. Introduction

We respect your privacy, and we are committed to protecting your personal information. This Privacy Notice applies to the processing of personal information by Foris DAX SA (PTY) LTD and Foris GFS SA (PTY) LTD and their group of undertakings (“Crypto.com”, “we”, “us”, “our”) in connection with:

use of any of our products, services or applications (together the “Services”),

visit or use of our websites (“Site”) or mobile application (“App”).

Please note that our Services, Site and App are not intended for minors below the age of 18 years, and we do not knowingly collect information relating to minors.

For services provided by other Crypto.com companies, please carefully read the respective privacy notice or policy available on the Site, in the App or through the links below.

2. Purpose

This Privacy Notice aims to give you information on why and how we collect and process your personal information.

This Privacy Notice informs you about your privacy rights and how the information protection principles set out in the POPIA and / or the respective applicable regulations protect you.

It is important that you read this Privacy Notice together with any other notice or policy we may provide on specific occasions when we are collecting or processing personal information about you so that you are fully aware of why and how we are using your information. This Privacy Notice supplements other notices and policies and is not intended to override them.

By submitting any personal information to us, you provide consent to the processing of your personal information as set out in this Privacy Notice. Please do not submit any personal information to us if you do not agree to any of the provisions of this Privacy Notice. If you do not consent to the provisions of this Privacy Notice, or parts of the Privacy Notice, we may not be able to provide our products and services to you.

3. Who we are

Responsible Parties

The Responsible Party for the processing of your personal information is the legal entity that determines the “means” and the “purposes” of any processing activities that it carries out.

For your convenience, you may find in the table below the respective details relevant to you when it comes to the exact entity which is the Responsible Party of your personal Information.

Crypto.com product or service

Responsible Party

Address

Fiat accounts, Crypto.com Prepaid Card, direct payment methods and related digital asset services

Foris GFS SA (Pty) Ltd

Unit 17 Katherine and West, 114 West Street, Sandown Sandton, Gauteng, 2196

South Africa

Digital asset wallet, crypto asset services, direct payment methods and related digital asset services

Foris DAX SA (Pty) Ltd

Unit 17 Katherine and West, 114 West Street, Sandown Sandton, Gauteng, 2196

South Africa

Information Officer

If you have any questions, concerns or complaints related to this Privacy Notice or our privacy practices, or if you want to exercise your legal rights, please contact us at [email protected].

Our duties and your duties in case of changes

We keep our Privacy Notice under regular review and reserve the right to amend this Privacy Notice from time to time. This version was last updated on the date above written. Please check from time to time for new versions of the Privacy Notice. We will also additionally inform you on material changes of this Privacy Notice in a manner which will effectively bring the changes to your attention.

It is important that the personal information we hold about you is accurate and up to date. Please keep us informed if your personal information changes during your relationship with us. The current version of this Privacy Notice will govern the respective rights and obligations between you and us each time that you access and use our Site or App.

Third-party links

The Site and any applicable web browser, the App or application programming interface required to access the Services (“Applications”), may include links to third-party websites, plug-ins and applications (“Third-Party Sites”). Clicking on those links or enabling those connections may allow third parties to collect or share information about you. We do not control these Third-Party Sites and we are not responsible for their privacy statements and policies. When you leave our Site or Applications, we encourage you to read the privacy notice or policy of every Third-Party Site you visit or use. This Privacy Notice does not extend to Third-Party Sites.

4. What information we collect about you

Personal information

Personal information means any information relating to an identifiable, living, natural person and where applicable, an identifiable, existing juristic person. This is a broad definition which includes the specific pieces of personal information which we have described below.

A “data subject” is the individual to whom the personal information relates. This is usually by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal information. It does not include:

· information that has been made anonymous so that it does not identify a specific person;

· permanently de-identified information that does not relate or cannot be traced back to you specifically;

· non-personal statistical information collected and compiled by us.

Depending on whether and how you use our Services, Site or App, we will collect, use, store and transfer different kinds of personal information about you which we have grouped in categories as follows:

Category of personal information


Examples of specific pieces of personal information

Identity Data

first name,

maiden name,

last name,

username or similar identifier,

title,

date of birth and gender,

biometric information, (including a visual image of your face and video recordings of you)

national identity cards,

passports, driving licenses or other forms of identification documents.





Social Identity Data

your group/company data,

information on referrals related to you,

political background,

close connections,

behavioral data,

risk assessment,

compliance assessment.

Contact Data

residence details,

billing address,

delivery address,

home address,

work address,

email address and telephone numbers,

proof of address documentation.

Financial Data

bank account,

payment card details,

virtual currency accounts,

stored value accounts,

amounts associated with accounts,

external account details,

source of funds and related documentation.


Transactional Data

details about payments to and from you,

other details of any transactions you enter into using the Services, Site or App.

Investment Data

information about your:

- investment objectives,

- investment experience,

- prior investments.

Technical Data

internet connectivity data,

internet protocol (IP) address,

operator and carrier data,

login data,

browser type and version,

device type, category and model,

time zone setting and location data,

language data,

application version and SDK version,

browser plug-in types and versions,

operating system and platform,

diagnostics data such as crash logs and any other data we collect for the purposes of measuring technical diagnostics, and

other information stored on or available regarding the devices you allow us access to when you visit the Site, or use the Services or the App.

Profile Data

your username and password,

your identification number as our user,

information on whether you have Crypto.com App account and the email associated with your accounts,

requests by you for products or services,

your interests, preferences and feedback,

other information generated by you when you communicate with us, for example when you address a request to our customer support.

Usage Data

information about how you use the Site, the Services, mobile applications and other offerings made available by us, including:

- device download time,

- install time,

- interaction type and time,

- event time, name and source.

Marketing and Communications Data

your preferences in receiving marketing from us or third parties,

your communication preferences,

your survey responses.

As explained above under Identity Data, we will also collect a visual image of your face and video recording of you which we will use, in conjunction with our sub-contractors (see section Disclosures of Your Information below), to check your identity for onboarding purposes or verify your identity as a security measure in a standard procedure before processing some of your requests. This information falls within the scope of special personal information.


Special personal information

Special personal information relates to certain types of sensitive personal information which are subject to additional protection under the legislation applicable to you. Depending on the products and services that you require, we may also collect special personal information for example your:

· demographic information – such as your race or ethnicity;

  • criminal information – such as information about your commission or alleged commission of any offence or about any related legal proceedings; and

· biometrics - such as digital photographs of you.

Generally, we will only collect special personal information if its collection is reasonably necessary for, or directly related to, one or more of our services or the collection is required or authorised by law.

We will consider the nature and sensitivity of personal information to ensure that appropriate legal justifications and security safeguards are applied to special categories of personal information.

If you refuse to provide personal information

Where we need to collect personal information by law, or under the terms of a contract we have with you, and you refuse to provide that information when requested, we may not be able to perform the contract we have or are trying to enter into with you for example, to provide you Services. In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.

5. How we collect your personal information

We use different methods to collect information from and about you, including through:

Direct interactions. You may voluntary choose to give us your Identity Data, Social Identity Data, Contact Data, Financial Data, Profile Data and Marketing and Communications Data by directly interacting with us, including by filling in forms, providing a visual image of yourself via the Service, by email or otherwise. This includes personal information you provide when you:

visit our Site or App;

apply for our Services;

create an account;

make use of any of our Services;

request marketing to be sent to you, for example by subscribing to our newsletters;

enter a competition, promotion or survey, including through social media channels;

give us feedback or contact us.

Indirectly / Automated technologies or interactions. As you interact with us via our Site or App, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We will also collect Transactional Data, Investment Data and Usage Data. We may also receive Technical Data and Marketing and Communications Data about you if you visit other websites employing our cookies. You may find more information about how we use cookies through the Cookie Preferences.

Third-party sources. We also obtain information about you, including Social Identity Data, from third-party sources if doing so does not violate your legitimate interest. Such collection could be conducted only under specific circumstances enlisted in the POPIA and / or the respective applicable regulations.

6. How we use your information

Lawful use

We will only process personal information where an appropriate legal justification for such processing exists. POPIA and / or the respective applicable regulations provides the following lawful basis for processing personal information, namely:

conclusion or performance of a contract: means all the processing that is required to enable us to sign you up for one or more of our products or services (e.g. verify your identity, verify the accuracy of your information against third party databases and public records from time to time, etc.) and to perform in terms of the obligations of contracts concluded with you for provision of our products or service and managing our business relationship for the duration of the contract and as required after its termination;

legitimate interests: means processing personal information in order to protect your legitimate interest and where it is necessary for pursuing the legitimate interest of the responsible party or a third party to whom the information is supplied. We process personal information based on this justification only where we believe that such processing is beneficial to you and is limited to such processing that is necessary to achieve the purpose. Where our own or a third party’s legitimate interest is used as the justification, we always consider the nature of the legitimate interest and whether there is a risk of harm or an unreasonable infringement of your right to privacy.

compliance with a legal obligation: means processing your personal information where we need to comply with a legal obligation we are subject to;

consent: means any voluntary, specific, and informed expression of will in terms of which permission is given for the processing of personal information relating to you.

Purposes for which we use your personal information

We have set out below, in a table format, a description of all the ways we plan to use your personal information, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.


Note that we may process your personal information for more than one lawful ground depending on the specific purpose for which we are using your information. Please
contact us if you need details about the specific legal ground, we are relying on to process your personal information where more than one ground has been set out in the table below.

Purpose and/or activity


Categories of personal information

Lawful basis for processing

To register you as a new customer

Identity Data

Social Identity Data

Contact Data

Financial Data

Conclusion or Performance of a contract

To carry out and comply with anti-money laundering requirements

Identity Data

Social Identity Data

Contact Data

Financial Data

Compliance with a legal obligation

To process and deliver our Services and any App features to you, including to execute, manage and process any instructions or orders you make

Identity Data

Contact Data

Financial Data

Transactional Data

Technical Data

Marketing and Communications Data

Performance of a contract

To prevent abuse of our Services and promotions

Identity Data

Contact Data

Financial Data

Transactional Data

Technical Data

Marketing and Communications Data

Legitimate interests

To manage our relationship with you which will include asking you to leave a review, take a survey or keeping you informed of our company's business and product development

Identity Data

Contact Data

Profile Data

Transactional Data

Marketing and Communications Data

Performance of a contract

Consent, if required

To keep our records

updated and to study

how customers use our

products/services

Identity Data

Contact Data

Profile Data

Transactional Data

Marketing and Communications Data

Legitimate interests

Consent, if required

To manage, process, collect and transfer payments, fees and charges, and to collect and recover payments owed to us

Identity Data

Contact Data

Financial Data

Performance of a contract

To ensure good management of our payments, fees and charges and collection and recovery of payments owned to us

Identity Data

Contact Data

Financial Data

Legitimate interests

To manage risk and crime prevention including performing anti-money laundering, counter terrorism, sanction screening, fraud and other background checks, detect, investigate, report and prevent financial crime in broad sense, obey laws and regulations which apply to us and respond to complaints and resolving them

Identity Data

Social Identity Data

Contact Data

Financial Data

Technical Data

Transactional Data

Investment Data

Special Personal Information that you give us directly or that we receive from third parties’ sources:

- data which might be revealed by KYC or other background checks (for example, because it has been reported in the press or is available in public registers);

- data that is incidentally revealed by photographic ID although we do not intentionally process this personal information

Compliance with a legal obligation

We may also process such data in connection with these purposes if it is necessary for the conclusion or performance of our contract with you

In addition to our legal obligations, we may process this personal information based on our legitimate interest in ensuring that we are not involved in dealing with the proceeds of criminal activities and do not assist in any other unlawful or fraudulent activities, as well as to develop and improve our internal systems for dealing with financial crime and to ensure effective dealing with complaints

For Special Personal Information, it is necessary for reasons of compliance with the respective applicable anti-money laundering and counter terrorist financing regulations.

To enable you to partake in a prize draw, competition or complete a survey

Identity Data

Contact Data

Profile Data

Usage Data

Marketing and Communications Data

Performance of a contract

Consent, if required

To gather market data for studying customers' behavior including their preference, interest and how they use our products/services, determining our marketing campaigns and growing our business

Identity Data

Contact Data

Profile Data

Usage Data

Marketing and Communications Data

Legitimate interests: understanding our customers and improving our products and services

To administer and protect our business, our Site, App(s) and social media channels including bans, troubleshooting, data analysis, testing, system maintenance, support, reporting, hosting of data

Identity Data

Contact Data

Financial Data

Technical Data

Transactional Data

Investment Data

Legitimate interests: to run our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

Identity Data

Contact Data

Profile Data

Usage Data

Technical Data

Marketing and Communications Data

Legitimate interests: to study how customers use our products/services, to develop them, to grow our business and to form our marketing strategy

Consent, if required

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

Technical Data

Usage Data

Legitimate interests: to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to form our marketing strategy

Consent, if required

To make suggestions and recommendations to you about goods or services that may be of interest to you

Identity Data

Contact Data

Technical Data

Usage Data

Profile Data

Investment Data

Marketing and Communications Data

Legitimate interests: to develop our products/services and grow our business

Consent, if required

To use the services of social media platforms or advertising platforms some of which will use the personal information they receive for their own purposes, including marketing purposes

Technical Data

Usage Data

Consent

To use the services of financial institutions, crime and fraud prevention companies, risk measuring companies, which will use the personal information they receive for their own purposes in their capacity of independent responsible parties

Identity Data

Social Identity Data

Contact Data

Financial Data

Transactional Data

Investment Data

Technical Data

Usage Data

Legitimate interests: to conduct our business activities on the market of financial services, to participate actively in the prevention of crime and fraud

To record voice calls for compliance, quality assurance and training purposes

Identity Data

Social Identity Data

Contact Data

Financial Data

Transactional Data

Legitimate interests: to comply with the industry standards and requirements in payments services, to ensure quality of our service, including by proper training of our personnel

Marketing

We may use your Identity Data, Contact Data, Technical Data, Transactional Data, Investment Data, Usage Data and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).

To the extent that we act in a capacity as a Direct Marketer, we shall strive to observe, and comply with our obligations under POPIA when implementing principles and practices in relation to Direct Marketing. You will receive marketing communications from us if you have requested information from us and consented to receive marketing communications, or if you have purchased from us and you have not opted out of receiving such communications. We will use your Marketing and Communications Data for our respective activities.

We will ensure that a reasonable opportunity is given to you to object to the use of your Personal Information for our marketing purposes when collecting the Personal Information and on the occasion of each communication to you for purposes of Direct Marketing.

Third-party marketing

We will get your opt-in consent before we share your personal information with any third party for marketing purposes.

Opting out

We will not use your Personal Information to send you marketing materials if you have requested not to receive them. You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you.

Further, you can let us know directly that you prefer not to receive any marketing messages by emailing [email protected].

Where you opt out of receiving marketing messages, this will not apply to service messages which are directly related to the use of our Services (e.g. maintenance, change in the terms and conditions and so forth).

Cookies

We make use of cookies, which are small text files sent by a web server to store on a web browser. They are used to ensure websites function properly, store user preferences when needed and collect anonymous statistics on website usage. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Services or Site may become inaccessible or not function properly. For more information about the cookies we use, please review the Cookie Preferences.

Change of purpose

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Sale or transfer of business

We may also need to process your information in connection with or during the negotiation of any merger, financing, acquisition, bankruptcy, dissolution, transaction or proceeding involving all or a part of our shares, business, or assets. This will be based on our legitimate interests in carrying out such transaction, or to meet our legal obligations.

7. Disclosures of your information

We share your personal information with our third-party service providers, agents, subcontractors and other associated organizations, our group of undertakings (as described below) in order to complete tasks and provide the Services and use of the App to you on our behalf.

When using third party service providers, they are required to respect the security of your personal information and to treat it in accordance with the applicable law.


We pass your personal information to the following entities:

companies and organizations that assist us in processing, verifying or refunding transactions/orders you make and in providing any of the Services that you have requested;

identity verification agencies to undertake required verification checks;

fraud or crime prevention agencies to help fight against crimes including fraud, money-laundering and terrorist financing;

anyone to whom we lawfully transfer or may transfer our rights and duties under the relevant terms and conditions governing the use of any of the Services;

any third party because of any restructure, sale or acquisition of our group or any affiliates, provided that any recipient uses your information for the same purposes as it was originally supplied to us and/or used by us; and

regulatory and law enforcement authorities, whether they are outside or inside of the South Africa, where the law allows or requires us to do so.

8. International transfers

We share your personal information within our group of undertakings. This will involve cross-border transfers of your personal information.

Many of our external third parties are based outside South Africa so their processing of your personal information will involve a cross-border transfer. These transfers are necessary for the performance of the contract between us.

Whenever we transfer your personal information out of the country, we ensure that the third party who is the recipient of the information is subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection that:

· effectively upholds principles for reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information provided by the POPIA and / or the respective applicable regulations; and

· includes provisions, that are substantially similar to the relevant regulation in the POPIA and / or the respective applicable regulations, relating to the further transfer of personal information from the recipient to third parties who are in a foreign country.

Please contact us if you want further information on the specific grounds used by us when transferring your personal information.

9. Information security

While there is an inherent risk in any information being shared over the internet, we have put in place appropriate, reasonable technical and organisational measures to prevent your personal information from being accidentally lost, used, damaged, unauthorisedly destroyed, or accessed in an unauthorised or unlawful way, altered, or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a legitimate business need to know. They will only process your personal information on our instructions, and they are subject to a duty of confidentiality.

Depending on the nature of the risks presented by the proposed processing of your personal information, we will have in place the following appropriate security measures:

organisational measures (including but not limited to staff training and policy development);

technical measures (including but not limited to physical protection of information, pseudonymization and encryption); and

securing ongoing availability, integrity, and accessibility (including but not limited to ensuring appropriate back-ups of personal information is held).

We have put in place procedures to deal with any suspected personal information breach and security compromises and will notify you and the Information Regulator where we are legally required to do so.

If you want to know more about our security practice, please visit this link.

10. Information retention

We will keep your personal information in a safe and controlled environment for the entire period that we store it.

We will keep your personal information for the necessary period according to the legal basis that justifies the retention of the information.

When applicable, and even after the closure of your account, cancellation of your card or other Services, we may store your personal information for an additional period for audit purposes, compliance with legal, regulatory, tax, accounting or other obligations and for exercise of rights.

Here are some exemplary factors which we usually consider when determining how long we need to retain your personal information:

· in the event of a complaint;

· if we reasonably believe there is a prospect of litigation in respect to our relationship with you or if we consider that we need to keep information to defend possible future legal claims (e.g. email addresses and content, chats, letters) will be kept until expiration of the respective statutory limitation periods;

· to comply with any applicable legal and/or regulatory requirements with respect to certain types of personal information:

o Under the anti-money laundering legislation, we may be obliged to retain your personal information for a period of up to 5 years after the end of the relationship between us as a company and you as a customer;

o Information needed for audit purposes and so forth; or

· in accordance with relevant industry standards or guidelines;

· in accordance with our legitimate business need to prevent abuse of the promotions that we launch. We will retain a customer’s personal information for the time of the promotion and for a certain period after its end to prevent the appearance of abusive behavior.

Please note that under certain condition(s), you can ask us to delete your information: see your legal rights below for further information. We will honor your deletion request only if the condition(s) is met.

11. Your legal rights

We want to ensure that you are aware of your rights in relation to the personal information that we process about you. If you need more detailed information or wish to exercise any of the rights set out below, please contact us.

· Right to access - You have a right to get access to the personal information that we hold about you. We may, if allowed by law, charge a fee for this.

· Right to rectify/correct/ update - You have a right to correct inaccurate personal information and to update incomplete personal information.

· Right to be notified – You have the right to be notified that your personal information is being collected by us or has been accessed or acquired by an unauthorised person.

· Right to object - You have a right to object to us processing your personal information where we have relied on one of the lawful grounds above for legitimate interest or where we perform a public law duty (and to request us to restrict processing). Please note that if you request us to restrict processing your personal information, we may have to stop or suspend the operation of your account or the products and services we provide to you. Please note that where the law permits us to process your personal information, we will have a legal obligation to do so.