Legal
Privacy Policy
Appture (Pty) Ltd trading as Appture Pay / iKWAZA
Fintech Service Provider and Third Party Payment Provider sponsored by Nedbank Limited
1. Introduction
Appture (Pty) Ltd respects your privacy and is committed to protecting personal information in a lawful, transparent and secure manner.
This Privacy Policy explains how Appture collects, uses, stores, shares, protects and retains personal information when users access or use our websites, applications, fintech service platform, merchant onboarding services, transaction-facilitation services, payout-support services, customer support services, compliance processes and related systems.
Appture operates as a South African fintech service provider and Third Party Payment Provider (TPPP) sponsored by Nedbank Limited. Appture provides a technology and service layer that facilitates payment-related services between merchants, consumers, banking partners, payment processors, payout processors and other approved service providers.
Appture is not a bank, card acquirer, payment gateway, payment processor or deposit-taking institution. Appture does not itself issue cards, acquire card transactions, operate a bank account for users as a bank, or hold itself out as a bank. Banking, acquiring, card processing, EFT processing, settlement and payout functions are performed through approved banking and payment-processing partners.
This Privacy Policy must be read together with our Terms and Conditions, merchant agreements, service notices, PAIA Manual, cookie notice and any other privacy notice that applies to a specific service. If there is a conflict between this Privacy Policy and the Terms and Conditions on a personal-information issue, this Privacy Policy and applicable privacy law will apply to that issue.
2. Definitions
In this Privacy Policy, unless the context indicates otherwise:
"Appture", "Appture Pay", "iKWAZA", "we", "us" or "our" means Appture (Pty) Ltd, registration number 2015/348528/07, trading as Appture Pay and/or iKWAZA where applicable.
"Consumer" or "Payer" means a person who makes a payment to a merchant or receiving party through or in connection with the Appture platform.
"Merchant", "Sub-merchant", "Receiving Party" or "Registered User" means a business, person or entity that registers with Appture to receive payment-related services or payout-support services.
"Personal information", "special personal information", "child", "operator", "responsible party" and "processing" have the meanings given to them in the Protection of Personal Information Act, 4 of 2013 (POPIA).
"Platform" means Appture's websites, applications, dashboards, systems, integrations, merchant tools, support channels and related technology used to provide our fintech services.
"TPPP" means Third Party Payment Provider in the South African National Payment System context.
3. Who this policy applies to
This Privacy Policy applies to personal information relating to:
- merchants and sub-merchants;
- company representatives;
- directors, members, shareholders and beneficial owners;
- authorised users and administrators;
- consumers and payers;
- receiving parties;
- website and app visitors;
- support contacts;
- fraud reporters;
- service providers and business partners;
- and any other person whose personal information we process in connection with our services.
4. What personal information we collect
The personal information we collect depends on your relationship with us and the services used. We may collect the categories below.
4.1 Merchant, company and business information
Registered company name, trading name, registration number, VAT number, tax number, registered address, trading address, postal address, website URL, business description, industry type, products and services offered, merchant category information, logo or profile image, business contact details, support contact details and bank account details used for settlement or payout purposes.
4.2 Directors, representatives and beneficial owners
Full names, identity numbers, passport numbers, date of birth, nationality, country of residence, contact details, residential or business address, proof of authority, board resolutions, signing mandates, ownership percentage, control structure, beneficial ownership details, source-of-funds information, source-of-wealth information where required, and supporting FICA/KYC documents.
4.3 Consumer and payer information
When a consumer makes a payment in connection with our services, we may process limited payment-related information, including payer name or identifier where provided, email address or cellphone number where required, transaction reference, transaction amount, transaction date and time, payment method, transaction status, dispute information, chargeback information and refund-related information.
Appture does not store full card numbers, CVV numbers or full card-authentication credentials. Card and EFT processing is performed by approved third-party payment-processing partners. We may receive limited card reference information, such as partial card details or payment tokens, where needed for transaction confirmation, support, reconciliation, dispute handling or fraud prevention.
4.4 Transaction, account and payout information
Transaction amounts, transaction dates and times, payment references, merchant identifiers, account entries, balances shown on the platform, payout requests, settlement references, payout bank account details, transaction status, transaction history, chargebacks, disputes, refunds, support records, risk flags and monitoring notes.
Appture does not pay interest to merchants, consumers, users or clients. Where user-related funds are held or facilitated through the Appture structure, they are handled through approved banking and processing arrangements and are not interest-bearing to users or clients.
4.5 FICA, KYC, CDD, EDD, AML/CTF and fraud-prevention information
Due diligence questionnaires, onboarding documents, company registration documents, identity documents, proof of address, bank confirmations, beneficial ownership forms, risk ratings, sanctions-screening results, politically exposed person screening results, adverse-risk information, merchant website review records, high-risk industry screening results, fraud alerts, incident logs, suspicious-activity indicators, investigation notes and information received from banks, processors, fraud-prevention providers, regulators or lawful authorities.
4.6 Technical, device and platform information
IP address, browser type, device type, operating system, access times, login history, session logs, security logs, device identifiers, online identifiers, cookies, analytics information, API logs, error logs and other technical information needed to provide, secure, monitor and improve the platform.
4.7 Support, complaints and communications
Your name, contact details, support queries, complaints, fraud reports, correspondence, call notes, email records, attachments, screenshots, documents and any other information you provide when communicating with us.
4.8 Special personal information and children's information
We do not intentionally collect special personal information or children's personal information unless it is necessary, lawful and relevant to a specific purpose, such as identity verification, fraud prevention, legal compliance, regulatory reporting, dispute handling or where a competent person has provided the required consent for a child.
Where biometric information is ever used for verification, it will only be processed where lawful, necessary and subject to appropriate safeguards and consent or other lawful authority where required.
5. How we collect personal information
We may collect personal information directly from you when you register, onboard, transact, request payouts, contact support, submit documents, report fraud or use our platform.
We may also collect information from merchants, consumers, company representatives, directors, shareholders, members, beneficial owners, banks, payment processors, payout processors, identity-verification providers, FICA/KYC providers, fraud-prevention providers, sanctions-screening providers, regulatory bodies, law-enforcement authorities, public registers, merchant websites and public online sources.
6. Why we process personal information
We process personal information to provide and manage our fintech service platform and related services, including:
- merchant onboarding and activation;
- account creation and account administration;
- user authentication and access control;
- transaction facilitation;
- payout-support services;
- reconciliation;
- customer support;
- complaints handling;
- chargeback, dispute and refund support;
- fraud prevention;
- risk management;
- KYC, CDD and EDD;
- AML/CTF and sanctions compliance;
- transaction monitoring;
- merchant website reviews;
- high-risk industry screening;
- audit and recordkeeping;
- legal, regulatory and banking-partner compliance;
- reporting to lawful authorities where required;
- platform security;
- service improvement;
- and direct marketing only where permitted by law.
7. Lawful bases for processing
We do not rely on a single blanket consent for all processing. Depending on the purpose, we process personal information on one or more of the following lawful bases under POPIA: consent; performance of a contract; compliance with a legal obligation; protection of a legitimate interest of the data subject; performance of a public-law duty by a public body where applicable; or pursuing the legitimate interests of Appture or a third party where lawful.
For example, merchant onboarding, transaction facilitation and payout support are generally processed to perform a contract or take steps at your request. FICA, AML/CTF, sanctions, fraud-prevention and regulatory recordkeeping are generally processed because of legal, regulatory, banking-partner, payment-system or legitimate-interest requirements. Marketing is processed only where consent or an existing-customer soft opt-in applies.
Where we rely on consent, you may withdraw that consent. Withdrawal of consent will not affect processing that occurred lawfully before withdrawal and will not prevent us from processing information where we are required or permitted to do so by law.
8. FICA, KYC, CDD, EDD and financial-crime compliance
Because Appture operates in a regulated payment environment as a fintech service provider and TPPP, we may be required by law, payment-system rules, banking-partner requirements, processor requirements and our internal compliance policies to process information for customer due diligence, enhanced due diligence, anti-money-laundering, counter-terrorist-financing, sanctions screening, fraud prevention and transaction monitoring.
This may include verifying identity and authority; verifying company registration and ownership; identifying directors, members, shareholders and beneficial owners; understanding the nature and purpose of the business relationship; reviewing business activities, websites, products and services; determining source of funds and source of wealth where required; screening against sanctions, politically exposed person and adverse-risk information; assessing high-risk industries and prohibited activities; monitoring transaction patterns, values, volumes and statuses; requesting updated FICA or due diligence documents; and preserving records for audit, compliance and reporting purposes.
We may refuse onboarding, delay activation, suspend services, delay payouts, block transactions, request further information, terminate a relationship or report activity where required if we cannot complete required due diligence or if risk is unacceptable.
9. High-risk and prohibited industries
Appture may refuse, restrict, suspend or terminate services for merchants operating in industries that Appture, our sponsoring bank, payment processors, payout processors, card schemes, regulators or payment-system rules consider prohibited, restricted or high risk.
These may include, without limitation, adult entertainment, gambling, money-service businesses, cryptocurrency exchanges, cannabis, illegal products, brand-damaging products, certain pharmaceutical or tobacco merchants, pawn brokers, scrap metal merchants, high-risk cyber lockers, certain loan or collection businesses and other prohibited or restricted merchant categories.
We may process personal information and business information to determine whether a merchant falls into a prohibited, restricted or high-risk category.
10. Transaction monitoring, fraud prevention and account suspension
We monitor transaction information to detect fraud, suspicious activity, unusual patterns, chargeback risk, disputes, regulatory risk, high-risk merchant behaviour and abuse of the platform.
Monitoring may include manual review by Appture staff, automated or rule-based checks by our service providers, bank alerts, processor alerts, fraud reports, transaction-history review and other risk controls.
Where we detect or suspect fraud, abuse, unauthorised activity, money laundering, terrorist financing, sanctions risk or other unlawful conduct, we may suspend or deactivate an account; delay, block or refuse a transaction or payout; request further documents or explanations; conduct an investigation; share relevant information with banks, payment processors, payout processors, regulators, SARS, the Financial Intelligence Centre, law enforcement or other lawful authorities where required or permitted; preserve records; and terminate the relationship where required.
11. Sharing personal information
We may share personal information where necessary and lawful with:
- Nedbank Limited and other approved banking partners;
- payment processors;
- payout processors;
- identity-verification providers;
- FICA/KYC providers;
- fraud-prevention providers;
- sanctions, PEP and adverse-risk screening providers;
- card schemes and payment-system participants where required;
- merchants, consumers, payers or receiving parties where necessary to complete or investigate a transaction;
- courier or logistics providers where applicable;
- cloud hosting, IT, cybersecurity, email, SMS, support and system providers;
- auditors, accountants, attorneys, insurers and professional advisers;
- SARS, the Financial Intelligence Centre, SARB, PASA, law-enforcement authorities, courts, regulators and government authorities where required or permitted;
- and prospective buyers, funders or advisers in a merger, restructure, sale, acquisition or similar corporate transaction subject to confidentiality safeguards.
We do not sell personal information to third parties.
12. Operators and service providers
Where a third party processes personal information on our behalf, we require that party to process the information only for authorised purposes and to protect it with appropriate security and confidentiality measures.
Where an operator or service provider becomes aware of a security compromise involving personal information processed for Appture, it must notify us without undue delay so that we can assess, contain, mitigate and report the incident where required.
13. Cross-border transfers
We may transfer, store or access personal information outside South Africa where necessary for payment-related services, payout-support services, cloud hosting, technical support, fraud prevention, risk management, regulatory compliance, service delivery or business continuity.
This may include transfers or disclosures to approved banks, processors, service providers or support providers in South Africa, Lesotho, Eswatini, Namibia or other jurisdictions where our approved providers operate.
Where we transfer personal information outside South Africa, we will take reasonable steps to ensure that the transfer complies with POPIA. This may include using contracts, data-protection safeguards, service-provider due diligence, consent where appropriate, or transfers necessary for the performance of a contract or implementation of pre-contractual measures.
14. Information security
We use reasonable technical and organisational safeguards to protect personal information against loss, damage, unauthorised access, unlawful processing, unauthorised disclosure, alteration or destruction.
Our security measures may include encrypted communications; TLS/SSL security; secure server-to-server communication with processors; access controls; role-based access; password and authentication controls; firewall and intrusion-prevention controls; DDoS protection; logging and monitoring; malware and vulnerability controls; secure backups; incident-response procedures; supplier due diligence; payment-security controls; PCI DSS-aligned practices where applicable; and regular review of security policies and controls.
No electronic system is completely secure. However, we take reasonable steps to protect personal information and to respond to security incidents.
15. Security compromises and data breaches
If we have reasonable grounds to believe that personal information has been accessed, acquired, disclosed, altered, lost or destroyed by an unauthorised person, we will take steps to investigate and contain the incident, mitigate possible harm, notify our Information Officer or Deputy Information Officer, notify the Information Regulator where required, notify affected data subjects where required, notify banks, processors, regulators or law enforcement where required, and review and improve controls after the incident.
Where possible, notifications to affected persons will include what happened; the information involved, where known; steps we are taking; steps you can take to protect yourself; and contact details for further assistance.
Security compromise notifications will be handled in accordance with POPIA, the Information Regulator's processes and any applicable banking, payment-system, cybercrime or regulatory reporting obligations.
16. Direct marketing and service communications
We may send service communications that are necessary for your account or use of our services. These may include transaction notices, payout notices, support messages, security alerts, compliance requests, policy updates and operational notices. These are not marketing communications.
We will only send direct marketing communications where permitted by POPIA. This means we may send marketing where you have consented, or where you are an existing customer, we obtained your contact details in the context of providing our services, the marketing relates to our own similar products or services, and you were given a clear opportunity to opt out.
Every electronic marketing message will identify the sender and include a simple way to opt out. You may opt out of marketing at any time. Opting out of marketing will not stop important service, security, legal or transaction-related communications.
17. Cookies, analytics and tracking
Our websites and platforms may use cookies, pixels, log files and similar technologies.
We may use these technologies to keep the platform secure; remember login sessions and preferences; detect fraud and abuse; measure platform performance; understand how users interact with our platform; improve services; and support marketing only where legally allowed.
Essential cookies may be required for the platform to function. Optional analytics or marketing cookies will be handled in accordance with applicable law and our cookie notice.
18. Automated or rule-based processing
Appture may use manual review, system rules, processor tools, bank alerts, fraud indicators and risk criteria to support onboarding, transaction monitoring, account restriction, payout review, fraud prevention, sanctions screening and compliance decisions.
Where a decision materially affects your access to services, payouts or account status, you may contact us to request further information or human review, subject to legal, regulatory, fraud-prevention and confidentiality limitations.
19. Retention of personal information
We keep personal information only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required or allowed by law, regulation, payment-system rules, card-scheme rules, contractual obligations, fraud prevention, dispute handling, audit or legitimate business needs.
We may retain onboarding, KYC, CDD, EDD and FICA records for the legally required period; transaction and payout records for regulatory, accounting, audit, fraud and dispute purposes; support and complaint records for as long as needed to resolve issues and maintain audit trails; fraud, suspicious-activity and investigation records for as long as required for legal, regulatory and risk-management purposes; and marketing consent and opt-out records for as long as necessary to prove compliance.
Where information is no longer required, we will delete, destroy, de-identify or restrict it where reasonably possible. Cancelling your account does not automatically mean that all personal information will be deleted immediately. We may still retain information where required or permitted by law, payment-system rules, regulatory obligations, dispute handling, fraud prevention or legitimate business needs.
20. Your rights
Subject to applicable law, you may have the right to ask what personal information we hold about you; request access to your personal information; request correction or updating of inaccurate personal information; request deletion or destruction of personal information where legally allowed; object to processing in certain circumstances; withdraw consent where processing is based on consent; opt out of direct marketing; and complain to the Information Regulator.
These rights are not absolute. We may refuse or limit a request where we are legally required or permitted to retain or process information, including for FICA, AML/CTF, payment processing, fraud prevention, dispute handling, regulatory reporting, audit or legal claims.
21. How to submit a privacy or PAIA request
To submit a privacy request, POPIA request or PAIA request, please contact us using the details below.
Information Officer / Privacy Contact: Appture's duly appointed Information Officer or Deputy Information Officer
Email: info@appturepay.co.za
Fraud reports: fraud@appturepay.com
Website: www.appturepay.com / www.ikwaza.com
We may ask you to verify your identity before we process a request. We will only request information that is reasonably necessary to confirm your identity and protect personal information from unauthorised disclosure.
Requests for access to records may also be handled under our PAIA Manual where applicable. Prescribed PAIA fees may apply where allowed by law.
22. Complaints
If you are unhappy with how we process your personal information, please contact us first so that we can try to resolve the issue.
You may also complain to the Information Regulator of South Africa:
Website: www.inforegulator.org.za
Email: complaints.IR@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Toll free: 0800 017 160
23. Children and minors
Our merchant onboarding services are not intended for use by children or minors acting independently.
If a person under 18 uses our platform, this must be with the involvement and consent of a parent, legal guardian or authorised representative, where legally permitted.
We do not knowingly onboard minors as merchants unless legally permitted and all required consent, authority and verification requirements have been met.
24. Third-party websites and services
Our platforms may contain links to third-party websites or services. We are not responsible for the privacy practices, security or content of third-party websites.
Where you use a third-party service, payment processor, bank, merchant website, courier service or other external service, that third party may process your personal information under its own privacy policy.
25. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
Where changes are material, we will take reasonable steps to notify users, such as by website notice, app notice, email or account notification.
The updated policy will apply from the effective date stated in the policy. Continued use of our services after the effective date means the updated policy applies to your use of the services.
26. Contact details
Appture (Pty) Ltd
Trading as: Appture Pay / iKWAZA, where applicable
Registration number: 2015/348528/07
Email: info@appturepay.co.za
Fraud reports: fraud@appturepay.com
Website: www.appturepay.com / www.ikwaza.com
Sponsoring bank: Nedbank Limited
Information Officer / Privacy Contact: Appture's duly appointed Information Officer or Deputy Information Officer