Privacy Policy
Updated 15 September 2026
- EFFECTIVE DATE
- 10 September 2026
What personal information 80eight collects, why, and the rights POPIA gives you over it.
A pointer to what this document covers, not a summary of it. The document below is what applies.
Website Privacy Policy
80 Eight SA (Pty) Ltd
Key Facts
- Who we are
- 80 Eight SA (Pty) Ltd ("80 Eight", "we"), an authorised Financial Services Provider (FSP 49010)
- What we collect
- Identity, contact, KYC/AML, biometric verification data, financial/transactional, device/usage, support communications, marketing preferences.
- Why we collect it
- To provide and secure our services, comply with AML/CTF, sanctions and Travel Rule obligations, support customers, improve and market our services.
- Lawful bases
- Contract; legal obligation; legitimate interests; consent (where required).
- Retention
- For as long as needed and to meet legal obligations (typically at least 5 years for AML/CTF records).
- Sharing
- Onboarding, custody, payment, and treasury partners (see Section 5), regulators and authorities when required.
- Transfers
- Processing may occur outside South Africa with POPIA section 72 safeguards.
- Your rights
- Access, correction, deletion, restriction/objection, and complaint to the Information Regulator.
- Contact
- Information Officer: Faadil Moti, faadil@80eight.io, 97 Central Street, Houghton, Johannesburg, 2198
1. Scope and Relationship to Our Terms
This Policy explains how 80 Eight SA (Pty) Ltd collects, uses, shares, stores, and protects personal information when you use our website, app, or services. It should be read together with our Terms of Use and, where applicable, our Risk Disclosure Statement.
2. What We Collect
2.1. Categories of Personal Information
| Category | Examples | Source |
|---|---|---|
| Identity and Contact | Full name, ID/passport, date of birth, address, email, phone | You |
| Biometric Verification | Selfie or video liveness check, or other evidence of identity collected during onboarding | You, via our verification partners |
| KYC/AML | Proof of address, sanctions/PEP screening results, risk flags | You; screening providers |
| Financial and Transactions | Bank details, card details (held only in encrypted, short-lived form; we retain the card brand, first six and last four digits, and expiry date), deposits/withdrawals, on/off ramp records, trade and custody history | You; banks; payment and custody partners |
| Institutional (juristic entities) | Company registration documents, shareholder and beneficial ownership information, authorised representative details | You |
| Device and Usage | Device identifiers, IP address, logs, app/web interactions | Your device; analytics |
| Support and Communications | Messages, call recordings (where lawful), complaints | You |
| Marketing Preferences | Opt ins, unsubscribes, interests | You |
2.2. Special Personal Information
We do not intentionally collect special personal information unless required by law, for example identity verification through biometric liveness checks as part of KYC. Where this occurs, we apply additional safeguards and only process it for the purpose of verifying your identity. Where you choose to use your device's fingerprint or face recognition to sign in or approve actions, that check happens on your device; 80 Eight receives only a cryptographic key and signature, never your fingerprint or face data.
2.3. From Your Browser (Usage Information)
We automatically receive and record internet usage information from your browser, such as your IP address, browsing habits, click patterns, software version, system type, screen resolution, colour capabilities, plug ins, language settings, cookie preferences, search engine keywords, JavaScript enablement, the content and pages you access on the website, dates and times of visits, paths taken, and time spent on pages.
2.4. Web Beacons
Our website may contain electronic image requests (single pixel gifs or web beacons) that allow us to count page views and access cookies. We do not use web beacons to collect personal information; they are used to compile anonymous information about our website.
2.5. Recording Calls
We may monitor and record telephone calls for quality, security and compliance where permitted by law; you may object where applicable.
3. How and Why We Use Personal Information
3.1. Primary Purposes
3.1.1. Financial services purposes, such as providing the trading, custody, wallet, ZAR8, payment and other products you have chosen;
3.1.2. Marketing purposes, such as pursuing lawful related marketing activities;
3.1.3. Business purposes, such as internal audit, accounting, business planning, or other proposed and actual transactions;
3.1.4. Legal purposes, such as handling claims, complying with regulations, or pursuing good governance; and
3.1.5. Analytics purposes, such as creating derived data from your personal information to understand how you use our services, including through aggregation, de-identification, and anonymisation.
3.2. Usage Information
We collect your information for the following usage purposes: remembering your information so you do not have to re-enter it on your next visit; monitoring website usage metrics; and tracking your entries and status in any promotions connected with your use of the website. Where you first found us through our website, we also record how you arrived (landing page, referring site, campaign parameters and advertising click identifiers) against your account so that we can measure our marketing.
3.3. Travel Rule Processing
Where you send or receive a qualifying crypto asset transfer through our services, we collect and share originator and beneficiary information (such as your name and account or wallet reference) with the receiving or sending virtual asset service provider, in order to comply with the Travel Rule under FIC Directive 9. This information is retained for regulatory review in the same way as other AML records described in Section 11 below.
4. Our Obligations
4.1. General
4.1.1. 80 Eight may use your personal information to fulfil our obligations to you.
4.1.2. 80 Eight may send administrative messages and updates about the website and services. We will not send you marketing by email or SMS unless you have opted in. Push notifications from the app are service notices about your account and the platform; you can switch them off in your device settings.
4.1.3. While logged in, 80 Eight may show you content or notices relevant to your account status. We do not share personal information with advertisers unless you specifically consent.
4.2. Security Measures
4.2.1. The security of our filing systems is managed to ensure personal information is adequately protected, with controls to minimise the risk of loss, unauthorised access, disclosure, interference, modification, or destruction.
4.2.2. Security measures are applied in a context sensitive manner; more sensitive information requires greater protection.
4.2.3. 80 Eight continuously reviews its security controls, including regular testing against cyber attacks on our IT networks.
4.2.4. All paper and electronic records comprising personal information are securely stored and accessible only to authorised individuals.
4.2.5. Employees sign employment contracts including terms on the use, storage, and confidentiality of information.
4.2.6. Operators and third party service providers enter into agreements committing to POPIA standards and obligations and the lawful processing of personal information.
5. Disclosure
5.1. Sharing
We may share your personal information with:
5.1.1. identity verification and screening providers appointed to conduct KYC/KYB checks and sanctions and PEP screening during onboarding and ongoing due diligence;
5.1.2. custody, payment, and treasury infrastructure providers who support the products and services you use;
5.1.3. regulatory case management and reporting providers, used to meet our suspicious transaction reporting obligations to the Financial Intelligence Centre;
5.1.4. other operators and service providers who support our business operations and workflow management, under agreements requiring them to use your information only for the purposes described in this Policy;
5.1.5. regulators, law enforcement, or other authorities, as required by law or governmental audit; and
5.1.6. any party to a subpoena, court order, or other lawful request.
5.2. No Selling
We do not sell personal information. We disclose personal information only as provided in this Policy.
5.3. Marketing Purposes
We may disclose aggregate statistics about our customer population, in general terms, to advertisers or business partners.
5.4. Employees
We may disclose personal information to employees who require it to perform their roles, including management, human resources, accounting, audit, compliance, and information technology.
5.5. Change of Ownership
If 80 Eight undergoes a change in ownership, merger, acquisition, or sale of assets, we may assign our rights in personal information to the successor entity. We will disclose any such transfer on our website. You may request deletion of your information, subject to legal retention requirements, if you are concerned about a transfer of ownership.
6. Security Incidents and Data Breach Notification
6.1. We maintain internal processes for identifying, escalating, and responding to suspected or actual security incidents involving personal information.
6.2. Where a security compromise has occurred and there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator as soon as reasonably possible, in accordance with POPIA.
6.3. Where the compromise poses a risk to you, we will also notify you as soon as reasonably possible, explaining the nature of the incident, the personal information affected, and the steps we have taken or recommend you take in response.
7. Rights of the Data Subject
7.1. Right to Access Personal Information
7.1.1. You have the right to establish whether we hold personal information related to you and to request access to it. Please email compliance@80eight.io for assistance with the Personal Information Request Form.
7.2. Right to Correction or Deletion
You have the right to request that your personal information be corrected or deleted where we are no longer authorised to retain it, subject to lawful retention requirements.
7.3. Right to Object to Processing
You may, on reasonable grounds, object to the processing of your personal information. We will consider your request in line with POPIA, using Form 1 (Objection to the Responsible Party).
7.4. Right to Object to Direct Marketing
You may object to the processing of your personal information for direct marketing purposes by means of unsolicited electronic communications. We request consent before processing for electronic direct marketing, using Form 4 (Consent to Direct Marketing).
7.5. Right to Complain to 80 Eight
POPIA related complaints can be submitted to the Information Officer at compliance@80eight.io. We will acknowledge within two working days and provide an outcome or update within seven working days of acknowledgement, with reasons for decisions and notice of any timeline deviations.
7.6. Right to Complain to the Information Regulator
You may submit a complaint to the Information Regulator regarding an alleged infringement of your rights under POPIA, and may institute civil proceedings. Forms are available from www.inforegulator.org.za.
7.7. Right to Be Informed
You have the right to be notified that your personal information is being collected. Our privacy notice describes how information is collected and for which purpose.
8. Disciplinary Action
8.1. Where a POPIA complaint or infringement investigation has been finalised, 80 Eight may take appropriate administrative, legal, and/or disciplinary action against any employee reasonably suspected of being implicated in non compliant activity.
8.2. In cases of ignorance or minor negligence, we will provide awareness training.
8.3. Gross negligence or wilful mismanagement of personal information is serious misconduct that may result in summary dismissal where evidence supports such action.
8.4. Examples of immediate actions include recommending disciplinary action, referral to law enforcement for criminal investigation, and recovery of funds and assets to limit prejudice or damages.
9. Lawful Basis for Processing
Depending on the context, we process personal information on one or more lawful bases: to perform a contract with you or take steps at your request; to comply with legal obligations, including AML/CTF, sanctions screening, and Travel Rule obligations; our legitimate interests in operating, securing, and improving the services; and your consent where required, such as certain direct marketing.
10. Cross-Border Transfers (POPIA Section 72)
We may store or process personal information outside South Africa using vetted operators subject to contractual safeguards. Transfers take place in terms of POPIA section 72, including on the basis of adequate protection, binding agreements imposing POPIA comparable safeguards, or your consent.
11. Retention
We keep personal information only for as long as necessary for the purposes described, or to comply with legal, tax, anti money laundering, and accounting obligations, which may require retention for at least 5 years after the end of the relationship, after which it is securely deleted or de-identified.
12. Cookies and Similar Technologies
We use cookies, SDKs, pixels, and similar technologies to operate the website/app, remember your preferences, enhance security, perform analytics, and measure marketing effectiveness. You can manage cookies in your browser or device settings; some features may not function properly without certain cookies. Further detail is set out in our Cookie Policy.
13. Children
Our services are not directed at persons under 18. We do not knowingly collect personal information from children without appropriate consent. If you believe a child has provided personal information, please contact us so we can delete it.
14. Automated Processing
Identity verification and fraud checks use automated tools provided by our verification partners, and the outcome, including a decline, may be applied automatically. If your verification is declined you may resubmit your documents or ask us to review the decision by contacting our compliance department, and we will consider any representations you make before a final decision is taken.
15. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified on our website/app with the effective date. Continued use of the services after the effective date constitutes acceptance.
16. Contact Us and the Information Regulator
Information Officer: Faadil Moti
Email: faadil@80eight.io (or compliance@80eight.io)
Address: 97 Central Street, Houghton, Johannesburg,2198
Information Regulator (South Africa): see www.inforegulator.org.za for current contact details.
17. Definitions
17.1. "POPIA" means the Protection of Personal Information Act 4 of 2013 and regulations.
17.2. "Personal information" has the meaning in POPIA and includes information about an identifiable, living natural person and, where applicable, an identifiable existing juristic person.
17.3. "Processing/Process" means any operation or activity concerning personal information, including collection, receipt, recording, organisation, collation, storage, updating, retrieval, use, distribution, erasure, or destruction.
17.4. "Responsible Party" means 80 Eight SA (Pty) Ltd, who determines the purpose and means of processing personal information.
17.5. "Operator" means a person who processes personal information on behalf of the Responsible Party in terms of a contract or mandate.
17.6. "Information Officer" means the person appointed by 80 Eight with responsibilities under POPIA, and includes any Deputy Information Officer.
17.7. "Website" means 80 Eight's public websites and web applications.
17.8. "Services" means the products and services provided by 80 Eight, including crypto asset buying, selling, conversion and custody, ZAR8 issuance and redemption and ZAR8 Yield, fiat deposits and withdrawals by bank transfer and card, payments (88Pay, pay links, point-of-sale, cross-border and mobile-money payments), business treasury and OTC desk services, recurring purchases (Autostack), investment products where offered, and related services.