Legal
POPIA Compliance
How FinVeil complies with the Protection of Personal Information Act.
Last updated: 14 September 2026
The eight POPIA conditions
FinVeil's platform and operating practices are designed around the eight conditions for lawful processing of personal information under POPIA:
- Accountability — FinVeil (Pty) Ltd (2026/540392/07) is the responsible party for its own customer and website data; for employee data an employer uploads, the employer is the responsible party and FinVeil acts as operator
- Processing limitation — data is collected only for the purposes described in the Privacy Policy
- Purpose specification — purposes are documented in the Privacy Policy
- Further processing limitation — data is not reused for unrelated purposes
- Information quality — employer customers are responsible for data accuracy; we provide correction tooling
- Openness — the Privacy Policy and this page describe our processing
- Security safeguards — AES-256-GCM field-level encryption for designated personal data, audit logging of key actions, application-layer tenant isolation
- Data subject participation — right of access, correction, deletion, and objection
Information Officer
Information Officer designated per POPIA Section 55. Registration with the Information Regulator in progress. Contact: privacy@finveil.money. Data subject requests are processed within 30 days.
Cross-border processing
FinVeil's production application and PostgreSQL database are hosted by Railway in its US West region (United States), so personal information processed by FinVeil is stored in the United States. See section 6 of the Privacy Policy.
Proof receipts
Proof receipts are batched into 32-byte Merkle root hashes that FinVeil stores in its own database. Nothing is published to a public ledger. A daily automated check confirms that stored anchor material contains only 64-character hash digests.