This POPIA Customer Privacy Policy explains how Bank Zero will process your personal information.
Where we refer to “process”, it means how we collect, use, store, make available, destroy, update, disclose, or otherwise deal with your personal information. Generally, we will only process your personal information if this is required to deliver or offer a service, provide a product or carry out a transaction with you. We respect your privacy and will treat your personal information confidentially.
We may combine your personal information and use the combined personal information for any of the purposes stated in this Privacy Policy. In this document any reference to “we” or “us” or “our” includes any one or more of the following Bank Zero entities:
Important to note:
If you use our services, goods, products and service channels you agree that we may process your personal information as explained under this Privacy Policy. Sometimes you may provide us with specific consent to process your personal information. Read it carefully because it may limit your rights.
(If Bank Zero processes personal information for another party under a contract or a mandate, the other party’s privacy policy will apply to the processing. Bank Zero reserves the right to change this Privacy Policy from time to time if the law or its business practices requires it. The version of the Privacy Policy displayed on our website will apply to your interactions with us. To read the latest version of this Privacy Policy visit the following website: www.bankzero.co.za)
We need your permission to collect your location data.
What exactly do we collect
We record the GPS location of your phone.
Why do we need your location data
This is to protect you. Location data is fully focussed on helping to keep your bank accounts secure and to prevent fraud on your bank account.
What will we NOT do with your location data
When do we collect your location data
Important to note:
How do we tell you about it
We make it clear to you where your location data is used, by displaying it to you against your relevant transactions and activities. (For example your welcome letter, when you re-pair, any payments you make, etc.)
How do we store your location data
Your location data is stored to the exact same high security levels as your financial transactions (see section 1.3.12) and is retained as per section 1.3.13.
How do we ask your permission
We don’t collect your location data unless you explicitly give us permission during your registration process. As you can see, location data is critical to the security of your banking profile. The Bank Zero App unfortunately cannot operate without this, because security is core to how we operate as a digital bank. Should you want to withdraw the use of your location data, the App cannot function. We respect your decision, as we hope you respect our commitment to keeping your money safe. See section 1.3.11 for more information.
We need your permission to collect your biometrics.
What exactly do we collect
We record specific facial features and your voice.
Why do we need your biometrics
This is to protect you, and is fully focussed on helping to keep your bank accounts secure and to prevent fraud on your bank account. We compare previously collected biometrics to subsequently collected biometrics during any high-risk situation.
What will we NOT do with your biometrics
When do we collect your biometrics
How do we tell you about it
We make it clear to you whenever biometrics are about to be recorded, by requesting you to provide facial biometrics in a specific way, and providing voice biometrics by way of reading a given sentence.
How do we store your biometrics
Your biometrics are stored to the exact same high security levels as your financial transactions (see section 1.3.12) and is retained as per section 1.2.13.
How do we ask your permission
No biometrics are collected unless you explicitly allow access to your camera and microphone, and unless we warn you in each instance before we start recording (as per above). As you can see, your biometrics are critical to the security of your banking profile. The Bank Zero App unfortunately cannot operate without this, because security is core to how we operate as a digital bank. Should you want to withdraw the use of your biometrics, the App cannot function. We respect your decision, as we hope you respect our commitment to keeping your money safe. See section 1.3.11 for more information.
It is important to us that children are handled with utmost privacy and as per law. A child is defined as by a country’s legislation and who has not been recognised as an adult by the courts of that country.
When and how will we process their personal information?
We process their personal information only if the law allows, and only if an adult who can legally agree, has approved the child’s registration. This adult must be a parent or a legal guardian. This adult must first register with Bank Zero in their own capacity and must then use the ‘Add Child’ feature to add the child. Only then can the relevant child proceed with their registration and subsequent use of the App.
When can we also process their personal information?
We can also process a child’s personal information if any one or more of the following applies, and only if the law allows:
When do we collect your biometrics
Note that where the child is legally old enough to open a bank account without assistance from their parent or guardian, or sign a document as a witness without assistance from their parent or guardian, then they will be handled accordingly.
This section provides insight into some of the questions, as it relates to your data privacy, that you may have
Personal information refers to any information that identifies you or specifically relates to you. It might include, but is not limited to, the following information about you:
We will only process your personal information for lawful purposes relating to our business if the following applies:
Special (sensitive) personal information is personal information about the following:
We may process your special (sensitive) personal information in the following circumstances:
We only collect personal information from you directly.
If the law requires us to do so, we will ask for your consent before collecting personal information about you from third parties. The third parties from whom we may collect your personal information include, but are not limited to, the following:
We will process your personal information for the following reasons:
By being a customer of Bank Zero, you give permission that we may send you operational notices as they relate to account or card activity (or inactivity), system problems and/or other operational banking matters. This is crucial to your experience of the bank and cannot be opted out of.
We will use your personal information to market Bank Zero related products and services to you. We could do this in person, by post, telephone, or electronic channels such as SMS and email. If you are not our customer, or in any other instances where the law requires, we will only market to you by electronic communications with your consent. In all cases you can request us to stop sending marketing communications to you at any time.
An automated decision is made when your personal information is analysed to decide without human intervention in that decision-making process. We may use your personal information to make an automated decision as allowed by the law. An example of automated decision making is the approval or decline of an application. You have a right to query any such decisions made and we will provide reasons for the decisions as far as reasonably possible.
In general, we will only share your personal information if any one or more of the following apply:
Where required, Bank Zero may share your personal information with the following persons. These persons have an obligation to keep your personal information secure and confidential:
We will only transfer your personal information to third parties in another country in any one or more of the following circumstances:
This transfer will happen within the requirements and safeguards of the law. Where possible, the party processing your personal information in the other country will agree to apply the same level of protection as available by law in your country or if the other country’s laws provide better protection the other country’s laws would be agreed to and applied.
You must provide proof of identity when enforcing the rights below. You must inform us when your personal information changes. You have the right to request access to the personal information we have about you by contacting us. This includes requesting:
We will attend to requests for access to personal information within a reasonable time. You may be required to pay a reasonable fee to receive copies or descriptions of records, or information about third parties. We will inform you of the fee before attending to your request. Please note that the law may limit your right to access information.
You have the right to request us to correct or delete the personal information we have about you if it is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, obtained unlawfully or we are no longer authorised to keep it. You must inform us of your request in writing. We may request documents from you to verify the change in personal information.
A specific agreement that you have entered into with us may determine how you must change your personal information provided at the time when you entered into the specific agreement. Please adhere to these requirements. If the law requires us to keep the personal information, it will not be deleted upon your request. The deletion of certain personal information may lead to the termination of your business relationship with us. You may object on reasonable grounds to the processing of your personal information.
We will not be able to give effect to your objection if the processing of your personal information was and is permitted by law; you have provided consent to the processing and our processing done according to your consent or the processing is necessary to conclude or perform under a contract with you.
Where you have provided your consent for the processing of your personal information, you may withdraw your consent. If you withdraw your consent, we will explain the consequences to you. We may proceed to process your personal information even if you have withdrawn your consent if the law permits or requires it. It may take up to 15 business days for the change to reflect on our systems, during this time we may still process your personal information.
You have a right to file a complaint with us or any Regulator with jurisdiction about an alleged contravention of the protection of your personal information by us. We will address your complaint as far as possible.
We will take appropriate and reasonable technical and organisational steps to protect your personal information according to industry best practices. Our security measures (including physical, technological and procedural safeguards) will be appropriate and reasonable. This includes the following:
We will keep your personal information for as long as:
Take note: We may keep your personal information even if you no longer have a relationship with us if the law permits.
A cookie is a small piece of data sent from our websites or applications to your computer or device hard drive or Internet browser where it is saved. The cookie contains information to personalise your experience on our websites or applications and may improve your experience on the websites or applications. The cookie will also identify your device, like the computer or smart phone.
By using our websites or applications you agree that cookies may be forwarded from the relevant website or application to your computer or device. The cookie will enable us to know that you have visited the website or application before and will identify you. We may also use the cookie to prevent fraud.
If you provide the personal information of a related person to us, you warrant that the related person is aware that you are sharing their personal information with us and that the related person has consented thereto. We will process the personal information of related persons as stated in this Privacy Policy, thus references to “you” or “your” in this Privacy Policy will include related persons with the necessary amendments.