> For the complete documentation index, see [llms.txt](https://docs.spendl.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.spendl.money/spendl-compliance-pack/spendl-privacy-policy.md).

# Spendl   Privacy Policy

1\. Document Control

| **Version**        | 1.2                                                     |
| ------------------ | ------------------------------------------------------- |
| **Effective Date** | 1 July 2026                                             |
| **Approved By**    | Board of Directors                                      |
| **Owner**          | Chief Compliance Officer                                |
| **Next Review**    | July 2027 or sooner on regulatory or operational change |

### 2. Introduction and Acceptance

Light Fusion (Pty) Ltd (Registration No. 2023/154151/07), t/a Spendl Technologies (SPENDL), is an Exempt Crypto Asset Financial Services Provider (FSP 53757, Category I) and an Accountable Institution registered with the Financial Intelligence Centre (Org ID 74993). SPENDL is a Responsible Party under POPIA.

This Privacy Policy explains how we collect, use, store, share, and protect your Personal Information when you access our Website, or use our Services (as defined in the Terms and Conditions). The Terms and Conditions provides that SPENDL processes Personal Information in accordance with POPIA and, where applicable to End Users in the European Economic Area or the United Kingdom, the EU GDPR and UK GDPR.

By creating a SPENDL Account, using the SPENDL Card, accessing the B2B Platform, or otherwise using our Services, you agree to this Privacy Policy. If you do not agree, you may not use our Services.

### 3. Personal Information We Collect

* Identification data: Full name, date of birth, ID or passport details, nationality, proof of residential or registered address.
* Contact data: Email address, mobile number, postal/physical address.
* Financial data: Bank account details, Card funding/payment records, transaction history, source of funds and source of wealth.
* Biometric data: Facial recognition, video/selfie, or similar identifiers used for identity verification and liveness checks.
* Blockchain data: Wallet addresses, on-chain transaction hashes, network identifiers, and gas/fee data associated with funding or transacting on the Platform.
* KYC/AML data: Sanctions screening results, PEP/PIP status, beneficial ownership information, regulatory licences, tax-residency self-certification (CRS/FATCA where applicable).
* Employment and demographic data: Employment status, product type, residency status.
* Device and technical data: IP address, browser/device identifiers, cookies, location data.
* Correspondence data: Records of communications with our support team, complaints, and dispute documentation.
* Third-party data: Information obtained from regulators, screening databases, the Programme Partner, banking partners, liquidity partners, or other trusted sources.

SPENDL does not knowingly collect or process Personal Information of children under the age of 18 (as contemplated in section 35 of POPIA and our Terms and Conditions). If SPENDL becomes aware that it has inadvertently collected such information, it will delete it without undue delay.

### 4. Lawful Bases for Processing

SPENDL processes Personal Information on the following lawful bases under section 11 of POPIA:

* Consent: Where you have given consent (e.g., marketing communications per the Terms and Conditions).
* Contract: Where processing is necessary for the performance of the contract between you and SPENDL.
* Legal obligation: Where processing is required by law, including the FIC Act, FAIS Act, SARS reporting, and Exchange Control.
* Legitimate interest: Where processing is necessary for SPENDL's legitimate interests (security, fraud prevention, service improvement), provided those interests are not overridden by your rights.

### 5. Purpose of Processing

* To onboard Customers, perform KYC, CDD, and EDD, and comply with FIC Act and FSCA obligations.
* To provide, operate and improve the Services (Card, B2B Platform, ITT, Treasury, Off-Ramp, Cross-Border).
* To facilitate Card funding, crypto-to-ZAR conversion, settlements, and disbursements.
* To detect and prevent fraud, unauthorised transactions, and financial crime.
* To meet regulatory and legal obligations including FAIS, FIC Act, POPIA, SARS, Exchange Control, and Travel Rule.
* To communicate with you regarding your Account, transactions, and security updates.
* To send marketing or promotional material (only with your consent, with opt-out per Terms and Conditions.
* To comply with Network Rules, Programme Partner operating rules, and card scheme requirements.
* To produce aggregated, anonymised insights to maintain and improve the Services in accordance with the Terms and Conditions.

### 6. Sharing of Information

We may share Personal Information with the following categories of recipients as disclosed in the Terms and Conditions):

* Programme Partner: For Card issuance, processing, and pooled-account operation.
* Card scheme/Network: For Card transaction processing under Network Rules.
* Banking partners: For ZAR settlement and fiat banking services.
* Liquidity partners: For crypto-to-ZAR conversion execution.
* KYC/AML vendors: For identity verification, sanctions screening, and adverse-media checks.
* Cloud and IT service providers: For hosting, security, and operational infrastructure.
* Regulators and authorities: FSCA, FIC, SARS, Information Regulator, law enforcement, as required by law.
* Professional advisors: Legal, audit, and compliance.
* Group companies or affiliates assisting in operations.

We will never sell your Personal Information.

### 7. B2B Data Processing

Where SPENDL processes Personal Information of a B2B Customer's End Users on the Customer's behalf, the B2B Customer is the Responsible Party and SPENDL is the Operator. The Data Processing Addendum at Schedule G of the Terms and Conditions applies and is incorporated by the Terms and Conditions. The DPA covers processing instructions, sub-processers, cross-border transfers, breach notification, and audit rights.

### 8. Security of Information

We use reasonable and appropriate technical and organisational measures to protect Personal Information, aligned with Joint Standard 1 of 2023 (IT Governance and Risk Management) and Joint Standard 2 of 2024 (Cybersecurity and Cyber Resilience), as referenced in the Terms and Conditions. Measures include access control (least privilege), encryption in transit and at rest, network segmentation, logging and monitoring, secure SDLC, vendor due diligence, and staff training.

### 9. Retention of Information

We retain Personal Information only for as long as necessary to fulfil the purposes set out in this Privacy Policy, comply with applicable laws and regulations (including the FIC Act minimum 5-year retention and FAIS record-keeping requirements), and resolve disputes or enforce agreements. After the retention period, records are securely destroyed or anonymised.

### 10. Cross-Border Transfers

Where Personal Information is transferred outside South Africa (for example, to cloud service providers, liquidity partners, or KYC vendors), SPENDL relies on a lawful basis under section 72 of POPIA, including adequacy or binding contractual commitments equivalent to POPIA standards. Where GDPR applies to End Users, SPENDL relies on a lawful transfer mechanism under Chapter V of the GDPR (Schedule G of the Terms and Conditions).

### 11. Cookies and Tracking

We use cookies and similar technologies for functionality, analytics, and fraud prevention as described in the Terms and Conditions and detailed in our standalone Cookie Policy published on the Website.

### 12. Marketing Communications

SPENDL will only send direct marketing communications where lawfully permitted under POPIA (section 69) and the Consumer Protection Act. You may opt out at any time via the unsubscribe mechanism or by emailing <compliance@spendl.money>. Service messages (transactional, security, regulatory) are not marketing and cannot be opted out of while you remain a Customer.

### 13. Your Rights

In terms of POPIA (and equivalent rights under GDPR where applicable), you have the right to:

* Be informed when your information is collected.
* Request access to your Personal Information.
* Correct or update your Personal Information.
* Object to the processing of your Personal Information for direct marketing.
* Request deletion of Personal Information where legally permissible (subject to FIC Act and FAIS retention requirements).
* Request restriction of processing in certain circumstances.
* Lodge a complaint with the Information Regulator of South Africa.

Requests should be sent to the Information Officer at <compliance@spendl.money>. We will respond within 30 days, subject to verification of your identity.

To ensure these rights are actioned consistently, SPENDL logs every request on its internal Data Subject Request Register and reports each request to the Information Regulator on receipt. Before any information is released, we verify that the request comes from the relevant Customer by requiring confirmation of their account details, and we disclose only Personal Information that pertains specifically to that Customer. All requests are actioned within 30 days of receipt.

### 14. Breach Notification

SPENDL will notify the Information Regulator and affected data subjects as soon as reasonably possible after confirmation of a Personal Information breach that poses a real risk of harm, in accordance with section 22 of POPIA. Material cyber incidents will also be reported to the FSCA in line with Joint Standard 2 of 2024.

### 15. Changes to this Policy

We may update this Privacy Policy from time to time. Material Changes will be communicated in accordance with the Terms and Conditions (at least 30 days' notice for Material Changes). The latest version will always be available on our Website. Continued use of our Services after changes are published constitutes acceptance.

### 16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact:

* Information Officer: <compliance@spendl.money>
* Website: [www.spendl.money](http://www.spendl.money)
* Registered Office: Central Square, Pinelands, Cape Town

### 17. Version Control

<table data-header-hidden><thead><tr><th width="71.3125"></th><th></th><th width="207.08203125"></th><th width="230.5546875"></th><th></th></tr></thead><tbody><tr><td><strong>Version</strong></td><td><strong>Effective Date</strong></td><td><strong>Summary of Changes</strong></td><td><strong>Reason for Changes</strong></td><td><strong>Approved By</strong></td></tr><tr><td>1.1</td><td>1 September 2025</td><td>Founding version - initial Privacy Policy issued</td><td>Initial Privacy Policy compliance requirement upon platform launch</td><td>Board of Directors</td></tr><tr><td>1.2</td><td>1 July 2026</td><td>Full revision aligning with the updated Terms and Conditions Added new sections for Lawful Bases, B2B Data Processing, Marketing Communications and Breach Notification. Expanded sharing, security, retention and cross-border provisions to reflect the current Terms and Conditions and FSCA Joint Standards. Updated to reference SPENDL's Data Subject Request Register and the request-handling procedure.</td><td>Alignment with the revised Terms and Conditions. Compliance with POPIA, the FIC Act, and FSCA Joint Standards 1 of 2023 and 2 of 2024. Introduced a tracking mechanism to ensure the 30-day response commitment is consistently met and evidenced to the FSCA.</td><td>Board of Directors</td></tr></tbody></table>
