Issuer: Cofi Compliance (Pty) Ltd ("Cofi Compliance", "we", "us", "our")
Website: https://coficompliance.com/
Effective date: 24 August 2026
Version: 2.1
1. Purpose of this Privacy Notice
This Privacy Notice explains how Cofi Compliance collects, uses, stores, shares, protects, and destroys personal information when people visit our website, contact us by email or telephone, request services, apply for a role, or otherwise interact with us.
We process personal information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA"), the Promotion of Access to Information Act, 2 of 2000 ("PAIA"), and other applicable South African laws.
2. Responsible party and contact details
Cofi Compliance (Pty) Ltd is the responsible party for personal information for which it determines the purpose and means of processing.
Information Officer: The head of Cofi Compliance (Pty) Ltd, acting in that statutory capacity. Requests are handled through the contact channel below.
Deputy Information Officer: No separate deputy contact is published. Requests should be directed to the Information Officer channel.
Email: info@coficompliance.com
Telephone: +27 81 479 1292
Physical delivery or inspection: By prior appointment arranged through info@coficompliance.com. The applicable service address will be confirmed before delivery or inspection.
Company registration number: 2025/665787/07
3. Personal information we may collect
We may collect and process:
- Identity and contact information, including names, job titles, email addresses, telephone numbers, company names and FSP numbers.
- Client and prospective-client information, including licence categories, compliance questions, regulatory correspondence, representative/KI information, service requirements, website URLs, and business records voluntarily supplied to us.
- Website and technical information that may be generated by hosting and security infrastructure, including IP address, device information, browser type, requested pages, timestamps, and referral information.
- Cookie-preference information stored on the visitor's device, including whether optional YouTube preview images may load.
- Recruitment information, including CVs, qualifications, employment history, references, interview notes, and suitability information.
- Billing and administration information, including invoices, payment status, tax information, engagement letters, and supplier information.
- Communication records, including emails, consultation requests, meeting notes, support queries, complaints, and consent records.
4. Sources of personal information
We may collect personal information directly from you, from your employer or authorised representative, from public regulatory sources, from public company or FSP records, from email, telephone and meeting interactions, and from service providers that support our hosting, email, document storage, security, accounting, or business operations.
5. Purposes for processing
We process personal information to:
- Respond to enquiries and consultation requests.
- Provide compliance, licensing, fit and proper, COFI readiness, website review, regulatory monitoring, training, and related services.
- Prepare proposals, engagement letters, reports, evidence files, regulatory submissions, and implementation plans.
- Maintain client records, compliance calendars, training records, billing records, and internal quality controls.
- Manage recruitment and supplier relationships.
- Operate, secure, maintain, and improve the website and its content.
- Send regulatory updates, service communications, or marketing communications where permitted by law.
- Comply with legal, regulatory, tax, accounting, recordkeeping, and dispute-resolution obligations.
- Detect, prevent, and respond to fraud, unlawful activity, security incidents, or unauthorised access.
Website enquiry workflow
When you submit the website contact form, the enquiry is stored in a Cloudflare D1 lead register together with the submission time, source, privacy-notice version, consent wording, and email-delivery status. Zoho Mail then sends a receipt from info@coficompliance.com containing a unique enquiry reference. Cofi Compliance also receives an internal lead alert. This automation applies only to valid submissions through the website form; it is not a general autoresponder for messages sent directly to the mailbox.
6. Legal bases and lawful processing
Depending on the circumstances, we process personal information because:
- You have consented to the processing.
- Processing is necessary to perform or enter into a contract.
- Processing is necessary to comply with a legal obligation.
- Processing protects a legitimate interest of Cofi Compliance, a client, a data subject, or another person, where such interest is not overridden by the data subject's rights.
- Processing is necessary for the proper performance of a public law duty, where applicable.
7. Special personal information and children's information
We do not intentionally collect special personal information or children's personal information through the website unless it is necessary for a specific lawful purpose and appropriate safeguards apply. If such information is provided to us as part of a client matter or recruitment process, we will process it only where permitted by POPIA and applicable law.
8. Direct marketing and regulatory updates
We may send regulatory updates or service communications to existing clients or subscribers where permitted. You may opt out of marketing communications at any time through the consent management page, by using the unsubscribe option in an email, or by contacting us at info@coficompliance.com.
The regulatory-updates option on the website form is separate from the consent needed to answer an enquiry. A new subscriber remains pending until the single-use confirmation link sent by email is used. The request, confirmation, applicable notice version, wording, time, and source are retained in the consent register. An enquiry may still be submitted when the optional updates box is left unticked.
We will not sell your personal information to third-party advertisers.
9. Sharing personal information
We may share personal information with:
- Employees, consultants, contractors, and authorised representatives who need access to perform their duties.
- Website hosting, database, DNS, email-routing, mailbox, document-management, cybersecurity, accounting, and professional-service providers, including Cloudflare for the website and lead register and Zoho Mail for website acknowledgements and mailbox delivery.
- Regulators, public bodies, ombuds, courts, law enforcement, or other authorities where required or permitted by law.
- Clients, counterparties, or advisers where necessary to deliver services or protect legal rights.
Where a service provider acts as an operator under POPIA, we require appropriate confidentiality and security undertakings.
10. Cross-border transfers
Some technology providers may store or access information outside South Africa. Where personal information is transferred cross-border, we will take reasonable steps to comply with section 72 of POPIA and apply appropriate contractual, legal, or organisational safeguards.
The public website is delivered using Cloudflare infrastructure. Email, document-storage, security, and other contracted operators may process information in more than one country or region, depending on the service in use. Information about a material operator or transfer relevant to a data subject may be requested through info@coficompliance.com.
11. Security safeguards
We take reasonable and appropriate technical and organisational measures to protect personal information against loss, damage, unauthorised access, unlawful processing, disclosure, alteration, or destruction. Measures may include access controls, password controls, secure storage, role-based permissions, backups, confidentiality undertakings, security reviews, and incident-response procedures.
No website, email system, or electronic storage platform can be guaranteed to be completely secure. Users should avoid sending unnecessary sensitive information through website forms or unsecured email.
12. Retention and destruction
We retain personal information only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required or permitted by law, contract, regulatory expectation, dispute-resolution need, or legitimate business purpose. When information is no longer required, we will delete, destroy, de-identify, or restrict it in a manner that prevents unauthorised use or reconstruction, where reasonably practicable.
13. Data subject rights
Subject to applicable law, you may request to:
- Confirm whether we hold your personal information.
- Access your personal information.
- Correct or update inaccurate, irrelevant, excessive, outdated, incomplete, misleading, or unlawfully obtained information.
- Delete or destroy information that we are no longer authorised to retain.
- Object to certain processing.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with the Information Regulator.
Requests may be sent to info@coficompliance.com. We may require proportionate proof of identity before acting on a request. Official objection, correction and deletion forms are linked from our Data Subject Requests page.
14. PAIA and access requests
Requests for access to records under PAIA must be submitted using the prescribed process described in our PAIA Manual. POPIA access and correction requests may be handled through the same contact point to ensure consistent processing.
15. Complaints
Complaints may be sent to info@coficompliance.com. A person may also use the Information Regulator's POPIA complaint service or contact the Regulator at enquiries@inforegulator.org.za or 010 023 5200.
16. Third-party websites and videos
Our website links to third-party websites, regulatory sources, FSCA pages, YouTube videos, and other external content. Optional YouTube preview images are withheld unless a visitor allows third-party content. Following an external link is a separate interaction with that provider. We do not control third-party privacy practices.
17. Cookies and device storage
The website stores a necessary cookie-preference record on the visitor's device. It does not currently deploy advertising or website-analytics tags. Details and controls are provided in our Cookie Notice.
18. Changes to this Privacy Notice
We may update this Privacy Notice from time to time. The latest version will be published on our website with its effective date.