Phishield Privacy Statement

Version: 2

Effective Date: 1 March 2026

Review Cycle: Annual

Phishield UMA (Pty) Ltd describes how it processes personal data while providing insurance services on behalf of Bryte Insurance Company Limited. This statement governs all personal information collected directly or from third parties and complies with South African legislation including POPIA, PAIA, and insurance regulations.

We process personal information in a lawful, reasonable and transparent manner. We reserve the right to amend this statement to reflect regulatory changes, with material modifications communicated via email or other appropriate channels.

1. Our Relationship to the Insurer

Phishield operates as an authorised financial services provider (FSP 46418) under a binder agreement with Bryte Insurance Company Limited (licensed insurer, FSP 17703). Under this arrangement:

  • Bryte retains primary responsibility as the licensed insurer
  • Phishield operates within delegated authority
  • Certain records are maintained on Bryte's behalf
  • Processing follows Bryte's instructions and applicable law

Phishield may function as a data operator, processor, or joint responsible party depending on the specific processing activity.

2. Contact Information

Information Officer: Lilian Mooney
Email: lilian@phishield.com
Phone: +27 (0) 10 312 5257

Phishield has appointed and registered an Information Officer per POPIA requirements.

3. Lawful Basis for Processing

Personal information is processed based on:

  • Data subject consent
  • Conclusion or performance of insurance contracts
  • Legal or regulatory compliance obligations
  • Legitimate interests protection (fraud prevention, risk management)
  • Establishment, exercise, or defence of legal claims

Consent may be withdrawn subject to legal or contractual constraints. Automated decision-making and profiling in underwriting, risk assessment, and fraud detection comply with Section 71 of POPIA, with appropriate safeguards including human intervention rights where applicable.

4. Data Subject Categories

We process information relating to:

  • Policyholders and insured persons
  • Intermediaries
  • Employees
  • Service providers

A comprehensive rights list appears in the PAIA Manual available on phishield.com.

5. Information We Collect

Categories of personal information collected include:

  • Identification details (name, address, contact information, identity/passport numbers, birth details)
  • Employment and financial data
  • Banking information
  • Tax identification numbers
  • Credit bureau information
  • Claims history and underwriting details
  • Correspondence records
  • Contract and transaction information
  • Biometric data (images, voice recordings, fingerprints)
  • Fraud detection and financial crime prevention information

Third-party personal information may be collected only with proper authorisation and awareness.

6. How We Collect Information

Information is gathered directly from individuals, through intermediaries or brokers, from insurers, regulatory bodies, fraud prevention agencies, credit bureaux, and other lawful third-party sources.

7. How We Use Your Information

Data may be used for:

  • Underwriting and risk assessment
  • Policy issuance, administration, and management
  • Claims processing and assessment
  • Fraud, money laundering, and financial crime detection and investigation
  • Risk modelling and portfolio management
  • Legal and regulatory compliance
  • Auditing and record-keeping
  • Identity and beneficial ownership verification
  • Complaint management and dispute resolution
  • Communication monitoring for quality assurance and legal purposes
  • Product and service improvement
  • Cross-border data transfers with appropriate safeguards

Special personal information is processed only where Section 27 of POPIA lawful grounds apply, including consent, contract necessity, or legal obligation compliance.

8. Direct Marketing

Existing clients may receive product-related communications, or those who have provided explicit marketing consent. Communications use email, SMS, or telephone channels. Consent is captured during onboarding and may be withdrawn by contacting enquiries@phishield.com or using unsubscribe links in communications.

All electronic marketing communications comply with applicable legal prohibitions.

9. Information Disclosure

Personal data may be shared with:

  • Bryte Insurance Company Limited
  • Reinsurers
  • Intermediaries and representatives
  • Service providers and subcontractors
  • Fraud prevention agencies
  • Regulatory and supervisory authorities
  • Law enforcement agencies
  • Professional advisers
  • Parties required by law

All recipients must implement appropriate confidentiality and security measures.

10. Data Security

We maintain reasonable technical and organisational safeguards to protect personal information against loss, unauthorised access, unlawful processing, and accidental disclosure. We acknowledge that no system is entirely secure. Phishield disclaims liability for unauthorised access losses beyond reasonable control where safeguards are in place, to the extent legally permissible.

11. Record Retention

Data retention follows applicable legal requirements and collection purpose fulfillment. Relevant legislation includes:

  • Insurance Act 18 of 2017
  • Financial Advisory and Intermediary Services Act 37 of 2002
  • Protection of Personal Information Act 4 of 2013
  • Promotion of Access to Information Act 2 of 2000
  • Financial Intelligence Centre Act 38 of 2001
  • Companies Act 71 of 2008
  • Financial Sector Regulation Act 9 of 2017

FAIS legislation requires minimum five-year retention of advice, intermediary service, and transaction records. The PAIA Manual specifies retention periods for various record categories. Subsequently, information undergoes secure destruction or de-identification.

12. Your Rights Under POPIA

Data subjects may:

  • Confirm personal information existence
  • Access personal information held about them
  • Request correction of inaccurate or incomplete data
  • Request deletion or processing restriction where legally permissible
  • Object to processing with reasonable grounds
  • Withdraw consent-based processing consent
  • Lodge complaints with the Information Regulator
  • Submit requests to the Information Officer

Formal objections use FORM 1 (Objection to Processing Personal Information), available on the Information Regulator's website. The response period is 30 days.

13. PAIA Access Requests

Access requests follow the PAIA Manual procedures available at phishield.com. Requests concerning records held on Bryte's behalf may require direct submission to Bryte per its PAIA Manual.

14. Complaints

Complaints regarding unlawful processing should be directed to complaints@phishield.com. Unsatisfied parties may escalate to:

Information Regulator (South Africa)
Phone: 010 023 5200
Email: POPIAComplaints@inforegulator.org.za

Bryte Insurance privacy resources are available at brytesa.com/legal.