Version: 2
Effective Date: 1 March 2026
Review Cycle: Annual
Phishield UMA (Pty) Ltd describes how it processes personal data while providing insurance services on behalf of Bryte Insurance Company Limited. This statement governs all personal information collected directly or from third parties and complies with South African legislation including POPIA, PAIA, and insurance regulations.
We process personal information in a lawful, reasonable and transparent manner. We reserve the right to amend this statement to reflect regulatory changes, with material modifications communicated via email or other appropriate channels.
Phishield operates as an authorised financial services provider (FSP 46418) under a binder agreement with Bryte Insurance Company Limited (licensed insurer, FSP 17703). Under this arrangement:
Phishield may function as a data operator, processor, or joint responsible party depending on the specific processing activity.
Information Officer: Lilian Mooney
Email: lilian@phishield.com
Phone: +27 (0) 10 312 5257
Phishield has appointed and registered an Information Officer per POPIA requirements.
Personal information is processed based on:
Consent may be withdrawn subject to legal or contractual constraints. Automated decision-making and profiling in underwriting, risk assessment, and fraud detection comply with Section 71 of POPIA, with appropriate safeguards including human intervention rights where applicable.
We process information relating to:
A comprehensive rights list appears in the PAIA Manual available on phishield.com.
Categories of personal information collected include:
Third-party personal information may be collected only with proper authorisation and awareness.
Information is gathered directly from individuals, through intermediaries or brokers, from insurers, regulatory bodies, fraud prevention agencies, credit bureaux, and other lawful third-party sources.
Data may be used for:
Special personal information is processed only where Section 27 of POPIA lawful grounds apply, including consent, contract necessity, or legal obligation compliance.
Existing clients may receive product-related communications, or those who have provided explicit marketing consent. Communications use email, SMS, or telephone channels. Consent is captured during onboarding and may be withdrawn by contacting enquiries@phishield.com or using unsubscribe links in communications.
All electronic marketing communications comply with applicable legal prohibitions.
Personal data may be shared with:
All recipients must implement appropriate confidentiality and security measures.
We maintain reasonable technical and organisational safeguards to protect personal information against loss, unauthorised access, unlawful processing, and accidental disclosure. We acknowledge that no system is entirely secure. Phishield disclaims liability for unauthorised access losses beyond reasonable control where safeguards are in place, to the extent legally permissible.
Data retention follows applicable legal requirements and collection purpose fulfillment. Relevant legislation includes:
FAIS legislation requires minimum five-year retention of advice, intermediary service, and transaction records. The PAIA Manual specifies retention periods for various record categories. Subsequently, information undergoes secure destruction or de-identification.
Data subjects may:
Formal objections use FORM 1 (Objection to Processing Personal Information), available on the Information Regulator's website. The response period is 30 days.
Access requests follow the PAIA Manual procedures available at phishield.com. Requests concerning records held on Bryte's behalf may require direct submission to Bryte per its PAIA Manual.
Complaints regarding unlawful processing should be directed to complaints@phishield.com. Unsatisfied parties may escalate to:
Information Regulator (South Africa)
Phone: 010 023 5200
Email: POPIAComplaints@inforegulator.org.za
Bryte Insurance privacy resources are available at brytesa.com/legal.