Privacy Policy
Learn how Zeroa handles and protects your personal information across our website, accounts and financial services.
Document Version 2.0
Effective Date 23 July 2026
Last Review Date 23 July 2026
FSCA licence FSP 36012
CASP status Approved
Information Officer Kevin Pillay
This Privacy Policy explains what personal information ChemBridge Capital (Pty) Ltd, trading as Zeroa, collects, why we collect it, how we use it, who we share it with, how long we retain it, how we protect it, and the rights available to you under the Protection of Personal Information Act (POPIA) and, where applicable, the EU GDPR and UK GDPR. It should be read together with our Terms and Conditions.
1. Introduction
ChemBridge Capital (Pty) Ltd, trading as Zeroa ("Zeroa", "ChemBridge Capital", "we", "our" or "us"), is a South African financial services provider authorised by the Financial Sector Conduct Authority ("FSCA") and approved as a Crypto Asset Service Provider ("CASP").
Zeroa provides cross-border payment, settlement and digital asset services to individuals, businesses and institutional clients through its website, digital wallet platform and associated products.
The protection of personal information is fundamental to our business and forms part of our broader governance, compliance and information security framework. We recognise that clients entrust us with sensitive information relating to their identity, financial affairs and transactional activity. We are committed to ensuring that such information is processed lawfully, responsibly, transparently and securely.
This Privacy Policy explains:
-
what personal information we collect;
-
why we collect it;
-
how we use it;
-
who we share it with;
-
how long we retain it;
-
how we protect it; and
-
the rights available to individuals whose personal information we process.
This Policy applies to information collected through:
-
www.zeroa.io;
-
the Zeroa Wallet;
-
onboarding portals;
-
customer support channels;
-
mobile applications;
-
business development interactions;
-
payment and settlement services; and
-
any other products or services offered by ChemBridge Capital.
Our processing of personal information is primarily governed by the Protection of Personal Information Act, 2013 ("POPIA").
Because Zeroa offers services to clients located outside South Africa, including clients within the European Economic Area ("EEA") and the United Kingdom ("UK"), certain processing activities may also be subject to the General Data Protection Regulation (EU) 2016/679 ("EU GDPR") and the UK General Data Protection Regulation ("UK GDPR"), to the extent those laws apply.
Nothing in this Privacy Policy limits any rights afforded to individuals under applicable data protection legislation.
Where different legal obligations apply depending on a customer's country of residence or location, this Privacy Policy should be interpreted accordingly.
2. Who We Are
ChemBridge Capital (Pty) Ltd, trading as Zeroa, is incorporated in the Republic of South Africa and is authorised by the Financial Sector Conduct Authority as a Financial Services Provider and approved Crypto Asset Service Provider.
For purposes of POPIA, ChemBridge Capital is the Responsible Party responsible for determining the purpose and means of processing personal information.
Where the EU GDPR or UK GDPR applies, ChemBridge Capital acts as the Data Controller in relation to the personal information processed through its products and services.
Our registered business details are:
ChemBridge Capital (Pty) Ltd
Trading Name: Zeroa
Financial Services Provider Licence Number: 36012
Crypto Asset Service Provider: Approved
Registered Office:
The Zenith
27th Floor
The Box
Cape Town CBD
South Africa
Information Officer
Kevin Pillay
Email:
kevin.pillay@chemtrade.io
Telephone:
+27 81 590 8213
The Information Officer is responsible for overseeing compliance with this Privacy Policy, POPIA and applicable international data protection legislation.
3. Scope of this Privacy Policy
This Privacy Policy applies to all personal information processed by ChemBridge Capital in connection with its business operations.
It applies to:
-
visitors to our website;
-
individuals who enquire about our products;
-
prospective customers;
-
individual customers;
-
business customers;
-
directors, shareholders and beneficial owners of business customers;
-
authorised representatives and signatories;
-
wallet users;
-
merchants;
-
payment beneficiaries;
-
suppliers and service providers;
-
applicants for employment; and
-
any other person whose personal information is processed by ChemBridge Capital.
This Policy applies regardless of whether information is collected:
-
electronically;
-
through our website;
-
through our wallet platform;
-
during onboarding;
-
by telephone;
-
through email;
-
through messaging platforms such as WhatsApp;
-
through application programming interfaces (APIs);
-
through third-party service providers;
-
through regulatory reporting processes; or
-
through any other lawful business interaction.
This Policy applies throughout the entire customer relationship, including pre-onboarding due diligence, onboarding, ongoing monitoring, transactional activity and post-termination record retention.
4. Definitions
For purposes of this Privacy Policy:
Biometric Information means measurable biological or behavioural characteristics used to verify an individual's identity, including facial recognition data generated during identity verification.
CASP means Crypto Asset Service Provider.
Customer Due Diligence (CDD) means the identification and verification procedures required under applicable anti-money laundering legislation.
Data Subject means the individual to whom personal information relates.
Financial Crime includes money laundering, terrorist financing, fraud, sanctions evasion, bribery, corruption and other unlawful financial activity.
Information Officer means the person appointed in terms of POPIA.
Operator has the meaning assigned under POPIA.
Personal Information has the meaning assigned under POPIA and, where applicable, the EU GDPR or UK GDPR.
Processing includes collecting, recording, organising, storing, updating, retrieving, consulting, using, disclosing, transferring, combining, restricting, deleting or destroying personal information.
Responsible Party has the meaning assigned under POPIA.
Travel Rule means the legal requirements applicable to Virtual Asset Service Providers requiring the exchange of originator and beneficiary information for qualifying virtual asset transfers.
Wallet means any hosted digital asset wallet or related service made available by Zeroa.
5. Information We Collect
The categories of personal information we collect depend upon the nature of our relationship with you, the products and services you use, and our legal and regulatory obligations.
5.1 Identity Information
We may collect:
-
full legal name;
-
previous names;
-
date of birth;
-
nationality;
-
citizenship;
-
gender;
-
identity number;
-
passport number;
-
driver's licence details;
-
tax identification numbers;
-
photographs; and
-
signatures.
5.2 Contact Information
Including:
-
email addresses;
-
telephone numbers;
-
residential address;
-
postal address;
-
business address;
-
communication preferences.
5.3 Corporate Information
For business clients we may collect:
-
company registration details;
-
constitutional documents;
-
shareholder information;
-
beneficial ownership information;
-
director information;
-
authorised signatories;
-
ownership structure;
-
licensing information;
-
tax registrations.
5.4 Verification Information
To comply with our regulatory obligations we may collect:
-
certified identity documents;
-
passports;
-
proof of residential address;
-
bank statements;
-
source of wealth information;
-
source of funds information;
-
tax residency declarations;
-
politically exposed person declarations;
-
sanctions declarations;
-
biometric verification results;
-
liveness verification results.
5.5 Financial Information
Including:
-
bank account details;
-
payment information;
-
wallet addresses;
-
virtual asset holdings where disclosed;
-
transaction history;
-
settlement instructions;
-
beneficiary details.
5.6 Technical Information
We automatically collect technical information including:
-
IP addresses;
-
browser type;
-
operating system;
-
device identifiers;
-
session identifiers;
-
login information;
-
cookies;
-
website usage information;
-
application logs;
-
security logs.
5.7 Transaction Information
As part of providing our services we collect information relating to:
-
payments;
-
settlements;
-
wallet activity;
-
blockchain transaction references;
-
receiving wallet addresses;
-
sending wallet addresses;
-
transaction values;
-
timestamps;
-
blockchain network information;
-
payment references;
-
merchant information;
-
beneficiary information.
5.8 Communications
We may retain:
-
emails;
-
WhatsApp communications;
-
support tickets;
-
live chat conversations;
-
telephone recordings (where lawful);
-
complaints;
-
onboarding communications;
-
compliance correspondence.
5.9 Information Received from Third Parties
We may receive personal information from:
-
identity verification providers;
-
blockchain analytics providers;
-
sanctions screening providers;
-
credit reference agencies where lawful;
-
banking partners;
-
payment service providers;
-
regulators;
-
law enforcement agencies;
-
publicly available corporate registers;
-
public sanctions databases;
-
politically exposed person databases.
We collect only the personal information reasonably necessary to fulfil our contractual, legal, regulatory and operational obligations and to provide our products and services efficiently and securely. We do not knowingly collect excessive or irrelevant personal information, and we regularly review our collection practices to ensure continued compliance with applicable data protection laws.
6. Verification Through Zeroa Wallets
Zeroa provides hosted digital wallet services to facilitate cross-border payments, digital asset settlement and related financial services. In order to comply with applicable legislation, regulatory requirements and our internal risk management framework, every wallet maintained by Zeroa is linked to a verified customer profile.
Wallets may only be created once the applicable customer identification and verification procedures have been successfully completed, unless otherwise permitted by law.
Throughout the customer relationship we maintain a risk-based approach to ongoing customer due diligence. This includes monitoring wallet activity to identify unusual, suspicious or prohibited transactions and to ensure continued compliance with our legal and regulatory obligations.
Information associated with a wallet may include:
-
wallet addresses;
-
wallet identifiers;
-
blockchain network information;
-
transaction hashes;
-
transaction timestamps;
-
transaction values;
-
originating and destination wallet addresses;
-
funding sources;
-
beneficiary information;
-
device information used to access the wallet;
-
authentication records; and
-
security event logs.
Where required by law or where necessary to protect the integrity of our services, we may request additional information regarding:
-
the purpose of a transaction;
-
the source of funds;
-
the source of wealth;
-
supporting commercial documentation;
-
invoices;
-
contracts;
-
proof of ownership of external wallets;
-
additional identity verification documentation; or
-
any other information reasonably required to satisfy our regulatory obligations.
Failure to provide requested information may result in delays, restrictions, suspension or termination of wallet functionality where permitted by law.
We may also implement transaction limits, enhanced due diligence or additional verification procedures based upon the customer's risk profile, transaction behaviour or applicable regulatory requirements.
Nothing in this section limits our obligations to report suspicious or unusual activity to competent authorities where required by applicable law.
7. Identity Verification, Biometric Verification and Customer Due Diligence
As a licensed Financial Services Provider and Crypto Asset Service Provider, ChemBridge Capital is required to identify and verify the identity of its customers and certain related persons before establishing a business relationship and throughout the duration of that relationship.
These obligations arise under, among other legislation:
-
the Financial Intelligence Centre Act, 38 of 2001 ("FICA");
-
applicable Anti-Money Laundering and Counter-Terrorist Financing ("AML/CFT") legislation;
-
FSCA licensing requirements;
-
applicable sanctions legislation;
-
exchange control requirements;
-
international AML/CFT standards issued by the Financial Action Task Force ("FATF"); and
-
other applicable legal or regulatory requirements.
-
To satisfy these obligations we may collect and verify:
-
identity documents;
-
passports;
-
driver's licences;
-
proof of residential address;
-
corporate registration documents;
-
trust documentation;
-
beneficial ownership information;
-
source of funds information;
-
source of wealth information;
-
tax residency information;
-
politically exposed person declarations;
-
sanctions-related information; and
-
any additional documentation reasonably required for enhanced due diligence.
Biometric Verification
As part of our identity verification process, we may require customers to complete biometric verification.
This may include:
-
facial image capture;
-
selfie verification;
-
liveness detection;
-
facial comparison against identity documents;
-
anti-spoofing technology;
-
document authenticity verification; and
-
fraud detection technologies.
Biometric information is processed solely for:
-
verifying identity;
-
preventing identity theft;
-
detecting fraud;
-
satisfying our regulatory obligations;
-
preventing impersonation;
-
protecting customer accounts; and
-
maintaining the integrity of our services.
We do not sell, licence or otherwise commercialise biometric information.
Access to biometric information is restricted to authorised personnel and authorised service providers who require such information to perform contracted services on our behalf.
Identity Verification Providers
We currently utilise specialist identity verification providers, including Sumsub, to perform identity verification, document authentication, biometric verification, sanctions screening, politically exposed person screening, adverse media screening, Travel Rule compliance and ongoing transaction monitoring.
These providers process personal information strictly in accordance with contractual agreements entered into with ChemBridge Capital and applicable data protection legislation.
Where these providers engage approved sub-processors or operators, appropriate contractual safeguards are implemented to protect personal information.
Customers are encouraged to review the privacy notices of these providers for additional information regarding their own processing activities.
Ongoing Customer Due Diligence
Customer due diligence is not limited to onboarding.
ChemBridge Capital may conduct ongoing reviews of customer information throughout the business relationship.
These reviews may include:
-
periodic identity verification;
-
sanctions re-screening;
-
politically exposed person monitoring;
-
adverse media screening;
-
source of funds reviews;
-
source of wealth verification;
-
transaction pattern analysis;
-
blockchain transaction monitoring;
-
wallet ownership verification;
-
enhanced due diligence reviews; and
-
regulatory reporting.

