top of page

Privacy Policy

Learn how Zeroa handles and protects your personal information across our website, accounts and financial services.

Document Version 2.0
Effective Date 23 July 2026
Last Review Date 23 July 2026
FSCA licence FSP 36012
CASP status Approved
Information Officer Kevin Pillay

This Privacy Policy explains what personal information ChemBridge Capital (Pty) Ltd, trading as Zeroa, collects, why we collect it, how we use it, who we share it with, how long we retain it, how we protect it, and the rights available to you under the Protection of Personal Information Act (POPIA) and, where applicable, the EU GDPR and UK GDPR. It should be read together with our Terms and Conditions.

1. Introduction

ChemBridge Capital (Pty) Ltd, trading as Zeroa ("Zeroa", "ChemBridge Capital", "we", "our" or "us"), is a South African financial services provider authorised by the Financial Sector Conduct Authority ("FSCA") and approved as a Crypto Asset Service Provider ("CASP").

Zeroa provides cross-border payment, settlement and digital asset services to individuals, businesses and institutional clients through its website, digital wallet platform and associated products.

The protection of personal information is fundamental to our business and forms part of our broader governance, compliance and information security framework. We recognise that clients entrust us with sensitive information relating to their identity, financial affairs and transactional activity. We are committed to ensuring that such information is processed lawfully, responsibly, transparently and securely.

This Privacy Policy explains:

  • what personal information we collect;

  • why we collect it;

  • how we use it;

  • who we share it with;

  • how long we retain it;

  • how we protect it; and

  • the rights available to individuals whose personal information we process.

This Policy applies to information collected through:

  • www.zeroa.io;

  • the Zeroa Wallet;

  • onboarding portals;

  • customer support channels;

  • mobile applications;

  • business development interactions;

  • payment and settlement services; and

  • any other products or services offered by ChemBridge Capital.

Our processing of personal information is primarily governed by the Protection of Personal Information Act, 2013 ("POPIA").

Because Zeroa offers services to clients located outside South Africa, including clients within the European Economic Area ("EEA") and the United Kingdom ("UK"), certain processing activities may also be subject to the General Data Protection Regulation (EU) 2016/679 ("EU GDPR") and the UK General Data Protection Regulation ("UK GDPR"), to the extent those laws apply.

Nothing in this Privacy Policy limits any rights afforded to individuals under applicable data protection legislation.

Where different legal obligations apply depending on a customer's country of residence or location, this Privacy Policy should be interpreted accordingly.

2. Who We Are

ChemBridge Capital (Pty) Ltd, trading as Zeroa, is incorporated in the Republic of South Africa and is authorised by the Financial Sector Conduct Authority as a Financial Services Provider and approved Crypto Asset Service Provider.

For purposes of POPIA, ChemBridge Capital is the Responsible Party responsible for determining the purpose and means of processing personal information.

Where the EU GDPR or UK GDPR applies, ChemBridge Capital acts as the Data Controller in relation to the personal information processed through its products and services.

Our registered business details are:

ChemBridge Capital (Pty) Ltd

Trading Name: Zeroa

Financial Services Provider Licence Number: 36012

Crypto Asset Service Provider: Approved

Registered Office:

The Zenith

27th Floor

The Box

Cape Town CBD

South Africa

Information Officer

Kevin Pillay

Email:

kevin.pillay@chemtrade.io

Telephone:

+27 81 590 8213

The Information Officer is responsible for overseeing compliance with this Privacy Policy, POPIA and applicable international data protection legislation.

3. Scope of this Privacy Policy

This Privacy Policy applies to all personal information processed by ChemBridge Capital in connection with its business operations.

It applies to:

  • visitors to our website;

  • individuals who enquire about our products;

  • prospective customers;

  • individual customers;

  • business customers;

  • directors, shareholders and beneficial owners of business customers;

  • authorised representatives and signatories;

  • wallet users;

  • merchants;

  • payment beneficiaries;

  • suppliers and service providers;

  • applicants for employment; and

  • any other person whose personal information is processed by ChemBridge Capital.

This Policy applies regardless of whether information is collected:

  • electronically;

  • through our website;

  • through our wallet platform;

  • during onboarding;

  • by telephone;

  • through email;

  • through messaging platforms such as WhatsApp;

  • through application programming interfaces (APIs);

  • through third-party service providers;

  • through regulatory reporting processes; or

  • through any other lawful business interaction.

This Policy applies throughout the entire customer relationship, including pre-onboarding due diligence, onboarding, ongoing monitoring, transactional activity and post-termination record retention.

4. Definitions

For purposes of this Privacy Policy:

Biometric Information means measurable biological or behavioural characteristics used to verify an individual's identity, including facial recognition data generated during identity verification.

CASP means Crypto Asset Service Provider.

Customer Due Diligence (CDD) means the identification and verification procedures required under applicable anti-money laundering legislation.

Data Subject means the individual to whom personal information relates.

Financial Crime includes money laundering, terrorist financing, fraud, sanctions evasion, bribery, corruption and other unlawful financial activity.

Information Officer means the person appointed in terms of POPIA.

Operator has the meaning assigned under POPIA.

Personal Information has the meaning assigned under POPIA and, where applicable, the EU GDPR or UK GDPR.

Processing includes collecting, recording, organising, storing, updating, retrieving, consulting, using, disclosing, transferring, combining, restricting, deleting or destroying personal information.

Responsible Party has the meaning assigned under POPIA.

Travel Rule means the legal requirements applicable to Virtual Asset Service Providers requiring the exchange of originator and beneficiary information for qualifying virtual asset transfers.

Wallet means any hosted digital asset wallet or related service made available by Zeroa.

5. Information We Collect

The categories of personal information we collect depend upon the nature of our relationship with you, the products and services you use, and our legal and regulatory obligations.

5.1 Identity Information


We may collect:

  • full legal name;

  • previous names;

  • date of birth;

  • nationality;

  • citizenship;

  • gender;

  • identity number;

  • passport number;

  • driver's licence details;

  • tax identification numbers;

  • photographs; and

  • signatures.

5.2 Contact Information


Including:

  • email addresses;

  • telephone numbers;

  • residential address;

  • postal address;

  • business address;

  • communication preferences.

5.3 Corporate Information


For business clients we may collect:

  • company registration details;

  • constitutional documents;

  • shareholder information;

  • beneficial ownership information;

  • director information;

  • authorised signatories;

  • ownership structure;

  • licensing information;

  • tax registrations.

5.4 Verification Information


To comply with our regulatory obligations we may collect:

  • certified identity documents;

  • passports;

  • proof of residential address;

  • bank statements;

  • source of wealth information;

  • source of funds information;

  • tax residency declarations;

  • politically exposed person declarations;

  • sanctions declarations;

  • biometric verification results;

  • liveness verification results.

5.5 Financial Information


Including:

  • bank account details;

  • payment information;

  • wallet addresses;

  • virtual asset holdings where disclosed;

  • transaction history;

  • settlement instructions;

  • beneficiary details.

5.6 Technical Information


We automatically collect technical information including:

  • IP addresses;

  • browser type;

  • operating system;

  • device identifiers;

  • session identifiers;

  • login information;

  • cookies;

  • website usage information;

  • application logs;

  • security logs.

5.7 Transaction Information


As part of providing our services we collect information relating to:

  • payments;

  • settlements;

  • wallet activity;

  • blockchain transaction references;

  • receiving wallet addresses;

  • sending wallet addresses;

  • transaction values;

  • timestamps;

  • blockchain network information;

  • payment references;

  • merchant information;

  • beneficiary information.

5.8 Communications


We may retain:

  • emails;

  • WhatsApp communications;

  • support tickets;

  • live chat conversations;

  • telephone recordings (where lawful);

  • complaints;

  • onboarding communications;

  • compliance correspondence.

5.9 Information Received from Third Parties


We may receive personal information from:

  • identity verification providers;

  • blockchain analytics providers;

  • sanctions screening providers;

  • credit reference agencies where lawful;

  • banking partners;

  • payment service providers;

  • regulators;

  • law enforcement agencies;

  • publicly available corporate registers;

  • public sanctions databases;

  • politically exposed person databases.


We collect only the personal information reasonably necessary to fulfil our contractual, legal, regulatory and operational obligations and to provide our products and services efficiently and securely. We do not knowingly collect excessive or irrelevant personal information, and we regularly review our collection practices to ensure continued compliance with applicable data protection laws.

6. Verification Through Zeroa Wallets

Zeroa provides hosted digital wallet services to facilitate cross-border payments, digital asset settlement and related financial services. In order to comply with applicable legislation, regulatory requirements and our internal risk management framework, every wallet maintained by Zeroa is linked to a verified customer profile.

Wallets may only be created once the applicable customer identification and verification procedures have been successfully completed, unless otherwise permitted by law.

Throughout the customer relationship we maintain a risk-based approach to ongoing customer due diligence. This includes monitoring wallet activity to identify unusual, suspicious or prohibited transactions and to ensure continued compliance with our legal and regulatory obligations.

Information associated with a wallet may include:

  • wallet addresses;

  • wallet identifiers;

  • blockchain network information;

  • transaction hashes;

  • transaction timestamps;

  • transaction values;

  • originating and destination wallet addresses;

  • funding sources;

  • beneficiary information;

  • device information used to access the wallet;

  • authentication records; and

  • security event logs.

Where required by law or where necessary to protect the integrity of our services, we may request additional information regarding:

  • the purpose of a transaction;

  • the source of funds;

  • the source of wealth;

  • supporting commercial documentation;

  • invoices;

  • contracts;

  • proof of ownership of external wallets;

  • additional identity verification documentation; or

  • any other information reasonably required to satisfy our regulatory obligations.

Failure to provide requested information may result in delays, restrictions, suspension or termination of wallet functionality where permitted by law.

We may also implement transaction limits, enhanced due diligence or additional verification procedures based upon the customer's risk profile, transaction behaviour or applicable regulatory requirements.

Nothing in this section limits our obligations to report suspicious or unusual activity to competent authorities where required by applicable law.

7. Identity Verification, Biometric Verification and Customer Due Diligence

As a licensed Financial Services Provider and Crypto Asset Service Provider, ChemBridge Capital is required to identify and verify the identity of its customers and certain related persons before establishing a business relationship and throughout the duration of that relationship.

These obligations arise under, among other legislation:

  • the Financial Intelligence Centre Act, 38 of 2001 ("FICA");

  • applicable Anti-Money Laundering and Counter-Terrorist Financing ("AML/CFT") legislation;

  • FSCA licensing requirements;

  • applicable sanctions legislation;

  • exchange control requirements;

  • international AML/CFT standards issued by the Financial Action Task Force ("FATF"); and

  • other applicable legal or regulatory requirements.

  • To satisfy these obligations we may collect and verify:

  • identity documents;

  • passports;

  • driver's licences;

  • proof of residential address;

  • corporate registration documents;

  • trust documentation;

  • beneficial ownership information;

  • source of funds information;

  • source of wealth information;

  • tax residency information;

  • politically exposed person declarations;

  • sanctions-related information; and

  • any additional documentation reasonably required for enhanced due diligence.

Biometric Verification


As part of our identity verification process, we may require customers to complete biometric verification.

This may include:

  • facial image capture;

  • selfie verification;

  • liveness detection;

  • facial comparison against identity documents;

  • anti-spoofing technology;

  • document authenticity verification; and

  • fraud detection technologies.

Biometric information is processed solely for:

  • verifying identity;

  • preventing identity theft;

  • detecting fraud;

  • satisfying our regulatory obligations;

  • preventing impersonation;

  • protecting customer accounts; and

  • maintaining the integrity of our services.

We do not sell, licence or otherwise commercialise biometric information.

Access to biometric information is restricted to authorised personnel and authorised service providers who require such information to perform contracted services on our behalf.

Identity Verification Providers


We currently utilise specialist identity verification providers, including Sumsub, to perform identity verification, document authentication, biometric verification, sanctions screening, politically exposed person screening, adverse media screening, Travel Rule compliance and ongoing transaction monitoring.

These providers process personal information strictly in accordance with contractual agreements entered into with ChemBridge Capital and applicable data protection legislation.

Where these providers engage approved sub-processors or operators, appropriate contractual safeguards are implemented to protect personal information.

Customers are encouraged to review the privacy notices of these providers for additional information regarding their own processing activities.

Ongoing Customer Due Diligence


Customer due diligence is not limited to onboarding.

ChemBridge Capital may conduct ongoing reviews of customer information throughout the business relationship.

These reviews may include:

  • periodic identity verification;

  • sanctions re-screening;

  • politically exposed person monitoring;

  • adverse media screening;

  • source of funds reviews;

  • source of wealth verification;

  • transaction pattern analysis;

  • blockchain transaction monitoring;

  • wallet ownership verification;

  • enhanced due diligence reviews; and

  • regulatory reporting.

Where customer information becomes inaccurate, incomplete or outdated, we may request updated documentation.

Customers are responsible for ensuring that information provided to ChemBridge Capital remains accurate and current.

8. Customer Relationship Management

ChemBridge Capital uses customer relationship management ("CRM") and business management platforms to manage customer interactions throughout the customer lifecycle.

These systems assist us with:

  • onboarding;

  • customer support;

  • compliance management;

  • relationship management;

  • sales administration;

  • customer communications;

  • document management;

  • marketing preference management;

  • complaint handling;

  • service delivery;

  • operational reporting; and

  • regulatory record keeping.

We currently utilise applications within the Zoho One suite, including but not limited to:

  • Zoho CRM;

  • Zoho Forms;

  • Zoho Campaigns;

  • Zoho Desk;

  • Zoho SalesIQ;

  • Zoho Sign;

  • Zoho Books; and

  • other Zoho applications implemented as part of our business operations.

Information processed within these systems may include:

  • customer contact information;

  • communications;

  • onboarding documentation;

  • compliance records;

  • customer preferences;

  • support interactions;

  • sales information;

  • transaction-related correspondence;

  • complaint records;

  • account history;

  • audit trails; and

  • system activity logs.

Our service providers act as Operators or Processors on our behalf and process personal information only in accordance with our documented instructions and applicable contractual obligations.

We implement appropriate contractual, technical and organisational safeguards to ensure that customer information processed by these providers remains protected.

9. Marketing and Transactional Communications

ChemBridge Capital communicates with customers using a variety of communication channels.

These communications fall into two broad categories:

  • Transactional communications; and

  • Marketing communications.


Transactional Communications


Transactional communications are necessary for the provision, administration and security of our services.

These communications may include:

  • onboarding updates;

  • identity verification requests;

  • payment confirmations;

  • settlement confirmations;

  • wallet notifications;

  • account alerts;

  • login notifications;

  • security alerts;

  • fraud alerts;

  • compliance requests;

  • regulatory notices;

  • customer support communications;

  • password reset notifications; and

  • changes to our services.

Transactional communications may be delivered through:

  • email;

  • WhatsApp;

  • SMS;

  • in-platform notifications;

  • push notifications;

  • telephone; or

  • other appropriate communication channels.

Because these communications are necessary for the provision of our services, customers cannot opt out of receiving them while maintaining an active relationship with ChemBridge Capital.

Marketing Communications


From time to time, we may communicate information regarding:

  • new products;

  • new services;

  • educational material;

  • industry insights;

  • webinars;

  • promotions;

  • events;

  • newsletters; and

  • business announcements.

Marketing communications are conducted in accordance with POPIA and, where applicable, the EU GDPR and UK GDPR.

Prospective customers will receive direct marketing only where:

  • consent has been obtained;

  • another lawful basis exists under applicable legislation; or

  • the communication is otherwise permitted by law.

Existing customers may receive marketing relating to products or services similar to those already provided, subject to applicable legal requirements and the customer's right to object.

Customers may withdraw consent or unsubscribe from marketing communications at any time by:

selecting the unsubscribe option included within our communications;
contacting the Information Officer;
updating communication preferences within their account; or
using any other opt-out mechanism provided.
Withdrawal of marketing consent does not affect our ability to send transactional communications.

10. Online Advertising and Digital Marketing

ChemBridge Capital promotes its products and services through various online advertising platforms.

These may include:

  • Google Ads;

  • Google Analytics;

  • Meta (Facebook and Instagram);

  • LinkedIn;

  • YouTube;

  • search engine advertising;

  • remarketing platforms; and

  • other digital advertising networks.

To understand the effectiveness of our advertising campaigns, we may use technologies including:

  • cookies;

  • pixels;

  • tags;

  • software development kits (SDKs);

  • conversion APIs;

  • analytics tools; and

  • similar technologies.

These technologies may be used to:

  • understand website usage;

  • improve website functionality;

  • measure campaign effectiveness;

  • analyse customer journeys;

  • identify technical issues;

  • improve customer experience;

  • deliver more relevant advertising;

  • create remarketing audiences; and

  • develop lookalike or similar audiences.

Where personal information is shared with advertising providers, we take reasonable steps to ensure that only the minimum information necessary for the intended purpose is disclosed. Where appropriate, information may be hashed, pseudonymised or otherwise protected before transmission.

Advertising providers process information in accordance with their own privacy notices, and customers are encouraged to review those notices and manage their advertising preferences directly through the relevant provider's privacy and advertising settings.

11. Cookies and Online Technologies

Our websites, applications and digital platforms use cookies and similar technologies to ensure their proper operation, improve user experience, enhance security and support analytics and advertising activities.

Cookies are small text files stored on a user's device that enable websites to recognise returning users, remember preferences and improve functionality.

We use the following categories of cookies:

Strictly Necessary Cookies
These cookies are essential for the operation of our websites and services and cannot be disabled without affecting core functionality.

Functional Cookies
These cookies remember user preferences and improve the functionality and usability of our services.

Analytics Cookies
Analytics cookies help us understand how visitors interact with our websites, identify performance issues and improve our products and services.

Advertising Cookies
Advertising cookies assist us and our advertising partners in delivering relevant advertising and measuring campaign performance.

Third-Party Technologies
Certain third-party providers, including analytics providers, customer support platforms and embedded services, may place cookies or similar technologies on our websites.

These technologies remain subject to the privacy practices of the relevant provider.

Cookie Preferences
Where required by applicable law, visitors will be presented with a cookie consent mechanism allowing them to accept, reject or customise non-essential cookies.

Users may also manage cookies through their browser settings.

Blocking certain cookies may affect the functionality or performance of portions of our website or services.

12. Legal Basis for Processing

ChemBridge Capital processes personal information only where there is a lawful basis to do so.

The lawful basis for processing will depend upon the nature of the relationship with the individual, the products or services being provided, and the legal or regulatory obligations applicable to the processing activity.

As a regulated Financial Services Provider and Crypto Asset Service Provider, much of our processing is undertaken because it is required by law or is necessary for the performance of our contractual obligations.

12.1 Processing under POPIA


In accordance with the Protection of Personal Information Act, ChemBridge Capital processes personal information where one or more of the following grounds apply:

  • the data subject has consented to the processing;

  • the processing is necessary to conclude or perform a contract with the data subject;

  • the processing complies with an obligation imposed by law;

  • the processing protects the legitimate interests of the data subject;

  • the processing is necessary for pursuing the legitimate interests of ChemBridge Capital; or

  • the processing is necessary for pursuing the legitimate interests of a third party to whom the information is supplied.

12.2 Processing under the EU GDPR and UK GDPR


Where the EU GDPR or UK GDPR applies, ChemBridge Capital processes personal information on one or more of the following lawful bases:

  • consent;

  • performance of a contract;

  • compliance with a legal obligation;

  • protection of vital interests;

  • performance of a task carried out in the public interest where applicable; or

  • legitimate interests pursued by ChemBridge Capital or a third party, provided such interests are not overridden by the rights and freedoms of the individual.

  • Where we rely on consent, individuals may withdraw that consent at any time, subject to legal or contractual limitations and without affecting the lawfulness of processing undertaken before withdrawal.

12.3 Special Categories of Personal Information


Certain services require us to process information regarded as sensitive or special personal information.

This may include:

  • biometric information;

  • identity verification information;

  • politically exposed person information;

  • criminal or sanctions-related information where legally permissible;

  • financial information required for regulatory compliance; and

  • information relating to source of wealth and source of funds.

Such information is processed only where permitted by applicable law and only to the extent necessary for:

  • customer identification and verification;

  • fraud prevention;

  • financial crime prevention;

  • compliance with AML/CFT legislation;

  • compliance with sanctions obligations;

  • regulatory reporting;

  • dispute resolution; and

  • the establishment, exercise or defence of legal rights.

We do not process special personal information for purposes incompatible with the reasons for which it was originally collected.

13. Disclosure of Personal Information

ChemBridge Capital treats personal information as confidential.

We do not sell, rent or otherwise disclose personal information to third parties for their own marketing purposes.

We may disclose personal information where reasonably necessary to operate our business, provide our services or comply with applicable legal and regulatory obligations.

Recipients may include:

Regulatory Authorities
Including but not limited to:

  • Financial Sector Conduct Authority (FSCA);

  • Financial Intelligence Centre (FIC);

  • South African Reserve Bank (SARB);

  • South African Revenue Service (SARS);

  • Information Regulator;

  • prudential authorities;

  • foreign regulators where legally authorised; and

  • law enforcement agencies.

Banking and Payment Partners
Including:

settlement banks;
correspondent banks;
payment processors;
payment service providers;
acquiring institutions;
banking infrastructure providers;
liquidity providers; and
foreign banking institutions involved in cross-border payment execution.


Compliance Service Providers
Including providers of:

  • KYC;

  • KYB;

  • identity verification;

  • sanctions screening;

  • adverse media screening;

  • politically exposed person screening;

  • fraud detection;

  • blockchain analytics;

  • transaction monitoring;

  • Travel Rule compliance;

  • document authentication;

  • biometric verification; and

  • regulatory reporting.

Professional Advisers
Including:

  • auditors;

  • legal advisers;

  • consultants;

  • insurers;

  • external compliance specialists; and

  • corporate finance advisers.

Technology Providers
Including cloud hosting providers, software providers, CRM platforms, cybersecurity providers, document management providers and communications providers.

Corporate Transactions
Where ChemBridge Capital is involved in:

  • a merger;

  • acquisition;

  • restructuring;

  • capital raise;

  • business transfer; or

  • sale of assets,

personal information may be disclosed to advisers and counterparties, subject to appropriate confidentiality obligations.

Where disclosure is not required by law, we require recipients to maintain appropriate confidentiality and security measures consistent with applicable privacy legislation.

13A. Blockchain Analytics and Transaction Monitoring

As part of our responsibilities as a licensed Crypto Asset Service Provider, ChemBridge Capital uses specialist blockchain analytics, transaction monitoring and wallet intelligence solutions to support financial crime prevention and regulatory compliance.

Unlike traditional financial transactions, blockchain transactions are recorded on public distributed ledgers. While blockchain addresses are generally pseudonymous, transaction analysis may allow blockchain activity to be associated with identifiable individuals or entities when combined with other information available to us.

Accordingly, certain blockchain information may constitute personal information under POPIA, the EU GDPR or the UK GDPR.

We use blockchain analytics platforms to:

  • identify sanctioned wallet addresses;

  • identify wallets associated with fraud, scams or theft;

  • identify wallets associated with ransomware;

  • identify wallets associated with darknet marketplaces;

  • identify exposure to terrorist financing;

  • identify money laundering typologies;

  • identify sanctioned entities;

  • identify mixers, tumblers and other obfuscation services;

  • monitor transaction risk;

  • identify unusual transactional behaviour;

  • conduct ongoing customer due diligence;

  • satisfy our obligations under FICA;

  • comply with FATF Recommendations;

  • comply with applicable sanctions legislation;

  • comply with CASP regulatory obligations; and

  • protect our customers and business against financial crime.


These monitoring activities may occur:

  • during onboarding;

  • before a transaction is processed;

  • during transaction processing;

  • after settlement;

  • periodically throughout the customer relationship; and

  • following receipt of intelligence from regulators or trusted industry participants.

Risk assessments generated through blockchain analytics are not used as the sole basis for decisions that produce legal or similarly significant effects without appropriate review by authorised personnel.

Where appropriate, customers may be requested to provide additional supporting information before transactions are processed.

Information shared with blockchain analytics providers is limited to what is reasonably necessary to perform these services and is subject to contractual confidentiality, security and data protection obligations.

13B. Travel Rule Compliance

ChemBridge Capital complies with applicable legal and regulatory requirements relating to the transfer of originator and beneficiary information between Virtual Asset Service Providers ("VASPs"), commonly referred to as the Travel Rule.

Where required by applicable law, regulatory guidance or recognised industry standards, we may collect, verify, process and securely transmit information relating to:

  • the originator of a virtual asset transfer;

  • the beneficiary of a virtual asset transfer;

  • wallet addresses;

  • account identifiers;

  • transaction references;

  • identifying information required by law; and

  • other information reasonably required to facilitate compliant virtual asset transfers.

Travel Rule information may be exchanged with:

  • regulated Virtual Asset Service Providers;

  • regulated financial institutions;

  • identity verification providers;

  • transaction monitoring providers;

  • Travel Rule messaging providers; and

  • competent regulatory authorities.

ChemBridge Capital currently utilises specialist providers, including Sumsub, to facilitate Travel Rule compliance and secure information exchange.

Information exchanged pursuant to the Travel Rule is processed solely for regulatory compliance, financial crime prevention and the secure execution of virtual asset transfers.

We maintain appropriate technical and organisational measures to ensure the confidentiality, integrity and security of Travel Rule information.

14. International Transfers of Personal Information

ChemBridge Capital provides international financial services and uses technology providers located in multiple jurisdictions.

Accordingly, personal information may be transferred outside the Republic of South Africa.

Recipients may include:

  • cloud infrastructure providers;

  • identity verification providers;

  • banking partners;

  • payment processors;

  • blockchain analytics providers;

  • cybersecurity providers;

  • software providers;

  • customer relationship management platforms;

  • regulators;

  • law enforcement authorities; and

  • other service providers reasonably necessary for the provision of our services.

Where personal information is transferred outside South Africa, ChemBridge Capital complies with section 72 of POPIA.

Where the EU GDPR or UK GDPR applies, we ensure that transfers are supported by an appropriate lawful transfer mechanism, which may include:

  • adequacy decisions;

  • Standard Contractual Clauses;

  • International Data Transfer Agreements;

  • approved codes of conduct;

  • approved certification mechanisms; or

  • another lawful safeguard recognised by applicable legislation.

Where appropriate, we conduct transfer risk assessments and implement supplementary technical, contractual and organisational measures to safeguard transferred personal information.

15. Information Security

ChemBridge Capital maintains an enterprise-wide information security programme designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Our security programme is based upon recognised information security principles and incorporates administrative, technical and physical safeguards appropriate to the sensitivity of the information processed.

These measures include, where appropriate:

  • encryption of data in transit using industry-standard protocols;

  • encryption of sensitive information at rest where appropriate;

  • role-based access controls;

  • multi-factor authentication;

  • privileged access management;

  • network segmentation;

  • endpoint protection;

  • vulnerability management;

  • penetration testing;

  • security monitoring and logging;

  • disaster recovery and business continuity planning;

  • secure software development practices;

  • employee confidentiality obligations;

  • periodic security awareness training;

  • third-party risk management; and

  • contractual security obligations imposed on operators and processors.

Access to personal information is limited to personnel who require such access to perform their authorised duties.

Employees and contractors are subject to confidentiality obligations and disciplinary measures in the event of unauthorised access, disclosure or misuse of personal information.

Where we become aware of a security compromise involving personal information, we will investigate the incident promptly and notify affected individuals and relevant regulatory authorities where required by applicable law.

Although we employ robust security measures, no method of electronic storage or transmission is entirely secure. Accordingly, we cannot guarantee absolute security, and users should also take reasonable steps to protect their own credentials, devices and accounts.

16. Retention of Personal Information

ChemBridge Capital retains personal information only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal and regulatory obligations, to protect our legitimate business interests, and to establish, exercise or defend legal claims.

Retention periods are determined with reference to:

  • applicable legislation;

  • regulatory requirements;

  • contractual obligations;

  • operational necessity;

  • industry best practice;

  • the nature and sensitivity of the information;

  • the purpose for which the information was collected; and

  • applicable limitation periods.

When personal information is no longer required, it will be securely deleted, destroyed, anonymised or de-identified unless we are required or permitted by law to retain it.

16.1 Typical Retention Periods


Unless a longer period is required by law or regulatory direction, we generally retain information for the following minimum periods:

Customer Identification and Due Diligence Records
Minimum of five (5) years after termination of the business relationship or completion of an occasional transaction, in accordance with FICA and applicable regulatory requirements.

Transaction Records
Minimum of five (5) years, or longer where required by law, regulatory investigation, litigation or audit.

Wallet Activity
Wallet activity and related audit records may be retained for regulatory, security, fraud prevention and financial crime investigation purposes.

Communication Records
Customer support communications, complaints and correspondence may be retained for operational, evidentiary and compliance purposes.

Marketing Records
Marketing preferences are retained until consent is withdrawn or marketing activities cease.

Suppression lists may be retained to ensure that individuals who have opted out are not contacted again.

Website and Technical Logs
Website activity logs, security logs and system audit logs are retained for periods appropriate to operational security, fraud detection and legal compliance.

16.2 Extended Retention


We may retain personal information beyond the periods described above where reasonably necessary:

  • to comply with legal obligations;

  • during litigation;

  • during regulatory investigations;

  • to comply with court orders;

  • to investigate fraud or financial crime;

  • to protect our legal rights;

  • where records are required for taxation purposes; or

  • where otherwise permitted by applicable law.

17. Automated Decision-Making, Fraud Detection and Artificial Intelligence

ChemBridge Capital uses automated systems to improve security, regulatory compliance, fraud detection and operational efficiency.

Automated processing assists us in identifying financial crime risks, protecting customers and complying with our legal obligations.

Automated processing may include:

  • sanctions screening;

  • politically exposed person screening;

  • adverse media screening;

  • blockchain analytics;

  • transaction monitoring;

  • fraud detection;

  • identity verification;

  • biometric comparison;

  • document authenticity verification;

  • risk scoring;

  • suspicious transaction identification;

  • cybersecurity monitoring;

  • account security monitoring; and

  • behavioural anomaly detection.

These technologies help us identify unusual or suspicious activity that may require further investigation.

Automated systems generally generate risk indicators or recommendations rather than final decisions.

Where an automated assessment identifies elevated risk, the matter is ordinarily referred to appropriately authorised personnel for further review before any final decision is taken.

Examples may include:

  • requests for additional documentation;

  • temporary delays pending investigation;

  • enhanced due diligence;

  • refusal of a transaction;

  • account restrictions;

  • suspicious transaction reporting; or

  • termination of a business relationship where permitted by law.


ChemBridge Capital does not intentionally rely solely upon automated processing to make decisions producing legal or similarly significant effects where applicable law requires meaningful human involvement.

Where the EU GDPR or UK GDPR applies, individuals may request:

  • human review of an automated decision;

  • an explanation of the decision-making process, where legally required;

  • the opportunity to express their point of view; and

  • reconsideration of the decision.

Nothing in this section limits our obligations to comply with anti-money laundering legislation or other legal requirements requiring immediate action to prevent financial crime.

18. Children's Privacy

ChemBridge Capital's products and services are intended solely for persons who are legally capable of entering into binding contractual relationships.

Our services are not directed at children under the age of eighteen (18) years.

We do not knowingly solicit, collect or process personal information from children except where:

  • expressly authorised by law;

  • necessary for the provision of a lawful service involving a parent or legal guardian;

  • required in connection with legal proceedings; or

  • otherwise permitted under applicable legislation.

If we become aware that personal information relating to a child has been collected inadvertently and without lawful authority, we will take reasonable steps to:

  • investigate the circumstances;

  • restrict further processing where appropriate;

  • securely delete the information where lawful; and

  • notify the relevant parent or guardian where appropriate.


Parents or guardians who believe that a child has provided personal information to ChemBridge Capital should contact our Information Officer immediately.

19. Your Privacy Rights

ChemBridge Capital respects the rights of individuals regarding their personal information.

The rights available to you may vary depending upon the jurisdiction in which you are located and the legislation applicable to the processing.

19.1 Rights under POPIA


Subject to applicable legal limitations, individuals have the right to:

  • be notified when personal information is collected;

  • be informed of the purpose for which information is collected;

  • request confirmation as to whether ChemBridge Capital holds personal information relating to them;

  • request access to personal information;

  • request correction of inaccurate information;

  • request updating of incomplete information;

  • request deletion of unlawfully processed information where applicable;

  • object to processing on reasonable grounds;

  • object to processing for direct marketing purposes;

  • withdraw consent where processing is based on consent;

  • submit complaints to the Information Regulator;

  • institute civil proceedings where permitted by law.


Certain requests may be refused where ChemBridge Capital is legally required to retain or continue processing the information.

19.2 Additional Rights under the EU GDPR and UK GDPR


Where the EU GDPR or UK GDPR applies, individuals may also have the right to:

  • access personal information;

  • rectify inaccurate information;

  • erase personal information ("right to be forgotten");

  • restrict processing;

  • object to processing;

  • receive personal information in a structured, commonly used and machine-readable format where applicable;

  • transmit information to another controller where technically feasible;

  • withdraw consent at any time;

  • object to profiling in certain circumstances;

  • request human review of automated decision-making; and

  • lodge complaints with the competent supervisory authority.


These rights are subject to limitations and exemptions contained within applicable legislation.

19.3 Exercising Your Rights


Requests relating to personal information should be directed to the Information Officer.

To protect the privacy and security of individuals, we may require reasonable proof of identity before processing any request.

Where permitted by law, ChemBridge Capital may refuse requests that are:

  • manifestly unfounded;

  • excessive;

  • repetitive;

  • fraudulent;

  • intended to interfere with regulatory obligations; or

  • otherwise not required by law.

We endeavour to respond to requests within the time periods prescribed by applicable legislation.

20. Changes to this Privacy Policy

ChemBridge Capital may amend this Privacy Policy from time to time.

Changes may become necessary due to:

  • amendments to legislation;

  • regulatory guidance;

  • technological developments;

  • new products or services;

  • changes to business operations;

  • cybersecurity developments;

  • changes in service providers; or

  • improvements to our privacy governance framework.


The latest version of this Privacy Policy will always be published on our website.

The "Effective Date" and "Version Number" appearing at the beginning of this Policy indicate the current version.

Where changes materially affect the way in which personal information is processed, we will take reasonable steps to notify affected individuals through appropriate communication channels, including:

  • email;

  • website notices;

  • customer portals;

  • in-platform notifications; or

  • other appropriate methods.


Continued use of our services after the effective date of an updated Privacy Policy constitutes acknowledgement of the revised Policy, except where applicable legislation requires renewed consent.

21. Complaints, Requests and Regulatory Contacts

ChemBridge Capital is committed to maintaining the privacy, confidentiality and integrity of personal information. If you believe that your personal information has been processed in a manner inconsistent with this Privacy Policy or applicable law, we encourage you to contact us in the first instance so that we have an opportunity to investigate and resolve your concerns promptly.

We treat all privacy-related enquiries and complaints seriously and investigate them in accordance with our internal governance framework.

21.1 Contacting the Information Officer


All privacy enquiries, requests and complaints should be directed to our Information Officer.

Information Officer
Kevin Pillay

Compliance Key Individual

ChemBridge Capital (Pty) Ltd t/a Zeroa

Email: kevin.pillay@chemtrade.io

Telephone: +27 81 590 8213

Registered Address:

The Zenith

27th Floor

The Box

Cape Town CBD

South Africa

The Information Officer is responsible for:

  • overseeing compliance with POPIA;

  • administering this Privacy Policy;

  • responding to privacy-related requests;

  • managing data subject rights requests;

  • coordinating responses to personal information security incidents;

  • liaising with regulators where appropriate;

  • monitoring compliance with our privacy governance programme; and

  • maintaining our internal privacy management framework.

21.2 Privacy Requests


Individuals may submit requests relating to:

  • access to personal information;

  • correction of inaccurate information;

  • deletion of information where legally permissible;

  • restriction of processing;

  • objections to processing;

  • withdrawal of consent;

  • data portability (where applicable);

  • automated decision-making;

  • marketing preferences;

  • complaints regarding privacy practices; or

  • any other matter relating to the processing of personal information.

To protect individuals against fraud and unauthorised disclosure, ChemBridge Capital may require satisfactory proof of identity before responding to any request.

Where permitted by law, we may:

  • request additional information to verify identity;

  • seek clarification regarding the scope of a request;

  • extend response periods where legislation permits;

  • refuse requests that are manifestly unfounded or excessive; or

  • retain information where continued processing is required by law.

21.3 Complaints to the Information Regulator


If you are dissatisfied with our response, or believe that we have not complied with applicable privacy legislation, you may lodge a complaint with the South African Information Regulator.

At the time of publication of this Privacy Policy, the Information Regulator's contact details are:

Information Regulator (South Africa)


Website: https://eservices.inforegulator.org.za

Email: enquiries@inforegulator.org.za

General Enquiries: enquiries@inforegulator.org.za

Physical Address:

Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg

Postal Address:

P.O. Box 31533

Braamfontein

Johannesburg

2017

Individuals are encouraged to first contact ChemBridge Capital to allow us an opportunity to resolve concerns before approaching the Information Regulator.

21.4 Supervisory Authorities Outside South Africa


Where the processing of personal information is subject to the EU GDPR or the UK GDPR, individuals may also have the right to lodge a complaint with the competent supervisory authority in the country in which they reside, work or where the alleged infringement occurred.

Nothing in this Privacy Policy limits any statutory rights available under applicable legislation.

22. Governing Law

This Privacy Policy is governed by the laws of the Republic of South Africa.

The collection, processing, storage, disclosure and protection of personal information by ChemBridge Capital is primarily regulated by:

  • the Protection of Personal Information Act, 2013 (POPIA);

  • the Financial Intelligence Centre Act, 38 of 2001 (FICA);

  • the Financial Advisory and Intermediary Services Act, 37 of 2002 (FAIS);

  • applicable Financial Sector Conduct Authority requirements;

  • applicable Crypto Asset Service Provider licensing conditions;

  • applicable exchange control requirements;

  • applicable anti-money laundering and counter-terrorist financing legislation; and

  • other applicable South African legislation.

Where ChemBridge Capital offers products or services to individuals located in the European Economic Area or the United Kingdom, the processing of personal information relating to those individuals may also be subject to:

  • the General Data Protection Regulation (EU) 2016/679 ("EU GDPR");

  • the UK General Data Protection Regulation ("UK GDPR"); and

  • any other applicable privacy legislation governing the relevant processing activity.

Where there is any inconsistency between this Privacy Policy and mandatory provisions of applicable privacy legislation, the mandatory provisions of that legislation shall prevail to the extent of the inconsistency.

Nothing in this Privacy Policy limits any rights or obligations imposed by applicable law.

Definitions and Interpretation

Unless the context indicates otherwise:

  • References to "ChemBridge Capital," "Zeroa," "we," "our," and "us" mean ChemBridge Capital (Pty) Ltd trading as Zeroa.

  • References to "you" and "your" refer to any individual whose personal information is processed under this Privacy Policy.

  • Headings are included for convenience only and do not affect interpretation.

  • References to legislation include amendments, replacements and subordinate legislation.

  • References to one gender include all genders, and references to the singular include the plural where the context requires.


Document Approval

Kevin Pillay
Compliance Key Individual · Information Officer
kevin.pillay@chemtrade.io  ·  +27 81 590 8213

bottom of page