loader image

Privacy Statement

This Privacy Statement was last updated on 01/05/2025 and applies to citizens and legal permanent residents of South Africa.
Approved By: Grant Smee, Director

1. Introduction

Vermillion (Pty) Ltd (“the Company”) is an Insurance and Wealth Management advisory business registered under the Financial Advisory and Intermediary Services Act (FAIS) FSP 50486. Vermillion is committed to ensuring the lawful processing of personal information in accordance with the Protection of Personal Information Act No. 4 of 2013 (POPIA). This policy outlines how we collect, process, store, protect, and dispose of personal data. More information

POPIA, or the Protection of Personal Information Act of South Africa, is a data privacy law that aims to protect the rights of individuals to have their personal information processed lawfully. It came into effect in 2020 and sets out conditions for the lawful processing of personal information by both public and private entities. The act is designed to ensure that personal data is handled responsibly and transparently, balancing the rights of individuals with the legitimate needs of organizations. POPIA outlines specific principles that must be followed when processing personal information, such as lawful processing, purpose limitation, and accuracy.

The Information Regulator in South Africa is responsible for monitoring and enforcing compliance with POPIA. In essence, POPIA ensures that individuals’ personal information is protected in South Africa by establishing a framework for lawful processing and respecting the rights of individuals to control their own data.

2. Purpose

The purpose of this policy is to:

    • Protect the rights of data subjects.
    • Ensure compliance with POPIA.
    • Establish the Company’s approach to handling personal information in a responsible and lawful manner.
    • Promote transparency regarding how personal information is used.

3. Scope

This policy applies to:

    • All employees, contractors, consultants, and service providers of Vermillion.
    • All personal information processed by the Company, whether in electronic or hard copy format.
    • Any processing activities conducted on behalf of the Company.

4. Definitions

    • Personal Information: Any information that identifies or can be used to identify a natural or juristic person.
    • Data Subject: The person to whom the personal information relates.
    • Processing: Any operation involving personal data (collection, storage, usage, transfer, deletion, etc.).
    • Responsible Party: Vermillion, who determines the purpose and means of processing.
    • Operator: A third party that processes personal information on behalf of the Responsible Party.

5. Data Collection

We collect personal information as disclosed by yourselve/s only where it is necessary for a specific, explicitly defined, and lawful purpose.

6. Lawful Processing

Personal information is processed:

    • With the consent of the data subject.
    • To fulfill a contractual obligation.
    • To comply with legal and regulatory requirements.
    • To protect the legitimate interests of the data subject or the Company.

Sharing Your Personal Information

We may share your personal information with trusted third parties under certain circumstances, including:

      • Group Companies: With any Vermillion (Pty) Ltd staff member, affiliated entity, or related business to assist with service delivery, customer relationship management, technical improvements, or to fulfil your requests for information, products, or services.
      • Service Providers and Agents: This includes third-party providers and their subcontractors who process data on our behalf, such as medical service providers, IT and cloud service providers, payment processors, or professional support providers.
      • Strategic Partners: Including software developers, integrators, and technology partners who support our platforms and services or offer related solutions you may find useful.
      • Payment Processing Institutions: Entities involved in payment facilitation such as banks, clearing houses, and financial institutions.
      • Authorised Third Parties: If you have an existing relationship with another party and have given consent for us to share data with them.
      • Marketing Partners: With your consent, we may share data with select partners whose products or services could benefit your business or personal financial goals.
      • Verification and Compliance Agencies: Credit bureaus, fraud prevention services, or background checking entities where needed.
      • Regulators: Where required to fulfil our legal and regulatory responsibilities.
      • Law Enforcement: When required to detect, prevent, or investigate criminal activity or as required by law.
      • Legal Proceedings: If required in the course of actual or anticipated legal action, such as responding to a court order.
      • Legal and Regulatory Disclosures: As required to comply with legislation or enforce lawful obligations.
      • Professional Advisors: Our attorneys, auditors, or other advisors, when required to obtain legal or financial guidance or meet our audit requirements.
      • Business Transfers: In the event of a merger, sale, or restructuring of our business or assets.
      • Government Institutions: Where mandatory reporting is required by law or regulation.

We may also share non-personal, anonymized data (which cannot identify you) about the usage of our platforms or services with third parties or the public for research, development, or marketing purposes.

Whenever we share your personal information, we ensure it’s protected by appropriate data sharing policy covered in our agreements. These agreements bind the recipient to strict confidentiality obligations and robust data security measures.

Marketing and Communication Preferences

From time to time, we may use your personal information to contact you with targeted advertising, promotional content, or marketing messages (including in-product notifications) that may be relevant or useful to you. These communications may be based on your use of our website or services, your relationship with us, or information shared during a transaction — and only where you have provided consent or submitted your details for such purposes. This processing is done under a legitimate and contractual interest.

We may also share your information with our affiliated companies or carefully selected partners, so they (or we) can inform you about their products or services that may align with your interests, provided you have given your consent.

You may be contacted through various channels such as telephone, mail, SMS, email, or other electronic communications.

You have the right to opt out of receiving marketing communications from us or our partners at any time.

You can also request that we do not share your personal information with any third parties for marketing purposes.

To manage your preferences or to exercise your rights, you may:

      • Select your preferred communication options when you initially provide your details;
      • Or email us directly at info@vsure.co.za.

If you no longer wish to receive email marketing from us, you can unsubscribe at any time by clicking the unsubscribe link included in our email communications.

If we transfer your personal data outside of South Africa, it will only be shared with entities located in countries with similar data protection laws. If not, the recipient will be required to sign agreements that ensure compliance with the same standards as required under POPIA.

By using our services or engaging with us through our website or other platforms, you consent to your information being shared as described in this section and in accordance with this policy.

7. Information Security

We implement appropriate technical and organizational security measures to prevent unauthorized access or loss of data.

8. Data Subject Rights

Data subjects have the right to:

    • access and correct their personal information;
    • object to processing under certain conditions;
    • request deletion or restriction of data;
    • lodge a complaint with the Information Regulator.

9. Third-Party Processing

We ensure that third-party processors comply with POPIA through binding agreements and controls.

10. Data Retention

Personal information is retained only for as long as necessary for its intended purpose or as required by law.

11. Breach Notification

In the event of a data breach, we will notify the Information Regulator and affected individuals where necessary.

12. Training and Awareness

All employees are required to complete annual POPIA training and adhere to this policy.

13. Responsibilities

    • Information Officer: Oversees implementation and compliance.
    • Employees: Must ensure all data is handled according to this policy.
    • IT and Security Teams: Maintain data protection infrastructure.

14. Policy Review

This policy is reviewed annually or in response to significant changes.

15. Contact Information

For POPIA-related queries or concerns, please contact the Information Officer at:

📧 info@vermillionwealth.co.za
📞 021 300-1143