Member-first. Governance-led. Secure by design.Enterprise preview EN
Privacy Policy

How Asonge Sonke protects personal information

This privacy notice explains how personal information is collected, used, protected, shared and retained in connection with Asonge Sonke member and business services.

South Africa: This notice is structured around the Protection of Personal Information Act, 2013 (POPIA). Other privacy laws may apply where services or individuals fall within their territorial scope.

1. Scope and responsible party

Asonge Sonke processes personal information required to administer membership, contributions, savings and wallet records, responsible lending, payments, statements, support, compliance, security and related business operations. The responsible party determines the purpose and means of processing for information under its control.

2. Information we may process

Depending on the service, information may include identification and contact details, membership records, verification information, financial and transaction records, loan and repayment information, support correspondence, consent records, device/security events and information required by law or risk controls. Passwords are not stored in readable form and users should never send passwords, PINs or full card credentials through contact forms.

3. Purpose and lawful processing

Information is processed for defined and legitimate purposes such as providing contracted/member services, meeting legal or regulatory obligations, protecting accounts and funds, preventing fraud, maintaining accurate financial records, responding to enquiries and improving controlled service delivery. Processing is limited to what is adequate, relevant and reasonably necessary for those purposes.

4. Identity, financial crime and credit checks

Where applicable, identity, KYC/AML, sanctions, affordability, responsible-credit and fraud controls may be performed before or during service delivery. Results are governed by applicable law, internal approval controls and human review where required.

5. Operators and service providers

Approved technology, hosting, messaging, payment, verification and professional service providers may process limited information on Asonge Sonke’s behalf under confidentiality, security and purpose-limitation requirements. Service-provider access is restricted to what is necessary for the contracted function.

6. AI-assisted processing

AI may assist authorised staff with anomaly detection, record review and recommendations. Sensitive datasets are minimised before external AI use, and AI does not independently approve loans or silently change member balances, interest, savings, wallet records or posted financial transactions. Material corrective actions require human review and approval.

7. Security safeguards

Safeguards include role-based access, multi-factor authentication for sensitive functions, encryption controls, secure sessions, audit evidence, logging, backup and recovery controls, vulnerability management and restricted administrative access. No internet service can eliminate all risk, so controls are reviewed and improved continuously.

8. Retention and disposal

Records are retained only for as long as required by the service, contractual obligations, dispute needs, financial-record requirements, fraud prevention and applicable law. When retention is no longer justified, information is deleted, anonymised or securely disposed of according to approved retention rules.

9. Cross-border processing

If personal information is processed outside South Africa, appropriate safeguards and POPIA requirements for transborder flows are considered before transfer, including the protection available in the receiving jurisdiction and contractual safeguards where appropriate.

10. Your rights

Subject to applicable law, individuals may request access to personal information, correction or deletion of inaccurate or unlawfully retained information, object to certain processing, withdraw consent where consent is the basis, and raise a complaint. Identity verification may be required before actioning a request.

11. Direct marketing

Electronic direct marketing is managed in accordance with applicable consent, opt-out and customer-relationship rules. Operational, security, legal and transactional notices are not treated as marketing where they are necessary to provide or protect the service.

12. Security incidents and complaints

Suspected compromises are assessed through incident-response procedures. Notifications are made where legally required. Privacy complaints can be sent through the Contact page and may also be escalated to South Africa’s Information Regulator where applicable.

13. Changes to this notice

The policy may be updated as services, law, technology or risk controls change. Material changes are published with an updated effective date and, where appropriate, communicated through member channels.

Preview effective date: 19 September 2026. The production version is managed by Super Admin and may contain organisation-specific contact and Information Officer details.