Privacy Policy

1. Introduction

Ethos Financial Services respects your right to privacy and is committed to protecting your personal information.

This Privacy Policy explains how we collect, use, store, share and protect personal information in accordance with:

  • The Protection of Personal Information Act 4 of 2013 (“POPIA”);
  • The Promotion of Access to Information Act 2 of 2000 (“PAIA”);
  • The Financial Advisory and Intermediary Services Act 37 of 2002 (“FAIS”), where applicable;
  • The Financial Intelligence Centre Act 38 of 2001 (“FICA”), where applicable; and
  • Other applicable South African laws and regulatory requirements.

This Policy applies to personal information processed through our website, https://ethosfin.co.za/, as well as information provided to us by telephone, email, online forms, social media, face-to-face engagements or through our insurance and financial-services partners.

2. Responsible party

For purposes of POPIA, the responsible party is:

Registered company name: Ethos Financial Services
Company registration number : 2023/506336/07
FSP number : 55168
Physical address: 183 high road Bredell Kempton park 1619
Telephone: 010 449 6056
General email: info@ethosfin.co.za
Website: https://ethosfin.co.za/

3. Personal information we collect

Depending on your relationship with Ethos and the services you request, we may collect:

  • Your name, surname, title and date of birth;
  • South African identity or passport number;
  • Contact details, including your telephone number, email address and physical address;
  • Company name, registration number and business contact details;
  • Employment, occupation and income information;
  • Banking, payment and other financial information;
  • Insurance requirements, policy details, premiums and claims history;
  • Information about your assets, vehicles, property, household contents, business operations, commercial fleet, cargo or equipment;
  • Driver’s licence and vehicle registration information;
  • Risk-assessment and underwriting information;
  • Communications, enquiries, complaints and correspondence;
  • Records of advice, quotations, applications and policy instructions;
  • Website usage information, IP address, browser type, device information and cookie identifiers;
  • Information received from insurers, underwriters, brokers, claims assessors, credit providers, regulatory bodies or other authorised third parties; and
  • Any other information reasonably required to provide our services or comply with legal obligations.

Our website enquiry form currently collects your first name, last name, telephone number, email address, insurance policy required, optional company name and message.

4. Special personal information

When reasonably necessary for insurance, underwriting, claims or legal purposes, we may process special personal information, including:

  • Health or medical information;
  • Biometric information;
  • Criminal-behaviour information;
  • Information relating to alleged fraud or financial misconduct; and
  • Information about children or other dependants.

We will only process special personal information where permitted by law, where necessary to establish, exercise or defend a right or obligation, or where valid consent has been obtained.

Where information concerns a child, we will process it only with the consent of a competent person or where otherwise permitted by law.

5. How we collect information

We may collect personal information:

  • Directly from you when you contact us, request advice, complete a form, request a quotation or apply for cover;
  • During telephone calls, consultations or correspondence;
  • From insurers, underwriting managers, brokers, reinsurers, claims administrators and other financial-service providers;
  • From your employer, authorised representative, business partner or intermediary;
  • From public records, regulatory bodies, credit bureaus, fraud-prevention databases and lawful verification services;
  • Through cookies and related website technologies; and
  • From third parties where you have authorised the disclosure or where collection is permitted by law.

Where information is obtained from another source, we will take reasonable steps to ensure that its collection and processing are lawful.

6. Why we process personal information?

We may process your personal information to:

  • Respond to enquiries and contact requests;
  • Understand your insurance and risk-management needs;
  • Conduct needs analyses and risk assessments;
  • Obtain, compare and present insurance quotations;
  • Recommend suitable insurance or financial solutions;
  • Submit applications to insurers and underwriting partners;
  • Arrange, administer, renew, amend or cancel policies;
  • Assist with claims and policy-related enquiries;
  • Verify your identity and prevent fraud;
  • Maintain records of advice and other regulatory documentation;
  • Communicate with you about products, services and policy matters;
  • Manage complaints and resolve disputes;
  • Conduct business analysis, reporting, auditing and quality assurance;
  • Improve our services, website and client experience;
  • Protect our systems, clients, employees and business against security threats;
  • Comply with legal, regulatory, tax, financial and reporting obligations; and

Establish, exercise or defend legal rights.

7. Lawful grounds for processing

We process personal information only where one or more lawful grounds apply, including:

  • You have consented to the processing;
  • Processing is necessary to enter into or perform a contract with you;
  • Processing is required to comply with a legal obligation;
  • Processing protects your legitimate interests;
  • Processing is necessary to pursue our legitimate business interests or those of an authorised third party; or
  • Processing is otherwise permitted under POPIA or another applicable law.

Providing information is generally voluntary. However, certain information may be required to provide an accurate quotation, conduct an assessment, place insurance cover, process a claim or comply with the law.

If you do not provide the required information, we may be unable to provide advice, obtain quotations, arrange cover or perform the requested service.

8. Sharing personal information

We may share relevant personal information with:

  • Insurers and underwriting managers;
  • Insurance brokers, intermediaries and representatives;
  • Reinsurers;
  • Claims administrators, loss adjusters, assessors, investigators, repairers and service providers;
  • Medical, legal, accounting and other professional advisers;
  • Banks, payment providers and credit bureaus;
  • Fraud-prevention and identity-verification services;
  • Technology, cloud-hosting, website, email, document-storage and cybersecurity providers;
  • Auditors, compliance officers and risk-management providers;
  • Government departments, courts, law-enforcement bodies and regulatory authorities;
  • The Financial Sector Conduct Authority, Prudential Authority, Information Regulator or Financial Intelligence Centre, where applicable; and
  • Other parties where you have authorised the disclosure or where disclosure is required or permitted by law.

We require third-party service providers that process information on our behalf to implement appropriate confidentiality, privacy and security safeguards.

We do not sell personal information.

9. Direct marketing

Where permitted by law, we may contact you about insurance products, financial solutions, company news or services that may be relevant to you.

We will obtain consent for electronic direct marketing where POPIA requires it. You may withdraw your consent or opt out at any time by:

  • Clicking the unsubscribe option in an electronic communication;
  • Contacting us at info@ethosfin.co.za; or
  • Calling us on 010 449 6056.

Opting out of marketing will not prevent us from sending necessary service, quotation, policy, claims or regulatory communications.

10. Cookies and website information

Our website may use cookies and similar technologies to:

  • Enable essential website functionality;
  • Remember preferences;
  • Improve website performance;
  • Understand how visitors use the website;
  • Protect the website against fraud and security threats; and
  • Measure the effectiveness of communications or marketing.

Some cookies may be placed by third-party services, including website-hosting, analytics, embedded media or social-media providers.

You may control cookies through your browser settings or through the website’s cookie-consent tool, where available. Disabling essential cookies may affect website functionality.

Non-essential analytics or advertising cookies should not be activated without the required consent.

11. Automated decision-making

Insurers or underwriting partners may use automated tools, risk models or scoring systems when assessing an application, calculating a premium or making an underwriting decision.

Where a decision with legal or substantial consequences is based solely on automated processing, we will comply with applicable legal requirements and, where appropriate, provide an opportunity for the decision to be reviewed or for you to make representations.

12. Information security

We implement reasonable technical and organisational safeguards to protect personal information against:

  • Loss, damage or unauthorised destruction;
  • Unlawful access;
  • Unauthorised use, alteration or disclosure; and
  • Accidental or unlawful processing.

Our safeguards may include access controls, passwords, encryption, system monitoring, backups, staff confidentiality obligations, secure disposal procedures and service-provider security requirements.

Although we take reasonable precautions, no internet transmission or electronic storage system is completely secure.

13. Security compromises

If we reasonably believe that personal information has been accessed or acquired by an unauthorised person, we will investigate the incident and notify the Information Regulator and affected data subjects as required by POPIA.

Notifications may be delayed where a law-enforcement authority determines that notification could impede a criminal investigation.

14. Retention of personal information

We retain personal information only for as long as reasonably necessary to:

  • Fulfil the purpose for which it was collected;
  • Provide services and administer our relationship with you;
  • Comply with FAIS, FICA, tax, insurance and other regulatory requirements;
  • Resolve disputes or complaints;
  • Enforce agreements; or
  • Establish, exercise or defend legal rights.

When information is no longer required, it will be securely deleted, destroyed or de-identified, subject to applicable legal retention obligations.

15. Your rights

Subject to POPIA and other applicable laws, you may:

  • Ask whether we hold personal information about you;
  • Request access to your personal information;
  • Request correction of inaccurate, incomplete, misleading or outdated information;
  • Request deletion or destruction where we are no longer authorised to retain the information;
  • Object to processing on reasonable grounds;
  • Withdraw consent where processing is based on consent;
  • Object to direct marketing;
  • Request information about third parties that have received your personal information;
  • Submit a complaint to our Information Officer; and
  • Lodge a complaint with the Information Regulator.

We may require proof of identity before processing a request. Certain requests may be refused or limited where permitted by law.

16. Access, correction and deletion requests

Requests may be submitted to:

Information Officer:
Email: info@ethosfin.co.za
Telephone: 010 449 6056
Address: 183 high road Bredell kempton

Prescribed POPIA forms for objections, corrections and deletion requests are available from the Information Regulator at:

https://inforegulator.org.za/popia-forms/

Requests for access to records may also be subject to our PAIA Manual and the procedures prescribed under PAIA.

17. Complaints to the Information Regulator

If you believe that we have unlawfully processed your personal information, please first contact our Information Officer so that we can investigate the matter.

You may also lodge a complaint with:

Information Regulator (South Africa)
Woodmead North Office Park
54 Maxwell Drive
Woodmead, Johannesburg, 2191
Telephone: 010 023 5200
Toll-free: 0800 017 160
General email: enquiries@inforegulator.org.za
POPIA complaints: POPIAComplaints@inforegulator.org.za
Website: https://inforegulator.org.za/

18. Third-party websites

Our website may contain links to insurers, social-media platforms and other third-party websites. We are not responsible for the privacy, security or content practices of those websites.

You should review the privacy policy of each third-party website before providing personal information.

19. Changes to this Policy

We may amend this Privacy Policy from time to time to reflect legal, regulatory, operational or technological changes.

The latest version will be published on our website and will indicate its effective date. Material changes may also be communicated through appropriate channels.

20. Contact us

For privacy questions, requests or complaints, contact:

Ethos Financial Services
Telephone: 010 449 6056
Email: info@ethosfin.co.za
Website: https://ethosfin.co.za/
Physical address: 183 high road Bredell 1619