Privacy Policy
1. Who we are
Heptagon Capital and Heptagon Wealth are South African financial services providers based in Gauteng.
- Heptagon Wealth is an independent Financial Services Provider authorised under FAIS, FSP number 9968.
- Heptagon Capital is an accredited Old Mutual franchise operating under FSP number 703.
For the purposes of POPIA, both entities act as responsible parties in respect of the personal information they collect.
2. Information Officer
In terms of section 55 of POPIA, our Information Officer is:
| Name | Corne Bouwer |
|---|---|
| Position | Group Chief Executive Officer |
| talktous@heptagonc.com | |
| Telephone | +27 11 660 1291 |
3. What personal information we collect
We collect personal information that is necessary to provide financial advice and to comply with our legal obligations. The categories of information we typically collect include:
3.1 Identification information
- Full name, identity number, date of birth, nationality
- Marital status and details of dependants
- Copies of identity documents required for FICA verification
3.2 Contact information
- Postal and residential addresses
- Telephone numbers and email addresses
- Preferred contact channels
3.3 Financial information
- Income, expenses, assets, and liabilities
- Existing insurance and investment products
- Tax reference numbers
- Banking details for the implementation of recommendations
- Risk profile and investment objectives
3.4 Health and lifestyle information
- Medical history relevant to underwriting of risk products
- Smoking status, occupation, and lifestyle factors relevant to underwriting
3.5 Information collected through our website and digital channels
- Information submitted through our enquiry, contact, and booking forms
- Information collected automatically via cookies and analytics (described in section 11)
- Records of correspondence by email, WhatsApp, and phone
4. How we collect personal information
We collect personal information:
- Directly from you, when you complete our forms, attend meetings, or correspond with us
- From third parties with your consent, including credit bureaus, product providers, and previous advisers
- Automatically when you visit our website (see section 11)
- From public sources where this is lawful and necessary for our services
5. Why we process your personal information
We process your personal information for the following purposes:
- To provide financial advice and intermediary services in terms of FAIS
- To verify your identity and comply with FICA, anti-money-laundering, and counter-terrorism financing obligations
- To prepare financial needs analyses and financial plans
- To apply for, implement, and service insurance and investment products on your behalf
- To communicate with you about your portfolio, our services, and relevant updates
- To comply with regulatory reporting obligations to the FSCA, SARS, and other regulators
- To handle complaints and disputes
- To maintain accurate records as required by applicable law
- To improve our services through analysis of aggregated data
6. Lawful basis for processing
We process your personal information on one or more of the following lawful bases set out in section 11 of POPIA:
- Your consent
- The conclusion or performance of a contract with you
- Compliance with a legal obligation
- The protection of your legitimate interests or those of a third party
- The pursuit of our legitimate interests, balanced against your rights
7. Who we share your personal information with
To provide our services, we may share your personal information with the following categories of third parties:
7.1 Product providers
Insurers, investment houses, retirement fund administrators, and medical scheme administrators when applying for or servicing products on your behalf. This includes Old Mutual and its affiliated entities by virtue of our franchise relationship, as well as the broader market of providers we access as an independent FSP.
7.2 Service providers
Technology and service providers who help us run our business, including our CRM and lead-management platform, email service providers, document storage and archiving systems, and call recording systems. These providers are contractually required to safeguard your personal information.
7.3 Professional partners
Where relevant to your plan and with your authority, we may share information with attorneys, tax practitioners, accountants, conveyancers, and trust administrators with whom we collaborate to deliver integrated planning.
7.4 Regulators and authorities
We disclose personal information to the FSCA, FIC, SARS, the Information Regulator, the FAIS Ombud, and any other regulator or court of competent jurisdiction where required by law.
7.5 Auditors and advisers
Our external auditors, compliance officers, and legal advisers, who are bound by confidentiality obligations.
8. Cross-border transfers
Some of the technology service providers we use may host data outside South Africa. Where this is the case, we ensure that the cross-border transfer complies with section 72 of POPIA, either through binding contractual safeguards or because the recipient country has comparable data protection laws.
9. How long we keep your personal information
We keep your personal information for as long as is necessary to provide our services and to comply with legal and regulatory record-keeping obligations. In practice, this means:
- Records of advice and related documents: at least 5 years after the date of advice (FAIS)
- FICA verification records: at least 5 years after the end of the business relationship
- Tax-related records: at least 5 years from the end of the relevant tax year
- Records relating to complaints: at least 5 years after resolution
- Other records: for the period necessary to fulfil the original purpose, after which they are securely destroyed or de-identified
10. Your rights as a data subject
Under POPIA, you have the following rights:
- To be notified that we are processing your personal information
- To request access to the personal information we hold about you (see our PAIA Manual)
- To request correction or deletion of inaccurate, incomplete, or out-of-date information
- To object to the processing of your personal information on reasonable grounds
- To object to direct marketing
- To withdraw consent where processing is based on consent
- To lodge a complaint with the Information Regulator
To exercise any of these rights, please contact our Information Officer at talktous@heptagonc.com.
11. Cookies and analytics
Our website uses cookies and similar technologies to support core functionality, remember your preferences, and understand how visitors use our site. We may use the following:
- Essential cookies required for the website to function properly
- Analytics cookies that help us understand site usage in aggregate
- Form and booking widgets embedded from third-party providers such as GoHighLevel, which may set their own cookies subject to their own privacy notices
You can manage cookies through your browser settings. Disabling cookies may affect the functionality of the site.
12. Direct marketing
We may send you newsletters, updates, and information about our services. You may opt out of marketing communications at any time by clicking the unsubscribe link in any email we send, or by emailing talktous@heptagonc.com.
13. How we protect your personal information
We take reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, alteration, or disclosure. These measures include access controls, encryption in transit, secure data storage, staff training, and confidentiality undertakings from service providers.
If you become aware of any security incident affecting your personal information, please contact our Information Officer immediately.
14. Children
We do not knowingly collect personal information directly from children under 18. Where we hold personal information relating to a minor (for example, in the context of family financial planning), this is collected and processed with the consent of the competent person responsible for the minor.
15. Complaints to the Information Regulator
If you believe we have not handled your personal information lawfully, you have the right to lodge a complaint with the Information Regulator (South Africa):
| Address | JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 |
|---|---|
| Postal address | P.O. Box 31533, Braamfontein, 2017 |
| Telephone | +27 10 023 5200 |
| Email (POPIA complaints) | complaints.IR@justice.gov.za |
| General email | inforeg@justice.gov.za |
16. Changes to this policy
We may update this Privacy Policy from time to time. The current version is published on our website at www.heptagonc.com. Material changes will be communicated through appropriate channels.
17. Contact us
Any questions about this policy or about how we process your personal information should be directed to our Information Officer:
Email: talktous@heptagonc.com
Telephone: +27 11 660 1291
WhatsApp: +27 60 541 4685