INTRODUCTION
About this Privacy Notice
Wahed Invest (Pty) Ltd (“Wahed Invest”, “Wahed”, “we”, “us” or “our”), Registration No. 2020/726348/07, Financial Services Provider (FSP) Number 51684, is committed to safeguarding the confidentiality, integrity, and lawful processing of personal information in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA) and all other applicable South African laws governing financial services providers.
This Privacy Notice explains how we collect, receive, store, use, share, retain, and protect personal information when you use our website, mobile application, digital platforms, or any of our financial products and services. It applies to all personal information processed by Wahed, whether it is provided directly by you or obtained from third parties, and whether it is collected online, in writing, by telephone, or in person.
Who we are
Wahed is an authorised Financial Services Provider regulated by the Financial Sector Conduct Authority (FSCA) and accountable to the Financial Intelligence Centre (FIC). We are the responsible party for the purposes of POPIA, which means we decide how and why your personal information is processed.
If you have any questions about this Privacy Notice or the way your personal information is handled, you may contact us through our official customer or compliance channels.
Our commitment to your privacy
This Privacy Notice is part of our commitment to providing financial services with integrity, transparency, and respect for your right to privacy. We are committed to:
- processing personal information lawfully, fairly, and in a transparent way;
- protecting your constitutional right to privacy;
- using appropriate technical and organisational safeguards to prevent loss, misuse, or unauthorised access;
- complying with all regulatory and reporting obligations imposed by the FSCA, the FIC, and other authorities; and
- enabling you to exercise your rights under POPIA, including the rights to access, correct, object to, or request deletion of your personal information.
Your consent
Please read this Privacy Notice carefully before providing any personal information to us. By using our website, mobile application, or services, or by submitting information to us, you acknowledge that you have read and understood this Privacy Notice and consent to the collection, use, disclosure, retention, and processing of your personal information as described here, unless you exercise any rights available to you under POPIA.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in law, technology, or our business practices. Any updates will be published on our website or app. We will not make changes that reduce your rights unless we are legally required to do so. Your continued use of our services after any update means you accept the revised Privacy Notice.
Third-party websites
Our website or app may contain links to third-party websites. These websites have their own privacy policies, and Wahed is not responsible for their content or data-handling practices.
1. DEFINITION OF PERSONAL INFORMATION
1.1 Definitions as prescribed in terms of POPIA:
Biometrics:
Means a technique of personal identification that is based on physical, physiological or behavioural characterisation including blood typing, fingerprinting, DNA analysis, retinal scanning and voice recognition.
Complainant:
Means any person who lodges a complaint with the Information Regulator
Consent:
Means any voluntary, specific and informed expression of will in terms of which permission is given for the processing of personal information.
Data Subject:
Means the natural or juristic person to whom personal information relates, such as an individual client, customer or a company that supplies Wahed with products or other goods.
De-Identify:
Means to delete any information that identifies a data subject or which can be used by a reasonably foreseeable method to identify, or when linked to other information, identifies the data subject.
Direct Marketing:
Means to approach a data subject, either in person or by mail or electronic communication, for the direct or indirect purpose of:
- Promoting or offering to supply, in the ordinary course of business, any goods or services to the data subject; or
- Requesting the data subject to make a donation of any kind for any reason.
Electronic communication:
Means any text, voice, sound or image message sent over an electronic communications network which is stored in the network or in the recipient's terminal equipment until it is collected by the recipient.
Information Officer:
Means the person who is responsible for ensuring Wahed’s compliance with POPIA. The Information Officer is the head of Wahed, and will be responsible for performing the Information Officer’s duties.
Information Regulator:
Is an independent juristic entity established under section 39 of the Protection of Personal Information Act (POPIA) to monitor, enforce, and promote compliance with POPIA and PAIA.
Non-electronic communication:
Means direct marketing communications that are not sent over an electronic communications network and therefore fall outside the definition of “electronic communication”.
Operator:
Means a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party. For example, a third-party service provider that has contracted with Wahed to shred documents containing personal information. When dealing with an operator, it is considered good practice for a responsible party to include an indemnity clause.
Personal Information:
Means any information that can be used to reveal a person’s identity. Personal information relates to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person (such as a company), including, but not limited to information concerning:
- race, gender, sex, pregnancy, marital status, national or ethnic origin, colour, sexual orientation, age, physical or mental health, disability, religion, conscience, belief, culture, language and birth of a person;
- information relating to the education or the medical, financial, criminal or employment history of the person;
- any identifying number, symbol, email address, physical address, telephone number, location information, online identifier or other particular assignment to the person;
- the biometric information of the person;
- the personal opinions, views or preferences of the person;
- correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence;
- the views or opinions of another individual about the person;
- the name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person.
Processing
Means any activity or any set of operations, whether or not by automatic means, concerning personal information and includes:
- the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation or use;
- dissemination by means of transmission, distribution or making available in any other form; or
- merging, linking, as well as any restriction, degradation, erasure or destruction of information.
Record:
Means any recorded information, regardless of form or medium, including:
- Writing on any material;
- Information produced, recorded or stored by means of any tape-recorder, computer equipment, whether hardware or software or both, or other device, and any material subsequently derived from information so produced, recorded or stored;
- Label, marking or other writing that identifies or describes anything of which it forms part, or to which it is attached by any means;
- Book, map, plan, graph or drawing;
- Photograph, film, negative, tape or other device in which one or more visual images are embodied so as to be capable, with or without the aid of some other equipment, of being reproduced.
Re-Identify:
In relation to personal information of a data subject, means to resurrect any information that has been de-identified that identifies the data subject, or can be used or manipulated by a reasonably foreseeable method to identify the data subject.
Responsible Party:
Means the entity that needs the personal information for a particular reason and determines the purpose of and means for processing the personal information. In this case, Wahed is the responsible party.
Once appointed, the Information Officer must be registered with the South African Information Regulator established under POPIA prior to performing their duties. Deputy Information Officers can also be appointed to assist the Information Officer.
Solicited electronic or non-electronic communication:
Means an electronic or non-electronic communication sent to a data subject who has requested, consented to, or reasonably expects the communication.
Unique Identifier:
Means any identifier that is assigned to a data subject and is used by a responsible party for the purposes of the operations of that responsible party and that uniquely identifies that data subject in relation to that responsible party.
Unsolicited electronic or non-electronic communication:
Means an electronic or non-electronic communication sent to a data subject without prior request, consent, or an existing relationship that creates a reasonable expectation of receiving such communication.
1.2 Statutory Meaning:
For the purposes of the Protection of Personal Information Act, 4 of 2013 (“POPIA”), personal information means any information relating to an identifiable, living natural person and, where applicable, an identifiable, existing juristic person.
1.3 Policy Purpose
This purpose of this policy is to protect Wahed from the compliance risks associated with the protection of personal information which includes:
- Breaches of confidentiality. For instance, Wahed could suffer loss in revenue where it is found that the personal information of data subjects has been shared or disclosed inappropriately.
- Failing to offer choice. For instance, all data subjects should be free to choose how and for what purpose Wahed uses information relating to them.
- Reputational damage. For instance, Wahed could suffer a decline in shareholder value following an adverse event such as a computer hacker deleting the personal information held by Wahed Invest.
This policy demonstrates Wahed’s commitment to protecting the privacy rights of data subjects in the following manner:
- Through stating desired behaviour and directing compliance with the provisions of POPIA and best practice.
- By cultivating a culture that recognises privacy as a valuable human right.
- By developing and implementing internal controls for the purpose of managing the compliance risk associated with the protection of personal information.
- By creating business practices that will provide reasonable assurance that the rights of data subjects are protected and balanced with the legitimate business needs of Wahed.
- By assigning specific duties and responsibilities to control owners, including the appointment of an Information Officer in order to protect the interests of Wahed and data subjects.
- By raising awareness through training and providing guidance to individuals who process personal information so that they can act confidently and consistently.
1.4 Policy Scope and Application
This policy and its guiding principles applies to:
- The Wahed’s governing body;
- All employees, independent contractors and interns;
- All contractors, suppliers and other persons acting on behalf of Wahed.
The policy’s guiding principles find application in all situations and must be read in conjunction with POPIA as well as the organisation’s PAIA Policy as required by the Promotion of Access to Information Act (Act No 2 of 2000).
The legal duty to comply with POPIA’s provisions is activated in any situation where there is:
- A processing of personal information entered into a record by or for a responsible person who is domiciled in South Africa.
POPIA does not apply in situations where the processing of personal information:
- is concluded in the course of purely personal or household activities, or
- where the personal information has been de-identified.
1.5 Categories of Personal Information Processed
Wahed processes personal information for the purpose of providing financial products and services, complying with legal and regulatory obligations, and operating its digital platforms. The personal information processed includes identification information such as a client’s full legal name, identity number or equivalent official identifier, date of birth, and copies of identity documents used for verification. It also includes contact information such as residential or postal address, email address, telephone number, and a client’s stated communication preferences.
Wahed further processes financial and regulatory information, including information relating to a client’s source of income, source of funds, and source of wealth, details of investment portfolios and transactions, banking and payment account information, and tax reference or identification numbers. In order to provide suitable and compliant investment advice, Wahed also processes information relating to a client’s financial objectives, financial needs, risk appetite, and investment preferences.
In addition, Wahed processes technical and transactional information generated through a client’s use of its platforms and services. This includes device identifiers, IP addresses, website usage data, cookies and similar technologies, records of communications between the client and Wahed, transaction histories, and other data reflecting how clients interact with Wahed’s systems. Wahed Invest also processes marketing and preference information, including marketing and communication preferences, product and service interests, communications history, survey responses, and feedback.
1.6 Processing of Special Personal Information
Where any personal information processed by Wahed constitutes special personal information as defined in POPIA, such information will only be processed where one or more lawful grounds for processing applies, including where:
- you have provided explicit and informed consent;
- the processing is necessary to establish, exercise, or defend a legal right or obligation;
- the processing is required or authorised by law;
- the processing is necessary to comply with financial services, anti-money laundering, counter-terrorist financing, or sanctions-screening obligations;
- the processing is conducted for historical, statistical, or research purposes in accordance with POPIA and subject to appropriate safeguards; and/or
- the processing is otherwise permitted under POPIA.
2. PURPOSE AND LAWFUL BASIS FOR PROCESSING
2.1 Purposes for Processing Your Personal Information
Wahed processes personal information for clearly defined and lawful purposes connected to the provision of financial services, regulatory compliance, and the operation of its business.
2.1.1. Service delivery and product administration
Wahed processes personal information in order to assess clients’ financial circumstances, financial needs, and investment objectives; to process applications for financial products and services; and to establish, administer, and maintain ongoing client relationships. This includes fulfilling contractual obligations, communicating with clients regarding their accounts and services, providing customer support, and responding to client enquiries in a timely and effective manner.
2.1.2 Risk management, financial crime prevention, and compliance
Personal information is processed for the purposes of managing risk and ensuring compliance with applicable laws and regulatory requirements. This includes conducting Know-Your-Customer (KYC) verification and Customer Due Diligence (CDD) in accordance with the Financial Intelligence Centre Act and applicable anti-money-laundering and counter-terrorist-financing requirements; screening clients against sanctions lists and politically exposed person databases; assessing and mitigating fraud, identity theft, and financial crime risks; conducting internal risk assessments; and ensuring compliance with requirements imposed by the FSCA and other competent authorities, including client suitability and appropriateness assessments.
2.1.3 Regulatory reporting and legal disclosures
Wahed processes personal information to comply with its statutory reporting and disclosure obligations. This includes reporting to the FSCA and the FIC as required by law, responding to lawful requests, subpoenas, and regulatory investigations, and maintaining audit trails and regulatory records in accordance with applicable legislation.
2.1.4 Marketing and business development
Subject to applicable law and a client’s stated marketing preferences, Wahed may process personal information for marketing and business development purposes. This includes communicating information about products and services that may be relevant to clients, conducting market research and client satisfaction surveys, analysing market trends and business performance, developing and improving products and services based on client feedback and market analysis, and conducting targeted campaigns and promotions in compliance with applicable marketing and communications requirements.
2.1.5 Financial analysis, profiling, and service optimisation
Wahed processes personal information for financial analysis and service optimization purposes. This includes conducting client risk profiling, analysing portfolio performance, developing investment recommendations tailored to a client’s profile, and optimising service delivery. Where permitted by law, and where required with the client’s consent, Wahed Invest may use automated tools, including artificial intelligence and machine-learning systems, to enhance product suitability, efficiency, and consistency of service delivery.
2.1.6 Record-keeping, historical, and continuity purposes
Personal information is further processed for record-keeping and accountability purposes, including the maintenance of records required under financial services and other applicable legislation, the preservation of audit and compliance trails, the archiving of information for business continuity and disaster-recovery planning, and the use of data for lawful historical, statistical, or research purposes subject to appropriate safeguards.
2.2 Lawful Basis for Processing
Wahed processes personal information only where a lawful basis exists in accordance with section 11 of the Protection of Personal Information Act, 4 of 2013 (POPIA). We rely on one or more of the following lawful bases, depending on the circumstances:
- Consent – Where you have explicitly consented to the processing of your personal information
- Contractual Performance – Where processing is necessary for entering into, executing, or performing a contract with you
- Legal Obligation – Where processing is required by South African law, including the FAIS Act, Financial Advisory and Intermediary Services Act, banking regulations, tax legislation, or anti-money laundering regulations including any other subordinated legislation as the case may be.
- Public Interest – Where processing is necessary for the protection of public interest
- Legitimate Interest – Where we have a legitimate interest in processing your information (such as fraud prevention, security, or business improvement), provided this does not materially damage your rights or interests
2.3 Withdrawal of Consent
Where processing is based on consent, a data subject may withdraw such consent at any time by providing written notice to Wahed. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to the withdrawal. Where consent is withdrawn, Wahed may be unable to continue providing certain products or services that depend on that consent. Wahed Invest may, however, continue to process personal information where another lawful basis for processing applies, including compliance with legal or regulatory obligations or the pursuit of a legitimate interest.
3. SOURCES OF PERSONAL INFORMATION
Wahed collects personal information through several channels, depending on how you interact with us the services you use:
3.1 Information Collected Directly From You
We collect personal information directly from you when you apply for or use our products and services, when you communicate with us, and when you interact with our digital platforms. This includes:
- Personal financial information – When you apply for our services or products;
- Online interactions – Information you provide when using our website, online portals, and digital platforms;
- Communications – Information shared when you contact us by email, through our website, online portals, and digital platforms;
- Account transactions – Information generated through your account activity and transactions;
- Customer enquiries and feedback – Information provided when you submit enquiries, complaints, or feedback;
- Survey responses – Responses you give when you participate in surveys or research
We will only collect the necessary and relevant information that would be required for the purpose of our services and products, and/or where specific legislation requires the same.
3.2 Information Collected Automatically
When you visit or use our website and digital platforms, some information is collected automatically through technology. This includes:
- Automated collection technologies – Through cookies and similar technologies that help us understand how our website is used.
- Log data – Automatic collection of IP addresses, browser information, and access times.
- Behavioral data – Information about how you move through and use our website.
3.3 Information from Third Parties
Where allowed by law and where appropriate, we may obtain personal information about you from trusted third parties. These may include:
- Fraud prevention agencies – To verify, identity and prevent fraud.
- Other financial institutions and service providers – To facilitate services or verify information
- Regulatory authorities – Not limited to the following, but definitely including the FIC, SARS, SAPS and/or any other relevant body.
- Public databases and official registers – For identity verification and sanctions screening
We only collect personal information from third parties where we have a lawful basis to do so. This will be where the third party is lawfully permitted to disclose the information and where you have given consent, or where it is reasonable and lawful for us to obtain the information in this way.
4. RECIPIENTS OF PERSONAL INFORMATION
Wahed only shares your personal information where this is necessary to provide services to you, to meet legal and regulatory requirements, or to operate our business in a safe and compliant way.
4.1 Sharing within Wahed
Your personal information may be shared internally within Wahed with people who need it to perform their duties. This includes:
- Senior management and Key Individual – For governance and compliance oversight
- Compliance and Risk Management teams – For regulatory, compliance and risk assessment.
- Customer Service and Support teams – For service delivery
- Financial and Administrative staff – For account administration and reporting
- IT and Security teams – For system management and security
- Internal auditors – For audit and governance purposes
4.2 Sharing with Third Parties
We may share your personal information with carefully selected third parties where this is required to provide services to you, to meet legal or regulatory obligations, or to protect against fraud and financial crime.
These third parties may include, but are not limited to:
A. Professional - Financial Services and Operations Providers
- Product providers and fund managers
- Investment platforms and custodians
- Fund administrators and asset managers
- Custodians of other services providers who support the operation of our investment services.
- Payment processors
B. Regulators and Authorities (not limited to below)
- Financial Sector Conduct Authority (FSCA) – For regulatory reporting and supervision
- Financial Intelligence Centre (FIC) – For anti-money laundering and counter-terrorism financing compliance
- South African Revenue Service (SARS) – For tax compliance and reporting
C. Fraud, identity, and compliance services
- Fraud prevention and financial-crime monitoring services
- Know Your Customer (KYC) services and identity-verification providers
We only share personal information with third parties who are required to protect it, use it only for the purpose for which it was shared, and comply with applicable data-protection and confidentiality laws.
4.3 Sale of Personal Information
We will never sell your personal information to third parties for marketing or commercial purposes. Any sharing of personal information takes place only for lawful business, regulatory, or service-delivery purposes.
5. DATA RETENTION AND DISPOSAL
Wahed keeps personal information only for as long as it is needed to provide services, meet legal and regulatory obligations, and protect our legal and business interests. Once information is no longer required, it is securely deleted or destroyed.
5.1 How Long We Keep Your Information
The length of time we keep personal information depends on the type of data and the reason we collected it. In general, the following periods apply:
A. Regulatory and Compliance Records
Please note that these periods are subject to change depending on legislation changes:
- Client identification and KYC records: kept for minimum five (5) years from the end of the business relationship (in accordance with FIC requirements)
- Transaction records and related communications: kept for minimum five (5) years (in accordance with FIC requirements)
- Account records: kept for the duration of the business relationship and at least five (5) years thereafter
- Tax-related documents: kept for the period required by SARS, usually between five (5) and seven (7) years
- Sanctions screening records: kept for at least five (5) years after termination of our products and/or services.
B. Contractual and Business Records
- Product documentation and agreements: kept for the duration of the relationship and typically for a further five (5) to seven (7) years
- Investment records and transaction history: kept for the duration of the relationship and at least five (5) years thereafter
- Communications records: for the duration of the business relationship and for up to five (5) years afterwards
C. Marketing and Operational Data
- Marketing preferences and communications: are kept until you unsubscribe or your relationship ends with us
- Cookies and web analytics: are kept for up to two (2) to three (3) years or as per our cookie policy
- Feedback, complaints and survey responses: are usually kept for three (3) to five (5) years for analysis and service-improvement purposes
D. Historical, Statistical, and Research Data
We may keep certain information for historical, statistical, or research purposes for longer periods, including indefinitely, where this is allowed by law and where appropriate safeguards are in place to protect your privacy and prevent misuse.
5.2 How We Delete And Destroy Information
When your personal information is no longer needed, or when your relationship with Wahed ends, we take steps to ensure it is removed in a secure way. This includes securely deleting or overwriting electronic records and shredding or otherwise destroying physical records so that they cannot be reconstructed. We use appropriate technical and organisational measures to make sure that deleted information cannot be recovered. Where reasonably practicable, we will also ask third parties who received your information on our behalf to delete or destroy their copies.
6. SECURITY MEASURES AND PROTECTION
Wahed takes the security of your personal information seriously and has put in place appropriate technical, physical, and organisational measures to protect it against unauthorised access, loss, misuse, alteration, or destruction.
6.1 Our Security Framework
We use a layered security approach to protect personal information.
A. Physical Security
- Restricted access: Access to our offices and facilities is restricted and controlled through identification and access controls.
B. Electronic and Technical Security
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest (AES-256)
- Firewalls and intrusion detection: Multi-layered network security systems
- Antivirus and malware protection: Continuous monitoring and updates
- Access controls: Role-based access with unique user IDs and passwords
- Multi-factor authentication: Where applicable, for sensitive systems
- Regular security assessments: Penetration testing and vulnerability assessments
- Secure deletion: Data securely wiped using industry-standard tools
- Backup and disaster recovery: Systems in place for business continuity
- Secure communication channels: Encrypted email and secure portals
C. Administrative and Operational Security
- Confidentiality agreements: All staff and service providers bound by confidentiality
- Compliance monitoring: Ongoing monitoring of POPIA compliance
- Vendor management: Third-party service providers screened and monitored
6.2 Data Breach Notification
In the event of a data breach or unauthorized disclosure of your personal information:
- We will notify you and the Information Regulator without unreasonable delay if there is a reasonable belief that the breach materially harms the protection of your personal information
- Notification will include details of the breach, affected information, measures taken, and your rights
- We will cooperate fully with regulatory investigations
6.3 Limitation of Liability
While we take comprehensive measures to protect your information, no security system is entirely impregnable. We cannot guarantee absolute security. We disclaim liability for:
- Information disclosed due to factors beyond our reasonable control
- Breaches resulting from your failure to maintain password security
- Unauthorized access to information through your accounts or devices
- Information disclosed with your consent or authorization
7. COOKIES AND ONLINE TRACKING
7.1 Cookie Usage
Our Services use cookies and other similar tools to enable secure functionality, improve performance, and analyze usage.
A. Categories of Cookies:
- Essential Cookies: Necessary for login, navigation, and core security. These cannot be disabled.
- Analytics Cookies: Help us understand how users interact with our Services by collecting anonymous usage data.
- Marketing Cookies: Track browsing behaviour to deliver tailored content and advertising. You may opt out of these.
B. User Consent and Management:
By using our Services, you consent to the use of cookies as described. You may:
- Accept All Cookies (enable all categories).
- Reject Non-Essential Cookies (allow only essential cookies).
Note: Disabling cookies may affect your ability to access certain website features or services.
C. Other Data Collection Tools:
In addition to cookies, we may use tools such as web beacons and server logs to help improve your experience. These tools may capture details about the device used to access the Services, including operating system type, browser type, domain, country, and time zone.
Such information does not ordinarily identify you personally and is primarily used for statistical analysis, fraud detection, security monitoring, and performance improvement.
7.2 Cookies in Emails
In addition to the cookies we use on this website, we also use cookies in some emails and push notifications. These help us to understand whether you have opened the email and how you have interacted with it.
8. YOUR RIGHTS AS A DATA SUBJECT
Under the Protection of Personal Information Act, 4 of 2013 (POPIA), you have a number of rights in relation to the personal information we hold about you. These rights are designed to give you control over how your information is used and to ensure that it is handled fairly and lawfully.
8.1 Right of Access
You have the right to ask whether Wahed holds personal information about you and, if so, to request access to that information. This includes the right to request:
- confirmation of whether we hold personal information about you;
- a copy of the personal information we hold about you;
- information about how and why your information is processed;
- details of the parties with whom your information is shared; and
- information about how long we keep your information;
8.1.1 How to Make an Access Request
To make an access request, you must submit a written request to our Information Officer. Requests should be reasonably specific so that we can identify the information you are asking for. We will normally respond within 15 business days, although this period may be extended to up to 30 business days where allowed by law. For security reasons, we may ask you to confirm your identity before we provide any information.
8.2 Right to Correction and Deletion
You have the right to ask us to correct or delete your personal information where appropriate. This includes the right to request correction if your information is inaccurate, incomplete, misleading, or outdated, and the right to request deletion if the information is no longer needed for the purpose for which it was collected. If you wish to submit a data correction or deletion request, please email us to notify us of the request at zafsupport@wahed.com
Where we correct or delete information, we will, where reasonably practicable, notify any third parties with whom the information was shared.
Requests must include sufficient detail to identify the information to be corrected or deleted. We will consider your request and respond within fifteen (15) business days. We may refuse a request where we are required by law to keep the information, where the information must be kept for a lawful business purpose, where deletion would prejudice your legal rights, or where another valid exception under POPIA applies.
8.3 Right to Object to Processing
You have the right to object to the processing of your personal information in certain circumstances. This includes where the processing is for a purpose other than the one for which the information was collected, where the processing is for direct marketing, or where we are relying on a legitimate interest and that interest does not outweigh your rights.
If we receive a valid objection, we will stop processing your information unless we have another lawful basis or a compelling legal reason to continue.
8.4 Right to Withdraw Consent
Where we process your personal information based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal, our right to continue processing where another lawful basis applies, or our obligation to comply with legal and regulatory requirements.
8.5 Right to Restrict Processing
You may ask us to restrict the processing of your personal information in certain situations, including where you dispute the accuracy of the information, where we no longer need it but you require it for legal purposes, or where you have objected to processing and we are assessing whether our legitimate interests override your rights. While processing is restricted, we will only store the information and will not otherwise use it unless you consent or the law requires us to do so.
8.6 Right to Data Portability
You have the right to ask us to provide personal information that you have given to us in a structured, commonly used, and machine-readable format. This right applies only to information you provided to us and does not include information that we have created, derived, or inferred.
8.7 Right to be Informed
You have the right to be notified that your personal information is being collected by Wahed. You also have the right to be notified in any situation where we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorized person.
8.8 Right to Lodge a Complaint
If you believe that your rights under POPIA have been violated, you may raise a complaint with Wahed by contacting our Information Officer. If you are not satisfied with our response, you may also lodge a complaint with the Information Regulator or bring a civil claim for damages arising from the unlawful processing of your personal information.
9. HOW TO EXERCISE YOUR RIGHTS
9.1 Making a Request
To exercise any of the rights described in this Privacy Notice, you may submit a written request to our Information Officer:
Name: Moaaz Ismail
Position: Key Individual and Information Officer
Company: Wahed Invest (Pty) Ltd
Email: zafsupport@wahed.com
Physical Address: Office 19, Third Floor, Arch Collab, 34 Whiteley Road, Melrose Arch, Johannesburg, Gauteng, 2196
9.2 What to include in your request
To help us process your request, please include:
- your full name and contact details;
- proof of your identity, such as a copy of your identity document;
- a clear description of the request you are making; and
- enough detail for us to locate the personal information you are asking about.
9.3 Response Timeframes
We will acknowledge receipt of your request within five (5) business days. We will normally provide a full response within fifteen (15) business days, although this may be extended to up to thirty (30) business days where allowed by law and where the request is complex or requires additional verification. If more time is needed, we will let you know.
Urgent requests may be handled more quickly where this is reasonably possible.
9.4 Fees
We do not charge a fee for access to your personal information unless a fee is allowed or required by the Information Regulator or where reasonable administrative costs apply.
10. MARKETING COMMUNICATIONS
10.1 Direct Marketing
Wahed may send you marketing communications about products and services that are relevant to you. We will only do this in line with your marketing preferences and, where required by law, with your consent. All marketing messages are sent in a fair, transparent, and non-misleading way.
10.2 How we may contact you
We may send marketing communications through the following channels:
- email;
- social-media platforms;
- online advertising; and
- other electronic communication methods.
10.3 How to opt out
You can stop receiving marketing communications from us at any time. You can do this by clicking the “unsubscribe” link in any marketing email or by contacting us through our support channels.
Once we receive your opt-out request, we will stop sending you marketing messages within a reasonable time. You may choose to opt back in at any time.
10.4 Messages you will still receive
Even if you opt out of marketing, we may still contact you about:
- transactions and activity on your account;
- important service-related updates;
- regulatory or compliance matters;
- responses to enquiries or requests you have made; and
- communications that we are legally required to send.
These messages are not marketing and are necessary for us to provide and manage our services.
11. CONTACT DETAILS
11.1 Information Officer
Name: Moaaz Ismail
Position: Key Individual & Information Officer
Email: zaf.key@wahed.com
Physical Address: Office 19, Third Floor, Arch Collab, 34 Whiteley Road, Melrose Arch, Johannesburg, Gauteng, 2196
11.2 Information Regulator
If you are dissatisfied with our response to a complaint or data subject request, you may lodge a complaint with:
The Information Regulator (South Africa)
Email: popia@inforegulator.org.za
Website: www.inforegulator.org.za
Postal Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Telephone: +27 10 023 5200
12. COMPANY INFORMATION
Company Name: Wahed Invest (Pty) Ltd
Registration Number: 2020/726348/07
FSP Number: 51684
Business Address: Office 19, Third Floor, Arch Collab, 34 Whiteley Road, Melrose Arch, Johannesburg, Gauteng, 2196
Website: www.wahed.com
13. THIRD-PARTY SERVICE PROVIDERS
Categories of service providers with whom we may share personal information:
- Financial Services Partners: Fund managers, custodians, administrators
- Regulatory Authorities: FSCA, FIC, SARS
- IT and Hosting Services: Cloud service providers, website hosting, cybersecurity firms
- Fraud Services: Fraud prevention agencies, sanctions screening providers
- Administrative Services: Document storage providers
- Other Service Providers: As necessary for service delivery and business operations
All service providers are subject to written service agreements requiring POPIA compliance and confidentiality obligations.
This Privacy Notice has been prepared in accordance with the Protection of Personal Information Act, 4 of 2013 (POPIA), and other applicable South African financial services laws and regulations.
Compiled by:
Moaaz Ismail – Key Individual & Information Officer
Wahed Invest (Pty) Ltd | FSP Number: 51684
Date: March 2026
Disclaimer: This Privacy Notice is provided for informational purposes. While compiled in accordance with current legal requirements, regulatory requirements may change. Wahed Invest reserves the right to update this notice as required by law or business necessity. Should there be any other information you are uncertain of, we will gladly assist and also provide relevant channels such as: https://inforegulator.org.za/popia-forms/
