Privacy Policy

Privacy Policy

Digi Ex Pro (Pty) Ltd — Crypto Asset Service Provider

Digi Ex Pro (Pty) Ltd — Privacy Notice (South Africa)

Last revision: 28 May 2026

1. Scope

This Privacy Notice explains how Digi Ex Pro (Pty) Ltd processes personal information when you visit our website, create an account, use our services (including any crypto-asset exchange, transfer, custody or related services we offer), contact us, or otherwise interact with us online. It explains your rights under the Protection of Personal Information Act 4 of 2013 (POPIA) and, where you are located in the European Union or the European Economic Area (EEA), the additional rights you have under the EU General Data Protection Regulation (GDPR). Because the Company predominantly serves clients outside South Africa, this Notice is written to operate under South African law while giving effect to equivalent protections for clients and data subjects abroad.

2. Responsible Party and contact details

For the purposes of POPIA, the Responsible Party (equivalent to the “data controller” under the GDPR) is:

Digi Ex Pro (Pty) Ltd, registration number 2023/150340/07, registered office at 1 Hood Avenue, Rosebank, Johannesburg, Gauteng, 2196, South Africa.

  • Information Officer / Data Protection contact: privacy@zione.com
  • General contact: support@zione.com

The Company’s Information Officer is registered with the Information Regulator (South Africa) in accordance with POPIA.

3. Categories of personal information we process

Depending on how you use our website and services, we may process:

  • Identification and contact data: name, e-mail address, telephone number, residential or business address, date of birth, nationality and identity- or passport-document data.
  • Account and service data: username, account identifiers, settings, support tickets and communication history.
  • Transaction and financial data: transaction identifiers, crypto-asset wallet addresses, deposit and withdrawal details, payment references, bank-account details and related records.
  • KYC/AML data: identity-verification results, source-of-funds and source-of-wealth information, and politically-exposed-person and sanctions-screening results, as required by the Financial Intelligence Centre Act 38 of 2001 (“FIC Act”).
  • Technical and usage data: IP address, device identifiers, browser type, operating system, referrer URL, timestamps and similar log data.
  • Cookies / analytics data: identifiers and events collected via cookies or similar technologies (only where you have consented to non-essential cookies — see Section 9).

4. Purposes and lawful bases of processing

We process personal information for the following purposes, relying on the justifications for lawful processing in section 11 of POPIA (and, for EU/EEA data subjects, the corresponding lawful bases in Article 6 of the GDPR):

4.1 Website operation and security. To operate the website, ensure information security, prevent fraud and abuse, and maintain logs — based on our legitimate interests (POPIA s11(1)(f); GDPR Art 6(1)(f)).

4.2 Account creation and service delivery. To create and manage your account, provide our services, process your requests and instructions, provide support and communicate service updates — necessary for the conclusion or performance of a contract with you (POPIA s11(1)(b); GDPR Art 6(1)(b)).

4.3 Legal and regulatory compliance (including AML/CFT). To comply with our legal obligations — including the FIC Act, the Financial Advisory and Intermediary Services Act 37 of 2002 (“FAIS Act”), tax and accounting law, and sanctions obligations — to respond to lawful requests by competent authorities, and to keep records required by law (POPIA s11(1)(c); GDPR Art 6(1)(c)).

4.4 Communication and handling enquiries. To respond to messages, process complaints and maintain correspondence — based on contract or our legitimate interests, depending on the context.

4.5 Analytics and improving our website (consent only). To understand website performance and usage in order to improve it — based on your consent (POPIA s11(1)(a); GDPR Art 6(1)(a)). You may withdraw consent at any time (Section 9).

4.6 Direct marketing. To send newsletters or marketing communications — based on your consent, in accordance with section 69 of POPIA (and, for electronic marketing, the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”) and the Consumer Protection Act 68 of 2008 (“CPA”)).

5. Special personal information and children

We do not seek to collect special personal information (as defined in POPIA) unless it is necessary and permitted by law. We do not knowingly process the personal information of children (persons under 18); our services are available only to persons aged 18 or older.

6. Whether providing personal information is mandatory

Some personal information is required to provide the services and to meet our legal obligations (for example, account, transaction and KYC/AML data). If you do not provide it, we may be unable to open an account, complete a transaction, or continue a business relationship. Where processing is based on consent, providing the information is voluntary and you may withdraw consent at any time without affecting processing carried out before the withdrawal.

7. Recipients of personal information (operators and third parties)

We may share personal information with:

  • Operators (processors) that support us — including hosting, IT and security providers, customer-support tools, analytics providers (where consent applies), e-mail/SMS delivery, electronic identity-verification and sanctions/PEP screening providers (for example Ondato UAB), and blockchain-analytics providers (for example Elliptic).
  • Professional advisers (lawyers, auditors) where necessary.
  • Competent authorities and law enforcement — including the Financial Intelligence Centre, the Financial Sector Conduct Authority and the South African Revenue Service — where we are legally required to disclose information or to protect our rights.

We require operators to process personal information only on our written instructions and to apply appropriate, reasonable security safeguards, in accordance with sections 20–21 of POPIA.

8. Cross-border transfers of personal information

Because we serve clients outside South Africa and use international service providers, personal information may be transferred to, or processed in, countries outside South Africa (and outside the EEA), including the European Union and the United States. Where we transfer personal information across borders, we do so in accordance with section 72 of POPIA — that is, only where the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection, where you have consented, or where the transfer is necessary for the performance or conclusion of a contract in your interest. For transfers of EU/EEA personal data, we additionally rely on an adequacy decision or the European Commission’s Standard Contractual Clauses (SCCs), together with appropriate supplementary safeguards. You may request further information about the safeguards applied to a specific transfer using the contact details in Section 2.

9. Cookies and similar technologies

9.1 Strictly necessary cookies. These are required for the website to function (for example, security and session management) and do not require consent.

9.2 Analytics cookies (consent only). We use analytics tools (for example Google Analytics 4) to understand how users interact with our website, and these are enabled only if you consent through our cookie banner / consent-management platform. If you do not consent, analytics cookies are not set.

9.3 Managing consent. Our cookie banner allows you to accept, reject or customise non-essential cookies, and you can change your preferences at any time via the cookie-settings link on our website. Withdrawing consent does not affect processing carried out before the withdrawal. You may also manage cookies through your browser settings; blocking strictly necessary cookies may affect website functionality. The use of cookies and similar technologies is consistent with POPIA and ECTA.

10. Server logs and IP addresses

When you visit our website, we (or our hosting provider) process server logs such as IP address, timestamps, device and browser information, and the pages requested. We use this to operate the website, maintain security, prevent abuse and troubleshoot incidents, based on our legitimate interests.

11. Retention of personal information

We keep personal information only for as long as necessary for the purposes described above and as required by law, including:

  • Website / server logs: up to 90 days, unless required longer for a security investigation.
  • Account data: for the duration of the account and afterwards as required for legal compliance and dispute handling.
  • Support communications: up to 5 years, depending on the nature of the enquiry and applicable prescription periods.
  • KYC/AML and transaction records: for at least 5 years after the end of the business relationship or the conclusion of a transaction, as required by sections 22–24 of the FIC Act, and longer where required for proceedings or audits.

Retention is applied in accordance with section 14 of POPIA.

12. Security safeguards and breach notification

In accordance with sections 19–22 of POPIA, we maintain appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information and to prevent loss, damage, unauthorised access or processing. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects as soon as reasonably possible, in accordance with section 22 of POPIA.

13. Your rights

Under POPIA (and, for EU/EEA data subjects, the GDPR) you have the right to:

  • request access to the personal information we hold about you, and details of third parties who have had access to it (POPIA s23; s11(3) of PAIA where applicable);
  • request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (POPIA s24);
  • object, on reasonable grounds, to the processing of your personal information (POPIA s11(3));
  • withdraw consent where processing is based on consent;
  • request erasure or destruction of personal information that we are no longer authorised to retain; and
  • (for EU/EEA data subjects) the additional GDPR rights of restriction of processing and data portability.

You can exercise your rights using the contact details in Section 2. We may need to verify your identity before responding.

14. Direct marketing

We will send you electronic direct marketing only where you have consented or as otherwise permitted by section 69 of POPIA, ECTA and the CPA. You may opt out of direct marketing at any time, free of charge, using the unsubscribe mechanism in the communication or by contacting us.

15. Right to lodge a complaint (Information Regulator)

If you believe that we have processed your personal information in breach of POPIA, you have the right to lodge a complaint with the Information Regulator (South Africa):

  • Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 (P.O. Box 31533, Braamfontein, 2017).
  • Complaints e-mail: POPIAComplaints@inforegulator.org.za (complaints are submitted in writing, using POPIA Form 5).
  • General enquiries: enquiries@inforegulator.org.za

If you are an EU/EEA data subject, you may also lodge a complaint with the supervisory authority in your country of residence.

16. Automated decision-making and profiling

In accordance with section 71 of POPIA, we do not make decisions based solely on the automated processing of your personal information that result in legal consequences for you or that substantially affect you, unless this is necessary for entering into or performing a contract, is authorised by law, or is based on your consent. Where we use automated checks (for example, fraud, sanctions or compliance screening), we apply appropriate safeguards and allow you to request human review where required by law.

17. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. The latest version will be published on our website with the revision date shown above.


Digi Ex Pro (Pty) Ltd

Privacy Policy — South Africa Addendum

Last revised: 24th June 2026 — Version 1.1

Supplementary clauses addressing South African law requirements under POPIA and related legislation, for publication on the Company website.

These supplementary clauses form part of, and must be read together with, the Digi Ex Pro (Pty) Ltd Privacy Notice last revised 28 May 2026. They address requirements under the Protection of Personal Information Act 4 of 2013 (“POPIA”) and related South African legislation. In the event of any inconsistency between these clauses and the main Privacy Notice, these clauses prevail to the extent of the inconsistency.

A. Information Officer

In accordance with section 55 of POPIA, the Company’s registered Information Officer is:

Name: Deivile Diliute Lenciauskiene

Role: Information Officer

E-mail: privacy@zione.com

Postal address: 1 Hood Avenue, Rosebank, Johannesburg, Gauteng, 2196, South Africa

The Information Officer is registered with the Information Regulator (South Africa) as required by POPIA. The Information Officer is responsible for:

  • encouraging and ensuring compliance with POPIA across the Company;
  • dealing with requests made by data subjects under POPIA;
  • working with the Information Regulator in relation to investigations; and
  • ensuring that the Company’s processing of personal information is conducted lawfully and transparently.

All data subject rights requests, privacy enquiries and complaints should be directed to the Information Officer at the e-mail address above. The Company will acknowledge receipt of any request within 3 business days.

B. The Eight Conditions for Lawful Processing

POPIA prescribes eight conditions for the lawful processing of personal information (sections 8–25). The Company processes personal information only where all applicable conditions are satisfied. Below is a summary of how each condition applies in practice.

B.1 Accountability (section 8)

The Information Officer (Section A above) is accountable for ensuring compliance with all conditions for lawful processing. The Company maintains an internal Record of Processing Activities (“RoPA”) documenting each processing activity, its purpose, lawful basis, data categories, retention period and security measures. The RoPA is reviewed at least annually.

B.2 Processing Limitation (sections 9–11)

Personal information is processed only:

  • in a manner that does not infringe the privacy of the data subject;
  • for a specific, explicitly defined and legitimate purpose related to the Company’s crypto-asset exchange and related services;
  • where the data subject has consented or another lawful ground applies (see Section 4 of the main Privacy Notice); and
  • in a way that is adequate, relevant and not excessive relative to the purpose. For example, KYC identity documents are collected only to the extent required by the FIC Act and are not used for any other purpose.

B.3 Purpose Specification (section 13)

Personal information is collected for a specific, explicitly defined and lawful purpose. Data subjects are informed of the purpose at or before the time of collection through this Privacy Notice, supplementary collection notices, and the account registration process. Personal information is not processed for any purpose other than the purpose for which it was collected unless a further processing ground exists under section 15 of POPIA.

B.4 Further Processing Limitation (section 15)

If the Company intends to use personal information for a purpose beyond the original collection purpose, it will assess compatibility under section 15(3) of POPIA, having regard to the relationship between the purposes, the nature of the information, the consequences of further processing, and the safeguards applied. Where further processing is incompatible, a separate lawful ground will be established before processing proceeds.

B.5 Information Quality (section 16)

The Company takes reasonable steps to ensure that personal information is complete, accurate, not misleading and kept up to date. Data subjects are encouraged to notify the Company of any changes to their personal information by contacting the Information Officer or updating their account settings. Where the Company becomes aware that information is inaccurate, it will correct it promptly.

B.6 Openness (sections 17–18)

The Company maintains documentation of all processing operations as required by section 17 of POPIA. Before or at the time of collection, data subjects are notified of the matters required by section 18, including the identity of the responsible party, the purpose of collection, whether supply is voluntary or mandatory, the consequences of not supplying information, and the data subject’s rights. This Privacy Notice and any supplementary collection notices constitute that notification.

B.7 Security Safeguards (sections 19–22)

See Section 12 of the main Privacy Notice. The Company maintains appropriate technical and organisational measures including encryption of data in transit and at rest, access controls, regular security assessments, and incident response procedures. In the event of a security compromise, the Company will notify the Information Regulator and affected data subjects as soon as reasonably possible in accordance with section 22 of POPIA.

B.8 Data Subject Participation (sections 23–25)

Data subjects may request access to, correction of, deletion of, or object to the processing of their personal information at any time. Response timeframes are set out in Section C below. Where a request is refused, the Company will provide written reasons and advise the data subject of their right to complain to the Information Regulator.

C. Response Timeframes for Rights Requests

C.1 Timeframes

When a data subject submits a request to exercise any of the rights set out in Section 13 of the main Privacy Notice, the Company will:

  • acknowledge receipt within 3 business days;
  • provide a full response within 30 calendar days of receipt of a complete and valid request, in accordance with section 23(3) of POPIA; and
  • for complex requests requiring additional time, notify the data subject within the initial 30-day period with an estimated completion date, which will not exceed a further 30 days without the data subject’s agreement.

C.2 Identity Verification

To protect the security of personal information and prevent unauthorised disclosure, the Company may require the data subject to verify their identity before a request is processed. Verification requirements will be proportionate and not unduly burdensome. The Company will specify what is required at the time of the request.

C.3 Refusal of Requests

If the Company refuses a rights request, it will notify the data subject in writing, setting out the reason for the refusal and advising the data subject of the right to lodge a complaint with the Information Regulator (see Section 15 of the main Privacy Notice for contact details).

D. Cross-Border Transfers — Additional Disclosure

This section supplements Section 8 of the main Privacy Notice. Transfers of personal information across South African borders are made in accordance with section 72 of POPIA.

D.1 Destination Countries and Service Providers

Personal information may be transferred to, or accessed from, the following countries through the service providers listed:

European Union / EEA — Ondato UAB (identity verification and KYC screening, Lithuania); hosting and IT infrastructure providers. Safeguard: adequacy — EU member states are recognised as providing adequate protection under applicable frameworks.

United Kingdom — Elliptic (blockchain analytics). Safeguard: binding data processing agreement providing protections equivalent to POPIA.

United States of America — Google LLC (Google Analytics 4, analytics cookies). Safeguard: binding data processing agreement incorporating standard contractual clauses and appropriate supplementary measures.

Other countries — where necessary from time to time for service delivery, the Company will ensure a lawful transfer ground under section 72 of POPIA exists before transfer and will update this notice accordingly.

Data subjects may request further information about the safeguards applied to a specific transfer by contacting the Information Officer at privacy@zione.com.

D.2 Operator Obligations

All third-party recipients acting as operators are required by written agreement to:

  • process personal information only on the Company’s documented instructions;
  • implement appropriate, reasonable technical and organisational security measures;
  • not engage sub-operators without prior written authorisation from the Company; and
  • notify the Company promptly of any actual or suspected security compromise involving the Company’s personal information.

E. Cookie Policy — Full Disclosure

This section supplements Section 9 of the main Privacy Notice and provides the full cookie disclosure required under POPIA and the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”).

E.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They may be first-party (set by us directly) or third-party (set by service providers on our behalf). They may be session cookies (which expire when you close your browser) or persistent cookies (which remain on your device for a defined period after your visit ends).

E.2 Cookie Register

The following cookies are currently used on the Company’s website:

Category: Strictly Necessary

  • Purpose: Session management, security (CSRF protection), remembering your cookie consent choice
  • Party: First-party
  • Examples: session_id, csrf_token, cookie_consent
  • Lifespan: Session (expires on browser close) or up to 24 hours
  • Consent required: No — these are essential for the website to function

Category: Analytics (Google Analytics 4)

  • Purpose: Understanding how visitors interact with our website — pages visited, time spent, referral sources — in order to improve performance and user experience
  • Party: Third-party (Google Ireland Ltd / Google LLC)
  • Cookie names: _ga, _ga_[container-id]
  • Lifespan: _ga — 13 months; _ga_[container-id] — 13 months (persistent)
  • Consent required: Yes — analytics cookies are not set unless you consent via the cookie banner. If you do not consent, no analytics data is collected.

Note: The cookie register is reviewed and updated whenever the Company adds, changes or removes cookies. The revision date at the top of this document reflects the most recent review.

E.3 Third-Party Data Processing

Where Google Analytics 4 is active (consent given), Google Ireland Ltd and Google LLC may process information about your use of the website in accordance with Google’s privacy policy (policies.google.com/privacy). The Company has configured Google Analytics 4 with IP anonymisation enabled, which means your full IP address is not stored by Google. The Company does not sell analytics data to any third party.

E.4 Managing Your Cookie Preferences

  • Cookie banner: When you first visit the website, a consent banner allows you to accept or reject non-essential cookies. You can change your preferences at any time using the cookie settings link in the website footer.
  • Browser settings: Most browsers allow you to refuse or delete cookies through their settings. Note that blocking strictly necessary cookies may affect website functionality.
  • Google Analytics opt-out: You may install the Google Analytics Opt-out Browser Add-on, available at tools.google.com/dlpage/gaoptout, to prevent your data from being used by Google Analytics across all websites.
  • Withdrawing consent: Withdrawing consent does not affect any processing carried out before the withdrawal.

F. Special Personal Information and KYC/AML

The main Privacy Notice states that the Company does not seek to collect special personal information (as defined in section 26 of POPIA). However, in the course of KYC/AML screening conducted under the Financial Intelligence Centre Act 38 of 2001 (“FIC Act”), the Company may incidentally process information that falls within the definition of special personal information, including:

  • criminal behaviour or alleged criminal offences (for example, adverse media screening results relating to financial crime); and
  • information concerning a data subject’s political views or affiliations (for example, politically exposed person (“PEP”) screening results).

Where the Company processes such information, it does so:

  • to the extent strictly necessary to comply with a legal obligation (FIC Act sections 21–22B) section 27(1)(a) of POPIA; and
  • where the information has been made public by the data subject or in publicly available sources: section 27(1)(d) of POPIA.

Such information is processed only for compliance screening purposes, retained for the minimum period required by the FIC Act (at least 5 years), and is not used for any other purpose.

G. Automated Processing and Compliance Screening

This section supplements Section 16 of the main Privacy Notice with additional detail about the Company’s automated compliance screening processes.

G.1 Automated Screening Activities

The Company uses automated tools as part of its AML/CFT and fraud-prevention obligations, including:

  • Identity verification and liveness checks (Ondato UAB) — automated checks to verify that identity documents are genuine and that the person submitting them is present;
  • Sanctions and PEP screening (Ondato UAB) — automated comparison of client details against international sanctions lists and PEP databases; and
  • Blockchain analytics (Elliptic) — automated risk scoring of crypto-asset wallet addresses and transactions to identify exposure to illicit activity.

G.2 Consequences and Human Review

Results from the above automated processes may affect whether the Company is able to open an account, complete a transaction, or continue a business relationship. Where an automated check produces a result that would substantially affect a data subject (for example, a potential sanctions match or a high-risk blockchain score), the Company applies the following safeguards:

  • a trained compliance officer reviews the automated result before any adverse decision is taken;
  • the data subject is notified where legally permissible that a review is taking place; and
  • the data subject may submit additional information or representations before a final decision is made, unless disclosure is prohibited by law (for example, tipping-off restrictions under the FIC Act).

Where a final adverse decision is taken following human review, the Company will inform the data subject to the extent permitted by law.

H. Direct Marketing — All Electronic Channels

This section supplements Sections 4.6 and 14 of the main Privacy Notice and sets out the Company’s approach to electronic direct marketing across all channels, including e-mail, SMS and WhatsApp.

H.1 Consent Requirement

The Company sends electronic direct marketing only where:

  • the data subject has given prior, specific, informed and voluntary consent; or
  • the data subject is an existing client and the communication relates to similar products or services to those previously provided, and the data subject was given a clear opportunity to opt out at the time their details were collected and in every subsequent communication (the “section 69 exception” under POPIA).

H.2 Channel-Specific Requirements

E-mail (POPIA s69; ECTA s45): Every marketing e-mail will clearly identify Digi Ex Pro (Pty) Ltd as the sender, include a valid reply-to address, and include a functioning unsubscribe link.

SMS (POPIA s69; ECTA s45): Every marketing SMS will identify the Company and include an opt-out instruction (e.g. “Reply STOP to unsubscribe”). The Company will provide a free opt-out mechanism where operationally possible.

WhatsApp and OTT messaging (POPIA s69; ECTA s45): WhatsApp and similar over-the-top messaging channels are treated as electronic communications for the purposes of POPIA and ECTA. The same consent, identification and opt-out requirements apply. Where WhatsApp Business is used, communications are also subject to Meta’s platform policies.

H.3 How to Opt Out

You may opt out of any or all electronic marketing channels at any time, free of charge and without detriment, by:

  • clicking the unsubscribe link in any marketing e-mail;
  • replying STOP (or the opt-out keyword stated in the message) to any marketing SMS or WhatsApp message;
  • e-mailing support@zione.com or privacy@zione.com and specifying the channel(s) from which you wish to unsubscribe; or
  • updating your communication preferences in your account settings (where available).

Opt-out requests will be actioned within 5 business days. After opting out you may still receive transactional or service communications necessary for the performance of your contract.

H.4 Consent Records

The Company maintains records of direct-marketing consents and opt-outs for a minimum of 3 years after the consent was given or the opt-out was received, in accordance with section 69(4) of POPIA and section 45 of ECTA.

I. Business Transfers

If the Company is involved in a merger, acquisition, sale of assets, restructuring or winding-up in which personal information constitutes or forms part of the transferred assets, the Company will:

  • notify affected data subjects at least 30 days in advance where practically possible, by direct communication to the contact details held and by publishing a notice on the Company’s website;
  • ensure that any acquirer or successor entity is contractually bound by obligations at least equivalent to those in this Privacy Notice before any transfer of personal information takes effect;
  • ensure that a lawful basis for the transfer exists under POPIA before proceeding; and
  • where the transaction does not proceed or the acquirer does not require the personal information, ensure that the personal information is securely returned or destroyed and that the data subject is notified accordingly.

Data subjects have the right to object to the processing of their personal information in connection with a business transfer, subject to any overriding legal requirements. Objections should be directed to the Information Officer at privacy@zione.com.

J. Scope of This Notice

This Privacy Notice and the supplementary clauses above apply to clients, prospective clients, website visitors and other individuals whose personal information is processed by Digi Ex Pro (Pty) Ltd in the course of its business activities. They do not apply to the personal information of employees, contractors or job applicants, which is governed by a separate HR Privacy Notice available on request from privacy@zione.com.

K. Effective Date, Version Control and Review

These supplementary clauses will be updated whenever the Company’s processing activities, service providers, or applicable law change materially. The revised version, with an updated revision date, will be published at the same permanent URL on the Company’s website. Where changes are material, the Company will notify data subjects directly where practicable.

Digi Ex Pro (Pty) Ltd — Registration number 2023/150340/07 — 1 Hood Avenue, Rosebank, Johannesburg, 2196, South Africa — privacy@zione.com