Privacy Policy

Last updated: 1 February 2026

FutureFund ("we", "our", or "us") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. We are registered in South Africa and comply with the Protection of Personal Information Act (POPIA) and the requirements of the Financial Sector Conduct Authority (FSCA).

1. Information We Collect

We collect information that you provide directly to us, as well as information generated through your use of our platform.

Personal information you provide:

  • Full name, date of birth, and South African ID number (for KYC verification)
  • Email address and mobile phone number
  • Residential address and proof of address documentation
  • Banking details for deposits and withdrawals
  • Information about your children (name and date of birth) for education fund creation

Information collected automatically:

  • Device information (device type, operating system, browser)
  • IP address and approximate location
  • Usage data (pages visited, features used, transaction history)
  • Cookies and similar tracking technologies

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and education savings funds
  • Process deposits, withdrawals, and currency conversions
  • Comply with KYC (Know Your Customer) and AML (Anti-Money Laundering) regulatory requirements
  • Verify your identity as required by FSCA regulations
  • Communicate with you about your account, transactions, and platform updates
  • Improve our platform, develop new features, and analyse usage patterns
  • Prevent fraud, detect security threats, and protect against unauthorised activity
  • Comply with legal obligations and respond to lawful requests from authorities

3. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • Service providers: Third-party companies that help us operate our platform, including payment processors, identity verification providers, and cloud hosting services
  • Regulatory authorities: The FSCA, South African Revenue Service (SARS), and other regulatory bodies as required by law
  • Legal compliance: When required by law, subpoena, court order, or other legal process
  • Family contributors: When family members contribute to a child's fund, they can see the child's name and fund progress, but not your personal financial details

All third-party service providers are contractually obligated to protect your information and may only use it for the specific purposes we authorise.

4. Data Security

We implement industry-standard security measures to protect your personal information:

  • AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • Multi-factor authentication for account access
  • Regular security audits and penetration testing
  • Strict access controls limiting employee access to personal data on a need-to-know basis
  • Secure cloud infrastructure with SOC 2 Type II certified providers

While we take all reasonable precautions, no method of electronic transmission or storage is 100% secure. We continuously review and update our security practices to address emerging threats.

5. Your Rights Under POPIA

Under the Protection of Personal Information Act (POPIA), you have the following rights:

  • Right to access: Request a copy of the personal information we hold about you
  • Right to correction: Request correction of inaccurate or incomplete personal information
  • Right to deletion: Request deletion of your personal information, subject to our legal retention obligations
  • Right to object: Object to the processing of your personal information for direct marketing purposes
  • Right to data portability: Request your personal information in a structured, commonly used format
  • Right to lodge a complaint: File a complaint with the Information Regulator of South Africa

To exercise any of these rights, please contact our Information Officer using the details provided below. We will respond to your request within 30 days as required by POPIA.

6. Data Retention

We retain your personal information for as long as your account is active and as required to fulfil the purposes outlined in this policy. After account closure, we retain certain information for a minimum of five years as required by the Financial Intelligence Centre Act (FICA) and other applicable legislation. Transaction records are retained for the periods prescribed by SARS.

7. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact our Information Officer:

FutureFund Information Officer

Email: privacy@futurefund.co.za

Phone: +27 (0) 21 555 0100

Address: Cape Town, South Africa

You may also lodge a complaint with the Information Regulator of South Africa at inforeg.org.za.