Privacy Notice and POPIA Policy

Last updated: 28 August 2026. This notice explains how 4me collects, uses, stores, shares and protects personal information. It is a notice about our processing practices, not a contract that you accept merely by visiting our website or using our services.
→ 1. About this notice
For Me Financial Services (Pty) Ltd, trading as 4me Financial Services ("4me", "we", "us" or "our"), respects your privacy and is committed to protecting your personal information.
This notice applies when you visit our website, use the 4me platform or web application, apply for or use a financial product or service, interact with us through an employer or payroll service, or otherwise communicate with us.
We process personal information in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the National Credit Act 34 of 2005 ("NCA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA") and other applicable South African law. Where we determine why and how personal information is processed, 4me is the responsible party under POPIA.
This notice should be read with our terms of use, applicable product or credit agreements, PAIA Manual and any additional notice presented when particular information is collected.
→ 2. Who we are and how to contact us
Responsible party: For Me Financial Services (Pty) Ltd, trading as 4me Financial Services
Company registration number: 2024/347787/07
National Credit Regulator registration: NCRCP21222
Physical/contact address: Unit 47 Westlake Square, Westlake, Cape Town, 7945
Website: www.4mefs.com
Telephone: 010 109 5169
Email: info@4mefs.com
Information Officer: Damian Testa
Information Officer email: info@4mefs.com
Questions, objections and requests concerning personal information may be sent to our Information Officer using these details.
→ 3. Personal information we may collect
The information we collect depends on your relationship with 4me and the products or services you use. It may include:
Identity information: your name, identity number, date of birth, nationality and information reasonably needed to identify or verify you.
Contact information: your mobile number, email address, residential or postal address and communication preferences.
Employment and payroll information: your employer, employee number, job and employment status, remuneration, salary dates, payslips, leave information and information supplied through authorised payroll integrations.
Financial and credit information: income, expenditure, affordability information, bank and account details, transactions, applications, quotations, agreements, advances or loans, repayment history, credit history and information obtained from or supplied to registered credit bureaus.
Identity-verification and supporting information: identity documents, bank statements, payslips, proof of address, photographs, facial images or other verification results where these are required for lawful KYC, fraud-prevention or identity-verification processes.
Interaction information: enquiries, instructions, complaints, support correspondence and records of transactions or communications with us.
Technical and usage information: IP address, browser and device information, operating system, session and login activity, security events, audit records, application logs and information about use of our website and platform.
We do not intentionally collect information that is irrelevant or excessive for the purpose for which it is needed. Where special personal information or biometric information is processed, we will do so only when permitted by POPIA or another applicable law.
→ 4. Where we obtain personal information
We may obtain personal information directly from you when you visit our website, register or sign in, complete an application, provide documents, contact us or use our services.
Where permitted or required by law, we may also obtain information from:
your employer, payroll provider or another person authorised to provide information for the service;
registered credit bureaus and lawful credit-information sources;
financial institutions, payment providers and account-verification services;
identity-verification, KYC and fraud-prevention providers;
authorised business partners, public records, regulatory authorities and other lawful sources.
If you give us personal information about another person, you must be authorised to do so and must make this notice available to that person where required.
→ 5. Why we process personal information
We process personal information for specific purposes connected with our business and services, including to:
create, secure and administer your account, authenticate you, and send one-time passwords and security messages;
process enquiries and applications and verify the information you provide;
perform identity, eligibility, affordability, fraud-prevention, risk and credit assessments;
provide and administer payday advances, short-term loans, business funding, payroll and related services;
prepare quotations and agreements, facilitate payments and payroll deductions, collect repayments, maintain account records and enforce agreements;
communicate with your employer or payroll provider where needed to provide or administer the service;
obtain and supply credit information where permitted or required by law;
provide support and investigate enquiries, disputes and complaints;
prevent, detect and investigate fraud, misuse, security incidents and other unlawful activity;
comply with legislation, regulatory requirements, court orders and lawful requests, and establish, exercise or defend legal claims;
operate, protect, monitor, troubleshoot and improve our website, platform and services; and
send direct marketing where POPIA permits us to do so.
If information is required to enter into or perform a contract, or to meet a legal requirement, failure to provide it may mean that we cannot process an application, verify your identity, assess eligibility, open or maintain an account, or provide the requested service. We will identify optional information where reasonably practicable.
→ 6. When our processing is permitted
Depending on the circumstances, POPIA permits us to process personal information where:
you have consented to the processing;
processing is necessary to carry out actions for the conclusion or performance of a contract to which you are a party;
processing complies with an obligation imposed by law;
processing protects one of your legitimate interests;
processing is necessary for the proper performance of a public-law duty by a public body; or
processing is necessary to pursue a legitimate interest of 4me or a third party to whom the information is supplied, without unjustifiably interfering with your privacy.
We do not rely on your acceptance of this notice as blanket consent for every processing activity. Where we rely on consent, you may withdraw it subject to applicable law and processing that has already lawfully taken place. Withdrawal does not affect processing that is independently justified, including processing needed for contractual, credit, record-keeping or legal obligations.
→ 7. Credit checks, credit reporting and automated assessments
Where applicable to a product or service, we may obtain information from registered credit bureaus and other permitted sources to verify identity, assess affordability and creditworthiness, prevent fraud and administer a credit relationship. We may also provide information about an application, agreement, account or payment performance to registered credit bureaus where permitted or required by law.
We may use automated systems to assist with identity verification, fraud detection, eligibility, affordability, risk and credit assessments. Where a decision that has legal consequences or substantially affects you is made solely through automated processing in circumstances regulated by section 71 of POPIA, we will apply the safeguards required by law. Where applicable, you may request reconsideration or make representations and request sufficient information about the underlying logic to enable you to do so.
→ 8. Who we may share personal information with
We do not sell personal information. We may disclose it where reasonably necessary for the purposes described in this notice, including to:
employers and payroll providers where required to verify employment, provide payroll-related services or administer authorised deductions;
registered credit bureaus, credit-industry participants, identity-verification, KYC and fraud-prevention providers;
banks, payment services and other financial-service providers;
cloud hosting, document storage, software, information-technology, cybersecurity, support, email and SMS providers;
auditors, lawyers, debt-recovery providers and other professional advisers;
regulators, law-enforcement bodies, courts, government authorities and other persons where disclosure is permitted or required by law;
a buyer, investor or adviser in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality safeguards; and
other persons you authorise or where disclosure is otherwise permitted by law.
Service providers that process personal information for us are operators under POPIA where applicable. We require operators to process information only with our knowledge or authorisation, maintain confidentiality and implement appropriate security safeguards through written arrangements.
→ 9. Storage and transfers outside South Africa
Our services use cloud infrastructure outside South Africa. The application infrastructure is hosted using DigitalOcean in Frankfurt, Germany. Documents and other application data may be stored using Amazon Web Services S3 in Northern Virginia, United States of America. These providers and their approved subprocessors may process technical, account, document or service information as needed to provide their services.
When personal information is transferred outside South Africa, we take reasonable steps to ensure that the transfer complies with section 72 of POPIA. Depending on the transfer, this may include a binding agreement that requires the recipient to provide an adequate level of protection that is substantially similar to POPIA, a recipient subject to an adequately protective law or corporate rules, consent where legally appropriate, or another transfer ground permitted by POPIA.
Cloud regions, providers and subprocessors may change as our systems develop. If they do, we will continue to apply POPIA requirements and appropriate contractual, organisational and technical safeguards to international transfers.
→ 10. Direct marketing
We will send direct marketing by email, SMS or other electronic communication only as permitted by section 69 of POPIA. This generally means that you have consented, or that you are an existing customer and the communication concerns our own similar products or services under the conditions permitted by law.
Marketing communications will identify the sender and provide a simple way to opt out. You may object to or opt out of electronic direct marketing at any time, free of charge and without unnecessary formality. Service, security, account and legally required messages are not marketing and may still be sent where necessary.
→ 11. Cookies and technical information
Our website and platform use cookies and similar technologies that are necessary to provide sessions, authentication, security and core functionality. A cookie is a small data file stored by your browser or device.
We may also collect IP address, browser and device details, pages or functions used, dates and times, referring information and diagnostic or security events. This information may itself be personal information or become identifiable when combined with other information.
You can control cookies through your browser settings, but blocking cookies that are strictly necessary may prevent the website or platform from working correctly. If we introduce optional analytics or advertising cookies, we will provide any additional notice and choice required by law.
→ 12. Security
We use reasonable and appropriate technical and organisational measures to protect the integrity and confidentiality of personal information against loss, damage, unauthorised destruction, unlawful access or unlawful processing. Measures may include access controls, least-privilege permissions, authentication controls, encryption in transit and where appropriate at rest, logging and monitoring, backups, vulnerability management, incident procedures and contractual requirements for operators.
No internet transmission or storage system can be guaranteed to be completely secure. We therefore review risks and safeguards on an ongoing basis and update measures where reasonably required.
→ 13. Retention and deletion
We retain personal information only for as long as it is needed to achieve the purpose for which it was collected or subsequently lawfully processed, unless retention is required or authorised by law, reasonably required for lawful purposes related to our functions or activities, required by a contract, or consented to where legally appropriate.
Retention periods differ according to the record and may be affected by the NCA, financial and tax requirements, prescription periods, litigation or regulatory obligations. When retention is no longer permitted or required, information will be destroyed, deleted or de-identified in a manner that prevents reconstruction in an intelligible form.
→ 14. Your rights
Subject to POPIA, PAIA and other applicable law, you may:
ask whether we hold personal information about you and request access to it;
ask us to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, unlawfully obtained or no longer authorised to be retained;
object, on reasonable grounds relating to your particular situation, to processing under the grounds provided by POPIA;
object at any time to processing for direct marketing;
withdraw consent where processing depends on consent;
make representations about a regulated solely automated decision; and
lodge a complaint with us or the Information Regulator.
Requests may be sent to our Information Officer at info@4mefs.com. We may need to verify your identity before acting. Rights are not absolute: we may decline or limit a request where POPIA, PAIA, the NCA or another law permits or requires us to do so, and any prescribed fee will be explained before it is charged.
→ 15. Children
Our financial products and platform are not intended for persons under 18 years of age. We do not knowingly offer credit products to children. If we need to process a child's personal information for another lawful purpose, we will do so only as permitted by POPIA, including with the authorisation of a competent person where required.
→ 16. Security compromises
If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and notify the Information Regulator and affected data subjects as soon as reasonably possible, subject to section 22 of POPIA and any lawful restriction or exception. A notice may describe the possible consequences, measures taken or planned, recommendations to reduce potential harm and, where known, the identity of the unauthorised person.
→ 17. Third-party websites and services
Our website or platform may link to websites and services operated by third parties. Their privacy practices are governed by their own notices and are not under our control. We encourage you to review the applicable privacy information before providing personal information directly to a third party.
→ 18. Changes to this notice
We may update this notice when our processing practices, services or legal obligations change. The updated version will be published on this page with a revised "Last updated" date. If a change is material, we will take reasonable steps to bring it to the attention of affected persons.
→ 19. Complaints and the Information Regulator
Please contact our Information Officer first if you have a privacy concern so that we can try to resolve it. You also have the right to lodge a complaint with the Information Regulator (South Africa):
Information Regulator
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone: 010 023 5200
Toll-free: 0800 017 160
POPIA complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: inforegulator.org.za