Privacy NoticeREGNR8 FIN — by Infinite Risk

Privacy Notice

EvidenceExposuresDependenciesSequence
01

1. Responsible Party

Infinite Risk CC, registration number 1996/014584/23, is the Responsible Party for personal information collected through the public Infinite Risk website where it determines the purpose and means of processing. Privacy and PAIA enquiries may be sent to regnr8-fin@infiniterisk.com.

02

2. Information collected through the public website

The public enquiry form is designed to collect only: name; email address; optional telephone number; optional country/region; enquiry route; a brief message; privacy acknowledgement; and technical anti-abuse information. It does not provide a document-upload facility and is not designed to collect policy schedules, investment statements, identity documents, bank account details or other sensitive financial records.

03

3. Why we process it

Personal information may be processed to receive and respond to an enquiry, route the enquiry to the appropriate person, maintain necessary correspondence, prevent abuse and protect the website, comply with legal or regulatory duties, and establish, exercise or defend legal rights where necessary.

04

4. Processing conditions

Infinite Risk processes personal information only where permitted by POPIA and applies purpose limitation, data minimisation and reasonable safeguards. Depending on the circumstances, processing may be based on consent, steps taken at a data subject's request, a legal obligation, or a legitimate interest recognised by POPIA.

05

5. Marketing

Submitting an enquiry does not enrol the visitor in a marketing list. At launch, the public enquiry form does not include marketing consent. If direct electronic marketing is introduced, it must be managed separately in accordance with POPIA and applicable consent or existing-customer rules, including an effective opt-out mechanism.

06

6. Service providers

The website and current enquiry email infrastructure are hosted through Hostinger services. Other operators may be used only where required for the relevant service. If analytics, CRM, scheduling, marketing or other providers are added, this notice and the website's technical controls must be reviewed before deployment.

07

7. Cross-border processing

Some service providers may process personal information in countries outside South Africa. Where a cross-border transfer occurs, Infinite Risk will apply the requirements of section 72 of POPIA and use appropriate contractual, legal or other safeguards.

08

8. Retention

Website enquiry correspondence should ordinarily be retained for no longer than 24 months after the last substantive interaction unless a longer period is required by law, an applicable FSP record-retention rule, a complaint, dispute or other legitimate need. PII-safe technical logs should ordinarily be retained for no longer than 90 days unless a security event or legal requirement justifies longer retention. If an enquirer becomes a client, client and regulated records are retained under the applicable FSP and legal record-retention rules.

09

9. Security

Infinite Risk applies reasonable technical and organisational safeguards appropriate to the information processed. The public form is deliberately not a secure financial-document intake channel. If there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, Infinite Risk will investigate and make notifications required by POPIA.

10

10. Automated decisions and AI

The public website does not make a decision about a visitor based solely on automated processing that has legal or similarly significant effects. Enquiry-form information is not intended to be automatically converted into a personalised financial recommendation. The REGNR8 FIN intelligence architecture is described separately in the Data & AI Governance notice.

11

11. Cookies and analytics

At launch, the website is intended to use only technical storage necessary to operate the site and no approved marketing or analytics tracking layer. A final production technical check is required. If non-essential analytics or marketing technologies are introduced, appropriate notice and consent controls must be implemented before activation.

12

12. Your rights

Subject to POPIA and applicable law, a data subject may request access to personal information, request correction or deletion where legally available, object to certain processing, withdraw consent where processing is based on consent, and complain to Infinite Risk or the Information Regulator.

13

13. Information Regulator

Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. General telephone: 010 023 5200. Toll-free: 0800 017 160. General enquiries: enquiries@inforegulator.org.za. POPIA complaints: POPIAComplaints@inforegulator.org.za. Check the Regulator's website for current channels before lodging.

14

14. Changes

This Privacy Notice will be reviewed when the website's processing changes, when new vendors or marketing technologies are introduced, or when legal or regulatory requirements change. Last updated: 31 August 2026.