Compliance · Personal information
Privacy Policy
This Privacy Policy explains how OneCompare (Pty) Ltd — an authorised Financial Services Provider (FSP 55551) — collects, uses, shares, secures, and retains your personal information when you use our car insurance comparison and policy review services. It is published in compliance with the Protection of Personal Information Act, 4 of 2013, and other applicable South African legislation.
Contents
- 1.Who this policy applies to
- 2.Our role and what makes us different
- 3.The legislation that governs how we handle your information
- 4.The personal information we collect
- 5.How we collect your personal information
- 6.Why we process your personal information (lawful purposes)
- 7.Direct marketing and your choices
- 8.When and with whom we share your personal information
- 9.Transfers of personal information outside South Africa
- 10.How we secure your personal information
- 11.Your rights under POPIA
- 12.Cookies and similar technologies
- 13.How long we keep your personal information
- 14.Changes to this Privacy Policy
- 15.Information Officer and how to contact us
- 16.The Information Regulator (South Africa)
- →Quick reference: how to reach us
1.Who this policy applies to
In this Privacy Policy, "OneCompare", "we", "us", and "our" refer to OneCompare (Pty) Ltd, an authorised Financial Services Provider (FSP 55551) authorised by the Financial Sector Conduct Authority (FSCA) under the Financial Advisory and Intermediary Services Act, 2002 ("FAIS"). Our registered office is at 377 Rivonia Boulevard, Rivonia, Johannesburg, Gauteng 2191, South Africa.
This policy applies to all personal information we obtain through our website at www.onecompare.co.za, our quote and policy review services, our email and telephone interactions with you, and any other channel through which you engage with us. By using our services or providing your personal information to us, you confirm that you have read and understood this policy.
2.Our role and what makes us different
OneCompare is a car insurance comparison service. We primarily act as an intermediary as defined in FAIS. When you obtain a quote through OneCompare, the actual insurance contract is concluded between you and the insurer of your choice, and your premium is paid directly to that insurer.
Our role is to help you compare cover and pricing across multiple insurers, to provide a free policy review service, and to facilitate your appointment with the insurer you select. We carry Professional Indemnity (PI) and Fidelity insurance as required of FSPs under the FAIS Act and the FSCA Conduct Standards.
3.The legislation that governs how we handle your information
We process your personal information in accordance with the laws of the Republic of South Africa, in particular:
- The Protection of Personal Information Act, 4 of 2013 ("POPIA"), which sets out the conditions for lawful processing of personal information in South Africa.
- The Financial Advisory and Intermediary Services Act, 37 of 2002 ("FAIS"), together with the General Code of Conduct for Authorised Financial Services Providers and Representatives, 2003.
- The Electronic Communications and Transactions Act, 25 of 2002 ("ECTA"), which regulates electronic communications, electronic signatures, and direct marketing through electronic means.
- The Consumer Protection Act, 68 of 2008 ("CPA"), where applicable.
- The Financial Intelligence Centre Act, 38 of 2001 ("FICA"), where its identity-verification and record-keeping obligations apply.
- The Insurance Act, 18 of 2017, and the Policyholder Protection Rules made under the Short-Term Insurance Act and the Insurance Act.
4.The personal information we collect
We only collect personal information that is necessary for the purposes set out in this policy. The categories of personal information we may collect include:
4.1Identification and contact information
- Your full name, surname, identity or passport number where required by an insurer for quoting or policy issue.
- Your date of birth, marital status, and occupation where relevant to the cover being quoted.
- Your contact details: telephone number, email address, residential and postal address.
4.2Information about your vehicle and intended cover
- Vehicle make, model, year, registration number, engine and VIN where required, modifications, garaging address, and typical usage pattern.
- Details of regular drivers, including age and licence information.
- Existing cover details from your current policy schedule (where you provide these for the policy review service).
- Information about previous claims, losses, or convictions where required by the insurer underwriting the cover.
4.3Communication and service records
- The content of emails, messages, callback requests, and other communications you send to us.
- Recordings of telephone calls where you contact us by phone (we will tell you at the start of the call if it is being recorded).
- Records of quotes obtained, policy reviews issued, and instructions you have given us in the course of our service.
4.4Website and technical information
- Standard server log information including your IP address, browser type, operating system, the pages you visit, and the date and time of your visit.
- Cookie information as described in section 12 below.
- Information about the device you use to access our website, where this is relevant to site performance and security.
5.How we collect your personal information
We collect personal information directly from you when you submit a quote request, request a policy review, contact us by email, phone, or web form, or otherwise interact with our services. We may also receive personal information from:
- Insurance partners that we have introduced you to, where the introduction has resulted in a policy and ongoing administration.
- Public sources such as the deeds office, vehicle registers, and credit information bureaus, but only where this is necessary and lawful for the service you have requested.
- Third parties acting on your behalf, such as a broker or family member, where you have authorised them to act for you.
6.Why we process your personal information (lawful purposes)
In accordance with section 11 of POPIA, we process your personal information for one or more of the following lawful purposes:
- To obtain quotes from our panel of insurance partners on your behalf, so that you can compare cover and pricing.
- To produce the free policy review that you have requested, including a comparison of your existing cover against alternatives in the market.
- To facilitate your appointment with the insurer you select, including transmitting your information to that insurer to enable them to issue the policy.
- To respond to your enquiries, complaints, callback requests, and other communications.
- To comply with our regulatory obligations under FAIS, POPIA, FICA, the Insurance Act, and other applicable law (including record-keeping for a minimum of five years).
- To detect and prevent fraud, including the use of risk information bureaus where appropriate.
- To improve our services, including analysing aggregate website usage so that we can make our content more useful to drivers.
- For direct marketing of our own services to existing clients, where you have not opted out (see section 7 below).
7.Direct marketing and your choices
We respect your right under section 69 of POPIA to decide whether you receive direct marketing communications from us.
7.1Existing clients
If you are an existing client and you have provided your contact details in the course of obtaining a quote or service from us, we may send you direct marketing about our own products and services that are similar to what you have already received. You may opt out of this marketing at any time, free of charge and without giving any reason, by clicking the unsubscribe link in any marketing email or by emailing legal@onecompare.co.za.
7.2New marketing through electronic channels
For direct marketing through electronic channels (email, SMS, WhatsApp) that does not fall within section 7.1, we will only send you communications if you have given prior consent. You can withdraw consent at any time using the channels above.
7.3Marketing by our partners
Where you choose to engage with one of our insurance partners through our service, that partner will conduct its own direct marketing in accordance with its own privacy policy. We do not sell your personal information to any third party for that party’s independent marketing purposes.
9.Transfers of personal information outside South Africa
Some of the operators we use to deliver our services (for example, email and analytics providers) are based outside South Africa. Where we transfer your personal information across the border, we do so only in accordance with section 72 of POPIA, which means one or more of the following must apply:
- The third party to which the information is being transferred is subject to a law, binding corporate rules, or binding agreement that provides an adequate level of protection effectively similar to POPIA.
- You have consented to the transfer.
- The transfer is necessary for the performance of a contract between you and us, or for the conclusion or performance of a contract concluded in your interest with a third party.
- The transfer is for your benefit and it is not reasonably practicable to obtain your consent, and if it were reasonably practicable, you would be likely to give it.
10.How we secure your personal information
We have implemented appropriate, reasonable technical and organisational security measures to protect your personal information against loss, damage, unlawful access, and unauthorised destruction or alteration, as required by section 19 of POPIA. These include:
- Encryption of data in transit using TLS for our website and our communications with insurance partners.
- Access controls so that only authorised employees and operators can access personal information, and only for the purposes for which they are authorised.
- Logging and monitoring of system access, with reviews of unusual activity.
- Confidentiality undertakings from all employees and contractors who handle personal information.
- Periodic review of our security measures and our operators’ security measures.
While we take security seriously, no electronic communication system is perfectly secure. We cannot guarantee the security of information transmitted to us over the internet, although we will act promptly and in accordance with our obligations under POPIA if a security compromise occurs.
11.Your rights under POPIA
POPIA gives you rights in respect of your personal information. These include:
- The right to be notified that your personal information is being collected and that there has been any unauthorised access to your information.
- The right to access your personal information that we hold, and to be given the identities of third parties to whom we have disclosed it.
- The right to request the correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained.
- The right to object to the processing of your personal information on reasonable grounds.
- The right to object to the processing of your personal information for direct marketing purposes.
- The right not to be subject to a decision based solely on the automated processing of your personal information, where that decision results in legal consequences for you or affects you in a substantially similar way.
- The right to submit a complaint to the Information Regulator (South Africa) in respect of an alleged contravention of POPIA.
To exercise any of these rights, please email us at legal@onecompare.co.za. We will respond within a reasonable time, and in any event within the timeframes prescribed by POPIA. There is no fee for exercising these rights, although a reasonable, proportionate fee may apply to a request for a copy of records under the Promotion of Access to Information Act, 2000 ("PAIA").
13.How long we keep your personal information
We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law.
- Quote and policy review records are retained for a minimum of five years from the date of last engagement, in line with FAIS record-keeping requirements.
- Communication records (email correspondence, call recordings) are retained for the same period.
- Website analytics data is retained in aggregated form for longer, but personal identifiers are removed in accordance with our analytics provider’s retention settings.
- Where we no longer need to retain personal information, we will delete or de-identify it in a secure manner.
14.Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, our service offering, or applicable law. The current version is always published on our website with the "Last updated" date shown at the top. Where the changes are material, we will bring them to your attention through a clear notice on our website or, where appropriate, by direct communication. Your continued use of our services after a material change has been notified will indicate your acceptance of the updated policy.
15.Information Officer and how to contact us
OneCompare has appointed an Information Officer in accordance with section 56 of POPIA. The Information Officer is responsible for compliance with POPIA and for handling requests from data subjects relating to their personal information.
15.1Contact details
- Email for privacy queries, access requests, and complaints: legal@onecompare.co.za
- Postal address: POSTNET SUITE 116, PRIVATE BAG X121, NOORDWYK, HALFWAY HOUSE, GAUTENG, 1687
16.The Information Regulator (South Africa)
If you are not satisfied with how we have responded to a privacy query or complaint, you have the right to lodge a complaint with the Information Regulator. The Regulator’s contact details are:
- Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
- Complaints email: POPIAComplaints@inforegulator.org.za
- General enquiries: enquiries@inforegulator.org.za
- Website: https://inforegulator.org.za
We would, however, ask that you give us the opportunity to address your concern first, by writing to legal@onecompare.co.za.
Quick reference: how to reach us
For any privacy-related question, request, or complaint, please contact our Information Officer at legal@onecompare.co.za. We aim to respond within five business days, and in any event within the timeframes prescribed by POPIA.
For general client service enquiries, please use legal@onecompare.co.za.