Privacy Policy
Last updated: 2 September 2026
1. Introduction
Banklink is a trading name of K2026171517 (South Africa), registration number K2026171517, a company incorporated in the Republic of South Africa. That company is the responsible party for the personal information described in this policy. Banklink is committed to protecting your personal information. This policy explains how we collect, use, and protect data when you use our services. We comply with the Protection of Personal Information Act 2013 (POPIA).
2. Information we collect
- ·Account information (name, email, organisation details) when you register
- ·Financial account data that the Banklink account holder, and where applicable the underlying bank-account holder, explicitly authorises us to access
- ·Usage data (API calls, access logs) for security and billing
- ·Device and browser information for security monitoring
3. How we use your information
- ·To provide and improve the services
- ·To process API requests you authorise
- ·For billing and account management
- ·To communicate service updates and important notices
- ·To detect and prevent fraud and security incidents
4. Data sharing
We do not sell your personal information. We may share data with:
- ·Service providers who assist in delivering the services (under strict confidentiality obligations)
- ·Regulators or law enforcement where required by law
- ·Third parties where you have explicitly consented
5. Credentials and sensitive financial data
Banklink is built to pass bank data through rather than accumulate it, and most organisations run it that way. In that configuration credentials are passed directly to the retrieval service to authenticate with the financial institution and are never written to our records, and retrieved transactions are delivered to the organisation’s chosen webhook or email destination and then discarded. Credentials are stored only where an organisation links an account for recurring fetches, and transactions are stored only where an organisation chooses to have them saved to the Banklink dashboard. To be precise about what pass-through means: retrieving data requires us to authenticate and handle the records in order to deliver them, so the commitment is that this happens in memory for the instructed purpose and is not retained, not that the data never reaches our systems. Banklink does not collect or store bank login credentials or other sensitive financial data by default. We process or retain this information only when the Banklink account holder — and, where applicable, the underlying bank-account holder — explicitly instructs and authorises us to do so, such as when linking an account or enabling scheduled transaction fetches. Where credentials must be retained to carry out that instruction, they are encrypted, stored separately, never written to logs, and never stored in plaintext. We do not use credentials or financial data for any unrelated purpose.
6. Consent and control
Authorisation is limited to the account and purpose selected by the account holder. The account holder may withdraw that authorisation, disable scheduled fetches, or disconnect an account at any time. This stops future access. Financial data already delivered or retained at the account holder’s instruction is kept only for as long as needed to provide the service, meet a documented instruction, or comply with law.
7. Security
Banklink is designed and operated in line with ISO/IEC 27001:2022 information-security controls; formal certification is in progress. All data is encrypted in transit and at rest, and access to your data is logged and audited.
8. Your rights
Under POPIA, you have the right to:
- ·Access the personal information we hold about you
- ·Correct inaccurate information
- ·Request deletion of your data
- ·Withdraw consent for data processing
- ·Lodge a complaint with the Information Regulator
9. Data retention
We apply data minimisation and retain personal and financial data only for as long as your account is active, as needed to follow your documented instructions, or as required by law. You may request deletion at any time, subject to any legal retention requirement.
10. Cookies
We use essential cookies for authentication and session management. We do not use tracking or advertising cookies.
11. Contact
Our Information Officer, appointed in terms of the Protection of Personal Information Act 4 of 2013, is Niel Barnard. For privacy enquiries, to exercise any of the rights above, or to request access to a record under the Promotion of Access to Information Act, contact privacy@banklink.co.za.
Our manual in terms of section 51 of the Promotion of Access to Information Act is published at banklink.co.za/paia.
12. Changes to this policy
We will notify you of material changes to this Privacy Policy with 30 days notice.