Privacy Policy
This policy explains how Knit collects, uses, discloses and safeguards personal information when people use its platform, website and related services.
Draft source date: 9 February 2026
Draft for business and legal review before launch. The legal entity, privacy contact, security controls, identity-processing activities, credit screening, affordability assessments and trust-account wording still require confirmation.
1. Introduction
Knit takes the protection of personal information seriously. As a financial infrastructure provider, Knit intends to process information in accordance with the Protection of Personal Information Act and other applicable data-protection legislation and regulations.
By accessing or using the service, you acknowledge that you have read and understood the collection, storage, use and disclosure practices described in this Privacy Policy and the Terms of Service.
2. Information we collect
Knit collects information provided directly by users and information generated when the service is used. This may include:
- Account information: name, email address, phone number, institution details and login credentials.
- Financial information: bank-account details, transaction history, payment records and fee structures needed to process payments.
- Identity-verification data: government-issued identity numbers and other details required for regulatory compliance, including Financial Intelligence Centre Act and Know Your Customer processes.
- Usage data: internet-protocol address, browser type, device information and information about how the service is accessed and used.
3. How we use information
Collected information may be used for the following purposes:
- Providing, operating and maintaining the service.
- Processing transactions and managing payment flows.
- Conducting credit screening and affordability assessments with consent.
- Improving, personalising and expanding the service.
- Preventing fraud and protecting the platform.
- Complying with applicable legal and regulatory obligations, including the National Credit Act and Protection of Personal Information Act.
4. Data security
The supplied policy describes the following safeguards:
- Encryption: AES-256 for data at rest and TLS 1.3 for data in transit.
- Access controls: role-based access intended to limit sensitive information to authorised personnel.
- Security review: regular security audits and penetration testing.
- Data segregation: client trust funds held in segregated accounts.
5. Data retention
Knit retains personal information only for as long as necessary for the purposes described in this policy. Information may also be retained where necessary to comply with legal obligations, resolve disputes, and enforce legal agreements and policies.
6. Your data rights
Under POPIA and other applicable laws, data subjects may have the right to:
- Access personal information Knit holds about them.
- Request correction or deletion of personal information.
- Object to the processing of personal information.
- Lodge a complaint with the Information Regulator.
Privacy contact
The privacy-specific address in the supplied source has not been confirmed. Until it is, privacy questions can be sent to Knit’s confirmed general email address.
