This Privacy Notice explains how we collect, use, share, store, and protect personal information when you use Coinfig. It is intended to support compliance with South Africa's Protection of Personal Information Act, 2013 ("POPIA"). References to personal information include information about identifiable natural persons and, where POPIA applies, identifiable existing juristic persons such as companies, trusts, and firms.

Privacy at a glance

This summary is for convenience and does not replace the full notice below.

  • You choose what to connect. Coinfig processes the crypto activity data you upload or authorise, using read-only access.
  • Our application and data infrastructure are hosted in South Africa (AWS Cape Town). Some supporting providers process limited data in other regions under safeguards.
  • We do not sell your personal information, and we do not use partner-controlled information for our own analytics, marketing, or AI model training.
  • We send marketing only with your consent or under the narrow existing-customer exception, and you can opt out at any time. Optional advertising cookies are governed by our Cookie Policy.
  • You can disconnect and delete an individual data source, or delete your whole account, and you can request access, correction, or export of your information.
  • Questions and requests go to our privacy contact below. You may also complain to the Information Regulator of South Africa.

Contents

1) Scope

This notice applies to:

  • Individuals using Coinfig directly.
  • Enterprise users, including accountants, auditors, and businesses, using Coinfig on behalf of their clients.

Coinfig and this notice are directed primarily at users in South Africa, and this notice is written to support compliance with POPIA. If we actively offer Coinfig to users in other jurisdictions, we will provide supplementary notices addressing the privacy laws of those jurisdictions where required.

This notice describes our processing practices and your rights. It is not a contract. Where we rely on your consent for a particular optional activity, we will request that consent separately.

Some information is necessary to create an account, authenticate you, connect a selected data source, process a payment, or generate a requested report. Other information and integrations are optional. If you do not provide information that is necessary for a selected function, we may be unable to provide that function or generate a complete report.

2) Personal information we collect

Depending on how you use Coinfig, we may collect or process:

2.1 Account and identity information

  • Name and surname.
  • Email address.
  • South African ID number and/or tax number where required for reporting context.

2.2 Crypto activity information (provided by you or connected by you)

  • Wallet addresses.
  • Deposit and withdrawal addresses, including hosted wallet or exchange deposit and withdrawal addresses you provide.
  • Transaction histories, such as dates, amounts, assets, fees, and counterparties where available.
  • Transaction identifiers, for example transaction IDs or hashes supplied in your data sources.
  • Exchange account identifiers or metadata included in statements or API responses.

2.3 User edits, classifications and audit logs

We may collect and process user-generated changes and audit-log information, including:

  • Transaction classifications and reclassifications.
  • Base cost inputs or adjustments.
  • Capital-versus-income assignments.
  • Tax-year or financial year-end settings.
  • Changes made to imported or uploaded transaction data.
  • Timestamps and user or account identifiers linked to those changes.

This information is processed to provide the Service, maintain data integrity, support report review, troubleshoot issues, and protect against misuse.

2.4 Authentication information

  • If you use SSO, we receive limited login data from your provider, currently Google and Microsoft, such as your email and basic profile identifiers required to authenticate you.

2.5 Technical information (website or app usage)

  • Device and browser information, for example IP address, device type, and browser type.
  • Activity logs, such as sign-ins, uploads, sync events, and errors.
  • Cookies and similar technologies. See Section 9.

2.6 Billing and subscription information

  • Subscription plan, status, and billing history.
  • Payment references from our payment processors. We do not store full card numbers. Card details are processed directly by our payment processors.

2.7 Source credentials and integration connection data

  • If you connect an exchange account, we store the read-only API keys, secrets, or tokens you authorise so that we can retrieve your transaction history. These credentials are stored encrypted and protected as described in Section 8.
  • If you connect an accounting integration such as Xero, we store connection identifiers and access tokens needed to operate the integration you authorised.

2.8 Generated outputs, settings, and support information

  • Jurisdiction and tax-residency settings you configure.
  • Generated calculations, tax reports, completeness scores, and derived classifications produced by the Service.
  • Accountant or enterprise relationships and permissions you authorise.
  • Customer-support messages and attachments you send us.
  • Consent records and timestamps.
  • Where you reach Coinfig through a referral or partner arrangement, a partner user reference, referral and campaign attribution records (such as source, campaign, and coupon), sign-in handoff (single sign-on ticket) metadata, and the conversion, subscription, and report-generation events used for permitted partner reconciliation.

3) How we collect personal information

We collect personal information when you:

  • Create an account using email and password or SSO.
  • Upload CSV files or complete templates.
  • Connect exchange accounts via API using read-only keys you create.
  • Subscribe to a paid plan and make payments.
  • Connect optional integrations, such as Xero.
  • Use the platform through logs and analytics.
  • Contact support through emails and ticket information.

We may also collect personal information indirectly from:

  • A partner organisation, such as an exchange, that has engaged us to provide Coinfig services to its customers, following your opt-in. See Section 12.
  • Accountants and enterprise customers acting under a mandate on your behalf.
  • Exchanges and integrations you connect.
  • Public blockchain networks and blockchain-data providers.
  • SSO and authentication providers.
  • Payment processors.
  • Device, security, and operational logs.

4) Why we process your personal information (purposes)

We process personal information to:

  • Provide Coinfig functionality, including imports, calculations, reports, and completeness scoring.
  • Maintain your account and authenticate access.
  • Support data syncing from connected integrations.
  • Provide customer support and respond to requests.
  • Secure the platform, prevent fraud or abuse, and maintain audit logs.
  • Improve the Service through debugging, quality monitoring, and feature development.
  • Where you reach Coinfig through a referral or partner arrangement, record the partner or channel through which you were referred, apply applicable benefits or discounts, operate the agreed partner journey, prevent attribution fraud, and prepare legally permitted partner reconciliation reports.

Statistical and de-identified use

We may use statistical and de-identified operational information internally to maintain, secure, test, and improve Coinfig. We do not treat information as de-identified merely because names or email addresses have been removed. We apply measures designed to ensure that a person, taxpayer, wallet owner, or End Client cannot reasonably be re-identified. We do not publish or provide transaction-level or wallet-level information, or use partner-controlled information for our own analytics, marketing, artificial-intelligence model training, or unrelated Sixpence products.

These statistical and de-identified uses do not apply to personal information we process on behalf of a partner or enterprise customer that is the responsible party (data controller) for that information. Such information is processed only as described in Section 12.

Automated calculations and decision support

Coinfig uses automated processing to import, normalise, classify, and calculate transaction information and to generate completeness indicators and reports. These outputs are decision-support tools. Coinfig does not make a solely automated decision that itself determines your legal rights or obligations. You can review and correct source data, classifications, and assumptions, and you should obtain professional advice where appropriate.

Direct marketing

We send electronic marketing only where you have consented or where the limited existing-customer exception permitted by law applies. That exception is limited to our own similar products or services. We provide an opt-out opportunity when the contact information is collected where required, and in each marketing communication. Service, security, billing, and report communications are not marketing communications. Personal information we process on behalf of a partner that is the responsible party is not added to our marketing lists unless the applicable agreement and consent position expressly permit it.

5) Lawful grounds for processing (POPIA)

We process personal information on lawful grounds such as:

  • Performance of a contract to provide the Service you requested.
  • Legitimate interests to secure and improve the Service.
  • Consent where required or appropriate, such as optional advertising and marketing cookies, which are set only if you accept them via our cookie banner. See Section 9.
  • Legal obligations where applicable.

6) Sharing your personal information

We do not sell your personal information.

We may share personal information only as necessary with:

  • Hosting and infrastructure providers. Our application and data infrastructure run on Amazon Web Services (AWS) in the Africa (Cape Town) region, and our website is delivered and protected through Cloudflare's network. Both operate under confidentiality and security obligations.
  • Our authentication provider, Clerk, which manages account sign-up and sign-in (including email/password and SSO) and processes your name, email address, and sign-in activity, together with SSO providers such as Google and Microsoft where you choose to sign in with them.
  • Payment processors (currently PayFast and Stripe) to process subscription payments. They receive the information needed to process your payment. We do not store full card details.
  • Pricing data sources (such as CoinGecko) where needed to obtain price feeds for calculations when pricing is not available via your connected statements or APIs.
  • Blockchain data providers. When you add a wallet address, we query third-party blockchain data services and public network nodes with that address to retrieve its transaction history.
  • Advertising services. Where you accept optional cookies, we share limited conversion and measurement data with Google to measure our advertising. See the Cookie Policy.
  • Accounting integrations such as Xero, where you connect them, to send the journals or reports you choose to export to your accounting organisation.
  • Enterprise customers where they are acting on your behalf and have the mandate to process your data.
  • Authorities if required by law or valid legal process.

7) Where we host and process data (location)

Coinfig's application and data infrastructure are hosted in South Africa, in the Amazon Web Services (AWS) Africa (Cape Town) region.

Some service providers process limited data outside South Africa, including our website delivery network (Cloudflare), our authentication provider (Clerk), and payment processors. Supporting services such as edge delivery, authentication, and payment processing may process IP addresses, authentication data, or support records in other regions even where our main data infrastructure remains in South Africa.

We transfer personal information outside South Africa only where a condition in section 72 of POPIA is met. In most cases we rely on contractual protections with the recipient that impose obligations substantially similar to POPIA's conditions for lawful processing. Where a provider operates under binding corporate rules or an equivalent binding instrument, we may rely on those. Where we rely on your consent for a specific transfer, we will request it separately.

8) Security and protection measures

We apply reasonable administrative, technical, and organisational safeguards designed to protect personal information.

Specific measures include:

  • Encryption of stored API credentials.
  • Access controls and least-privilege practices for internal access.
  • Logging and monitoring to detect misuse and operational issues.

Coinfig supports multi-factor authentication (MFA) through our authentication provider. We recommend enabling MFA on your account, securing your email or SSO account, and using strong passwords.

No system can be guaranteed 100% secure. You use the Service and store data at your own risk.

Security compromises

If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will take reasonable steps to investigate, contain, and remediate the incident.

Where Sixpence is the responsible party for the affected information, we will assess the incident and make any notifications to the Information Regulator and affected data subjects required by POPIA or other applicable law. Where we process the affected information as an operator on behalf of a partner or enterprise customer that is the responsible party, we will notify and assist that party without undue delay in accordance with our agreement, and that party is responsible for regulatory and data-subject notifications, except where we are separately required by law to notify.

9) Cookies and similar technologies

See our Cookie Policy for details.

10) Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Notice, including providing the Service, maintaining reports and audit logs, supporting account access, resolving disputes, complying with legal obligations, enforcing our Terms of Use, and maintaining security records.

Unless a different retention period is required or justified by law, contract, dispute, security, audit-log integrity, or legitimate business purposes:

  • Account and billing records are retained for as long as required for accounting, tax, and legal record-keeping purposes.
  • Transaction data, report data, user classifications, tax-year settings, and calculation assumptions are retained while your account or relevant workspace remains active.
  • Audit logs may be retained to preserve report integrity, investigate misuse, support dispute resolution, and maintain a record of user changes.
  • Security logs may be retained for security, fraud-prevention, and operational purposes.
  • Anonymised data may be retained indefinitely where it can no longer reasonably identify you.

Where we process personal information on behalf of a partner or enterprise customer that is the responsible party, we retain, return, or destroy that information as required by our agreement with that party, including on termination of the agreement.

Deleting a single source versus deleting your account

You can disconnect and delete an individual data source, such as a connected exchange or wallet, without deleting your account. In that case we delete the stored credential for that source and the transaction data imported from it, while preserving the data you added from other sources. Full account deletion is handled separately: we delete or de-identify all personal information we control, subject to lawful retention requirements.

You may request account deletion or data export by contacting [email protected]. Following a verified deletion request, we will delete or de-identify personal information from active systems within a reasonable period, unless we are required or permitted to retain it. Backup copies may remain for a limited period until overwritten or deleted in the ordinary course of backup management, and are not restored to active systems except where necessary, in which case the deletion is reapplied.

11) Your rights (POPIA)

Subject to POPIA and applicable limits, you may request to:

  • Access your personal information.
  • Correct or update it.
  • Delete it through account deletion.
  • Object to certain processing where applicable.
  • Request data export where feasible.

To exercise these rights, email [email protected]. We may request verification before acting on a request.

12) Enterprise and partner use (accountants, auditors, businesses, and platform partners)

Where an enterprise user processes personal information on behalf of an end client, the enterprise is responsible for ensuring that it has a lawful basis, mandate, consent, or other authority to upload and process the end client's data.

To the extent Sixpence processes End Client personal information on behalf of an Enterprise Customer, Sixpence acts as an operator or service provider for the purpose of providing Coinfig. Additional enterprise-specific obligations are set out in the Enterprise Addendum to the Terms of Use.

Sixpence may also provide Coinfig services to the customers of a partner organisation, such as an exchange, under an agreement with that partner. Our role depends on the relationship and the information concerned. Where a partner provides or makes personal information available to us under a data-processing agreement, the partner acts as the responsible party (data controller) and Sixpence acts as its operator (data processor) for the agreed services, on the partner's documented instructions. We process such information only to provide the contracted services and to perform permitted partner reconciliation, do not use it for our own purposes (including the statistical, de-identified, or marketing uses described in Section 4), and return or destroy it in accordance with the partner agreement. Where that agreement contains data-processing terms, those terms govern our processing of the partner's customer data if they conflict with this notice.

Where you provide information directly to Coinfig to create or manage your Coinfig account, connect additional sources, purchase services, contact support, or use optional functionality, Sixpence will generally act as the responsible party for that information, unless a written agreement states otherwise.

Requests concerning information a partner controls may need to be coordinated with that partner. You may contact either the partner or Coinfig, and we will route and assist with the request in accordance with the applicable agreement and law. You may also ask us to disconnect and delete a partner-connected source without deleting other sources you have added directly to Coinfig. See Section 10.

13) Children

Coinfig is not intended for persons under 18. Do not create an account for a child or submit a child's personal information unless you have lawful authority and Coinfig has expressly agreed to that use. If we learn that personal information concerning a child was collected unlawfully, we will take appropriate steps to restrict or delete it.

14) Changes to this Privacy Notice

We may update this notice from time to time. If changes are material, we will take reasonable steps to notify you, for example by in-app notice or email. The revised notice applies from its stated effective date. Where a change introduces processing that requires consent, we will request that consent before beginning the processing.

Version history

  • Version 1.1 (23 July 2026). Clarified our responsible-party and operator roles, tightened the statistical and de-identified use commitments, added mandatory-versus-optional information, indirect collection sources, cross-border transfer mechanisms, automated-processing and source-deletion explanations, and added the Information Regulator's contact details.
  • Version 1.0 (22 July 2026). First Coinfig Privacy Notice, replacing the earlier LedgerTax notice.

Prior versions are retained and are available on request via our privacy contact.

15) PAIA and contact details

Questions, requests, or complaints may be sent to: [email protected].

Information Officer contact: [email protected]

Physical and service address: 1269 Gordon Hood Rd, Centurion Central, Centurion, 0046, South Africa

Our PAIA Manual is available on request.

If you are not satisfied with how we handle a privacy request or complaint, you may lodge a complaint with the Information Regulator (South Africa) at Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. You can email [email protected] or visit inforegulator.org.za.