POPIA Compliance & Data Processing Agreement (DPA)

Effective Date: 18 June 2026 Company: FNA Solutions (Pty) Ltd trading as Consilium 360

This document serves as a binding Data Processing Agreement outlining the strict data protection relationship between FNA Solutions (Pty) Ltd (t/a Consilium 360) and you, the subscribing Financial Advisor or FSP, in accordance with the Protection of Personal Information Act, No. 4 of 2013 (POPIA).

1. Definitions of Roles (Section 1 POPIA)

In the context of the highly sensitive client data (financials, health indicators for life cover, ID numbers, dependents) inputted into the Consilium 360 platform to generate FNAs and CRM pipelines:

  • The Financial Advisor / FSP acts as the Responsible Party. You independently determine the purpose of and means for processing the Personal Information of your clients. You explicitly warrant that you have obtained the lawful mandate, valid consent, and legal justification required to capture, process, and upload your clients’ data into our cloud platform.
  • FNA Solutions (Pty) Ltd (Consilium 360) acts solely as the Operator. We process the Personal Information strictly on your behalf, acting only on your electronic instructions as you interact with the Platform’s user interface.

2. Strict Limits on Processing

As the Operator, Consilium 360 will:

  • Only process Client Data to deliver the SaaS functionalities (executing mathematical FNA calculations, rendering CRM dashboards, and generating PDF Records of Advice).
  • NEVER use, sell, mine, or aggregate your clients’ Personal Information for our own marketing, profiling, or monetization purposes.
  • AI Processing: When using the Generative AI ROA feature, relevant client data points are sent to our secure enterprise AI API partners. We warrant that we utilize “Zero-Retention” or “Non-Training” API agreements, meaning your clients’ sensitive financial data is never used to train external or public AI models.

3. Security Safeguards (Section 19 POPIA)

Consilium 360 implements enterprise-grade technical and organizational measures to prevent loss, damage, or unauthorized access to Personal Information:

  • Architecture: Client Data is hosted securely on Google Cloud Platform.
  • Hierarchical Silos: Data is logically segregated using strict Row-Level Security (RLS). Advisors can only access their own clients. FSP Principals can only view data strictly within their organizational tenant.
  • Encryption: All Client Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).

4. Use of Sub-Operators (Sub-Processors)

You authorize Consilium 360 to engage third-party infrastructure providers (e.g., Google Cloud, DocuSign, secure AI endpoints) to facilitate the Service. We remain liable for the actions of our Sub-Operators and ensure they are bound by written agreements that offer the same or greater data protection standards as outlined in this document. If we add or replace a core Sub-Operator, we will notify you via the platform or email.

5. Cross-Border Transfers

Consilium 360 utilizes global cloud infrastructure. If Client Data is routed or backed up to servers located outside the borders of the Republic of South Africa (e.g., EU or US data centers), we warrant that those jurisdictions are subject to binding corporate rules, data protection laws (such as the GDPR), or specific contractual clauses that provide an adequate level of protection upholding the principles of POPIA.

6. Incident Response & Data Breaches (Section 22 POPIA)

In the event of a confirmed security compromise where there are reasonable grounds to believe that the Personal Information of your clients has been accessed or acquired by an unauthorized person:

  • Consilium 360 will notify you (the Responsible Party) without unreasonable delay (typically within 48 to 72 hours of confirmation).
  • We will provide you with all available information regarding the nature of the breach, the data affected, and the remedial steps taken, allowing you to fulfill your legal obligation to notify the Information Regulator and the affected Data Subjects.

7. Data Extraction, Return, and Deletion

  • Assistance: The software is designed to allow you to easily export your CRM records and download PDF reports directly. Should you receive a Subject Access Request (SAR) or “Right to be Forgotten” request from a client, you can execute the deletion directly within the CRM UI.
  • Termination: Upon cancellation or termination of your Consilium 360 subscription, you are granted a 30-day grace period to export your Client Data. Following this 30-day period, Consilium 360 will initiate an automated, irrevocable routine to securely and permanently delete or irreversibly anonymize all Client Data associated with your tenant from our active production databases.