
JAROCEL PTY LTD (operating under the trading name "Headway")
Version: 2.0 Last updated: September 2026 Effective Date: September 03, 2026
1. Scope & General Information
1.1. Application: This Privacy Policy (the "Policy") establishes the protocols for gathering, storing, transferring, and processing Personal Information of users when accessing the official website at https://hw.site/, its associated subdomains, mobile applications, or connected web environments (collectively, the "Main Platform"), as well as when utilizing the financial and trading services (the "Services") provided by JAROCEL PTY LTD (operating under the trading name "Headway", hereinafter referred to as the "Company", "We", "Us", or "Our").
1.2. Legal Consent & Discontinuation: By opening a Client Account, registering a Personal Area, or using any feature of our Main Platform, you confirm that you have read, understood, and agreed to be legally bound by this Policy. If you do not accept these data protection terms, you must immediately terminate your use of the Main Platform and the Services.
1.3. Corporate Commitment: We prioritize the confidentiality, integrity, and lawful processing of all personal data. Our processing framework is designed to prevent data leakage, identity theft, or unauthorized access, utilizing advanced physical, administrative, and technological security controls.
1.4. Inquiries: If you have questions, privacy concerns, or requests regarding the processing of your data, please reach out directly to our support team at care@hw.site.
2. Definitions & Key Terms
In this Policy, terms defined in the Headway General Terms and Conditions (Client Agreement) shall carry the same meaning. Additionally, the following definitions apply:
- Client Agreement – The General Terms and Conditions published on the Main Platform that govern the legal relationship and execution of transactions between the Client and the Company.
- Consent – Any voluntary, specific, informed, and unambiguous expression of will by which the User agrees to the processing of their Personal Information.
- Responsible Party – Under POPIA, the legal entity which, alone or in conjunction with others, determines the purpose of and means for processing Personal Information. In this Policy, the Company acts as the Responsible Party.
- Operator – Any natural or legal person who processes Personal Information on behalf of the Responsible Party (Company) under a written contract, without coming under the direct authority of the Company.
- Data Subject – The natural or juristic person (the Client, Corporate Entity, User, or visitor) whose Personal Information is processed by the Company.
- Personal Information (or Personal Data) – Any information relating to an identifiable, living natural person, or where applicable, an identifiable, existing juristic person, including but not limited to identity numbers, contact details, financial positions, and transactional records.
- Processing – Any operation or activity, whether automated or manual, concerning Personal Information, such as collection, recording, storage, updating, dissemination, or destruction.
- POPIA – The Protection of Personal Information Act, No. 4 of 2013 of South Africa, including any regulations, guidelines, or notices issued by the Information Regulator of South Africa.
- FICA – The Financial Intelligence Centre Act, No. 38 of 2001 of South Africa, governing anti- money laundering (AML) and counter-terrorist financing (CTF) compliance.
- Special Personal Information – Categories of sensitive personal data that require heightened protection under POPIA (such as biometric information, criminal histories, racial or ethnic origin, or religious beliefs).
- User / Client / You – Any individual or authorized representative of a legal entity who accesses the Main Platform or registers for the Services.
3. Guiding Data Protection Principles
As the Responsible Party, the Company guarantees that all Personal Information will be:
- Processed lawfully, fairly, and with absolute transparency.
- Collected only for explicitly defined, legitimate, and lawful purposes connected to our financial operations and not further processed in any incompatible manner.
- Limited to what is strictly necessary, adequate, and relevant to the purposes of the processing.
- Kept accurate, complete, and up to date, with prompt measures taken to rectify or delete obsolete data.
- Retained only for as long as legally required or necessary for the purpose of collection.
- Secured against unauthorized alteration, accidental loss, damage, or unlawful deletion. Minors Policy: Our Services are strictly prohibited for individuals under the age of eighteen (18) or the age of majority in the Client's jurisdiction (whichever is higher). We do not knowingly collect or process data of minors. Any such discovered records will be immediately deleted.
4. Categories of Data & Legal Grounds for Processing
In accordance with POPIA (Section 11), we process your Personal Information only under the following lawful grounds: 1. Consent: Where you have explicitly agreed to the processing (e.g., marketing newsletters). 2. Contractual Necessity: To perform our obligations under the Client Agreement or to take pre-
contractual steps at your request (e.g., executing market orders, managing your Personal Area). 3. Legal Obligation: To comply with statutory and regulatory mandates (e.g., AML/KYC verifications under FICA, tax reporting, and market surveillance). 4. Legitimate Interests: To protect our business integrity, prevent financial fraud, optimize our trading platforms, and secure our network infrastructure.
Summary Table of Data Processing:
5. Your Personal Data Rights
Under POPIA and other applicable data protection laws, Data Subjects (both natural persons and juristic persons) possess the following rights regarding their Personal Information:
- Right of Access: You may request confirmation of whether the Company holds your Personal Information, as well as a record of any third parties who have had access to your data.
- Right to Rectification: You have the right to request the correction, amendment, or updating of any inaccurate, incomplete, misleading, or outdated Personal Information (subject to Clause 1.3(b) of the Client Agreement).
- Right to Erasure (De-registration): You can request the destruction or deletion of your data where it is no longer necessary for the purpose it was collected, or where the legal basis for processing no longer exists.
- Right to Object: You may object, on reasonable grounds, to the processing of your Personal Information, including processing for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time. This will not affect the lawfulness of processing carried out prior to the withdrawal.
How to Exercise Your Rights:
To submit a rights request, please contact our Information Officer / Data Protection Officer at care@hw.site. To ensure security, we will require you to verify your identity before processing any access, deletion, or correction request. Note: Certain rights are subject to statutory limitations. For example, the Company is legally prohibited from deleting data that must be retained under AML/FICA regulations.
6. Disclosing and Sharing Personal Information
6.1. The Company may disclose your Personal Information to selected third parties to provide the Services, comply with legal duties, or protect our legitimate interests. Recipients are bound by strict confidentiality obligations and include:
- Corporate Group Entities: Affiliates, parent companies, and subsidiaries to ensure standardized compliance, support services, and global operations.
- Operators & Service Providers: Under written agreement, including IT hosting companies, KYC/AML verification software providers, email and customer chat platforms, and market research partners.
- Financial Institutions & Payment Processors: Banks, payment card networks, and e-wallet providers to process deposits, withdrawals, refunds, and to resolve chargebacks or transaction disputes.
- Professional Advisers & Auditors: Legal counsel, compliance consultants, and financial auditors to manage risk, verify corporate governance, or defend against legal claims.
- Regulatory & Public Authorities: Law enforcement agencies, tax authorities (such as SARS), the Financial Intelligence Centre (FIC), or courts of competent jurisdiction when required by law or under formal investigation.
6.2. Payment Card and Digital Asset Disclaimer: The Company strictly operates on a non-storage basis regarding sensitive financial credentials. We do not directly collect, process, or store sensitive payment card details (such as the Full Primary Account Number (PAN), CVV/CVC codes, or 3D-Secure passwords), nor do we ever access or store private keys, passwords, or seed phrases for cryptocurrency transactions. All payment processing operations are fully outsourced to regulated, external Payment Service Providers (PSPs) and financial institutions that comply with the Payment Card Industry Data Security Standard (PCI- DSS) and other applicable financial security protocols. For security and withdrawal verification purposes (pursuant to Clause 3.2.8 of the Client Agreement), We may only process and store masked card copies where only the first six (6) and last four (4) digits of the card number are visible, and the CVV/CVC code is completely redacted.
7. Cross-Border Transfers of Personal Information
Due to the global nature of our financial services and cloud infrastructure, your Personal Information may be transferred to, stored, and processed in jurisdictions outside of South Africa for the due performance of the Company’s obligations under the Client Agreement. We ensure that all international transfers conform to Section 72 of POPIA by ensuring that:
- The recipient country provides an adequate level of data protection substantially similar to POPIA.
- We enter into formal Data Transfer Agreements or apply Standard Contractual Clauses (SCCs) that bind the foreign recipient to strict security, confidentiality, and data protection standards.
- Operational, backup, and storage environments are heavily encrypted both in transit (HTTPS/TLS) and at rest (disk-level encryption).
8. Data Retention and Compliance with AML Laws
The Company retains Personal Information strictly in accordance with its legal, regulatory, and business obligations.
- AML & Transaction Records (FICA Compliance): Pursuant to South African anti-money laundering regulations and FICA, all records pertaining to client identity verification (KYC documents), transaction histories, account statements, and business correspondence must be retained for a minimum of five (5) years from the date of the termination of the business relationship. This requirement overrides any deletion requests.
- Active Accounts: Personal Information associated with active Client Accounts is retained for the entire duration of the client relationship.
- Incomplete Applications & Leads: Personal Information from incomplete registrations, demo accounts, or marketing inquiries is retained for a period of up to one hundred and eighty (180) days from submission for the explicit purposes of fraud prevention, detecting duplicate profiles, and preventing service abuse. Unless renewed interest (such as account activity or login) is demonstrated (in which case the retention may be extended by an additional thirty (30) days), such data will be securely deleted or anonymized upon expiry of this period.
- Marketing Suppression Lists: If you opt out of marketing communications, we will retain your minimal contact details (email/phone number) on a suppression list indefinitely to ensure your preference is honored.
9. Data Security and technical Safeguards
The Company implements robust technical, physical, and administrative safeguards designed to protect Personal Information against accidental loss, unauthorized access, destruction, or disclosure. These measures include:
- Standard encryption of data in transit (TLS/SSL) and at rest.
- Robust firewalls, secure private networks, and monitored server hosting environments.
- Strict role-based access control (RBAC), ensuring that only authorized compliance and support staff can access sensitive Client Data.
- Multi-factor authentication (MFA) protocols for administrative access.
- Regular vulnerability assessments, penetration testing, and security audits of our systems.
- Breach Notification: In the event of a suspected or confirmed security breach affecting your Personal Information, we will notify the South African Information Regulator and affected Users as soon as reasonably possible, in accordance with Section 22 of POPIA.
10. Direct Marketing & Cookie Usage
- Direct Marketing: Any direct electronic marketing (via email, SMS, or automated calls) sent to Users who are not existing clients will only be conducted with their prior opt-in Consent. Existing clients may receive marketing updates regarding similar services, subject to their right to opt out at any time.
- Cookies: We utilize cookies and tracking pixels to analyze traffic, manage user sessions, and deliver tailored promotional content. You can manage your cookie preferences through our dedicated Cookie Policy and your browser settings.
11. Dispute Resolution & Right to Lodge a Complaint
- Internal Resolution: Any complaints or disputes concerning the handling of your Personal Information should be directed first to our compliance department at care@hw.site for resolution under our formal Claim Procedure (Section 9 of the Client Agreement).
- Information Regulator (South Africa): If you are not satisfied with our internal resolution, you have the right to lodge a formal complaint regarding any alleged POPIA violation directly to the South African Information Regulator: ○ Website: https://inforegulator.org.za/ ○ Email (Complaints): POPIAComplaints@inforegulator.org.za ○ Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
12. Miscellaneous Provisions
12.1. Amendments: We reserve the right to modify this Policy at any time to reflect legislative updates or changes in our operational procedures. If we make material changes, we will post a prominent notification on the Main Platform or send an email update.
12.2. Severability: If any provision of this Policy is found to be invalid, illegal, or unenforceable, the remaining provisions shall remain in full force and effect.
12.3. Prevailing Language: This Privacy Policy is executed in the English language. Pursuant to Clause 1.4 of the Client Agreement, if this Policy is translated into another language for informational purposes, the English version shall always prevail in the event of any discrepancy or conflict.
13. Contact Details & Data Protection Officer
- Responsible Party: JAROCEL PTY LTD (trading as "Headway")
- Customer Support: care@hw.site
- Information officer (or Data Protection Officer / DPO): care@hw.site
- Corporate Address: 3 Flamingo Crescent, Beacon Bay, East London, 5241, South Africa.