Plain-language summary: We collect only what we need to operate this publication — primarily your email address if you subscribe, and basic analytics data about how the site is used. We do not sell your data. We do not share it with advertisers. We store it securely and respect your right to access, correct, or delete it at any time.

Section 01

Overview

This Privacy Policy explains how Antifragile Africa Crypto ("we," "us," or "our") collects, uses, stores, and protects personal information when you access our website, read our publications, subscribe to our reports, or otherwise interact with our Service.

We are committed to handling your personal information responsibly and in compliance with applicable data protection law — including South Africa's Protection of Personal Information Act, 2013 (POPIA) and, where applicable, the European Union's General Data Protection Regulation (GDPR).

By using this Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please discontinue use of the Service.

Section 02

Who We Are

Antifragile Africa Crypto is a weekly intelligence publication covering African cryptocurrency markets. For the purposes of data protection law, we are the responsible party (POPIA) and data controller (GDPR) in respect of personal information we process in connection with this Service.

Our publication is operated from the Republic of South Africa and is governed by South African law. Contact details for privacy-related enquiries are provided in Section 16.

Section 03

Data We Collect

We collect the minimum personal information necessary to operate and improve the Service. The categories of data we may collect include:

Category Examples Required?
Identity Data Email address; name (if voluntarily provided) For subscribers only
Usage Data Pages visited, time on page, referral source, browser type, device type Automatically collected
Communication Data Messages or enquiries sent to us via contact channels Only if you contact us
Technical Data IP address (anonymised where possible), operating system, screen resolution Automatically collected
Preference Data Report preferences, subscription status, unsubscribe actions For subscribers only

We do not collect sensitive personal information such as financial account details, identity document numbers, biometric data, health information, or political or religious views. We do not collect payment card information — any future subscription payments would be processed directly by a third-party payment provider under their own privacy terms.

Section 04

How We Collect It

We collect personal information through the following channels:

  • Direct submission — when you enter your email address to subscribe to the weekly report, or when you contact us directly
  • Automated technologies — when you visit our website, standard web server logs and analytics tools automatically record certain technical and usage data
  • Email interaction — if you receive our reports by email, your email client may transmit open and click data back to our email service provider, depending on your email settings
  • Third-party referrals — if you arrive at our site from a link shared by a third party, the referral source may be recorded in our analytics data

We do not purchase contact lists, acquire personal data from data brokers, or obtain personal information from social media platforms for marketing purposes.

Section 05

Why We Use It

We use the personal information we collect for the following purposes:

  • Delivering the Service — sending you the weekly report and any updates you have subscribed to receive
  • Service communications — responding to enquiries, providing support, and notifying you of material changes to the Service or these policies
  • Analytics and improvement — understanding how readers use and navigate the site so we can improve content, structure, and performance
  • Security and integrity — detecting and preventing fraudulent, abusive, or unauthorised use of the Service
  • Legal compliance — meeting our obligations under applicable laws and regulations, including record-keeping requirements
  • Subscription management — processing subscriptions, managing unsubscribe requests, and maintaining accurate mailing lists

We do not use your personal information for automated individual decision-making or profiling that produces legal or significant effects, for targeted advertising, or for any purpose incompatible with those stated above without first obtaining your explicit consent.

Section 07

Sharing & Disclosure

We do not sell, rent, or trade your personal information to any third party. We do not share your data with advertisers or allow third parties to use it for their own marketing purposes.

We may share your personal information only in the following limited circumstances:

  • Service providers — trusted third-party vendors who assist us in operating the Service (e.g. email delivery platforms, web hosting providers, analytics tools). These parties are bound by confidentiality obligations and may only use your data to provide services to us, not for their own purposes.
  • Legal requirements — where we are required by law, court order, or lawful authority to disclose personal information, we will comply with such requirements and, where legally permitted, notify you.
  • Protection of rights — where disclosure is necessary to protect the rights, property, or safety of Antifragile Africa Crypto, its users, or the public.
  • Business transfers — in the event of a merger, acquisition, or sale of the publication, personal information may be transferred as part of that transaction. We will notify subscribers of any such change and their options.
Key Commitment

Your email address and subscription data will never be provided to third-party marketers, advertisers, data brokers, financial institutions, or crypto projects — regardless of commercial incentive. This is a foundational principle of how we operate.

Section 08

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.

  • Subscriber email addresses — retained for the duration of your subscription and deleted within 30 days of an unsubscribe request, unless retention is required for legal compliance purposes.
  • Analytics data — aggregated and anonymised usage data may be retained indefinitely as it no longer constitutes personal information once anonymised. Non-anonymised technical data (e.g. IP logs) is deleted or anonymised within 90 days.
  • Communication records — correspondence you send us is retained for up to 3 years for record-keeping purposes, after which it is securely deleted.
  • Legal records — where we are required to retain data for legal, regulatory, or compliance purposes, we will do so for the period required by law.

When personal information is no longer required, it is securely deleted or anonymised using industry-standard methods.

Section 09

Security

We implement appropriate technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • HTTPS encryption for all data transmitted between your browser and our website
  • Access controls limiting who within our operations can access subscriber data
  • Use of reputable, security-certified third-party service providers
  • Regular review of our data handling practices and security posture

No method of transmission over the internet or electronic storage is completely secure. While we take reasonable precautions, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals as required by law.

Section 10

Your Rights

Subject to applicable law, you have the following rights in relation to your personal information. Under POPIA, these rights apply to all South African data subjects. Under the GDPR, these rights apply to individuals in the European Economic Area.

Right of Access
Request a copy of the personal information we hold about you and information about how we use it.
Right to Correction
Request that we correct any inaccurate or incomplete personal information we hold about you.
Right to Deletion
Request that we delete your personal information where there is no lawful reason for us to continue holding it.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Right to Restrict
Request that we restrict processing of your data in certain circumstances, such as while a dispute is being resolved.
Right to Portability
Receive a copy of your personal information in a structured, commonly used, machine-readable format (GDPR only).
Right to Withdraw Consent
Withdraw consent at any time where we rely on consent as our lawful basis. Withdrawal does not affect prior processing.
Right to Complain
Lodge a complaint with the Information Regulator (South Africa) or your local supervisory authority (GDPR).

To exercise any of these rights, please contact us using the details in Section 16. We will respond within 30 days. In some cases we may need to verify your identity before processing a request.

To unsubscribe from our mailing list at any time, use the unsubscribe link included in every email we send, or contact us directly.

Section 11

Cookies & Tracking

Our website may use cookies and similar tracking technologies to improve functionality and understand how the site is used. Cookies are small text files stored on your device by your browser.

The types of cookies we may use include:

  • Strictly necessary cookies — essential for the website to function. These cannot be disabled.
  • Analytics cookies — used to collect anonymised or aggregated data about how visitors use the site (e.g. pages visited, time on site). We use privacy-respecting analytics tools that do not build individual profiles or share data with third-party advertisers.
  • Preference cookies — used to remember settings or preferences you have chosen (e.g. language, display options).

We do not use advertising cookies, behavioural tracking cookies, third-party retargeting pixels, or any cookies designed to track you across other websites for commercial purposes.

You can control or disable cookies through your browser settings. Disabling analytics cookies will not affect your ability to read our reports. Note that disabling strictly necessary cookies may affect site functionality.

GitHub Pages Hosting Note

This site is hosted on GitHub Pages. GitHub may collect basic technical data such as IP addresses as part of its hosting infrastructure. This data is subject to GitHub's own Privacy Statement, available at github.com/privacy. We do not control this data collection and it is separate from our own data practices.

Section 12

Third-Party Services

We use a limited number of third-party services to operate this publication. Each is selected for its commitment to data privacy. Where these services process personal information on our behalf, they do so as data processors under our instruction.

  • Web hosting — GitHub Pages (GitHub, Inc. / Microsoft). Site files are hosted on GitHub's infrastructure. GitHub's privacy practices apply to infrastructure-level data collection.
  • Email delivery — if and when we implement email delivery for the newsletter, we will use a reputable email service provider and update this policy to name the provider and describe their data practices.
  • Analytics — if we implement web analytics, we will use a privacy-respecting tool and disclose this here. We do not currently use Google Analytics or Meta Pixel.
  • Fonts — this site loads Google Fonts. Google may process your IP address when serving font files. You can review Google's privacy practices at policies.google.com/privacy.

We do not embed social media widgets, share buttons, or third-party advertising scripts on this site. We do not use Facebook Pixel, Google Ads, or any equivalent behavioural advertising technology.

Section 13

International Transfers

Antifragile Africa Crypto is based in South Africa. If you are accessing the Service from outside South Africa — including from within the European Economic Area or the United Kingdom — your information may be transferred to and processed in South Africa or in countries where our service providers are located.

Where personal information is transferred outside South Africa, we take steps to ensure that appropriate safeguards are in place in accordance with POPIA's requirements for cross-border transfers. Where GDPR applies, we ensure transfers are protected by appropriate mechanisms such as standard contractual clauses or adequacy decisions.

By using the Service, you acknowledge that your information may be transferred to and processed in jurisdictions that may not provide the same level of data protection as your home country. We address this through contractual and organisational safeguards with our service providers.

Section 14

Children's Privacy

This Service is intended solely for adults aged 18 and over. We do not knowingly collect personal information from individuals under the age of 18.

If we become aware that we have inadvertently collected personal information from a person under 18, we will take immediate steps to delete that information from our records. If you believe we may have collected information from a minor, please contact us using the details in Section 16.

Section 15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the nature of our Service. When we make material changes, we will update the "Last Updated" date at the top of this page.

Where changes are significant, we will take reasonable steps to notify active subscribers — for example by including a notice in the next published report or by email, where we hold your address.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any update constitutes your acceptance of the revised Policy.

Section 16

Contact & Complaints

For any privacy-related questions, requests to exercise your rights, or concerns about how we handle your personal information, please contact us. We are committed to resolving concerns promptly and transparently.

Privacy Contact

Antifragile Africa Crypto

Jurisdiction: Republic of South Africa

For privacy enquiries, data access requests, or concerns, please reach out via the contact information provided in the publication or via the email address associated with your subscription. We aim to respond to all privacy-related requests within 30 days.

Supervisory Authorities

If you are located in South Africa and are unsatisfied with our response to a privacy concern, you may lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za. If you are located in the EEA, you may contact your local data protection supervisory authority.