Harambee DT Sacco Society Data Privacy Policy Statement
Last Updated: 20th January 2025
Introduction
Harambee DT Sacco Society Limited ('us', 'we' or 'our') is a Sacco regulated by SASRA to offer financial services. We operate the www.harambeesacco.com website, which provides more information about us and our various services/facilities as well as the Harambee M-cash mobile application. As an organization, we take our responsibility regarding the management of our stakeholders' data very seriously. This document informs you of our policy regarding the collection, use and disclosure of personal data when you use our services. It sets out how we manage our responsibility in the use of your data and the choices you have associated with that data. This data policy is in compliance with the Data Protection Act 2019.
The policy document is intended to ensure that Harambee DT Sacco Society Limited:
- Is clear about how personal data must be processed and Sacco's expectations for all those who process personal data on its behalf.
- Complies with existing data protection laws and with good practice.
- Protects its reputation by ensuring the personal data entrusted to it is processed in accordance with data subjects' rights.
- Protects itself from risks of personal data breaches and other breaches of data protection law.
Scope
The policy applies to:
- Employees of Harambee DT Sacco Society Limited associated parties such as vendors, contractors and any other third party who handle and use Harambee DT Sacco Society Limited information (where Harambee DT Sacco Society Limited is the 'Controller' for the personal data being processed, be it in manual and automated forms or if others hold it on their systems for Harambee DT Sacco Society Limited).
- All personal data processing Harambee DT Sacco Society Limited carries out for others (where Harambee DT Society Limited is the 'Processor' for the personal data being processed) and,
- All formats, e.g., printed, digital information, text and images, documents and records, data and audio recordings.
Definitions
Data controller: means a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purpose and means of processing personal data
Data processor: means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the data controller
Data subject: means an identified or identifiable natural person who is the subject of personal data
"Processing" collectively means handling, collecting, using, altering, merging, linking, organizing, disseminating, storing, protecting, retrieving, disclosing, erasing, archiving, destroying, or disposing of your personal information.
"You" means:
- Member – (which includes personal representatives and assigns) operating an Account held with us and includes (where appropriate) any person you authorize to give us instructions, the person who uses any of our products and services or accesses our websites. "Customer" shall include both the masculine and the feminine gender as well as juristic person.
- Any agent, dealer and/or merchants who has signed an agreement with us and is recognized as a merchant or agent in accordance with any applicable laws or Regulations.
- Any visitor that is a person (including contractors/subcontractors or any third parties) who gains access to any Harambee DT Sacco Society Limited premises or other areas/sites of operations.
- Any supplier/service provider who has been contracted by Harambee DT Sacco Society Limited.
- Any external lawyer who has tendered his/her application and/or signed a service level agreement with Harambee DT Sacco Society Limited.
- Any valuer or auctioneer who has signed an agreement with Harambee DT Sacco Society Limited.
The word "includes" means that what follows is not necessarily exhaustive and therefore the examples given are not the only things/situations included in the meaning or explanation of that text.
Personal data; means any information relating to an identified or identifiable natural person
'Harambee', 'us', 'we', 'our' or 'ours' means Harambee DT Sacco Limited.
Legal Basis/Lawful purposes Data Collection
- All data processed by SACCO will be done on one of the following lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests
- Where consent is relied upon as a lawful basis for processing data, evidence of opt-in consent shall be kept with the corresponding personal data.
- Where communications are sent to individuals based on their consent, the option for the individual to revoke their consent should be clearly available and systems shall be in place to ensure such revocation is reflected accurately in Harambee SACCO systems.
Data Collection
Harambee DT Sacco Society Limited will only collect personal data about you in so far as is necessary to achieve the purposes set out in this privacy statement. We collect your personal information with your knowledge and consent with the exception of cases where prior consent cannot be obtained for real reasons and the processing of the data is permitted by law.
We collect your personal information during the following instances (this list may not be exhaustive):
- When you join the Sacco and fill in a membership form or give your details during virtual registration, electronically (email), telephonically etc.
- When you apply for a loan.
- Register for a specific product or service offered by Harambee Sacco, including but not limited to; Harambee M-cash, ATM cards, Salary agreement, Toto junior or any other Harambee Sacco product
- Ask Harambee Sacco for more information about a product or service or contact the Sacco with a query or complaint.
- Respond to or participate in a survey, marketing promotion, prize competition or special offer.
- We may also collect your information from other organizations including the credit-reference bureaus, fraud prevention agencies, government agencies and business directories.
- We may collect your information when you interact with us as a supplier, agent, merchant or dealer.
- We also collect information when you visit any of our buildings or premises
- Use any of our products and/or service online, on a mobile or other device or in any of our branches or with any of our agents or merchants.
- Ask Harambee Sacco for more information about a product or service or contact Harambee Sacco with a query or a complaint.
- Where you've been identified as a next of kin by our member or employee.
- Where you have applied for employment at Harambee Sacco.
- Attend an event sponsored by Harambee Sacco.
- Visit, access or use any of our online platforms/websites.
- Subscribe to any of our online services, Short Message Service (SMS), email or social media platforms.
- When you engage our insurance services or as a result of your relationship with one or more of our staff and clients.
These examples are non-exhaustive, which is reflective of the varied nature of the personal information we may collect.
What information is collected
From individuals who are our members and prospective members, or are representatives of members and prospective members, we may collect personal information that includes but is not limited to the following:
The information we collect and store about you includes but is not limited to the following:
- Your identity information, including your title, name, photograph, marital Status, nationality, occupation, residence, address, location, phone number, identity document type and number, date of birth, age, gender, your email address.
- Name of your employer, terms of employment and if on contract, expiry of the contract.
- Your signature specimen
- Salary details
- Next of Kin/Beneficiaries details
- We maintain a register of visitors in which we collect and keep your personal data such as name, company/institution details, telephone number, vehicle registration details and National ID number. This information is collected for health, safety, and security purposes.
- Your credit or debit-card information, information about your bank account numbers and/or other banking information.
- Your transaction information when you use our electronic and digital platforms, branches, our agents and/or merchants.
- Your contact with us, such as when you: call us or interact with us through social media, email (we may record your conversations, social media or other interactions with us), register your biometric information such as your voice, fingerprints etc, visit our branches.
- Relevant information as required by regulatory Know Your Client and/or Anti Money Laundering regulations and as part of our member onboarding procedures.
- We use Closed Circuit Television (CCTV) surveillance recordings. CCTV Devices are installed at strategic locations to provide a safe and secure environment in all our branches, Harambee DT Sacco premises as a part of our commitment to security and crime prevention.
- We maintain a register of visitors in which we collect and keep our personal data such as names, company/institution details, telephone number.
- We collect and retain your personal data (name, telephone number, and vehicle registration details) when you request a parking space in any of our Harambee DT Sacco premises.
- When you use Harambee DT Sacco network for guests and visitors, we collect email IDs and will provide username and password.
- The information you provide to us for the purpose of attending meetings and events.
- Information that you provide to us and/or Correspondent as part of the provision of Services to you, which depends on the nature of your engagement.
- We may collect details of a minor which include name, date of birth, birth certificate number, relationship with the applicant and any other information relevant to the provision of our products and services. We will only process such data where parental or legal consent has been given.
Use of Information
Some of the purposes for which we collect and process your data includes (this list may not be exhaustive):
- To notify you about changes to our Service, your transactions.
- To detect, prevent and address technical issues and/fraud
- To provide you with news, special offers and general information about our products, services and events or enquiries about unless you have opted not to receive such information.
- Verifying your identity information through publicly available and/or restricted government databases to comply with applicable Know Your Customer (KYC) requirements.
- Creating a record of you on our system to verify your identity, provide you with the products and/or services you have applied for from us or from third parties on our ecommerce platforms.
- Communicate with and keep you informed about the products and/or services you have applied for.
- Identifying you and similar information
- Assessing your personal financial circumstances and needs before providing advice to you.
- Responding to any of your queries or concerns, we may record or monitor telephone calls between us so that we can check instructions and make sure that we are meeting our service standards.
- Carrying out credit checks and credit scoring.
- To perform our obligations under a contractual arrangement with you.
- Fraud prevention, detection and investigation
- Any purpose related to the prevention of financial crime, including sanctions screening, monitoring of anti-money laundering and any financing of terrorist activities.
- To understand how you use our products and services for purposes of developing or improving products and services.
- Administer any of our online platforms/websites.
- To comply with any legal, governmental, or regulatory requirement or for use by our lawyers in connection with any legal proceedings.
- Keeping you informed generally about new products and services and contacting you with offers or promotions unless you opt out of receiving such marketing messages.
- Where you have applied for employment at Harambee DT Sacco Society, we perform applicant screening and background checks.
- Where you are a Harambee DT Sacco Society employee (including contractors), we create an employment record of you on our system.
- Where you are a Harambee DT Sacco Society director, and we create a record of you as a director on our system.
- Where you are a supplier to Harambee DT Sacco Society, we process your personal information for due diligence, risk assessment, administrative and payment purposes.
- For security purposes when accessing any of Harambee DT Sacco Society buildings/premises; and
- When you attend an event sponsored by Harambee DT Sacco Society, we will be taking photos or videos of the event.
Where personal data relates to a child, we will process the personal data only where parental or legal guardian consent has been given. The processing of such data will be done in a manner that protects and advances the rights and best interests of the child.
Transfer of Personal Data
Harambee DT Sacco Society may transfer your personal information for the purpose of implementing/implementing, administering, and securing any product or service that you have applied for or for other purpose set out in this privacy statement. We also share data with Harambee DT Sacco Society-controlled affiliates and subsidiaries; with vendors working on our behalf; when required by law or to respond to legal process; to protect our customers; to protect lives; to maintain the security of our products; to comply with regulatory requirements and to protect the rights and property of Harambee DT Sacco Society and its members.
We may transfer or disclose the personal data we collect to regulatory, supervisory authorities, correspondent banks on transaction enquiries, third party contractors, subcontractors, and/or their subsidiaries and affiliates who provide support to Harambee DT Sacco Society in providing its services. The third-party providers may use their own third-party subcontractors that have access to personal data (sub-processors).
It is our policy to use only third-party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by Harambee DT Sacco Society, and to carry those same obligations down to their sub-processors.
Direct Marketing
From time to time, we may also use your personal information to contact you for market research or to provide you with information about other services we think would be of interest to you. You may be required to opt-in or give any other form of explicit consent before receiving marketing messages from us. We respect your right to control your personal data depending on which of our products you use. Therefore, at a minimum, we will always give you the opportunity to opt-out of receiving such direct marketing or market research communications. You may exercise this right to opt-out at any time.
Disclosure of Information
Harambee Sacco Limited may disclose your Personal Data to 3rd Parties in the good faith belief that such action is necessary but not limited to:
- To comply with a legal obligation.
- To protect and defend the rights or property of Harambee DT Sacco Limited.
- To prevent or investigate possible wrongdoing in connection with the Service.
- To protect the personal safety of users of the Service or the public.
- To protect the Sacco against legal liability.
- To service providers contracted to improve the customer/member experience.
Retention of Information
Harambee DT Sacco Limited will retain your Personal Data only for as long as is necessary for the purposes set out in this Data Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
The Use of Cookies
We may store some information (using "cookies") on your computer when you visit our websites. This enables us to recognize you during subsequent visits. The type of information gathered is non-personal such as: the Internet Protocol (IP) address of your computer, the date and time of your visit, which pages you browse and whether the pages have been delivered successfully. We use cookies for storing and honoring your preferences and settings, enabling you to sign in, providing interest-based advertising, combating fraud, analyzing how our products perform, and fulfilling other legitimate purposes.
We may also use this data in aggregate form to develop customized services - tailored to your individual interests and needs. Should you choose to do so, it is possible (depending on the browser you are using), to be prompted before accepting any cookies, or to prevent your browser from accepting any cookies at all. This will however cause certain features of the web site not to be accessible.
Your data rights
As a Data Subject you have the following Rights as set out in the Data Protection Act No. 24 of 2019:
- The right to be informed of the use of your information/data.
- The right to access, update or delete the information or data in our custody. This right is not absolute and maybe subject to the nature of the data and other prevailing laws.
- The right of rectification. You have the right to have your information/data rectified or deleted if that information is misleading, inaccurate, or incomplete.
- The right to object. You have the right to object to our processing of your Personal Data.
- The right of restriction. You have the right to request that we restrict the processing of your personal information.
- The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable, and commonly used format
- The right to withdraw consent. You also have the right to withdraw your consent at any time where Harambee DT Sacco Society Limited relied on your consent to process your personal information, without any detriment to your interests.
Data minimization
The SACCO shall ensure that personal data is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Accuracy
- The SACCO shall take reasonable steps to ensure personal data has integrity and is kept accurate.
- Where necessary for the lawful basis on which data is processed, steps shall be put in place to ensure that personal data is kept up to date.
Security
- The SACCO shall ensure that personal data is stored securely in order to guarantee Confidentiality, Integrity, and Availability of personal data
- Access to personal data shall be limited to personnel who need access and appropriate security shall be in place to avoid unauthorized sharing of information.
- When personal data is deleted, it shall be done safely such that the data is irrecoverable across the data value chain.
Data Breach
In the event of a personal data breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, the SACCO shall promptly assess the risk to data subjects' rights and freedoms and appropriately report to the Data Commissioner as per the provisions of the Data Protection Act.
Data Protection Officer Contact
If you wish to exercise any of the rights set out above, please contact us on either of the following:
Please note that we may ask you to verify your identity and provide signed instructions before responding to such requests. This is a security measure to ensure that personal data is not disclosed to any person who has no right to access
We try to respond to all legitimate requests within a reasonable time. Occasionally it could take us longer if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Amendments to this Policy
Harambee DT Sacco Society reserves the right to amend or modify this privacy policy from time to time and your continued use of our products and services constitutes your agreement to be bound by the terms of any such amendment or variation. You can access the most current version of the privacy statement from www.harambeesacco.com and Any amendment or modification to this statement will take effect from the date of notification on the Harambee DT Sacco Society website.
If you have any questions about this Data Privacy Policy, please contact us on logachi@harambeesacco.com or 0709943000/0709943100/0709943112