Back to Home

PesaMind Privacy Policy

This policy explains how PesaMind collects, processes, secures, and governs personal data in compliance with Uganda's Data Protection and Privacy Act.

Version: 1.0

Effective Date: 1 July 2025

Last Reviewed: 1 July 2025

Data Controller: dLabs Uganda Limited

Governing Law: Laws of the Republic of Uganda

DefinitionsData CollectedLegal BasisAI TrainingSecurityYour RightsContact

1. DEFINITIONS

In this Privacy Policy, unless the context otherwise requires:

  • (a) "Act" means the Data Protection and Privacy Act 2019 (Act No. 9 of 2019) of Uganda and any Regulations made thereunder.
  • (b) "Anonymised Data" means Personal Data that has been irreversibly altered by aggregation, pseudonymisation, generalisation, suppression, or any combination thereof, such that no individual can reasonably be identified, directly or indirectly, whether by dLabs Uganda Limited alone or in combination with any other data controller, consistent with the standard described in Recital 26 of the General Data Protection Regulation (EU) 2016/679 (applied as a persuasive interpretive standard).
  • (c) "App" means the PesaMind mobile application available on iOS and Android platforms, including all versions, updates, and successor products.
  • (d) "Company," "we," "us," or "our" means dLabs Uganda Limited, a company incorporated under the laws of Uganda, and its affiliates, subsidiaries, assigns, and successors in title.
  • (e) "Financial Data" means any information relating to your income, expenditure, savings, budget targets, mobile money transactions, bank account references, and financial channel configurations entered into or derived by the App.
  • (f) "Personal Data" has the meaning assigned to it under section 3 of the Act and includes any information relating to an identified or identifiable natural person.
  • (g) "Processing" has the meaning assigned to it under section 3 of the Act and includes collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, erasure, and destruction.
  • (h) "Sensitive Personal Data" has the meaning assigned to it under section 3 of the Act and includes Financial Data, biometric data, and data relating to your financial standing.
  • (i) "Training Data" means Anonymised Data derived from aggregated usage patterns, spending trends, budget behaviours, and feature interactions, used solely to improve, train, fine-tune, or evaluate machine learning models and artificial intelligence systems operated by or on behalf of the Company.
  • (j) "User," "you," or "your" means any natural person who downloads, installs, registers for, or uses the App.

2. IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER

dLabs Uganda Limited
Registered Office: Kampala, Uganda
Email: privacy@dlabs.cc
Website: https://dlabs.cc

The Company is the Data Controller in respect of all Personal Data processed through the App. The Company shall, in accordance with section 27 of the Act, maintain a register of all data processing activities.

3. PERSONAL DATA WE COLLECT

We collect and process the following categories of Personal Data:

3.1 Account and Identity Data

  • (a) Full name and username
  • (b) Email address
  • (c) Password (stored as a one-way cryptographic hash; we never store your plain-text password)
  • (d) Account type and registration date

3.2 Financial Data (Sensitive Personal Data)

  • (a) Monthly and yearly budget targets (income, expenditure, savings goals)
  • (b) Transaction records including amount, type (income/expense), date, and note
  • (c) Financial channel configurations including mobile money provider (MTN, Airtel), mobile number (stored in encrypted form), bank name, and account number
  • (d) Budget utilisation percentages and derived financial health scores

3.3 Device and Technical Data

  • (a) Device model, operating system version, and unique device identifier
  • (b) App version and installation identifier
  • (c) Network type and connectivity status
  • (d) Crash reports and error logs
  • (e) Session timestamps and feature interaction logs

3.4 SMS Transaction Data (Android only, with your explicit consent)

  • (a) Sender identification from mobile money SMS alerts (MTN, Airtel)
  • (b) Transaction amounts and types parsed from SMS content
  • (c) We do not store the raw SMS body beyond the session in which it is processed; only the parsed transaction record is retained

3.5 Usage and Analytics Data

  • (a) Features accessed, screens viewed, and time spent in the App
  • (b) Button taps, form submissions, and navigation paths
  • (c) Error occurrences and performance metrics

5. HOW WE USE YOUR PERSONAL DATA

We use your Personal Data for the following purposes:

  • (a) To create and manage your PesaMind account and authenticate your identity.
  • (b) To provide budget management, transaction recording, and financial analytics services.
  • (c) To automatically parse mobile money SMS alerts (Android, with consent) and create transaction records without manual entry.
  • (d) To generate personalised financial health scores, spending velocity reports, anomaly alerts, and AI-powered recommendations within the App.
  • (e) To send you in-app notifications, budget alerts, and transaction confirmations.
  • (f) To maintain the security of the App, detect suspicious activity, and prevent unauthorised access.
  • (g) To comply with applicable laws, respond to lawful requests from competent authorities, and enforce our legal rights.
  • (h)To create Anonymised Data and use it as Training Data to improve, develop, and fine-tune the Company's machine learning models and AI systems, as further described in Section 6 below.

6. AI MODEL TRAINING AND ANONYMISED DATA

6.1 Our Commitment

The Company is committed to advancing the quality of financial management tools available to Ugandan users. To achieve this, we derive Training Data from aggregated and anonymised usage information.

6.2 What We Anonymise

We apply irreversible anonymisation techniques - including k-anonymity (k >= 5), differential privacy noise injection, and data aggregation - to Financial Data and usage patterns before any such data is used for model training. The resulting Training Data:

  • (a) contains no name, email address, phone number, or account number;
  • (b) contains no individual transaction record attributable to a specific person;
  • (c) consists only of aggregated statistical patterns (e.g., median expenditure-to-income ratios across user cohorts, budget utilisation distributions);
  • (d) cannot reasonably be used to re-identify any individual, whether by us alone or in combination with other data.

6.3 Legal Basis

We rely on our legitimate interests under section 11(f) of the Act to process Anonymised Data for model training. Because the data is irreversibly anonymised, it falls outside the definition of Personal Data under section 3 of the Act and is therefore not subject to the restrictions on Personal Data processing. Nevertheless, we maintain this disclosure in the interest of full transparency.

6.4 Your Right to Object

Although Anonymised Data does not constitute Personal Data, we respect your autonomy. If you do not wish your usage data to contribute to the anonymisation pipeline, you may opt out at any time by:

  • (a) navigating to Settings -> Privacy -> AI Training Opt-Outwithin the App; or
  • (b)emailing privacy@dlabs.cc with the subject line "Training Data Opt-Out."

Opting out shall not affect your access to any features of the App. Your opt-out preference shall be applied within 30 days of receipt.

6.5 No Sale of Personal Data

We do not sell, rent, or trade your Personal Data to third parties for their own marketing or commercial purposes.

7. DATA SHARING AND DISCLOSURE

We do not share your Personal Data with third parties except in the following circumstances:

  • (a) Service Providers: We engage carefully selected third-party processors (including cloud hosting providers, analytics services, and crash reporting tools) who process data on our behalf under binding data processing agreements that comply with section 25 of the Act. A current list of sub-processors is available on request.
  • (b) Legal and Regulatory Requirements: We shall disclose Personal Data where required by a court order, statute, or lawful request from a competent Ugandan authority, including the PDPO, Bank of Uganda, Uganda Communications Commission, or Financial Intelligence Authority.
  • (c) Business Transfers: In the event of a merger, acquisition, restructuring, or sale of assets, your Personal Data may be transferred to the successor entity, subject to the same protections described in this Policy. We shall notify you of any such transfer within 30 days.
  • (d) Protection of Rights: We may disclose Personal Data where necessary to enforce our Terms and Conditions, protect our intellectual property, or prevent fraud, abuse, or illegal activity.
  • (e) With Your Consent: In all other circumstances, we shall seek your prior written consent before disclosing your Personal Data to any third party.

8. DATA RETENTION

  • (a) We retain your Personal Data for as long as your account is active and for a period of five (5) years thereafter, in accordance with financial record-keeping requirements under Ugandan law.
  • (b) Transaction records and financial data may be retained for seven (7) years to comply with the Income Tax Act Cap. 340 and Anti-Money Laundering Act 2013.
  • (c) Upon expiry of the applicable retention period, we shall securely delete or irreversibly anonymise your Personal Data.
  • (d) You may request deletion of your account and associated Personal Data at any time in accordance with Section 10(c) below. Where legal retention obligations apply, we shall retain the minimum data required and delete the remainder.

9. DATA SECURITY

  • (a) We implement industry-standard security measures including AES-256 encryption at rest, TLS 1.3 encryption in transit, and HTTPS-only API communication.
  • (b)Authentication tokens are stored in the device's secure keychain (iOS) or encrypted shared preferences (Android) and are never written to device logs.
  • (c) Mobile money channel phone numbers and account numbers are stored in encrypted form using field-level encryption.
  • (d) Access to Personal Data is restricted to authorised personnel on a need-to-know basis, and all access is logged and audited.
  • (e) In the event of a Personal Data breach likely to result in a risk to your rights and freedoms, we shall notify the PDPO within 72 hours of becoming aware of the breach, in accordance with section 31 of the Act, and shall notify you without undue delay where the breach is likely to result in a high risk to you.
  • (f) No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee absolute security.

10. YOUR RIGHTS UNDER THE DATA PROTECTION AND PRIVACY ACT 2019

Under the Act, you have the following rights, which you may exercise by contacting us at privacy@dlabs.cc:

  • (a) Right of Access (s.19): You have the right to request confirmation of whether we process your Personal Data and to receive a copy of that data.
  • (b) Right to Rectification (s.20): You have the right to request correction of inaccurate or incomplete Personal Data.
  • (c) Right to Erasure (s.21): You have the right to request deletion of your Personal Data, subject to our legal retention obligations described in Section 8.
  • (d) Right to Restrict Processing (s.22): You have the right to request that we restrict processing of your Personal Data in certain circumstances.
  • (e) Right to Data Portability (s.23): You have the right to receive your Personal Data in a structured, commonly used, machine-readable format (JSON or CSV) and to transmit it to another controller.
  • (f) Right to Object (s.24): You have the right to object to processing based on legitimate interests, including the use of your data in the Anonymised Data pipeline described in Section 6.
  • (g) Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • (h) Right to Lodge a Complaint: You have the right to lodge a complaint with the Personal Data Protection Office (PDPO) of Uganda at any time.

We shall respond to all rights requests within 21 days of receipt, in accordance with section 19(3) of the Act.

11. CHILDREN'S DATA

The App is not directed at persons under the age of 18 years. We do not knowingly collect Personal Data from minors. If we become aware that we have collected Personal Data from a person under 18 without verifiable parental consent, we shall delete such data within 30 days. If you believe a minor has registered for the App, please notify us at privacy@dlabs.cc.

12. CROSS-BORDER DATA TRANSFERS

  • (a) Your data may be transferred to, and processed in, countries outside Uganda where our cloud service providers operate (including but not limited to the European Union, United States, and South Africa).
  • (b) We ensure that all cross-border transfers comply with section 28 of the Act and are subject to appropriate safeguards, including standard contractual clauses, binding corporate rules, or adequacy determinations.
  • (c) By using the App, you consent to such cross-border transfers for the purpose of providing the services described in our Terms and Conditions.

13. CHANGES TO THIS POLICY

  • (a) We reserve the right to update this Privacy Policy at any time. When we make material changes, we shall notify you via in-app notification and email at least 14 days before the changes take effect.
  • (b) Your continued use of the App after the effective date of any updated Policy constitutes your acceptance of the updated terms.
  • (c) The version history of this Policy is maintained and available on request.

14. CONTACT AND COMPLAINTS

For any privacy-related enquiries, requests, or complaints, please contact:

Privacy Officer
dLabs Uganda Limited
Email: privacy@dlabs.cc

If you are not satisfied with our response, you may lodge a complaint with:

Personal Data Protection Office (PDPO)
Ministry of ICT and National Guidance
Republic of Uganda
Website: https://pdpo.go.ug

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Uganda. This document does not constitute legal advice and should be reviewed by a licensed advocate before publication.