Security & Privacy

Your data deserves clarity, care,and protection.

This policy explains how Sandi AI collects, uses, protects, retains, and manages your personal information.

01

Introduction and Regulatory Alignment

Sandi AI is deeply committed to the privacy and security of our community in Uganda. We operate as a financial technology and AI organization under the laws of the Republic of Uganda. This Policy is specifically designed to meet the rigorous standards of the Data Protection and Privacy Act, 2019, and the Data Protection and Privacy Regulations, 2021.

We believe that transparency is the bedrock of trust. This document outlines how we handle your information with the care, integrity, and security it deserves. By using our platforms, you are choosing to partner with us under these established safeguards, which combine Ugandan legal requirements with global best-in-class security practices.

02

Understanding Your Rights as a Data Subject

In alignment with Section 13 of the Ugandan Data Protection and Privacy Act, we want to ensure you are fully informed before you share any information with us. We break down the details of our data practices so you know exactly what to expect.

Nature and Purpose

We will always explain exactly what data we are collecting - such as your name or savings history - and why we need it, specifically to power our AI financial services.

Our Identity

As the data controller, Sandi AI is responsible for your information, and we provide this policy as our formal commitment to you.

Mandatory vs. Discretionary

We will clarify whether providing specific data is a strict requirement for using a service, such as KYC identity checks, or optional information provided at your convenience.

Your Right to Access

You have the legal right to ask us what information we hold about you and to have any mistakes corrected immediately.

Data Sharing

We will be transparent about who receives your data, ensuring you know if and when it is shared with authorized service providers.

Consequences

We will explain what happens if you choose not to share certain data, such as a limitation on specific financial product features.

03

Our Approach to Data Collection and Minimization

We believe in collecting only what is truly necessary to help you reach your financial goals. By practicing data minimization, we reduce risks to your privacy.

Identity Information

To keep our communal platform safe and compliant with KYC laws, we collect details such as your full name, age, gender, and National Identification Number (NIN).

Financial Data

We analyze transactional history and savings habits. This is the core of our AI, which helps us build credit profiles to better serve your community.

Special Personal Data

If we ever need to collect more sensitive financial or personal data, we treat it with an even higher level of cryptographic protection, ensuring it is never accessible to unauthorized parties.

05

Multi-Layered Technical Security Architecture

We treat your data like a vault. Our Zero-Trust Architecture means we do not rely on one lock; we have layers of security protecting your information from every angle.

Identity Governance

We use multi-factor authentication (MFA) for our staff. This means even if someone had a password, they could not get in without a second form of verification.

Infrastructure Isolation

We keep our AI inference clusters completely separate from our financial ledgers. This ensures that a technical issue in one area cannot affect the safety of your personal financial records.

Cryptographic Integrity

All your data is scrambled using high-level AES-256 encryption. Whether it is moving across the internet or sitting in secure storage, it is unreadable to anyone without authorized, hardware-protected keys.

06

Your Right to Manage Your Data

Retention

We keep your data only for as long as the law requires or as long as it is actually useful for the services you signed up for.

Right to be Forgotten

You can request that we delete or destroy your personal data. We will fulfill this request promptly, though we may need to keep some records if Ugandan law strictly requires us to maintain them for financial auditing.

Legal Retention

In rare cases, such as court processes or investigations, we may be legally obligated to hold certain records, but we only do this to the exact extent required by Ugandan authorities.

07

Data Sovereignty and International Transfers

Standard Clauses

If we ever need to move data to a secure international server, we ensure that the destination country provides protection at least as strong as what you enjoy here in Uganda.

Legal Compliance

We strictly follow Section 19 of the Ugandan Act, ensuring all international processing is done through legally binding contracts that put your privacy first.

08

Incident Response and Accountability

WORM Storage

We use Write-Once-Read-Many logs. This means every time someone touches your data, it is recorded in a way that cannot be changed or deleted, providing an honest history for auditors.

Rapid Notification

If there were ever a breach, we would notify both the Personal Data Protection Office (PDPO) and you immediately, with full details on what happened and how we are fixing it.

Continuous Audit

We do not just set these rules; we test them. We undergo regular security assessments and invite independent experts to check our work to ensure we are always living up to our promises.

09

We Are Here to Help

If you have questions, concerns, or simply want to know what data we have about you, please reach out. Our team is dedicated to listening and assisting you.