Privacy Policy
1. Who we are (data controller)
For membership, savings, credit, dividends, collections, and related SACCO services, Soyosoyo SACCO is the primary data controller. We determine why and how member data is processed for SACCO purposes.
Technology that powers our digital member experience may be provided by Nichomez / Nichomez Enterprise (and its hosting and connectivity partners) as a data processor or service provider acting on our documented instructions. Where Nichomez processes data for its own platform operations, its role and notices may also apply; this Policy remains the SACCO-facing statement for Soyosoyo members.
Contact for privacy requests: info@soyosoyosacco.com (subject line: “Data Protection / Privacy”). We may designate a Data Protection Officer (DPO) or privacy contact as our scale and ODPC requirements evolve; updated contacts will appear on this page.
2. Scope
This Policy covers personal data relating to:
- prospective members, applicants, and registered members;
- guarantors, beneficiaries, next of kin, and authorised contacts you provide;
- officials and staff accessing SACCO systems;
- website visitors, form submitters, and users of calculators or public tools;
- users of the member portal (including api.soyosoyosacco.com) and the Nichomez Android / web apps configured for Soyosoyo SACCO.
It does not replace our constitution, by-laws, credit policy, or loan product schedules. If there is a conflict on a SACCO governance matter, those governing documents prevail for membership and credit, while this Policy governs personal-data handling to the extent required by law.
3. Categories of data we process
Depending on your relationship with us, we may process:
- Identity & KYC: name, national ID / passport details, date of birth, photographs or selfies used for verification, membership / registration numbers.
- Contact: phone numbers (including M-Pesa MSISDN), email, physical / postal address, town or county.
- Membership & finance: contributions, share capital, risk fund, invoices, arrears, loan applications and balances, repayment schedules, dividends / outlook figures, standing orders, family-pay beneficiaries, wallet balances and transfers.
- Payments & banking: paybill / till references, STK / funds-transfer status messages, bank account or payout channel details you register, fee and charge records.
- Device & security: device identifiers, app version, IP address, login timestamps, authentication events (including biometrics if you enable them on your device), push-notification tokens, fraud / abuse signals.
- Communications: SMS, in-app notifications, emails, support chats, call notes where you contact us.
- Website analytics: if enabled (e.g. Google Analytics), aggregated or pseudonymous usage metrics such as pages viewed and approximate location derived from IP.
- Special / sensitive data: only where necessary and lawful (e.g. limited health-related context if you voluntarily provide it for a medical-purpose loan narrative, or biometric templates stored on-device for unlock). We do not seek unnecessary sensitive data.
4. Sources of data
- you (registration forms, app profile, loan applications, uploads);
- your activity on our website, portal, and apps;
- payment processors and banks (e.g. M-Pesa / KCB IPN, STK, funds-transfer callbacks);
- guarantors, officials, and other members where your role requires it (e.g. guarantor requests);
- public or regulatory sources where we must verify identity or comply with law;
- legacy SACCO records migrated into digital systems with appropriate controls.
5. Purposes and legal bases (Kenya DPA)
We process personal data only for specified, explicit, and legitimate purposes, including:
- Membership administration — onboarding, KYC, contributions, statements, dividends, exits / reinstatement (contract / membership rules; legal obligation; legitimate interests in orderly co-operative governance).
- Credit assessment & loan servicing — qualification, approval workflows, disbursement, repayment, arrears, guarantors, collections (contract; legitimate interests; legal obligation where applicable).
- Payments & treasury — allocating deposits, wallet operations, payouts, reconciliation (contract; legitimate interests; legal obligation for financial records).
- Security & fraud prevention — authentication, access control, abuse detection (legitimate interests; legal obligation).
- Communications — transactional notices (due dates, OTP, disbursement status). Marketing only where permitted and with opt-out where required (consent or legitimate interests as applicable).
- Analytics & product improvement — aggregated insights to improve services (legitimate interests; consent where cookies / analytics require it).
- Legal & regulatory — Co-operative Societies framework, SASRA / county co-operative supervision where applicable, tax, court orders, ODPC, AML/CFT expectations as they apply to SACCOs (legal obligation / public interest).
- App store & platform compliance — meeting Google Play and similar requirements for user data transparency, security, and account deletion pathways (legitimate interests / legal obligation).
Where we rely on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal. Withdrawal may limit certain optional features but will not erase records we must keep for membership, credit, or law.
6. Nichomez app & digital channels
When you use the Nichomez-powered Soyosoyo experience (Android app or web portal):
- login credentials and session tokens are used to authenticate you;
- financial screens display data from SACCO systems under access controls;
- device permissions (camera, biometrics, notifications, contacts if you opt in for pickers) are requested only for stated features and can usually be revoked in device settings;
- crash / diagnostic data may be collected in limited form to keep services reliable;
- we do not sell your personal data.
Third-party SDKs (maps, analytics, push, payment SDKs) process data only as needed for those features and under their own policies where they act as independent controllers.
7. Sharing and disclosures
We may share personal data with:
- Nichomez and infrastructure hosts / cloud providers under processing terms;
- banks, mobile-money operators, and payment rails you use;
- auditors, advocates, collection agents, insurers, or professional advisors under confidentiality;
- guarantors and credit-committee participants as required by loan process;
- regulators, courts, or law-enforcement where legally required;
- another co-operative or successor entity in a merger / restructuring, with appropriate notice and safeguards.
We do not sell membership lists for unrelated third-party marketing.
8. Cross-border transfers
Systems may be hosted in Kenya or abroad. Where personal data is transferred outside Kenya, we take steps consistent with the Data Protection Act, 2019 (e.g. adequacy, contractual safeguards, or other lawful transfer mechanisms) and apply security controls appropriate to the risk.
9. Retention
We retain personal data only as long as needed for the purposes above, including:
- active membership and service delivery;
- statutory and co-operative record-keeping periods for financial and membership archives;
- loan and guarantee lifecycle plus limitation periods for disputes;
- security logs for a shorter operational window unless needed for investigations.
When retention ends, we delete, anonymise, or archive data in a manner that reduces identifiability where feasible.
10. Security (duty of care)
We apply organisational and technical measures appropriate to the sensitivity of SACCO financial data, including access roles, authentication, encryption in transit where supported, logging, staff confidentiality expectations, and vendor diligence. No method of transmission or storage is perfectly secure; you must also protect your PIN, OTP, device lock, and passwords and notify us promptly of suspected compromise.
11. Your rights (Kenya)
Subject to the Data Protection Act, 2019 and applicable exemptions, you may have rights to:
- be informed about processing;
- access your personal data;
- object to processing in certain cases;
- correction of inaccurate data;
- deletion where lawful (see also Account deletion);
- data portability where applicable;
- restriction of processing in defined circumstances;
- not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, except where permitted (e.g. necessary for a contract, authorised by law, or with your consent with suitable safeguards).
To exercise rights, email info@soyosoyosacco.com with enough detail to verify your identity. We will respond within timelines required by law. You may also lodge a complaint with the Office of the Data Protection Commissioner (ODPC).
12. Children
Our membership and digital services are intended for persons who can lawfully contract and join under SACCO rules (generally adults). We do not knowingly market the app to children. Where a minor’s data appears (e.g. as a dependent name you supply), we process it only as needed for your membership administration.
13. Cookies and similar technologies
Our website may use essential cookies for security and session continuity, and analytics cookies (e.g. Google Analytics) to understand traffic. You can control cookies via browser settings. Blocking some cookies may affect site features.
14. Breach notification
Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will take steps consistent with Kenyan law, including notifying the ODPC and, where required, affected individuals, and documenting the incident and remediation.
15. Google Play / app-store alignment
For Android distribution we maintain this publicly accessible Privacy Policy, disclose data practices accurately in store listings (Data safety), and provide a pathway to request account / data deletion as described in Account deletion. In-app and store links should point to this Policy URL: https://soyosoyosacco.com/Privacy-Policy.html.
16. Changes
We may update this Policy to reflect legal, product, or governance changes. The “Effective” date above will change when we publish a material revision. Continued use of digital services after notice of material changes constitutes acknowledgement of the updated Policy, except where consent is legally required for a new purpose.
17. Contact
Soyosoyo SACCO — Privacy / Data Protection
Email: info@soyosoyosacco.com
Web: https://soyosoyosacco.com
Member portal: https://api.soyosoyosacco.com/login
