Privacy & Data Protection Notice
Last updated: 22 June 2026 · Version 1.0
This notice explains what personal data Mizani processes, why and on what legal basis, who we share it with, where it is stored, and the rights you have over it.
1. About this notice
Mizani is a record-keeping platform for savings groups, SACCOs, VSLAs and chamas. We help groups keep accurate records of savings, shares, contributions, loans and welfare cover. Mizani never holds members' money — money is held and moved by the group and its members outside our platform. We serve users in the United Kingdom, Uganda, Kenya, Rwanda and the wider East Africa region.
The controller for the purposes covered by this notice is Mizani UK Limited ("Mizani", "we", "us"), a company incorporated in England and Wales (company number [COMPANY NUMBER]), registered office [REGISTERED OFFICE ADDRESS].
We comply with the UK GDPR and the Data Protection Act 2018, together with applicable local data-protection law in Uganda, Kenya and Rwanda.
Controller and processor — the split
Data-protection law assigns responsibilities depending on who decides how and why data is used:
- Your group's member records. For the records a group keeps about its members (savings, shares, contributions, loans, welfare and the like), the group (the SACCO, VSLA or chama) is the data controller and Mizani acts as its processor. We process those records on the group's documented instructions.
- Account, billing and marketing data. For the data we hold to run your account, take payment from paying groups, secure the service and send you marketing, Mizani is the controller.
2. The information we collect
We process the following categories of personal data:
Identity
- Surname, other names and preferred name.
- National ID reference.
- Country.
Contact
- Phone number and email address.
- WhatsApp and SMS contact details, with recorded opt-in consent before we send business-initiated messages.
Identity checks
- Identity-check (KYC) status held against a member's record.
Your group's financial records
Records we keep on the group's behalf, as its processor — including savings, shares, contributions, loans and repayments, welfare cover, claims and payouts, withdrawals and ledger entries.
Account & security
- Sign-in identifiers.
- Session cookies.
- Audit logs of actions taken in the platform.
- A record of your acceptance of these terms — the version you accepted, the date and time, your IP address and device (browser) information — which we keep as evidence of consent.
Messages
- Messaging logs of the notifications and messages we send and their delivery status.
3. How we use your information and our legal basis
Under Article 6 of the UK GDPR we must have a lawful basis for each use of your personal data. The bases we rely on are:
- Performance of a contract. To run the service: create and maintain accounts, keep group records on the group's behalf, and provide the features you and your group use.
- Consent. To send WhatsApp, SMS and marketing messages. Members opt in, and can stop at any time by replying STOP.
- Legal obligation. To meet record-keeping, tax, identity-check and other obligations the law places on us.
- Legitimate interests. To keep the service secure, prevent and detect fraud, and improve our product. Where we rely on legitimate interests we balance them against your rights and interests.
4. Messages and your consent
Some messages we send are business-initiated — for example reminders, statements and updates over WhatsApp or SMS. We only send these to members who have opted in, and we record that opt-in. You can opt out at any time by replying STOP to a message; we will stop sending you those messages.
Service messages are different. Sign-in codes, security notices and other messages that are essential to operate your account are service communications, not marketing, and you cannot opt out of them while you use the service.
5. Cookies
We use a small number of cookies, including session cookies needed to keep you signed in. For the full list and how to control them, see our Cookie Policy.
6. Who we share information with
We use trusted third parties ("sub-processors") to deliver the service. They process personal data on our behalf under contract and only on our instructions:
- Supabase — Database, authentication and file storage. European Union (France). Privacy policy.
- Cloudflare — Edge network and background processing (Workers). Global edge network. Privacy policy.
- Meta Platforms (WhatsApp) — WhatsApp Business messaging to members who opt in. Ireland / United States. Privacy policy.
- Resend — Transactional email (sign-in codes, invites, notices). United States. Privacy policy.
We do not sell your personal data. We may disclose personal data where we are required to do so by law, regulation or a valid legal request, or to establish, exercise or defend legal claims.
7. Where your information is stored and international transfers
Your data is stored in the European Union (Paris, France), on infrastructure provided by Supabase. Because our users are in the UK and East Africa, your data may be transferred internationally:
- For UK users. Data stored in the EU (France) relies on the UK–EU adequacy decision, under which the EU is recognised as providing an adequate level of data protection.
- For users in Uganda, Kenya and Rwanda. Transfers to the EU/UK use appropriate safeguards. [PLACEHOLDER: transfer mechanism] (for example standard contractual clauses or another lawful safeguard, to be confirmed by counsel for each jurisdiction).
8. How long we keep it
We keep personal data only for as long as we need it for the purposes above, or as required by law. Our proposed default retention periods are:
- Your group's records. Kept for as long as the group uses Mizani and in line with the group's instructions as controller; on the group's instruction we delete or return them. [PLACEHOLDER: firm retention period after a group stops using Mizani — proposed default: 90 days, then deletion].
- Account & security data. [PLACEHOLDER: proposed default — keep audit logs for 12 months].
- Messaging logs. [PLACEHOLDER: proposed default — 12 months].
- Billing records. [PLACEHOLDER: proposed default — 6 years to meet UK tax/accounting obligations].
9. How we protect your information
We apply technical and organisational measures appropriate to the data we hold, including:
- Row-level security in our database, so each group can only see its own records.
- Encryption in transit for data moving between you, us and our sub-processors.
- Access controls and audit logs, so access is limited to those who need it and significant actions are recorded.
10. Your rights
Subject to the conditions in applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data ("the right to be forgotten").
- Restriction of how we process your data.
- Objection to processing based on legitimate interests, and to direct marketing.
- Portability — to receive your data in a portable format.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email privacy@mizaniapp.com. Where a request concerns records we hold for your group, the group is the controller, and we may need to direct your request to the group so it can decide how to respond. We aim to respond to requests within about one month.
11. Complaints
If you have a concern, please contact us first at privacy@mizaniapp.com so we can try to put it right. You also have the right to complain to the data-protection regulator in your country:
- United Kingdom: Information Commissioner's Office (ICO) — https://ico.org.uk
- Uganda: Personal Data Protection Office (PDPO), under NITA-U — https://www.pdpo.go.ug
- Kenya: Office of the Data Protection Commissioner (ODPC) — https://www.odpc.go.ke
- Rwanda: National Cyber Security Authority (NCSA) — https://ncsa.gov.rw
12. Children
Mizani is not intended for under-18s. Where a member is under 18, their participation should only be through a parent or guardian, or under the group's authority. [PLACEHOLDER: confirm the process and consent requirements for members under 18 across the UK, Uganda, Kenya and Rwanda].
13. Changes to this notice and how to contact us
We may update this notice from time to time. When we make a material change we will update the "last updated" date above and, where appropriate, tell you directly.
For any question about this notice or your personal data, or to reach our data protection contact, email privacy@mizaniapp.com.
Mizani UK Limited, a company registered in England and Wales (company number [COMPANY NUMBER]). Questions about this document? privacy@mizaniapp.com.

