Data Security & Governance

Privacy Policy

Your privacy and data security are foundational to our mission of empowering African SACCOs and credit cooperatives with transparent digital infrastructure.

Last Updated: August 2026

PostgreSQL RLS Security

Strict tenant data isolation enforced at the database level with 256-bit encryption for all member records.

Data Minimization

We collect strictly necessary SACCO member KYC and financial data required for cooperative operations.

Audit Transparency

Complete audit logs and access tracking giving members and SACCO leadership total visibility over data usage.

1. Introduction

Mikopo Platform ("we," "our," or "us") is committed to safeguarding the privacy and security of personal and financial information processed through our SACCO Management System. This Privacy Policy outlines how we collect, use, store, and protect data when SACCO staff, administrators, and members interact with our system, in compliance with regional data protection frameworks and international standards.

2. Information We Collect

A. Member KYC & Personal Information

  • Full legal name, date of birth, gender, and national identification details (NIN)
  • Contact details (phone number, email address, village/district location)
  • Employment status, declared monthly income, and Next-of-Kin details
  • Uploaded KYC verification documents (National ID photo, passport photo)

B. SACCO Financial & Share Data

  • Savings balances, fixed deposit records, and transaction histories
  • Loan applications, guarantor commitments, repayment schedules, and arrears tracking
  • Share capital contributions, share holdings, and dividend payout history
  • Linked payout accounts (Mobile Money numbers and Bank account details)

C. Technical & System Logs

  • Session identifiers, IP address logs, browser metrics, and operational audit trails
3. How We Use Information
SACCO Operations: Managing member accounts, processing loan applications, calculating share dividends, and generating financial statements.
Compliance & KYC: Verifying member identities, maintaining legal audit trails, and satisfying regulatory requirements.
Communications: Sending operational updates, loan repayment reminders, and real-time support messages.
Security & Fraud Prevention: Enforcing PostgreSQL Row-Level Security, preventing unauthorized cross-tenant data access, and monitoring system integrity.
4. Data Security & Multi-Tenant Protection

Mikopo employs enterprise-level safeguards to protect member records:

Technical Controls
  • PostgreSQL Row-Level Security (RLS)
  • 256-bit TLS/SSL encrypted transit
  • Encrypted database storage
  • Vercel Blob secure document vault
Access Controls
  • Role-Based Access Control (RBAC)
  • JWT session guards & hydration
  • Session timeout policies
  • Comprehensive operational audit trails
5. Data Retention
Active Member KYC RecordsDuration of Membership + 7 Years
SACCO Loan & Guarantor Files7 Years after Loan Closure
Financial Transaction Ledgers7 Years from Transaction Date
System Audit Logs2 Years
6. Contact Privacy Office

If you have questions regarding this Privacy Policy or wish to exercise your data subject rights, please reach out to our Privacy Office:

Email
privacy@mikopo.africa
Phone
+256 700 000 000
Offices
Kampala & Nairobi