Skip to content

Privacy policy

Last updated 24 September 2026. This policy explains how personal data is handled in SaccoMonitor, the SACCO management software provided by the operator of SaccoMonitor.

Who is responsible for the data

Each SACCO that uses SaccoMonitor decides what member and staff information it records and why; for that data the SACCO is responsible (the data controller) and SaccoMonitor processes it on the SACCO’s behalf. For account information of people who register a SACCO or sign in, and for this website, the operator of SaccoMonitor is responsible.

What data is processed

  • Identity and contact: name, phone number, e-mail, gender, date of birth, national ID number, address, occupation and employer, as entered by the SACCO.
  • Membership: member number, member type, branch, next of kin and beneficiaries, identity documents uploaded by the SACCO.
  • Financial: savings, share, fixed deposit and loan balances and transactions, loan applications, guarantors and collateral.
  • Account and security: login identifiers, hashed passwords, active sessions, sign-in history, IP address and device information, and an audit trail of changes.
  • Messages: SMS and e-mail messages sent to members through the system, and their delivery status.

Why it is processed

  • To run the SACCO’s membership, savings, loan and accounting records at the SACCO’s instruction.
  • To let members see their own accounts and make requests.
  • To send the notifications the SACCO has switched on, such as transaction receipts and loan reminders.
  • To keep the service secure: authentication, fraud prevention and the audit trail.
  • To meet legal, accounting and audit obligations.

Personal data is not sold, and it is not used for advertising.

Who it is shared with

Data is shared only as needed to provide the service: with the hosting provider that runs the servers, with message providers used to deliver SMS,or e-mail (which receive the recipient’s number or address and the message), and with authorities where the law requires. Staff of a SACCO see only that SACCO’s data, within the permissions their role grants.

How it is protected

Access is controlled by role and branch, passwords are stored as one-way hashes, sessions expire, every change is recorded in an audit trail, and each SACCO’s data is kept separate. Private screens are excluded from search engines. More detail is on the security page.

How long it is kept

Financial records are kept for as long as the SACCO needs them to meet accounting, audit and legal requirements. Transactions are never deleted, because that would break the accounts; corrections are recorded as reversals. When a SACCO stops using the service, its data is handled as agreed with that SACCO.

Your rights

Depending on the law that applies to you — in Uganda, the Data Protection and Privacy Act, 2019 — you may ask to access or correct your personal data, or object to certain processing. Members should contact their SACCO first, as it controls their records. You can also contact the operator of SaccoMonitor at support@saccomonitor.com.

This website

The public pages of this website do not require an account. If website analytics are enabled, they record pages visited and general device information to understand how the site is used; they are not loaded inside the application.

Changes to this policy

When this policy changes, the date at the top is updated.