Privacy policy
Welcome to Mwalimu National!
We respect your right to privacy, and we guard it jealously. In this respect, this Privacy Policy sets out details of the personal data the Sacco collects, processes and for what purposes. This Policy should be read alongside, and in addition to, the Data Protection Policy and therefore read it carefully. The policy applies to all customers, suppliers, agents, and all visitors frequenting any of the Saccos premises.
Unless otherwise defined in this Privacy Policy, terms used have the same meaning as in the Terms.
TERMS
- Customer/Member- An individual who joins Mwalimu National and uses any of our products and services or accesses our website and applications. It also includes any person who accesses any of the products and services you have subscribed to.
- Agent- A person or entity who has signed an agreement with Mwalimu National and is recognized as a merchant or agent in accordance with any applicable laws or Regulations.
- Visitor - A person (including contractors/subcontractors or any third parties) who gains access to any Mwalimu National premises.
- Vendor/supplier- Any supplier who has been contracted by Mwalimu National and executed a supplier contract.
- Employee- An individual who works for Mwalimu National, typically under a contract of employment, in exchange for wages or salary.
1 About Us
In this Privacy Policy, references to “we” or “us” are to Mwalimu National Savings and Credit Co-operative Society Limited, which was founded and registered in the year 1974 under the Co-operative Societies Act, Cap 490 as a Sacco Society No CS/2265 whose main business is to mobilize savings and provide credit to its members, who will be the controller of any personal data processed as described in this Privacy Policy.
2 Scope
This Privacy Policy applies only to your use of our products and services or access to our website, facilities and applications. Other linking sites found on our website and applications may also gather information and you should consult those other parties’ privacy policies as appropriate and applicable.
3 Collection of Information
- 1We collect your personal information with your knowledge and consent when you do any of the following (please note that this list is not exhaustive):
- Apply for a specific product or service, including but not limited to Sacco membership application, loan applications, member updates, ATM applications, M-Hela, and e-commerce platforms.
- subscribe to or use a Mwalimu product or service online, on the cloud, on a mobile or other device.
- Visit, access or use our websites and portals.
- Respond to or participate in a survey, marketing promotion, prize competition or special offer.
- subscribe to our services, Short Message Service (SMS), email or social media platforms.
- ask us for more information about a product or service or contact us with a query or complaint.
- We may also collect your information from other organizations including credit-reference bureaus, fraud prevention agencies and business directories.
- We may collect your information when you interact with us as a visitor, supplier, agent.
- We also collect information when you visit any of our premises.
- When you apply for insurance claims arising from demise of our members
- 2 We do not onboard minors (any person under 18 years of age) except where you additionally register
4 What Information is collected?
The information we collect and store about you includes but is not limited to the following:
- Your identity and employment information, including your name, photograph, address, location, phone number, identity document type and number, date of birth, email address, age, gender, employment number, NHIF number, NSSF number, marital status, family details, belief, biometric data, postal address, Tax information, salary information, bank information and health status during member enrollment, during nominee declaration, Internal Funds Transfer, Opening a Fixed Deposit Account, Account Activation, M-Hela onboarding, Online Onboarding and loan origination application, E-channels onboarding, Opening a Call Deposit Account, Member Details Update, Standing Order placement, RTGS Service, employee onboarding process and when applying for ATM cards
- Name, family details, age, profiling information such as level of education, bank account information, income brackets, etc. collected as part of surveys conducted by us or our agents on behalf of Mwalimu National.
- In our loaning processes we shall collect your employment information, including your name, Phone number, Employment number, Email address, Biometric, Property details, Marital status, Family details, Tax information, salary information, bank information, phone number, identity document type and number, PIN number/ Tax information, salary / Business income and postal address.
- In our marketing activities we collect your Names, Email address, Phone number, Residence address, Employment number and Sacco membership number.
- Your transaction information when you use our services such as ATM, M-Hela, FOSA banking etc.
- Your debit-card information, information about your FOSA account numbers and other banking information.
- Your preferences for particular products and services, based on information provided by you or on your use of Mwalimu’s products and services.
- Your call data records, Email contact details and Social media contact details whenever you contact Sacco.
- We use Closed Circuit Television (CCTV) surveillance recordings. CCTV Devices are installed at strategic locations to provide a safe and secure environment in all Mwalimu National premises as a part of our commitment to community safety, security and crime prevention.
- When you request us to reserve parking for you, we will collect and retain your personal data (name, telephone number, and vehicle registration details) and where you use any of our parking facilities as a tenant to the Sacco’s facilities. We use the data you provide to ensure effective visitor, client, employee and car park management, Health, and Safety compliance (orderly entry and exiting to and from the car parks and buildings) and inventory management.
- We maintain a register of visitors in which we collect and keep your personal data such as names, company/institution details, telephone number, vehicle registration details and National ID number. This information is collected for health, safety, and security purposes.
- When you use Mwalimu National WIFI for guests and visitors, we collect and record the device address and also log traffic information in the form of sites visited, duration and date sent/received.
- We may use your medical information to manage our services and products to you e.g., in tax exemption computations.
- When you visit us, Mwalimu National collects your personal information for accident and incident reporting reasons. This includes gathering data from the injured individual or someone experiencing health issues, such as their name, address, age, next of kin, and details of the incident, including relevant medical history. The purpose of collecting this data is because Mwalimu National is legally obligated to document workplace incidents/accidents and report specific types of accidents, injuries, and hazardous situations to the appropriate authority responsible for enforcement.
- We may collect and process certain personal information, including names, employment numbers, residence addresses, CCTV records, IP addresses, Sacco membership numbers, email addresses, and phone numbers. This data is collected for the sole purpose of conducting investigations when necessary. We understand the importance of safeguarding your privacy and assure you that any personal information collected will be treated confidentially and in accordance with applicable data protection laws. We will only retain this information for as long as necessary to fulfill the investigation purposes outlined above.
5 Use of Your Information
We may use and analyze your information for the following purposes:
- Processing products and services that you have applied for from us or through third parties on our ecommerce
- Executing deduction or recovery instructions for loans owed and collections of your Sacco contributions, fees, and charges from your employers, financial institutions etc.
- In the event of defaulted loans, your contact information, and your defaulted loan, may be shared with your guarantors, your employers, debt collectors, auctioneers, and our legal service providers. This sharing of information is necessary for the purpose of facilitating debt recovery and ensuring the proper handling of defaulted loans.
- As a data subject acting as a guarantor, that in the event of loan defaults by the borrower, your contact details may be disclosed to other co-guarantors. This disclosure is made in default notices to ensure transparency and facilitate communication among all parties involved in the loan agreement.
- Responding to any of your queries or concerns.
- In order to meet the necessary regulatory obligations, we may verify your identity information by accessing publicly available and/or restricted government databases.
- Carrying out credit checks and credit scoring.
- Unless you choose not to receive marketing messages, we will keep you updated about new products and services, as well as reach out to you with offers or promotions based on your usage of our own or third-party products and services. (At any given time, you have the option to contact us and choose to opt out of receiving marketing messages).
- In order to meet any legal, governmental, or regulatory obligations or to support our legal representation in any legal proceedings, we may use your information as required.
- In business practices including quality control, training, electronic records management, online meetings and ensuring effective systems operations.
- To protect our network.
- We gather information on how you utilize our products and services to gain insights and enhance their quality. This is done with the intention of developing and improving our offerings to better meet your needs.
- Preventing and detecting fraud or other crimes and for debt recovery.
- For research, statistical, survey and other scientific or business purposes.
- Provide aggregated data (which do not contain any information which may identify you as an individual) to third parties for research and scientific purposes.
- Management of any of our online platforms/websites.
- Management of human resource services to our employees.
- To manage your membership account that you hold with us.
- To fulfil any contractual agreements between you and us
6 Storage of Information
- 1All information is stored on our secure servers. When you register on any of our platforms, we will ask you to choose a password which enables you to access the platform, where applicable. You are responsible for keeping this password confidential. We ask you not to share this password with anyone.
- 2In addition, we (or third parties acting on our behalf) may also store or process information that we collect about you in countries outside Kenya, which may have lower standards of data protection. Specifically, servers used for Sacco operations are located in Kenya. We have put in place technical and organizational security measures to prevent the loss or unauthorized access to your personal data. However, whilst we have used our best efforts to ensure the security of your data, please be aware that we cannot guarantee the security of information transmitted over the internet.
- 3We utilize cloud services for data storage. Your personal data, as provided in accordance with this privacy statement, may be processed and stored securely using these cloud services.
7 Legal Basis for Processing Your Information
- 1Our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.
- 2However, we will normally collect personal information from you only.
- Where we have your consent to do so
- Where we need the personal information to perform a contract with you (provide you with a product/service you have applied for)
- Where the processing is in our legitimate interests and not overridden by your rights.
- In some cases, we may also have a legal obligation to collect personal information from you.
- 3If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as the possible consequences if you do not provide your information).
- 4Similarly, if we collect and use your personal information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.
8 Disclosure of Your Information
We may disclose your personal information to third parties when permitted by law including:
- 1With your consent.
- 2To our suppliers in order for them to help us provide our product/services to you, this includes:
- Loyalty program providers.
- Our provider of customer relationship management services (which allows us, for example, to send personalized email communications to you);
- Our provider of file storage and management services if you email us directly.
- Our payment services provider when you make a payment for a service on the website to enable us to process your payment.
- Our identity verification partner to verify your identity where you choose to select this option.
- Where you have agreed, to our refer-a-member program provider, solely to enable your participation in the program.
- Suppliers of channel and integrated services we require in order to provide you with our products and services.
- Our customer service software if you contact our support team; and
- Our third-party review and ratings partner, who assists us with collecting and moderating your review and rating of our product/services.
- 3These suppliers’ use of your personal data may be subject to their own privacy policies, which are available on their websites, and which we suggest you familiarize yourself within the relevant circumstances set out above.
- 4If we sell or buy any business or assets, in which case we may disclose your information to the prospective seller or buyer of such business or assets, provided that they continue to use your information substantially in accordance with the terms of this Privacy Policy and the Data Protection Policy.
- 5If all, or substantially all of our assets or the assets of our subsidiary, are acquired by a third party provided that they continue to use your information substantially in accordancewith the terms of this Privacy Policy and the Data Protection Policy, in which case information held by us will be one of the transferred assets; and
- 6If we are under a duty to disclose or share your information in order to comply with any legal obligation, or in order to enforce or apply our Terms and other agreements; or to protect our rights, property, or safety, our users, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
9 Data Retention
- 1We retain personal information we collect from you where we have an ongoing legitimate business need to do so and in line with relevant laws and our Records Policy (for example, to provide you with a product service you have requested, you continue to be a member of Mwalimu National or to comply with applicable legal, tax or accounting requirements).
- 2When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
10 Your Rights
- 1You have the following data protection rights:
- You have the right to request access to your personal data and obtain a copy of the information we hold about you, along with information on how and why we process your data.
- You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.
- You have the right to object to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.
- You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, if you withdraw your consent, or if you object to the processing and there are no overriding legitimate grounds for the processing.
- You can edit your personal details via the approved member update procedure whenever you wish. We maintain a procedure in order to help you confirm that your personal information remains correct and up-to-date or choose whether or not you wish to receive material from us or some of our partners.
- You have the right to request the transfer of your personal data to another data controller in a structured, commonly used, and machine-readable format, where technically feasible.
- In addition, you can object to processing your personal information, ask us to restrict processing of your personal information or request portability of your personal information. Again, you can exercise these rights by contacting us using the contact details provided under the “Contacting Mwalimu National” heading below.
- You may unsubscribe from certain email communications by following the Unsubscribe link in the email communication itself. You may also email us at This email address is being protected from spambots. You need JavaScript enabled to view it. in order to access, correct, or update your personal information on our systems. We will answer every email as promptly as possible.
- Similarly, if we have collected and processed your personal information on the basis of your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
- If you have any privacy-related questions or unresolved problems, you may contact us using the information provided at clause 15 below.
- You have the right to complain to the Data Commissioner about our collection and use of your personal information.
- Our platforms may, from time to time, contain links to and from the websites of third parties. If you follow a link to any of these websites, please note that these websites have their own privacy policies. Please check these policies before you submit any personal information to these websites.
11 Children
We strongly believe in protecting the privacy of children. In line with this belief, we do not knowingly collect or maintain personal information from persons under 18 years of age, and no part of the Website is directed to persons under 18 years of age. If you are under 18 years of age, then please do not use or access the Website at any time or in any manner. We will take appropriate steps to delete any personal information of persons less than 18 years of age.
12 Cookies
- 1Sacco’s website uses cookies. Cookies are small files stored on your computer’s hard drive which are used to collect your personal information. You may choose to refuse cookies but, if you do so, some of the functionality of the Website may no longer be available to you.
- 2For more information about cookies, including further details as to what they are and how to refuse them, please see our Cookies Policy.
13 Links to Third Party Websites
When clicking on a link within our platforms, you will be taken to third party websites, the use of which has been arranged by and is the responsibility of the third party. On these websites you may be asked to submit some information about yourself. Please make sure you are familiar with the terms and conditions and privacy policy of the third-party website before submitting your information. The third party may use your personal information for the purposes in their privacy policy and in accordance with the terms of the third-party website.
14 Updating this Privacy Policy
We reserve the right to amend or modify this statement at any time. Any amendment or modification to this statement will take effect from the date of uploading on the Mwalimu National website.
15 Contacting Mwalimu National
If you have any questions, comments or complaints about this Privacy Policy, please contact us using the details below:
The Data Protection Officer: Mwalimu National Sacco,
Mwalimu Towers,
Upper Hill, Hill Lane,
P.O. Box 62641, City Square,
Nairobi, Kenya.
TEL: (020) 2956000/0709898000
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
16 Right to Lodge a Complaint
If you believe that Mwalimu Sacco has infringed your data protection rights or if you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at https://www.odpc.go.ke/
For. CEO: Kenneth Odhiambo Sign……………………………