Download App
Privacy Notice
Legal Document

Privacy Notice

Effective Date3rd February 2024
Regulated byCommissioner of Cooperative Development
Governed byData Protection Act, 2019

1. Scope of this Privacy Notice

Mombo App is a mobile application used by Savings and Credit Cooperative Society to serve its members. The Sacco is a Commissioner of Cooperative Development licensed savings and credit cooperative society and the data controller responsible for processing your data when you download and use the Mombo App (hosted on the Google Play Store or Apple App Store) or when you access our Services through other Channels.

The Sacco may also act as a data processor for a data controller with whom you have a contractual relationship. In such instances, the Sacco will act in accordance with the instructions given by the data controller.

If you have any questions about this Privacy Notice, please contact us via email at support@mombo.africa.

By expressing your acceptance of the terms of this Privacy Notice and our Privacy Policy through the Mombo App or other Channels, you accept that your personal data will be processed in accordance with this Privacy Notice and the Data Protection Act, 2019.

Mombo App's Services are not intended for children. We do not knowingly collect data relating to individuals below the age of 18 years.

2. Definitions

Channels
Any system or medium — including the Mombo App, USSD, and web — established by the Sacco to enable access to Services.
Children
Individuals below the age of 18 years.
Consent
An express, unequivocal, free, specific, and informed indication of wishes by a statement or clear affirmative action.
Customer / User
Any individual to whom the Sacco provides its Services.
Personal data
Any information relating to an identified or identifiable individual, including sensitive personal data.
Sensitive personal data
Data about race, health, ethnic origin, belief, genetic/biometric data, property, marital status, family details, or sexual orientation.
Services
Financial products and features provided through the App, partner channels, or other Channels.
We / Our / Us
Refers to the Sacco.

3. The Data We Collect About You

We collect personal data from you as you use our Services. This includes the following categories:

Identity Data
Full name, title, date of birth, age, gender, identity document, KRA PIN certificate number and photo.
Profile Data
Education level, employment status, income, images, marital status, and survey responses.
Contact Data
Present address, permanent address, email address, and mobile numbers.
Financial Data
Bank statements, payslips, M-Pesa statements, title deeds, logbooks, mobile account numbers, and payment card details.
Transaction Data
Payments and transfers to and from you, and your Mombo App transaction history.
Device Data
Device type, specs, unique identifiers (IMEI, IP, MAC address), mobile network, and OS.
Content Data
Contact lists, call and SMS logs, and installed applications on your device.
Network Data
Information about users in your network — volume, repayment behaviour, demographics.
Usage Data
Username, password/PIN, OTP, and details of your use of the Mombo App or Channels.
Communications Data
Messages, customer service tickets, call logs, recordings, and other interactions with the Sacco.
Marketing Data
Your preferences for receiving promotional messages and data related to special offers.
Location Data
Your current location determined by geolocation technology.
Third Party Data
Information from partners, credit reference bureaus, identity verification providers, mobile network providers, and marketing partners.

Sources of personal data:

  • Information you give us — submitted via the App, USSD, forms, website, or social media interactions.
  • Information from your device — collected by installing the Mombo App and enabling device permissions.
  • Third-party and public sources — from payment service providers, mobile network providers, identity verification agencies, credit reference agencies, collection agencies, and publicly available sources.

If you fail to provide personal data that we request, we may be unable to provide you with our Services.

4. Purposes and Lawful Basis for Processing

We will only process your personal data when we have a lawful basis to do so. The main lawful bases are:

Lawful BasisWhen It Applies
ConsentWhere you have expressly consented to the processing of your personal data.
ContractWhere we need to perform a contract with you, or take steps at your request before entering into a contract.
Legal ObligationWhere we need to comply with a legal or regulatory requirement.
Legitimate InterestsWhere it is necessary for our legitimate interests and your fundamental rights do not override those interests.

Purposes include: providing and improving Services, verifying identity, assessing creditworthiness, preventing fraud, complying with legal obligations, communicating about your account, and conducting marketing activities where you have given consent.

5. Sharing Your Personal Data

We may share your personal data with the following categories of third parties where necessary and lawful:

  • Service providers and technical partners (payment processors, USSD providers, cloud services)
  • Credit reference bureaus and identity verification agencies
  • External debt collection agencies
  • Regulatory bodies and law enforcement where legally required
  • Business partners for marketing activities, with your consent
  • Successor entities in the event of a merger, acquisition, or restructuring

We require all third parties to maintain appropriate security of your personal data and to process it only for specified purposes in accordance with our instructions.

6. International Transfers

Where we transfer your personal data outside Kenya, we ensure that appropriate safeguards are in place in accordance with the Data Protection Act, 2019. These safeguards may include contractual clauses, adequacy decisions, or other legally recognised mechanisms.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting, or reporting requirements.

To determine the appropriate retention period, we consider the nature and sensitivity of the data, potential risk of harm from unauthorised use or disclosure, and applicable legal obligations.

When your personal data is no longer required, we will securely delete or anonymise it.

8. Your Rights

Under the Data Protection Act, 2019, you have the following rights regarding your personal data:

Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Request correction of inaccurate or incomplete personal data.
Right to erasure
Request deletion of your personal data where there is no lawful basis for continued processing.
Right to object
Object to processing of your personal data for legitimate interests or direct marketing.
Right to portability
Request transfer of your personal data in a structured, machine-readable format.
Right to restriction
Request restriction of processing in certain circumstances.
Withdraw consent
Withdraw consent at any time without affecting prior lawful processing.
Right to complain
Lodge a complaint with the Office of the Data Protection Commissioner.

To exercise any of your rights, contact us at support@mombo.africa. We will respond within the timeframe required by applicable law.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Notice or how we handle your personal data, please reach out to us:

Data Protection
support@mombo.africa

This Privacy Notice was last updated on 3rd February 2024. The Sacco reserves the right to amend this notice from time to time. We will notify you of material changes through the App or other Channels.