Daima DT Sacco Ltd

PRIVACY POLICY

1. INTRODUCTION

Daima Sacco Society Limited (“Daima Sacco”, “we”, “us”, or “our”) is committed to protecting the privacy, confidentiality, and security of personal data entrusted to us. We process personal data lawfully, fairly, and transparently, in strict compliance with the Constitution of Kenya, the Data Protection Act, 2019, and all applicable regulations and guidelines issued by the Office of the Data Protection Commissioner (ODPC).

This Privacy Policy explains how Daima Sacco collects, uses, discloses, stores, and protects personal data, as well as the rights of data subjects. This Policy should be read together with our Data Protection Policy and other internal governance documents.

This Policy applies to all customers/members, employees, agents, suppliers, contractors, visitors, and any other persons whose personal data is processed by Daima Sacco.

2. DEFINITIONS

For purposes of this Policy, unless the context otherwise requires:

  • Customer/Member: An individual who has joined Daima Sacco or uses any of our products or services, including access to our websites, mobile applications, USSD platforms, and other digital channels.
  • Employee: An individual engaged by Daima Sacco under a contract of employment.
  • Agent: A person or entity contracted by Daima Sacco to provide services or act on its behalf in accordance with applicable laws and regulations.
  • Vendor/Supplier: A third party contracted to supply goods or services to Daima Sacco.
  • Visitor: Any person, including contractors or third parties, who accesses Daima Sacco premises.
  • Personal Data: Any information relating to an identified or identifiable natural person, as defined under the Data Protection Act, 2019.
  • Processing: Any operation performed on personal data, whether automated or manual, including collection, storage, use, disclosure, or deletion.

3. ABOUT DAIMA SACCO

Daima Sacco Society Limited was founded and registered in 1991 under the Co‑operative Societies Act, Cap 490 (SACCO Society No. C/S 6267). Our core business is mobilizing savings and providing credit facilities to our members.

For purposes of this Privacy Policy, Daima Sacco is the Data Controller in respect of personal data processed in the course of our operations.

4. SCOPE OF THIS POLICY

This Privacy Policy applies to all personal data processed by Daima Sacco through: – Our products and services; – Physical premises; – Websites, mobile applications, USSD services, and digital platforms; and – Any other engagement with Daima Sacco.

Links to third‑party websites or platforms are governed by the respective third parties’ privacy policies, and Daima Sacco bears no responsibility for their data practices.

5. DATA PROTECTION PRINCIPLES

Daima Sacco adheres to the following data protection principles when processing personal data:

  1. Lawfulness, Fairness, and Transparency – Personal data is processed in a lawful, fair, and transparent manner.
  2. Purpose Limitation – Personal data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  3. Data Minimisation – Only personal data that is adequate, relevant, and limited to what is necessary is collected.
  4. Accuracy – Reasonable steps are taken to ensure personal data is accurate and kept up to date.
  5. Storage Limitation – Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected.
  6. Integrity and Confidentiality – Appropriate technical and organisational measures are implemented to safeguard personal data.
  7. Accountability – Daima Sacco takes responsibility for and demonstrates compliance with the Data Protection Act, 2019.

6. COLLECTION OF PERSONAL DATA

We collect personal data with your knowledge and, where required, consent, including when you:

  • Apply for membership, accounts, loans, or other SACCO products and services;
  • Use our mobile applications, USSD services, online platforms, or e‑channels;
  • Visit or interact with our websites and digital platforms;
  • Participate in surveys, promotions, or marketing campaigns;
  • Subscribe to SMS, email, or social media communications;
  • Contact us with inquiries, complaints, or requests;
  • Visit our premises as a member, visitor, supplier, or agent; or
  • Submit claims, including those arising from the demise of a member.

We may also collect personal data from third parties such as credit reference bureaus, fraud prevention agencies, employers, regulators, and publicly available sources, where permitted by law.

Daima Sacco does not knowingly onboard minors (persons under 18 years of age), except where permitted by law and with appropriate parental or guardian consent.

7. CATEGORIES OF PERSONAL DATA COLLECTED

Depending on the nature of your relationship with Daima Sacco, we may collect and process the following categories of personal data:

  • Identification and Contact Information: Names, photographs, national ID or passport details, PIN, date of birth, gender, postal and physical addresses, phone numbers, and email addresses.
  • Employment and Financial Information: Employment details, salary or business income, bank account details, tax information, and contribution records.
  • Membership and Account Information: SACCO membership numbers, account details, transaction history, loan and guarantorship information.
  • Digital and Communication Data: Call recordings, emails, IP addresses, and social media interactions where applicable.
  • CCTV and Security Data: Video recordings captured at Daima Sacco premises for safety and security purposes.
  • Visitor Information: Names, contact details, company information, vehicle registration numbers, and identification details recorded for security and safety.
  • Investigation and Compliance Data: Information processed for audits, investigations, fraud prevention, dispute resolution, and regulatory compliance.

Sensitive personal data is processed only where permitted by law and with appropriate safeguards.

8. LAWFUL BASIS FOR PROCESSING

We process personal data on one or more of the following lawful bases:

  • Consent of the data subject;
  • Performance of a contract;
  • Compliance with a legal obligation;
  • Legitimate interests of Daima Sacco, provided such interests do not override the rights and freedoms of the data subject; or
  • Establishment, exercise, or defence of legal claims.

9. PURPOSES OF PROCESSING PERSONAL DATA

We use personal data for purposes that include:

  • Providing and managing SACCO products and services;
  • Processing membership applications, loans, contributions, repayments, and recoveries;
  • Credit scoring, risk assessment, and fraud prevention;
  • Regulatory compliance and reporting;
  • Communication with members, guarantors, employers, and service providers;
  • Marketing and promotional communications (subject to your right to opt out);
  • Business operations, system security, quality assurance, and service improvement;
  • Human resource management;
  • Research, statistical analysis, and reporting using aggregated or anonymised data; and
  • Establishment, exercise, or defence of legal rights.

10. DATA RETENTION

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, in accordance with our Data Retention Policy and applicable legal requirements.

As a general rule, financial and transactional records are retained for a minimum of seven (7) years after the termination of the contractual relationship, unless a longer retention period is required by law or for legal proceedings.

11. ACCESS AND SECURITY OF PERSONAL DATA

Access to personal data is restricted to authorised personnel who require such access for legitimate business purposes. All staff and service providers are bound by confidentiality obligations and receive data protection training.

We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, or misuse.

12. INFORMATION SHARING AND DISCLOSURE

We may share personal data with third parties only where necessary and lawful, including:

  • Regulators and government authorities;
  • Credit reference bureaus;
  • Contracted data processors and service providers;
  • Payment and identity verification service providers; and
  • Professional advisers, debt collectors, auctioneers, and legal service providers.

All third parties are required to comply with applicable data protection laws and contractual confidentiality obligations.

13. DATA SUBJECT RIGHTS

Under the Data Protection Act, 2019, you have the right to:

  • Access your personal data;
  • Rectify inaccurate or incomplete data;
  • Erase personal data where legally applicable;
  • Restrict processing;
  • Object to processing, including direct marketing;
  • Data portability; and
  • Lodge a complaint with the Office of the Data Protection Commissioner.

Requests may be submitted at any Daima Sacco branch or via email, and will be addressed within statutory timelines.

14. CHILDREN’S PRIVACY

Daima Sacco does not knowingly collect personal data from children without lawful justification and appropriate consent. Any such data identified will be securely deleted.

15. THIRD‑PARTY WEBSITES

Daima Sacco is not responsible for the privacy practices of third‑party websites or platforms accessed through our services. Users are encouraged to review the relevant third‑party privacy policies.

16. CHANGES TO THIS PRIVACY POLICY

We may amend this Privacy Policy from time to time. Updated versions will be published on our website and take effect from the date of publication.

17. CONTACT DETAILS

For questions, requests, or complaints relating to this Privacy Policy or the processing of personal data, please contact:

Data Protection Officer
Daima Sacco Society Limited
Email: info@daimasaccoltd.com

Copyright © 2025 Daima DT Sacco Ltd. All Rights Reserved. | Designed and Developed by Urban Kreative Ltd