1. Purpose and Scope
This policy applies to data processed through all Imara Stride modules, including business profiles, service identification, members and partners, customers, sales, inventory, procurement, assets, expenses, finance ledger, surveys, files, approvals, GPS, reports, and any support or onboarding work carried out by CWR staff, field agents, contracted partners, or authorised sub-processors.
It covers Local Partners such as MSEs, NGOs, CSOs, SACCOs, and MFIs; individuals whose data is recorded by those Local Partners; and CWR employees, agents, contractors, institutional partners, and investors.
2. Governing Legal Frameworks
CWR is incorporated in Uganda and treats the Uganda Data Protection and Privacy Act, 2019, together with the Data Protection and Privacy Regulations, 2021 and the Personal Data Protection Office under NITA-U, as the primary binding framework for its processing activities.
CWR also uses the EU GDPR as a best-practice benchmark and adopts CCPA-style individual rights language as a contractual-readiness measure where institutional partners or future markets require comparable protections. This policy is a working operational policy and should be reviewed by qualified counsel where a new jurisdiction, funder, or legal requirement applies.
3. Roles and Responsibilities
CWR designates a Privacy Lead responsible for maintaining this policy, the data inventory, records of processing activities, PDPO registration, breach response, contract review, and regulator or individual rights correspondence.
CWR acts as a controller for data it collects for its own purposes, including employee and agent records, institutional partner contacts, billing, subscription records, marketing, demo requests, and platform usage or security logs. For records entered by a Local Partner into its own modules, the Local Partner is normally the controller and CWR acts as processor on that Local Partner's instructions.
Local Partners are responsible for having a lawful basis for the personal data they enter, informing their staff, members, customers, suppliers, and beneficiaries, and correcting or removing records when required. CWR provides tools and support to help fulfil those duties.
4. Data We Process
| Module | Typical personal data | Purpose |
|---|---|---|
| Business Profile / Service Identification | Owner or director name, national ID or business registration number, contact details, location | Onboarding, identity verification, and account setup |
| Members / Partners | Name, contact details, role, membership or shareholding status, ID number | Membership records, governance, and payouts |
| Customers, Sales, Invoices, Receipts, Delivery Notes | Customer name, contact details, transaction history, payment method or reference | Sales recording, invoicing, payment reconciliation, and customer records |
| Procurement | Supplier contact name, business details, bank or mobile money payment details | Purchasing, supplier management, bills, and payments |
| Expenses, Finance Ledger, Reports | Transaction-level financial data and payee names where applicable | Bookkeeping, reporting, audit trails, and financial statements |
| Assets | Asset custodian name, location, assigned staff | Fixed asset tracking and accountability |
| Surveys | Gender, age bracket, disability status, household or beneficiary data where collected | Donor-required disaggregated reporting and programme analysis |
| GPS and Files | Location data, uploaded documents, IDs, contracts, photos, approver identity and decision trails | Field verification, document storage, audit trails, and approvals |
5. Lawful Basis for Processing
CWR relies on contract performance for onboarding, subscriptions, and processing records required to provide the service; consent for sensitive survey data and marketing communications; legitimate interest for platform security, fraud prevention, and service improvement analytics; and legal obligation for data CWR must keep under tax, company, labour, or regulatory law.
CWR does not sell personal data. If advertising or cross-context sharing tools are introduced in future, this policy will be updated and an opt-out mechanism will be added before launch.
6. Sensitive and Special Category Data
Gender, age, disability, household, beneficiary, location, payment, ID, and financial data may require stronger protection depending on context. Sensitive survey or GESI data should be collected only with explicit, separately recorded consent or another documented lawful basis, restricted by role, and aggregated or de-identified before donor reporting wherever individual-level detail is not required.
7. Data Collection Model
During the Crawl phase, CWR field agents may enter records for a Local Partner from source documents. Agents must collect only required fields, avoid retaining incidental personal data, access only assigned Local Partners, and return or securely destroy paper documents after entry. During Walk, the Local Partner takes over more of its own data entry with CWR coaching support. During Run, CWR retains administrative or support access only as needed for the subscription and support relationship.
8. Sharing and Disclosure
CWR shares personal data only with the Local Partner and its authorised users; infrastructure and technical sub-processors required to operate the platform; institutional partners where reporting is contractually agreed, normally in aggregate or summary form; and regulators or law enforcement where legally required. CWR maintains a current list of sub-processors and makes it available on request.
9. Security Measures
- Encryption of data in transit and appropriate hosting safeguards for data at rest.
- Role-based access control across modules, scoped to the user's responsibilities.
- Authentication controls for platform accounts, with stronger controls for administrative and agent accounts where available.
- Audit logging of record creation, edits, approvals, and security-relevant activity.
- Confidentiality undertakings, privacy training, device security expectations, and vendor due diligence for staff, agents, and sub-processors.
10. Data Retention and Deletion
| Data category | Default retention | Basis |
|---|---|---|
| Active operational and financial records | Duration of subscription plus 7 years after closure | Tax, financial record-keeping, audit, credit, and donor evidence |
| Survey / GESI sensitive data | Duration required for the specific donor reporting cycle, then anonymised or deleted | Data minimisation for sensitive data |
| GPS location data | 12 months rolling unless tied to an open asset, audit, or field record | Limits exposure of movement patterns |
| Marketing or demo-request data | 24 months from last contact, or until opt-out | Time-bound legitimate interest |
| Account closure / offboarding | Export provided to the Local Partner; CWR copy deleted or anonymised within 90 days unless a legal hold applies | Right to deletion and data minimisation |
11. Individual Rights
Subject to identity verification and applicable law, individuals may request access to personal data held about them, correction of inaccurate data, deletion where no legal or contractual basis requires retention, export in a usable format, and objection or opt-out from certain processing such as marketing.
Requests about records inside a Local Partner's modules should usually be directed first to that Local Partner as controller. Requests about CWR-controlled data are handled by the Privacy Lead within the shortest applicable statutory period.
12. Data Breach Notification
If CWR believes personal data has been accessed, lost, or acquired without authorisation, the Privacy Lead and technical lead will contain and assess the incident, notify the Uganda Personal Data Protection Office as required, follow any PDPO direction on subject notice, apply GDPR-aligned timelines where EU data subjects may be affected, notify affected institutional partners according to contract terms, and document the incident and remedial actions in a breach register.
13. Cross-Border Data Transfers
Where personal data is stored or processed outside Uganda, CWR records the legal basis and safeguards relied on, such as consent, equivalent protection by the recipient, provider data protection commitments, or contractual safeguards. Local Partner-facing notices should disclose in plain language that data may be stored outside Uganda where this applies.
14. Accountability and Review
CWR maintains this policy, its data inventory, breach register, and sub-processor list as core accountability documentation. The policy is reviewed at least annually and whenever there is a material change in law, platform modules, data flows, jurisdictions, or processing activities.
Public Privacy Notice
We collect and process information needed to set up and run your account, generate records and reports, support onboarding, meet legal or donor reporting obligations, and keep the platform secure. Your organisation's authorised users, CWR support staff and agents, contracted technical providers, and approved institutional partners may see information only where their role or agreement allows it.
To request access, correction, deletion, export, or to object to certain uses of your data, contact your organisation first where the data belongs to that organisation, or contact CWR directly for data controlled by CWR.
