Data Privacy and Protection Policy

Privacy Policy

This policy explains how Crawl Walk Run Digital Solutions Ltd, trading as Imara Stride, collects, uses, stores, shares, and protects personal data across the platform.

ProductImara Stride
CompanyCrawl Walk Run Digital Solutions Ltd
Version1.0
Primary lawUganda Data Protection and Privacy Act, 2019

1. Purpose and Scope

This policy applies to data processed through all Imara Stride modules, including business profiles, service identification, members and partners, customers, sales, inventory, procurement, assets, expenses, finance ledger, surveys, files, approvals, GPS, reports, and any support or onboarding work carried out by CWR staff, field agents, contracted partners, or authorised sub-processors.

It covers Local Partners such as MSEs, NGOs, CSOs, SACCOs, and MFIs; individuals whose data is recorded by those Local Partners; and CWR employees, agents, contractors, institutional partners, and investors.

2. Governing Legal Frameworks

CWR is incorporated in Uganda and treats the Uganda Data Protection and Privacy Act, 2019, together with the Data Protection and Privacy Regulations, 2021 and the Personal Data Protection Office under NITA-U, as the primary binding framework for its processing activities.

CWR also uses the EU GDPR as a best-practice benchmark and adopts CCPA-style individual rights language as a contractual-readiness measure where institutional partners or future markets require comparable protections. This policy is a working operational policy and should be reviewed by qualified counsel where a new jurisdiction, funder, or legal requirement applies.

3. Roles and Responsibilities

CWR designates a Privacy Lead responsible for maintaining this policy, the data inventory, records of processing activities, PDPO registration, breach response, contract review, and regulator or individual rights correspondence.

CWR acts as a controller for data it collects for its own purposes, including employee and agent records, institutional partner contacts, billing, subscription records, marketing, demo requests, and platform usage or security logs. For records entered by a Local Partner into its own modules, the Local Partner is normally the controller and CWR acts as processor on that Local Partner's instructions.

Local Partners are responsible for having a lawful basis for the personal data they enter, informing their staff, members, customers, suppliers, and beneficiaries, and correcting or removing records when required. CWR provides tools and support to help fulfil those duties.

4. Data We Process

ModuleTypical personal dataPurpose
Business Profile / Service IdentificationOwner or director name, national ID or business registration number, contact details, locationOnboarding, identity verification, and account setup
Members / PartnersName, contact details, role, membership or shareholding status, ID numberMembership records, governance, and payouts
Customers, Sales, Invoices, Receipts, Delivery NotesCustomer name, contact details, transaction history, payment method or referenceSales recording, invoicing, payment reconciliation, and customer records
ProcurementSupplier contact name, business details, bank or mobile money payment detailsPurchasing, supplier management, bills, and payments
Expenses, Finance Ledger, ReportsTransaction-level financial data and payee names where applicableBookkeeping, reporting, audit trails, and financial statements
AssetsAsset custodian name, location, assigned staffFixed asset tracking and accountability
SurveysGender, age bracket, disability status, household or beneficiary data where collectedDonor-required disaggregated reporting and programme analysis
GPS and FilesLocation data, uploaded documents, IDs, contracts, photos, approver identity and decision trailsField verification, document storage, audit trails, and approvals

5. Lawful Basis for Processing

CWR relies on contract performance for onboarding, subscriptions, and processing records required to provide the service; consent for sensitive survey data and marketing communications; legitimate interest for platform security, fraud prevention, and service improvement analytics; and legal obligation for data CWR must keep under tax, company, labour, or regulatory law.

CWR does not sell personal data. If advertising or cross-context sharing tools are introduced in future, this policy will be updated and an opt-out mechanism will be added before launch.

6. Sensitive and Special Category Data

Gender, age, disability, household, beneficiary, location, payment, ID, and financial data may require stronger protection depending on context. Sensitive survey or GESI data should be collected only with explicit, separately recorded consent or another documented lawful basis, restricted by role, and aggregated or de-identified before donor reporting wherever individual-level detail is not required.

7. Data Collection Model

During the Crawl phase, CWR field agents may enter records for a Local Partner from source documents. Agents must collect only required fields, avoid retaining incidental personal data, access only assigned Local Partners, and return or securely destroy paper documents after entry. During Walk, the Local Partner takes over more of its own data entry with CWR coaching support. During Run, CWR retains administrative or support access only as needed for the subscription and support relationship.

8. Sharing and Disclosure

CWR shares personal data only with the Local Partner and its authorised users; infrastructure and technical sub-processors required to operate the platform; institutional partners where reporting is contractually agreed, normally in aggregate or summary form; and regulators or law enforcement where legally required. CWR maintains a current list of sub-processors and makes it available on request.

9. Security Measures

  • Encryption of data in transit and appropriate hosting safeguards for data at rest.
  • Role-based access control across modules, scoped to the user's responsibilities.
  • Authentication controls for platform accounts, with stronger controls for administrative and agent accounts where available.
  • Audit logging of record creation, edits, approvals, and security-relevant activity.
  • Confidentiality undertakings, privacy training, device security expectations, and vendor due diligence for staff, agents, and sub-processors.

10. Data Retention and Deletion

Data categoryDefault retentionBasis
Active operational and financial recordsDuration of subscription plus 7 years after closureTax, financial record-keeping, audit, credit, and donor evidence
Survey / GESI sensitive dataDuration required for the specific donor reporting cycle, then anonymised or deletedData minimisation for sensitive data
GPS location data12 months rolling unless tied to an open asset, audit, or field recordLimits exposure of movement patterns
Marketing or demo-request data24 months from last contact, or until opt-outTime-bound legitimate interest
Account closure / offboardingExport provided to the Local Partner; CWR copy deleted or anonymised within 90 days unless a legal hold appliesRight to deletion and data minimisation

11. Individual Rights

Subject to identity verification and applicable law, individuals may request access to personal data held about them, correction of inaccurate data, deletion where no legal or contractual basis requires retention, export in a usable format, and objection or opt-out from certain processing such as marketing.

Requests about records inside a Local Partner's modules should usually be directed first to that Local Partner as controller. Requests about CWR-controlled data are handled by the Privacy Lead within the shortest applicable statutory period.

12. Data Breach Notification

If CWR believes personal data has been accessed, lost, or acquired without authorisation, the Privacy Lead and technical lead will contain and assess the incident, notify the Uganda Personal Data Protection Office as required, follow any PDPO direction on subject notice, apply GDPR-aligned timelines where EU data subjects may be affected, notify affected institutional partners according to contract terms, and document the incident and remedial actions in a breach register.

13. Cross-Border Data Transfers

Where personal data is stored or processed outside Uganda, CWR records the legal basis and safeguards relied on, such as consent, equivalent protection by the recipient, provider data protection commitments, or contractual safeguards. Local Partner-facing notices should disclose in plain language that data may be stored outside Uganda where this applies.

14. Accountability and Review

CWR maintains this policy, its data inventory, breach register, and sub-processor list as core accountability documentation. The policy is reviewed at least annually and whenever there is a material change in law, platform modules, data flows, jurisdictions, or processing activities.

Public Privacy Notice

We collect and process information needed to set up and run your account, generate records and reports, support onboarding, meet legal or donor reporting obligations, and keep the platform secure. Your organisation's authorised users, CWR support staff and agents, contracted technical providers, and approved institutional partners may see information only where their role or agreement allows it.

To request access, correction, deletion, export, or to object to certain uses of your data, contact your organisation first where the data belongs to that organisation, or contact CWR directly for data controlled by CWR.

Crawl Walk Run Digital Solutions LtdKampala, Ugandacwrdigitalsolutionsltd@gmail.com