Smart Fundi | Privacy Policy | Terms of Service
SMART FUNDI
PERSONAL DATA PROTECTION POLICY
(Code of Ethics for Personal Data Protection)
Prepared pursuant to Section 65 of the Personal Data Protection Act, Cap. 44 (Act No. 11 of 2022), for submission to the Personal Data Protection Commission (PDPC) and for internal governance use.
Data Controller: Barah Technologies Ltd
Version 1.0 | Effective Date:
4. Data Controller Information
5. Data Protection Officer (DPO)
6. Principles of Personal Data Protection
6.1 Lawfulness, Fairness and Transparency
6.3 Data Minimisation and Proportionality
6.6 Integrity, Confidentiality and Security
6.7 Respect for Data Subject Rights
7. Categories of Personal Data Collected
8. Purpose and Legal Basis for Processing
10. Rights of Data Subjects and How Smart Fundi Fulfils Them
11. Data Sharing and Third-Party Data Processors
12.1 Legal Basis: Transfer to a State with Adequate Protection (Section 31)
12.2 Residual Uncertainty and Recommended Next Step
13. Data Retention and Disposal
15. Data Breach Notification Procedure
16. Data Protection Impact Assessment (DPIA)
17. Registration with the Personal Data Protection Commission
18. Staff Training and Ongoing Compliance
Appendix A: Register of Processing Activities
This Personal Data Protection Policy ("Policy") sets out how Smart Fundi collects, uses, discloses, retains, secures, and disposes of personal data belonging to customers, fundis (service providers), shop owners, super agents, and other individuals who interact with the Smart Fundi platform ("data subjects").
This Policy is prepared as the written code of ethics required under section 65 of the Personal Data Protection Act, Cap. 44 (Act No. 11 of 2022) ("the Act"), and is intended, in accordance with section 65(2), to be submitted to the Personal Data Protection Commission ("the Commission" or "PDPC") for consideration and approval. It also serves as Smart Fundi's internal governance document for data protection compliance.
This Policy has been prepared with reference to the Act, the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 (GN No. 449C), and the Personal Data Protection (Complaints Settlement Procedures) Regulations, 2023 (GN No. 449B).
This Policy applies to all personal data collected or processed by Smart Fundi, whether collected directly through the Smart Fundi mobile application, through the DigitalOcean-hosted payment proxy server, through Supabase (the platform's database and backend infrastructure), or through any other means, in connection with the following user roles:
Customers who search for and book fundis, shops, or agents;
Fundis (independent tradespeople) who register to offer services;
Shop Owners who register businesses on the platform;
Super Agents (Wakala Mkuu) who register as bulk material suppliers.
This Policy applies to Mainland Tanzania, consistent with section 2 of the Act.
Terms used in this Policy carry the meanings given to them in section 3 of the Act, including in particular:
“Personal data” means data about an identifiable person recorded in any form, including name, identifying numbers, address, and correspondence.
“Sensitive personal data” includes, among other things, financial transactions of the individual, biometric data, and data related to children.
“Data controller” means the natural or legal person who determines the purpose and means of processing personal data — for the purposes of this Policy, Smart Fundi.
“Data processor” means a person who processes personal data on behalf of, and under the instruction of, the data controller — for Smart Fundi, this includes Supabase Inc. (database/backend hosting) and Selcom Paytech Ltd (payment processing).
“Data subject” means the individual to whom personal data relates — for Smart Fundi, its customers, fundis, shop owners, and super agents.
“Processing” means any operation on personal data, including collection, storage, use, disclosure, or destruction.
| Field | Details |
|---|---|
| Registered name | SMART FUNDI |
| Business registration number (BRELA) | 635582 |
| Physical address | DODOMA, DODOMA CBD, DODOMA MAKULU |
| Postal address | 41107 |
| Contact email | smartfundis@gmail.com |
| Contact phone | +255796381261 |
| Nature of business | Digital marketplace connecting customers with handymen (fundis), shops, and material suppliers (super agents) in Tanzania |
In accordance with section 27(3) of the Act and regulation 32 of GN No. 449C, Smart Fundi has appointed a Data Protection Officer responsible for:
Ensuring compliance with the Act and these Regulations in all processing of personal data carried out by Smart Fundi;
Advising on and implementing rectification measures where violations are identified;
Preparing and submitting quarterly compliance reports to the Commission;
Receiving and handling data subject applications and complaints relating to personal data;
Serving as the primary point of contact for the Commission on data protection matters.
| Field | Details |
|---|---|
| DPO name | Joshua Calvin Maimu |
| DPO contact email | maimujr@gmail.com |
| DPO contact phone | +255748777436 |
In accordance with section 5 of the Act and regulations 23–31 of GN No. 449C, Smart Fundi processes personal data on the basis of the following principles:
Personal data is collected and processed lawfully, fairly, and transparently. Users are informed, at the point of registration, what data is collected and why.
Personal data is collected for specific, explicit, and legitimate purposes (e.g. enabling bookings, processing subscription payments, verifying business credentials) and is not further processed in a manner incompatible with those purposes.
Smart Fundi collects only the personal data that is adequate, relevant, and necessary for the stated purpose — for example, collecting a fundi's location for search-matching purposes, without collecting unrelated data.
Smart Fundi takes reasonable steps to ensure personal data is accurate and, where necessary, kept up to date, including allowing users to update their own profile information.
Personal data is retained only for as long as necessary for the purposes for which it was collected, as set out in section 13 of this Policy.
Personal data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, loss, destruction, or damage, as set out in section 14 of this Policy.
Personal data is processed in accordance with the rights of data subjects set out in Part VI of the Act and section 10 of this Policy.
| Category | Examples | Collected From |
|---|---|---|
| Identity data | Full name, date of birth, national ID / verification documents | Fundis, Shop Owners, Super Agents (business verification) |
| Contact data | Phone number, email address | All user roles |
| Location data | GPS coordinates (PostGIS) | Fundis (for search-matching), Customers (for job requests) |
| Financial / transaction data | Mobile money phone number, subscription payment amount, transaction reference, payment status | All paying user roles, via Selcom |
| Business verification data | Business licence PDFs, shop registration documents | Shop Owners, Super Agents, Fundis |
| Profile & portfolio data | Photos, captions, prices of past work | Fundis, Shops, Super Agents |
| Ratings & review data | Star ratings, written reviews | Customers (about Fundis/Shops) |
| Usage data | App activity, job requests, search history | All user roles |
| Google account data | Name, email address, profile photo (via Google Sign-In) | Users who choose to register/sign in with Google |
Where a user chooses to register or sign in using their Google account ("Sign in with Google"), Smart Fundi receives and stores the name, email address, and profile photo associated with that Google account, as provided by Google, for the sole purpose of creating and authenticating the user’s Smart Fundi account. Smart Fundi does not request or receive access to any other Google account data (such as Gmail, Google Drive, or Google Contacts).
| Purpose | Data used | Legal basis (s.25 of the Act) |
|---|---|---|
| Account creation & authentication | Name, phone, email | Necessary for performance of the contract with the user (app terms of service) |
| Matching customers with nearby fundis | Location data | Necessary for performance of the contract; legitimate interest in enabling the core marketplace function |
| Processing subscription payments | Financial/transaction data | Necessary for performance of the contract; consent (see section 9 below, given this is sensitive personal data) |
| Verifying business credentials | ID documents, business licences | Necessary for performance of the contract; legal obligation to prevent fraud |
| Displaying fundi portfolios and reviews | Photos, ratings, reviews | Consent (user opts in by uploading/posting) |
| Customer support & dispute resolution | Account & usage data | Legitimate interest; necessary for performance of the contract |
Section 3 of the Act defines “sensitive personal data” to include, among other categories, “financial transactions of the individual.” Smart Fundi's processing of Selcom mobile money payment data (phone number used for payment, transaction amounts, and payment status) therefore constitutes processing of sensitive personal data.
In accordance with section 30(1) of the Act, Smart Fundi obtains prior written consent from data subjects before processing this category of data. This consent is captured at the point a user proceeds with a subscription or event payment within the app, and is documented in the app's Terms of Service and this Policy.
In accordance with section 30(2), users may withdraw this consent at any time and without charge, though doing so will mean Smart Fundi can no longer process payments on the user's behalf and paid features of the app will become unavailable.
Action item: Smart Fundi should add an explicit, standalone consent checkbox (not bundled with general Terms of Service acceptance) at the payment screen, referencing this sensitive-data processing specifically, to strengthen documentary evidence of consent under section 30.
In accordance with Part VI of the Act (sections 33–38) and Part III of GN No. 449C, data subjects have the following rights, which Smart Fundi will honour through the process described:
| Right | How exercised | Smart Fundi's response time |
|---|---|---|
| Right of access (s.33) | Request via app support / email to DPO | Within a reasonable time, and in any case consistent with the 14-day timelines used elsewhere in GN No. 449C |
| Right to prevent/suspend processing (s.34; reg.15) | Written application to DPO, copied to Commission | Acknowledge and temporarily suspend within 72 hours; final decision within 7 days |
| Right to rectification (s.29; reg.16) | Written application to DPO, copied to Commission | Accept/reject within 14 days, with written reasons if rejected |
| Right to erasure/destruction (s.38; reg.17) | Written application to DPO, copied to Commission | Accept/reject within 14 days, with written reasons if rejected |
| Right to object to direct marketing (s.35) | In-app notification settings, or written request | Immediate opt-out |
| Right to compensation (s.37) | Complaint to the Commission | Handled per the Commission's Complaints Settlement Procedures (GN No. 449B) |
Where a data subject is a child, Smart Fundi will handle requests in accordance with regulation 18(2) of GN No. 449C, requiring proper identification of the person exercising the right and, where applicable, notice to the parent or guardian.
Smart Fundi shares personal data with the following third-party data processors, each acting under Smart Fundi's instructions in accordance with section 27(4) of the Act:
| Processor | Role | Data shared | Location |
|---|---|---|---|
| Selcom Paytech Ltd (Vendor ID SB00183906) | Mobile money payment processing (USSD push) | Phone number, payment amount, order reference | Tanzania |
| Supabase Inc. | Database hosting, authentication, file storage | All categories in section 7 | Frankfurt, Germany (EU) |
| DigitalOcean, LLC | Hosting of the payment proxy server | Payment request/response data in transit | Frankfurt, Germany (EU) |
Smart Fundi does not sell personal data to third parties, and does not share personal data with any party for direct marketing purposes without the data subject's consent.
Action item: Formalise a written data processing agreement/addendum with each processor, addressing security obligations, consistent with section 27(4) of the Act, which requires that processor activities be “governed by a contract” obligating the processor to act only on the controller's instructions and to meet the Act's security standards.
Sections 31 and 32 of the Act, together with regulations 20–22 of GN No. 449C, govern the transfer of personal data outside Tanzania. Smart Fundi's technical architecture uses Supabase (database/backend) and a DigitalOcean droplet (payment proxy server), both confirmed to be hosted in Frankfurt, Germany. All personal data described in section 7 of this Policy is therefore subject to transborder data flow, and this Policy is written on that basis.
Germany, as a member state of the European Union, is subject to the General Data Protection Regulation (GDPR) — a comprehensive statutory data protection framework widely recognised internationally as providing a high standard of protection for personal data, covering equivalent principles to the Act (lawfulness, purpose limitation, data minimisation, security, and data subject rights) with independent regulatory oversight and enforcement.
Section 31(2) of the Act permits transfer of personal data to a country with an adequate data protection framework where the transfer is necessary for the data controller's lawful functions, or where there is no reason to believe the data subject's legitimate interests would be prejudiced by the transfer or processing in the recipient country. Both conditions are credibly met here: hosting in Germany is necessary to operate Smart Fundi's core marketplace functions, and GDPR's protections mean data subjects are, if anything, subject to stronger statutory safeguards abroad than would apply to purely domestic processing.
Section 31(3) additionally requires the data controller to make a provisional evaluation of the necessity of the transfer. This Policy constitutes that evaluation: hosting in Frankfurt was a practical infrastructure decision (Supabase and DigitalOcean's available regions), the transfer is necessary for the app's core functionality, and Germany's GDPR framework provides an equivalent or stronger standard of protection than Tanzania's own regime.
At the time of writing, the Personal Data Protection Commission has not published a formal list of countries recognised as having “adequate” protection under section 31. Smart Fundi's position above is a reasonable, good-faith legal interpretation, not a guarantee of the Commission's own assessment.
Action item: To remove residual uncertainty, consider submitting an application for permission to transfer personal data outside the country under regulation 20 of GN No. 449C (Form No. 7) at the same time as initial registration under section 17 of this Policy — this converts a reasonable legal interpretation into an explicit, documented Commission approval, and is the more conservative path given financial transaction data (sensitive personal data) is included in what is transferred.
Action item: In the interim, and as a fallback if the adequacy position above were ever challenged, Smart Fundi can also rely on section 32(4)(b) — transfer necessary for performance of the contract between Smart Fundi and the data subject — which independently supports the current hosting arrangement regardless of the adequacy question.
Action item: Confirm whether Supabase's and DigitalOcean's standard terms of service include GDPR-compliant data processing agreements (both companies generally offer these as standard for EU-hosted infrastructure) — if so, retain a copy as supporting evidence of the security standard applied to the transferred data.
In accordance with section 28 of the Act and regulation 30 of GN No. 449C, Smart Fundi retains personal data only for as long as necessary for the purpose for which it was collected:
| Data category | Retention period | Disposal method |
|---|---|---|
| Active account data | Duration of active account, plus 10 months after account closure, to handle disputes | Secure deletion from Supabase database |
| Payment/transaction records | 5–7 years for financial/tax record-keeping obligations under Tanzanian law | Archived securely, then deleted |
| Verification documents (IDs, licences) | Duration of active registration, plus one year | Secure deletion from Supabase Storage |
| Portfolio photos & reviews | Until user deletes content or closes account | Secure deletion from Supabase Storage |
In accordance with section 27 and regulation 27 of GN No. 449C, Smart Fundi implements the following technical and organisational security measures:
Row Level Security (RLS) policies on the Supabase database, restricting data access by user role;
Service-role credentials for backend/webhook operations kept out of client-side code and restricted to the server-side payment proxy;
Encrypted transit (HTTPS) for API communications between the app and backend;
Phone number normalisation and validation to reduce data entry errors;
PM2-managed proxy server with automated restart to maintain availability and reduce data loss from unplanned downtime;
Access to the production server (SSH) restricted to authorised personnel.
Planned / recommended additional measures:
Formal, documented incident response and breach notification procedure (see section 15);
Periodic (at minimum annual) security review of the proxy server and database access policies;
Enabling SSH key-based authentication (rather than password authentication) on production servers;
Regular backups of the Supabase database with tested restore procedures;
Audit logging of access to sensitive personal data (financial/payment records).
In accordance with section 27(5) of the Act, Smart Fundi must notify the Commission, without undue delay, of any security breach affecting personal data being processed by or on behalf of Smart Fundi.
Upon discovery of a suspected or confirmed data breach, the following procedure will be followed:
1. The DPO is notified immediately upon discovery of the incident;
2. The DPO assesses the scope, cause, and severity of the breach, and whether personal data (particularly sensitive personal data) was affected;
3. Smart Fundi notifies the Commission without undue delay, describing the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed to address it;
4. Where the breach poses a risk to affected data subjects, Smart Fundi notifies those data subjects directly, where feasible;
5. The DPO documents the incident, root cause, and remedial actions taken, for internal record-keeping and for the quarterly compliance report to the Commission.
Regulation 33 of GN No. 449C requires a Data Protection Impact Assessment where processing is likely to significantly affect the rights and freedoms of data subjects — including large-scale processing of personal data, and processing that combines or cross-references datasets from different sources.
Given Smart Fundi's processing involves location data, financial transaction data, and identity verification documents at a platform-wide scale, Smart Fundi should conduct a DPIA using Form No. 9 in GN No. 449C, covering the data flows described in section 7 of this Policy, before further scaling the platform's user base.
Section 14(1) of the Act provides that a person shall not collect or process personal data without being registered as a data controller (or data processor) with the Commission. Smart Fundi is required to register using Form No. 1 in the First Schedule to GN No. 449C, accompanied by:
Proof of identity (if registering as a natural person) or a certificate of incorporation/registration (if registering as a legal person, e.g. once Abba Ltd is incorporated);
Details of the categories of personal data processed and the purposes of processing (as set out in section 7 and 8 of this Policy);
The applicable registration fee.
| Category (Second Schedule, GN No. 449C) | Threshold | Registration fee | Renewal fee (every 5 years) |
|---|---|---|---|
| Small-scale data controller | 1–49 employees, turnover under TZS 100,000,000/year | TZS 100,000 | TZS 50,000 |
| Medium-scale data controller | 50–99 employees, turnover TZS 100M–500M/year | TZS 200,000 | TZS 150,000 |
| Large-scale data controller | 100+ employees, turnover over TZS 500,000,000/year | TZS 1,000,000 | TZS 500,000 |
Based on Smart Fundi's current scale, registration as a small-scale data controller (TZS 100,000 registration fee) is the applicable category. Registration is valid for five years from the date of issuance and must be renewed within three months before expiry.
Action item (high priority): Submit Form No. 1 (First Schedule, GN No. 449C) to the Commission, together with this Policy, as soon as practicable. Registration under section 14 is a precondition to lawful collection or processing of personal data under the Act.
All individuals involved in operating Smart Fundi who have access to personal data will be made aware of this Policy and their obligations under the Act. As the team grows, formal onboarding training on data protection principles will be introduced.
This Policy will be reviewed at least annually, or sooner if there is a material change to Smart Fundi's data processing activities, technical infrastructure, or applicable law. Material changes to this Policy affecting registered particulars will be notified to the Commission within 14 days, in accordance with regulation 10 of GN No. 449C.
| Processing activity | Data categories | Purpose | Retention | Processor(s) involved |
|---|---|---|---|---|
| Account registration | Identity, contact data | Enable app access | Duration of account + [x] | Supabase |
| Location-based search | Location data | Match customers with fundis | Real-time / rolling | Supabase (PostGIS) |
| Subscription payments | Financial/transaction data | Enable paid platform access | [x] years (tax records) | Selcom, Supabase |
| Business verification | ID documents, licences | Fraud prevention, trust & safety | Duration of registration + [x] | Supabase Storage |
| Portfolio & reviews | Photos, ratings, text | Marketplace discovery & trust | Until deleted by user | Supabase Storage |
| Version | Date | Summary of changes | Author |
|---|---|---|---|
| 1.0 | Initial policy drafted |