Smart Fundi  |  Privacy Policy  |  Terms of Service

Smart Fundi - Personal Data Protection Policy

SMART FUNDI

PERSONAL DATA PROTECTION POLICY

(Code of Ethics for Personal Data Protection)

Prepared pursuant to Section 65 of the Personal Data Protection Act, Cap. 44 (Act No. 11 of 2022), for submission to the Personal Data Protection Commission (PDPC) and for internal governance use.

Data Controller: Barah Technologies Ltd

Version 1.0 | Effective Date:

Table of Contents

Table of Contents

1. Introduction and Purpose

2. Scope and Application

3. Key Definitions

4. Data Controller Information

5. Data Protection Officer (DPO)

6. Principles of Personal Data Protection

6.1 Lawfulness, Fairness and Transparency

6.2 Purpose Limitation

6.3 Data Minimisation and Proportionality

6.4 Accuracy

6.5 Storage Limitation

6.6 Integrity, Confidentiality and Security

6.7 Respect for Data Subject Rights

7. Categories of Personal Data Collected

8. Purpose and Legal Basis for Processing

9. Sensitive Personal Data

10. Rights of Data Subjects and How Smart Fundi Fulfils Them

11. Data Sharing and Third-Party Data Processors

12. Transborder Data Flow

12.1 Legal Basis: Transfer to a State with Adequate Protection (Section 31)

12.2 Residual Uncertainty and Recommended Next Step

13. Data Retention and Disposal

14. Data Security Measures

15. Data Breach Notification Procedure

16. Data Protection Impact Assessment (DPIA)

17. Registration with the Personal Data Protection Commission

18. Staff Training and Ongoing Compliance

19. Review of this Policy

Appendix A: Register of Processing Activities

Appendix B: Document Control

1. Introduction and Purpose

This Personal Data Protection Policy ("Policy") sets out how Smart Fundi collects, uses, discloses, retains, secures, and disposes of personal data belonging to customers, fundis (service providers), shop owners, super agents, and other individuals who interact with the Smart Fundi platform ("data subjects").

This Policy is prepared as the written code of ethics required under section 65 of the Personal Data Protection Act, Cap. 44 (Act No. 11 of 2022) ("the Act"), and is intended, in accordance with section 65(2), to be submitted to the Personal Data Protection Commission ("the Commission" or "PDPC") for consideration and approval. It also serves as Smart Fundi's internal governance document for data protection compliance.

This Policy has been prepared with reference to the Act, the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023 (GN No. 449C), and the Personal Data Protection (Complaints Settlement Procedures) Regulations, 2023 (GN No. 449B).

2. Scope and Application

This Policy applies to all personal data collected or processed by Smart Fundi, whether collected directly through the Smart Fundi mobile application, through the DigitalOcean-hosted payment proxy server, through Supabase (the platform's database and backend infrastructure), or through any other means, in connection with the following user roles:

This Policy applies to Mainland Tanzania, consistent with section 2 of the Act.

3. Key Definitions

Terms used in this Policy carry the meanings given to them in section 3 of the Act, including in particular:

4. Data Controller Information

Field Details
Registered name SMART FUNDI
Business registration number (BRELA) 635582
Physical address DODOMA, DODOMA CBD, DODOMA MAKULU
Postal address 41107
Contact email smartfundis@gmail.com
Contact phone +255796381261
Nature of business Digital marketplace connecting customers with handymen (fundis), shops, and material suppliers (super agents) in Tanzania

5. Data Protection Officer (DPO)

In accordance with section 27(3) of the Act and regulation 32 of GN No. 449C, Smart Fundi has appointed a Data Protection Officer responsible for:

Field Details
DPO name Joshua Calvin Maimu
DPO contact email maimujr@gmail.com
DPO contact phone +255748777436

6. Principles of Personal Data Protection

In accordance with section 5 of the Act and regulations 23–31 of GN No. 449C, Smart Fundi processes personal data on the basis of the following principles:

6.1 Lawfulness, Fairness and Transparency

Personal data is collected and processed lawfully, fairly, and transparently. Users are informed, at the point of registration, what data is collected and why.

6.2 Purpose Limitation

Personal data is collected for specific, explicit, and legitimate purposes (e.g. enabling bookings, processing subscription payments, verifying business credentials) and is not further processed in a manner incompatible with those purposes.

6.3 Data Minimisation and Proportionality

Smart Fundi collects only the personal data that is adequate, relevant, and necessary for the stated purpose — for example, collecting a fundi's location for search-matching purposes, without collecting unrelated data.

6.4 Accuracy

Smart Fundi takes reasonable steps to ensure personal data is accurate and, where necessary, kept up to date, including allowing users to update their own profile information.

6.5 Storage Limitation

Personal data is retained only for as long as necessary for the purposes for which it was collected, as set out in section 13 of this Policy.

6.6 Integrity, Confidentiality and Security

Personal data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, loss, destruction, or damage, as set out in section 14 of this Policy.

6.7 Respect for Data Subject Rights

Personal data is processed in accordance with the rights of data subjects set out in Part VI of the Act and section 10 of this Policy.

7. Categories of Personal Data Collected

Category Examples Collected From
Identity data Full name, date of birth, national ID / verification documents Fundis, Shop Owners, Super Agents (business verification)
Contact data Phone number, email address All user roles
Location data GPS coordinates (PostGIS) Fundis (for search-matching), Customers (for job requests)
Financial / transaction data Mobile money phone number, subscription payment amount, transaction reference, payment status All paying user roles, via Selcom
Business verification data Business licence PDFs, shop registration documents Shop Owners, Super Agents, Fundis
Profile & portfolio data Photos, captions, prices of past work Fundis, Shops, Super Agents
Ratings & review data Star ratings, written reviews Customers (about Fundis/Shops)
Usage data App activity, job requests, search history All user roles
Google account data Name, email address, profile photo (via Google Sign-In) Users who choose to register/sign in with Google

Where a user chooses to register or sign in using their Google account ("Sign in with Google"), Smart Fundi receives and stores the name, email address, and profile photo associated with that Google account, as provided by Google, for the sole purpose of creating and authenticating the user’s Smart Fundi account. Smart Fundi does not request or receive access to any other Google account data (such as Gmail, Google Drive, or Google Contacts).

8. Purpose and Legal Basis for Processing

Purpose Data used Legal basis (s.25 of the Act)
Account creation & authentication Name, phone, email Necessary for performance of the contract with the user (app terms of service)
Matching customers with nearby fundis Location data Necessary for performance of the contract; legitimate interest in enabling the core marketplace function
Processing subscription payments Financial/transaction data Necessary for performance of the contract; consent (see section 9 below, given this is sensitive personal data)
Verifying business credentials ID documents, business licences Necessary for performance of the contract; legal obligation to prevent fraud
Displaying fundi portfolios and reviews Photos, ratings, reviews Consent (user opts in by uploading/posting)
Customer support & dispute resolution Account & usage data Legitimate interest; necessary for performance of the contract

9. Sensitive Personal Data

Section 3 of the Act defines “sensitive personal data” to include, among other categories, “financial transactions of the individual.” Smart Fundi's processing of Selcom mobile money payment data (phone number used for payment, transaction amounts, and payment status) therefore constitutes processing of sensitive personal data.

In accordance with section 30(1) of the Act, Smart Fundi obtains prior written consent from data subjects before processing this category of data. This consent is captured at the point a user proceeds with a subscription or event payment within the app, and is documented in the app's Terms of Service and this Policy.

In accordance with section 30(2), users may withdraw this consent at any time and without charge, though doing so will mean Smart Fundi can no longer process payments on the user's behalf and paid features of the app will become unavailable.

10. Rights of Data Subjects and How Smart Fundi Fulfils Them

In accordance with Part VI of the Act (sections 33–38) and Part III of GN No. 449C, data subjects have the following rights, which Smart Fundi will honour through the process described:

Right How exercised Smart Fundi's response time
Right of access (s.33) Request via app support / email to DPO Within a reasonable time, and in any case consistent with the 14-day timelines used elsewhere in GN No. 449C
Right to prevent/suspend processing (s.34; reg.15) Written application to DPO, copied to Commission Acknowledge and temporarily suspend within 72 hours; final decision within 7 days
Right to rectification (s.29; reg.16) Written application to DPO, copied to Commission Accept/reject within 14 days, with written reasons if rejected
Right to erasure/destruction (s.38; reg.17) Written application to DPO, copied to Commission Accept/reject within 14 days, with written reasons if rejected
Right to object to direct marketing (s.35) In-app notification settings, or written request Immediate opt-out
Right to compensation (s.37) Complaint to the Commission Handled per the Commission's Complaints Settlement Procedures (GN No. 449B)

Where a data subject is a child, Smart Fundi will handle requests in accordance with regulation 18(2) of GN No. 449C, requiring proper identification of the person exercising the right and, where applicable, notice to the parent or guardian.

11. Data Sharing and Third-Party Data Processors

Smart Fundi shares personal data with the following third-party data processors, each acting under Smart Fundi's instructions in accordance with section 27(4) of the Act:

Processor Role Data shared Location
Selcom Paytech Ltd (Vendor ID SB00183906) Mobile money payment processing (USSD push) Phone number, payment amount, order reference Tanzania
Supabase Inc. Database hosting, authentication, file storage All categories in section 7 Frankfurt, Germany (EU)
DigitalOcean, LLC Hosting of the payment proxy server Payment request/response data in transit Frankfurt, Germany (EU)

Smart Fundi does not sell personal data to third parties, and does not share personal data with any party for direct marketing purposes without the data subject's consent.

12. Transborder Data Flow

Sections 31 and 32 of the Act, together with regulations 20–22 of GN No. 449C, govern the transfer of personal data outside Tanzania. Smart Fundi's technical architecture uses Supabase (database/backend) and a DigitalOcean droplet (payment proxy server), both confirmed to be hosted in Frankfurt, Germany. All personal data described in section 7 of this Policy is therefore subject to transborder data flow, and this Policy is written on that basis.

Germany, as a member state of the European Union, is subject to the General Data Protection Regulation (GDPR) — a comprehensive statutory data protection framework widely recognised internationally as providing a high standard of protection for personal data, covering equivalent principles to the Act (lawfulness, purpose limitation, data minimisation, security, and data subject rights) with independent regulatory oversight and enforcement.

Section 31(2) of the Act permits transfer of personal data to a country with an adequate data protection framework where the transfer is necessary for the data controller's lawful functions, or where there is no reason to believe the data subject's legitimate interests would be prejudiced by the transfer or processing in the recipient country. Both conditions are credibly met here: hosting in Germany is necessary to operate Smart Fundi's core marketplace functions, and GDPR's protections mean data subjects are, if anything, subject to stronger statutory safeguards abroad than would apply to purely domestic processing.

Section 31(3) additionally requires the data controller to make a provisional evaluation of the necessity of the transfer. This Policy constitutes that evaluation: hosting in Frankfurt was a practical infrastructure decision (Supabase and DigitalOcean's available regions), the transfer is necessary for the app's core functionality, and Germany's GDPR framework provides an equivalent or stronger standard of protection than Tanzania's own regime.

At the time of writing, the Personal Data Protection Commission has not published a formal list of countries recognised as having “adequate” protection under section 31. Smart Fundi's position above is a reasonable, good-faith legal interpretation, not a guarantee of the Commission's own assessment.

13. Data Retention and Disposal

In accordance with section 28 of the Act and regulation 30 of GN No. 449C, Smart Fundi retains personal data only for as long as necessary for the purpose for which it was collected:

Data category Retention period Disposal method
Active account data Duration of active account, plus 10 months after account closure, to handle disputes Secure deletion from Supabase database
Payment/transaction records 5–7 years for financial/tax record-keeping obligations under Tanzanian law Archived securely, then deleted
Verification documents (IDs, licences) Duration of active registration, plus one year Secure deletion from Supabase Storage
Portfolio photos & reviews Until user deletes content or closes account Secure deletion from Supabase Storage

14. Data Security Measures

In accordance with section 27 and regulation 27 of GN No. 449C, Smart Fundi implements the following technical and organisational security measures:

Planned / recommended additional measures:

15. Data Breach Notification Procedure

In accordance with section 27(5) of the Act, Smart Fundi must notify the Commission, without undue delay, of any security breach affecting personal data being processed by or on behalf of Smart Fundi.

Upon discovery of a suspected or confirmed data breach, the following procedure will be followed:

16. Data Protection Impact Assessment (DPIA)

Regulation 33 of GN No. 449C requires a Data Protection Impact Assessment where processing is likely to significantly affect the rights and freedoms of data subjects — including large-scale processing of personal data, and processing that combines or cross-references datasets from different sources.

Given Smart Fundi's processing involves location data, financial transaction data, and identity verification documents at a platform-wide scale, Smart Fundi should conduct a DPIA using Form No. 9 in GN No. 449C, covering the data flows described in section 7 of this Policy, before further scaling the platform's user base.

17. Registration with the Personal Data Protection Commission

Section 14(1) of the Act provides that a person shall not collect or process personal data without being registered as a data controller (or data processor) with the Commission. Smart Fundi is required to register using Form No. 1 in the First Schedule to GN No. 449C, accompanied by:

Category (Second Schedule, GN No. 449C) Threshold Registration fee Renewal fee (every 5 years)
Small-scale data controller 1–49 employees, turnover under TZS 100,000,000/year TZS 100,000 TZS 50,000
Medium-scale data controller 50–99 employees, turnover TZS 100M–500M/year TZS 200,000 TZS 150,000
Large-scale data controller 100+ employees, turnover over TZS 500,000,000/year TZS 1,000,000 TZS 500,000

Based on Smart Fundi's current scale, registration as a small-scale data controller (TZS 100,000 registration fee) is the applicable category. Registration is valid for five years from the date of issuance and must be renewed within three months before expiry.

18. Staff Training and Ongoing Compliance

All individuals involved in operating Smart Fundi who have access to personal data will be made aware of this Policy and their obligations under the Act. As the team grows, formal onboarding training on data protection principles will be introduced.

19. Review of this Policy

This Policy will be reviewed at least annually, or sooner if there is a material change to Smart Fundi's data processing activities, technical infrastructure, or applicable law. Material changes to this Policy affecting registered particulars will be notified to the Commission within 14 days, in accordance with regulation 10 of GN No. 449C.

Appendix A: Register of Processing Activities

Processing activity Data categories Purpose Retention Processor(s) involved
Account registration Identity, contact data Enable app access Duration of account + [x] Supabase
Location-based search Location data Match customers with fundis Real-time / rolling Supabase (PostGIS)
Subscription payments Financial/transaction data Enable paid platform access [x] years (tax records) Selcom, Supabase
Business verification ID documents, licences Fraud prevention, trust & safety Duration of registration + [x] Supabase Storage
Portfolio & reviews Photos, ratings, text Marketplace discovery & trust Until deleted by user Supabase Storage

Appendix B: Document Control

Version Date Summary of changes Author
1.0 Initial policy drafted