Legal
Privacy policy
How Sinefe collects, uses, and protects personal data under European and African data protection law.
This policy is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, the EU ePrivacy rules, and applicable African data protection laws, including South Africa’s POPIA, Kenya’s Data Protection Act 2019, Nigeria’s Data Protection Act 2023, Ghana’s Data Protection Act 2012, and similar national laws where you reside or use our services.
1. Data controller
Sinefe ("we", "us", "our") is the data controller for personal data processed through this platform, except where a merchant processes member data as an independent controller for their savings groups.
- Privacy contact: info@topsusu.com
2. Scope and roles
This policy applies to visitors, registered users, merchants, and members in the European Economic Area (EEA), the United Kingdom, Africa, and other regions where our services are available.
- Platform operator: we process account, security, and service data as controller.
- Merchants: when you join a merchant’s group, that merchant may also process your membership and contribution data under their own privacy obligations and any documents they provide to you.
- Processors: hosting, email, payment, and support providers process data on our documented instructions.
3. Personal data we collect
- Identity and contact: name, email, phone number.
- Account credentials: password (stored hashed); we never store plain-text passwords.
- Merchant profile: company name, country, city, business settings.
- Savings activity: group memberships, targets, contributions, receipts, and audit records.
- Payment metadata: amounts, currency, status, gateway references. Card and wallet details are processed by Stripe or PayPal on the merchant’s account, not stored by us.
- Technical and security data: IP address, device/browser type, session identifiers, logs, and fraud-prevention signals.
- Communications: support messages and service emails you receive from us.
We do not intentionally collect special categories of data (such as health or biometric data). Please do not upload such data unless necessary and lawful.
4. Lawful bases and purposes
Under the GDPR and comparable African laws, we rely on the following grounds as applicable:
- Contract: to create and manage your account, operate groups, and record contributions you request.
- Legal obligation: tax, accounting, anti-fraud, and regulatory requests where required.
- Legitimate interests: securing the platform, preventing abuse, and improving reliability, balanced against your rights.
- Consent: optional cookies, marketing (if offered), and any processing where consent is required by local law. You may withdraw consent at any time.
5. Cookies and similar technologies
Non-essential cookies and local storage (such as theme preference) are used only after you consent via our cookie banner, in line with the GDPR, the ePrivacy Directive, and African consent requirements. Details are in our Cookie policy.
6. Sharing and international transfers
We do not sell personal data. We may share data with:
- Merchants you choose to join: limited to data needed for their workspace.
- Payment processors: Stripe and PayPal, subject to their privacy policies and PCI standards.
- Infrastructure and communication providers: under data processing agreements with appropriate safeguards.
- Authorities: when required by law or to protect rights and safety.
Where data is transferred outside the EEA, UK, or your African country, we use appropriate safeguards such as EU Standard Contractual Clauses, UK IDTA/addendum, adequacy decisions, or other mechanisms recognised under POPIA, Kenya DPA, NDPA, and equivalent laws.
7. Retention
We retain personal data only as long as necessary for the purposes above, including:
- Active account data: for the life of your account.
- Financial and contribution records: as required by applicable accounting, tax, and cooperative-savings laws in your jurisdiction.
- Security logs: typically up to 12 months unless a longer period is needed for an investigation.
When data is no longer needed, we delete or anonymise it securely.
8. Security
We implement technical and organisational measures including encryption in transit, access controls, hashed passwords, and monitoring. No method of transmission over the internet is 100% secure; please use a strong password and protect your credentials.
9. Your rights
Depending on where you live, you may have the following rights (subject to legal exceptions):
- Access: obtain a copy of your personal data.
- Rectification: correct inaccurate data.
- Erasure: request deletion where there is no overriding legal need to retain data.
- Restriction: limit processing in certain circumstances.
- Portability: receive data you provided in a structured, machine-readable format (GDPR/UK GDPR).
- Objection: object to processing based on legitimate interests or direct marketing.
- Withdraw consent: where processing is consent-based, without affecting prior lawful processing.
- Lodge a complaint: with a supervisory authority listed below or your local regulator.
To exercise your rights, email info@topsusu.com. We respond within 30 days (GDPR/UK: one month, extendable where permitted). We may need to verify your identity.
For data held by a merchant about their group, contact that merchant first; we will assist where we act as processor.
10. Supervisory authorities
You may complain to your local authority, including:
- Your EU/EEA national data protection authority
- Information Commissioner’s Office (ICO)
- Information Regulator (South Africa: POPIA)
- Office of the Data Protection Commissioner (Kenya)
- Nigeria Data Protection Commission (NDPC)
- Data Protection Commission (Ghana)
11. Children
Our services are not directed at children under 16 (or the higher age set by law in your country). We do not knowingly collect data from children. Contact us to request deletion if you believe a child has registered.
12. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.
13. Data breaches
If a personal data breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours where the GDPR applies, and inform affected individuals without undue delay when required by EU, UK, or African law.
14. Changes
We may update this policy. Material changes will be posted here with a new "last updated" date. Where required by law, we will seek renewed consent or give you advance notice.