Our commitment: Basket Advisory Technologies complies with Uganda's Data Protection and Privacy Act, 2019 (Cap. 97) and the Data Protection and Privacy Regulations, 2021. We collect only what we need, we never sell personal data, and we protect it with appropriate security safeguards.
1. Introduction
Basket Advisory Technologies ("Basket", "we", "us", "our") builds technology that brings Uganda's casual and informal workforce into the formal economy. In doing so, we collect and process personal data belonging to workers, agents, clients, patients, farmers and business contacts.
We are committed to protecting that data and to full compliance with the Data Protection and Privacy Act, 2019 (Cap. 97) and the Data Protection and Privacy Regulations, 2021 of Uganda, together with directions issued by the Personal Data Protection Office (PDPO) under the National Information Technology Authority – Uganda (NITA-U).
2. Scope
This policy applies to all personal data we process through our platforms:
- Basket Payroll (including Cash Collect) — payroll and cash payouts for casual and formal workers
- Jirani — agricultural sourcing and traceability
- Tajiri — corporate field distribution
- Basket Books — bookkeeping and invoicing
- BwalaPay — informal-economy credit scoring and savings
- Rafiki — healthcare donation traceability
It applies to all Basket staff, field agents, contractors, and any third party who processes personal data on our behalf.
3. Our Role Under the Law
For the personal data of our own clients and users, Basket acts as a data controller (we decide why and how data is processed).
For personal data that our client companies upload and manage through our platforms (for example, a manpower company's list of workers), that client is the data controller and Basket acts as a data processor, handling the data on their instructions. Our respective obligations are set out in our client agreements. Where we determine purposes jointly with a client, we act as joint controllers and allocate responsibilities in writing.
4. The Principles We Follow
In line with Section 3 of the Act, we adhere to the seven principles of data protection. We:
- Are accountable to every data subject for the data we hold.
- Collect and process data lawfully and fairly, with a valid legal basis.
- Collect only what is adequate, relevant and necessary — never excessive.
- Retain data only as long as the law requires or the purpose demands, then securely destroy or de-identify it.
- Keep data accurate, complete, up to date and not misleading.
- Ensure transparency and participation of data subjects.
- Observe security safeguards appropriate to the sensitivity of the data.
5. What Personal Data We Collect
We practise data minimisation — we collect a field only where it is needed for the stated purpose.
Identity and contact data
Full name, telephone number, email address, National Identification Number (NIN), physical location or district, and employer or organisation.
Financial data (special personal data)
Payment amounts, wages and salaries, daily rates, amounts owed and collected, agent float balances, bank or mobile-money account details, and credit-related information used for scoring. Financial information is special personal data under Section 9 of the Act and receives heightened protection.
Biometric data (special personal data)
For worker and beneficiary verification, our platforms are designed to use facial images, fingerprint data, and wristband (QR) identifiers. Biometric identifiers are highly sensitive and are treated as special personal data.
Current status: During pilot phases, biometric verification steps may be operated in a demonstration mode. Where biometric capture is not yet live, we say so plainly and do not represent simulated verification as a completed biometric match. When live biometric capture is enabled, it is governed fully by this policy.
Health data (special personal data)
Through Rafiki, we process data relating to the receipt of donated medical supplies by patients and beneficiaries, including their identity and confirmation of delivery. Health status and medical records are special personal data under Section 9 of the Act.
Geolocation data
GPS coordinates captured at points of hand-off, delivery or payout, used as proof of presence and to prevent fraud.
Account and usage data
Login credentials (passwords are stored in hashed form by our authentication provider, never in plain text), and records of actions taken in the platform for audit purposes.
6. Why We Collect It
We only process personal data where we have a lawful basis under Sections 7 and 9 of the Act:
- Consent — freely given, specific, informed and unambiguous.
- Performance of a contract — to deliver the services requested.
- Legal obligation — where an employer or accountable institution is required by law to collect and retain certain data (payroll, tax, anti-money-laundering).
- Legitimate activities — for the proper functioning of the service, where this does not override the data subject's rights.
Special personal data (financial, biometric, health) is only processed where a Section 9 exception applies — most commonly the free and informed consent of the data subject, or an obligation imposed by law on an employer.
Children's data: We do not knowingly collect personal data relating to a child (under 18) without the prior consent of a parent or guardian, and only where necessary and lawful. Our gold-sourcing traceability in Jirani includes an adult-verification step specifically to support the exclusion of child labour.
7. Consent
Where we rely on consent, we request it in clear language before collecting data, explain what is collected and why, and make consent as easy to withdraw as to give. For workers and beneficiaries who may have limited literacy, our field agents explain the purpose verbally, in a language the person understands, before any data is captured. Withdrawing consent does not affect processing already carried out lawfully.
8. How We Protect Your Data
In line with Sections 20 and 22 of the Act, we implement appropriate technical and organisational measures:
- Access control — authenticated logins and row-level security, so each company, agent or user sees only the data they are entitled to.
- Encryption in transit — data is transmitted over encrypted connections (HTTPS).
- Password protection — credentials are stored hashed and are never visible to Basket staff.
- Immutable audit trails — payout and traceability records are tamper-resistant.
- Least privilege — staff and agents get only the access their role requires.
- Risk management — we identify, safeguard against, verify and update against foreseeable risks.
- Vendor diligence — our providers must maintain security at least equivalent to our own.
9. Sharing and Disclosure
We do not sell personal data — the Act makes the sale of personal data a criminal offence, and we treat it as an absolute prohibition. We share personal data only: with the client company that owns it; with service providers who process it on our behalf under contract; where required by law or a lawful order of a court or the PDPO; or with the data subject's consent.
10. Storage and Cross-Border Transfers
Some infrastructure and service providers may store or process data outside Uganda. Where this occurs, in line with Section 19 of the Act, we ensure that the destination country has data-protection measures at least equivalent to Uganda's, or that the data subject has consented. Where our clients require data to remain within Uganda, we accommodate that.
11. Data Retention
We retain personal data only as long as necessary for the purpose or as required by law. Payroll, payout and financial records are retained for the periods required by Ugandan tax and anti-money-laundering law; traceability and delivery records for the period needed for donor, buyer or regulatory accountability; account data while the account is active and for a reasonable period afterwards. At the end of the retention period we securely destroy or de-identify the data.
12. Your Rights
Under the Act, every person whose data we hold has the right to:
- Be informed of what data we hold and why.
- Access their personal data (we respond within 30 days of a verified request).
- Rectify data that is inaccurate, incomplete, misleading or out of date.
- Object to or restrict processing that causes unwarranted damage or distress.
- Have data erased where it is inaccurate or was unlawfully obtained or held.
- Withdraw consent where processing is based on consent.
- Complain to Basket, and to the PDPO.
To exercise any of these rights, contact our Data Protection Officer (Section 15). Exercising these rights is free of charge.
13. Data Breaches
If we believe personal data has been accessed or acquired by an unauthorised person, we will act immediately to contain and assess the breach, notify the PDPO as required, and notify affected data subjects where the breach is likely to cause them harm. We maintain an internal breach-response procedure and a record of any breaches.
14. Data Protection Impact Assessments
Because we process special personal data (financial, biometric and health) and monitor location, we carry out a Data Protection Impact Assessment (DPIA) before launching processing activities likely to pose a high risk to data subjects' rights, as anticipated by the Regulations.
15. Our Data Protection Officer
In line with Section 6 of the Act and the Regulations, Basket has designated a Data Protection Officer (DPO) responsible for compliance, liaising with the PDPO, maintaining our record of processing activities, and handling data-subject requests and complaints.
Data Protection Officer
Basket Advisory Technologies
Nakawa, Innovation Hub Port Bell Road, 1st Floor Wing A, Kampala
Email: solutions@basketadvisory.com
We are registered, or are completing registration, with the Personal Data Protection Office as a data collector, processor and controller, as required by Regulation 15, and we renew that registration as required.
16. Complaints
If you have a concern about how we handle your personal data, please contact our DPO first — we aim to resolve complaints amicably and promptly. You also have the right to complain directly to the Personal Data Protection Office (PDPO), National Information Technology Authority – Uganda, at www.pdpo.go.ug.
17. Changes to This Policy
We review this policy regularly and update it to reflect changes in our platforms, our processing activities, or the law. The version number and date at the top show when it was last updated. Material changes will be communicated to affected users.
This policy reflects the requirements of the Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021 of Uganda. It does not constitute legal advice.