Privacy Policy
Last updated: December 2024
1. Introduction
Deisky Technologies Limited ("Deisky," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our websites, mobile applications, and services, including but not limited to Chilimba and other products we develop.
This policy is prepared in compliance with the Data Protection Act No. 3 of 2021 of the Republic of Zambia, the Electronic Communications and Transactions Act No. 21 of 2009, and other applicable data protection regulations.
2. About Deisky Technologies
Deisky Technologies Limited is a technology company registered in Zambia. We develop and operate various digital products and services designed to improve everyday life for Zambians. Our products include mobile applications, web platforms, and digital solutions across various sectors including financial technology, e-commerce, and digital services.
3. Information We Collect
3.1 Personal Information
We collect information you provide directly to us, which may include:
- Full name and contact details (phone number, email address, physical address)
- National Registration Card (NRC) number or other government-issued identification
- Date of birth and gender
- Mobile money account details (Airtel Money, MTN Money, Zamtel Kwacha)
- Bank account information (where applicable)
- Profile photograph
- Business registration details (for business users)
3.2 Transaction Information
Depending on the services you use, we may collect:
- Payment and transaction history
- Purchase records and order details
- Service usage patterns and preferences
- Communication records with our support team
3.3 Device and Technical Information
We automatically collect certain information, including:
- Device type, model, and operating system
- Unique device identifiers (IMEI, advertising ID)
- IP address and network information
- Browser type and version
- App version and crash logs
- Location data (with your consent)
3.4 Cookies and Tracking Technologies
Our websites use cookies and similar technologies to enhance your experience, analyse usage patterns, and deliver personalized content. You can manage cookie preferences through your browser settings.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our products and services
- Process transactions and send related notifications
- Create and manage your user account
- Verify your identity and prevent fraud
- Communicate with you about products, services, and promotions
- Respond to your inquiries and provide customer support
- Conduct research and analytics to improve user experience
- Comply with legal obligations under Zambian law
- Enforce our terms of service and protect our rights
- Detect and prevent security threats and abuse
5. Legal Basis for Processing
Under the Data Protection Act 2021, we process your personal data based on the following legal grounds:
- Consent: Where you have given explicit consent for specific purposes
- Contractual Necessity: To perform our contractual obligations to you
- Legal Obligation: To comply with Zambian laws and regulations
- Legitimate Interest: For our legitimate business interests, balanced against your rights
6. Information Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- With Service Providers: Third-party vendors who perform services on our behalf (hosting, payment processing, analytics, customer support)
- With Payment Partners: Mobile money providers (Airtel Money, MTN Money, Zamtel Kwacha), banks, and payment processors to facilitate transactions
- Within Deisky Products: Your information may be shared between Deisky products to provide integrated services, with your consent where required
- For Legal Compliance: When required by law or to comply with requests from the Bank of Zambia, Zambia Information and Communications Technology Authority (ZICTA), Zambia Revenue Authority (ZRA), Financial Intelligence Centre, or other regulatory authorities
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity
- With Your Consent: We may share information with your explicit consent
7. International Data Transfers
Your information may be transferred to and processed in countries outside Zambia where our servers or service providers are located. When we transfer data internationally, we ensure appropriate safeguards are in place in accordance with the Data Protection Act 2021, including ensuring the recipient country provides adequate data protection or implementing contractual protections.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication mechanisms including multi-factor authentication
- Regular security assessments, penetration testing, and audits
- Access controls limiting employee access to personal data
- Employee training on data protection and security
- Incident response procedures for data breaches
- Secure data centers with physical security controls
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
9. Your Rights Under Zambian Law
Under the Data Protection Act 2021, you have the following rights:
- Right of Access: Request access to your personal data that we hold
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements
- Right to Restrict Processing: Request limitation on how we process your data
- Right to Object: Object to processing of your personal data for direct marketing or based on legitimate interests
- Right to Data Portability: Request your data in a commonly used electronic format
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time
- Right Not to be Subject to Automated Decisions: Object to decisions made solely by automated processing that significantly affect you
To exercise these rights, please contact us at privacy@deisky.com. We will respond within thirty (30) days.
10. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services and fulfill the purposes described in this policy
- Comply with legal obligations (financial records are retained for seven (7) years per Zambian tax and financial regulations)
- Resolve disputes and enforce our agreements
- Meet Anti-Money Laundering Act requirements
Upon account deletion or when data is no longer needed, we will delete or anonymize your personal data within ninety (90) days, except where retention is required by law.
11. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@deisky.com. We will take steps to delete such information.
12. Third-Party Links and Services
Our services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new policy on our website, updating the "Last updated" date, and where appropriate, notifying you via email or in-app notification. We encourage you to review this policy periodically.
14. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or have concerns about how we handle your data, please contact us:
Deisky Technologies Limited
Data Protection Officer
Email: privacy@deisky.com
General Inquiries: hello@deisky.com
Lusaka, Zambia
15. Supervisory Authority
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the Data Protection Commissioner at: