JavaScript is not enabled, please check your browser settings and enable it to continue.

Privacy Policy

Privacy Policy

Effective Date: 12 April, 2026 Last Updated: 13 April, 2026

1. Introduction

Welcome to SACCOs Manager, a product of Softneedstack Technologies ("we," "our," "us," or the "Company"). We are committed to protecting your privacy and personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023, the Nigeria Data Protection Regulation (NDPR) 2019, the National Information Technology Development Agency (NITDA) Act, and other applicable laws of the Federal Republic of Nigeria.

This Privacy Policy explains how we collect, use, store, disclose, and protect your personal data when you access or use our SACCO (Savings and Credit Cooperative Organisation) management platform and related services.

By using our services, you acknowledge that you have read, understood, and consent to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our platform immediately.

2. Data Controller

The data controller responsible for your personal data is:

Softneedstack Technologies Email: softneedstacktechnologies@gmail.com

3. Personal Data We Collect

We collect the following categories of personal data:

a. Account Information

Name, email address, phone number, password (encrypted), role, and profile details provided during registration.

b. Member/Customer Data

SACCO administrators may register and manage members' data including: full name, gender, phone number, email, residential address, state, LGA, next-of-kin details, bank information, registration number, PSN number, account number, and profile photographs.

c. Financial Data

Transaction records, loan details, savings and contribution records, repayment histories, dividend calculations, account balances, and payment information processed through third-party payment processors (e.g., Paystack).

d. Communication Data

Messages sent via SMS, email, WhatsApp, and Telegram through the platform, AI chat interactions, support requests, and feedback.

e. Telegram Data

If you choose to link your Telegram account to our Platform, we collect your Telegram chat ID (a unique numeric identifier assigned by Telegram). This is collected when you initiate a link via our Telegram bot (@SACCOsManagerBot) using a secure, time-limited deep link. We do not collect your Telegram username, profile photo, or message history.

f. Technical Data

IP address, browser type and version, device information, operating system, login timestamps, pages visited, and session data.

g. KYC/Identity Documents

Where applicable, identification documents uploaded for compliance and verification purposes.

4. Legal Basis for Processing

We process your personal data on the following legal bases under the NDPA 2023:

  • Consent: You have given clear consent for us to process your personal data for specific purposes.
  • Contract: Processing is necessary for the performance of a contract to which you are a party (e.g., providing SACCO management services).
  • Legal Obligation: Processing is necessary for compliance with Nigerian laws and regulations.
  • Legitimate Interest: Processing is necessary for our legitimate business interests, provided such interests do not override your fundamental rights and freedoms.

5. How We Use Your Personal Data

We use your personal data to:

  • Provide, maintain, and improve our SACCO management platform and services
  • Process financial transactions, loans, contributions, and dividends
  • Send transactional notifications via SMS, email, WhatsApp, and Telegram
  • Facilitate AI-powered features such as financial insights, risk assessments, and message composition
  • Verify your identity and prevent fraud
  • Respond to support requests and communicate with you
  • Generate reports and analytics for SACCO administrators
  • Comply with legal, regulatory, and audit requirements
  • Enforce our Terms and Conditions

6. Data Sharing and Disclosure

We do not sell your personal data. We may share your data with:

a. SACCO Administrators

Member data is accessible to the SACCO entity (and its authorised personnel) under which the member is registered.

b. Third-Party Service Providers

We engage trusted third-party providers who process data on our behalf, including:

  • Paystack — payment processing
  • Twilio — WhatsApp messaging
  • BulkSMS Nigeria / Termii — SMS delivery
  • Google (Gmail SMTP) — email delivery
  • OpenAI — AI-powered features (data is processed per OpenAI's data usage policies; no personal identifiers are intentionally sent)
  • Telegram — instant messaging notifications via the Telegram Bot API. When you link your account, your Telegram chat ID is stored and used to deliver notifications. Messages are transmitted via Telegram's servers, which are operated by Telegram FZ-LLC.

All third-party processors are bound by data processing agreements and are required to implement adequate security measures.

c. Legal Authorities

We may disclose your data if required by law, court order, or lawful request from a government agency or regulatory body in Nigeria.

7. Data Retention

We retain your personal data for as long as:

  • Your account remains active
  • It is necessary to fulfil the purposes outlined in this policy
  • Required by applicable Nigerian law (e.g., financial records may be retained for a minimum of 6 years per CBN guidelines)

When data is no longer needed, we will securely delete or anonymise it. Deleted accounts are soft-deleted and permanently purged after 90 days unless retention is required by law.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of passwords using bcrypt hashing
  • HTTPS/TLS encryption for data in transit
  • CSRF protection and XSS sanitisation
  • Session encryption and secure cookie settings
  • Role-based access control (RBAC) to limit data access
  • Regular database backups with secure storage
  • Rate limiting to prevent abuse

Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you and the relevant authorities in the event of a data breach in accordance with the NDPA 2023.

9. Your Rights

Under the NDPA 2023 and NDPR 2019, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention obligations.
  • Right to Restrict Processing: Request that we limit the processing of your data in certain circumstances.
  • Right to Data Portability: Request your data in a structured, commonly used, and machine-readable format.
  • Right to Object: Object to processing based on legitimate interest.
  • Right to Withdraw Consent: Withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at softneedstacktechnologies@gmail.com. We will respond within 30 days.

10. International Data Transfers

Your data is primarily stored and processed in Nigeria. Where data is transferred to third-party processors located outside Nigeria (e.g., OpenAI, Twilio, Telegram), we ensure that adequate safeguards are in place as required by the NDPA 2023, including data processing agreements with appropriate security obligations.

11. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately and we will take steps to delete such data.

12. Automated Decision-Making

Our platform uses AI-powered features to provide financial insights, risk assessments, and recommendations. These features are tools to assist SACCO administrators and do not constitute solely automated decision-making that produces legal effects. Final decisions regarding loans, membership, and other matters remain with the SACCO administrators.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The updated version will be posted on our platform with the revised effective date. We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.

14. Complaints

If you believe that we have violated your data protection rights, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or any other competent regulatory authority.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Softneedstack Technologies Email: softneedstacktechnologies@gmail.com

16. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023, the NDPR 2019, and the NITDA Act.