Data Protection and Privacy Policy
| Version | 1.2 |
| Date | 10 October 2026 |
| Applies to | Users of GoSavis in Uganda |
| Data controller | Gosavis Ltd |
| Data Protection Officer | Joash Trevor Nowe |
| Registration number | 80046934363764 |
| privacy@gosavis.com | |
| Incorporated in Uganda | 15 September 2026 |
| Address | KIIRA ROAD, 202654 Nakawa, Kiwana Road, Bukoto, Church Street Mall |
| Approved by: | Director |
| Name of Approver: | Mawanda Raymond Samson |
| Signature: | |
| Date: | 10/10/2026 |
1.0 Definitions
1.1 In this policy, the words below have the meanings set out beside them. Words in the singular include the plural, and the other way round.
| Act | The Data Protection and Privacy Act, Cap. 97 of the Laws of Uganda, enacted as the Data Protection and Privacy Act, 2019. |
| Regulations | The Data Protection and Privacy Regulations, 2021, made under the Act. |
| PDPO or the Office | The Personal Data Protection Office established under the Act within the National Information Technology Authority, Uganda, and headed by the National Personal Data Protection Director. It oversees and enforces the Act, keeps the data protection register and receives complaints. |
| GoSavis or the platform | The GoSavis website and apps: GoSavis, where customers find, book and pay for services, and GoSavis Business, where businesses manage their presence, bookings and payments. |
| Gosavis Ltd, we, us or our | Gosavis Ltd, a company incorporated in Uganda under registration number 80046934363764, which provides GoSavis in Uganda. It is the data controller for the personal data this policy covers, except for the processing it carries out on a business’s documented instructions under clause 3.14, where the business is the controller and Gosavis Ltd acts as its data processor. |
| GoSavis Limited | GoSavis Limited, a company registered in England and Wales under company number 12899784, which builds and runs the platform and processes personal data for Gosavis Ltd as its data processor. |
| User or you | A person who uses GoSavis in Uganda, as a customer, as a business or a person acting for one, or as a visitor, and any other person whose personal data we process under this policy. |
| Customer | A person who uses GoSavis to find, book or pay for a service. |
| Business | A company, sole trader, individual practitioner, event organiser, charity or other organisation that offers services through GoSavis Business, and the people who act for it. |
| Visitor | A person who views GoSavis without signing in to an account. |
| Data subject | An individual from whom, or about whom, personal data is requested, collected, collated, processed or stored. |
| Personal data | Information about a person from which the person can be identified, recorded in any form. It includes information about the person’s nationality, age or marital status, education or occupation, an identification number or other particulars assigned to them, identity data, and any expression of opinion about them. |
| Special personal data | Personal data about a person’s religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records, which the Act allows to be collected or processed only in limited cases. |
| Child | A person under the age of eighteen years. |
| Consent | A freely given, specific, informed and unambiguous indication of your wishes by which you, through a statement or a clear affirmative action, agree to the collection or processing of personal data about you. |
| Processing | Any operation performed on personal data, by automated means or otherwise, including collecting, recording, organising, adapting, retrieving, using, disclosing, combining, blocking, erasing or destroying it. |
| Data controller | A person who, alone or with others, decides the purposes for which, and the manner in which, personal data is processed. |
| Data processor | A person, other than an employee of the data controller, who processes personal data on the data controller’s behalf. |
| Data Protection Officer or DPO | The person Gosavis Ltd has designated under the Act as responsible for ensuring compliance with the Act. |
| Recipient | A person to whom personal data is disclosed, including an employee or agent of the data controller or of a data processor. |
| Third party | A person other than the data subject, the data controller, a data processor or a person authorised to process personal data for either of them. |
| Direct marketing | The communication, by any means, of advertising or marketing material that is directed at an individual. |
| Personal data breach | An event in which personal data is accessed or acquired by an unauthorised person, or is lost, destroyed, altered or disclosed without authority. |
| Anonymisation | Removing identifiers from personal data so that the person can no longer be identified from it. |
| Pseudonymisation | Replacing the identifiers in personal data so that it can no longer be linked to a person without further information that is kept separately. |
| Cookies | Small text files stored by your browser, together with similar technologies such as local storage, session storage, IndexedDB and cache storage. |
| Retention period | The period for which we keep a category of personal data before it is deleted, destroyed or de-identified. |
2.0 Introduction, Purpose and Scope
Introduction
2.1 GoSavis is a platform that connects people who need local services with the businesses and individuals that supply them. In Uganda, GoSavis is provided by Gosavis Ltd, a company incorporated in Uganda on 15 September 2026 under registration number 80046934363764, whose address is KIIRA ROAD, 202654 Nakawa, Kiwana Road, Bukoto, Church Street Mall.
2.2 GoSavis is not yet offered to the public in Uganda. From the day this version is published, this policy applies to the personal data of anyone who signs up on our Ugandan pages to hear when the service opens. Otherwise it describes how Gosavis Ltd will collect and use personal data from the day the service opens in Uganda, and the safeguards it describes are in place before that day. Where a safeguard is being built, it is completed and working before we accept a booking from a user in Uganda. We will publish the opening date in this policy.
2.3 This policy explains what personal data we collect when you use GoSavis in Uganda, why we collect it, who we share it with, how long we keep it and the rights you have over it. It is written to meet the requirements of the Act and the Regulations.
2.4 Gosavis Ltd acts as the data controller for the platform activities described in this policy, except where clause 3.14 identifies processing carried out on a business’s documented instructions. For those activities, the relevant business is the data controller and Gosavis Ltd acts as its data processor. Our responsibilities are determined by our actual role in the relevant processing activity.
2.5 GoSavis Limited, a company registered in England and Wales under company number 12899784, builds and runs the GoSavis platform. It processes personal data for Gosavis Ltd as our data processor, only on our instructions and under a written contract that requires it to keep the data confidential and secure. All processing of personal data on GoSavis in Uganda is carried out for Gosavis Ltd, under our registration with the Personal Data Protection Office (clause 2.7). The platform’s servers and services are outside Uganda: section 7.0 explains where your personal data is processed and how it is protected there.
2.6 Our Data Protection Officer is Joash Trevor Nowe. If you have a question about how your personal data is handled, or want to use any of your rights, you can write to our Data Protection Officer at privacy@gosavis.com or at our address above.
2.7 Gosavis Ltd, incorporated in Uganda on 15 September 2026 under registration number 80046934363764, is registered with the Personal Data Protection Office as a data collector, a data processor and a data controller under registration number PDPO‑202609‑15515, issued on 24 September 2026. That registration covers both the capacities this policy describes: as a data controller for the platform activities, and as a data processor for the processing it carries out on a business’s documented instructions under clause 3.14. All processing of personal data on GoSavis in Uganda, including what GoSavis Limited does as our data processor, is carried out for Gosavis Ltd and under this registration. The registration is renewed each year. The Office’s data protection register is open to inspection by anyone, free of charge, and anyone may obtain a certified copy of an entry in it from the Office for the fee the Regulations set.
2.8 We have written this policy to be plain rather than legalistic. Where a passage needs to be precise for legal reasons, we have tried to follow it with a sentence in ordinary language. If anything here is unclear, please contact us and we will explain.
Policy statements
2.9 We collect and process personal data lawfully, fairly and transparently, in line with the Act, the Regulations and the other laws of Uganda.
2.10 We collect personal data with your consent, or on one of the other grounds the Act and the Regulations recognise, and only for the specific purposes this policy describes. Section 6.0 explains when each applies.
2.11 We do not sell personal data or offer it for sale, and we do not allow our suppliers to use account, booking or payment information for their own advertising.
2.12 We require everyone who handles personal data for us to follow this policy, and our Data Protection Officer arranges the training they need to do so.
Purpose and objectives
2.13 This policy sets out how Gosavis Ltd collects, uses, shares, protects, keeps and deletes personal data. Its objectives are:
to tell you, before we collect your personal data, what the law requires you to be told: what we collect, who is responsible for it, why we need it, whether you must provide it and what happens if you do not, who receives it, your rights and how long we keep it;
to set out the principles we follow and the people responsible for following them;
to explain your rights, how to use them and how we respond;
to explain how we protect personal data, including when it is processed outside Uganda, and what we do if a personal data breach occurs; and
to give you a clear route to raise a concern with us or with the Personal Data Protection Office.
Scope
2.14 This policy applies to the personal data of users of GoSavis in Uganda: customers, businesses and the people who act for them, visitors, and people whose details a user gives us, such as a person a customer books a service for or a team member a business invites.
2.15 It applies to all personal data we process through GoSavis, whether you give it to us directly, we collect it automatically or we receive it from someone else.
2.16 It does not cover the personal data of Gosavis Ltd’s own staff, which a separate internal policy covers. Nor does it cover what a business does with personal data outside GoSavis, for which that business is responsible, or the services of third parties you choose to open, such as sign-in with Google or Apple or an external video, which process information under their own privacy terms.
3.0 Personal Data
Collection of personal data
3.1 We collect personal data directly from you when you:
create an account or sign in, including with Google or Apple if you choose to;
complete your profile or set your preferences;
list a business, offer services and complete business verification;
search for, book and pay for a service, or accept, manage and provide a booked service as a business;
send a message, write a review, post content, make a report or contact support; and
choose your cookie settings or allow your browser to share your location.
3.2 We also collect some personal data automatically when you use GoSavis (clause 3.3.8) and, in limited cases, from other people: a customer who books a service for someone else gives us that person’s details (clause 3.13); a business gives us the details of team members it invites (clause 3.14); MTN Mobile Money or Airtel Money tells us the outcome of a payment, refund or payout, and may give us the name registered to a mobile money number; and Google or Apple gives us the details you allow when you choose to sign in with them. Where we collect personal data about you from someone else, we tell you what we hold as soon as practicable, as clause 3.13 explains for a person someone else booked for.
Types of personal data
3.3 The personal data we collect depends on the features you use. It can include the following.
3.3.1 Account details
Your name, the email address you sign in with, a phone number if you have provided one, any password you set, and your confirmation, when you register, that you are 18 or over. Passwords are never stored in readable form.
3.3.2 Profile details
Your username, display photo, biography, contact and location visibility choices, service area, portfolio, favourites and other preferences, including interests you choose to declare and the feedback you give on categories, which we use to order what you see.
3.3.3 Booking and service data
Listings, availability, booking times, service locations (including your own address where a business comes to you), prices, cancellation conditions, notes, answers to a business’s booking questions, and booking history.
3.3.4 Payment and payout records
Payment status, amount and currency, how a booking was paid (MTN MoMo Pay, Airtel Pay or cash), the mobile money number a payment is made from or a business is paid to, the name registered to that number where the mobile money provider returns it, the provider’s transaction references, tips, fees, refunds, reversals and a business’s payout status. Your mobile money PIN is entered only on your own phone, in your mobile money provider’s own prompt: GoSavis never receives or stores it. A payment in cash is made to the business directly, and GoSavis records only that it was paid in cash and the amount.
3.3.5 Communications and content
Messages, comments, reviews, posts, requests for work and bids on them, reports, complaints, support enquiries, feedback, and any photos or other media you upload.
3.3.6 Business and verification details
Trading and legal names, registration and tax identifiers, business addresses, licences, insurance, ownership or representative details, identity documents, proof of address, date of birth where verification requires it, and the mobile money number the business is paid to, with the name registered to it.
3.3.7 Location
If you ask GoSavis to use your location, your browser supplies coordinates, which we use to find services near you and to show the place they correspond to. Your location preferences may stay on your device until you clear or change them. Addresses saved on GoSavis, such as a business’s premises or your address for a service at home, are converted into map coordinates.
3.3.8 Device, usage and security information
Your IP address, browser and device type, user agent, session and device identifiers, sign-in and security events, approximate route information, timestamps, crash details, and the actions needed to prevent fraud or to investigate a failure.
3.3.9 Views of a business profile
When you open a business profile, we count the view so that businesses can see how often their profile is seen. To count each visitor only once a day, we combine your IP address and browser type with a key that changes every day and is deleted once the day ends, and keep only the code that results, so your address cannot be recovered from it and your visits cannot be linked from one day to the next. No cookie is used. We do not count the business itself or its team, automated visitors such as search engine crawlers, or a browser sending the Global Privacy Control signal. The daily records are deleted after 8 days.
Use of personal data
3.4 We use personal data for the following purposes:
registering, authenticating and supporting accounts, including email verification, sign-in with Google or Apple, two-factor authentication and trusted-device controls;
publishing profiles, listings, posts, reviews and other content according to the visibility choices you make;
creating, administering, cancelling and evidencing bookings and the conditions a business sets for them;
processing mobile money payments, refunds, platform fees and payouts to businesses, and recording payments made in cash;
delivering messages and notifications between customers, businesses and their teams;
verifying businesses, protecting users, preventing fraud, moderating content and investigating reports and complaints;
answering support requests, handling requests to use your rights, and keeping legal, consent and audit records;
ordering search results and suggesting services you are likely to want; and
measuring and improving the service where you have allowed the technology concerned.
3.5 Search ordering, recommendations, fraud signals and moderation queues may use rules or scoring to decide what to show first or what to review. GoSavis does not make any decision that significantly affects you based solely on automated processing. Where a person on our team restricts content or an account, the applicable terms explain the notice you receive and how to challenge the decision.
3.6 We use personal data only for the purpose we collected it for, or for a purpose compatible with it. Before any new use, we consider how it relates to the original purpose, the nature of the data, how it was collected, the likely consequences for you and our contract with you; where a new use is not compatible, we ask for your consent first.
Special personal data
3.7 The Act treats personal data about a person’s religious or philosophical beliefs, political opinion, sexual life, financial information, health status or medical records as special personal data. It may be collected or processed only in the limited cases the Act allows, including where you give the information freely and with your consent.
3.8 Financial information. To take a payment, make a refund or pay a business, we process financial information: the amounts, the payment details described in clause 3.3.4, and a business’s payout status. We process it only for those purposes and only with your consent, which you give when you choose to pay by mobile money and approve the payment on your phone, or, for a business, when it gives us the mobile money number it is paid to. You can remove a mobile money number you have kept for future payments at any time in your settings. Where we rely on consent, we explain the personal data concerned, the purpose of processing and the relevant recipients before asking you to agree, and we keep a record of your agreement. Approval of a payment or selection of a feature is relied upon as consent only where that accompanying information and your affirmative action establish the agreement. We keep the record of each payment for the period in section 9.0, because tax and accounting law requires it.
3.9 Health and other sensitive information. Apart from the financial information described in clause 3.8, we do not ask users to provide the special personal data described in this clause through booking questions or general free-text fields. GoSavis refuses a business’s booking question that asks about health (including allergies and medical conditions), disability, religion or belief, ethnicity or racial origin, sex life or sexual orientation, political opinions, trade union membership, biometric or genetic data, or criminal records, and the answer box asks you not to enter health, medical or other sensitive details. If you nevertheless choose to include such information in a booking note, a message, a review or a support request, you give it freely, and we use it only to pass it to the people you address it to and to provide the service you asked for. Entering such information voluntarily does not dispense with the consent requirements that apply to it. Please share only what the business genuinely needs. Where the information concerns another person, we establish the appropriate authority or another lawful basis before processing it; otherwise we remove or restrict it as appropriate.
Children
3.10 In Uganda a child is a person under the age of eighteen. The Regulations require us to have a system to ascertain the age of the people whose personal data we collect and, where that data relates to a child, a way of obtaining the consent of a parent or guardian. Our system has two parts. First, GoSavis accounts and bookings are for people aged 18 or over: when you register, you confirm that you are 18 or over, and we record that confirmation. Second, a booking made for a child goes ahead only once the consent of a parent or guardian has been established and recorded, and where the person making the booking is not the parent or guardian we obtain that confirmation from them, as clause 3.12 describes. We do not knowingly collect personal data from a child through an account.
3.11 Public pages, listings and content can be viewed without an account, so children may see them. If you believe that a child has created an account or given us personal data, please contact privacy@gosavis.com and we will remove it, unless the law requires us to keep it.
3.12 A customer can book a service for someone else, including a child. Where a booking involves a child’s personal data and the consent of a parent or guardian is required, we establish and record that consent before we process the child’s details for the booking. The booking is held for the business to accept rather than confirmed automatically, and we record the wording shown and the age it named, because the age of majority differs between the countries we operate in. We take reasonable and proportionate steps to establish the identity of the person giving consent and their authority as a parent or legal guardian. Where the person making the booking is not the parent or legal guardian, we obtain confirmation from the parent or legal guardian through an appropriate verification process. If the required consent cannot be established, we do not proceed with the processing. We collect no more verification information than we need, the business is told before it provides the service, and we never use a child’s details for marketing.
If someone else booked a service for you
3.13 This part is for you if someone booked a service for you on GoSavis and gave us your details to do so. It explains what we hold about you, where it came from and what we do with it. You do not need a GoSavis account to use any of the rights it describes.
What we hold: your name and the phone number or email address the person who made the booking gave us. Where they told us that you are under 18, we also hold that fact. Where we emailed you about the booking, we keep a record of that email and whether it was sent.
Where it came from: from the person who made the booking, not from you.
Why we use it: so that the business can provide the service to you, since it needs to know who it is serving and how to reach you. Where the contact given is an email address, we send you one email when the booking is made, saying who booked what for you, with whom and when. Where the contact given is a phone number, we ask the person who made the booking to tell you and to share this policy with you. Where you were marked as under 18, we also use that fact to protect you, as clause 3.12 describes. We do not use your details for marketing.
Our basis: the legitimate interest, which the Regulations recognise, of the person who made the booking, of the business and of you in the service reaching the person it was booked for. This is processing you would reasonably expect when someone books a service for you. If you object, please tell us.
Who receives it: the business providing the service, and those of its staff who handle its bookings, see your name, the contact given and, where it applies, that you are under 18. GoSavis Limited and the suppliers that host GoSavis and send its email handle these details for us.
How long we keep it: with the booking record, as section 9.0 describes. If the person who made the booking closes their account, your name and contact details are removed from the booking, and from our record of any email we sent you, when their account is deleted. Where you were marked as under 18, that fact stays on the business’s record of the booking without your name or contact details.
Your rights: the rights in section 10.0, including to see these details, to have them corrected or deleted, and to object to our using them. Write to privacy@gosavis.com, naming the business and the date of the booking if you can. You can also complain to the Personal Data Protection Office (clause 10.6).
Information businesses give us about their team
3.14 A business is responsible, as data controller, for the workforce, rota, private customer-management and internal operational information it chooses to keep in its private workspace on GoSavis Business. We handle that information only on the business’s documented instructions, as its data processor, under the data processing terms that form part of the business’s agreement with us. For everything else, including platform accounts, marketplace listings, bookings, platform payments and fees, messages and reviews, security, fraud prevention, moderation, support, legal records and the administration of the service, Gosavis Ltd is the data controller. Team members and customers may contact either the business or us, and we will pass a request to the party responsible for the processing it concerns.
Cookies and similar technologies
3.15 GoSavis uses cookies and similar browser storage. Some are strictly necessary, and we use them without asking because the service cannot work securely without them:
a sign-in session cookie, which lasts for the browser session, 7 days or 90 days if you choose to be remembered, and a cookie that renews your session, which lasts for the browser session, 30 days or 90 days;
a cookie that protects signed-in forms against cross-site request forgery, which lasts for 7 days;
a device identifier used to recognise your device, to send security alerts and to remember a trusted device for two-factor authentication, which lasts for up to 1 year;
a cookie that remembers which GoSavis Business page to return you to after you move between GoSavis and GoSavis Business, which lasts for 1 day;
a cookie that records access to a restricted preview environment where that restriction is switched on, which lasts for 30 days; and
a cookie that stores your choices about external media and analytics, which lasts for 180 days, after which we ask again.
3.16 We also use your browser’s storage to remember settings you choose, such as theme, language, region and layout, to protect work in progress such as a form, a search or a checkout, and to support media uploads and the installed app. These records stay until you change the setting or clear your browser data, and are not used for advertising or to follow you across other sites.
3.17 Two categories are optional and are used only with your consent. External media: videos from YouTube, Vimeo and TikTok stay behind a placeholder until you allow them, and loading one lets that provider receive your IP address, browser information and the page containing the video. Analytics: where Google Analytics is set up, it loads only after you allow it, with advertising storage and personalisation switched off, and it may set cookies for up to 2 years to distinguish visits.
3.18 Some providers are contacted only when you ask for the feature they provide: Google or Apple when you choose to sign in with them, Cloudflare Turnstile when a protected form needs a security check, and Mapbox, OpenStreetMap tile services or Nominatim when you open a map, search for a place or ask your browser to use your location. These providers may use their own cookies or storage to complete what you asked for.
3.19 You can change your choice at any time in Cookie preferences, which uses the same category names: Strictly necessary, External media and Analytics. Withdrawing consent stops new optional content from loading, and for analytics we also remove the analytics cookies we can identify. Blocking strictly necessary storage in your browser will stop sign-in, bookings and other secure features from working.
Direct marketing
3.20 We send direct marketing, such as a newsletter or news about GoSavis, only to people who have asked to receive it, and we ask separately for that consent. Messages about your account, your bookings, your payments, security or changes to our terms and this policy are service messages, not marketing.
3.21 You can tell us at any time, in writing, to stop using your personal data for direct marketing, by writing to privacy@gosavis.com or by using the unsubscribe link where a message includes one. We will tell you in writing within 14 days that we have stopped or will stop, or give you our reasons if we will not. If we give reasons, we also send a copy of our reply to the Personal Data Protection Office within those 14 days, and you may ask the Office in writing, within 14 days of receiving our reply, to review our decision to continue; the Office reviews it within 14 days of your request.
3.22 We do not pass your personal data to another organisation for its own marketing.
Information you must give us
3.23 Some personal data is needed to provide a feature, and if you do not give it we cannot provide that feature: to create an account, your name, an email address and a password, or sign-in through Google or Apple; to make a booking, the details the booking needs, and, where you pay through GoSavis, the mobile money number you pay from; and, for a business to take bookings and be paid, its business and verification details.
3.24 Other information is your choice, such as a display photo, a biography, a phone number, declared interests, your location, reviews and posts. Leaving it out does not stop you using GoSavis, although some features may be less useful to you.
3.25 Some information is required by law or by the rules that apply to payments: we must keep records of payments for tax and accounting purposes, and the mobile money providers must identify their own customers under the rules that apply to them.
If you use the preview
3.26 The preview lets you look around a sample account without creating one of your own, so we collect no name, email address or profile information from you. It uses a session cookie to keep you in the sample while you look around, together with the device information in clause 3.3.8. The session ends when you leave the preview or close your browser, and anything you do inside it stays in the sample.
4.0 Principles
4.1 Gosavis Ltd, GoSavis Limited and everyone who handles personal data for us follow these principles, which the Act sets:
Accountability: we are accountable to you for the personal data we collect, process, hold or use.
Fair and lawful processing: we collect and process personal data fairly and lawfully, with your consent or on one of the other grounds the Act and the Regulations recognise.
Specific purpose: we collect personal data for a lawful purpose that is specific, explicitly defined and related to what GoSavis does, and use it only for that purpose or a compatible one.
Minimality: we collect, process, use and hold only personal data that is adequate, relevant and not excessive for the purpose.
Retention: we keep personal data only for the period the law authorises or for which it is needed, and then delete, destroy or de-identify it (section 9.0).
Quality: we keep personal data complete, accurate, up to date and not misleading, having regard to the purpose.
Transparency and participation: we tell you how we process your personal data and give you ways to take part, including the rights in section 10.0.
Security: we protect personal data with appropriate safeguards (section 8.0).
Privacy: we do not collect, hold or process personal data in a way that infringes your privacy.
4.2 You can help us keep your information accurate. The Act asks you to make sure that the personal data you give us is complete, accurate, up to date and not misleading. You can correct most of your details in your account settings, or ask us to correct them (clause 10.1.3).
4.3 When we design a new feature or change how GoSavis uses personal data, we apply these principles from the start. Where processing is likely to pose a high risk to people’s rights and freedoms, we carry out a data protection impact assessment before it begins (clause 8.6).
5.0 Responsible Parties
5.1 Everyone to whom this policy applies must read it, follow it and report any suspected breach of it as soon as they become aware of it. The directors of Gosavis Ltd are responsible for making sure that this policy is followed and that it is made available to the people and organisations who handle personal data for us.
Data Protection Officer
5.2 Gosavis Ltd has designated Joash Trevor Nowe as its Data Protection Officer, responsible for ensuring compliance with the Act. The Data Protection Officer can be reached at privacy@gosavis.com.
5.2.1 The Data Protection Officer’s responsibilities include:
conducting regular assessments and audits to ensure that our processing complies with the Act;
serving as the point of contact between Gosavis Ltd and the Personal Data Protection Office, including registering Gosavis Ltd with the Office, applying to renew the registration at least three months before it expires each year, notifying the Office in writing of any change in our registered particulars within 14 days, and notifying it in writing within 30 days if we cease to collect or process personal data;
maintaining records of all processing activities carried out by or for Gosavis Ltd;
responding to data subjects, and telling them how their personal data is used and what measures protect it;
ensuring that requests to see copies of personal data, to correct it or to have it deleted are fulfilled or answered within the times this policy sets;
notifying the Personal Data Protection Office of a personal data breach, and keeping a record of every breach and of the action taken;
advising on, and carrying out, data protection impact assessments where processing is likely to pose a high risk;
advising on and promoting awareness of data protection, and arranging training for anyone who handles personal data for us;
keeping the directors informed of our data protection responsibilities, risks and issues;
submitting to the Personal Data Protection Office, within 90 days after the end of each financial year, a summary of the complaints we have received and the personal data breaches we have had, with their status and the action taken; and
reviewing this policy and the procedures that support it at least once a year, and whenever the law, the platform or our suppliers change.
5.2.2 Gosavis Ltd gives the Data Protection Officer the training and the resources the role needs.
GoSavis Limited, our data processor
5.3 GoSavis Limited processes personal data for Gosavis Ltd only with our prior knowledge and authorisation and on our documented instructions. It must treat the personal data as confidential, apply the security measures in section 8.0, and not disclose it unless the law requires it or its duty to us does. It may use other processors, the suppliers named in clause 8.20, only under written terms that impose the same obligations, and it remains responsible to us for them.
5.4 GoSavis Limited must tell us immediately if it believes that personal data it processes for us has been accessed or acquired by an unauthorised person.
Everyone who handles personal data
5.5 Anyone who handles personal data for Gosavis Ltd, whether our own staff or the staff and contractors of GoSavis Limited, must:
access only the personal data they need for their work, and only through the accounts and systems they are authorised to use;
keep personal data confidential, and not disclose it to anyone inside or outside the company who is not authorised to receive it;
handle personal data in line with the principles in section 4.0 and the rest of this policy;
ask the Data Protection Officer whenever they are unsure how this policy applies; and
report any suspected personal data breach to the Data Protection Officer immediately.
Consequences of non-compliance
5.6 A breach of this policy may lead to the withdrawal of access, disciplinary action or the ending of a contract. Under the Act, unlawfully obtaining or disclosing personal data, unlawfully destroying, deleting, concealing or altering it, and selling it or offering it for sale are offences, punishable by fines and imprisonment, and a company and its responsible officers can both be convicted. Under the Regulations, collecting or processing personal data without the consent the Act requires, failing to register with the Personal Data Protection Office and failing to comply with a notice of the Office are also offences.
6.0 Processing
Consent
6.1 Except where clause 6.2 applies, we collect and process personal data about you only with your prior consent. Consent must be freely given, specific, informed and unambiguous, and given by a statement or a clear affirmative action, such as ticking a box, choosing a setting or confirming a step.
6.1.1 We ask for consent separately for each optional purpose, at the point where it matters: when you choose your cookie settings, allow your browser to share your location, ask to receive news from us, or choose to pay by mobile money (clause 3.8).
6.1.2 We keep a record of the consents and acceptances you give, including the version of our terms and of this policy you accepted, your cookie choices and when you made them.
6.1.3 You can withdraw your consent at any time, by changing your settings or by writing to privacy@gosavis.com. The Regulations prescribe a form for this, the notice of objection to the collection or processing of personal data (Form 1 in Schedule 1 to the Regulations), in which you can withdraw your consent for all the purposes you gave it for or only for the purposes you name. We will send you the form on request, and we also act on a withdrawal or objection you make through your settings or by writing to us. Withdrawing consent does not affect processing that took place before you withdrew it. It may mean that we can no longer provide the feature that depends on it, and if so we will tell you.
6.1.4 We process a child’s personal data only with the prior consent of a parent or guardian, or where the law requires or permits it (clause 3.12).
Processing without consent
6.2 The Act allows personal data to be collected and processed without consent in limited cases, and the Regulations also recognise processing in a legitimate interest. We rely on the following:
6.2.1 Performance of a contract: where processing is necessary for a contract you are party to, or to take steps you ask for before entering one. This covers creating your account and keeping it secure, including recognising your devices; showing the profile or listing you asked us to publish; running bookings; carrying messages; processing payments and payouts; diagnosing failures so that the service keeps working; enforcing our terms; and supporting you with the service, including handling your complaints about it.
6.2.2 Legal obligation: where processing is necessary to comply with a legal obligation that applies to us, such as keeping tax and accounting records, answering complaints about how we handle personal data through the complaints handling system the Regulations require, responding to a lawful request from a court or public body, and meeting the requirements that apply to payments.
6.2.3 Authorised or required by law, and the prevention of offences: where processing is authorised or required by law, or is necessary for the prevention, detection or investigation of an offence or a breach of law. We rely on it to secure the platform against attack, misuse and unauthorised access, to prevent and detect fraud, and to moderate content and investigate reports, including reports of illegal content.
6.2.4 Legitimate interest: the Regulations recognise processing that you would reasonably expect, or for which there is a compelling justification, and they do not apply the procedure for objecting to it (clause 6.3). We rely on it only to count views of a business profile (clause 3.3.9) and to deliver a booking to the person it was made for (clause 3.13). It is for us to establish the legitimate interest, and we check that it does not override your privacy.
6.2.5 Emergencies: where it is necessary to prevent or lessen a serious and imminent threat to public health or safety, or to the life or health of any person. The Act treats such a use as compatible with the purpose for which the personal data was collected.
6.3 Where you object to processing that relies on your consent, we stop it. Where we rely on clause 6.2, the law does not oblige us to stop on an objection, but we will consider it, tell you our decision and our reasons, and stop where we can. You also have the rights in section 10.0 to require us to stop processing that causes you unwarranted substantial damage or distress, or that is not compatible with the purpose for which the data was collected.
Third-party processing
6.4 We do not permit anyone to process personal data for us unless they have agreed in writing to keep it confidential and secure and to process it only on our instructions. GoSavis Limited processes personal data for us on those terms, and the suppliers it uses are listed in clause 8.20.
6.5 We make sure that each processor establishes and complies with appropriate security measures before it processes personal data for us, and we review this whenever its service or our use of it changes.
6.6 A business that receives personal data through GoSavis to provide a booked service is not our processor. It is responsible under the Act for its own use of that data.
Modes of collection
6.7 We collect personal data in three ways:
6.7.1 Direct interactions: information you give us when you register, complete your profile, list a business, book, pay, send a message, write a review, make a report, contact support or fill in a form.
6.7.2 Automated technologies: information your device and browser send when you use GoSavis, and information from cookies and similar technologies (clause 3.15).
6.7.3 Other people and services: the details a customer gives us about a person they book for, a business gives us about a team member it invites, MTN Mobile Money or Airtel Money gives us about a payment, refund or payout, and Google or Apple gives us when you choose to sign in with them.
7.0 Data Transfers
7.1 The GoSavis platform’s servers and services are outside Uganda. When you use GoSavis, your personal data is transferred to, and processed in, the following places:
Germany: the application and its database are hosted in Frankfurt, by Render and Neon;
the European Union: uploaded files and business verification documents are stored in Cloudflare’s European Union storage;
the United Kingdom: GoSavis Limited runs the platform for us from there, and our email service, Amazon Web Services, sends our service email from London;
the data centre nearest to you on Cloudflare’s global network, through which requests to GoSavis pass for delivery and security; and
for services you choose to use, such as sign-in with Google or Apple, maps, analytics and external videos, the countries where those providers operate, which include the United States.
7.2 The Act allows personal data to be processed or stored outside Uganda only where the country concerned has adequate measures in place for the protection of personal data, at least equivalent to the protection the Act provides, or where you have consented.
7.3 Germany and the other member states of the European Union, and the United Kingdom, each have a comprehensive data protection law (the European Union’s General Data Protection Regulation and, in the United Kingdom, its own version of that Regulation together with the Data Protection Act 2018) and an independent regulator that enforces it. We transfer personal data to them on the basis that their protection is at least equivalent to the Act’s. The Personal Data Protection Office has not yet published, by notice in the Gazette, the countries it considers to have adequate protection, so it is for us to prove that equivalence to the Office. We do so through the Office’s adequacy assessment before we process the personal data of users in Uganda in those countries, and we keep a record of the basis and the safeguards for each transfer, which is available to the Office on request.
7.4 We document the countries in which personal data is processed or stored and the applicable legal basis and safeguards for each transfer. We demonstrate the applicable basis to the Personal Data Protection Office as required by regulation 30 and comply with the undertaking submitted under regulation 16(3) and Form 3. Any proposed processing inconsistent with that undertaking will not commence unless the position has been lawfully resolved with the Office.
7.5 Where a service you choose to use operates in a country whose protection has not been shown to be adequate, including the United States, we transfer personal data to it only with your consent, which you give by choosing that service: by choosing to sign in with Google or Apple, by allowing Analytics or External media in your cookie settings, or by opening a map or searching for a place. You can avoid these transfers by not choosing those services. Where we rely on consent for an overseas transfer, we also explain the relevant destination or destinations, and your agreement must relate to that disclosed processing. We keep a record of it.
7.6 Where personal data processed outside Uganda is to be further transferred to, or processed in, a third country, we obtain your express consent before that further transfer or processing. This requirement also applies to access by supplier personnel or subprocessors where that access constitutes processing in a third country. We require our processors to observe these restrictions and to disclose the proposed destination and purpose before such processing begins.
7.7 We do not transfer your personal data to any country other than those described in clause 7.1. Before we transfer it to another country, we will make sure that the country has adequate measures in place for the protection of personal data, at least equivalent to the protection the Act provides, and demonstrate this to the Personal Data Protection Office, and we will obtain your express consent where clause 7.6 requires it. We will update this policy.
7.8 Wherever your personal data is processed, it is protected by the measures in section 8.0 and by the written terms our processors have agreed to. You can ask our Data Protection Officer for more information about the basis for a particular transfer.
8.0 Data Security
8.1 We secure the integrity of the personal data in our possession or control by adopting appropriate, reasonable, technical and organisational measures to prevent its loss, damage or unauthorised destruction, and unlawful access to it or unauthorised processing of it.
8.2 To do so, we identify reasonably foreseeable internal and external risks to the personal data; establish and maintain appropriate safeguards against them; regularly verify that the safeguards are effectively implemented; and update them continually in response to new risks or deficiencies. We follow generally accepted information security practices and procedures, and any that the Personal Data Protection Office publishes.
8.3 No online service can guarantee absolute security, and each supplier’s own security controls apply to the information held in its systems.
Data protection by design and default
8.4 The measures built into GoSavis include:
encryption in transit for every connection to GoSavis, with strict transport security;
passwords stored only as hashes, never in readable form;
session cookies that page scripts cannot read, protection against cross-site request forgery, and limits on the rate of requests;
two-factor and step-up authentication, with a further check that it is you before sensitive actions such as downloading your data or closing your account;
mobile money payments approved on your own phone, in your provider’s own prompt, so that your PIN never reaches GoSavis;
identity and verification documents kept in a separate, private store, never the public one;
access to personal data limited by role on every protected part of the platform, and two-factor authentication required of our own staff who administer it;
credentials and private details removed before any information is served on a public page;
an audit record of administrative actions that cannot be rewritten, from which only the personal details are removed when the account concerned is deleted; and
error reporting designed not to collect form contents, booking notes, payment data or passwords, with email addresses, access tokens and card-number-like digits removed from error text.
8.5 We use pseudonymisation and anonymisation where they serve the purpose. A view of a business profile is counted with a one-way code that cannot be traced to you once the day ends (clause 3.3.9), and when an account is deleted, the records other people still need, such as a review or a booking, are kept without the person’s identifying details.
8.6 Where processing is likely to pose a high risk to people’s rights and freedoms, we carry out a data protection impact assessment before it begins. Each assessment sets out a systematic description of the processing and its purposes, an assessment of the risks to personal data and the measures to address them, and any other matter the Personal Data Protection Office requires, and we follow any list the Office publishes of the processing operations that need one.
Data storage
8.7 We hold users’ personal data electronically, in the hosting, database and storage services described in clause 7.1, and not on paper.
8.8 Only authorised people can reach the systems and data that run GoSavis, through accounts protected by two-factor authentication, including every supplier account that holds or controls that data.
8.9 Our backups are the database provider’s own point-in-time history, kept for a maximum of 30 days, and we keep no separate copies. A backup is restored only to recover from a failure, never to bring back information that has been deleted, and where a restore is unavoidable we re-apply every deletion and anonymisation that had already taken effect before the restored copy is used again.
Data retention
8.10 We keep personal data only for as long as is necessary to achieve the purpose for which it was collected, unless the law requires or authorises us to keep it for longer, keeping it is necessary for a lawful purpose related to a function or activity for which it was collected, a contract between the parties requires it, or you consent to our keeping it.
8.11 In setting each period, we take into account why we hold the data; our obligations and rights under our contracts with you; the periods the law requires, including Uganda’s requirement that tax records are kept for five years after the end of the tax period they relate to; the time needed to resolve refunds, disputes and complaints; the prevention of fraud and the protection of users; and any request you have made to have your data deleted.
8.12 Where we use personal data to make a decision about you, such as a decision on a business’s verification or on content that has been reported, we keep that data long enough for you to be able to ask to see it.
8.13 Where the law requires us to keep a record for longer than its usual period, for example because it is needed for proceedings that have begun, we keep it for as long as the law requires, and then delete it.
8.14 Section 9.0 sets out the period for each category. At the end of each period the platform deletes, destroys or de-identifies the data automatically.
8.15 You can close your account in your settings (Settings, Account, Deactivate account). Your access stops at once and the account enters a grace period of 30 days, during which you can restore it, and we remind you 7 days before the grace period ends. When the account is then deleted, any future bookings are first cancelled and refunded, and your profile and other personal data are deleted or anonymised, unless a legal, safety or dispute hold applies.
8.16 A deletion does not erase information another person needs as part of their own record, or content that must be kept for safety or legal reasons. In those cases we remove or replace your identifying details where we can: a review you wrote stays published, shown as written by “Deleted account”, and a business keeps its record of a booking without your notes, answers or contact details. Replacing an account name with “Deleted account” does not, by itself, anonymise a record. Before treating retained reviews, bookings, support notes or other content as anonymous, we assess whether the person remains identifiable from the content or from information reasonably available with it. Where necessary, we remove identifying details or delete the content. Information that remains identifiable continues to be treated as personal data and is subject to the applicable retention and security requirements.
8.17 If the GoSavis service closes, we will tell the people whose personal data we hold, stop processing it and delete it within 90 days, except for the financial records the law requires us to keep, which we keep for the period in section 9.0 and then delete. Until it is deleted, we keep that personal data secure and treat it in line with the Act, and we notify the Personal Data Protection Office in writing within 30 days of ceasing to collect or process personal data.
Data sharing
8.18 We share personal data only where there is a clear reason to do so, as set out below. Outside these cases, we do not share it with third parties.
8.19 With other users, to provide a booking. When a customer books a service, the booking information the business needs (the customer’s display name, the service, the time and any notes or answers the customer has chosen to give) goes to the business that will provide it, and when the business confirms or changes the booking, the relevant information goes back to the customer. Profiles, listings, reviews and posts are visible according to the choices you make.
8.20 With the companies that run GoSavis for us. These are GoSavis Limited, which runs the platform for us, and the suppliers it uses, each under written terms:
GoSavis Limited (United Kingdom): runs the platform, including its hosting, support, security and administration;
Render (Frankfurt, Germany): hosts the application;
Neon (Frankfurt, Germany): hosts the application database;
Cloudflare (global network, with storage in the European Union): delivers the website and apps, provides security checks and protection against automated abuse, and stores uploaded files and verification documents;
Amazon Web Services (London, United Kingdom): sends our service email through Amazon SES; and
Microsoft Azure Key Vault: stores the platform’s own keys and passwords, and does not receive users’ personal data.
8.21 With the mobile money providers. GoSavis takes payments through MTN MoMo Pay, provided by MTN Mobile Money Uganda Limited, and Airtel Pay, provided by Airtel Mobile Commerce Uganda Limited, both licensed by the Bank of Uganda. When you pay, we send your provider the mobile money number you pay from, the amount and a reference; it asks you to approve the payment on your phone, and it tells us the outcome. We send the same kind of details to make a refund, and to pay a business to the mobile money number it gave us. Each provider processes this under its own licence and its own privacy notice. Where a business accepts cash, you can pay it in cash instead: the payment is made to the business directly, and no payment provider is involved.
8.22 With services you choose. Google or Apple, when you choose to sign in with them; Mapbox, OpenStreetMap tile services and Nominatim, which provide maps and place search and turn saved addresses into map coordinates; Google Analytics, only if you allow it; and YouTube, Vimeo or TikTok, only if you allow external media. These providers process the information under their own privacy terms.
8.23 GoSavis also runs its own crash-reporting service, which receives a limited error message, bounded technical details, the page concerned and the context needed to diagnose a failure. It is designed not to collect form contents, booking notes, payment data or passwords. If a separately hosted error-monitoring provider is ever switched on, we will update this policy before any error reports are sent to it.
8.24 For legal and safety reasons. We may disclose personal data when the law requires it, when we receive a valid request from a court or public body, or when disclosure is reasonably necessary to protect the safety of our users, our staff or the public. Where we can lawfully tell you about such a disclosure, we will.
Data archiving and destruction
8.25 We do not archive personal data beyond its retention period. When a period ends, the platform’s automated retention and deletion processes delete or destroy the data, or de-identify it, in a way that prevents it from being reconstructed in an intelligible form.
8.26 Deletion reaches every store that holds the data, including the separate private store for verification documents. Backups age out as clause 8.9 describes.
8.27 Where an audit record must keep an entry for accountability, the personal details in it are removed while the fact of the action is kept.
8.28 When GoSavis Limited, or any supplier, stops processing personal data for us, it must delete or return the personal data it holds for us, unless the law requires it to keep it.
9.0 Data Retention Schedule
9.1 We keep the categories of personal data below for the periods shown. The platform applies each period automatically unless the schedule says otherwise. Where a record is needed for a dispute, an investigation, legal proceedings or a safety concern, it may be kept until that matter is resolved (clause 8.13). For each category, this schedule specifies a fixed period or an objective event and criterion determining when retention ends. Account closure is not the sole deletion trigger where information ceases to be necessary earlier. Any extension for a dispute, investigation, legal obligation or other lawful purpose is documented, restricted to the necessary information and reviewed periodically. At the end of the justified period, the information is deleted or irreversibly anonymised.
| Category | What it covers | How long we keep it |
|---|---|---|
| Account and profile | Name, email address, phone number, password (stored only as a hash), username, photo, biography, preferences and settings | For as long as your account is open. When you close it, access stops at once and the account enters a grace period of 30 days, with a reminder 7 days before it ends, during which you can restore it. At the end of the grace period it is deleted or anonymised. |
| Registrations not completed | An account that was started and never completed | Anonymised after 90 days. |
| Email verification and password reset records | Codes and links sent to confirm your email address or to reset your password | 7 days. |
| Sign-in and security records | Sign-in and sign-out events, with the IP address, device information and email address used | 90 days. |
| Usernames given up | A username you change, or leave behind when your account is deleted | Held for 90 days so that nobody else can take it, then released. |
| Business listings | Services, prices, opening hours, offers, branches and the public profile of a business | For as long as the listing is live. When a business account is deleted, the business’s identifying details are anonymised. |
| Bookings | The service, time, place, price, status, notes, answers to booking questions, and the details of a person booked for | Six years from the end of the accounting year in which the booking falls, then deleted or irreversibly anonymised. That is the same period as the payment it belongs to, because the booking is the record of what the payment was for. When a customer’s account is deleted before then, their notes and answers, their own address, their contact details and the names and contact details of anyone they booked for are removed from the booking at once, and what remains is the business’s record of the service. A booking is kept for longer only while a dispute, refund, payout, investigation or safety concern on it is unresolved. |
| Payments, refunds, payouts, tips and fees | Amounts, status, how it was paid (mobile money or cash), the mobile money number and the name registered to it, the mobile money provider’s references and payout status | Six years from the end of the accounting year in which the transaction falls, then deleted. This is longer than the five years after the end of the tax period that Ugandan tax law requires. A record is kept for longer while a dispute, refund, payout or other matter on it is unresolved. |
| Saved mobile money numbers | The mobile money number and network you choose to keep for your next payment | Until you remove it or your account is deleted. |
| Abandoned payment attempts | A checkout that was started and not completed | 90 days after the attempt expires. An attempt on which money may have moved is kept until that is resolved. |
| Messages | Messages you send and receive | For as long as your account is open. When your account is deleted, the messages you sent are deleted; the other person keeps the messages they sent. |
| Reviews | Rating, title, comment and tags | For as long as the review is published. When your account is deleted, the review stays, anonymised and shown as written by “Deleted account”. |
| Posts, comments, requests for work and bids | Content you publish, with its likes, comments and media | For as long as your account is open; deleted with your account. |
| Reports and moderation | Reports you make, and decisions on reported content or accounts with the evidence they were based on | A moderation decision and its record: 3 years from the decision. Removed media, and the text of a reported private message held as evidence: 1 year. Evidence kept after a reported account is deleted: 1 year. The words you wrote with a report are deleted when your account is deleted. |
| Business verification documents | Identity documents, proof of address, licences, insurance and other evidence uploaded for verification | 180 days after the decision on the application or, for a document with its own expiry date, 180 days after the later of that decision and that date. The record of the decision itself, which is what we rely on to let a business trade, is kept while the business is on GoSavis and for six years after it leaves, and is then deleted. |
| Business compliance details | Registration and tax identifiers, legal form and the declarations made at verification | For as long as the business’s account is open; deleted with the account. |
| Support requests | Your enquiry, name, email address, phone number and the technical details sent with it | For as long as your account is open. When it is deleted, your name, contact details and technical details are removed from the case and your own messages in it are deleted. Our team’s notes on the case are kept for two years after the case is closed and then deleted, or for six years from the end of the accounting year where the case concerns a payment, a refund or a payout, so that it can be reconciled with the record of the money. |
| Consent and legal records | The versions of our terms and of this policy you accepted, your cookie choices, your age confirmation and the notices sent about a booking | Six years from the end of the relationship the consent or agreement relates to, which is the withdrawal of the consent, the closing of your account or the expiry of the obligation, whichever happens first, and then deleted. We keep them for that period because they are the evidence of what was agreed and may have to be proved. The IP address, device information and addresses in them are removed when your account is deleted, and what remains is the record that the agreement was given, when, and in which wording. |
| Audit records | Records of administrative actions taken on the platform | Kept for accountability. The log is append-only: an entry cannot be altered or deleted except in the two ways described here. The personal details in an entry are removed when the account concerned is deleted. Reconciliation records of a payment that could not be matched are deleted six years after the entry was written; the database itself enforces that period, so it cannot be shortened by a change to our software. |
| Error reports | A limited error message, technical details and the page where the error happened | 90 days from the last time the error occurred. |
| Profile view codes | The one-way daily code described in clause 3.3.9 | 8 days. The key used to make each day’s codes is deleted when that day ends. |
| Pre-launch sign-ups | Name, email address, phone number, town and the details given on a sign-up form | Deleted once we have contacted you or you have opened an account, and no sooner than 30 days after you signed up. A sign-up we never contact is deleted after 365 days. |
| Cookies and browser storage | The cookies and stored settings described in clause 3.15 | As clause 3.15 sets out for each. Preferences stay on your device until you change them or clear your browser data. |
| Backups | The database provider’s point-in-time history of the database | Held only as the database provider’s own point-in-time history, for a maximum of 30 days, and aged out through it; we keep no separate copies. A backup is restored only to recover from a failure, never to bring back information that has been deleted. Where a restore is unavoidable, we re-apply every deletion and anonymisation that had already taken effect before the restored copy is used again, so information you asked us to delete does not return to ordinary use. A deletion therefore takes effect at once in the live service and is complete across every copy we hold within 30 days. |
9.2 Where the law of Uganda requires a longer period for any record, we keep it for that longer period.
10.0 The Data Subject
10.1 Under the Act and the Regulations you have the following rights. Some have limits set by the law, for example where we must keep a record or where another person’s rights are affected; if a limit applies, we will explain it.
10.1.1 The right to be informed: to be told, before we collect your personal data, the information this policy sets out.
10.1.2 The right of access: to ask us to confirm whether we hold personal data about you, to describe it, to tell you which third parties, or which categories of third party, have had access to it, and to give you a copy. Section 11.0 explains how.
10.1.3 The right to have your personal data corrected or deleted: to ask us in writing to correct or delete personal data about you that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, and to destroy or delete personal data we no longer have the authority to keep. We will tell you our decision in writing within 7 days of receiving your request. If we make the change, we will tell you what we have done, and we will tell each person to whom we disclosed the data of the correction and the action taken, in a way that suits the correction, the nature of the data and the number of people concerned. If we cannot comply, we will tell you so in writing, with our reasons and any action we have taken as a result of your request.
10.1.4 The right to object and to withdraw consent: to object to the collection or processing of your personal data, and to withdraw a consent you have given, at any time (clauses 6.1.3 and 6.3).
10.1.5 The right to prevent processing: by notice in writing, to require us to stop processing personal data that causes, or is likely to cause, unwarranted substantial damage or distress to you, or processing that is not compatible with the purpose for which the data was collected. We will tell you in writing within 14 days that we have complied or intend to comply, or give you our reasons for not doing so. If we give reasons, we send a copy of our reply to the Personal Data Protection Office within 7 days, and if the Office does not agree with our reasons, it can direct us to comply within 7 days.
10.1.6 The right to stop direct marketing: by notice in writing, to require us to stop processing your personal data for direct marketing. We will reply in writing within 14 days (clause 3.21).
10.1.7 Rights about automated decisions: by notice in writing, to require us to make sure that no decision which significantly affects you is based solely on automated processing. We will tell you in writing within 14 days that we have complied or intend to comply, or give you our reasons for not doing so, and if we give reasons, we send a copy of our reply to the Personal Data Protection Office within 14 days. GoSavis does not currently make such decisions. If it ever does, we will tell you as soon as reasonably practicable that a decision was taken that way; you may then, within 21 days of our telling you, ask us in writing to reconsider it, and we will tell you in writing, within 14 days of your notice, what we have done. If you are not satisfied with our reply, you may complain in writing to the Office within 14 days, and the Office can direct us to comply.
10.1.8 The right to have inaccurate personal data rectified, blocked, erased or destroyed: if you believe we hold inaccurate personal data about you, you may ask us in writing to rectify, block, erase or destroy it. If we do not do so within 30 days of receiving your request, you may complain to the Personal Data Protection Office, using the form the Regulations prescribe for a complaint about inaccurate personal data (Form 9 in Schedule 1 to the Regulations). The Office decides such a complaint within 7 days and can order us to rectify, update, block, erase or destroy the data; if it does, we tell the third parties to whom we disclosed the data, in the way and within the time the Office specifies.
10.1.9 The right to complain and to compensation: to complain to the Personal Data Protection Office (clause 10.6), and to apply to a court for compensation if you suffer damage or distress because we have not complied with the Act.
10.2 A right under this policy may be used by you, by a parent or guardian on behalf of a child, by a person with legal authority to act for someone who cannot act for themselves, or by a person you have authorised in writing. We may ask for evidence of that authority.
10.3 We do not charge a fee for any request to use your rights.
10.4 Your account settings let you correct most of your details, change what is visible, download a copy of your data and close your account. For anything else, write to privacy@gosavis.com.
Complaints
10.5 If you are unhappy with how we have handled your personal data, please tell our Data Protection Officer first, at privacy@gosavis.com or at our address. We will acknowledge your complaint, investigate it and reply in writing within 30 days, and we keep a record of every complaint and its outcome.
10.6 You can complain to the Personal Data Protection Office at any time. The Office investigates a complaint within 21 days of receiving it, decides it within 30 days and can direct us to put things right. Its contact details are:
Personal Data Protection Office
7th Floor, Padre Pio House, Plot 32 Lumumba Avenue
P.O. Box 33151, Kampala, Uganda
Email: info@pdpo.go.ug
Telephone: 0417 801008
Website: pdpo.go.ug, which also takes complaints online
10.7 A complaint that we are infringing your rights or the Act is made in writing on the form the Regulations prescribe (Form 11 in Schedule 1 to the Regulations) and addressed to the National Personal Data Protection Director. The Regulations prescribe Form 6 for a complaint that a data processor is processing personal data without appropriate security measures, and Form 9 for a complaint that we have not rectified inaccurate personal data (clause 10.1.8). We will send you any of these forms on request.
10.8 A person aggrieved by a decision of the Office may appeal to the Minister responsible for information and communications technology within 30 days of the date of the notice of the decision. The appeal is made on the form the Regulations prescribe (Form 13 in Schedule 1 to the Regulations), addressed to the Permanent Secretary of that Ministry for the attention of the Minister, with a copy to the Office, and the Minister decides it within 30 days of receiving it.
11.0 Data Access Request and Procedure
11.1 We have procedures to receive and answer requests, complaints and enquiries about how we handle personal data. This section explains how to ask for access to your personal data.
Downloading your own data
11.2 If you have a GoSavis account, the quickest way to get a copy of your personal data is to download it yourself: sign in, open Settings, choose Account, and under Your data select Download my data. You will be asked to confirm that it is you first. You do not need to fill in a form to do this.
Making a formal request
11.3 You can also make a formal request in writing, using the form in Appendix A, which follows the form the Regulations prescribe for a request to confirm possession of personal data (Form 8 in Schedule 1 to the Regulations). Send it to privacy@gosavis.com, or post it to Gosavis Ltd at our address, for the attention of the Data Protection Officer.
11.4 With your request, please give a copy of one of the following as proof of identity: a national identification card or an aliens identification card; a passport or other travel document; or a driving licence. We use it only to confirm who you are, and we do not keep the copy for longer than your request needs.
11.5 We may also ask for information we reasonably need to identify you and to find the personal data you are asking about, such as the email address or username on your account.
11.6 We will tell you our decision within 7 days of receiving your request, and we will give you the information promptly and in any event within 30 days. If we refuse all or part of a request, we will tell you why.
11.7 We provide the information in the form you ask for, electronically or on paper, free of charge.
11.8 If we cannot answer your request without revealing personal data about another person, we will not disclose that person’s data unless they consent, it is reasonable in all the circumstances to disclose it without their consent, or a court orders it. We will still give you as much of the information as we can, leaving out the other person’s name or other identifying details.
11.9 If your request concerns personal data that a business controls in its private workspace (clause 3.14), we will tell you and pass the request to the business, unless the law requires us to answer it.
11.10 Requests to correct, delete, block or object to processing, or to stop it, can be made in the same way, in writing to privacy@gosavis.com. The times for our replies are set out in section 10.0.
12.0 Data Breach
12.1 A personal data breach includes any event in which personal data we hold is accessed or acquired by an unauthorised person, or is lost, destroyed, altered or disclosed without authority, for example:
unauthorised access to an account, a system or a store of personal data;
personal data sent or shown to the wrong person;
personal data published or disclosed without authority;
the loss, theft, deletion or corruption of personal data; and
personal data becoming unavailable because of a failure or an attack.
12.2 Anyone who handles personal data for us, including GoSavis Limited and its suppliers, must report a suspected breach to the Data Protection Officer immediately.
12.3 When we believe that personal data has been accessed or acquired by an unauthorised person, we notify the Personal Data Protection Office immediately, on the notification of data breach form the Regulations prescribe (Form 7 in Schedule 1 to the Regulations). Our notification sets out the nature of the breach, the personal data concerned, the categories and approximate number of people affected, the likely consequences, the remedial measures taken or proposed, and the name and contact details of our Data Protection Officer.
12.4 Where the Office decides that the people affected should be told, we tell them by the means the Office directs, which may be an email to their last known email address, a notice in a prominent position on GoSavis, registered mail or publication in the media. Our notice gives them enough information to take steps to protect themselves. We follow the guidance the Office gives us on the remedial measures to take, on how to tell the people affected and on any measures to alert the public.
12.5 We follow our breach procedure to contain the breach, assess its risks, recover the data where possible and fix the cause. We keep a record of every breach, its effects and the action taken, and we report a summary of our breaches to the Office each year (clause 5.2.1).
12.6 We rehearse our breach procedure before GoSavis opens to users in Uganda and at least once a year after that, and we review it after every breach and every rehearsal.
13.0 Changes to this Policy and Contact Details
13.1 We review this policy at least once a year and whenever the platform, our suppliers or the law change. If we make a material change to how we use your personal data, we will tell account holders through the channels they have chosen for service updates before the change takes effect, and where the change needs your consent, we will ask for it.
13.2 This is version 1.2 of this policy, dated 10 October 2026.
13.3 You can contact us as follows:
Data Protection Officer: Joash Trevor Nowe, privacy@gosavis.com
General support: support@gosavis.com
Telephone: 0773 628619
Post: Gosavis Ltd, KIIRA ROAD, 202654 Nakawa, Kiwana Road, Bukoto, Church Street Mall
The Personal Data Protection Office: clause 10.6
Appendix A: Request to Confirm Possession of Personal Data
Use this form to ask Gosavis Ltd to confirm whether it holds personal data about you and to give you
a copy of it. It is the form the law prescribes for such a request, Form 8 in Schedule 1 to the Data
Protection and Privacy Regulations, 2021, with a few questions added to help us find what you ask
for.
If you have a GoSavis account, you can download a copy of your data yourself at any time, without
this form: sign in, open Settings, choose Account, and under Your data select Download my data.
Please send the completed form, with a copy of your proof of identity, to privacy@gosavis.com, or
post it to the Data Protection Officer, Gosavis Ltd, KIIRA ROAD, 202654 Nakawa, Kiwana Road,
Bukoto, Church Street Mall.
We use the information on this form only to identify you, to find the personal data you ask about and to
respond to your request. We will tell you our decision within 7 days of receiving it and give you the information
within 30 days, free of charge.
1. Details of the data subject
Full name of the data subject
National Identification Number, passport
number, driving licence number or aliens
identification card number
Email address
Telephone number(s)
Postal address (needed if you want a
paper copy)
GoSavis username or account email, if
you have an account
2. Data controller from whom the information is requested
Name of the data controller Gosavis Ltd, provider of GoSavis in Uganda
3. I am making this request (tick one)
□ as the data subject
□ on behalf of the data subject (please also complete part 4)
4. Person acting on behalf of the data subject (complete only if this applies)
Full name
Relationship to the data subject, or
authority to act (for example parent or
guardian, or authorised in writing)
Email address
Telephone number
Evidence of authority enclosed
5. Description of the personal data requested (tick all that apply)
□ all the personal data you hold about me
□ account and profile details
□ bookings
□ payments, refunds and payouts
□ messages
□ reviews, posts and other content
□ business verification records
□ support requests
□ sign-in and security records
□ other (please describe below)
I would also like to know (tick all that apply):
□ the purposes for which my personal data is processed
□ the third parties, or categories of third party, to whom it has been disclosed
□ where it came from
□ the period for which it has been, and will be, held
Details of the information sought:
6. Relevant period of the information
From .................................................................... To ....................................................................
7 . Preferred form of access (tick one)
□ soft copy (an electronic file sent by email)
□ hard copy (a paper copy sent by post)
8. Proof of identity enclosed (tick one)
□ National Identification Card
□ Aliens Identification Card
□ Passport or other travel document
□ Driving licence
9. Declaration
I confirm that the information on this form is correct, and that I am the data subject or am authorised
to act on the data subject’s behalf.
Name .....................................................................................................
Signature .............................................................................................. Date .........................................................
Signature of the data subject, or of the person authorised to act on the data subject’s behalf.
For office use
Date received
Decision sent (within 7 days of receipt)
Information provided (within 30 days of
receipt)
Handled by