Effective March 2024
Umurimo Finance Plc is committed to safeguarding personal data across every channel we operate. This statement
summarises our approach in line with applicable laws in Rwanda. For a plain-language summary of how we handle
your information online and in-branch, see also our Privacy Policy.
1. Introduction
Umurimo Finance Plc is committed to ensuring the protection of personal data in accordance with applicable data
protection laws and regulations in Rwanda. This policy outlines how personal data is collected, processed,
stored, and protected.
2. Scope
This policy applies to:
- All employees, customers, suppliers, and partners
- All branches and operational units
- All personal data processed in both digital and physical formats
3. Data Protection Principles
Umurimo Finance Plc adheres to the following principles:
Core principles
3.1
Lawfulness, fairness & transparency
Personal data is processed lawfully and transparently, with clear communication to data subjects.
3.2
Purpose limitation
Data is collected for specified, legitimate purposes and not used beyond those purposes without consent.
3.3
Data minimization
Only data necessary for the intended purpose is collected and processed.
3.4
Accuracy
Personal data is kept accurate and up to date.
3.5
Storage limitation
Data is retained only for as long as necessary and securely deleted thereafter.
3.6
Integrity & confidentiality
Appropriate security measures protect personal data from unauthorised access or breaches.
4. Legal Basis for Processing
Personal data is processed under one or more of the following conditions:
- Consent of the data subject
- Performance of a contract
- Compliance with legal obligations
- Protection of vital interests
- Legitimate business interests
5. Data Subject Consent
Consent is obtained prior to processing personal data. For minors, parental or guardian consent is required.
6. Data Subject Rights
Individuals have the right to:
- Access their personal data
- Request correction or deletion
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
7. Data Sharing
Personal data may be shared with authorised third parties only when necessary and under strict contractual and
security obligations.
8. Data Security Measures
We implement appropriate technical and organisational measures including:
- Encryption and secure communication protocols
- Access control mechanisms
- Regular security audits and monitoring
9. Data Breach Management
In the event of a data breach, Umurimo Finance Plc will notify the relevant authority within 48 hours and affected
individuals where required.
10. Responsibilities
- Board of Directors: Oversight and governance
- Management: Implementation of policies
- Data Protection Officer: Compliance monitoring
- Employees: Responsible handling of data
11. Contact