Our commitment to protecting the privacy and security of your personal data.
RANS understands that protecting the privacy and security of Personal Data is crucial in maintaining customer trust, complying with data protection laws and regulations, and safeguarding sensitive information from unauthorised access or misuse.
In Uganda, every person has a constitutionally-guaranteed and statute-backed right to have their private affairs remain confidential and their communications safeguarded. Our commitment to data protection goes beyond mere legal compliance. We strive to cultivate a culture of trust, transparency, and accountability.
| Who / What | Details |
|---|---|
| Data formats | All Personal Data in electronic, paper, or verbal form |
| Geographic reach | All Company operations within and outside Uganda relating to Data Subjects located in Uganda |
| Employees | Permanent, fixed-term, temporary/casual employees, interns, and directors |
| Third Parties | Agents, representatives, operators, service providers, contractors, and associated third parties handling Personal Data on behalf of the Company |
| Company | RANS |
| Data Subject | An identified or identifiable natural person who is the subject of Personal Data |
| Personal Data | Any information relating to an identified or identifiable natural person — identifiable by name, ID number, location data, online identifier, etc. |
| Processing | Any activity or set of operations on Personal Data (collection, recording, organisation, storage, use, disclosure, etc.) |
| Sensitive Personal Data | Data revealing race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details, sex, or sexual orientation. |
Processed lawfully, fairly, and transparently. Data Subjects informed about collection and use.
Collected for explicit, specified, and legitimate purposes. No incompatible processing.
Adequate, relevant, and limited to what is necessary for the stated purposes.
Kept no longer than necessary for its collected purpose, per retention guidelines.
The Company must always have a legal basis and purpose. Processing is lawful without consent where necessary for:
Where none apply, explicit informed Consent is required.
May only be processed where data is manifestly made public, or necessary for legal claims, carrying out specific rights, or protecting vital interests where consent cannot be given.
We may collect data indirectly where contained in public records, deliberately made public, or collection won't prejudice the Data Subject's interests. When collecting directly, we inform subjects of their rights, purposes, third-party transfers, and security measures.
Clear, concise information about data purposes.
Consent may be withdrawn at any time.
If accuracy is contested or no longer required.
Access to processing purposes, categories, and recipients.
If data is no longer necessary or consent is withdrawn.
Not to be subject to decisions based solely on automated processing.
The Company may share Personal Data with third-party service providers whose services are necessary for the Company's obligations. Sharing is only permitted where:
In line with Applicable Laws, the Company will notify the ODPC within 72 hours of becoming aware of any notifiable Personal Data Breach, and notify the Data Subject where required by law.
| Data Category | Retention Period |
|---|---|
| Customer & Supplier | Duration of business relationship + period required by obligations |
| Employee Data | Duration of employment + reasonable period for legal obligations |
| Website Usage | Period necessary to analyse traffic and ensure security |
| Financial Data | Minimum 7 years from the end of the relevant financial year |
The Company has implemented appropriate technical and organisational measures to uphold data protection principles:
General: Name, address, contact details for communication, order fulfilment, and invoicing.
Real Estate: Land use info, property characteristics, location, market indicators for property valuation, risk assessment, and regulatory compliance.
Financial & Marketing: Bank details, preferences, purchase history for processing payments, tailoring promotions, and market research.
All Employees who process Personal Data must read, understand, and comply with this policy. The Data Protection Officer (DPO) is responsible for registration, regulatory liaison, compliance advisory, impact assessments, risk management, and advising on engagements with data processors.
Data Subjects may submit complaints regarding the use of their Personal Data via email. Acknowledgement is provided within 7 working days, and investigations are completed within 30 working days. If aggrieved after review, complainants may lodge a complaint with the ODPC.
Discovered or suspected Personal Data Breaches, as well as general privacy inquiries, must be immediately reported to our designated office:
This policy is a living document and shall be reviewed annually, or earlier where necessary, to accommodate changes in legislation, regulatory requirements, industry standards, or operational practices.