Document Ref: RANS/DP-001/2026

Data Protection & Privacy Policy

Our commitment to protecting the privacy and security of your personal data.

1. Introduction

1.1 Policy Statement

RANS understands that protecting the privacy and security of Personal Data is crucial in maintaining customer trust, complying with data protection laws and regulations, and safeguarding sensitive information from unauthorised access or misuse.

In Uganda, every person has a constitutionally-guaranteed and statute-backed right to have their private affairs remain confidential and their communications safeguarded. Our commitment to data protection goes beyond mere legal compliance. We strive to cultivate a culture of trust, transparency, and accountability.

  • Lawful, fair, and transparent processing of Personal Data
  • Collection limited to specified and legitimate purposes
  • Data minimisation — collecting only what is necessary
  • Maintaining data accuracy and relevancy
  • Setting limits on data retention
  • Safeguarding data integrity and confidentiality
  • Accountability for all data processing activities

1.2 Scope

Who / WhatDetails
Data formatsAll Personal Data in electronic, paper, or verbal form
Geographic reachAll Company operations within and outside Uganda relating to Data Subjects located in Uganda
EmployeesPermanent, fixed-term, temporary/casual employees, interns, and directors
Third PartiesAgents, representatives, operators, service providers, contractors, and associated third parties handling Personal Data on behalf of the Company

1.3 Definitions

CompanyRANS
Data SubjectAn identified or identifiable natural person who is the subject of Personal Data
Personal DataAny information relating to an identified or identifiable natural person — identifiable by name, ID number, location data, online identifier, etc.
ProcessingAny activity or set of operations on Personal Data (collection, recording, organisation, storage, use, disclosure, etc.)
Sensitive Personal DataData revealing race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details, sex, or sexual orientation.

2. Data Processing

2.1 Personal Data Protection Principles

Lawfulness & Transparency

Processed lawfully, fairly, and transparently. Data Subjects informed about collection and use.

Purpose Limitation

Collected for explicit, specified, and legitimate purposes. No incompatible processing.

Data Minimisation

Adequate, relevant, and limited to what is necessary for the stated purposes.

Storage Limitation

Kept no longer than necessary for its collected purpose, per retention guidelines.

2.2 Lawful Processing

The Company must always have a legal basis and purpose. Processing is lawful without consent where necessary for:

  • Performance of a contract
  • Legal compliance obligations
  • Protecting vital interests
  • Public duty or legitimate interest not overridden by fundamental rights

Where none apply, explicit informed Consent is required.

2.3 Processing of Sensitive Personal Data

⚠️ Warning: Processing sensitive Personal Data without lawful basis may result in disciplinary action, criminal offence, civil liability, or administrative penalties.

May only be processed where data is manifestly made public, or necessary for legal claims, carrying out specific rights, or protecting vital interests where consent cannot be given.

2.4 Collection of Personal Data

We may collect data indirectly where contained in public records, deliberately made public, or collection won't prejudice the Data Subject's interests. When collecting directly, we inform subjects of their rights, purposes, third-party transfers, and security measures.

3. Rights & Sharing

3.1 Data Subject Rights and Requests

Right to Be Informed

Clear, concise information about data purposes.

Right to Withdraw Consent

Consent may be withdrawn at any time.

Right to Object/Restrict

If accuracy is contested or no longer required.

Right to Data Access

Access to processing purposes, categories, and recipients.

Right to Erasure

If data is no longer necessary or consent is withdrawn.

Right to Object to Automated Processing

Not to be subject to decisions based solely on automated processing.

3.2 Sharing Personal Data

The Company may share Personal Data with third-party service providers whose services are necessary for the Company's obligations. Sharing is only permitted where:

  • There is a legitimate Company need
  • The sharing has been communicated to the Data Subject
  • The recipient has agreed to confidentiality under a written agreement

3.3 Reporting Personal Data Breaches

In line with Applicable Laws, the Company will notify the ODPC within 72 hours of becoming aware of any notifiable Personal Data Breach, and notify the Data Subject where required by law.

4. Retention & Security

4.1 Retention of Personal Data

Data CategoryRetention Period
Customer & SupplierDuration of business relationship + period required by obligations
Employee DataDuration of employment + reasonable period for legal obligations
Website UsagePeriod necessary to analyse traffic and ensure security
Financial DataMinimum 7 years from the end of the relevant financial year

4.2 Security, Integrity and Confidentiality

The Company has implemented appropriate technical and organisational measures to uphold data protection principles:

  • Confidentiality: Only authorised personnel with a need to know may access Personal Data.
  • Integrity: Personal Data must be accurate and suitable for its processing purpose.
  • Availability: Authorised users can access Personal Data when needed for authorised purposes.

4.3 Data Collected and Purpose

General: Name, address, contact details for communication, order fulfilment, and invoicing.

Real Estate: Land use info, property characteristics, location, market indicators for property valuation, risk assessment, and regulatory compliance.

Financial & Marketing: Bank details, preferences, purchase history for processing payments, tailoring promotions, and market research.

5. Administration & Complaints

5.1 Responsibilities

All Employees who process Personal Data must read, understand, and comply with this policy. The Data Protection Officer (DPO) is responsible for registration, regulatory liaison, compliance advisory, impact assessments, risk management, and advising on engagements with data processors.

5.2 Complaints Handling

Data Subjects may submit complaints regarding the use of their Personal Data via email. Acknowledgement is provided within 7 working days, and investigations are completed within 30 working days. If aggrieved after review, complainants may lodge a complaint with the ODPC.

5.3 Communication & Contact

Discovered or suspected Personal Data Breaches, as well as general privacy inquiries, must be immediately reported to our designated office:

Policy Review

This policy is a living document and shall be reviewed annually, or earlier where necessary, to accommodate changes in legislation, regulatory requirements, industry standards, or operational practices.