Privacy Policy

Last Updated: July 11, 2026 • Version 1.0.2 • Applicable in the Republic of Botswana

1. Scope, Controller, and Consent

Dithebe Technologies (Pty) Ltd ("Dithebe", "Company", "we", "us", "our"), incorporated in Gaborone, Botswana, respects your privacy and is committed to protecting your personal information.

This Privacy Policy describes how we collect, use, store, process, disclose, and protect your personal and financial information when you install, register, and use the Dithebe digital wallet mobile application, website, and related transfer services (collectively, the "Services").

By clicking "Accept" or registering an account on the Platform, you provide your explicit and informed consent to the collection, processing, and transfer of your personal data as outlined in this policy. If you do not consent, you must immediately uninstall the application and discontinue using our Services.

2. Personal Data We Collect

To provide a functional mobile wallet and ensure compliance with identity verification standards, we collect several categories of information:

A. Information You Provide to Us

  • Onboarding & Profile Data: Mobile telephone number, full legal names, physical address, email address, and demographic details.
  • KYC Documents: High-resolution optical scans or photographs of your National Identity Card (Omang) for citizens, or passports for foreign residents, including card data (Omang number, date of birth, expiry date, gender).
  • Biometric Data: Camera selfie photograph uploaded during identity verification to perform facial comparison checks against the Omang card image.

B. Automatically Collected Technical Data

  • Device Fingerprint & Serial: Handset make, model, operating system version, IP address, cellular carrier network provider, and hardware serial numbers (IMEI or unique hardware identifiers used to execute our Anti-Clone device binding lock).
  • Log and Usage Data: Session start and end times, app interaction statistics, crashes, button clicks, and general application diagnostic statistics.

C. Transactional Data

  • Transfer Ledger: Sender and recipient mobile numbers, transaction values (Pula transfers), timestamps, transaction description text, and wallet ledger balance states.

3. Legal Ground and Processing Purposes

We process your personal information strictly based on established legal grounds:

  1. Performance of a Contract: To execute peer-to-peer transfers, hold balance custody, resolve transaction issues, and manage your account.
  2. Compliance with Legal Obligations: Under the Financial Intelligence Act, 2019, we are legally required to verify customer identity, detect patterns of money laundering or terrorist financing, and log all transactional interactions.
  3. Legitimate Interests: To protect the integrity and security of our Platform, prevent software piracy, detect fraudulent account access attempts, and protect Company intellectual property.

4. Data Retention and Storage Rules

Dithebe stores personal data on secure servers in certified cloud repositories. Cross-border transfers of data, if required for backup or processing systems, are conducted in compliance with Section 48 of the Data Protection Act, 2018, ensuring appropriate safeguards exist.

We retain your information as follows:

  • Registration & Profile Data: Retained for the entire duration that your Dithebe account remains active, and for a period of five (5) years following the closure of your account.
  • Transaction Ledgers & KYC Verification Records: Retained for a mandatory minimum period of five (5) years from the date of the transaction or account closure, as strictly mandated under Section 13 of the Financial Intelligence Act, 2019.
  • System Diagnostic Logs: Retained for up to twelve (12) months before automated deletion, unless required for ongoing security audits.

Upon the expiry of the mandatory retention periods, personal data is permanently deleted, anonymized, or destroyed using secure digital wiping mechanisms.

5. Security Standards and Protections

We implement industry-grade technical and organizational security measures to prevent unauthorized access, alteration, disclosure, loss, or destruction of your personal data.

  • Encryption: All personal data and identity documents are encrypted at rest using AES-256 standards, and all network transmissions between the App and backend API servers are protected using Transport Layer Security (TLS 1.3).
  • Handset Hardware Lock: Accounts are locked to your specific physical device serial number. If a third party gains access to your PIN, they cannot log into your wallet from another phone.
  • Strict Internal Controls: Access to user KYC database records is strictly restricted to designated compliance personnel who have passed rigorous security screenings.

No method of transmission over the internet, or method of electronic storage, is 100% secure. While we strive to use state-of-the-art protections to secure your data, we cannot guarantee absolute security.

6. Third-Party Data Sharing & Disclosure

Dithebe will never sell, rent, or trade your personal data with marketing third parties. We share data only in the following limited situations:

  • Regulatory Authorities: We disclose customer details and transaction histories to the Financial Intelligence Agency (FIA), Bank of Botswana, and law enforcement agencies when legally required by subpoena, court order, or AML directives.
  • Verification Partners: To run automated KYC checks, we share details (such as your Omang ID number) with authorized government registration databases or private compliance APIs to verify document validity.
  • Custodian Banking Intermediaries: We share necessary transactional info with partnering commercial banks who hold the trust custody of pre-funded wallet assets to settle transfers.

7. Your Data Subject Rights

Under Part IV of the Data Protection Act, 2018, users in Botswana possess specific rights regarding their personal data:

  • Right of Access: You have the right to request a copy of all personal information Dithebe holds about you.
  • Right to Rectification: You may request the correction of any inaccurate or outdated personal details.
  • Right to Erasure ("Right to be Forgotten"): You may request the deletion of your account and personal data, subject to the legal retention rules under the Financial Intelligence Act, 2019 (mandating retention for 5 years).
  • Right to Object: You have the right to object to processing based on legitimate interests.

To exercise any of these rights, please contact our Data Protection Officer at privacy@dithebe.co.bw. We will respond to your request within thirty (30) days.

8. Intellectual Property & Liability Limitation on Data Breaches

Intellectual Property: All database structures, security protocols, Anti-Clone schemas, customized OCR algorithms, metadata models, and UI data representations generated on the Platform remain the sole intellectual property of the Company.

Limitation of Liability: Dithebe is not liable for data breaches, leaks, or financial losses caused by events outside our direct operational control, including:

  • User negligence, such as sharing transaction PINs or failing to implement device passcodes.
  • Compromises of your cellular mobile provider network (SIM swapping or SMS interception).
  • Malware, spyware, or screen recorders installed on your phone by other applications.

Our total liability for data privacy breaches shall be limited to the maximum extent permissible under Botswana law, capped at the amount you paid to use the Services or P100.00 (One Hundred Pula).

9. Cookies & Web Tracking

Dithebe's marketing landing page and web dashboard use basic, secure cookies and browser local storage mechanisms to:

  • Maintain user theme configurations (light and dark mode preferences).
  • Protect session states and authenticate web access to dashboards.
  • Gather anonymous, aggregated traffic statistics to analyze page loading speeds and Core Web Vitals performance.

You can configure your web browser to reject cookies; however, doing so may cause certain segments of our website or dashboard to function incorrectly.

10. Policy Updates and Contact Information

Dithebe reserves the right to modify or update this Privacy Policy at any time. If changes are material, we will provide notice through the App or by emailing registered users at least fourteen (14) days prior to the updates taking effect. Your continued use of the Services after the notice period constitutes your acceptance of the updated policy.

For any inquiries, requests to exercise your rights, or complaints regarding how we handle your personal data, please contact us:

Data Protection & Compliance Officer
Dithebe Technologies (Pty) Ltd
Plot 54352, Gaborone West, Gaborone, Botswana
Email: privacy@dithebe.co.bw

If you feel we have not addressed your concerns adequately, you have the right to lodge a complaint with the Data Protection Information Commissioner under the Ministry of Communications, Knowledge and Technology of the Republic of Botswana.