1. Scope, Controller, and Consent
Dithebe Technologies (Pty) Ltd ("Dithebe", "Company", "we", "us", "our"), incorporated in Gaborone, Botswana, respects your privacy and is committed to protecting your personal information.
This Privacy Policy describes how we collect, use, store, process, disclose, and protect your personal and financial information when you install, register, and use the Dithebe digital wallet mobile application, website, and related transfer services (collectively, the "Services").
Data Protection Commissioner Registry
In compliance with the Data Protection Act, 2018 (DPA) of Botswana, Dithebe acts as the "Data Controller" for all personal data collected through the Platform. Our data processing systems are operated and structured to meet the lawful processing principles defined under Part III of the DPA.
By clicking "Accept" or registering an account on the Platform, you provide your explicit and informed consent to the collection, processing, and transfer of your personal data as outlined in this policy. If you do not consent, you must immediately uninstall the application and discontinue using our Services.
2. Personal Data We Collect
To provide a functional mobile wallet and ensure compliance with identity verification standards, we collect several categories of information:
A. Information You Provide to Us
- Onboarding & Profile Data: Mobile telephone number, full legal names, physical address, email address, and demographic details.
- KYC Documents: High-resolution optical scans or photographs of your National Identity Card (Omang) for citizens, or passports for foreign residents, including card data (Omang number, date of birth, expiry date, gender).
- Biometric Data: Camera selfie photograph uploaded during identity verification to perform facial comparison checks against the Omang card image.
B. Automatically Collected Technical Data
- Device Fingerprint & Serial: Handset make, model, operating system version, IP address, cellular carrier network provider, and hardware serial numbers (IMEI or unique hardware identifiers used to execute our Anti-Clone device binding lock).
- Log and Usage Data: Session start and end times, app interaction statistics, crashes, button clicks, and general application diagnostic statistics.
C. Transactional Data
- Transfer Ledger: Sender and recipient mobile numbers, transaction values (Pula transfers), timestamps, transaction description text, and wallet ledger balance states.
3. Legal Ground and Processing Purposes
We process your personal information strictly based on established legal grounds:
- Performance of a Contract: To execute peer-to-peer transfers, hold balance custody, resolve transaction issues, and manage your account.
- Compliance with Legal Obligations: Under the Financial Intelligence Act, 2019, we are legally required to verify customer identity, detect patterns of money laundering or terrorist financing, and log all transactional interactions.
- Legitimate Interests: To protect the integrity and security of our Platform, prevent software piracy, detect fraudulent account access attempts, and protect Company intellectual property.
Legitimate Interest & Cyber Security
In accordance with the Cybercrime and Computer Related Crimes Act, 2018, we process connection logs, hardware serial numbers, and session activities to monitor and secure our network against hacking, clone profiles, phishing attacks, and unauthorized system access.
4. Data Retention and Storage Rules
Dithebe stores personal data on secure servers in certified cloud repositories. Cross-border transfers of data, if required for backup or processing systems, are conducted in compliance with Section 48 of the Data Protection Act, 2018, ensuring appropriate safeguards exist.
We retain your information as follows:
- Registration & Profile Data: Retained for the entire duration that your Dithebe account remains active, and for a period of five (5) years following the closure of your account.
- Transaction Ledgers & KYC Verification Records: Retained for a mandatory minimum period of five (5) years from the date of the transaction or account closure, as strictly mandated under Section 13 of the Financial Intelligence Act, 2019.
- System Diagnostic Logs: Retained for up to twelve (12) months before automated deletion, unless required for ongoing security audits.
Upon the expiry of the mandatory retention periods, personal data is permanently deleted, anonymized, or destroyed using secure digital wiping mechanisms.
5. Security Standards and Protections
We implement industry-grade technical and organizational security measures to prevent unauthorized access, alteration, disclosure, loss, or destruction of your personal data.
- Encryption: All personal data and identity documents are encrypted at rest using AES-256 standards, and all network transmissions between the App and backend API servers are protected using Transport Layer Security (TLS 1.3).
- Handset Hardware Lock: Accounts are locked to your specific physical device serial number. If a third party gains access to your PIN, they cannot log into your wallet from another phone.
- Strict Internal Controls: Access to user KYC database records is strictly restricted to designated compliance personnel who have passed rigorous security screenings.
No method of transmission over the internet, or method of electronic storage, is 100% secure. While we strive to use state-of-the-art protections to secure your data, we cannot guarantee absolute security.
6. Third-Party Data Sharing & Disclosure
Dithebe will never sell, rent, or trade your personal data with marketing third parties. We share data only in the following limited situations:
- Regulatory Authorities: We disclose customer details and transaction histories to the Financial Intelligence Agency (FIA), Bank of Botswana, and law enforcement agencies when legally required by subpoena, court order, or AML directives.
- Verification Partners: To run automated KYC checks, we share details (such as your Omang ID number) with authorized government registration databases or private compliance APIs to verify document validity.
- Custodian Banking Intermediaries: We share necessary transactional info with partnering commercial banks who hold the trust custody of pre-funded wallet assets to settle transfers.
7. Your Data Subject Rights
Under Part IV of the Data Protection Act, 2018, users in Botswana possess specific rights regarding their personal data:
- Right of Access: You have the right to request a copy of all personal information Dithebe holds about you.
- Right to Rectification: You may request the correction of any inaccurate or outdated personal details.
- Right to Erasure ("Right to be Forgotten"): You may request the deletion of your account and personal data, subject to the legal retention rules under the Financial Intelligence Act, 2019 (mandating retention for 5 years).
- Right to Object: You have the right to object to processing based on legitimate interests.
To exercise any of these rights, please contact our Data Protection Officer at privacy@dithebe.co.bw. We will respond to your request within thirty (30) days.
8. Intellectual Property & Liability Limitation on Data Breaches
Intellectual Property: All database structures, security protocols, Anti-Clone schemas, customized OCR algorithms, metadata models, and UI data representations generated on the Platform remain the sole intellectual property of the Company.
Limitation of Liability: Dithebe is not liable for data breaches, leaks, or financial losses caused by events outside our direct operational control, including:
- User negligence, such as sharing transaction PINs or failing to implement device passcodes.
- Compromises of your cellular mobile provider network (SIM swapping or SMS interception).
- Malware, spyware, or screen recorders installed on your phone by other applications.
Our total liability for data privacy breaches shall be limited to the maximum extent permissible under Botswana law, capped at the amount you paid to use the Services or P100.00 (One Hundred Pula).
10. Policy Updates and Contact Information
Dithebe reserves the right to modify or update this Privacy Policy at any time. If changes are material, we will provide notice through the App or by emailing registered users at least fourteen (14) days prior to the updates taking effect. Your continued use of the Services after the notice period constitutes your acceptance of the updated policy.
For any inquiries, requests to exercise your rights, or complaints regarding how we handle your personal data, please contact us:
Data Protection & Compliance OfficerDithebe Technologies (Pty) Ltd
Plot 54352, Gaborone West, Gaborone, Botswana
Email: privacy@dithebe.co.bw
If you feel we have not addressed your concerns adequately, you have the right to lodge a complaint with the Data Protection Information Commissioner under the Ministry of Communications, Knowledge and Technology of the Republic of Botswana.