PRIVACY POLICY
Introduction
This Privacy Policy is intended to provide you with specific details about how the Uganda Securities Exchange (USE) collects and processes your personally identifiable information (“Personal Information”) and to explain your rights relating to the privacy of your personal information and how the law protects you through your use of the USE Easy Portal (Portal) and mobile applications (Apps). USE is the data processor and data controller of all information collected through the services. We are committed to maintaining the accuracy, confidentiality, and security of Personal Information. We have implemented reasonable measures to ensure that your personal information is protected. Our privacy policy is based upon the Uganda Data Protection and Privacy Act, 2019.
By providing USE with your personally identifiable data and using the services, you warrant that you are over the age of eighteen (18). If you are younger than eighteen (18) please do not use the USE services and please do not provide personal information to us.
Personal Information Collected.
When you use the services on our platforms, we may collect personally identifiable information from you (“PII”). PII may include any information that identifies with a particular individual. It does not include anonymized data.
We may collect and process the following categories of PII about you:
Information You Directly and Voluntarily Provide to Us
Communication Data. Communication data like email addresses and phone numbers you send to us through the services is processed and used to communicate with you, to provide you with customer support.
User Data. User data includes data you use to authorize through the services. This includes data stored in persistent cookies when you login to the services. We collect and process this data to operate the services, to authenticate you as a user of the services, to ensure that timely and relevant content is provided to you, to secure the services, to ensure that the services operate in a fast and efficient manner.
Financial Information. We collect certain information from you about your Financial Account such as your bank name, bank branch, account number, your transaction information, amount of funds, and other information about your Financial Information. USE will use your Financial Information to provide you the services.
Personally Sensitive Data. Personally sensitive data includes data about name, gender, nationality, address, your date of birth, sex, passport photo, identification/Passport number and photo.
Information We Automatically Collect.
As you navigate through and interact with the Easy Portal and mobile applications, we may use automatic data collection technologies to collect certain information about your device (computer, tablet, smartphone) and your activities, including:
If you access the services through a computer, we will automatically collect information such as your browser type and version, computer and connection information, IP address, mobile device advertising identifier, Media Access Control (MAC) address pages you have visited, type of device, operating system name and version, device manufacturer, browser information (type, version), screen resolution, Internet service provider or mobile carrier’s name, connection speed and connection type, date stamp, URL of the last webpage visited before visiting our Platform, and URL of the first page visited after leaving our Platform, pages viewed, time spent on a page, click through, clickstream data, queries made, search results selected, comments made, search history, type of service requested, purchases made, and information collected through cookies, pixel tags, and other technologies.
If you access the services through a mobile device, we may also be able to identify the location of your mobile device. We use your location information (if shared) to identify the geographic locations from which our content is accessed so that we can better understand what content topics may be most relevant in that region, and to our members generally, and to develop resources around those content topics. You may choose not to share your location details with us by adjusting your mobile device’s location services settings. For instructions on changing the relevant settings, please contact your service provider or device manufacturer.
We rely on our legitimate interest in understanding how our clients use the Portal and Apps in processing personal information in this way. Such processing assists us in providing more relevant products and services to our members, and with providing value to our stakeholders.
How do we collect your personal information?
We will collect personal information directly from you through our brokers or through online channels such as our Portal and mobile applications.
We also collect personal information about you from other sources where lawful and reasonable, such as reputable third parties that you deal with. These third parties include:
Business partners (including partners and participating partners involved in reward programs, campaigns, or other business activity) and joint-venture partners.
Information You Provide to Payment Processors. All payments made to us are processed by a PCI/DSS-compliant (these are payment card industry security standards) payment processing service. All information collected by these third party providers for purposes of processing your payments is not available to us unless you have otherwise provided this information to us in connection with your use of the sites or our services.
Government departments, regulatory authorities, courts of law and law enforcement agencies, ombudsmen and tax authorities.
WHY WE COLLECT YOUR INFORMATION
The purposes for which we collect Personal Information will be identified before or at the time we collect the information. If USE needs to use your PII for an unrelated new purpose, USE will provide you with notice of this new use.
To Provide and Maintain our Services.
We will use your personal information to provide information on investments to enable you invest. For example, we process your personal information to provide information on trading securities and participating in an IPO.
To Provide Customer Support or Respond to You
We collect any information that you provide to us when you contact us, such as with questions, concerns, feedback, disputes or issues. Without your personal information, we cannot respond to you.
To Advise You of Other Services
From time to time, subject to the Data Protection Act and other applicable law, we may share your personal information with third parties or partners. You may opt out of having your personal information shared with third parties. If you choose to limit the use of your personal information, certain features or Services may not be available to you.
To Personalize Your Experience
We may also use your personal information to tailor your experience at all our portals and apps, to compile and display content and information that we think you might be interested in, and to provide you with content according to these preferences. We may also use this information to help us understand your needs and interests, and to better tailor our products and services to meet your needs.
For Research and Development
We may use your information to gather analysis or valuable information so that we can improve our Services and to detect, prevent and address technical issues. We may also use your information to monitor the usage of our Site including without limitation search terms entered, pages visited, and documents viewed.
For Security Reasons
We may use personal information to help monitor, prevent, and detect fraud, enhance security, monitor and verify identity or access, or security risks.
To Enforce Compliance with Our Terms and Agreements or Policies.
When you access or use our Services, you are bound to our Terms of Use and this Policy. To ensure you comply with them, we process your personal information by actively monitoring, investigating, preventing, and mitigating any alleged or actual prohibited, illicit or illegal activities on our Services. We also may process your personal information to investigate, prevent or mitigate violations of our internal terms, agreements, or policies; enforce our agreements with third parties and business partners; and, as applicable, collect fees based on your use of our Services.
Other Legitimate Business Purposes. We may use your personal information when it is necessary for other legitimate purposes such as protecting our confidential and proprietary information.
Consent
Knowledge and consent are required for the collection, use or disclosure of Personal Information except where required or permitted by law. Providing us with your Personal Information is usually voluntary. However, your decision not to provide certain information may limit our ability to provide you with our services or comply with our legal obligations. We will not require you to consent to the collection, use, or disclosure of information as a condition to the supply of a service, except as required to be able to supply the service.
Limiting Collection
The Personal Information collected will be limited to those details necessary for the purposes identified by us. With your consent, we may collect Personal Information from you in person, over the telephone or by corresponding with your email.
How we share your information
Except as set forth in this Privacy Policy or when specifically agreed to by you, we take care to allow your personal information to be accessed only by those who really need access in order to perform their tasks and duties, and to share with third parties who have a legitimate purpose for accessing it. In general, we do not share your information with a third party for their independent use unless:
(i) you request or authorize it,
(ii) it is required by law, or
(iii) it is in connection with a co-sponsored event. We may share personal information in the following circumstances:
Service Providers. We may share your information with our suppliers, subcontractors, and other third parties who provide services to us (collectively “service providers”) in connection with, hosting, data analytics, information technology and infrastructure, email delivery, auditing, training providers and other related activities, vendors or third parties who deliver or provide goods and services or otherwise act on our behalf of or at our direction. Our service providers are given only the information they need to perform their designated functions and are prohibited from using the information we provide them for their own purposes.
Compliance with Laws or Regulatory Bodies. We may disclose your information to government authorities or third parties if:
i. required to do so by law or regulation, or in response to a subpoena or court order or any other enforceable governmental request or order.
ii. we believe disclosure is reasonably necessary to protect against fraud, to protect the property or other rights of us or other users, third parties or the public at large; or
iii. to exercise, establish, or defend our legal rights.
Limiting Use, Disclosure, and Retention
Personal Information may only be used or disclosed for the purpose for which it was collected unless you have otherwise consented, or when it is required or permitted by law. Personal Information will only be retained for the period required to fulfill the purpose for which we collected it or as may be required by law.
Accuracy
Personal Information will be maintained in as accurate, complete, and up-to-date form as is necessary to fulfill the purposes for which it is to be used.
Data Security.
USE has put into place data security measures to protect your PII. USE allows access to your PII only by employees and service providers who have a need to know or on USE’s instructions. We may use encryption technologies to enhance data privacy and help prevent loss, misuse, or alteration of the information under the control of the USE. However, no security measures are impenetrable and there are always security risks. The Internet by its nature is a public forum. We encourage you to use caution when disclosing information online. Often, you are in the best situation to protect yourself online. You are responsible for protecting your login ID and password from third-party access, and for selecting passwords that are secure. USE will notify you and any regulatory body of any breach of your PII or USE’s security measures if it is legally required to do so.
Right to Access, Rectification, Correction, Deletion, Transfer, and Withdrawal.
As a client, you have the right to request access to your personally identifiable information (PII) for rectification, correction, deletion, transfer, or restriction, or to object to its processing or withdraw your consent. If you wish to exercise any of these rights, please contact your broker: https://www.use.or.ug/content/trading-participants
We do not charge a fee for accessing your PII or exercising your rights. However, we may charge a reasonable fee for retrieving copies of your KYC.
To ensure the security of your PII, we may need to request specific information from you to confirm your request. We strive to respond to any verifiable consumer request within seven (7) days of receipt.
If we require more time, we will inform you of the reason and extension period in writing. We will deliver our written response by email.
In the case of data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information.
If we modify or delete some or all your personal information, we will retain your personal data if reasonably necessary to fulfil any other requests from you (for example, to opt-out of further messages or for a copy of your data.
Notification of Changes.
We may need to update this Privacy Policy from time to time to reflect changes in our business practices, data collection practices or organization. If we make a change that we believe materially affects how we process your personal information, we will provide notice of such change on this Site or via email, at the email address we have on file for you. After such notice, your continued use of our Services will be subject to the then-current Privacy Policy. We encourage you to look for updates and changes to this Privacy Policy by checking the “Effective Date” located at the top of the new Privacy Policy.
Handling Customer Complaints and Suggestions
If you have any questions about this Privacy Policy or how we collect or use Personal Information about you, email us at info@use.or.ug.