PRIVACY POLICY

Introduction

This Privacy Policy is intended to provide you with specific details about how the Uganda Securities Exchange (USE) collects and processes your personally identifiable information (“Personal Information”) and to explain your rights relating to the privacy of your personal information and how the law protects you through your use of the USE Easy Portal (Portal) and mobile applications (Apps). USE is the data processor and data controller of all information collected through the services. We are committed to maintaining the accuracy, confidentiality, and security of Personal Information. We have implemented reasonable measures to ensure that your personal information is protected. Our privacy policy is based upon the Uganda Data Protection and Privacy Act, 2019.

By providing USE with your personally identifiable data and using the services, you warrant that you are over the age of eighteen (18). If you are younger than eighteen (18) please do not use the USE services and please do not provide personal information to us.

  1. Personal Information Collected.

When you use the services on our platforms, we may collect personally identifiable information from you (“PII”). PII may include any information that identifies with a particular individual. It does not include anonymized data.

We may collect and process the following categories of PII about you:

  1. Information You Directly and Voluntarily Provide to Us







  1. Information We Automatically Collect. 

As you navigate through and interact with the Easy Portal and mobile applications, we may use automatic data collection technologies to collect certain information about your device (computer, tablet, smartphone) and your activities, including:

We rely on our legitimate interest in understanding how our clients use the Portal and Apps in processing personal information in this way. Such processing assists us in providing more relevant products and services to our members, and with providing value to our stakeholders.

  1. How do we collect your personal information?

We will collect personal information directly from you through our brokers or through online channels such as our Portal and mobile applications.

We also collect personal information about you from other sources where lawful and reasonable, such as reputable third parties that you deal with. These third parties include:

  1. Business partners (including partners and participating partners involved in reward programs, campaigns, or other business activity) and joint-venture partners.

Information You Provide to Payment Processors. All payments made to us are processed by a PCI/DSS-compliant (these are payment card industry security standards) payment processing service. All information collected by these third party providers for purposes of processing your payments is not available to us unless you have otherwise provided this information to us in connection with your use of the sites or our services.

  1. Government departments, regulatory authorities, courts of law and law enforcement agencies, ombudsmen and tax authorities.



  1. WHY WE COLLECT YOUR INFORMATION

The purposes for which we collect Personal Information will be identified before or at the time we collect the information. If USE needs to use your PII for an unrelated new purpose, USE will provide you with notice of this new use.

  1. To Provide and Maintain our Services.

We will use your personal information to provide information on investments to enable you invest. For example, we process your personal information to provide information on trading securities and participating in an IPO.

  1. To Provide Customer Support or Respond to You

We collect any information that you provide to us when you contact us, such as with questions, concerns, feedback, disputes or issues. Without your personal information, we cannot respond to you.

  1. To Advise You of Other Services

From time to time, subject to the Data Protection Act and other applicable law, we may share your personal information with third parties or partners. You may opt out of having your personal information shared with third parties. If you choose to limit the use of your personal information, certain features or Services may not be available to you.

  1. To Personalize Your Experience 

We may also use your personal information to tailor your experience at all our portals and apps, to compile and display content and information that we think you might be interested in, and to provide you with content according to these preferences. We may also use this information to help us understand your needs and interests, and to better tailor our products and services to meet your needs.

  1. For Research and Development

We may use your information to gather analysis or valuable information so that we can improve our Services and to detect, prevent and address technical issues. We may also use your information to monitor the usage of our Site including without limitation search terms entered, pages visited, and documents viewed.

  1. For Security Reasons 

We may use personal information to help monitor, prevent, and detect fraud, enhance security, monitor and verify identity or access, or security risks.

  1. To Enforce Compliance with Our Terms and Agreements or Policies. 

When you access or use our Services, you are bound to our Terms of Use and this Policy. To ensure you comply with them, we process your personal information by actively monitoring, investigating, preventing, and mitigating any alleged or actual prohibited, illicit or illegal activities on our Services. We also may process your personal information to investigate, prevent or mitigate violations of our internal terms, agreements, or policies; enforce our agreements with third parties and business partners; and, as applicable, collect fees based on your use of our Services.

  1. Other Legitimate Business Purposes. We may use your personal information when it is necessary for other legitimate purposes such as protecting our confidential and proprietary information.



  1. Consent

Knowledge and consent are required for the collection, use or disclosure of Personal Information except where required or permitted by law. Providing us with your Personal Information is usually voluntary. However, your decision not to provide certain information may limit our ability to provide you with our services or comply with our legal obligations. We will not require you to consent to the collection, use, or disclosure of information as a condition to the supply of a service, except as required to be able to supply the service.

  1. Limiting Collection

The Personal Information collected will be limited to those details necessary for the purposes identified by us. With your consent, we may collect Personal Information from you in person, over the telephone or by corresponding with your email.

  1. How we share your information

Except as set forth in this Privacy Policy or when specifically agreed to by you, we take care to allow your personal information to be accessed only by those who really need access in order to perform their tasks and duties, and to share with third parties who have a legitimate purpose for accessing it. In general, we do not share your information with a third party for their independent use unless:

(i) you request or authorize it,

(ii) it is required by law, or

(iii) it is in connection with a co-sponsored event. We may share personal information in the following circumstances:

i. required to do so by law or regulation, or in response to a subpoena or court order or any other enforceable governmental request or order.

ii. we believe disclosure is reasonably necessary to protect against fraud, to protect the property or other rights of us or other users, third parties or the public at large; or

iii. to exercise, establish, or defend our legal rights.

  1. Limiting Use, Disclosure, and Retention

Personal Information may only be used or disclosed for the purpose for which it was collected unless you have otherwise consented, or when it is required or permitted by law. Personal Information will only be retained for the period required to fulfill the purpose for which we collected it or as may be required by law.

  1. Accuracy

Personal Information will be maintained in as accurate, complete, and up-to-date form as is necessary to fulfill the purposes for which it is to be used.

  1. Data Security.

USE has put into place data security measures to protect your PII. USE allows access to your PII only by employees and service providers who have a need to know or on USE’s instructions. We may use encryption technologies to enhance data privacy and help prevent loss, misuse, or alteration of the information under the control of the USE. However, no security measures are impenetrable and there are always security risks. The Internet by its nature is a public forum. We encourage you to use caution when disclosing information online. Often, you are in the best situation to protect yourself online. You are responsible for protecting your login ID and password from third-party access, and for selecting passwords that are secure. USE will notify you and any regulatory body of any breach of your PII or USE’s security measures if it is legally required to do so.

  1. Right to Access, Rectification, Correction, Deletion, Transfer, and Withdrawal.

As a client, you have the right to request access to your personally identifiable information (PII) for rectification, correction, deletion, transfer, or restriction, or to object to its processing or withdraw your consent. If you wish to exercise any of these rights, please contact your broker: https://www.use.or.ug/content/trading-participants

We do not charge a fee for accessing your PII or exercising your rights. However, we may charge a reasonable fee for retrieving copies of your KYC.

To ensure the security of your PII, we may need to request specific information from you to confirm your request. We strive to respond to any verifiable consumer request within seven (7) days of receipt.

If we require more time, we will inform you of the reason and extension period in writing. We will deliver our written response by email.

In the case of data portability requests, we will select a format to provide your personal information that is readily usable and should allow you to transmit the information.

If we modify or delete some or all your personal information, we will retain your personal data if reasonably necessary to fulfil any other requests from you (for example, to opt-out of further messages or for a copy of your data.

  1. Notification of Changes.



We may need to update this Privacy Policy from time to time to reflect changes in our business practices, data collection practices or organization. If we make a change that we believe materially affects how we process your personal information, we will provide notice of such change on this Site or via email, at the email address we have on file for you. After such notice, your continued use of our Services will be subject to the then-current Privacy Policy. We encourage you to look for updates and changes to this Privacy Policy by checking the “Effective Date” located at the top of the new Privacy Policy.

  1. Handling Customer Complaints and Suggestions

If you have any questions about this Privacy Policy or how we collect or use Personal Information about you, email us at info@use.or.ug.