Data Protection Policy

Effective March 2024

Umurimo Finance Plc is committed to safeguarding personal data across every channel we operate. This statement summarises our approach in line with applicable laws in Rwanda. For a plain-language summary of how we handle your information online and in-branch, see also our Privacy Policy.

1. Introduction

Umurimo Finance Plc is committed to ensuring the protection of personal data in accordance with applicable data protection laws and regulations in Rwanda. This policy outlines how personal data is collected, processed, stored, and protected.

2. Scope

This policy applies to:

  • All employees, customers, suppliers, and partners
  • All branches and operational units
  • All personal data processed in both digital and physical formats

3. Data Protection Principles

Umurimo Finance Plc adheres to the following principles:

Core principles

3.1

Lawfulness, fairness & transparency

Personal data is processed lawfully and transparently, with clear communication to data subjects.

3.2

Purpose limitation

Data is collected for specified, legitimate purposes and not used beyond those purposes without consent.

3.3

Data minimization

Only data necessary for the intended purpose is collected and processed.

3.4

Accuracy

Personal data is kept accurate and up to date.

3.5

Storage limitation

Data is retained only for as long as necessary and securely deleted thereafter.

3.6

Integrity & confidentiality

Appropriate security measures protect personal data from unauthorised access or breaches.

6. Data Subject Rights

Individuals have the right to:

  • Access their personal data
  • Request correction or deletion
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time

7. Data Sharing

Personal data may be shared with authorised third parties only when necessary and under strict contractual and security obligations.

8. Data Security Measures

We implement appropriate technical and organisational measures including:

  • Encryption and secure communication protocols
  • Access control mechanisms
  • Regular security audits and monitoring

9. Data Breach Management

In the event of a data breach, Umurimo Finance Plc will notify the relevant authority within 48 hours and affected individuals where required.

10. Responsibilities

  • Board of Directors: Oversight and governance
  • Management: Implementation of policies
  • Data Protection Officer: Compliance monitoring
  • Employees: Responsible handling of data

11. Contact

For data protection enquiries, contact us by email at info@umurimofinance.com or reach the team through our contact page—we will route your message to the Data Protection Officer where appropriate.