Legal
Data Privacy Policy
How mBenki collects, uses, protects and deletes personal data across the website, the apps and the agent network.
1. Purpose and scope
This Policy explains how we collect, use, disclose, secure, retain and delete personal data across mBenki's operations, including: our website and online tools (contact forms, analytics, cookies, portals and apps); Smart Agents (onboarding, training, performance, compliance); customers engaged by Smart Agents or through our digital channels; and participating institutions whose products and services we market and help distribute.
2. Our roles and Data Commission registration
Role classification. We act as Data Controller for our own operations (Smart Agent management, platform security, marketing). We act as Data Processor when handling consumer data on behalf of a participating institution during a product journey.
Registration status. mBenki is required to be registered with the Office of the Data Protection Commissioner (ODPC) as a Data Controller and, where applicable, as a Data Processor. The registration number will be published here when issued.
Data protection contact details appear in Section 19.
3. Definitions
- Personal data: information that identifies or can identify a person.
- Controller: decides why and how personal data is processed.
- Processor: handles personal data for a controller under instructions.
- Processing: any operation on personal data (collect, store, use, share, delete).
- Special or sensitive data: personal data requiring higher protection.
4. Data we collect
- Identification and contact: names, national ID details where lawful and required, phone, email.
- Smart Agent professional: onboarding, certifications, training completion, quality reviews.
- Interaction and application: product interests, eligibility checkpoints, application status and outcomes, support history.
- Operational and telemetry: timestamps, activity events, device and app logs for quality and security.
- Website, app and device: IP address, device identifiers, usage analytics and events consistent with your choices.
5. Why we use data
- Deliver services to institutions and consumers; enable agent-led sales; standardise field engagements; digitise interactions.
- Provide analytics and reporting to institutions (dashboards, conversion tracking, market insights).
- Train and support Smart Agents (knowledge tools, quality assurance, compliance).
- Maintain security, prevent fraud and meet legal and regulatory obligations.
- Communicate about services and, where permitted, send marketing with a simple opt-out.
Legal bases: consent, contractual necessity, legal obligation, and legitimate interests in secure, efficient operations.
6. How we collect data
- Directly from you: forms, chats, calls, events, or during agent interactions.
- From Smart Agents: details captured in the field through mBenki apps.
- From institutions: product rules, eligibility inputs and application status updates.
- Automatically: via cookies, SDKs, device data and system logs (see Section 12).
7. Sharing and disclosures
- Service providers: hosting, analytics, training, communications and support under written contracts.
- Participating institutions: data shared as needed to fulfil product journeys (lead transfer, eligibility, applications).
- Legal and regulatory: when required by law, to protect rights or prevent fraud.
- Business changes: if we reorganise or transfer parts of our business, we will protect the data and notify where appropriate.
8. Cross-border processing and localisation
Data is processed and stored in Zambia where feasible. Transfers occur only when necessary and subject to legally required safeguards and written agreements with processors and partners. Sensitive data receives heightened protection; cross-border handling follows applicable approvals and conditions.
9. Security
- Access management: least privilege, strong authentication for privileged roles, periodic reviews.
- Protection: TLS in transit; proportionate encryption and key management at rest.
- Monitoring: audit logs for sensitive actions, anomaly detection, secure engineering practices.
No system is impenetrable; we continuously improve our controls.
10. Retention and disposal
- Operational logs and telemetry: generally up to 12 months, then deleted or aggregated.
- Lead and application records: for the service lifecycle and contractual or statutory periods, then deleted or anonymised.
- Smart Agent records: for the engagement term plus statutory labour and tax periods; training and QA records for defined dispute windows.
- Financial and transaction records: as required by law and tax rules.
- Backups: not for active use; securely rotated on scheduled cycles.
11. Your rights and how to exercise them
Rights: access, rectification, erasure, objection to certain processing, and withdrawal of consent where relied upon.
How: submit a request by email (Section 19). We verify identity and act without undue delay, updating you on progress for complex requests. Where we act as Processor, we relay your request to the relevant institution and assist their response.
Complaints: you may contact the ODPC if you are not satisfied with our response.
12. Cookies, SDKs and tracking
What we use: strictly necessary cookies required to operate the site and portals; performance and analytics cookies to improve features and reliability; marketing cookies to measure campaigns and show relevant content.
Your choices: optional cookies run only after opt-in via our banner or settings. You can change preferences at any time via Cookie Settings. We respect supported browser-level preference signals where technically feasible.
Data handling: identifiers may include IP, device IDs and session IDs; we minimise retention and rotate identifiers where possible.
13. Smart Agent data handling
- Confidentiality and accuracy: protect customer and institutional information; use approved scripts and current product materials; avoid misrepresentation.
- Device hygiene: enable lock or PIN; keep OS and apps updated; do not store customer photos or personal data outside approved apps; never share credentials.
- Minimum necessary: collect only fields required for each product journey; give just-in-time notices before sensitive capture.
- Telemetry: location and call capture may be used for quality and compliance with clear notice and limited access.
- Incidents and complaints: escalate immediately via designated support channels; cooperate with investigations and remediation.
- On termination: return company equipment and delete any mBenki or institutional data from personal devices as directed.
14. Children's data
Our services are intended for adults and business users; we do not knowingly collect data from children. If discovered, we will delete it promptly.
15. Incident response and breach notification
Process: detect, triage, contain, investigate, notify, remediate and document.
Notifications: institutions first where we act as Processor; authorities and affected individuals when required by law or contract. We apply lessons learned and improve controls after every incident.
16. Vendor and sub-processor management
We assess privacy and security controls before onboarding a vendor; contracts require confidentiality, security, assistance with rights requests and breach duties. We maintain an inventory of processors and material sub-processors and notify institutions of significant changes where contractually required.
17. Data deletion and withdrawal of consent
Scope: removal from active systems; data placed beyond use in backups pending scheduled overwrites. We notify relevant processors and partners to erase copies where feasible.
Limits: we may retain data required by law or for legal claims and will restrict processing in the interim.
To request deletion: log in to the mBenki Pro app and choose “Close account”, or email privacy@mbenki.com.
18. Changes to this Policy
We will post updates here and revise the effective date. Continued use after updates indicates acceptance. Material changes will be communicated appropriately.
19. Contact and corporate disclosures
- Legal name: mBenki Business Solutions Zambia Ltd
- PACRA registration no.: 120230053952
- Registered address (for service): Plot No. 20436, Yotam Muleya Road, Libala South, Libala Mall, Lusaka, Zambia
- Telephone: 260 773 158 012
- Email: information@mbenki.com (general) · privacy@mbenki.com (privacy)
- Directors / office bearers: Pamfred Hasweeka (CEO), Chris Sinchende (COO), Chimuka Moonde (CTO)
Questions about this document: information@mbenki.com · 260 773 158 012 · Data Privacy Policy · Terms of Use