Data Policy & Security
Last updated: August 10, 2026
1. Purpose of the Policy
This is the policy of Weaf. It is for the purpose of giving users a comprehensive guide of how they should expect us to use their data. This Data Policy and Security document is intended to provide an overview of Weaf's data practices.
2. Definitions
- Personal data: Data privacy to an enterprise which would otherwise not be available to the public.
- Processing: Any operation or set of operations performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
- Data subject: An individual from whom, or in respect of whom, personal data has been requested, collected, collated, processed or stored.
- Data controller: A person who alone, jointly with other persons, or in common with other persons, determines the purpose for and the manner in which personal data is processed or is to be processed.
- Data collector: A person who collects personal data.
- User: Enterprise or individual using our API.
3. Data Collection
We gather information pertinent to legitimate purposes only. Weaf possesses information about an enterprise if: an enterprise has provided the information, Weaf has automatically collected the information, or Weaf has obtained the information from a third party. The various scenarios encompassed by these categories and the information collected in each are outlined below.
3.1 Information provided by users
- Account signup: Upon registering for an account, we request details such as name, contact number, email address and company name. Users select a unique username and password, may optionally provide their organization's logo, and may set a security question and answer used exclusively for password resetting.
- Event registrations and other form submissions: We retain information submitted during newsletter subscriptions, survey responses or any other form submission for customer support requests, quotations or general inquiries.
- Payment processing: When making a purchase, users furnish their name, bank account number, contact information or mobile money number or other payment account information.
- Testimonials: With authorization, testimonials may include users' names and other personal details. Users may review and approve content before publication and can request updates or deletion.
- Interactions with Weaf: We may record, analyze and utilize interactions with our sales and customer support teams via email, telephone or chat to enhance user experiences.
3.2 Automatically collected information
- From browsers, devices and servers: IP addresses, browser types, language preferences, time zones, referring URLs, access date and time, operating systems, mobile device manufacturers and mobile network information, included in our log files.
- From application logs and mobile analytics: clicks, scrolls, features accessed, access times, error reports, performance data, storage usage, user settings, device configurations and access devices and their locations — vital for improving our products.
3.3 Information obtained from third parties
- From reselling partners and service providers: partners may provide your name, email address, company name and other relevant details; event organizers may share information if you register for Weaf-sponsored events; review sites and other marketing service providers may share information.
- From social media and publicly available sources: feedback, reviews, interactions or engagements with Weaf on marketplaces, review sites or social platforms (Facebook, Twitter, LinkedIn, Instagram).
4. Data Usage
Weaf utilizes the gathered data for the following purposes:
- Communication regarding products downloaded, services signed up for, changes to our Privacy Policy and Terms of Service, and important notices.
- Information updates about new products, services, events, offers and promotions.
- Feedback and surveys on our products and services.
- Account maintenance, collaboration, website and mail hosting, and backing up and restoring your data.
- Usage analysis, monitoring and preventing issues, and enhancing our offerings.
- Customer support, analyzing and improving customer interactions.
- Security and protection — detecting and preventing fraud and illegal activity, reporting spam, and safeguarding the rights of Weaf, its users, third parties and the public.
- Marketing and customer engagement, trend analysis and website administration.
- Marketing campaigns monitoring and improvement.
- Security services — analyzing threats and vulnerabilities and ensuring legal and regulatory compliance.
5. Your Choice in Information Use
You may refrain from receiving newsletters and other non-essential messages via the "unsubscribe" function included in all such communications. However, essential notices — account notifications (e.g. password change, renewal reminders), security incident alerts, security and privacy update notifications, and essential transactional and payment-related emails — will continue to be sent to you.
6. Consent
Weaf shall obtain the informed consent of a data subject prior to collecting or processing their personal data. Consent shall be freely given, specific, informed and unambiguous. Where Weaf relies on consent as the legal basis for processing, users may withdraw their consent at any time by contacting us at the details provided in the Contact Us section, without affecting the lawfulness of processing carried out before withdrawal. Exceptions apply only where processing is authorized or required by law, necessary for the performance of a contract, required for national security, medical purposes, or compliance with a legal obligation.
7. Children's Personal Data
Weaf does not knowingly collect or process personal data relating to children (persons under 18 years of age) without the prior written consent of a parent or legal guardian. Where we become aware that personal data of a child has been collected without verifiable parental consent, we shall promptly delete such data. If you believe we may hold personal data about a child without consent, please contact us immediately using the details below.
8. Data Sharing and Disclosure
Weaf will not disclose user data to third parties without explicit consent from the user, except in the following circumstances:
- Third-party service providers such as marketing and advertising partners, event organizers, web analytics providers and payment processors, authorized to use your information only as necessary to provide these services to us.
- Reselling partners in your region, solely to contact you about products downloaded or services signed up for; you may opt out of further collaboration with that partner.
- Mergers or acquisitions, with the condition that the new combined entity adheres to this Privacy Policy; you will be given prior notice if your information could be used contrary to this policy.
- Legal requests — where disclosure is required by the courts of law or law enforcement agencies.
9. Data Processing
The financial data of users is processed by Weaf for the purpose of facilitating the issuance of electronic invoices and receipts, ensuring prompt recording and reflection on the relevant revenue authority portal (e.g. URA EFRIS, MRA EIS, ZRA Smart Invoice).
10. Data Retention
Data from users will be retained for no longer than is necessary to fulfil the purposes set out in this policy, or as otherwise required by applicable law. Personal data shall not be retained beyond the period authorized by law or required for its original purpose. Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized.
11. Data Breach Notification
In the event of a personal data breach, Weaf shall, as soon as practicable upon becoming aware of the breach, notify the affected data subjects and the Personal Data Protection Office (PDPO) under NITA-U. The notification shall include:
- (a) the nature of the breach;
- (b) the categories and approximate number of data subjects affected;
- (c) the likely consequences of the breach; and
- (d) the measures taken or proposed to address the breach.
Weaf maintains an internal incident response procedure to detect, investigate and remediate data security incidents promptly.
12. Cross-Border Data Transfers
Weaf does not transfer personal data outside Uganda without implementing adequate safeguards equivalent to the protections offered by the Data Protection and Privacy Act, 2019. Any transfer of personal data to a foreign country or international organization shall only be carried out:
- (a) with the informed consent of the data subject; or
- (b) where the destination country or organization ensures an adequate level of protection for the rights and freedoms of data subjects; or
- (c) where such transfer is necessary for the performance of a contract between the data subject and Weaf, or for the implementation of pre-contractual measures taken at the data subject's request.
13. Your Rights With Respect to Information We Hold About You
- Right to access (and get a copy of) the categories of personal information we hold, including its source, purpose, period of processing and the entities it is shared with.
- Right to rectification — update or correct inaccuracies, and ask us to add additional information.
- Right to erasure — ask us to delete your personal information in certain situations.
- Right to restriction of processing in specific situations.
- Right to data portability in a structured, commonly used and machine-readable format.
- Right to object to the use of your information, e.g. for direct marketing.
- Right to complain to the supervisory authority. In Uganda this is the Personal Data Protection Office (PDPO) under NITA-U; complaints may be submitted at pdpo.go.ug.
14. Data Security
Weaf prioritizes the security of the information we handle and complies with the Data Protection and Privacy Act. We employ various measures to keep your data safe, such as:
- Confidentiality agreements for all employees and recipients of your data, who process data only as outlined in our policy.
- Enforcing an Information Security Policy for all consultants and authorized enterprises, applied to all stored information and related hardware and software.
- Reviewing and implementing security practices annually with executive approval and staff communication.
- Mandatory privacy and security training for employees and consultants.
- Robust authentication and authorization controls.
- Continuous monitoring and analysis to address new threats and vulnerabilities.
- Regularly updating servers, workstations and gateway devices with the latest antivirus definitions.
- Conducting yearly risk assessments.
15. Legal Compliance
We confirm compliance with relevant data protection laws, such as Uganda's Data Protection and Privacy Act.
16. Changes to This Policy
Users will be notified of any changes to this data policy as soon as is practical.
17. Applicable Law
The applicable law is the law of Uganda.
18. Contact Us
If you have any questions about Weaf's data policy or security practices, please contact us:
WEAF Company Uganda Ltd
Ham Towers, Wandegeya, Kampala, Uganda
Phone: +256-756-508361
Email: info@weafcompany.com
Website: weafcompany.com