Rotary Club of Mbarara ("RC Mbarara", "the Club", "we", "us") respects your privacy and is committed to protecting the personal data of its members, officers, guests, and other users of the member portal and admin console (together, the "Platform"). This Privacy Policy explains what personal data we collect, why, how we use and protect it, and the rights available to you under the Data Protection and Privacy Act, 2019 (Act No. 9 of 2019) and the Data Protection and Privacy Regulations, 2021 of Uganda, read together with Article 27 of the Constitution of the Republic of Uganda (right to privacy).
This Policy applies to personal data processed through the Platform, whether you are a Member, an elected Officer/Administrator, a Guest checking in at a session or project, or a visitor to a publicly shared page (e.g. a shared news post).
For the purposes of the Data Protection and Privacy Act, 2019, Rotary Club of Mbarara is the Data Controller of the personal data processed through the Platform.
Rotary Club of Mbarara
[club postal/physical address — set in Admin → Settings]
Email: [club contact email — set in Admin → Settings]
Our nominated data protection contact point, who handles enquiries and requests relating to your personal data, is the Club Secretary, reachable at [club contact email — set in Admin → Settings].
We collect the following categories of personal data, generally provided directly by you or recorded by an authorised officer in the course of Club administration:
- Identity & contact data: full name, phone number, WhatsApp number, email address, physical/postal address, date of birth, membership/classification category, profile photo.
- Membership & participation data: attendance and check-in records (including timestamp of check-in and, where applicable, the session/project it relates to), make-up visit records, apology submissions, mentorship pairings, awards and recognitions, guide/tour progress.
- Financial data: dues, raffle and category payment records, payment status and method, mobile money phone number used for a transaction, and transaction references. Full card numbers and mobile money PINs are never collected or stored by the Club — these are handled directly by our payment processors (Pesapal, MTN Mobile Money).
- Content you submit: blog posts, comments, project sign-ups, TRF (The Rotary Foundation) giving records, documents you upload.
- Technical data: authentication tokens/cookies, device and browser information, IP address, and app-installation identifiers used to keep you securely signed in and to deliver push notifications.
- Guest data: for visitors checking in at a fellowship session or project, we collect name and contact details necessary to record attendance and follow up on membership interest.
Exception — the Suggestion Box. If you submit feedback through the in-portal Suggestion Box, we deliberately collect none of the categories above for that submission: no name, member ID, account link, or IP address is captured or stored alongside your message. Only the category and message text you type are saved. This means the submission cannot be traced back to you by anyone, including Club administrators and System Administrators — there is no reply feature for this reason, and no request under Section 10 (Your Rights) can be actioned against an individual Suggestion Box entry, because we have no way of identifying which entry, if any, came from you.
We do not knowingly collect special/sensitive categories of personal data (e.g. health, biometric, or religious data) through the Platform beyond what a member voluntarily discloses (for example, in a make-up or apology note), and we ask that such disclosures be limited to what is necessary.
We collect personal data when you: register as a Member or check in as a Guest; log in using a one-time PIN or verification token; update your Profile; check in to a fellowship session or service project; submit an apology, make-up, or TRF contribution; make or record a payment; interact with announcements, calendar events, or blog posts; or when an authorised Club officer enters or updates your record as part of routine Club administration (e.g. onboarding a new member).
In line with Section 3 of the Data Protection and Privacy Act, 2019, we process your personal data only where one or more of the following applies:
- Contract/membership administration — processing necessary to administer your membership of Rotary Club of Mbarara, a voluntary, non-profit association whose Constitution and By-Laws you agree to on joining;
- Consent — for example, where you opt in to push notifications, or where a Guest voluntarily provides contact details at check-in;
- Legitimate interest — such as maintaining attendance and financial records necessary for good governance, recognition, and continuity of the Club, balanced against your rights and freedoms;
- Legal obligation — where processing is required to comply with Ugandan law (e.g. financial record-keeping) or the constitutional obligations of Rotary International and the District to which the Club belongs.
All processing adheres to the data protection principles in the Act: data is collected for specified, explicit and legitimate purposes; is adequate, relevant and not excessive; is kept accurate and up to date; is retained only as long as necessary; and is processed lawfully, fairly, and transparently.
We use your personal data to: verify your identity and log you into the Platform; record and calculate attendance, standing, and make-up credit; process and reconcile dues, raffle, category, and TRF payments; send session, event, and payment reminders and receipts by WhatsApp, email, or push notification; administer mentorship pairings, awards, and recognitions; publish Club announcements, news, and calendar events; maintain an audit trail of administrative actions for accountability; and, where relevant, report aggregate or required membership/attendance information to the Rotary District and Rotary International in line with RI's own governance requirements.
We do not sell your personal data. We share it only as necessary with:
- Payment processors — Pesapal Limited and MTN Uganda, to process card and mobile-money payments you initiate;
- Communication providers — our WhatsApp Business messaging gateway and email/SMTP delivery provider, to send reminders, OTPs, and receipts;
- Productivity integrations — Google Calendar/Drive, where an administrator chooses to sync Club scheduling or documents through their own authorised Google account;
- Rotary International and District — where membership, attendance, or service data must be reported under RI's own bylaws and reporting requirements;
- Authorised Club officers — Secretary, Treasurer, Sergeant-at-Arms, Project Leads, and the System Administrator, strictly on a need-to-know basis to perform their Club duties, governed by role-based access controls;
- Regulators or law enforcement — where disclosure is required by Ugandan law or a valid court order.
Some of the third-party services described above (e.g. cloud email delivery, WhatsApp messaging infrastructure, Google services) may process data on servers located outside Uganda. Where personal data is transferred outside Uganda, we take steps consistent with Section 19 of the Data Protection and Privacy Act, 2019 to ensure the receiving party is subject to a law, binding corporate rules, or contractual clauses that provide an adequate level of protection substantially similar to that under Ugandan law, or that you have consented to the transfer.
We apply technical and organisational measures appropriate to the risk, including: hashed/salted authentication (no plaintext PINs or passwords stored), single-use time-limited login tokens rather than long-lived passwords for members, role-based access control limiting administrators to the records their role requires, a full audit log of sensitive administrative actions, view-only/watermarked access controls on restricted Club documents, HTTPS encryption in transit, and periodic review of third-party integrations. No system is completely immune to risk, and we continuously work to improve these safeguards.
We retain personal data only for as long as necessary for the purposes described in this Policy: active members' records are retained for the duration of membership and thereafter for a reasonable period to satisfy Club governance, historical, and financial record-keeping needs (in line with the Club's own records policy); Guest check-in data used for follow-up on membership interest is retained for a limited period and then archived or deleted if no membership results; financial/payment records are retained for the period required by applicable Ugandan tax and accounting practice. Where you exercise your right to erasure (see below) and no overriding legal or legitimate ground for retention applies, we will delete or irreversibly anonymise your data.
Under the Data Protection and Privacy Act, 2019, you have the right to:
- Access the personal data we hold about you (you can view most of it directly in your Profile, and may request a full copy from us);
- Correct or update inaccurate or outdated personal data;
- Object to the processing of your personal data for a particular purpose, on reasonable grounds;
- Withdraw consent at any time where processing is based on consent (e.g. push notifications), without affecting the lawfulness of processing before withdrawal;
- Request erasure of personal data that is inaccurate, excessive, unlawfully obtained, or no longer necessary for the purpose it was collected;
- Data portability — request your data in a structured, commonly used format where technically feasible;
- Prevent processing likely to cause unwarranted substantial damage or distress to you or another individual;
- Lodge a complaint with us, and if unresolved, with the National Information Technology Authority – Uganda (NITA-U), Personal Data Protection Office — the statutory regulator for data protection in Uganda (www.nita.go.ug).
To exercise any of these rights, contact us using the details in Section 17 below. We will respond within a reasonable time and, in any event, within the timeframes required by the Act and its Regulations. We may need to verify your identity before actioning a request.
Note on the Suggestion Box: because Suggestion Box entries are collected with no identifying information (see Section 4), we are unable to locate, correct, or erase a specific entry on your behalf, as we have no way to link any entry to you.
The Platform is primarily intended for adult Rotarians. Where it is extended to members of an affiliated Interact club or other members under the age of 18, we collect and process their personal data only with the involvement of a parent/guardian or the supervising Club officer responsible for that youth programme, and we limit the data collected to what is necessary for participation and safety purposes.
The Platform uses strictly necessary cookies (e.g. your login/session token) to keep you signed in securely, and browser local storage to remember interface preferences (such as which onboarding tour or guide tip you have already seen, and which award celebrations you have viewed) so they are not repeated. If you enable browser or app push notifications, we use that permission only to deliver session reminders, event alerts, and award notifications — you can revoke this permission at any time through your device or browser settings, or the in-portal notification toggle.
The Platform automatically calculates figures such as attendance percentage and makeup credit from the records described above. These calculations support — but do not replace — human review: check-ins are reviewed and approved or rejected by an authorised officer, and no purely automated decision is made about your Club standing without the opportunity for human review.
If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, your personal data, and that breach is likely to result in a risk to your rights, we will notify the National Information Technology Authority – Uganda and affected individuals without undue delay, in accordance with the Data Protection and Privacy Act, 2019 and its Regulations.
We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or the law. The "Last updated" date at the top of this page will change accordingly, and material changes will be flagged via an in-portal announcement.
For any question, request, or concern about this Privacy Policy or how your personal data is handled, contact:
Rotary Club of Mbarara — Data Protection Contact: the Club Secretary
[club postal/physical address — set in Admin → Settings]
Email: [club contact email — set in Admin → Settings]
If you are not satisfied with our response, you may lodge a complaint with:
National Information Technology Authority – Uganda (NITA-U)
Personal Data Protection Office
Kampala, Uganda | www.nita.go.ug