RC Mbarara
Legal & Data Protection
Back to Home
Privacy Policy
How RC Mbarara collects, uses & protects your personal data
Last updated 15 July 2026 Uganda Data Protection & Privacy Act, 2019
1. Introduction & Scope

Rotary Club of Mbarara ("RC Mbarara", "the Club", "we", "us") respects your privacy and is committed to protecting the personal data of its members, officers, guests, and other users of the member portal and admin console (together, the "Platform"). This Privacy Policy explains what personal data we collect, why, how we use and protect it, and the rights available to you under the Data Protection and Privacy Act, 2019 (Act No. 9 of 2019) and the Data Protection and Privacy Regulations, 2021 of Uganda, read together with Article 27 of the Constitution of the Republic of Uganda (right to privacy).

This Policy applies to personal data processed through the Platform, whether you are a Member, an elected Officer/Administrator, a Guest checking in at a session or project, or a visitor to a publicly shared page (e.g. a shared news post).

2. Who We Are — the Data Controller

For the purposes of the Data Protection and Privacy Act, 2019, Rotary Club of Mbarara is the Data Controller of the personal data processed through the Platform.

Rotary Club of Mbarara
[club postal/physical address — set in Admin → Settings]
Email: [club contact email — set in Admin → Settings]

Our nominated data protection contact point, who handles enquiries and requests relating to your personal data, is the Club Secretary, reachable at [club contact email — set in Admin → Settings].

3. What Personal Data We Collect

We collect the following categories of personal data, generally provided directly by you or recorded by an authorised officer in the course of Club administration:

  • Identity & contact data: full name, phone number, WhatsApp number, email address, physical/postal address, date of birth, membership/classification category, profile photo.
  • Membership & participation data: attendance and check-in records (including timestamp of check-in and, where applicable, the session/project it relates to), make-up visit records, apology submissions, mentorship pairings, awards and recognitions, guide/tour progress.
  • Financial data: dues, raffle and category payment records, payment status and method, mobile money phone number used for a transaction, and transaction references. Full card numbers and mobile money PINs are never collected or stored by the Club — these are handled directly by our payment processors (Pesapal, MTN Mobile Money).
  • Content you submit: blog posts, comments, project sign-ups, TRF (The Rotary Foundation) giving records, documents you upload.
  • Technical data: authentication tokens/cookies, device and browser information, IP address, and app-installation identifiers used to keep you securely signed in and to deliver push notifications.
  • Guest data: for visitors checking in at a fellowship session or project, we collect name and contact details necessary to record attendance and follow up on membership interest.

Exception — the Suggestion Box. If you submit feedback through the in-portal Suggestion Box, we deliberately collect none of the categories above for that submission: no name, member ID, account link, or IP address is captured or stored alongside your message. Only the category and message text you type are saved. This means the submission cannot be traced back to you by anyone, including Club administrators and System Administrators — there is no reply feature for this reason, and no request under Section 10 (Your Rights) can be actioned against an individual Suggestion Box entry, because we have no way of identifying which entry, if any, came from you.

We do not knowingly collect special/sensitive categories of personal data (e.g. health, biometric, or religious data) through the Platform beyond what a member voluntarily discloses (for example, in a make-up or apology note), and we ask that such disclosures be limited to what is necessary.

4. How We Collect Your Data

We collect personal data when you: register as a Member or check in as a Guest; log in using a one-time PIN or verification token; update your Profile; check in to a fellowship session or service project; submit an apology, make-up, or TRF contribution; make or record a payment; interact with announcements, calendar events, or blog posts; or when an authorised Club officer enters or updates your record as part of routine Club administration (e.g. onboarding a new member).

6. How We Use Your Data

We use your personal data to: verify your identity and log you into the Platform; record and calculate attendance, standing, and make-up credit; process and reconcile dues, raffle, category, and TRF payments; send session, event, and payment reminders and receipts by WhatsApp, email, or push notification; administer mentorship pairings, awards, and recognitions; publish Club announcements, news, and calendar events; maintain an audit trail of administrative actions for accountability; and, where relevant, report aggregate or required membership/attendance information to the Rotary District and Rotary International in line with RI's own governance requirements.

7. Data Sharing & Third Parties

We do not sell your personal data. We share it only as necessary with:

  • Payment processors — Pesapal Limited and MTN Uganda, to process card and mobile-money payments you initiate;
  • Communication providers — our WhatsApp Business messaging gateway and email/SMTP delivery provider, to send reminders, OTPs, and receipts;
  • Productivity integrations — Google Calendar/Drive, where an administrator chooses to sync Club scheduling or documents through their own authorised Google account;
  • Rotary International and District — where membership, attendance, or service data must be reported under RI's own bylaws and reporting requirements;
  • Authorised Club officers — Secretary, Treasurer, Sergeant-at-Arms, Project Leads, and the System Administrator, strictly on a need-to-know basis to perform their Club duties, governed by role-based access controls;
  • Regulators or law enforcement — where disclosure is required by Ugandan law or a valid court order.
8. Cross-Border Data Transfer

Some of the third-party services described above (e.g. cloud email delivery, WhatsApp messaging infrastructure, Google services) may process data on servers located outside Uganda. Where personal data is transferred outside Uganda, we take steps consistent with Section 19 of the Data Protection and Privacy Act, 2019 to ensure the receiving party is subject to a law, binding corporate rules, or contractual clauses that provide an adequate level of protection substantially similar to that under Ugandan law, or that you have consented to the transfer.

9. How We Protect Your Data

We apply technical and organisational measures appropriate to the risk, including: hashed/salted authentication (no plaintext PINs or passwords stored), single-use time-limited login tokens rather than long-lived passwords for members, role-based access control limiting administrators to the records their role requires, a full audit log of sensitive administrative actions, view-only/watermarked access controls on restricted Club documents, HTTPS encryption in transit, and periodic review of third-party integrations. No system is completely immune to risk, and we continuously work to improve these safeguards.

10. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy: active members' records are retained for the duration of membership and thereafter for a reasonable period to satisfy Club governance, historical, and financial record-keeping needs (in line with the Club's own records policy); Guest check-in data used for follow-up on membership interest is retained for a limited period and then archived or deleted if no membership results; financial/payment records are retained for the period required by applicable Ugandan tax and accounting practice. Where you exercise your right to erasure (see below) and no overriding legal or legitimate ground for retention applies, we will delete or irreversibly anonymise your data.

11. Your Rights as a Data Subject

Under the Data Protection and Privacy Act, 2019, you have the right to:

  • Access the personal data we hold about you (you can view most of it directly in your Profile, and may request a full copy from us);
  • Correct or update inaccurate or outdated personal data;
  • Object to the processing of your personal data for a particular purpose, on reasonable grounds;
  • Withdraw consent at any time where processing is based on consent (e.g. push notifications), without affecting the lawfulness of processing before withdrawal;
  • Request erasure of personal data that is inaccurate, excessive, unlawfully obtained, or no longer necessary for the purpose it was collected;
  • Data portability — request your data in a structured, commonly used format where technically feasible;
  • Prevent processing likely to cause unwarranted substantial damage or distress to you or another individual;
  • Lodge a complaint with us, and if unresolved, with the National Information Technology Authority – Uganda (NITA-U), Personal Data Protection Office — the statutory regulator for data protection in Uganda (www.nita.go.ug).

To exercise any of these rights, contact us using the details in Section 17 below. We will respond within a reasonable time and, in any event, within the timeframes required by the Act and its Regulations. We may need to verify your identity before actioning a request.

Note on the Suggestion Box: because Suggestion Box entries are collected with no identifying information (see Section 4), we are unable to locate, correct, or erase a specific entry on your behalf, as we have no way to link any entry to you.

12. Children's & Young Members' Data

The Platform is primarily intended for adult Rotarians. Where it is extended to members of an affiliated Interact club or other members under the age of 18, we collect and process their personal data only with the involvement of a parent/guardian or the supervising Club officer responsible for that youth programme, and we limit the data collected to what is necessary for participation and safety purposes.

13. Cookies, Local Storage & Notifications

The Platform uses strictly necessary cookies (e.g. your login/session token) to keep you signed in securely, and browser local storage to remember interface preferences (such as which onboarding tour or guide tip you have already seen, and which award celebrations you have viewed) so they are not repeated. If you enable browser or app push notifications, we use that permission only to deliver session reminders, event alerts, and award notifications — you can revoke this permission at any time through your device or browser settings, or the in-portal notification toggle.

14. Automated Processing

The Platform automatically calculates figures such as attendance percentage and makeup credit from the records described above. These calculations support — but do not replace — human review: check-ins are reviewed and approved or rejected by an authorised officer, and no purely automated decision is made about your Club standing without the opportunity for human review.

15. Data Breach Notification

If a breach of security leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, your personal data, and that breach is likely to result in a risk to your rights, we will notify the National Information Technology Authority – Uganda and affected individuals without undue delay, in accordance with the Data Protection and Privacy Act, 2019 and its Regulations.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or the law. The "Last updated" date at the top of this page will change accordingly, and material changes will be flagged via an in-portal announcement.

17. Contact Us / Lodge a Complaint

For any question, request, or concern about this Privacy Policy or how your personal data is handled, contact:

Rotary Club of Mbarara — Data Protection Contact: the Club Secretary
[club postal/physical address — set in Admin → Settings]
Email: [club contact email — set in Admin → Settings]

If you are not satisfied with our response, you may lodge a complaint with:

National Information Technology Authority – Uganda (NITA-U)
Personal Data Protection Office
Kampala, Uganda  |  www.nita.go.ug