1. Scope and controller
SPEKITA GENERAL TRADERS CO LTD controls the personal data processed through SpekitaAgent. The app is a restricted work tool used by authorized agents and staff in Tanzania to onboard customers, record informed consent, prepare financing records and contracts, collect an initial payment, enroll an eligible financed device and support the customer lifecycle.
2. Information we collect
Depending on the authorized workflow, we process:
- Customer identity and contact details: full name, phone and alternate phone numbers, date of birth, gender, residential address and postcode.
- Government-identification data: NIDA or other identification number and images of the identity document.
- KYC evidence: a customer-with-product photo, front/right/left face and liveness-challenge images, customer-and-agent joint photo, consent records, customer and agent signatures, and the generated contract PDF.
- Guarantor identity, contact, address and relationship details.
- Device and financing data: brand, model, IMEI, price, deposit, loan amount, term, repayment amounts, payment status, enrollment and device-management status.
- Agent account, phone number, assigned work scope, timestamps, actions and security/audit records.
- App and device diagnostics needed to keep the service secure and reliable.
3. Why we use the information
- Verify identity, eligibility, phone ownership and the completeness of a KYC application.
- Prepare and administer the financing agreement, initial payment and repayments.
- Link the correct customer, agreement, product and IMEI, and enroll/manage the financed device under the agreement.
- Prevent identity fraud, duplicate onboarding, unauthorized device substitution and contract abuse.
- Provide customer support, investigate incidents, keep audit records and meet accounting, contractual and legal duties.
4. Camera, face images, government ID and IMEI
Before collection, the app presents a prominent notice and requires the agent to confirm that it was explained to the customer and that the customer agreed to continue. The camera is used only when an authorized agent starts an ID, face/liveness or IMEI-scan step. Identity and face images are sensitive KYC evidence and are not used to identify people outside the submitted application, for advertising, or to train advertising profiles.
Image quality and face-presence checks use the bundled Google ML Kit library on the device. Input images are processed on the device and are not sent to Google by ML Kit. Google may receive device/app information, per-installation identifiers, configuration, performance, event and error metrics for diagnostics and analytics. Approved KYC evidence is then encrypted in transit and uploaded to private Spekita storage.
IMEI is linked to personal and financing data only for the enterprise Device Owner/managed-device workflow, contract administration, support, fraud prevention and enforcement of the financed-device agreement. It is not used for advertising.
5. Sharing and public access
We do not sell personal data or use it for advertising. Data is shared only with authorized Spekita personnel and processors needed to deliver the service, including secure hosting/database/storage, SMS and phone verification, payment processing, contract delivery and enterprise device-management providers. We may disclose limited information to regulators, courts or law-enforcement authorities where legally required. Government IDs, face images, signatures, contracts and financing records are never made publicly available.
6. Retention
Incomplete application drafts and temporary capture files are removed when they are no longer needed. Submitted KYC, contract, payment, device, fraud-prevention and audit records are retained for the duration of the application or agreement and thereafter only for the period required by Tanzanian law, accounting, dispute, security and legitimate audit obligations. When a record no longer has a lawful or operational retention purpose, it is deleted or irreversibly de-identified. A deletion request may therefore result in immediate deletion of some data and restricted retention of records that must lawfully remain.
7. Security and access
We use encrypted network connections, private KYC storage, role-based access, row-level database controls, authenticated staff accounts, audit records and restricted administrative systems. Agents must protect customer information and must not copy or use it outside approved Spekita workflows. No internet service is risk-free, but we review and improve these controls as the service changes.
8. Customer and agent choices
A customer may decline the KYC notice or camera collection and exit the workflow, although Spekita may then be unable to process the application. Subject to identity verification and legal limits, a person may ask to access, correct, export or delete personal data, or raise a privacy concern. Authorized agents may ask an administrator to correct an accidental submission error while preserving the audit trail.
9. Contact and requests
Use our data request and account-deletion page, email support@spekita.com, or call +255 652 772 743. Do not email passwords, PINs, OTPs, full bank details or unrequested identity-document images. We verify identity and authority before fulfilling a request.
Changes to This Policy
We may update this policy when the service, legal requirements, or our data practices change. The current version will be published on this page with its effective date.
