Privacy Policy
Your privacy is important to us. This policy complies with the Tanzania Data Protection Act and international data protection standards
Quick Navigation
1. Introduction
Our commitment to your privacy
CitiOne("we", "our", or "us") is committed to protecting your privacy in accordance with the Tanzania Personal Data Protection Act No. 11 of 2022 and international data protection standards. This Privacy Policy explains how your personal information is collected, used, and disclosed by CitiOne.
This Privacy Policy applies to our website, and its associated subdomains (collectively, our "Service") alongside our application, CitiOne. By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.
🔒 We comply with the Tanzania Personal Data Protection Act, GDPR, and maintain the highest standards of data protection as regulated by the Personal Data Protection Commission of Tanzania.
2. Information We Collect
Types of data we gather
Information You Provide
Data collected when you:
- Create an account
- Make a purchase
- Subscribe to newsletter
- Contact support
- Submit reviews
Automatic Collection
Data collected automatically:
- Log & browser data
- Device information
- Location data
- Usage patterns
- Cookies & tracking
3. How We Use Your Information
Purpose of data processing
We use the information we collect for the following purposes:
Provide, operate, and maintain our Service
Process transactions and send order confirmations
Send important updates about your account
Respond to your questions and provide support
Send marketing communications (with consent)
Analyze usage to improve our services
Detect and prevent fraudulent activities
Comply with legal obligations
We process your data based on legitimate interests, contract fulfillment, legal obligations under Tanzanian law, or your explicit consent as required by the Tanzania Personal Data Protection Act.
6. Data Security
How we protect your information
We take the security of your personal data seriously and implement industry-standard measures to protect your information.
Our Security Measures Include:
Encryption
SSL/TLS encryption for data in transit
Access Control
Strict access controls and authentication
Monitoring
Regular security audits and monitoring
Backup
Secure backup and disaster recovery
Training
Employee security awareness training
Updates
Regular security patches and updates
While we implement robust security measures, no system is completely secure. We continuously work to improve our security practices.
7. Data Retention
How long we keep your data
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy.
Active Account Data
Retained while your account is active and for legitimate business purposes
After Account Deletion
Most data deleted immediately, some retained for legal compliance
⏰ Retention periods vary based on data type, legal requirements, and business needs.
8. Your Privacy Rights
Control over your personal data
You have specific rights regarding your personal information. We respect these rights and provide mechanisms to exercise them.
Access
Request copies of your data
Rectification
Correct inaccurate information
Erasure
Delete your personal data
Restriction
Limit data processing
Portability
Transfer data to another service
Objection
Object to data processing
To exercise any of these rights, contact us using the information below. We'll respond within 30 days.
9. Tanzania Legal Compliance
Our compliance with local regulations
We operate in full compliance with the Tanzania Personal Data Protection Act No. 11 of 2022and other relevant Tanzanian legislation.
Key Compliance Areas:
Data Controller Registration
We are registered with the Personal Data Protection Commission of Tanzania
Local Data Storage
Personal data of Tanzanian residents is stored within Tanzania or in countries with adequate data protection laws
Consent Requirements
We obtain explicit consent for data processing as required by Tanzanian law
Data Subject Rights
We honor all rights granted under the Tanzania Personal Data Protection Act
Regulatory Authority:
For complaints or inquiries about data protection in Tanzania, you may contact:
Personal Data Protection Commission
P.O. Box 2831, Dodoma, Tanzania
Email: info@pdpc.go.tz
10. Third-Party Services
External links and services
Our Service may contain links to third-party websites, services, or content that we don't control or operate.
Important Notice
- • We're not responsible for third-party privacy practices
- • Review privacy policies of sites you visit
- • Third-party terms and conditions apply
- • We don't endorse external content
11. Children's Privacy
Protection for minors
In compliance with Tanzanian law, our Service requires parental consent for users under 18 years of age. We do not knowingly collect personal information from minors without appropriate parental or guardian consent.
Parent/Guardian Notice:
In accordance with Tanzanian law, we do not collect data from children under 18 years without parental consent. If you believe your child has provided us with personal information, please contact us immediately. We will take steps to remove such information from our servers.
We encourage parents to monitor their children's online activities and help enforce this policy by instructing them never to provide personal information without permission.
12. Changes to This Privacy Policy
Policy updates and notifications
We may update our Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations.
Update Process
- • Policy updates posted on this page
- • "Last updated" date changed
- • Email notification for material changes
- • 30-day notice period when applicable
By continuing to use our Service after changes become effective, you acknowledge and agree to the updated Privacy Policy.
Contact Our Data Protection Officer
If you have any questions about this Privacy Policy, wish to exercise your rights under the Tanzania Personal Data Protection Act, or need to contact our Data Protection Officer, please reach out to us:
We respond to privacy inquiries within the timeframe required by Tanzanian law (30 days)