Skip to content
LoanTabsLoanTabs

Legal

Data Processing Terms

The commitments we make when we process personal data on behalf of lending institutions that use LoanTabs.

Last updated: 30 September 2026

1. Scope and roles

These Data Processing Terms (“DPT”) form part of the agreement between Powersoft Company Ltd (“we”, the “Processor”) and the institution that subscribes to LoanTabs (“you”, the “Controller”), and apply to the personal data in Customer Data — such as borrower, guarantor, member, staff, loan, savings and accounting records — that we process on your behalf when providing the Services (“Customer Personal Data”). They apply automatically when you accept our Terms of Service; a signed copy is available on request.

You are the controller (or a processor acting for your own client) and we are the processor, or your sub-processor. This DPT does not cover personal data we control ourselves, which is described in our Privacy Policy. It is intended to meet the requirements of Article 28 of the EU and UK GDPR, Uganda’s Data Protection and Privacy Act, 2019, and similar laws (“Data Protection Laws”), and the service-provider requirements of US state privacy laws such as the CCPA/CPRA.

2. Our obligations

We will:

  • process Customer Personal Data only on your documented instructions, which are these DPT, the Terms and your use of the Services, unless the law requires otherwise (and we will tell you first where permitted);
  • not sell or share Customer Personal Data, not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing the Services, and not combine it with other data except as the law allows;
  • ensure everyone authorised to process it is bound by confidentiality;
  • apply the security measures in the Annex below;
  • tell you if we believe an instruction breaches Data Protection Laws; and
  • give you the information needed to show compliance, and allow and contribute to reasonable audits (see “Audits”).

You are responsible for the lawfulness of your instructions and Customer Personal Data, including providing notices to, and obtaining any consents from, the individuals concerned.

3. Sub-processors

You give us general authorisation to use sub-processors, such as hosting, email, payment and AI model providers, under written terms that give the same level of protection as this DPT. We remain responsible for their performance. Our current list is available on request from support@loantabs.com. We will give at least 30 days’ notice of a new sub-processor by email or in the product; you may object on reasonable data-protection grounds within that period, and if we cannot resolve the objection you may cancel the affected Services and receive a pro-rata refund of prepaid fees for the remaining term.

4. Data subject requests and assistance

Taking into account the nature of the processing, we will help you respond to requests from individuals to exercise their rights, mostly through features of the Services. If an individual contacts us directly about Customer Personal Data, we will refer them to you and will not respond substantively without your instruction unless the law requires. We will reasonably help with data-protection impact assessments and consultations with regulators, taking into account the information available to us.

5. Personal data breaches

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and give the information we reasonably have to help you meet your own notification duties. We will take reasonable steps to contain and investigate the breach.

6. International transfers

You authorise us to transfer and process Customer Personal Data in Uganda and in the other countries where we and our sub-processors operate. Where Customer Personal Data subject to the EU GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision:

  • the European Commission’s Standard Contractual Clauses (Module Two: controller to processor, and Module Three where you are a processor) are incorporated by reference, with the optional docking clause, Clause 17 governed by the law of Ireland, Clause 18 courts of Ireland, and the Annex information supplied by this DPT;
  • for UK transfers, the UK International Data Transfer Addendum to those clauses applies, governed by the law of England and Wales; and
  • for Swiss transfers, references to the GDPR include the Swiss FADP and the competent authority is the Swiss FDPIC.

For transfers under other laws, such as those of Uganda, Kenya, Nigeria and South Africa, we apply an equivalent contractual safeguard or other lawful mechanism.

7. Return and deletion

You can export Customer Personal Data at any time using the Services. After your subscription ends we will make your data available for export for 30 days, then delete or irreversibly anonymise it within a further 90 days, except for backups that are overwritten on their normal cycle and anything we must keep by law, which stays protected by this DPT. On request we will confirm deletion in writing.

8. Audits

On reasonable written request, no more than once a year unless a breach or regulator requires otherwise, we will provide the information reasonably needed to show compliance with this DPT, such as written answers to a security questionnaire. If that is not enough, you may carry out an audit on 30 days’ notice, during business hours, under confidentiality, without unreasonably disrupting our operations or other customers, and at your own cost.

9. Liability and precedence

Each party’s liability under this DPT is subject to the limitations in the Terms of Service, except where the law or the Standard Contractual Clauses provide otherwise. If this DPT conflicts with the Terms or the Privacy Policy on the processing of Customer Personal Data, this DPT prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.

10. Annex: details of processing and security

Details of processing

ItemDescription
Subject matter and natureHosting, storage, retrieval, calculation, display, back-up, analysis (including AI-assisted analysis you request) and transmission of Customer Personal Data to provide LoanTabs.
DurationThe subscription term plus the return and deletion period above.
PurposeProviding, securing, supporting and improving the reliability of the Services for you.
Categories of individualsYour borrowers, guarantors, members, next of kin and referees, staff and other users, and their contacts.
Types of personal dataNames, contact details, identification numbers and documents, addresses, employment and income details, loan, savings, repayment and transaction records, collateral details, photos and uploaded documents, user credentials and activity logs.
Special-category dataNot intended. You must not enter it unless you have a lawful basis and tell us first.
FrequencyContinuous, for the subscription term.
Competent authorityFor the EU SCCs, the supervisory authority of the exporter’s member state, or the authority of the Controller’s establishment.

Security measures

  • Encryption of data in transit.
  • Logical separation of each customer’s workspace (multi-tenant isolation).
  • Role-based access controls and approval workflows for customers’ users; least-privilege access for our staff.
  • Audit logging of loan and accounting events.
  • Regular backups of customer data and procedures to restore them.
  • Confidentiality obligations and data-protection awareness for personnel with access.
  • Vulnerability handling and incident response procedures, as described on our Security & Compliance page.

Contact for data-protection matters

Powersoft Company Ltd
Ntinda, Kampala, Uganda
Email: support@loantabs.com