1. Scope and who we are
This Privacy Policy and Notice (“Notice”) applies to personal data processed by Eylorin Technologies Limited (“Eylorin”, “we”, “us” or “our”) through our websites, mobile applications, software platforms, APIs, support channels, events, business relationships and other products or services that link to or expressly adopt this Notice (together, the “Services”).
It covers users, prospective users, merchants, business customers, customer personnel, developers, suppliers, partners, healthcare personnel, investors, website visitors, contributors and other individuals who interact with Eylorin. Workforce and job-applicant information may be addressed by a separate notice.
This Notice does not replace a product-specific or point-of-collection notice. Where a Service displays a shorter or more specific notice, both apply. The more specific notice governs that processing to the extent of a conflict, unless law requires otherwise.
| Company information | Details |
|---|---|
| Legal name | Eylorin Technologies Limited |
| Registration number | 80020001529212 |
| Tax identification number | 1015397771 |
| Principal address | Plot 3 Bata Close, 5th Street Industrial Area, Kampala, Uganda |
| Postal address | P.O. Box 200473, Kampala, Uganda |
| Privacy contact | legal-compliance@eylorin.com |
| Telephone and website | +256 393 104 233; www.eylorin.com |
| Important role distinction. Eylorin may provide technology to a bank, broker, merchant, healthcare provider, employer, public body or another customer. That organisation may decide why and how your data is used. Its privacy notice may therefore apply in addition to this Notice. |
|---|
2. Our role: controller, processor or technology provider
2.1 When Eylorin is a controller
Eylorin acts as a controller where it decides the purposes and essential means of processing. Examples include:
creating and securing an Eylorin Account;
operating our Website and public communications;
administering Huddle user profiles, service integrity and platform safety;
managing customer, supplier and partner relationships;
preventing fraud, cyber abuse and policy violations;
meeting Eylorin’s legal, regulatory and corporate obligations; and
communicating about our Services.
2.2 When Eylorin is a processor
Eylorin may act as a processor or service provider where it handles data for a business customer under documented instructions. For example, Kinetic Transactions may host merchant customer or employee records, PulseHub Healthcare may process records for a healthcare organisation, and an enterprise system may process a customer’s operational data.
In that situation, the customer is normally responsible for the primary privacy notice, lawful basis, instructions and response to individual rights requests. Eylorin will assist as required by contract and law.
2.3 Independent participants
Banks, mobile-money operators, payment networks, brokers, securities exchanges, custodians, merchants, healthcare providers, app stores, communications networks, regulators and other participants may act as independent controllers for their own activities. Their privacy notices and legal duties apply to their processing.
3. Privacy principles
Our privacy programme is designed around the following principles:
Lawfulness, fairness and transparency: process personal data on a valid basis and explain material uses clearly.
Purpose limitation: collect data for specified, explicit and legitimate purposes and assess compatibility before materially reusing it.
Data minimisation: limit collection, access and disclosure to what is relevant and reasonably necessary.
Accuracy: take reasonable steps to keep data accurate, complete and current.
Storage limitation: retain identifiable data only as long as needed for the stated purpose, legal obligations, disputes or legitimate records.
Security and confidentiality: apply technical and organisational safeguards proportionate to risk.
Accountability: document material decisions, assign responsibilities, conduct appropriate assessments and maintain evidence of compliance.
Privacy by design and default: include privacy controls in product design, engineering, testing and change management.
Respect for user choice: provide meaningful controls where processing depends on consent, preference or audience selection.
4. Personal data we collect
We may collect the categories below. We do not collect every category from every person.
| Category | Examples |
|---|---|
| Identity and verification | Name, date of birth, photograph, signature, nationality, identification number or document, tax or business identifiers, liveness or verification results, eligibility and screening results where lawful |
| Contact and profile | Email, telephone number, address, username, display name, profile image, language, country, organisation, role, biography, preferences and Account settings |
| Financial and transaction | Payment tokens or masked details, bank or mobile-money references, account or wallet identifiers, balances where applicable, amount, currency, merchant, counterparty, time, status, refund, chargeback and dispute data |
| Securities and investment | Investor profile, brokerage or custody references, orders, holdings, market activity, suitability or appropriateness responses, tax residence and regulatory classification |
| Retail and merchant | Products, prices, inventory, receipts, invoices, customers, suppliers, branches, staff roles, tax references, device and till activity, and EFRIS-related records |
| Healthcare and care operations | Appointment, provider, service, workflow, communications and health-related information entered or generated in an authorised PulseHub context |
| Voice and cultural material | Audio recordings, transcripts, translations, language or dialect labels, contributor details, consent and licence records, annotations, moderation history and provenance |
| Huddle communications | Messages, attachments, reactions, Stories, Files, selected call content where a recording feature is used, profile and group Content, reports and user-selected sharing settings |
| Huddle communications metadata | Sender and recipient identifiers, group membership, timestamps, delivery status, call start and end time, participants, device and network information, file attributes, safety and abuse signals |
| Contacts and connections | Contacts you enter, invite or choose to connect with; address-book matches where you enable contact discovery; group and relationship information |
| Device and technical | IP address, device and application identifiers, browser, operating system, app version, network, approximate location derived from IP, session, cookie, SDK, telemetry and diagnostic logs |
| Security and fraud | Login history, authentication factors, device reputation, threat indicators, risk signals, suspected abuse, investigation records and communications relevant to disputes |
| Location | Approximate location and, only where enabled and permitted, precise device location for a disclosed feature such as fraud prevention, branch discovery or location-based functionality |
| Communications and support | Emails, support chats, call recordings where notified, tickets, complaints, survey responses, event interactions and marketing preferences |
| Business relationship | Professional contact information, organisation, proposals, contracts, due-diligence information, meeting notes, invoices and relationship history |
| Sensitive or specially protected data | Financial information, identity evidence, biometrics used for verification, health information and other protected data only where necessary and permitted |
4.1 Payment-card security
Payment-card data may be processed by regulated payment providers and tokenisation partners. Eylorin aims to minimise direct handling of full card numbers. We do not ask you to send card security codes through support channels and do not retain them after authorisation where retention is prohibited.
4.2 Contact discovery
If you enable contact discovery in Huddle, we may receive contact identifiers from your device, such as telephone numbers or email addresses, to help determine which contacts use Huddle or to send invitations you initiate. We may use hashing, matching or other minimisation techniques where appropriate. You should enable this feature only if you are authorised to share those identifiers for that purpose. You may disable access through application or device settings.
4.3 Data we ask you not to send
Do not send passwords, PINs, one-time authentication codes, private cryptographic keys, full payment-card details, unnecessary identity documents, medical emergencies or other highly sensitive information through ordinary email or an unauthorised support channel.
5. Product-specific processing
5.1 PayEast
Depending on the feature and market, PayEast data may be used to:
open and secure Accounts;
verify identity and eligibility;
link payment methods;
initiate, route, reconcile and evidence transactions;
calculate or display exchange rates and fees;
manage refunds and disputes;
prevent fraud and financial crime;
provide support; and
meet regulatory, audit, reporting and recordkeeping obligations.
Banks, mobile-money operators, payment networks, FX providers and regulators may process relevant data independently.
5.2 Kinetic Transactions
Kinetic Transactions may process merchant Accounts, staff access, catalogues, inventory, prices, customers, suppliers, orders, receipts, invoices, tax information, till activity, settlement and analytics. Where enabled, it may exchange required information with EFRIS or another fiscal system.
The merchant or enterprise customer is normally the controller of customer and employee records entered into its workspace. Eylorin ordinarily acts as its processor for hosted functions and as an independent controller for security, billing and its legal obligations.
5.3 Kwip
Depending on licensing and partners, Kwip may process onboarding, know-your-customer information, investor classifications, suitability responses, orders, holdings, market activity, funding and withdrawal references, corporate-action notices and compliance records.
Execution, custody, settlement, market infrastructure and regulated investment services may be provided by authorised third parties with independent legal duties and notices.
5.4 Voice Vault Uganda
Voice Vault Uganda may collect recordings, transcripts, translations, vocabulary, dialect or community information, contributor identity, consent, licensing choices, provenance, annotations and moderation records.
A voice may identify a person and may reveal linguistic, regional or cultural attributes. Access and reuse must therefore follow the contributor notice, consent, licence and documented cultural restrictions presented at collection.
5.5 PulseHub Healthcare
PulseHub Healthcare may process patient, provider, appointment, workflow, service, communications and health-related information for authorised healthcare uses. The specific customer agreement and product notice will define whether Eylorin is a controller or processor, authorised user roles, permitted purposes and retention.
Health information receives heightened protection. Eylorin will not use identifiable health records for unrelated advertising or general-purpose external AI model training without a distinct lawful basis, appropriate safeguards and any required consent.
5.6 Huddle
Huddle may process information to:
create profiles and connect users;
route Messages, Files, Stories and Calls;
apply audience, group, block, privacy and notification settings;
display delivery, presence or interaction information where enabled;
synchronise Content across authorised devices;
support encryption, authentication and key or session management;
detect spam, fraud, malware, account compromise and platform abuse;
receive and assess user reports;
provide safety, moderation and appeal functions;
troubleshoot delivery, call quality and application performance; and
enforce legal obligations and the Acceptable Use and Platform Conduct Policy.
Messages and Files
Message and file Content may be stored or transmitted for the period needed to deliver the feature, synchronise authorised devices, support user-selected storage and apply deletion settings. Recipients may make copies outside Huddle. Eylorin cannot delete copies controlled by a recipient or another service.
Stories
Stories may be displayed for a limited period selected or communicated by the feature. Limited visibility does not guarantee immediate deletion from every cache, backup, report, legal hold or recipient copy. Eylorin may retain limited records after expiry for security, complaints and legal compliance.
Calls
Huddle may process call routing, participant, device, network, quality and duration information. We do not record call content unless a recording feature is offered and clearly indicates recording, or another lawful and disclosed basis applies.
Encryption
Huddle may use encryption for supported messages, files and calls during transmission, storage or both. The current product interface or documentation will identify any feature that is end-to-end encrypted.
Encryption does not necessarily conceal metadata needed to route, secure and troubleshoot communications. It also does not protect Content after a recipient displays, copies, exports, screenshots or reports it, or where a device or Account is compromised.
If a user reports encrypted Content, the report may include selected Content and context made available by the reporting user. We do not claim the ability to routinely read end-to-end encrypted Content where the technical design prevents it.
5.7 Websites, APIs, enterprise systems and future Services
Our Websites and enterprise systems may process enquiries, Account data, API credentials, service logs, project contacts and usage analytics. New or materially changed products will receive an additional notice where their processing is not reasonably described here.
6. How we collect personal data
We may collect information:
directly from you, when you register, verify identity, transact, communicate, contribute Content, request support, submit a form or attend an event;
from your organisation, where an employer, merchant, school, healthcare provider, broker, customer or partner provisions access or supplies authorised records;
from other Huddle users, when they communicate with you, add you to a group, share Content, report activity or enable contact discovery;
from transaction participants, such as banks, mobile-money operators, issuers, acquirers, payment networks, merchants, brokers, exchanges, custodians and settlement providers;
automatically, through devices, applications, APIs, cookies, SDKs, local storage, logs, telemetry and security tools;
from verification and compliance providers, including identity, fraud, sanctions, politically exposed person and adverse-information checks where permitted;
from public or official sources, such as registries, professional profiles, sanctions lists and regulator records, subject to law and source terms; and
from service providers and partners, including hosting, communications, analytics, support and integration providers.
7. Purposes and lawful bases
The applicable lawful basis depends on the context and law. Where a law requires a stated basis, Eylorin may rely on the following:
| Purpose | What it includes | Typical legal basis |
|---|---|---|
| Provide and administer Services | Create Accounts, authenticate, route communications, execute instructions, maintain records, deliver features and support | Contract; requested pre-contract steps; legitimate interests; consent where required |
| Process and reconcile transactions | Route payments or orders, calculate fees or FX, reconcile, refund and resolve disputes | Contract; legal obligation; legitimate interests |
| Connect Huddle users | Contact discovery, invitations, profiles, groups, Messages, Stories, Files and Calls | Contract; consent for device permissions; legitimate interests |
| Verify identity and comply with law | KYC, AML/CFT, sanctions, tax, fiscal, securities, communications, audit and reporting | Legal obligation; contract; legitimate interests; public interest where recognised |
| Protect users and Services | Detect fraud, abuse, cyber threats, malware and policy violations; investigate incidents; enforce rights | Legitimate interests; legal obligation; contract; vital interests in exceptional cases |
| Moderate and respond to reports | Assess reported Content, apply policy, preserve evidence, provide appeals and protect people | Legitimate interests; legal obligation; contract; public or vital interests where applicable |
| Improve and develop Services | Quality assurance, diagnostics, analytics, testing, research and product design, preferably using aggregated or de-identified data | Legitimate interests; consent where required |
| Communicate | Service notices, receipts, security alerts, support, surveys and requested information | Contract; legitimate interests; legal obligation; consent where required |
| Marketing | Send relevant offers, measure campaigns and manage preferences | Consent where required; otherwise legitimate interests with opt-out |
| Corporate operations | Billing, accounting, governance, due diligence, restructuring, legal claims, insurance and continuity | Legal obligation; legitimate interests; contract |
| Language contributions | Host, moderate, preserve, license and make authorised material available | Contributor agreement; consent; legitimate interests; research or public-interest basis where lawfully established |
7.1 Consent
Where we rely on consent, the request will be specific and capable of withdrawal. Withdrawing consent does not affect earlier lawful processing. Some Services may become unavailable if required data or device permissions are withdrawn.
7.2 Legitimate interests
Where we rely on legitimate interests, we consider necessity, expected benefits, user expectations, the nature of data, likely impact and available safeguards. Where applicable, you may object. We will stop unless compelling legitimate grounds or legal claims justify continuation.
7.3 Legal obligations and public interests
Financial, securities, communications, fiscal, healthcare, safeguarding and other laws may require verification, monitoring, retention, disclosure or reporting. Eylorin will limit processing to what it reasonably considers necessary and authorised.
7.4 If you do not provide data
Some data is optional. Information marked as required is normally necessary to create an Account, deliver a feature, complete a transaction, connect a communication, verify eligibility or meet legal duties. Without it, we may be unable to provide all or part of a Service.
8. When we disclose personal data
We disclose personal data only where reasonably necessary and permitted. Recipients may include:
people you choose, including Huddle recipients, Story audiences, group members, file recipients and transaction counterparties;
your organisation, such as the customer, employer, merchant, healthcare provider, administrator or workspace owner;
transaction and regulated-service participants, such as banks, mobile-money operators, payment networks, FX providers, brokers, exchanges, custodians, settlement systems and fiscal platforms;
service providers, including hosting, cloud infrastructure, content delivery, cybersecurity, identity verification, fraud prevention, communications, support, analytics, professional advice, document management and disaster recovery;
Eylorin affiliates, where needed to operate Services, manage risk or conduct administration, subject to access controls;
authorities and lawful recipients, such as courts, regulators, tax bodies and law-enforcement agencies where required or permitted;
safety and emergency recipients, where Eylorin reasonably believes disclosure is necessary and lawful to address a serious threat, exploitation, abuse or emergency;
corporate transaction participants, including advisers, financiers, insurers and prospective buyers or sellers under confidentiality safeguards; and
others with your instruction or consent.
We require processors to use personal data only for documented purposes, protect it and support applicable compliance obligations.
8.1 Public and audience-selected information
Profile fields, Stories, group Content, contributions or other information may be visible to the public or an audience you select. Review settings before posting. Search engines, recipients and external services may copy or index public Content beyond Eylorin’s control.
8.2 Legal and authority requests
We assess government and legal requests for authority, scope and legal validity. We may challenge, narrow or refuse a request where appropriate and permitted. We may preserve information while a valid request is assessed. Advance notice may be withheld where prohibited, unsafe or likely to prejudice an investigation.
9. Cookies, SDKs and similar technologies
We may use cookies, local storage, pixels, software-development kits, mobile identifiers and similar technologies to:
keep sessions secure and remember authentication;
store preferences and consent choices;
prevent fraud, abuse and account compromise;
enable communications and product functionality;
measure reliability and performance;
understand aggregate use; and
support marketing only where permitted and appropriately controlled.
Non-essential technologies will not be activated before a required choice. You can use the consent tool, application controls, browser settings or device settings to withdraw or change a choice. Blocking necessary technologies may prevent parts of a Service from working.
Our Cookie Notice and Consent Policy describes categories, control methods and the required deployment inventory.
10. Communications confidentiality and user safety
Eylorin respects the confidentiality of private communications. Access to communication Content is restricted according to technical design, authorised support needs, user reports, security requirements and law.
We do not use private Huddle message or call Content for behavioural advertising. We do not use identifiable private Huddle communications, financial information, health records or confidential customer-workspace data to train a general-purpose external AI model unless a specific lawful basis, appropriate safeguards and any required notice or consent are in place.
Service integrity measures may use metadata, rate information, device signals, user reports, known malicious files or other proportionate indicators. Where encryption prevents access to Content, Eylorin may be unable to detect a violation unless a user reports it or another lawful signal is available.
11. Automated decisions, profiling and artificial intelligence
Eylorin may use rules, statistical models or machine-learning tools to detect fraud, prioritise security reviews, assess transaction risk, identify suspected spam or harmful activity, personalise interfaces or support compliance.
These tools may flag or delay activity, request additional verification, restrict a feature or refer a case for human review. Eylorin will not make a solely automated decision producing legal or similarly significant effects unless authorised by law, necessary for a contract or based on valid consent where required.
When applicable, we will provide meaningful information about the logic and likely consequences and a method to request human review, express your view and challenge the outcome.
Product-improvement testing should use minimised, de-identified or synthetic data where practicable. AI-assisted moderation is subject to human oversight proportionate to the risk and potential impact.
12. International transfers
Eylorin is based in Uganda. Service providers, transaction participants, communications networks or users may process data in other countries with different privacy laws.
Before a restricted transfer, we assess the applicable legal mechanism and safeguards:
for Uganda-related transfers, we use a method permitted by Uganda’s Data Protection and Privacy Act and Regulations, including adequate or equivalent protection, authorised contractual measures or valid consent where applicable;
for EEA data, safeguards may include an adequacy decision, approved standard contractual clauses and supplementary measures;
for UK data, safeguards may include adequacy regulations, the International Data Transfer Agreement or approved addendum and supplementary measures; and
for other jurisdictions, we use the required local mechanism or an appropriate contractual and security framework.
Safeguards may include contractual controls, access restrictions, encryption, pseudonymisation, transfer-risk review and data minimisation. You may request information about a relevant safeguard, subject to redaction of confidential and security-sensitive information.
13. Security
No system is completely secure. Eylorin uses risk-based technical and organisational safeguards designed to protect confidentiality, integrity and availability. Depending on the Service and risk, these may include:
encryption in transit and at rest;
in-chat encryption controls for supported Huddle features;
tokenisation and masking;
multi-factor authentication;
least-privilege and role-based access;
key and secrets management;
logging and monitoring;
secure development and change management;
vulnerability management and testing;
malware and abuse controls;
backups and resilience testing;
incident-response procedures;
personnel confidentiality and training; and
vendor due diligence and contractual controls.
You are responsible for protecting credentials, using strong unique passwords, enabling available security features, securing devices, reviewing audiences and reporting suspected misuse.
14. Personal-data breaches
If a personal-data breach occurs, Eylorin will:
investigate and contain the incident;
assess affected systems, data and people;
preserve necessary evidence;
remediate and reduce ongoing risk;
document required facts and decisions;
notify the relevant customer, authority or affected individuals when and within the period required by law; and
conduct lessons-learned and corrective-action review.
Uganda law requires prompt notification of qualifying breaches to the Personal Data Protection Office. Notification may be delayed or limited where law enforcement, legal privilege, safety or another lawful restriction requires it.
15. Retention and deletion
We retain personal data for the shortest period reasonably necessary for the purpose, while accounting for legal, regulatory, tax, AML/CFT, securities, fiscal, audit, communications, safeguarding, security, dispute and continuity obligations.
| Record | General retention approach |
|---|---|
| Account and profile | For the Account relationship and a reasonable period after closure to complete deletion, resolve disputes and meet legal duties |
| Huddle Messages and Files | According to user settings, delivery and synchronisation requirements, recipient copies, backup cycles, legal holds and safety evidence |
| Huddle Stories | For the displayed duration plus limited technical, complaint, security and backup periods where necessary |
| Huddle call metadata | For call delivery, quality, billing where applicable, security, complaints and lawful retention needs |
| Huddle reported Content | For investigation, appeal, repeat-abuse prevention, legal obligations and claims, with restricted access |
| Transaction, financial and securities | For the period required by financial, tax, AML/CFT, securities, audit and limitation law; this may extend several years |
| Kinetic customer workspace | As instructed by the customer agreement, subject to backup cycles, legal holds and independent legal obligations |
| PulseHub customer workspace | As instructed by the healthcare customer and applicable health-record rules, subject to legal holds and independent obligations |
| Identity and compliance evidence | For applicable verification, regulatory, fraud-prevention and limitation periods with risk-based access restrictions |
| Security logs | For a period proportionate to security, investigation, audit and threat-detection needs |
| Support records and calls | For service, training, complaint and evidence needs, then deleted or de-identified |
| Marketing preferences | Until opt-out or withdrawal, plus a minimal suppression record |
| Voice Vault contributions | For the consent, contributor agreement, licence term and heritage purpose, subject to valid withdrawal and archival commitments |
| Backups | Until overwritten or securely expired; restored data remains subject to the underlying deletion control |
When retention ends, we delete, securely destroy, anonymise or de-identify the data. Deletion may be deferred for legal holds, fraud or security evidence, unresolved disputes, protection of users, exercise or defence of claims or another lawful obligation.
16. Your rights and choices
Subject to applicable law, exemptions and Eylorin’s role, you may have the right to:
be informed about collection and use;
obtain confirmation and access;
correct inaccurate or complete incomplete data;
request deletion or erasure;
restrict or object to processing, including direct marketing;
receive certain data in a structured, commonly used and machine-readable format;
withdraw consent;
challenge certain solely automated decisions and request human review;
opt out of a legally defined sale, sharing or targeted advertising;
limit certain uses of sensitive personal information;
complain to a data-protection authority; and
receive non-discriminatory treatment for exercising a right.
To make a request, email legal-compliance@eylorin.com with the subject “Privacy Request”. Identify the Service and right involved and provide enough information to locate the relevant Account. Do not send sensitive credentials or full identity documents unless we provide a secure method.
We may verify identity and authority, request clarification, refuse or charge a reasonable fee for a manifestly unfounded, excessive or repetitive request where law permits, and retain a record of the request.
If Eylorin acts only for a customer, we may direct the request to that customer. Authorised agents must provide proof of authority, and we may still verify the individual directly.
We will respond within the period required by applicable law. Under Uganda’s framework, rights requests are generally handled within 30 days, subject to the Act, Regulations, lawful extensions and exceptions. We will explain a lawful extension, refusal and available complaint route.
16.1 Huddle controls
Depending on the released features, Huddle may provide controls to:
update profile and audience settings;
manage contact discovery and device permissions;
delete or unsend eligible Content;
leave groups;
block or report users;
manage notifications;
download certain Account information; and
close an Account.
These controls do not remove recipient copies, external exports or records lawfully retained for safety, legal or technical reasons.
17. Children and age limits
Eylorin’s transactional, payment, securities, merchant-administration and enterprise Services are not directed to children and ordinarily require users to be at least 18.
Huddle and a language or education-related feature may permit younger users only where the product design, age rules and applicable law allow it. Where required, Eylorin will use age-appropriate explanations, parent or guardian consent, restricted discovery, safer defaults, reporting and blocking tools, limits on public identifiers and location, and enhanced review of high-risk features.
We do not knowingly collect personal data from a child contrary to applicable requirements. If you believe a child has provided data unlawfully or is at risk, contact legal-compliance@eylorin.com. Eylorin will investigate, take proportionate action and make any required report.
Where the United States Children’s Online Privacy Protection Act applies, a child-directed service or a service with actual knowledge that it processes personal information of a child under 13 will provide required notice and obtain verifiable parental consent before collection, unless an exception applies.
18. Communications and marketing
We send essential operational messages such as receipts, security alerts, legal notices, moderation outcomes and service updates. These are not marketing and may continue while you use the relevant Service.
Marketing messages are sent where permitted. You can unsubscribe using the message link, reply instruction, in-app preference or legal-compliance@eylorin.com. We may retain a suppression record to respect the choice. Your opt-out does not stop messages sent independently by another user, merchant, bank, broker, healthcare provider or third party.
19. Third-party services and app permissions
Services may link to or integrate with app stores, device operating systems, maps, identity providers, payment methods, communications networks, social platforms or regulated institutions. Eylorin does not control their independent processing.
Your device may request permissions for contacts, microphone, camera, photos, Files, notifications or location. The purpose should be explained at or before permission. You can manage permissions in device settings, but disabling them may prevent the related feature from working.
20. Sale, sharing and targeted advertising
Eylorin does not sell personal data for money. We do not use private Huddle communications, identifiable financial data, health records or confidential customer-workspace data for behavioural advertising.
If Eylorin introduces a practice legally defined as selling or sharing personal information or using it for targeted advertising, we will provide the required notice, consent or opt-out method before relying on it. Where applicable, we will recognise qualifying browser-based preference signals such as Global Privacy Control.
21. Changes to this Notice
We may update this Notice to reflect new Services, practices, legal requirements or safeguards. We will post the revised version with a new effective date.
If a change materially affects your rights or how we use data, we will provide additional notice through the Service, email or another appropriate channel and obtain consent where required. Earlier versions may be requested from legal-compliance@eylorin.com.
22. Contact and complaints
Privacy, personal-data, policy, legal and compliance enquiries and rights requests:
Eylorin Technologies Limited | For the attention of: Privacy Lead or designated Data Protection Officer | Plot 3 Bata Close, 5th Street Industrial Area, Kampala, Uganda | P.O. Box 200473, Kampala, Uganda | Email: legal-compliance@eylorin.com | Telephone: +256 393 104 233 | Website: www.eylorin.com
General product or service enquiries not concerning privacy, policy, legal or compliance matters: support@eylorin.com.
We encourage you to contact Eylorin first so we can investigate. You may also complain to the Personal Data Protection Office in Uganda or the data-protection authority in the country where you live, work or believe an infringement occurred.
Schedule A: Processing overview by person and product
| Person or context | Main data | Main purposes |
|---|---|---|
| Website visitor | Device, cookie, enquiry and usage data | Operate and secure the Website; respond; measure use |
| PayEast user | Identity, contact, payment, FX, transaction, device and risk | Onboard; transact; reconcile; comply; support |
| Kinetic merchant user | Account, role, retail, inventory, invoice, tax, customer and device | Operate workspace; fiscal integration; reporting |
| Kwip user | Identity, investor profile, orders, holdings, funding and compliance | Access market features through authorised participants |
| Voice Vault contributor | Identity, voice, transcript, language, consent, licence and metadata | Curate, preserve, moderate and lawfully share |
| PulseHub user | Identity, role, provider, appointment, workflow and health-related data | Provide authorised healthcare workflow features |
| Huddle user | Profile, contacts where enabled, Messages, Stories, Files, Calls, metadata, reports and settings | Connect users; route communications; secure and moderate the service |
| Developer | Identity, organisation, API credentials, logs and integration records | Provision, authenticate, monitor and support APIs |
| Business contact | Professional details, correspondence, contracts and due diligence | Sales, partnership, procurement and governance |
Schedule B: Jurisdiction-specific information
B.1 Uganda
Eylorin’s principal privacy framework is Uganda’s Data Protection and Privacy Act, 2019, published in the revised laws as Cap. 97 where applicable, and the Data Protection and Privacy Regulations, 2021.
These rules address lawful and fair processing, notice, consent and other permitted grounds, purpose limitation, data quality, security, retention, individual rights, registration, breach notification, impact assessment and transfers outside Uganda.
Eylorin must maintain any required registration as a data collector, controller or processor with the Personal Data Protection Office and designate a personal data protection officer where required. Publication of this Notice is not evidence of registration, licensing or regulatory approval.
B.2 European Economic Area
Where the EU General Data Protection Regulation applies, the controller identity, purposes, data categories, lawful bases, recipients, transfers, retention criteria and rights described in this Notice apply as supplemented by the relevant point-of-collection notice.
Eylorin will appoint an EEA representative where legally required and publish contact information. Individuals may complain to their local supervisory authority.
Where the EU Digital Services Act applies to a Huddle feature, Eylorin will address applicable transparency, notice-and-action, statement-of-reasons, complaint and content-moderation duties through the relevant product processes and notices.
B.3 United Kingdom
Where UK data-protection law applies, this Notice is intended to address the UK GDPR and Data Protection Act 2018 as amended, including relevant changes under the Data (Use and Access) Act 2025.
Eylorin will appoint a UK representative where required and publish contact information. If Huddle is a regulated user-to-user service under the Online Safety Act 2023, Eylorin must complete the applicable risk assessments, safety measures, reporting and user-protection duties before or while making the service available to UK users.
B.4 California and similar United States laws
If Eylorin is subject to the California Consumer Privacy Act or a similar state law, eligible residents may request to know, access, correct or delete covered personal information; receive portability information; opt out of legally defined sale, sharing or targeted advertising; limit certain uses of sensitive information; and receive non-discriminatory treatment.
The categories collected and disclosed are described in sections 4 and 8 and Schedule A. If Eylorin introduces a covered sale or sharing practice, it will provide the required method and recognise qualifying preference signals where required.
B.5 Other countries
Local privacy, communications, online-safety, consumer, financial-services, tax, securities, healthcare and cybersecurity laws may provide additional rights or impose different requirements. Where applicable, Eylorin will provide a local supplement. Nothing in this Notice limits a non-waivable right.
Schedule C: Key definitions
| Term | Meaning |
|---|---|
| Controller | A person or organisation that determines the purposes and essential means of processing personal data |
| Personal data or personal information | Information relating to an identified or reasonably identifiable individual, as defined by applicable law |
| Processing | Any operation performed on data, including collection, recording, organisation, storage, retrieval, use, disclosure, analysis, restriction, deletion or destruction |
| Processor or service provider | A person or organisation that processes personal data for a controller under instructions |
| Sensitive or special data | Data receiving heightened legal protection, which may include financial, biometric, health, political, religious, sexual-life, precise-location or government-identifier data |
| De-identified data | Data processed so it cannot reasonably be linked to an individual, subject to safeguards against re-identification |